Show users all their active sessions with device type, location, and last activity timestamp. Allow revoking specific sessions remotely and enforce maximum concurrent session limits per user.
If a team member's credentials are compromised, we need to see active sessions and kill unauthorized access immediately. This is basic security hygiene that's currently missing.
