Settings
Settings is where an administrator configures how the whole instance behaves: the language people land in, the scales assessments are scored on, how risk matrices are drawn, what a day of work costs, and which security policies are enforced at login. Everything here is instance-wide, so a change lands for every user in every domain.
Where to find it
Section titled “Where to find it”Extra → Settings in the sidebar. It requires the permission to change global settings, so most users never see it.
The page is organised as tabs: General, SSO, Feature flags, Vulnerability SLA policy and Sec intel feeds, with Webhooks appearing when outgoing webhooks are enabled.
General settings
Section titled “General settings”The General tab is a stack of collapsible sections.
Language
Section titled “Language”Default language sets the locale new users start in. Below it, Force language for all users is a one-off administrative action that overwrites every existing user’s preference with the default — it asks for confirmation twice, because it cannot be undone and people who deliberately chose another language will lose that choice.
Workspace
Section titled “Workspace”Default landing chooses the page users arrive at: Analytics, respondent mode, or a portal. Personal folders and Personal folders parent control whether each user gets a private workspace and where those folders are created. Show get started button toggles the onboarding entry point, and Default packager sets the identifier stamped on libraries you author.
Notifications
Section titled “Notifications”A single switch enables outgoing email notifications for deadlines, assignments and status changes. Leave it off until the mailer is configured, or users will see notification settings that never produce mail.
Assets
Section titled “Assets”Security targets scale sets the range used when scoring security objectives on assets — the default is 1 to 4. Change it to match your internal classification before people start scoring; re-scaling afterwards means revisiting existing assessments.
Compliance assessments
Section titled “Compliance assessments”Disable partially compliant result removes that option from requirement scoring when your methodology only allows a binary answer. Audit tree aggregation strategy decides how a parent audit’s result is derived from its children: none, parent wins, child wins, best case or worst case.
Risk matrix
Section titled “Risk matrix”These options control display only, never the underlying scores: aggregate scenarios on the matrix, swap the axes, flip the matrix vertically, and choose the label set — ISO 27005 or EBIOS RM — used for the axes. Pick whichever orientation your risk team already reads matrices in.
EBIOS radar parameters
Section titled “EBIOS radar parameters”Green, yellow and red zone radii for the EBIOS RM radar chart, so the zones match your severity thresholds.
Financial settings
Section titled “Financial settings”Currency and Daily rate feed the cost model. The daily rate is what converts people-days recorded on an applied control into money, so an annual cost per control can be computed and rolled up.
Requirement mapping sets
Section titled “Requirement mapping sets”Mapping max depth caps how many hops a chained framework mapping will follow before the platform stops. Raising it finds more indirect equivalences and costs more computation.
Workflows and assignments
Section titled “Workflows and assignments”Allow self validation decides whether someone may approve their own submission. Allow assignments to entities extends ownership fields to third-party entities rather than internal actors only.
Security
Section titled “Security”The security block carries the login and session policy: warn on external links, Enforce MFA for every account, Account lockout after repeated failures, and Session lock with its Idle timeout in minutes. Enforce MFA and session lock are the two most commonly required by frameworks — turn them on before an audit rather than during one.
The other tabs
Section titled “The other tabs”SSO configures SAML and OpenID Connect providers. Vulnerability SLA policy sets remediation deadlines per severity. Sec intel feeds manages the advisory feeds that enrich the security advisories catalogue.
Feature flags switches whole modules on and off, and has its own page: see Feature flags.
Related
Section titled “Related”- Feature flags — enabling and disabling modules.
- Applied controls — where the daily rate is used.
- Data wizard — bulk-loading data once the instance is configured.
