Settings
Settings is where tenant admins shape the tenant behind daily work. Each area below manages one slice: identity, membership, hygiene, external connections, and operating config. Agent capabilities (MCP, plugins, skills, tools, models) live under Agent Ops, not here. Get the required parts right during Day-0; revisit the rest deliberately, not accidentally.
Org: organization name, domain, and branding. What is required, what is cosmetic, what lands in audit.
Org SSO: how this org authenticates at /settings/organization/sso.
Org branding: tenant presentation touches.
Org members: the org-scoped read view; admin actions live in People.
Org audit: the org-scoped record of what changed and who changed it.
Org egress: where this org’s data is allowed to leave to.
Org agents: which agents are available to this org.
Org data export: bulk export discipline across the egress boundary.
People: inviting members, pending invites, offboarding, and the quarterly membership review.
Roles: what each role can do. System roles with keys, assignment in People.
Job Roles: the position catalog. Titles behind staffing and assignment, not access (screenshot pending).
Security: sign-in hygiene, least privilege, session and approval hygiene, and what to watch.
Security architecture: how client secrets stay protected across the vault and managed storage (diagram pending).
Integrations / Connectors: how external applications plug in. Packages own auth, install, config, and scheduling; code existing is not the same as connected.
Connector binding: the last mile to org scope. Coordinates, destinations, and the authorized runner.
Field Mappings: source-to-destination bindings per org, package, and connection (screenshot pending).
MCP registry: MCP capabilities moved here from Settings. Platform catalog vs. tenant install, OAuth profiles, verify before use.
Persona Roles: buying-role labels (Champion, Decision Maker, Economic Buyer, End User, Gatekeeper, Influencer) used against products or services.
Notifications: event catalog and per-channel delivery templates for Email, Slack, and Webex.
Objects: organizational and platform object groups behind lists and records.
Custom Fields: tenant-specific fields on records, defined once and used everywhere (screenshot pending).
Workflows: workflows, status counts, and unified status mappings.
Triggers: what starts automated work, and keeping triggers narrow (screenshot pending).
Deals: deal pipelines with stage probabilities for weighted forecasting.
File Tags: predefined tags and categories for file organization.
Logs: searchable system and jobs logs with level, type, user, and date filters.
Menu: sidebar quick links, sections, groups, and items behind product navigation.
Table Views: public views per list and the org default per list.
Tooltips: guided onboarding tooltip tours with steps and status.
Work Item Types: types, fields, and defaults behind tracked work.
Work Schedules: working hours, time off, categories, and user assignments.
Roles pair with settings
Section titled “Roles pair with settings”Settings manages the tenant; Roles decides what members may do. People is the who, Roles is the what they may do. Keep admin count at 3 or fewer with absence coverage, grant smallest sufficient role at invite time, and review membership quarterly.
If your tenant shows settings sections beyond these, treat the product UI as the source of truth for those.

