Tenant settings
Configure AI behavior, access, integrations, branding, and model resources for one tenant.
The Administration workspace groups tenant-wide controls under the selected Keycloak Organization. These settings affect users and workloads in that tenant rather than the signed-in administrator alone.
Select a tenant
- Switch from Chat & Work to Administration.
- Use Tenant to manage in the Tenant section of the sidebar.
- Select the organization whose configuration you want to inspect or change.
Tenant pages remain disabled until a tenant is selected. The page header identifies the tenant currently being managed. Changing the selection reloads the current administration area with the new tenant context.
Available settings
| Area | Purpose | Required permission |
|---|---|---|
| General | configure embedding, reranking, retrieval, web search, and upload limits | can_edit_config |
| Access Control | inspect users and groups and manage tenant roles | can_manage_roles for role changes |
| Vector Store | inspect the tenant's platform-managed collections | platform admin role |
| Theme | configure the tenant's portal theme and logo | can_edit_config |
| Service Desk | configure the tenant's support-oriented Agent experience | can_edit_config |
| Integrations | manage outbound web-search providers and credentials | can_edit_config |
| Allowed Resource Profiles | choose the runtime profiles available for model deployment | can_manage_models |
General
Open Administration → Tenant → General to manage retrieval and document-processing behavior for the selected tenant.
Reranker
The reranker is an optional retrieval step that reorders search results before they are passed to the model. Administrators can enable or disable it, select the reranker model, and set Reranker Top N from 1 to 50.
A model and Top N value must be configured before the reranker can be enabled.
Embedding and reindexing
Administrators select the active embedding model and its output dimension. The backend derives the collection name from the tenant, model, and dimension; administrators do not enter a collection name.
Changing the embedding model or dimension starts a reindex operation into a new tenant-scoped target collection. The page reports:
- active and target collections
- completed, failed, skipped, and total files
- current progress and errors
Search continues to use the active collection until reindexing succeeds. New uploads are routed to the target collection while reindexing is active. Administrators can cancel the operation without changing the active collection.
Retrieval
Retrieval K controls how many document chunks similarity search returns as RAG context. The accepted range is 1 to 50, with a default of 3.
Web search
The active provider determines which configured integration powers the Chat Search control and the web_search tool used by supported Agents. Provider credentials and connection settings are managed under Integrations.
File size
The maximum file size setting controls the upload limit applied by the Files pipeline. The value is configured in megabytes.
Reset configuration
Reset to default restores the selected tenant's system configuration to backend defaults. The portal requires confirmation before applying the reset.
Access Control
Open Administration → Tenant → Access Control to inspect Keycloak-backed identities together with their effective OpenFGA roles.
The Users view supports search and shows identity information, group memberships, directly assigned roles, and computed roles. The Groups view presents the nested group tree and the roles assigned to or inherited by each group.
Direct assignments can be changed by an administrator with can_manage_roles. Computed roles are read-only because they result from group membership and the authorization hierarchy.
The authorization model derives capabilities such as:
can_access_apifor Chat, Files, Agents, MCP Servers, and personal settingscan_manage_modelsfor model lifecycle actions, Model Presets, and Allowed Resource Profilescan_edit_configfor tenant configuration, Theme, Service Desk, and Integrationscan_manage_rolesfor role assignment and revocation
The BSQAI API enforces these permissions in addition to the portal's UI gates.
Vector Store
Open Administration → Tenant → Vector Store to inspect the collections created for the selected tenant's embedding and reindex cycles.
The page displays each collection's generated name and vector dimension. Selecting a row opens the dimension detail. Collection lifecycle is managed automatically; the portal does not expose manual collection creation, document inspection, similarity search, or deletion controls on this page.
The backend derives collection identity from the canonical tenant identifier, embedding model, and embedding dimension. Search and Responses API file_search use only the tenant's active collection. Foreign or inactive collection identifiers are returned as not found.
The end-to-end retrieval flow is:
- General defines the embedding model and dimension.
- Files ingestion writes document chunks to the managed collection.
- Vector Store exposes the resulting collection identity and dimension.
- Chat and Service Desk retrieve context from the active collection.
See Files & RAG for the platform-level retrieval pipeline.
Theme
Open Administration → Tenant → Theme to customize the selected tenant's portal appearance.
Administrators can:
- edit independent light and dark color palettes
- review WCAG contrast warnings before applying a theme
- adjust the global border radius
- upload an SVG, PNG, or WebP logo up to 512 KB
- import CSS variables or a tweakcn registry JSON theme
- preview Theme, Chat, Files, and Agents surfaces
- reset the tenant to the default theme
Theme changes are applied to open portal tabs after they are saved. Font customization is not available because the portal uses bundled fonts for air-gap compatibility.
Service Desk
Open Administration → Tenant → Service Desk to configure the tenant's support-oriented chat entry point.
Administrators select:
- an Agent that supplies the model and system prompt
- one optional Files folder used for retrieval grounding
- whether Service Desk is enabled
An Agent must be selected before Service Desk can be enabled. The retrieval folder is optional.
The page also manages a custom icon and localized text for English, French, German, and Swedish. Each locale can define the display title, welcome message, and input placeholder. Uploading an icon opens a cropper; removing it restores the default.
At runtime, Service Desk fixes the Agent and retrieval scope chosen by the administrator. End users receive a message input without model, file-upload, RAG, or web-search controls.
Integrations
Open Administration → Tenant → Integrations to manage outbound web-search providers for the selected tenant.
The portal supports:
- Tavily
- Brave
- Exa
- DuckDuckGo
- custom HTTPS providers
The table shows the provider name, type, masked credential, and creation date. Administrators can add, edit, or delete entries. Existing secrets remain masked; entering a new value replaces the stored credential.
A custom HTTPS provider can define its endpoint, HTTP method, query parameter, authentication header, and response-field mappings. After creating a provider, return to General to select it as the tenant's active web-search provider.
Allowed Resource Profiles
Open Administration → Tenant → Allowed Resource Profiles to select which platform-defined KServe runtime profiles are available to the tenant.
The table supports search and shows each profile's CPU, memory, and active status. Enabling or disabling a profile changes the choices available in model deployment and Model Presets. The profiles themselves are defined by the platform operator and reflect the compute capacity supported by the deployment.