Administration and Configuration
The Configuration workspace is where administrators manage tenant-scoped settings. It may include members, tenant profile, billing, permissions, API keys, integrations, and audit history.
Administrative safeguards
- Grant the least-privileged role needed for each person.
- Review the tenant identity before inviting members or changing integrations.
- Store API keys in an approved secret manager and rotate them if exposure is suspected.
- Test integrations with a limited scope before enabling broad collection or actions.
- Use audit history to investigate a configuration change; do not rely on memory alone.
Administrative workflows
| Surface | Operator workflow |
|---|---|
| Members and permissions | Verify tenant and role, invite or update the member, then confirm the resulting access in the audit log. |
| Tenant settings | Review the existing tenant identity and operating configuration before saving a scoped change. |
| API keys | Create keys only for an identified workload, store them in an approved secret manager, and rotate exposed keys immediately. |
| Integrations | Start with the narrowest available scope, validate delivery with non-sensitive evidence, then record the owner and recovery path. |
| Billing | Confirm the tenant and billing owner before viewing or changing account information. |
| Audit log | Filter by actor, resource, action, and time range to investigate a change or retain evidence. |
Configuration changes are tenant-scoped. If a setting is unavailable, confirm your role and whether the capability is enabled for the deployment rather than attempting a change through an unrelated API or browser session.
For managing users and tenant access, see Tenant and user administration. For help with an account-specific setting, contact Pavri Support.