Settings
Workspace Settings guide
Navigate the centralized Workspace Settings shell and configure general, billing, finance, communications, integrations, devices, security, and AI domains.
Workspace Settings controls shared policy and configuration. It is separate from Account Settings, which controls the signed in user's profile, preferences, personal security, personal integrations, and AI usage.
Open Settings as a Super Admin or Manager. Access can also be delegated narrowly for supported Access Rights administration.
Search and navigation
The centralized shell contains these domains:
| Domain | Typical contents |
|---|---|
| General | Company identity, branding, document layout, localization |
| Plan and Billing | Current plan, payment method, installed modules, subscription |
| Finance | Tax, fiscal settings, lists, customer payment provider |
| Communications | Inbound email, digests, templates, authentication emails, delivery diagnostics |
| Integrations | Gmail, Outlook, Google Calendar, address autocomplete, geolocation |
| Devices | Barcode software and hardware, readers, rules, printers |
| Security and Access | Security policy, roles, Access Rights, settings audit, privacy |
| Developer and AI | Workspace model, team budgets, API and MCP keys |
Use Search workspace settings to find a setting by label or description. Search results respect your role, modules, and platform scope, so unavailable settings are not advertised.
Use arrow keys to move through domain tabs. Home selects the first visible tab and End selects the last.
General
Company controls the core workspace name used on supported documents and reports.
Branding controls application identity, logos, colors, and supported email presentation. Agency client branding can override an agency default.
Document Layout controls the supported invoice and quote presentation, typography, colors, logo, and footer.
Localization controls enabled languages and fiscal country configuration. Finance localization can install country specific chart, tax, and statutory configuration where supported.
Plan and Billing
Review plan name, status, period, payment method, and installed modules. The detailed Subscription page is Super Admin controlled and opens hosted provider checkout or billing portal actions.
Add ons are managed through Subscription. The Apps catalog remains the operational catalog for module requests and installed capability.
Finance
The Finance domain includes:
- Workspace tax defaults and jurisdiction rates
- Expense, income, and payment method lists
- Fiscal year
- Fiscal localization
- Cash rounding
- Exchange rates
- Invoice and vendor bill sequences
- Payment terms
- Invoice terms
- Invoicing options
- Discount accounts
- ZATCA configuration for eligible KSA use
Availability depends on installed modules and role. Configure numbering before production documents are issued. Changing a sequence does not rewrite existing document numbers.
The customer payment provider under Settings → Payments is restricted to Super Admin and belongs to tenant customer payments, not the agaro platform subscription.
Communications
Inbound Email shows the workspace BCC dropbox and unmatched queue.
Digest Emails manages supported scheduled workspace KPI digests.
Email Templates manages reusable workspace content when Marketing is available.
Authentication Emails controls safe invitation, activation, reset, verification, and login alert content.
Delivery Diagnostics shows bounce, retry, and delivery health evidence. Use it before resending a business communication manually.
Integrations
Workspace integrations store shared organization credentials and provider application configuration. Personal Gmail and Google Calendar connections belong under Account Settings.
See Workspace and personal integrations.
Devices
Barcode settings include software activation, nomenclature, readers, rules, hardware, and troubleshooting when Inventory is available. Printers can be registered and assigned for supported reporting paths.
Device configuration does not replace network security. Use trusted device addresses and restrict administrative access.
Security and Access
Review workspace two factor policy, Roles, Access Rights, settings activity, and privacy requests. Only a Super Admin can change the workspace two factor policy, although a Manager can review it.
Access Rights can control groups, apps, data model actions, record scope, rules, fields, and menus. Test a new group with a nonadministrator account before broad assignment.
Developer and AI
Workspace selects the default assistant model from the platform funded catalog.
Team AI Budgets shows usage and supported member limits.
API and MCP Keys is Super Admin only and requires an eligible seated actor.
Platform AI configuration is visible only in the canonical platform owner workspace.
Save and audit behavior
Settings forms use explicit Save actions and display validation or read only errors. Successful supported settings changes are recorded in the Settings Audit or broader activity system.
Do not change several unrelated settings at once during an incident. Make one bounded change, verify the result, and preserve the audit trail.
Troubleshooting
A settings domain is missing
Visibility depends on role, installed modules, access rights, and platform owner scope. Search does not show settings you cannot open.
Save returns read only
Restore the workspace subscription under Subscription. Personal profile reads can remain available while workspace mutations are blocked.
A setting moved
Use centralized search. Older routes redirect to the current workspace domain or operational module where possible.
A Manager can view but cannot change a setting
Some sensitive controls, including platform billing, Stripe customer payments, API keys, and two factor policy changes, require Super Admin.