Tenant settings
Configure a tenant in the web app, from time zone, package feeds and Robot behaviour to Robot updates, retention, alerts, calendars, external applications, security and subscription.
Tenant settings live under Tenant ▸ Settings, in tabs. You need settings.view to see them and settings.edit to change them (the Administrator role has both). Many fields show an Inherited badge: the tenant has no value of its own and uses the platform value. Enter a value to override it for this tenant; clear it to inherit again. How platform and tenant values combine is explained in Settings. General# Go to Tenant ▸ Settings ▸ General. Set the Default time zone used for dates and schedules. Under Alerts, tick Send alert emails to opted-in members, and check the Web application URL used in links in those emails. Under Workspaces, optionally choose a Default workspace for new members. Select Save changes. Package feeds# Robots restore the packages a job needs from feeds. A Robot always tries its own installed feed first, then the tenant's feeds in the order listed. The built-in orchestrator feed is the tenant's own package feed. Go to Tenant ▸ Settings ▸ Package feeds. Select Add feed. Enter a Name, choose the Kind (Remote feed (NuGet v3), Local folder or Python package index) and the Location. Optionally limit it to Package patterns, and choose Authentication: None, or Username and password (with Password or API key). Select Add feed, then use the arrows in the Order column to place it. Require signed packages makes the tenant refuse unsigned or untrusted publishes. It is off by default, so unsigned packages are accepted, and it can only tighten what the deployment allows. See Package signing and supply chain. Robots# Go to Tenant ▸ Settings ▸ Robots. Each card has its own save button. Card What it sets Command channel How robots receive commands: HTTPS polling (the default) or WebSocket gateway (faster, but your front door must pass WebSocket connections). See Move a tenant to the WebSocket command channel. Attended sign-in Attended authentication: Machine only, Machine or signed-in (default) or Signed-in only, which decides how Assistant starts are authenticated and whether personal connections are allowed. Machine authentication Token endpoint authentication: Machine key or Mutual TLS. Robot defaults Defaults for every machine: log level, RDP sessions, screen resolution, colour depth. A machine can override them. Offline alert Threshold (minutes) after which an offline robot raises an alert. UI automation policy Whether robots may take failure screenshots, execute JavaScript, use hardware input and image targets for high-risk actions, and the Fuzzy match floor. Robot updates# Roll out new Robot versions to your machines from the Orchestrator. A platform administrator first uploads signed Robot installers (see Platform administration). Go to Tenant ▸ Settings ▸ Robot updates. Under Policy, choose Updates: Off: robots are told nothing, Notify: robots report the update, install nothing, or Automatic: install when idle, inside the window. For automatic updates, set the Maintenance window start (UTC) and end (UTC), the Drain timeout (minutes), the Install timeout (minutes) and Pause after failures. Select Save policy. To start a rollout, use Roll out a Robot release: pick the Release, a Percentage of machines and optional Pilot machines. Rollback is the only way to move robots to a lower version. Current rollout shows each machine's progress, and History lists past rollouts. Each Robot checks the installer's signature before it runs it, waits for its running job to finish, and keeps the previous version if the install fails. See Updating the Robot. Retention# Go to Tenant ▸ Settings ▸ Retention. Keep Delete data past its retention window ticked to let the retention sweep remove data older than its window. Under Windows, set the number of days to keep Queue items, Jobs, Job logs, Audit events and Notifications. Select Save changes. Allowed ranges and how the sweep works: Retention. Expressions# Studio workflows contain expressions. The expression policy decides which ones packages may use. Go to Tenant ▸ Settings ▸ Expressions. Choose the Policy: Strict, Default, or Default plus named types (then list the Extra types). Optionally turn on Refuse code execution in unattended jobs: unattended jobs that run Invoke Code or Invoke PowerShell are refused. Select Save changes. Alerts# Alert rules notify people when something needs attention. Go to Tenant ▸ Settings ▸ Alerts and select Add rule. Enter a Name, and choose When: Job failed, Job ran too long, Queue SLA at risk, Queue SLA breached, Robot offline or Trigger failed. Choose the Severity (Error, Warning, Info) and, optionally, limit it to one Workspace. For job failures you can narrow it by Fault kind and Fault code; for long jobs, set Minutes running. Tick the Channels: In-app, Email and Webhook. Optionally pick the Roles, Groups or Users who receive it. With no one picked, everyone who can see the alert gets it. Set a Cooldown (minutes) and select Add rule. Emails go only to people who opted in under My account ▸ Notifications, and only when Send alert emails to opted-in members is on (General). The Webhook channel sends com.velophex.alert.raised (and com.velophex.alert.resolved) to webhooks subscribed to them. ⋮ ▸ Send test alert checks a rule; Open now lists alerts that are still open. Calendars# A calendar lists non-working days. Time triggers can skip them (Non-working days on the trigger). Go to Tenant ▸ Settings ▸ Calendars and select Add calendar. Enter a Name and choose the Time zone. Under Non-working days, enter one date per line as YYYY-MM-DD. Select Add calendar. External applications# An external application (a reporting tool, an integration) gets its own client ID and secret instead of a person's token. It requests a one-hour access token from /api/v1/oauth/token with grant_type=client_credentials and acts in this tenant with its scopes only. It cannot sign in to the web app or reach the Robot API. Go to Tenant ▸ Settings ▸ External applications and select Add application. Enter a Name and tick its Scopes. You can only grant permissions you hold. Select Add application, then copy the Client ID and Client secret. The secret is shown only once. ⋮ ▸ Rotate secret issues a new secret, and Revoke disables the application. If an application's creator left, select Reassign to me. See Authentication. Security# Go to Tenant ▸ Settings ▸ Security. Turn on Require for every local account in this tenant to make two-step sign-in mandatory. Members without it set it up at their next sign-in. To provision users and groups from your identity provider, copy the Tenant URL under SCIM provisioning, select New token, name it and copy the token (shown once). Give both to your identity provider. Password rules, lockout and session length are set by a platform administrator under Platform administration ▸ Security (a tenant can override them through the API). See Users and roles. Subscription# Tenant ▸ Settings ▸ Subscription shows the tenant's subscription: Status, Plan, Covered by, Term, Grace period, Days left and Features. It is read-only; a platform administrator assigns and renews plans. See Licensing. Next steps# Settings reference Retention Platform administration
General
Package feeds
Robots
Robot updates
Retention
Expressions
Alerts
Calendars
External applications
Security
Subscription
Next steps