Administration
Tenant settings and enforced defaults
Read the tenant security boundaries enforced by the control plane.
The Settings view is intentionally read-only. It reports control-plane security boundaries rather than browser preferences.
Tenant metadata
Confirm:
- tenant name and UUID;
- assigned region; and
- creation timestamp.
Use the UUID—not the display name—when a CLI or integration requires an exact tenant identifier.
Security defaults
The view reports:
| Setting | Effect |
|---|---|
| Default offline mode | Initial behavior for new host groups |
| Certificate maximum | Maximum default SSH certificate lifetime |
| Grant maximum | Longest permitted approved access window |
| Recent MFA window | Freshness required for sensitive changes |
| Static-key lease | Maximum human compatibility-key lease |
| Self approval | Whether a requester can approve their own access |
| Browser bearer tokens | Whether bearer credentials are accepted in browser flows |
The browser does not offer a weaker override. If a value is unexpected, stop the rollout and have a platform owner review the deployed control-plane configuration.
Trust rotation
Owners, administrators, and auditors can inspect trust-rotation evidence from Settings. Owners and administrators perform prepare, promote, and retire transitions with recent MFA. See Rotate SSH trust.