Skip to main content

Settings

The Settings page centralizes your organization's configuration. Access from Administration > Settings in the sidebar. Settings are organized into five sections in a left-side navigation panel.

Settings page showing General tab active with Organization and Branding sections

Organization

General

FieldDescription
Company NameYour organization's display name
IndustryIndustry classification (e.g., Healthcare Technology)
WebsiteOrganization website URL
AddressBusiness address
Primary Contact EmailMain contact email for the organization

Branding

FieldDescription
LogoOrganization logo (PNG, JPG, or SVG; max 2 MB)
Primary ColorBrand color with hex input and color picker

Click Reset to Default to revert branding to the platform defaults.

Compliance

The Compliance section has two sub-tabs:

Frameworks

Toggle which compliance frameworks are active for your organization. Available frameworks include SOC 2, ISO 27001, ISO 42001, PCI DSS, HIPAA, GDPR, and others from the Master Framework Library.

Enabling a framework auto-enrolls the associated controls, evidence requests, and recurring activities.

Products

Manage products and scopes for per-product compliance tracking. Each product can be mapped to specific frameworks, allowing independent status and evidence per product.

Task Defaults

Configure default settings for task management across your organization. Requires the tenant.settings.manage permission.

Notifications

Configure organization-wide notification preferences:

  • Digest emails -- Enable/disable, set frequency (daily/weekly), preferred day and time, timezone
  • Email notifications -- Toggle per event type: task assigned, task overdue, task due soon, mentions, comment replies, control status changes, assessment assignments, report reviews, security alerts, support ticket updates
  • In-app notifications -- Same toggles as email, controlling the in-platform notification bell

Connections

Integrations

Browse and configure integrations from the platform catalog. Integrations are grouped by category:

CategoryExamples
Cloud InfrastructureAWS, Microsoft Azure, Google Cloud Platform
Identity & AccessMicrosoft 365 (Entra ID), Google Workspace
Endpoint ManagementMicrosoft Intune, Jamf Pro, SimpleMDM
CommunicationSlack
Task ManagementMotion
Source Control & CI/CDGitHub

Each integration card shows connection status and provides configure/manage actions. Some integrations support multiple connections (e.g., multiple AWS accounts).

See Integrations for detailed setup guides.

SSO & MFA

Configure Single Sign-On and multi-factor authentication for your organization.

Supported Providers

ProviderDescription
Google WorkspaceGoogle OAuth/OIDC integration
Microsoft Entra IDMicrosoft 365 SSO with tenant ID and client credentials

SSO Settings

SettingDescription
SSO EnforcementWhether SSO is required or optional
Max SessionMaximum session duration in minutes
Idle TimeoutSession timeout after inactivity
MFA PolicyMulti-factor authentication requirements
MFA Grace PeriodDays before MFA enforcement takes effect

Security

Activity Log

View a chronological record of all changes made within your organization:

FieldDescription
WhoUser who made the change
WhatRecord type and ID that was changed
WhenTimestamp of the change
ChangesPrevious and new field values

Use the activity log for compliance evidence, incident investigation, or tracking configuration changes.

Employee Portal

Configure your organization's employee-facing portal. The portal provides employees with self-service access to vendor directories, training assignments, policy acknowledgments, and incident reporting. See Employee Portal for details.


Data

AI

View and configure AI-powered features across four categories: Orchestrator, Auto-Suggest, Analysis, and Generation. Each feature can be individually enabled/disabled with per-feature model selection.

info

AI model and prompt settings are managed by platform administrators (Concerto operators). Tenant administrators can view configurations but cannot modify them directly.

See AI Configuration for detailed settings.

Import / Export

Bulk import data into your organization from CSV files.

Supported Entity Types

EntityDescription
VendorsVendor inventory records
RisksRisk register entries
Recurring ControlsRecurring activity definitions
PoliciesPolicy and procedure records
BIABusiness impact assessment entries
Key ContactsOrganizational key contacts
VulnerabilitiesVulnerability records
ProjectsProject/initiative records

Import Workflow

  1. Select entity type -- Choose what to import
  2. Upload CSV -- Upload your data file
  3. Map fields -- Match CSV columns to platform fields
  4. Set duplicate strategy -- Skip, update, or create duplicates
  5. Preview -- Review mapped data before importing
  6. Execute -- Run the import with progress tracking

Export history is available for previously completed imports.


Account

Support Access

Available for self-service and audit firm tenants. Grant temporary access to the Concerto support team for troubleshooting assistance.

DurationDescription
24 hoursShort-term support session
7 daysExtended troubleshooting
30 daysLonger engagement
IndefiniteUntil manually revoked

All grants and revocations are recorded in the Activity Log.