Setup
Profile, organization policies, security, API keys, billing, usage, and referrals.
Complete reference for the Setup section — profile, organization policies, notifications, security, API keys, usage, billing, and referrals.
The section is always visible in the sidebar, but its pages are gated individually and not uniformly. See Who can open what first.
For the fast path, use the Quick Start.
Section map#
| Sidebar page | Path | What it covers |
|---|---|---|
| Profile | /settings/profile | Your name and avatar |
| Organization | /settings/organization | Org-wide policy: timezone, retention, PII, business hours |
| Reports | /settings/reports | Scheduled operational reports |
| Escalation | /settings/escalation | Idle-time rules for chats and tickets |
| Notifications | /settings/notifications | In-app inbox, alert preferences, customer notification history |
| Security | /settings/security | Password, 2FA, org 2FA policy, single sign-on |
| API Keys | /settings/api-keys | REST API keys, scopes, and request logs |
| Usage History | /settings/usage-history | Consumption per billing period, invoices |
| Subscription | /subscription | Plan, limits, upgrade, cancel |
| Payment Methods | /payment-methods | Saved cards |
| Referrals | /referrals/links | Referral links and payout account |
| Referral Earnings | /referrals/earnings | Conversions and payout history |
Who can open what#
| Page | Visible to |
|---|---|
| Profile, Notifications, Security | Everyone — but the org 2FA policy is owner-only and the single sign-on panel is owner or admin |
| Organization | Owner (or a user with no organization yet) |
| Reports, Escalation | Owner only |
| API Keys | Owner or admin |
| Subscription, Payment Methods, Referrals, Referral Earnings | Everyone except agents and supervisors |
| Usage History | Anyone with an organization |
That table is the default for each role. An owner can tighten it per role under Users → Permissions, documented in Member permissions — never loosen it, so a page absent above cannot be opened by policy.
Two clarifications worth stating plainly, because they are commonly assumed otherwise:
Organization, Reports, and Escalation are owner-only, not owner-or-admin. An admin cannot change the organization timezone or the escalation rules.
Team management is not on the Organization page. Inviting and managing people happens in the sidebar's Users section — the Admins, Agents, and Supervisors pages — documented in Support.
The settings pages have no in-page role check of their own. Gating is by sidebar visibility plus server-side authorisation on save, so a directly pasted URL may render a page your role cannot actually act on.
Profile#
| Field | Notes |
|---|---|
| First Name | 1–50 characters |
| Last Name | 1–50 characters |
| Profile Picture | Update via URL or Direct Upload |
Update Profile saves. Your first name is what the dashboard greeting uses.
Organization#
Owner only. With no organization yet, this page becomes Create Organization instead, asking for an Organization Name and Domain.
Identity
| Field | Notes |
|---|---|
| Organization ID | Read-only with a copy button — Quote this when contacting support. |
| Organization Name | Free text |
| Domain | Normalised on save; the page previews Will be stored as: … |
| Organization Logo | JPEG, PNG, GIF, SVG, or WebP, max 5MB, with Remove |
Timezone
Timezone defaults to your browser's zone and defines your organization's local day.
This single field has effects across the product: scheduled reports and escalation alerts fire relative to it, and Dashboard → Call Centre counts its days in it while every other analytics page uses UTC. If a colleague reports that a scheduled report arrives at an odd hour, check here first.
Billing currency
Billing Currency determines which pricing plans you are shown and what currency subscriptions and add-ons are charged in.
It locks once a paid subscription is active — Locked because this organization has an active subscription. Cancel the current subscription before changing currency. On single-currency deployments it is fixed by the platform and cannot be changed at all.
Limits and policy
| Field | Range | What it does |
|---|---|---|
| Allowed Domains | Comma-separated | Domains permitted for the organization |
| Max Chat Sessions | 0–10000 | Cap on concurrent chat sessions |
| Retention Days | 0–90 | How long transcripts are retained |
| Enable Analytics | Toggle | Whether analytics are collected |
Transcript PII Redaction
Scrub email, phone, credit card, SSN, IP, and street address from chat and call transcripts before they reach LLM enrichment, dashboard responses, and post-call trigger matching. Raw transcripts remain in storage until your retention window expires.
| Control | Notes |
|---|---|
| Enable PII Redaction | Master toggle |
| Entity types to scrub | email, phone, credit_card, ssn, ipv4, street_address |
| Persist a redacted copy | Keeps the redacted version alongside the raw transcript |
Leaving every entity unticked uses the default set of all six — an empty selection is not "scrub nothing".
Read the second sentence of that description carefully: redaction governs what reaches the AI, the dashboard, and trigger matching. It does not delete the raw transcript, which persists until retention expires. For a compliance story you generally want redaction on, the redacted copy persisted, and Retention Days set deliberately rather than left open.
Support Agent Business Hours
Set working days and hours for agent availability. Outside these hours, support requests will stay pending.
Tick Enable Business Hours Restriction, then set slots per day with From and To times and Add Slot for split shifts. Days with no slots show Day off — not available.
The consequence is the part to internalise: outside these hours a customer asking for a human is told nobody is available and their request stays pending rather than being dropped. It waits for the next working window. Set these hours honestly — an empty schedule with the toggle on means requests never get picked up.
Update Organization saves everything on the page.
Reports#
Owner only. Heading: Daily Reports Settings — but the frequency is configurable, so this is really "scheduled reports".
| Control | Options |
|---|---|
| Enable Daily Reports | Toggle; the rest of the form appears only when on |
| Who should receive daily reports? | owner, supervisor, Agents |
| Delivery Medium (Select one or more) | Email, WhatsApp Group, Microsoft Teams |
| Report Frequency | daily, weekly, monthly |
| Schedule Time | Defaults to 09:00, in the organization timezone |
Choosing WhatsApp reveals WhatsApp Group ID (WhatsApp credentials themselves are server-side configuration). Choosing Teams reveals Teams Webhook URL — Create an incoming webhook in your Teams channel and paste the URL here.
Recipients are chosen by role, not by person. Selecting Agents sends to every agent.
This toggle also governs the emailed monthly insights write-up described in Insights — a workspace with reports disabled never receives it.
Escalation#
Owner only. Two independent rule sets on one page, each with its own toggle, timings, and notification settings.
Escalated Support Chat Configuration
When enabled, active conversations that haven't received a response within the specified time will be automatically flagged as "Escalated".
| Field | Range |
|---|---|
| Enable Automatic Escalation | Toggle |
| Idle Time (Hours) | 0–720 |
| Idle Time (Minutes) | 0–59, default 5 |
| Escalation Notification Method | Email, WhatsApp Group, Microsoft Teams |
| Who should receive escalation emails? | owner, supervisor, agents |
Escalated Support Ticket Configuration
When enabled, unresolved support tickets that haven't been updated within the specified time will trigger escalation alerts. Minimum 5 minutes.
Same shape, applied to ticket inactivity rather than chat silence, with a hard floor of 5 minutes total.
Save All Escalation Settings commits both.
What this is and is not: escalation here flags and alerts. It marks a conversation Escalated so it surfaces in the Support inbox filters and pings the people you nominated. It does not itself move a conversation to a specific person — that is the Human Handoff workflow node and the assignment controls in Support.
Notifications#
Open to everyone. Three tabs.
| Tab | Contents |
|---|---|
| Inbox | Your in-app notification feed |
| Preferences | Which events notify you |
| History | Customer notification history |
Preferences is headed Alert Preferences — Choose which floGPT events notify you and your team on WhatsApp — escalations, tickets, CRM activity, and daily reports. More channels (email, in-app) are coming.
Delivery here is WhatsApp only today. Without a connected WhatsApp Business account you get No WhatsApp Business account connected and a link to Integrations → Meta Messaging. Connect that first — see Integrations.
History shows Shopify order notifications sent to your customers over WhatsApp and email — outbound customer messaging, not your own alerts.
Security#
Open to everyone. Four panels stacked: the first two are about your own account, the Organization Security Policy is owner-editable only, and Single Sign-On is owner or admin.
Password
Update Password reveals Change Password with Old Password, New Password, and Confirm New Password.
The enforced rule: Password must be at least 8 characters long and contain at least one uppercase letter, one lowercase letter, and one number. This rule is fixed — there is no configurable complexity policy.
Two-Factor Authentication
Add an extra layer of security to your account by requiring a one-time code from your authenticator app (Google Authenticator, Authy, 1Password, etc.) in addition to your password.
Setup is a two-step wizard: Step 1 — Scan the QR code (with a manual-entry code as a fallback) and Step 2 — Enter the 6-digit code.
You are then shown recovery codes under the heading Save your recovery codes — this is the only time you'll see them, with Download codes (.txt) and Copy to clipboard. Each code works exactly once. Store them in a password manager before closing that panel.
Once enabled the panel reports You have {n} unused recovery codes left, and offers Regenerate recovery codes (which invalidates the old set and needs a current 6-digit code) and Disable 2FA (which needs your account password).
Organization Security Policy
Owner-editable; others see a read-only Organization 2FA policy summary.
Require members of this organization to enable two-factor authentication. Members without 2FA enabled will be redirected to the setup wizard at their next login and won't be able to disable it as long as the policy is active.
Apply to is either all members or a chosen set of Owners, Admins, Supervisors, Agents, Editors, Viewers. Leaving every role unticked requires 2FA from everyone.
You must have 2FA on your own account first — otherwise: Heads up — you must enable 2FA on your own account first (above) before turning on org-wide enforcement.
Single Sign-On (SSO)
Owner or admin. Others see Only organization owners and admins can manage single sign-on.
Let your team sign in with your own identity provider — Okta, Microsoft Entra ID, Google Workspace, Auth0, JumpCloud, Ping, or anything else that publishes an OpenID Connect discovery document.
OpenID Connect only. There is no SAML and no SCIM provisioning, and floGPT does not map IdP groups to floGPT roles — every account provisioned by a sign-in gets the one role you pick below. If your security review asks for SAML or SCIM, the answer is still no.
Registering floGPT at your provider
Create an OpenID Connect web application with the authorization-code flow, then fill in four fields:
| Field | Where it comes from |
|---|---|
| Provider name | Yours to choose. Shown to your team on the sign-in screen. |
| Issuer URL | Your provider's issuer, e.g. https://acme.okta.com/oauth2/default. Paste the issuer itself, not the /.well-known/openid-configuration URL. |
| Client ID | From the application you just registered. |
| Client secret | From the same place. Leave blank for a public client using PKCE only. |
Copy the Redirect URI shown in the panel into your provider's sign-in redirect URIs before enabling. floGPT requests the openid, email, and profile scopes.
Test connection fetches the discovery document and reports what it found — an issuer that comes back with a different value than you typed is the usual mistake, and it is fatal because ID tokens are checked against the issuer byte for byte. If your provider publishes no userinfo endpoint it must send the email claim in the ID token itself, and the test says so.
Role for new accounts is Viewer, Agent, Supervisor, or Editor. Owner and admin are deliberately unavailable — a federated sign-in must not be able to arrive holding administrative rights, so promoting somebody stays a manual act inside floGPT.
Sharing the login link
Once enabled, the panel shows a Login link specific to this workspace. Send it to your team, or point them at Sign in with SSO on the login page, where they paste the same link.
floGPT does not route by email domain. Your people reach their workspace by its link, not by typing an @acme.com address into a form that then guesses.
What a first sign-in does
A first-time user gets a floGPT account in this workspace at the role above. An account that already exists under the same email address is linked rather than duplicated. A sign-in never creates a workspace, so someone whose provider account has no floGPT workspace to join is turned away rather than onboarded.
Accounts created this way have no password. Their holder can still set one through Forgot your password? against their own verified address.
Require single sign-on
Members of this organization will not be able to sign in with an email and password.
The tick box stays disabled until a sign-in has actually succeeded through the connection. Until then a wrong issuer or a stale secret would lock out everyone but you, and that is not something support can fix from outside.
Three rules are worth knowing before you turn it on:
- The workspace owner always keeps password access. This is deliberate — a provider outage would otherwise be unrecoverable. Every such sign-in is recorded in the SSO audit trail.
- A member of several workspaces must use SSO if any one of them requires it. A floGPT session is not scoped to a single workspace, so a password sign-in would reach the strict workspace too. Being a member of a relaxed workspace does not buy anyone a password.
- Owning a workspace elsewhere is not a way around it. The owner exception applies only to someone who owns every workspace that requires SSO of them.
A refused sign-in tells the user which workspace is asking, which provider to use, and the link to use — they do not have to go and ask.
Removing the connection deletes the stored client secret and drops enforcement with it, so a workspace can never be left requiring a provider it no longer has.
There is no session or idle-timeout policy. Sessions last 7 days and there is nothing to configure.
API Keys#
Owner or admin. Others see Only organization owners and admins can manage API keys. An owner can also close it to admins via Member permissions, in which case they see The owner has removed your access to this organization's API keys. Revoking only Create and revoke API keys leaves the list and its logs readable without the Create key, Edit scopes, and Revoke controls.
Create org-scoped keys for the REST API at /api/v1. Edit scopes anytime without rotating the secret. An API documentation button links to the API reference.
Creating and managing a key
Create key asks for a Name and at least one Scope — Name and at least one scope are required.
The dialog then flips to Save your API key with Copy this key now. It will not be shown again. Afterwards the list shows only a masked prefix…last4.
| Action | Behaviour |
|---|---|
| Edit scopes | Changing scopes takes effect immediately for subsequent requests. The secret itself is unchanged. |
| Revoke | Revoke this API key? This cannot be undone. |
There is no rotation. To replace a key you revoke and create a new one, which means a brief overlap has to be managed on your side — create the new key first, migrate, then revoke the old one.
Each row shows the name, masked key, scopes, and Last used, which is the quickest way to find a key nothing is calling any more.
Scopes
Read and write are separate, per area: Chat widgets, Call widgets, Knowledge bases, CRM, Conversations, Call logs (write is manual reinitiate only), Analytics (read only), Meta Lead Ads integrations, Outbound triggers, Data collections, and Email integrations.
Grant read where you only need read. Scopes are editable later, so starting narrow costs nothing.
Usage and logs
API usage & logs — Rolling 30-day summary, errors, and recent request logs, with Refresh.
Metrics: Requests, Successful, Errors, Rate limited, Last 24 hours, Avg. latency.
Log table: Time, Key, Request, Client IP, Status, Duration, filterable to All logs or Errors only and by key. Empty: No API errors recorded for this filter. / No API requests recorded yet.
Using a key from an AI coding agent or the terminal
mcp/flogpt-mcp/ in the repository ships two front ends over the same API:
- An MCP server, so Claude Code, Cursor, Codex and other MCP clients can operate the workspace directly. The client spawns it locally and talks over pipes, so nothing listens on a port and the key never leaves your machine.
- A CLI (
flogpt), with the same commands, so you can reproduce by hand whatever an agent just did.
export FLOGPT_API_KEY=fg_live_...
flogpt whoami
flogpt call-logs --status failed --limit 20 --table
Scope the key to what the agent should be allowed to do — the scopes you tick here are exactly the ceiling on what it can reach. A refused request names the missing scope rather than failing vaguely.
About seventeen commands cover the endpoints an agent actually reaches for; flogpt request handles everything else. See mcp/flogpt-mcp/README.md.
Usage History#
Anyone with an organization. Subscription Usage History — Billing period breakdown of token and message consumption.
Summary cards: Latest Period, LLM Tokens Used, Messages Sent.
Table: Billing Period, LLM Tokens, Messages, Last Updated, Invoice. The active period is badged Current, and the invoice column offers Download PDF where an invoice exists.
This page shows consumption, not limits. For usage against your plan's allowances, use the Usage Statistics panel on Subscription.
Empty: No usage history yet — Usage data will appear here once your subscription is active.
Subscription#
Hidden from agents and supervisors.
Current plan
Current Plan with a status pill (active, trialing, past_due, canceled), a Billed via Shopify pill where applicable, and Annual billing / Monthly billing.
Details: Period Start, Period End, Next Billing. Trial ends on {date} appears while a trial is running, and Subscription will cancel on {date} after you cancel.
Choosing a plan
Choose Your Plan — Select the plan that fits your needs. A currency toggle (USD, INR, EUR, subject to the lock described above) and a Monthly / Yearly switch sit above the grid.
Plan cards show the price, a Save X% pill on annual, the feature list with each limit (or Unlimited), and pills for Most Popular and Current Plan. Plans and their limits are defined by the platform, so what you see depends on your billing currency.
Upgrading or downgrading means picking another card and completing the payment dialog; proration is handled for you. Cancelling is at period end — You'll continue to have access until the end of your billing period. This action can be reversed by resubscribing.
Some plans carry a one-time setup fee (Chat setup, Call setup), shown in the payment dialog and skipped if already paid.
Usage Statistics
Your consumption against the active plan's limits. Bars for LLM Tokens, Messages, Chat Widgets, Workflows, Knowledge Bases, and Data Collections, each showing used against limit, or Unlimited.
This is the panel to check before a launch. Hitting a widget or workflow limit fails at creation time, which is a bad thing to discover mid-campaign.
Shopify billing
If FloGPT was installed through Shopify, this page replaces the plan grid, billing portal, and card dialog with Billing is managed in Shopify and buttons for Open Shopify Billing and Open Shopify Admin.
Your plan and your metered add-ons — phone numbers, call minutes, SMS — are charged on your Shopify invoice. Saved cards under Payment Methods play no part. See FloGPT for Shopify.
INR subscriptions are completed through Razorpay rather than the inline card form: You'll be redirected to Razorpay to securely complete your INR subscription.
Payment Methods#
Manage cards saved to your organization. Add Card opens New card details.
Cards list with brand, last four digits, expiry, and a Default badge, with actions to set default or remove.
Deleting a card is blocked while a subscription is active — Cannot delete a payment method while an active subscription exists, with the note Card deletion is disabled while an active subscription is running. Cancel first, or add a replacement and make it default.
Shopify-billed organizations see Billed through Shopify — no card needed here.
Referrals#
Hidden from agents and supervisors. Two tabs.
My Referral Links
Stat cards: Total Clicks, Signups, Conversions, Total Earnings, Pending Payout.
Generate Link opens Generate Referral Link:
| Field | Notes |
|---|---|
| Custom Code (optional) | 3–20 characters, letters, numbers, hyphens, underscores. Blank auto-generates |
| Label (optional) | A label helps you track which campaign this link belongs to |
The result is a link of the form /signup?ref={code}. The table lists Label / Code, Clicks, Signups, Conversions, Earnings, Status, Actions, with copy, pause or activate, and delete per row.
Generate a separate link per channel and label it. There is no other way to attribute where a signup came from.
Payouts
Stripe Connect handles payout onboarding. Statuses are Stripe Account Connected, Verification Pending, Account Restricted, and No Account Connected, with Connect Stripe Account, Complete on Stripe, Refresh Status, and Resolve in Stripe Dashboard as appropriate.
The Referral Earnings tab lists Converted Referrals with Referee, Link, Status, Earned, Converted, and an expandable Payout History per row showing Amount, Status, Transfer ID, Requested, Paid, with a rejection reason where one applies.
Two honest caveats. The commission rate is set by the platform, not shown or chosen here — you see the resulting earnings only. And although the onboarding copy mentions requesting a payout from the Earnings tab, there is no self-service request button: payouts are initiated and approved by the FloGPT team, and this tab is read-only. Contact your account manager to chase one.
Troubleshooting#
| Symptom | Usual cause |
|---|---|
| Organization, Reports, or Escalation missing | Those three are owner-only — an admin cannot see them |
| Cannot find where to invite people | Team management is in the Users section — the Admins / Agents / Supervisors pages, not here |
| Scheduled report arrives at the wrong hour | Timezone on the Organization page is wrong |
| Reports enabled but nothing arrives | Recipients are chosen by role — check a role is ticked and has members |
| No monthly insights email | Scheduled reports are disabled for the organization |
| Support requests sit pending overnight | Expected with Business Hours Restriction on — they wait for the next window |
| Business hours on but nobody ever picks up | The schedule has no slots; an empty schedule blocks every hour |
| PII still visible in stored transcripts | Redaction governs AI, dashboard, and trigger matching; raw transcripts persist until retention expires |
| Cannot change billing currency | Locked by an active subscription, or fixed by the platform |
| Cannot delete a card | Blocked while a subscription is active |
| Lost the API key | It is shown once only; revoke it and create a new one |
| API returns 403 after a scope change | Scopes apply to subsequent requests only; check the right scope is ticked |
| Cannot enforce org-wide 2FA | Enable 2FA on your own account first |
| Looking for SSO or session timeout | Neither exists |
| Alert preferences say no WhatsApp account | Connect WhatsApp Business under Integrations → Meta Messaging |
| Plan grid missing, Shopify notice instead | The workspace is billed through Shopify |
| No payout request button | Payouts are team-initiated; the tab is read-only |
Related#
- Setup quick start
- Start here — first-run setup in order
- Support — team management and where escalations land
- Insights — the scheduled reports and the timezone effect
- Integrations — WhatsApp and Teams delivery channels
- FloGPT for Shopify — Shopify-managed billing