Configure Your Tenant Settings
Phase 1 — Account & Workspace Setup · OpenFrame Onboarding
Guide maintenance · Owner: Conrad Lunderstedt · Last full review: 22 Sep 2026
Each section below carries its own Last verified date. When a feature changes, update that section and its date only.
You've just signed up. Before you push the agent to a single device, spend ten minutes setting up the workspace the way you actually run your shop. Almost everything here is one-time configuration, and getting it right now means you won't be redoing it with a few hundred endpoints in play.
Everything in this guide lives in one place: Settings.
Where your settings live
Last verified: 22 Sep 2026
Open the left navigation and click Settings (the gear icon near the bottom). Your profile sits at the top of the page, and below it you'll find a card for each area covered in this guide:
| Card | What it's for | Do it now? |
|---|---|---|
| Edit Organization | Your company's name, logo and website | Yes |
| Edit User | Your own profile and notifications | Yes |
| Billing and Usage | Plan, devices, token usage, billing date | Skim |
| Employees | Invite and manage your team | Yes, if you're not solo |
| Guardrails & AI Settings | How Mingo and Fae behave, and what they're allowed to do | Yes |
| SSO Configurations | How people sign in | Recommended |
| API Keys Management | Keys for external integrations | Later |
| Get OpenFrame Apps | Desktop apps for Windows and macOS | Optional |
Work through them in this order. The first two take a minute; Guardrails deserves the most attention.
Edit Organization
Last verified: 22 Sep 2026
This is how your tenant presents itself, including in the branded end-user app your clients will see.
- Click Edit Organization.
- Set your organization name. This appears in the app header and in emails OpenFrame sends on your behalf.
- Upload a logo. Square or near-square PNG works best; it's shown small, so avoid detailed artwork.
- Add your website.
- Save.
Tip: Use the trading name your clients recognise, not the legal entity. This is what shows up when Fae introduces itself on an end user's machine.
Edit User
Last verified: 22 Sep 2026
Your personal profile. Every technician you invite gets their own copy of this.
- Click Edit User (/settings).
- Set your name and avatar. Your name is what appears in ticket history and approval logs, so use the one your team knows you by.
- Open Notification Settings:
- Turn notifications on or off for your account.
- Choose which events notify you. Start with device offline, approval requests from Mingo, and new tickets; add more once you know what noise you can live with.
- Save.
Tip: Notifications are per user, not per tenant. If you want an on-call tech to get device alerts and nobody else, set it on their profile, not yours.
Billing and Usage
Last verified: 22 Sep 2026
Nothing to configure here on day one, but know where it is. This card shows:
- Your current plan and next billing date
- Devices enrolled against your tenant
- Token usage: how much AI work Mingo and Fae have done this cycle
Mingo and Fae consume tokens from a shared balance for the tenant, so come back here in your first week to see what a normal day looks like for your team. Set a reminder if you don't want to be surprised.
Employees
Last verified: 22 Sep 2026
The first person to sign up is always the Owner. Everyone else comes in through this card.
- Click Employees.
- Click Add user and enter their work email.
- They receive an invite. Until they accept, their status shows as pending; use Resend invitation if it gets lost.
- Once accepted, they appear with their current status alongside the rest of the team.
Tip: Invite people with the email they'll use for SSO (see below). Mismatched addresses are the most common reason an invite "doesn't work".
Guardrails & AI Settings
Last verified: 22 Sep 2026
This is the card that decides what the AI can do on its own. It has three parts: settings for Mingo (your technicians' AI), settings for Fae (your clients' AI), and the guardrails that apply to both.
Mingo AI Chat
Mingo is the AI technician your team works with in the dashboard.
- Provider / Model: which LLM Mingo uses. The default is fine to start; change it later if you have a preference or a cost reason.
- Answer Style: how verbose Mingo is. Concise suits experienced techs; detailed suits a team that's still learning the platform.
- Mingo Quick Actions: a set of pre-built tasks (for example, "check disk space across a customer") that appear as one-click prompts. They're a good way to show new techs what Mingo can do. Edit or add your own once you have recurring jobs.
Default Customer AI Configuration (Fae)
Fae is the end-user-facing assistant your clients interact with. These are the defaults every new customer inherits; you can override them per customer later.
- Assistant Name: brand it. "Ask Contoso" lands better with end users than "Fae".
- LLM Provider / Model
- Application Theme: Dark, Light or System.
- Accent Colour: match your brand.
- Answer Style: end users generally want short, plain-language answers.
- Assistant Quick Actions: pre-built prompts end users see when they open Fae ("my Wi-Fi is slow", "I need software installed"). Tailor these to the requests your helpdesk actually gets.
Default Customer AI Guardrails
Guardrails set how much the AI can do without a human in the loop. The default you pick here applies to every new customer; existing customers keep whatever they were assigned.
Every action the AI can take is classed at one of three levels:
| Level | What happens |
|---|---|
| Ask User | The agent pauses and asks the person it's helping before running. Your safety net for anything that changes state: deleting files, restarting a machine, installing software. |
| Ask Technician | Escalates to one of your techs for approval. Used for the heaviest actions, such as deleting user accounts. |
| Restrict | Blocked outright. The agent cannot run it. |
A policy is a preset that assigns a level to every action. From most to least restrictive:
| Policy | Best for | In one line |
|---|---|---|
| Restrictive | Sensitive environments | Monitor only. All configuration changes are blocked. |
| Balanced (default) | Standard MSP operations | Routine reads and fixes run; state-changing actions ask first. |
| Permissive | Experienced teams | Most operations run freely; only destructive actions need human approval. |
| Autonomous | Trusted environments | Maximum autonomy; most operations, including many destructive ones, are auto-approved. |
| Custom | Anyone with specific needs | Start from a copy of any policy above and change individual actions. |
Recommendation for a new tenant: leave the default on Balanced, open it, and confirm every destructive action is at Ask User or Ask Technician. Loosen per customer once you trust the environment. It is much easier to grant autonomy later than to explain an unapproved change.
SSO Configurations
Last verified: 22 Sep 2026 — confirm field names against a live tenant before publishing
How your team (and, later, your clients) sign in. Three settings stack on top of each other.
Enable OpenFrame SSO
The built-in sign-in: generic Google, Microsoft and Apple buttons plus an OpenFrame email/password account. It's on by default. Leave it on until you have a custom provider configured and tested, otherwise you can lock yourself out.
Open access for your domains
A domain allow-list for self-registration. With yourmsp.com listed, anyone who signs in with a @yourmsp.com address gets an account in this tenant automatically, with no invite. Public mail domains like gmail.com can't be listed.
Read this before you use it: open access admits everyone who can authenticate on that domain, from the engineer to the receptionist. Use it for your own MSP domain only, and never for a client's. For clients, invite users explicitly or gate access in their identity provider (below).
Google SSO / Microsoft SSO (custom providers)
Your own OAuth app in your Google Workspace or Microsoft Entra tenant. Each shows as Inactive / Not configured until you add a client ID and secret and activate it. Once active, a user who enters their email on the login page is routed to this provider, which means your Entra or Workspace conditional-access rules and group assignments decide who gets in.
- Create an OAuth app in Google Cloud or Entra (app registration).
- Enter the client ID and secret here and set the redirect URL the screen gives you.
- Activate the provider.
- Test with a second browser before touching Enable OpenFrame SSO.
Note: SSO handles sign-in only. It does not enforce your identity provider's MFA inside OpenFrame today; native MFA and role-based access are on the roadmap. Restrict the OAuth app to an assigned group in your IdP if you need a hard gate now.
API Keys Management
Last verified: 22 Sep 2026
Generate keys here when you want another system (PSA, documentation tool, a script) to talk to OpenFrame. Nothing to do on day one. When you do create one: name it after the system that will use it, copy it immediately (it's shown once), and revoke it here if that system is retired.
Get OpenFrame Apps
Last verified: 22 Sep 2026
Optional desktop app for your technicians, available for Windows and macOS. Download from this card. This is the tech-side app, not the agent you deploy to client devices; that comes in Phase 2.
Quick checklist
Before you move on to deploying devices, confirm you've:
- Set your organization name and logo
- Set your own name, avatar and notification events
- Invited your team
- Reviewed Mingo's model and Answer Style
- Branded Fae with your company name
- Opened the default guardrail policy and confirmed destructive actions are Ask User / Ask Technician
- Decided on SSO: keep OpenFrame SSO on, and only allow-list your own domain
- Noted that API keys and desktop apps are here when you need them
What's next
Your workspace is configured. Next up is Phase 2 — Device Deployment: getting the OpenFrame agent onto your first macOS and Windows machines and confirming they show up in the dashboard.
