Tenant Admins manage branding, usage, subscriptions, members, and content packs. Viewers are read‑only; Creators/Admins can create and upload.
API connection settings. These are auto-detected from the deployment config. Change only for local development or debugging.
Enable SSO/SCIM and domain restrictions by upgrading to Enterprise. This will open checkout prefilled; domain verification and SSO setup are handled after upgrade.
View and manage organization members. Change roles (Viewer, Creator, Admin, Owner) and resend pending invites.
Manage organizational structure (Groups and Business Units). Nodes can be assigned to units for filtering and grouping.
Admin action audit trail. Filter by event type (invites, role changes, etc.) to review recent activity.
Customize your organization's look and feel. Colors and logo appear in the app navbar and accents.
{}Primary and secondary colors drive the navbar and accents. Logo renders at 28px height.
Current plan and feature gates for this organization, as returned by the Control Plane.
Organization-level feature flags that control user capabilities.
When disabled, only Owner and Admin roles can access prompt editing. Useful for locking down prompts after the pilot phase.
{}Aggregated AI token consumption and API call counts for this organization.
{}Shows subscription status if your role permits (Owner/Admin/BillingAdmin).
{}Read-only view of External Data Plane and Custom AI Provider configuration for this Org.
{}Add Creator seats or Business Lever add-on. Opens a Stripe checkout link you can share with your billing contact.
Single Sign-On (SAML/OIDC) and SCIM user provisioning are configured at the infrastructure level. Domain claims restrict org membership to verified email domains.
To configure or change SSO/SCIM settings, contact your platform administrator. Changes take effect on next user login.
Send read-only viewer invitations. Viewers are free and don't count toward seat limits.
{}Manage custom AI prompt packs. Publish a pack to override default system prompts for all users in your organization.
Set an organization AI key used by the App when Remote AI is enabled.
Tip: First set Control Plane Base URL and Org Id at the top of this page. Then save your key here and click Refresh to see a masked reference below.
The input field shows what you type; masking appears only in the server response and JSON preview.
Azure OpenAI requires these additional fields:
A binding saved to the wrong provider can be corrected with Save/Rotate, or removed with Disable above (the stored key is retained, so re-saving the provider just overwrites it). Keys are never displayed — only masked references.
{}OpenAI uses model IDs. Azure OpenAI uses deployment targets; model name and version are capability metadata.
Targets are configured manually. Saving does not discover or provision Azure deployments.
Effective effort is provider default in this release.
{}