The decision
Session expiry should protect access without unexpectedly erasing work. Decide what can be preserved, how the user is informed, and where they return after signing in again. The behavior should fit the sensitivity of the data and the task.
In practice
A staff member completing a long inspection should not discover at submission that the app silently stopped accepting requests. Warn or recover appropriately, preserve permitted draft data, and make reauthentication understandable.
- Test expiry during editing, upload, approval, and background activity.
- Confirm what remains on the device and what is sent to the server.
- Review shared-device use and avoid restoring private content to the wrong account.
When to take the next step
Review expiry behavior before releasing long forms or field tasks. Use realistic task durations and inspect what happens when the user returns from background activity.
Questions clients ask
Should every draft survive logout?
No. Define draft storage according to the data, device context, and access requirements.
What should happen after login?
Return the user to a valid task state and explain whether a draft was retained.

