OpenFrame is on your phone now!

Configure Your Tenant Settings

AI INTEGRATIONBEST PRACTICESCONFIGURATIONDOCUMENTATIONGUIDEIMPLEMENTATIONOPENFRAME

Phase 1 — Account & Workspace Setup · Step 2

Section

October 2, 2026

Published

Vlad Rudnitskyi

Vlad Rudnitskyi

Video Editor | AI Generalist

Configure Your Tenant Settings

Phase 1 — Account & Workspace Setup · OpenFrame Onboarding

Guide maintenance · Owner: Conrad Lunderstedt · Last full review: 22 Sep 2026
Each section below carries its own Last verified date. When a feature changes, update that section and its date only.

You've just signed up. Before you push the agent to a single device, spend ten minutes setting up the workspace the way you actually run your shop. Almost everything here is one-time configuration, and getting it right now means you won't be redoing it with a few hundred endpoints in play.

Everything in this guide lives in one place: Settings.


Where your settings live

Last verified: 22 Sep 2026

Open the left navigation and click Settings (the gear icon near the bottom). Your profile sits at the top of the page, and below it you'll find a card for each area covered in this guide:

CardWhat it's forDo it now?
Edit OrganizationYour company's name, logo and websiteYes
Edit UserYour own profile and notificationsYes
Billing and UsagePlan, devices, token usage, billing dateSkim
EmployeesInvite and manage your teamYes, if you're not solo
Guardrails & AI SettingsHow Mingo and Fae behave, and what they're allowed to doYes
SSO ConfigurationsHow people sign inRecommended
API Keys ManagementKeys for external integrationsLater
Get OpenFrame AppsDesktop apps for Windows and macOSOptional

Work through them in this order. The first two take a minute; Guardrails deserves the most attention.


Edit Organization

Last verified: 22 Sep 2026

This is how your tenant presents itself, including in the branded end-user app your clients will see.

  1. Click Edit Organization.
  2. Set your organization name. This appears in the app header and in emails OpenFrame sends on your behalf.
  3. Upload a logo. Square or near-square PNG works best; it's shown small, so avoid detailed artwork.
  4. Add your website.
  5. Save.

Tip: Use the trading name your clients recognise, not the legal entity. This is what shows up when Fae introduces itself on an end user's machine.


Edit User

Last verified: 22 Sep 2026

Your personal profile. Every technician you invite gets their own copy of this.

  1. Click Edit User (/settings).
  2. Set your name and avatar. Your name is what appears in ticket history and approval logs, so use the one your team knows you by.
  3. Open Notification Settings:
    • Turn notifications on or off for your account.
    • Choose which events notify you. Start with device offline, approval requests from Mingo, and new tickets; add more once you know what noise you can live with.
  4. Save.

Tip: Notifications are per user, not per tenant. If you want an on-call tech to get device alerts and nobody else, set it on their profile, not yours.


Billing and Usage

Last verified: 22 Sep 2026

Nothing to configure here on day one, but know where it is. This card shows:

  • Your current plan and next billing date
  • Devices enrolled against your tenant
  • Token usage: how much AI work Mingo and Fae have done this cycle

Mingo and Fae consume tokens from a shared balance for the tenant, so come back here in your first week to see what a normal day looks like for your team. Set a reminder if you don't want to be surprised.


Employees

Last verified: 22 Sep 2026

The first person to sign up is always the Owner. Everyone else comes in through this card.

  1. Click Employees.
  2. Click Add user and enter their work email.
  3. They receive an invite. Until they accept, their status shows as pending; use Resend invitation if it gets lost.
  4. Once accepted, they appear with their current status alongside the rest of the team.

Tip: Invite people with the email they'll use for SSO (see below). Mismatched addresses are the most common reason an invite "doesn't work".


Guardrails & AI Settings

Last verified: 22 Sep 2026

This is the card that decides what the AI can do on its own. It has three parts: settings for Mingo (your technicians' AI), settings for Fae (your clients' AI), and the guardrails that apply to both.

Mingo AI Chat

Mingo is the AI technician your team works with in the dashboard.

  • Provider / Model: which LLM Mingo uses. The default is fine to start; change it later if you have a preference or a cost reason.
  • Answer Style: how verbose Mingo is. Concise suits experienced techs; detailed suits a team that's still learning the platform.
  • Mingo Quick Actions: a set of pre-built tasks (for example, "check disk space across a customer") that appear as one-click prompts. They're a good way to show new techs what Mingo can do. Edit or add your own once you have recurring jobs.

Default Customer AI Configuration (Fae)

Fae is the end-user-facing assistant your clients interact with. These are the defaults every new customer inherits; you can override them per customer later.

  • Assistant Name: brand it. "Ask Contoso" lands better with end users than "Fae".
  • LLM Provider / Model
  • Application Theme: Dark, Light or System.
  • Accent Colour: match your brand.
  • Answer Style: end users generally want short, plain-language answers.
  • Assistant Quick Actions: pre-built prompts end users see when they open Fae ("my Wi-Fi is slow", "I need software installed"). Tailor these to the requests your helpdesk actually gets.

Default Customer AI Guardrails

Guardrails set how much the AI can do without a human in the loop. The default you pick here applies to every new customer; existing customers keep whatever they were assigned.

Every action the AI can take is classed at one of three levels:

LevelWhat happens
Ask UserThe agent pauses and asks the person it's helping before running. Your safety net for anything that changes state: deleting files, restarting a machine, installing software.
Ask TechnicianEscalates to one of your techs for approval. Used for the heaviest actions, such as deleting user accounts.
RestrictBlocked outright. The agent cannot run it.

A policy is a preset that assigns a level to every action. From most to least restrictive:

PolicyBest forIn one line
RestrictiveSensitive environmentsMonitor only. All configuration changes are blocked.
Balanced (default)Standard MSP operationsRoutine reads and fixes run; state-changing actions ask first.
PermissiveExperienced teamsMost operations run freely; only destructive actions need human approval.
AutonomousTrusted environmentsMaximum autonomy; most operations, including many destructive ones, are auto-approved.
CustomAnyone with specific needsStart from a copy of any policy above and change individual actions.

Recommendation for a new tenant: leave the default on Balanced, open it, and confirm every destructive action is at Ask User or Ask Technician. Loosen per customer once you trust the environment. It is much easier to grant autonomy later than to explain an unapproved change.


SSO Configurations

Last verified: 22 Sep 2026 — confirm field names against a live tenant before publishing

How your team (and, later, your clients) sign in. Three settings stack on top of each other.

Enable OpenFrame SSO
The built-in sign-in: generic Google, Microsoft and Apple buttons plus an OpenFrame email/password account. It's on by default. Leave it on until you have a custom provider configured and tested, otherwise you can lock yourself out.

Open access for your domains
A domain allow-list for self-registration. With yourmsp.com listed, anyone who signs in with a @yourmsp.com address gets an account in this tenant automatically, with no invite. Public mail domains like gmail.com can't be listed.

Read this before you use it: open access admits everyone who can authenticate on that domain, from the engineer to the receptionist. Use it for your own MSP domain only, and never for a client's. For clients, invite users explicitly or gate access in their identity provider (below).

Google SSO / Microsoft SSO (custom providers)
Your own OAuth app in your Google Workspace or Microsoft Entra tenant. Each shows as Inactive / Not configured until you add a client ID and secret and activate it. Once active, a user who enters their email on the login page is routed to this provider, which means your Entra or Workspace conditional-access rules and group assignments decide who gets in.

  1. Create an OAuth app in Google Cloud or Entra (app registration).
  2. Enter the client ID and secret here and set the redirect URL the screen gives you.
  3. Activate the provider.
  4. Test with a second browser before touching Enable OpenFrame SSO.

Note: SSO handles sign-in only. It does not enforce your identity provider's MFA inside OpenFrame today; native MFA and role-based access are on the roadmap. Restrict the OAuth app to an assigned group in your IdP if you need a hard gate now.


API Keys Management

Last verified: 22 Sep 2026

Generate keys here when you want another system (PSA, documentation tool, a script) to talk to OpenFrame. Nothing to do on day one. When you do create one: name it after the system that will use it, copy it immediately (it's shown once), and revoke it here if that system is retired.


Get OpenFrame Apps

Last verified: 22 Sep 2026

Optional desktop app for your technicians, available for Windows and macOS. Download from this card. This is the tech-side app, not the agent you deploy to client devices; that comes in Phase 2.


Quick checklist

Before you move on to deploying devices, confirm you've:

  • Set your organization name and logo
  • Set your own name, avatar and notification events
  • Invited your team
  • Reviewed Mingo's model and Answer Style
  • Branded Fae with your company name
  • Opened the default guardrail policy and confirmed destructive actions are Ask User / Ask Technician
  • Decided on SSO: keep OpenFrame SSO on, and only allow-list your own domain
  • Noted that API keys and desktop apps are here when you need them

What's next

Your workspace is configured. Next up is Phase 2 — Device Deployment: getting the OpenFrame agent onto your first macOS and Windows machines and confirming they show up in the dashboard.

Vlad Rudnitskyi

Video Editor | AI Generalist

Hi! I'm Vlad, a Video Editor and AI Generalist. I run the full AI video pipeline: concept, script, prompting, generation, editing, sound design, final grade. Beyond video, I'm always happy to take on anything visual. I'm originally from Zhytomyr, Ukraine 🇺🇦, now based in Lviv.

Related Content

Product Releases

Webinars

Case Studies

Blog Posts

Frequently Asked Questions

MSP AI Agents

On a five-person desk, reported deployments show $78,000 to $130,000 in annual direct labor savings, roughly 30% fewer escalations, and 15% to 20% better SLA compliance. Broader MSP adoption data adds ticket handling time cut by 45% and five to 12 points of margin, all from reclaimed capacity rather than headcount cuts.
Yes. In production MSP shops today, 10% to 25% of tickets close before a human opens them. Thread alone has processed 173 million tickets across 750-plus MSP partners at 96% triage accuracy, handing back 490,000-plus technician hours. Agents own the low-risk, high-volume work (password resets, MFA enrollment, known installs, onboarding and offboarding) and flag anything that touches production data or needs judgment for a human to take.

AI MSP

Most MSPs start with AI features inside their existing PSA, RMM, and ticketing systems rather than standalone products. Common categories include AI ticket triage, alert correlation, scripting assistants, and AI-native all-in-one platforms like OpenFrame that run intelligence across the whole stack.
Start with a readiness assessment, not a tool purchase. Confirm your ticket history is clean and your RMM, PSA, and monitoring systems connect. Then pick one high-volume, low-risk workflow, usually ticket triage, and pilot it on internal tickets before any client sees it.
Automate high-volume, low-risk tasks first. Ticket triage and alert noise reduction top the list because they run constantly and a human still resolves the underlying issue. Save security approvals, billing changes, and client-facing actions for later, always with a human in the loop.

AI Safety

It can be, with governance. Keep a human in the loop on high-risk actions, log every automated step for audit, and choose platforms that keep your data yours with no vendor lock-in. Pilot on internal data first so you catch issues before client systems are involved.

AI for MSPs

Set a baseline before rollout, then track tickets closed per technician, mean time to resolution, percentage of tickets resolved with no human touch, technician hours reclaimed, and cost per ticket. AI-driven automation commonly cuts operational cost per ticket by 25 to 40%.

Getting Started

The People Hub is Flamingo's internal home for the team. Every employee can browse the team roster, open a colleague's “Who Am I” profile, share what they shipped each month, and keep their own profile up to date. Managers additionally see performance insights built on the SPACE framework.

About OpenFrame

OpenFrame isn't built to plug into your stack. It replaces it. Instead of duct-taping a dozen tools together (RMM, MDM, SIEM, patching, remote access, each its own login and bill), we bundle it into one unified platform: RMM, MDM, monitoring, automation, remote access, patch management, security monitoring, and ticketing, plus built-in AI copilots. So "does it integrate with X?" usually means: you won't need X anymore.
Five covers almost every small office: staff, guest, printers and IoT, voice, and management. Add a sixth for servers if anything stays on-premises. Each is a VLAN on the switch and a /24 subnet on the firewall, with default deny between them and specific allowed flows written down.