Skip to main content

Settings

The Settings page centralizes your organization's configuration across seven tabs. Access from Administration → Settings in the sidebar.

Settings page showing General tab active with seven tabs (General, Compliance, Notifications, Integrations, AI, SSO, Import/Export), Organization section with Company Name, Industry, Website, Address, and Primary Contact Email fields, and Branding section with Logo file upload and Primary Color hex picker with Reset to Default button

General

Organization

FieldDescription
Company NameYour organization's display name
IndustryIndustry classification (e.g., Healthcare Technology)
WebsiteOrganization website URL
AddressBusiness address
Primary Contact EmailMain contact email for the organization

Branding

FieldDescription
LogoOrganization logo (PNG, JPG, or SVG; max 2 MB)
Primary ColorBrand color with hex input and color picker

Click Reset to Default to revert branding to the platform defaults.

Compliance

The Compliance tab has two sub-tabs:

Frameworks

Toggle which compliance frameworks are active for your organization. Available frameworks include SOC 2, ISO 27001, ISO 42001, PCI DSS, HIPAA, and others from the platform library.

Enabling a framework auto-enrolls the associated controls, evidence requests, and recurring activities from the Master Framework Library.

Products

Manage products and scopes for per-product compliance tracking. Each product can be mapped to specific frameworks, allowing independent status and evidence per product.

Notifications

Configure organization-wide notification preferences:

  • Digest emails — Enable/disable, set frequency (daily/weekly), preferred day and time, timezone
  • Email notifications — Toggle per event type: task assigned, task overdue, task due soon, mentions, comment replies, control status changes, assessment assignments, report reviews, security alerts, support ticket updates
  • In-app notifications — Same toggles as email, controlling the in-platform notification bell

Integrations

Browse and configure integrations from the platform catalog. Integrations are grouped by category:

CategoryExamples
CloudAWS (GuardDuty, IAM, Infrastructure)
IdentityGoogle Workspace, Microsoft 365 (Entra ID)
SecurityEndpoint management (SimpleMDM, Intune, Jamf Pro)
NotificationsSlack, Microsoft Teams
TicketingJira, Motion

Each integration card shows connection status and provides configure/manage actions. Some integrations support multiple connections (e.g., multiple AWS accounts).

See Integrations for detailed setup guides.

AI

Configure AI features for your organization:

AI Feature Categories

CategoryDescription
OrchestratorCore AI orchestration capabilities
Auto SuggestAutomatic suggestions for field values and mappings
AnalysisAI-powered analysis (risk, evidence, vendor review)
GenerationContent generation (reports, policies, remediation plans)

Per-Feature Controls

Each AI feature can be individually:

  • Enabled/disabled — Toggle the feature on or off
  • Model selection — Override the default model for this feature
  • Cost estimation — View estimated cost per invocation

Access Level

Control who can use AI features:

  • Operators only — Only Concerto staff can use AI
  • All users — All tenant users can use AI features

See AI Configuration for detailed settings.

SSO

Configure Single Sign-On for your organization:

Supported Providers

ProviderDescription
Google WorkspaceGoogle OAuth/OIDC integration
Microsoft Entra IDMicrosoft 365 SSO with tenant ID and client credentials
Custom SAML/OIDCStandard SAML 2.0 or OIDC configuration

SSO Settings

SettingDescription
SSO EnforcementWhether SSO is required or optional
JIT ProvisioningAutomatically create user accounts on first SSO login
Default JIT RoleRole assigned to auto-provisioned users
Max SessionMaximum session duration in minutes
Idle TimeoutSession timeout after inactivity
MFA PolicyMulti-factor authentication requirements
MFA Grace PeriodDays before MFA enforcement takes effect

Import / Export

Bulk import data into your organization from CSV files.

Supported Entity Types

EntityDescription
VendorsVendor inventory records
RisksRisk register entries
Recurring ControlsRecurring activity definitions
PoliciesPolicy and procedure records
BIABusiness impact assessment entries
Key ContactsOrganizational key contacts
VulnerabilitiesVulnerability records
ProjectsProject/initiative records

Import Workflow

  1. Select entity type — Choose what to import
  2. Upload CSV — Upload your data file
  3. Map fields — Match CSV columns to platform fields
  4. Set duplicate strategy — Skip, update, or create duplicates
  5. Preview — Review mapped data before importing
  6. Execute — Run the import with progress tracking

Export history is available for previously completed imports.

Support Access

Available for self-service and audit firm tenants. Grant temporary access to the Concerto support team for troubleshooting assistance.

DurationDescription
24 hoursShort-term support session
7 daysExtended troubleshooting
30 daysLonger engagement
IndefiniteUntil manually revoked

All grants and revocations are recorded in an audit log accessible from this tab.

Audit Log

Access from Administration → Audit Log. View a chronological record of all changes made within your organization:

FieldDescription
WhoUser who made the change
WhatRecord type and ID that was changed
WhenTimestamp of the change
ChangesPrevious and new field values

Use the audit log for compliance evidence, incident investigation, or tracking configuration changes.