Skip to main content
Security settings define tenant-wide controls for Personal Access Tokens (PATs), security notifications, and access to the TrueFoundry UI.
You need the Tenant Admin role or a custom role with the Manage Settings (settings:ManageSettings) permission to update these settings.

Open security settings

1

Log in to your tenant

Log in to the TrueFoundry tenant you want to configure.
2

Open Security settings

Go to Settings > Organisation > Security & Access > Security, then select the edit icon.
Configure Settings for Security form showing Personal Access Token limits, Optional team assignment selected, token retrieval disabled, security notifications enabled, and UI login IP restrictions enabled

Configure tenant-wide security settings

Personal Access Token controls

Use these settings to control how users create and retrieve Personal Access Tokens.

Team assignment modes

Enable PAT retrieval after creation only when a workflow requires it. Anyone who obtains a PAT can act with the permissions of the user who owns it.

Security notifications

Turn on Send security updates to and add one or more email addresses that should receive security-related notifications. Use a monitored group address, such as security@example.com, so notifications do not depend on one person.

Restrict UI logins by IP

Turn on Restrict UI Logins by IP to allow browser access only from the listed IP addresses and CIDR ranges.
UI login IP allowlisting is available only on TrueFoundry SaaS.
This restriction applies to the TrueFoundry UI. It does not restrict API or AI Gateway access.
Include the public IP address from which you are configuring the allowlist. TrueFoundry prevents you from saving the settings if your current IP address is not allowed.
Add each permitted IP address or CIDR range under Allowed IPs and CIDRs. Use the narrowest ranges that cover your corporate network, VPN, or approved administrator locations.

Save or apply using YAML

  • Select Save to apply the settings from the form.
  • Select Apply using YAML to manage the same configuration declaratively, then follow the instructions shown in the dashboard.

API keys

Create, use, rotate, and revoke Personal Access Tokens and Virtual Account tokens.

SaaS security

Review TrueFoundry security controls and the tenant security checklist.