Firm Settings: Tenant Configuration Overview
Overview of the Quartyl firm settings panel: the tabs, what is configured tenant-wide versus per study, secret masking, and who can read, change or reset each block.
Firm settings is the one place a firm configures the tenant instead of a study: one panel, one row per firm, holding the policy the whole practice runs on. This page is the map — what is configured firm-wide, what stays per-study, and how the panel handles access and secrets.
The panel and its plan boundary
Plan feature: This capability requires the
firm_settingsplan feature (see Plan Features).
The panel lives at Firm Settings in the Administration group of the sidebar. Each configuration area is stored as its own document and returned merged over the platform defaults, so a firm that has never touched a field still sees a complete, valid configuration.
The tabs
The panel renders three tabs, and which of them you see depends on your role and on the firm’s plan:
| Tab | Who sees it | What it holds | Sub-page |
|---|---|---|---|
| Security | always (first tab) | Session timeout, the firm-wide MFA mandate, audit retention | Security Settings |
| Single Sign-On | Firm Admin only (a Partner must not be able to block password login) | The tenant’s OIDC issuer, client credentials, email domains and the enforce toggle | — |
| Branding | only when the firm holds white_label |
Brand name and accent color | Branding and White-Label |
Two further configuration documents exist on the API but have no tab in this panel:
| API block | State today |
|---|---|
tp_defaults — jurisdiction, PLI, permitted methods, range percentiles, base currency |
Stored, validated, returned and reset with the firm’s settings document; no editor UI, and nothing in the study wizard reads it — see TP Defaults |
integrations — financial database keys, ERP connections |
Stored and secret-masked on the API; no editor UI, and no pipeline call reads them |
There is no workflow tab: the study states, their order and the roles allowed on each transition are fixed in the platform, and firms configure nothing there — see Workflow Configuration.
Each tab is its own form with its own save; saving one never touches the others, and a save records who changed it and when.
Firm-wide versus per-study
The dividing line is: a policy is firm-wide, a decision is per-study.
- Firm-wide, and effective: the security policy (MFA mandate, audit retention), single sign-on, branding, and the plan’s feature gates.
- Firm-wide, but recorded rather than applied: the
tp_defaultsbaseline (jurisdiction, PLI, permitted methods, range percentiles, currency) and theintegrationsdocument. Both are stored, validated and reset with the firm’s settings, and both are returned by the API — but the study wizard starts from the platform defaults (India,OP/OC) and no pipeline step reads these blocks. TP Defaults carries the detail. - Per-study (configured in the wizard, recorded on the study): the data file and its column mapping, the tested party profile, the data years and averaging approach, the search region and size filters, and every comparable disposition. A study’s own parameters are part of its record, not a runtime preference.
Secrets: masked, never plaintext
Integration credentials (financial database API keys, ERP passwords) follow
one rule: they are never returned verbatim. Every read of the settings
document shows the masked sentinel •••••••• in place of the stored secret.
The round-trip is deliberate:
- Submitting the masked value back (leaving the field as shown) preserves the stored secret.
- Submitting a real new value replaces it.
- Submitting an explicit empty value clears it.
The same treatment applies wherever the document is read — no plaintext secret
surfaces in the API response, and the SSO client secret is never echoed back
either. Note that the integrations document has no editor in the panel
today, so this is a rule the API enforces on data a firm cannot yet fill in
through the UI.
Access, save and reset
| Action | Who |
|---|---|
| Read the panel | Partner, Firm Admin, Superadmin |
| Change a block | Partner, Firm Admin |
| Configure single sign-on | Firm Admin only |
| Reset everything to platform defaults | Firm Admin only |
- Partial saves. Each top-level block is applied only when present in the save, so editing Security never rewrites TP Defaults.
- Reset restores every document to the platform defaults in one action — including clearing branding back to the platform identity. It returns a confirmation only; the panel re-fetches its values after the reset.
- Superadmin sees the panel read-only with a notice, and the Reset action is hidden — the platform operates the workspace, it does not configure a firm’s.
- All three actions carry the same plan gate. Read, save and reset each
require
firm_settings; a tenant without it gets a403on the endpoint and a locked panel in the workspace.
FAQ
What does Reset actually reset? Every settings document for the tenant back
to the platform defaults: TP Defaults to the standard baseline, Security to the
defaults (MFA mandate off, 30-minute session value, 7-year audit retention),
Integrations to empty, and Branding to the platform identity. It is one
endpoint, guarded by firm_settings, and it returns a confirmation only.
Does changing a default rewrite existing studies? No. A study’s recorded parameters stand as they were captured.
Where do I configure review routing? Nowhere in this panel — there is no workflow tab, and the state machine and its per-transition roles are fixed. Routing follows the team console’s reports-to chain: set each analyst’s manager and each manager’s partner there, and the review queue resolves from those links. See Workflow Configuration.
See it working in your workspace
Sign in to run the steps above on a real study — or book a demo and we will walk the workflow end to end.
Related docs
Branding and White-Label: Firm Name and Accent Color in the Workspace
How white-label branding works in Quartyl: the firm brand name and accent color, where they show in the workspace, the design-token override, and why generated reports stay platform-branded.
Read docTP Defaults: Tenant-Wide Benchmarking Configuration
The tenant-wide TP defaults document in Quartyl: jurisdiction, PLI, permitted methods, arm length range and base currency, what the block records, and what the study wizard actually starts from.
Read doc