Skip to main content

Overview

System settings provide access to low-level configuration values organized by category. These settings control database connections, authentication, job processing, infrastructure, and AI model behavior. Navigate to Admin > Settings > System Settings.

Categories

Settings are organized into tabs by category: Each tab shows the number of settings in that category.

Viewing Settings

Settings are displayed as key-value pairs with:
  • Setting name
  • Current value (encrypted values are masked)
  • Read-only indicator (for settings that cannot be changed from the UI)

Editing Settings

Settings marked as editable can be modified directly from the admin panel. Read-only settings must be changed through environment variables or the Django admin interface.
Only settings marked “Show in Dashboard” in the Django admin are visible here. If you need to access additional settings, use the Django admin interface or configure them via environment variables.
Changing system settings can affect the behavior of the entire platform. Ensure you understand the impact of a change before saving. Some changes may require a server restart to take effect.

Asking the Copilot

The Admin Copilot panel (⌘J / Ctrl+J) sees the settings of the category you have open and the reference below, and can:
  • Explain a setting in plain words — what it controls and what a value means in practice — citing this page. It checks that the admin guide is indexed first; if the index is out of date it says so and offers the re-index rather than answering from memory.
  • Propose a change when you ask (“set it to enforce”, “is this set up right?”) as a card listing setting · current → proposed · reason. Apply stages the value in the page’s form exactly as if you had typed it — it is not saved — and the page’s own Save persists it, with the same validation, confirmations, and permissions as a hand edit.
Encrypted settings are shown to the copilot only as set or not set and can’t be proposed — a person types those. If you can’t save on this page, the copilot explains without proposing.

Settings Reference

Legend: Settings prefixed with 🔒 store encrypted values. Settings marked (Dashboard) are visible in the admin dashboard UI. Settings marked (Client) are accessible to the frontend client application.

LLM Settings

Produced Documents in Chat Context

When a flow writes a document into a conversation, an excerpt of that document is included in the chat’s context as a head start on follow-up questions about it. The two caps bound that excerpt only — they are not the limit of what the assistant can see, because it can also list the documents produced in the conversation, search inside one, and read any part of it on demand (each read is access-checked for the person asking). They still matter, because the excerpt is what the assistant has before it goes looking. PRODUCED_DOC_CONTEXT_CHARS bounds the document text in a single excerpt. PRODUCED_DOC_CONTEXT_TOTAL_CHARS is spent on document text and on the sentences that announce a cut — an excerpt that had to be truncated carries that sentence on top of its own allowance, and the sentence is charged in full against the conversation budget. A conversation full of truncated documents therefore carries less document text than the total alone suggests. The conversation budget is spent newest first, so the document the flow just wrote — the one the user’s next message is almost certainly about — keeps its excerpt, and older documents give way instead. Nothing is dropped quietly: an excerpt that was cut short says so, and a document that got no budget at all is still named in the context as existing, with its body omitted. That announcement is deliberately exempt from PRODUCED_DOC_CONTEXT_TOTAL_CHARS — saying a document exists must not be starved by the budget it is announcing — so the injected text can exceed the total by one short fixed sentence for every document whose body was omitted. A truncation notice is never cut in half either, because half a notice reads as document text: when the leftover budget cannot hold body text plus a whole notice, that document degrades to the omission announcement instead of getting a sliver of body.

DB Settings

Graph connectivity uses GRAPH_PROVIDER plus either the Neo4j or FalkorDB connection group. See Graph backend (Neo4j & FalkorDB) for how switching works and when to run a migration.
Older deployments may still list USE_NEO4J, USE_FALKOR, FALKOR_DB_USER, or FALKOR_DB_PASSWORD. Those keys are legacy; GRAPH_PROVIDER with NEO4J_* / FALKOR_* is authoritative for new installs and the dashboard. Prefer aligning configuration with the rows above.

AUTH Settings

Login Methods

ALLOW_PASSWORD_LOGIN, ALLOW_MAGIC_LINK_LOGIN, and ALLOW_SELF_REGISTRATION control which authentication paths the public login/register pages expose. They compose with USE_PROPELAUTH and ALLOW_HYBRID_LOGIN:
  • For SSO-only tenants, set ALLOW_PASSWORD_LOGIN=False, ALLOW_MAGIC_LINK_LOGIN=False, ALLOW_SELF_REGISTRATION=False, USE_PROPELAUTH=True, and ALLOW_HYBRID_LOGIN=False.
  • Magic-link login requires a working email provider (see Transactional Email below). The link is valid for MAGIC_LINK_TOKEN_TTL_MINUTES minutes.

Transactional Email Deliverability

The AZURE_ECS_SENDER_ADDRESS, AUTH_FROM_DISPLAY_NAME, and AUTH_REPLY_TO_ADDRESS settings together control how outbound auth emails appear to recipients and to mailbox spam filters:
  • The From: line is rendered as "<AUTH_FROM_DISPLAY_NAME>" <AZURE_ECS_SENDER_ADDRESS> (e.g. "Experio" <login@experiolabs.ai>).
  • A Reply-To header points at AUTH_REPLY_TO_ADDRESS so replies land in a monitored inbox instead of bouncing off the no-reply sender.
  • Every send also sets Message-ID (with the sender’s host), Date, and Auto-Submitted: auto-generated, and ships a real plain-text alternative alongside the HTML body — these reduce the chance of the message landing in junk.
  • AZURE_ECS_SENDER_ADDRESS must be a verified MailFrom on the Azure ECS linked domain. Update it (and the corresponding domain verification) if you re-brand the sender.

SSO / PropelAuth

The five PropelAuth settings (USE_PROPELAUTH, PROPELAUTH_API_KEY, PROPELAUTH_AUTH_URL, PROPELAUTH_SSO_USERS_ACTIVE_BY_DEFAULT, and ALLOW_HYBRID_LOGIN) work together to enable enterprise Single Sign-On. See the SSO Configuration page for complete setup instructions, identity provider guides, and troubleshooting.

Google Workspace Integration

The GOOGLE_MCP_CLIENT_ID and GOOGLE_MCP_CLIENT_SECRET settings enable per-user Google Workspace MCP integration. See the Integrations page for setup instructions.

CORE Settings

Persona feature flags

PERSONAS_ENABLED and REQUIRED_PERSONAS ship off so existing tenants are unaffected until you opt in. See Personas for the behavior matrix, admin workflow, and deploy checklist.
  • PERSONAS_ENABLED — Off hides persona gate, profile picker, and composer toggle; the agent does not inject identity or run persona graph nodes. Admin Settings > Personas stays available for seeding.
  • REQUIRED_PERSONAS — On (with master on) blocks the app until the user picks a persona. Seed active personas and gating forms before enabling.

JOBS Settings

INFRA Settings

FEATURE_FLAGS Settings

Enter the policy before switching GRAPH_AUTHORIZATION_MODE to enforce. A label with no baseline row is treated as private, so on a deployment where the policy has not been entered yet, enforce makes the knowledge graph invisible to everyone. Use shadow first: it works out and records the same decision while still answering from the unfiltered query, so you can see what would change before anything does.
GRAPH_AUTHZ_SUPERUSER_BYPASS is one switch for all superusers, not a per-account setting. Turning it on means every superuser reads the graph unfiltered, immediately, with no further step. It exists so a tester or the customer’s own IT owner can check the whole graph; it is not a way to give one person more access.It has no effect unless the mode is enforce, and a bypassed read still works out the decision it is ignoring and records it, so the audit trail survives. Anyone whose session is bypassing sees a banner saying so — see What the AI can see.