For preventative measures, when the system is accessed with a token we should check the device and if a mismatch from the logged-in device, notify the user.
- unsure if expire token and force re-login for both
- unsure if prevent access for new device only (most likely)