| Tab | What it controls | Who |
|---|---|---|
| Profile | Your name, avatar, password if not using single sign-on. | Everyone |
| Notifications | Which notification kinds reach you and how; quiet hours. | Everyone |
| Personalization | Density, default time range, auto-refresh, default organization. | Everyone |
| Team & roles | Accounts, roles, organization grants. | Admin |
| Organizations | Tenants and their per-organization settings. | Admin |
| Agents | Installer bundles and enrolment tokens per organization. | Admin |
| Fleet | Fleet groups and policy: telemetry collection, required tools, uninstall token, update channel. | Admin |
| AI | Model endpoints, investigation budget, minimum evidence grade for automation, staged action expiry. | Admin |
| Suppressions | Suppressions across rules, with reasons, counters and expiry. | Lead, Admin |
| Tags | The tag vocabulary for alerts and cases. | Lead, Admin |
| Case categories | Categories with write-up structure and task templates. | Lead, Admin |
| Report templates | Report structures, branding, signing team name. | Lead, Admin |
| Integrations | Pull connectors, enrichment services, egress channels, ingest keys, syslog source mapping. | Admin |
| Audit log | The audit trail with filters and export. | Admin |
| System | Database health and size, version, session limits, licence. | Admin |
Settings reference
Every tab under Settings and what it controls.