Tenant settings

Configure AI behavior, access, integrations, branding, and model resources for one tenant.

Agentic Friendly

The Administration workspace groups tenant-wide controls under the selected Keycloak Organization. These settings affect users and workloads in that tenant rather than the signed-in administrator alone.

Select a tenant

  1. Switch from Chat & Work to Administration.
  2. Use Tenant to manage in the Tenant section of the sidebar.
  3. Select the organization whose configuration you want to inspect or change.

Tenant pages remain disabled until a tenant is selected. The page header identifies the tenant currently being managed. Changing the selection reloads the current administration area with the new tenant context.

Available settings

AreaPurposeRequired permission
Generalconfigure embedding, reranking, retrieval, web search, and upload limitscan_edit_config
Access Controlinspect users and groups and manage tenant rolescan_manage_roles for role changes
Vector Storeinspect the tenant's platform-managed collectionsplatform admin role
Themeconfigure the tenant's portal theme and logocan_edit_config
Service Deskconfigure the tenant's support-oriented Agent experiencecan_edit_config
Integrationsmanage outbound web-search providers and credentialscan_edit_config
Allowed Resource Profileschoose the runtime profiles available for model deploymentcan_manage_models

General

Open Administration → Tenant → General to manage retrieval and document-processing behavior for the selected tenant.

Reranker

The reranker is an optional retrieval step that reorders search results before they are passed to the model. Administrators can enable or disable it, select the reranker model, and set Reranker Top N from 1 to 50.

A model and Top N value must be configured before the reranker can be enabled.

Embedding and reindexing

Administrators select the active embedding model and its output dimension. The backend derives the collection name from the tenant, model, and dimension; administrators do not enter a collection name.

Changing the embedding model or dimension starts a reindex operation into a new tenant-scoped target collection. The page reports:

  • active and target collections
  • completed, failed, skipped, and total files
  • current progress and errors

Search continues to use the active collection until reindexing succeeds. New uploads are routed to the target collection while reindexing is active. Administrators can cancel the operation without changing the active collection.

Retrieval

Retrieval K controls how many document chunks similarity search returns as RAG context. The accepted range is 1 to 50, with a default of 3.

The active provider determines which configured integration powers the Chat Search control and the web_search tool used by supported Agents. Provider credentials and connection settings are managed under Integrations.

File size

The maximum file size setting controls the upload limit applied by the Files pipeline. The value is configured in megabytes.

Reset configuration

Reset to default restores the selected tenant's system configuration to backend defaults. The portal requires confirmation before applying the reset.

Access Control

Open Administration → Tenant → Access Control to inspect Keycloak-backed identities together with their effective OpenFGA roles.

The Users view supports search and shows identity information, group memberships, directly assigned roles, and computed roles. The Groups view presents the nested group tree and the roles assigned to or inherited by each group.

Direct assignments can be changed by an administrator with can_manage_roles. Computed roles are read-only because they result from group membership and the authorization hierarchy.

The authorization model derives capabilities such as:

  • can_access_api for Chat, Files, Agents, MCP Servers, and personal settings
  • can_manage_models for model lifecycle actions, Model Presets, and Allowed Resource Profiles
  • can_edit_config for tenant configuration, Theme, Service Desk, and Integrations
  • can_manage_roles for role assignment and revocation

The BSQAI API enforces these permissions in addition to the portal's UI gates.

Vector Store

Open Administration → Tenant → Vector Store to inspect the collections created for the selected tenant's embedding and reindex cycles.

The page displays each collection's generated name and vector dimension. Selecting a row opens the dimension detail. Collection lifecycle is managed automatically; the portal does not expose manual collection creation, document inspection, similarity search, or deletion controls on this page.

The backend derives collection identity from the canonical tenant identifier, embedding model, and embedding dimension. Search and Responses API file_search use only the tenant's active collection. Foreign or inactive collection identifiers are returned as not found.

The end-to-end retrieval flow is:

  1. General defines the embedding model and dimension.
  2. Files ingestion writes document chunks to the managed collection.
  3. Vector Store exposes the resulting collection identity and dimension.
  4. Chat and Service Desk retrieve context from the active collection.

See Files & RAG for the platform-level retrieval pipeline.

Theme

Open Administration → Tenant → Theme to customize the selected tenant's portal appearance.

Administrators can:

  • edit independent light and dark color palettes
  • review WCAG contrast warnings before applying a theme
  • adjust the global border radius
  • upload an SVG, PNG, or WebP logo up to 512 KB
  • import CSS variables or a tweakcn registry JSON theme
  • preview Theme, Chat, Files, and Agents surfaces
  • reset the tenant to the default theme

Theme changes are applied to open portal tabs after they are saved. Font customization is not available because the portal uses bundled fonts for air-gap compatibility.

Service Desk

Open Administration → Tenant → Service Desk to configure the tenant's support-oriented chat entry point.

Administrators select:

  • an Agent that supplies the model and system prompt
  • one optional Files folder used for retrieval grounding
  • whether Service Desk is enabled

An Agent must be selected before Service Desk can be enabled. The retrieval folder is optional.

The page also manages a custom icon and localized text for English, French, German, and Swedish. Each locale can define the display title, welcome message, and input placeholder. Uploading an icon opens a cropper; removing it restores the default.

At runtime, Service Desk fixes the Agent and retrieval scope chosen by the administrator. End users receive a message input without model, file-upload, RAG, or web-search controls.

Integrations

Open Administration → Tenant → Integrations to manage outbound web-search providers for the selected tenant.

The portal supports:

  • Tavily
  • Brave
  • Exa
  • DuckDuckGo
  • custom HTTPS providers

The table shows the provider name, type, masked credential, and creation date. Administrators can add, edit, or delete entries. Existing secrets remain masked; entering a new value replaces the stored credential.

A custom HTTPS provider can define its endpoint, HTTP method, query parameter, authentication header, and response-field mappings. After creating a provider, return to General to select it as the tenant's active web-search provider.

Allowed Resource Profiles

Open Administration → Tenant → Allowed Resource Profiles to select which platform-defined KServe runtime profiles are available to the tenant.

The table supports search and shows each profile's CPU, memory, and active status. Enabling or disabling a profile changes the choices available in model deployment and Model Presets. The profiles themselves are defined by the platform operator and reflect the compute capacity supported by the deployment.

On this page