TVTenvyrDocs
Administration

Tenant settings and enforced defaults

Read the tenant security boundaries enforced by the control plane.

The Settings view is intentionally read-only. It reports control-plane security boundaries rather than browser preferences.

Tenant metadata

Confirm:

  • tenant name and UUID;
  • assigned region; and
  • creation timestamp.

Use the UUID—not the display name—when a CLI or integration requires an exact tenant identifier.

Security defaults

The view reports:

SettingEffect
Default offline modeInitial behavior for new host groups
Certificate maximumMaximum default SSH certificate lifetime
Grant maximumLongest permitted approved access window
Recent MFA windowFreshness required for sensitive changes
Static-key leaseMaximum human compatibility-key lease
Self approvalWhether a requester can approve their own access
Browser bearer tokensWhether bearer credentials are accepted in browser flows

The browser does not offer a weaker override. If a value is unexpected, stop the rollout and have a platform owner review the deployed control-plane configuration.

Trust rotation

Owners, administrators, and auditors can inspect trust-rotation evidence from Settings. Owners and administrators perform prepare, promote, and retire transitions with recent MFA. See Rotate SSH trust.

On this page