# Tenant settings (/docs/administration/tenant-settings)



The **Administration** workspace groups tenant-wide controls under the selected Keycloak Organization. These settings affect users and workloads in that tenant rather than the signed-in administrator alone.

## Select a tenant [#select-a-tenant]

1. Switch from **Chat & Work** to **Administration**.
2. Use **Tenant to manage** in the Tenant section of the sidebar.
3. Select the organization whose configuration you want to inspect or change.

Tenant pages remain disabled until a tenant is selected. The page header identifies the tenant currently being managed. Changing the selection reloads the current administration area with the new tenant context.

## Available settings [#available-settings]

| Area                      | Purpose                                                                  | Required permission                 |
| ------------------------- | ------------------------------------------------------------------------ | ----------------------------------- |
| General                   | configure embedding, reranking, retrieval, web search, and upload limits | `can_edit_config`                   |
| Access Control            | inspect users and groups and manage tenant roles                         | `can_manage_roles` for role changes |
| Vector Store              | inspect the tenant's platform-managed collections                        | platform `admin` role               |
| Theme                     | configure the tenant's portal theme and logo                             | `can_edit_config`                   |
| Service Desk              | configure the tenant's support-oriented Agent experience                 | `can_edit_config`                   |
| Integrations              | manage outbound web-search providers and credentials                     | `can_edit_config`                   |
| Allowed Resource Profiles | choose the runtime profiles available for model deployment               | `can_manage_models`                 |

## General [#general]

Open **Administration → Tenant → General** to manage retrieval and document-processing behavior for the selected tenant.

### Reranker [#reranker]

The reranker is an optional retrieval step that reorders search results before they are passed to the model. Administrators can enable or disable it, select the reranker model, and set **Reranker Top N** from 1 to 50.

A model and Top N value must be configured before the reranker can be enabled.

### Embedding and reindexing [#embedding-and-reindexing]

Administrators select the active embedding model and its output dimension. The backend derives the collection name from the tenant, model, and dimension; administrators do not enter a collection name.

Changing the embedding model or dimension starts a reindex operation into a new tenant-scoped target collection. The page reports:

* active and target collections
* completed, failed, skipped, and total files
* current progress and errors

Search continues to use the active collection until reindexing succeeds. New uploads are routed to the target collection while reindexing is active. Administrators can cancel the operation without changing the active collection.

### Retrieval [#retrieval]

**Retrieval K** controls how many document chunks similarity search returns as RAG context. The accepted range is 1 to 50, with a default of 3.

### Web search [#web-search]

The active provider determines which configured integration powers the Chat **Search** control and the `web_search` tool used by supported Agents. Provider credentials and connection settings are managed under **Integrations**.

### File size [#file-size]

The maximum file size setting controls the upload limit applied by the Files pipeline. The value is configured in megabytes.

### Reset configuration [#reset-configuration]

**Reset to default** restores the selected tenant's system configuration to backend defaults. The portal requires confirmation before applying the reset.

## Access Control [#access-control]

Open **Administration → Tenant → Access Control** to inspect Keycloak-backed identities together with their effective OpenFGA roles.

The **Users** view supports search and shows identity information, group memberships, directly assigned roles, and computed roles. The **Groups** view presents the nested group tree and the roles assigned to or inherited by each group.

Direct assignments can be changed by an administrator with `can_manage_roles`. Computed roles are read-only because they result from group membership and the authorization hierarchy.

The authorization model derives capabilities such as:

* `can_access_api` for Chat, Files, Agents, MCP Servers, and personal settings
* `can_manage_models` for model lifecycle actions, Model Presets, and Allowed Resource Profiles
* `can_edit_config` for tenant configuration, Theme, Service Desk, and Integrations
* `can_manage_roles` for role assignment and revocation

The BSQAI API enforces these permissions in addition to the portal's UI gates.

## Vector Store [#vector-store]

Open **Administration → Tenant → Vector Store** to inspect the collections created for the selected tenant's embedding and reindex cycles.

The page displays each collection's generated name and vector dimension. Selecting a row opens the dimension detail. Collection lifecycle is managed automatically; the portal does not expose manual collection creation, document inspection, similarity search, or deletion controls on this page.

The backend derives collection identity from the canonical tenant identifier, embedding model, and embedding dimension. Search and Responses API `file_search` use only the tenant's active collection. Foreign or inactive collection identifiers are returned as not found.

The end-to-end retrieval flow is:

1. General defines the embedding model and dimension.
2. Files ingestion writes document chunks to the managed collection.
3. Vector Store exposes the resulting collection identity and dimension.
4. Chat and Service Desk retrieve context from the active collection.

See [Files & RAG](/docs/ai/rag) for the platform-level retrieval pipeline.

## Theme [#theme]

Open **Administration → Tenant → Theme** to customize the selected tenant's portal appearance.

Administrators can:

* edit independent light and dark color palettes
* review WCAG contrast warnings before applying a theme
* adjust the global border radius
* upload an SVG, PNG, or WebP logo up to 512 KB
* import CSS variables or a tweakcn registry JSON theme
* preview Theme, Chat, Files, and Agents surfaces
* reset the tenant to the default theme

Theme changes are applied to open portal tabs after they are saved. Font customization is not available because the portal uses bundled fonts for air-gap compatibility.

## Service Desk [#service-desk]

Open **Administration → Tenant → Service Desk** to configure the tenant's support-oriented chat entry point.

Administrators select:

* an Agent that supplies the model and system prompt
* one optional Files folder used for retrieval grounding
* whether Service Desk is enabled

An Agent must be selected before Service Desk can be enabled. The retrieval folder is optional.

The page also manages a custom icon and localized text for English, French, German, and Swedish. Each locale can define the display title, welcome message, and input placeholder. Uploading an icon opens a cropper; removing it restores the default.

At runtime, Service Desk fixes the Agent and retrieval scope chosen by the administrator. End users receive a message input without model, file-upload, RAG, or web-search controls.

## Integrations [#integrations]

Open **Administration → Tenant → Integrations** to manage outbound web-search providers for the selected tenant.

The portal supports:

* Tavily
* Brave
* Exa
* DuckDuckGo
* custom HTTPS providers

The table shows the provider name, type, masked credential, and creation date. Administrators can add, edit, or delete entries. Existing secrets remain masked; entering a new value replaces the stored credential.

A custom HTTPS provider can define its endpoint, HTTP method, query parameter, authentication header, and response-field mappings. After creating a provider, return to **General** to select it as the tenant's active web-search provider.

## Allowed Resource Profiles [#allowed-resource-profiles]

Open **Administration → Tenant → Allowed Resource Profiles** to select which platform-defined KServe runtime profiles are available to the tenant.

The table supports search and shows each profile's CPU, memory, and active status. Enabling or disabling a profile changes the choices available in model deployment and Model Presets. The profiles themselves are defined by the platform operator and reflect the compute capacity supported by the deployment.

## Related pages [#related-pages]

* [Administration and operations](/docs/administration)
* [Portal Guide](/docs/use/portal)
* [Access and tenant context](/docs/use/access)
* [Models](/docs/ai/model-as-a-service)
* [Files & RAG](/docs/ai/rag)
* [Security and compliance](/docs/security)
