Skip to content

Config (admin only)

Not a tab in the left navigation: open it from the account menu — your name at the bottom-left of the sidebar — under Administration, or type "Config" into the ⌘K search. Admins only; members do not see the entry.

Deployment-wide settings — everything in config.yaml with a form for each block: team accounts, member bot creation (whether non-admins may create their own bots, how many each may own, and which templates they may pick from), cognition defaults, heartbeat, disk monitoring, MCP connection health, context window (what a compaction keeps and the MCP result cap), revisions, issues, speech, media, web search, rate limits, catalog sync, and the ports.

The Cloud catalogs card shows each synced catalog (model pricing, the MCP directory, credit rates, agent archetypes, official connector clients) with its revision and where it is being served from, and a Sync now button that re-fetches everything immediately instead of waiting for the hourly background check — useful right after a new official connector is enabled for your deployment, so its one-click Connect button appears without the wait.

The Disk encryption card appears only on a managed instance whose data lives on an encrypted volume (see Privacy and security); a self-hosted install never shows it. It reads the state of that volume (the custody mode, the volume's identifier, whether a header backup exists and which generation is current, whether the instance's encryption service is answering) and holds the one action the volume asks of you: Create recovery key. The key is generated on the instance, shown to you once, and confirmed by typing it back, so a copy you never checked cannot be the one you rely on. A key that was shown and not confirmed stays pending for fifteen minutes (Confirm the shown key or Cancel pending key on the card), and Replace recovery key makes a new one that takes over only once it is confirmed. The Encryption service row names the version of the service on the instance that answers these actions; when it reads Unavailable, that service is not answering: your data stays encrypted and the instance keeps working, only the recovery-key actions pause (Refresh re-reads the state; if it stays unavailable after a restart of the instance from the cloud console, contact support). Every row's hint explains what the value means and what the buttons do.

Some fields (ports, team accounts) only take effect after a runtime restart; the form says so.

Saving. The page is long, so Save changes and Discard live in the bar at the top, which stays put while you scroll — you never have to scroll back up to save. While anything on the page differs from what is saved, an Unsaved changes badge sits beside the buttons. Three things then guard the edits: clicking anywhere that would leave the page (a sidebar entry, the ⌘K search, a link inside the page) asks Save and leave / Leave without saving / Stay on this page — Save and leave is greyed out while a field is invalid, and the dialog says which case you are in; closing or reloading the tab gets the browser's own "leave site?" prompt; and if the edits sit untouched for about a minute, one reminder toast says so. The browser's Back button is the one exit that is not intercepted, so use the sidebar or the dialog to leave. The Usage budgets card has its own Save button beside its fields and is not part of this — save it where you edit it.