Platform Settings
The Platform Settings page, its tabs, and the permission each tab needs.
Platform Settings holds what applies to the whole installation rather than to one boundary.
Open it with Settings → Platform Settings in the sidebar. The entry is shown to principals who
hold kernel/emailSettings/manage at the platform root — Platform Owners and Platform
Contributors.
Tabs
Every permission below is checked at the platform root, so only platform roles grant it.
| Tab | What it holds | Needs | Page |
|---|---|---|---|
| Email (SMTP) | The mail server the platform sends through | kernel/emailSettings/manage |
Set up e-mail delivery |
| Email templates | The texts of the e-mails the platform sends | kernel/emailTemplates/manage |
Edit e-mail templates |
| Clusters | The Kubernetes clusters the platform deploys onto | kernel/clusters/read; kernel/clusters/write to change |
Clusters |
| Single sign-on | Each tenant's e-mail domains and identity providers | rbac/idpBindings/admin |
Single sign-on |
| AI clients | Whether AI clients can connect over MCP, and which hosts may register one | kernel/mcpSettings/manage |
Turn on AI clients |
| Telemetry | Whether and where the platform exports its own logs, metrics and traces | kernel/telemetrySettings/manage |
Export platform telemetry |
| LLM gateways | The language-model endpoints platform services use | kernel/llmGateways/read; kernel/llmGateways/write to change, kernel/llmGateways/delete to delete |
Create an LLM gateway |
| Sentinel settings | Which gateway and model each Sentinel stage uses | kernel/llmGateways/read; kernel/llmGateways/write to change |
Assign models to Sentinel |
The LLM gateways and Sentinel settings tabs are shown only to principals who can read LLM gateways. The other tabs are shown to everyone who opens the page; a tab whose permission you lack shows an error instead of its content.
Who holds what
| Role | Tabs |
|---|---|
| Platform Owner | All |
| Platform Contributor | All; on Clusters it can look but not change anything |
| Platform Reader | LLM gateways and Sentinel settings, read-only; the sidebar has no entry for it |
A role assigned on a boundary never reaches these settings, Owner included.