Skip to main content

Settings catalog

A find-anything reference for workspace admins. Every row points to the in-app Settings page where the setting lives, names the exact toggle or field the customer sees on screen, lists the default value where one applies, and links out to the page that documents the setting in depth.

For the workflow-style narratives (how to invite a teammate, how to add a cloud account, how to enable SSO), follow the linked pages. This catalog is the lookup table.

No UI on this page

This is a reference index. The settings live on the pages it links to.

How the in-app Settings nav is organised

The settings sidebar in the app groups pages into four collapsible categories:

  • Profile is per-user. Each teammate manages their own profile, password, and two-factor authentication. Workspace admins do not control these for others.
  • Organization is workspace-wide. Roles, team membership, the workspace timezone and assignment defaults, single sign-on, and the audit trail all live here.
  • Infrastructure is the data-source layer. Cloud credentials, on-prem agents, FortiGate firewalls, Windows servers, and the site groupings that hold them.
  • Billing Settings routes from the workspace selector to the per-tenant subscription page.

Pages are gated by role. If a row is missing from your sidebar, your role does not have the matching permission. See Roles and permissions for which gates control which pages.

Account settings

The Profile section of the settings sidebar holds the per-user controls. Every Retrievy user has the same two pages and can change their own values without an admin.

In-app pageWhat you controlDefaultDocumented in
My ProfileFull Name and Email Address on your user record, plus the Resend verification email action when your address is unverified. Avatar is generated from your initials and not editable.Name and email captured at signup or invitation.Profile and 2FA
Password & 2FAThe Update password form (current password, new password, confirmation) and the Two-factor authentication card (Enable 2FA, Disable 2FA, View recovery codes, Regenerate codes).2FA off until you enable it. Passwords required at signup, no expiry.Profile and 2FA
AppearanceTheme switcher with Light, Dark, and System. Reached via the Settings → Appearance URL; not surfaced in the settings sidebar in tenant mode.System (follows OS preference).Workspace settings (Personal appearance section)
SSO-provisioned accounts

If your account was created by signing in with Google or Microsoft, the Update password section is permanently disabled and password login is blocked at sign-in. Manage your password through your identity provider instead.

Organization settings

The Organization section holds the workspace-wide controls. The page heading you see on screen sometimes differs from the sidebar label, so both are listed below.

Sidebar labelPage headingWhat you controlDefaultDocumented in
General SettingsTenantScan Timezone dropdown, the six Assignment & Attribution toggles and numeric fields (Auto-claim on Mark-as-Fixed, Auto-assign from remediation projects, Lock status transitions to the assignee, Daily assignment digest email, Stale claim timeout (days), Digest send hour), and the Clear assignments for deactivated users admin tool.Timezone UTC. All four toggles on. Stale claim timeout 14 days. Digest send hour 8 (8 a.m.).Workspace settings
Roles & PermissionsRoles & PermissionsThe role builder. Permission toggles per role, Data Scope (all or scoped to selected cloud accounts, identity sources, or devices), role create or delete.Stock roles: tenant-admin (workspace owner, bypasses every check), manager, user.Roles and permissions
Team MembersTeam MembersInvite users by email with a role attached, change a user's role, block or unblock a user, and delete users who have never logged in.Workspace owner is the only seat at creation.Roles and permissions (Team Members section)
Single Sign-OnSingle Sign-OnConfigure Google Workspace or Microsoft Entra ID as the identity provider, paste in Client ID and Client Secret, and toggle Enforce SSO Only to block password sign-in once SSO is verified.SSO disabled. Enforce SSO Only off. Plan-gated on Advanced and Build Your Own.Microsoft Entra ID SSO, Google Workspace SSO
Exceptions ManagementSecurity ExceptionsBrowse, edit, extend, and revoke security exceptions, plus the Accept Risk dialog reached from any finding.No exceptions until an admin accepts one.Security exceptions
Audit TrailForensicsRead-only stream of every audited write in the workspace. Filters by event type, user, resource, IP, and date range. Live updates via the Real-time Live chip.All events recorded once enabled. Plan-gated on Advanced and Build Your Own.Audit trail

Infrastructure settings

The Infrastructure section holds the data-source controls. Each connected provider, on-prem agent, firewall, or domain becomes a row on one of these pages.

Sidebar labelPage headingWhat you controlDefaultDocumented in
Sites ManagerSites ManagerCreate, edit, recolour, and delete Sites. A site is a label for a group of agents or devices (typical use is one site per office or data centre). Fields: Name, Location, Description, colour swatch from a 12-colour palette.No sites until you create one. Colour defaults to #6366f1 (indigo).Agents (sites section)
Cloud CredentialsCloud IntegrationsThe list of connected cloud accounts per provider (AWS, Azure, GCP, Microsoft 365, OCI, Cloudflare, Kubernetes). Edit, Test Connection, Run scan now, deactivate, and delete actions per row. The Add data source button opens the multi-provider wizard.No cloud accounts until you connect one.Integrations, and per provider: AWS, Azure, GCP, Microsoft 365, OCI, Cloudflare
Windows ServersWindows ServersInventory of Active Directory domains reported by every Windows agent. Drill into a domain to see which sites and agents cover it, scan freshness, and trigger a Scan now for the domain.Populated automatically once a Windows agent reports its first domain.Active Directory, Agents
FortiGate FirewallsFortiGate FirewallsInventory of FortiGate devices. The three-step Add a FortiGate Device wizard collects Identity (name, host, port, VDOM, HA flag, site, tags), Connect (which Docker agent proxies the connection, Verify SSL), and Auth (SSH username and credentials, optional REST API token).Port 443, Verify SSL on, no HA cluster. Documented separately.FortiGate
AgentsAgentsFleet view of every installed Retrievy Agent (Windows MSI and Docker). Status, version, sites, modules, Scan now, Rotate token, Revoke, and the install-token generator under New Token.No agents until you install one. Install tokens are single-use and expire 60 minutes after issue if unredeemed.Agents, Windows MSI install, Docker install

Billing settings

The Billing Settings entry in the settings sidebar opens the per-tenant Subscription Management page. If you own multiple Retrievy workspaces, a selector modal opens first so you pick which workspace to manage.

In-app pageWhat you controlDefaultDocumented in
Subscription ManagementPlan tier (Essentials, Advanced, Build Your Own), Build Your Own sliders (Data sources, Seats), monthly versus yearly cadence, Cancel subscription, Reactivate subscription, Pay outstanding balance.Trial workspace until you subscribe. Yearly cadence on flat plans, monthly only on Build Your Own.Subscriptions, Plans and pricing
Stripe Portal (button)Opens the Stripe Customer Portal in a new tab. Payment method, billing address, tax ID, and invoice history live there.Sourced from the card on file at signup.Subscriptions (Stripe Portal section)
Plan feature matrixSide-by-side capability grid across all plans. Not a setting, but the reference customers reach for when comparing tiers.n/aPlan feature matrix
Cancellation and reactivation timing

Cancellation takes effect at the end of the current billing cycle. The workspace stays read-only for 30 days after cancellation with a Reactivate Subscription button, then falls back to the Essentials baseline. See Plans and pricing for the full failure flow.