Settings & Team
Settings are split in two: Settings covers your personal profile and account security, while Organisation covers everything shared by your team — members, API keys, notifications, risk tolerance, SLA policy, and compliance frameworks.
Personal Settings
Navigate to Settings to manage your own account.
Profile
- Update your display name
- View your email address (read-only)
Password
- Change your password from Settings → Security
Two-Factor Authentication
- Navigate to Settings → Security → Two-Factor Authentication
- Click Setup 2FA
- Scan the QR code with your authenticator app
- Enter the verification code
- Save your backup codes in a secure location
Store backup codes securely. If you lose access to your authenticator app, backup codes are the only way to recover your account.
Active Sessions
- View all active sessions (device, IP, last activity)
- Revoke sessions you don't recognise
- Current session is marked
Organisation Settings
Navigate to Organisation to manage shared configuration:
- Organisation — update the organisation name
- Team — invite, manage, and remove members (below)
- API Keys — create and revoke keys for the REST API
- Notifications — in-app, email, and Slack channels, plus the security digest email (frequency and recipients)
- Policy Management — automated policy review workflows
- Risk Tolerance — maximum acceptable risk level per category; risks exceeding tolerance are flagged in the risk register
- SLA Policy — remediation deadlines per AI-adjusted severity (see SLA Policies)
- Compliance Frameworks — the frameworks your organisation tracks
- Billing & Plan — current plan, usage limits, and AI token usage
Team Management
Inviting Members
- Navigate to Organisation → Team
- Enter the email address
- Select a role (member, admin, or viewer)
- Click Invite
- Invitations expire after 7 days
- Resend or revoke pending invitations as needed
Roles
| Role | Permissions |
|---|---|
| Owner | Full access including team management and org settings |
| Admin | Full access except ownership transfer — can manage settings and team |
| Member | Standard access — can view and edit findings, actions, policies |
| Viewer | Read-only access to all data |
Removing Members
- Owners and admins can remove members from the team section
- Removed members lose access immediately