Settings
/settings is a full-page workspace for profile, appearance, and (platform
admins) the Control Center. Open it from Settings at the bottom of the
sidebar or in the account menu. Bookmark a tab with ?tab=appearance or
?tab=control§ion=overview.
Profile (everyone)
Edit display name. The hero shows key count, team count, and last updated. The account card lists role, status, email, member since, and organizations. Memberships lists every org and team you belong to.
Email notifications has the Weekly digest email switch (on by default): a Monday summary of your spend, keys that need attention and requests waiting on you. Preview my digest opens this week's version in a new tab. Weeks with nothing to report are not sent.
Appearance (everyone)
Theme and display preferences, applied immediately and saved to your account. There is no separate Save button.
- Display preferences: Dark mode, High contrast, Compact density and Right to left switches.
- Layout and navigation: Sidebar, full or mini (the icon rail; see Navigating the portal). Navigation color (Integrate / Apparent) only changes the Interface preview; the sidebar ignores it.
- Brand colors: eight accent presets: Violet (the default), Cobalt, Green, Cyan, Purple, Blue, Orange and Red.
- Typography: Geist (the default), Public Sans, Inter, DM Sans or Nunito Sans, and a root font size from 13 to 20 px (default 16).
- Interface preview: a miniature of the current theme.
Two of these also have shortcuts outside Settings. The Dark / Light toggle in the top bar sets dark mode. The top-bar menu button and Ctrl+B (Cmd+B on macOS) switch the sidebar between full and mini; on FinOps Analytics that switch is temporary.
Reset to defaults restores every preference, including the Violet preset. Any appearance change saves the whole set, including the preset. If you changed an appearance setting (even dark mode or the sidebar width) before Violet became the default, you keep the preset saved then until you pick another one or reset.
Control Center (platform admin)
One domain at a time via underline tabs: Overview, Identity, Security, Integrations, Logging, and Cost. Existing admin pages stay the source of truth; this tab surfaces status and owns only the channels that had no home.
Overview
Four status cards from live data: master-key health plus Entra/SMTP,
integration counts, security (key source and payload logging), and this
month's SpendLog cost. Cards jump into Integrations, Security, or Cost.
Identity
Entra SSO status from AZURE_AD_* environment variables, directory counts,
and jumps to Users, Organizations, Teams, and Access and Tiers.
Security
- Payload logging (
logging.storePayloads) — store truncated request and response bodies on Request Logs. Off by default. - Encryption and secrets — master key source (env or Azure Key Vault), AES vs vault credential counts, and Re-encrypt credentials. Follow the rotation runbook.
- Audit explorer.
Integrations
A logo list (Slack, Teams, Email) with category, description, status pill,
enable switch, and Details. The switch enables a channel that already
has config. Secrets are stored encrypted and shown as Configured · …last4.
- Slack and Microsoft Teams — incoming webhook URL, event checkboxes, Test. Portal notifications and gateway budget alerts fan out here.
- Email — SMTP stays in environment variables. This card enables fan-out and optional extra admin recipients. Email stays on until you turn it off (no saved row still sends SMTP).
Events: budget alerts, key request submitted/approved/rejected, temporary budget granted, membership changes.
Webhook URLs must be HTTPS and cannot target private hosts.
Logging
Datadog, Splunk HEC, and a generic HTTPS log webhook appear in the same
list layout. They save config and send a sample test event. They do
not stream live SpendLog volume.
Cost
Status for active chargeback rate cards plus jumps to Chargeback, FinOps Analytics, Budgets, Cost Centers, and model pricing. Rate-card editors stay on Chargeback.