Complete Manual

Setup

Profile, organization policies, security, API keys, billing, usage, and referrals.

19 min readSidebar: SetupSwitch to Quick Start
Who can see this: Always visible; Organization, Reports, and Escalation are owner-only, and API keys and billing are owner or admin.

Complete reference for the Setup section — profile, organization policies, notifications, security, API keys, usage, billing, and referrals.

The section is always visible in the sidebar, but its pages are gated individually and not uniformly. See Who can open what first.

For the fast path, use the Quick Start.

Section map#

Sidebar pagePathWhat it covers
Profile/settings/profileYour name and avatar
Organization/settings/organizationOrg-wide policy: timezone, retention, PII, business hours
Reports/settings/reportsScheduled operational reports
Escalation/settings/escalationIdle-time rules for chats and tickets
Notifications/settings/notificationsIn-app inbox, alert preferences, customer notification history
Security/settings/securityPassword, 2FA, org 2FA policy, single sign-on
API Keys/settings/api-keysREST API keys, scopes, and request logs
Usage History/settings/usage-historyConsumption per billing period, invoices
Subscription/subscriptionPlan, limits, upgrade, cancel
Payment Methods/payment-methodsSaved cards
Referrals/referrals/linksReferral links and payout account
Referral Earnings/referrals/earningsConversions and payout history

Who can open what#

PageVisible to
Profile, Notifications, SecurityEveryone — but the org 2FA policy is owner-only and the single sign-on panel is owner or admin
OrganizationOwner (or a user with no organization yet)
Reports, EscalationOwner only
API KeysOwner or admin
Subscription, Payment Methods, Referrals, Referral EarningsEveryone except agents and supervisors
Usage HistoryAnyone with an organization

That table is the default for each role. An owner can tighten it per role under Users → Permissions, documented in Member permissions — never loosen it, so a page absent above cannot be opened by policy.

Two clarifications worth stating plainly, because they are commonly assumed otherwise:

Organization, Reports, and Escalation are owner-only, not owner-or-admin. An admin cannot change the organization timezone or the escalation rules.

Team management is not on the Organization page. Inviting and managing people happens in the sidebar's Users section — the Admins, Agents, and Supervisors pages — documented in Support.

The settings pages have no in-page role check of their own. Gating is by sidebar visibility plus server-side authorisation on save, so a directly pasted URL may render a page your role cannot actually act on.

Profile#

FieldNotes
First Name1–50 characters
Last Name1–50 characters
Profile PictureUpdate via URL or Direct Upload

Update Profile saves. Your first name is what the dashboard greeting uses.

Organization#

Setup → Organization.

Owner only. With no organization yet, this page becomes Create Organization instead, asking for an Organization Name and Domain.

Identity

FieldNotes
Organization IDRead-only with a copy button — Quote this when contacting support.
Organization NameFree text
DomainNormalised on save; the page previews Will be stored as: …
Organization LogoJPEG, PNG, GIF, SVG, or WebP, max 5MB, with Remove

Timezone

Timezone defaults to your browser's zone and defines your organization's local day.

This single field has effects across the product: scheduled reports and escalation alerts fire relative to it, and Dashboard → Call Centre counts its days in it while every other analytics page uses UTC. If a colleague reports that a scheduled report arrives at an odd hour, check here first.

Billing currency

Billing Currency determines which pricing plans you are shown and what currency subscriptions and add-ons are charged in.

It locks once a paid subscription is active — Locked because this organization has an active subscription. Cancel the current subscription before changing currency. On single-currency deployments it is fixed by the platform and cannot be changed at all.

Limits and policy

FieldRangeWhat it does
Allowed DomainsComma-separatedDomains permitted for the organization
Max Chat Sessions0–10000Cap on concurrent chat sessions
Retention Days0–90How long transcripts are retained
Enable AnalyticsToggleWhether analytics are collected

Transcript PII Redaction

Scrub email, phone, credit card, SSN, IP, and street address from chat and call transcripts before they reach LLM enrichment, dashboard responses, and post-call trigger matching. Raw transcripts remain in storage until your retention window expires.

ControlNotes
Enable PII RedactionMaster toggle
Entity types to scrubemail, phone, credit_card, ssn, ipv4, street_address
Persist a redacted copyKeeps the redacted version alongside the raw transcript

Leaving every entity unticked uses the default set of all six — an empty selection is not "scrub nothing".

Read the second sentence of that description carefully: redaction governs what reaches the AI, the dashboard, and trigger matching. It does not delete the raw transcript, which persists until retention expires. For a compliance story you generally want redaction on, the redacted copy persisted, and Retention Days set deliberately rather than left open.

Support Agent Business Hours

Set working days and hours for agent availability. Outside these hours, support requests will stay pending.

Tick Enable Business Hours Restriction, then set slots per day with From and To times and Add Slot for split shifts. Days with no slots show Day off — not available.

The consequence is the part to internalise: outside these hours a customer asking for a human is told nobody is available and their request stays pending rather than being dropped. It waits for the next working window. Set these hours honestly — an empty schedule with the toggle on means requests never get picked up.

Update Organization saves everything on the page.

Reports#

Setup → Reports.

Owner only. Heading: Daily Reports Settings — but the frequency is configurable, so this is really "scheduled reports".

ControlOptions
Enable Daily ReportsToggle; the rest of the form appears only when on
Who should receive daily reports?owner, supervisor, Agents
Delivery Medium (Select one or more)Email, WhatsApp Group, Microsoft Teams
Report Frequencydaily, weekly, monthly
Schedule TimeDefaults to 09:00, in the organization timezone

Choosing WhatsApp reveals WhatsApp Group ID (WhatsApp credentials themselves are server-side configuration). Choosing Teams reveals Teams Webhook URLCreate an incoming webhook in your Teams channel and paste the URL here.

Recipients are chosen by role, not by person. Selecting Agents sends to every agent.

This toggle also governs the emailed monthly insights write-up described in Insights — a workspace with reports disabled never receives it.

Escalation#

Setup → Escalation.

Owner only. Two independent rule sets on one page, each with its own toggle, timings, and notification settings.

Escalated Support Chat Configuration

When enabled, active conversations that haven't received a response within the specified time will be automatically flagged as "Escalated".

FieldRange
Enable Automatic EscalationToggle
Idle Time (Hours)0–720
Idle Time (Minutes)0–59, default 5
Escalation Notification MethodEmail, WhatsApp Group, Microsoft Teams
Who should receive escalation emails?owner, supervisor, agents

Escalated Support Ticket Configuration

When enabled, unresolved support tickets that haven't been updated within the specified time will trigger escalation alerts. Minimum 5 minutes.

Same shape, applied to ticket inactivity rather than chat silence, with a hard floor of 5 minutes total.

Save All Escalation Settings commits both.

What this is and is not: escalation here flags and alerts. It marks a conversation Escalated so it surfaces in the Support inbox filters and pings the people you nominated. It does not itself move a conversation to a specific person — that is the Human Handoff workflow node and the assignment controls in Support.

Notifications#

Open to everyone. Three tabs.

TabContents
InboxYour in-app notification feed
PreferencesWhich events notify you
HistoryCustomer notification history

Preferences is headed Alert PreferencesChoose which floGPT events notify you and your team on WhatsApp — escalations, tickets, CRM activity, and daily reports. More channels (email, in-app) are coming.

Delivery here is WhatsApp only today. Without a connected WhatsApp Business account you get No WhatsApp Business account connected and a link to Integrations → Meta Messaging. Connect that first — see Integrations.

History shows Shopify order notifications sent to your customers over WhatsApp and email — outbound customer messaging, not your own alerts.

Security#

Setup → Security.

Open to everyone. Four panels stacked: the first two are about your own account, the Organization Security Policy is owner-editable only, and Single Sign-On is owner or admin.

Password

Update Password reveals Change Password with Old Password, New Password, and Confirm New Password.

The enforced rule: Password must be at least 8 characters long and contain at least one uppercase letter, one lowercase letter, and one number. This rule is fixed — there is no configurable complexity policy.

Two-Factor Authentication

Add an extra layer of security to your account by requiring a one-time code from your authenticator app (Google Authenticator, Authy, 1Password, etc.) in addition to your password.

Setup is a two-step wizard: Step 1 — Scan the QR code (with a manual-entry code as a fallback) and Step 2 — Enter the 6-digit code.

You are then shown recovery codes under the heading Save your recovery codes — this is the only time you'll see them, with Download codes (.txt) and Copy to clipboard. Each code works exactly once. Store them in a password manager before closing that panel.

Once enabled the panel reports You have {n} unused recovery codes left, and offers Regenerate recovery codes (which invalidates the old set and needs a current 6-digit code) and Disable 2FA (which needs your account password).

Organization Security Policy

Owner-editable; others see a read-only Organization 2FA policy summary.

Require members of this organization to enable two-factor authentication. Members without 2FA enabled will be redirected to the setup wizard at their next login and won't be able to disable it as long as the policy is active.

Apply to is either all members or a chosen set of Owners, Admins, Supervisors, Agents, Editors, Viewers. Leaving every role unticked requires 2FA from everyone.

You must have 2FA on your own account first — otherwise: Heads up — you must enable 2FA on your own account first (above) before turning on org-wide enforcement.

Single Sign-On (SSO)

Owner or admin. Others see Only organization owners and admins can manage single sign-on.

Let your team sign in with your own identity provider — Okta, Microsoft Entra ID, Google Workspace, Auth0, JumpCloud, Ping, or anything else that publishes an OpenID Connect discovery document.

OpenID Connect only. There is no SAML and no SCIM provisioning, and floGPT does not map IdP groups to floGPT roles — every account provisioned by a sign-in gets the one role you pick below. If your security review asks for SAML or SCIM, the answer is still no.

Registering floGPT at your provider

Create an OpenID Connect web application with the authorization-code flow, then fill in four fields:

FieldWhere it comes from
Provider nameYours to choose. Shown to your team on the sign-in screen.
Issuer URLYour provider's issuer, e.g. https://acme.okta.com/oauth2/default. Paste the issuer itself, not the /.well-known/openid-configuration URL.
Client IDFrom the application you just registered.
Client secretFrom the same place. Leave blank for a public client using PKCE only.

Copy the Redirect URI shown in the panel into your provider's sign-in redirect URIs before enabling. floGPT requests the openid, email, and profile scopes.

Test connection fetches the discovery document and reports what it found — an issuer that comes back with a different value than you typed is the usual mistake, and it is fatal because ID tokens are checked against the issuer byte for byte. If your provider publishes no userinfo endpoint it must send the email claim in the ID token itself, and the test says so.

Role for new accounts is Viewer, Agent, Supervisor, or Editor. Owner and admin are deliberately unavailable — a federated sign-in must not be able to arrive holding administrative rights, so promoting somebody stays a manual act inside floGPT.

Sharing the login link

Once enabled, the panel shows a Login link specific to this workspace. Send it to your team, or point them at Sign in with SSO on the login page, where they paste the same link.

floGPT does not route by email domain. Your people reach their workspace by its link, not by typing an @acme.com address into a form that then guesses.

What a first sign-in does

A first-time user gets a floGPT account in this workspace at the role above. An account that already exists under the same email address is linked rather than duplicated. A sign-in never creates a workspace, so someone whose provider account has no floGPT workspace to join is turned away rather than onboarded.

Accounts created this way have no password. Their holder can still set one through Forgot your password? against their own verified address.

Require single sign-on

Members of this organization will not be able to sign in with an email and password.

The tick box stays disabled until a sign-in has actually succeeded through the connection. Until then a wrong issuer or a stale secret would lock out everyone but you, and that is not something support can fix from outside.

Three rules are worth knowing before you turn it on:

  • The workspace owner always keeps password access. This is deliberate — a provider outage would otherwise be unrecoverable. Every such sign-in is recorded in the SSO audit trail.
  • A member of several workspaces must use SSO if any one of them requires it. A floGPT session is not scoped to a single workspace, so a password sign-in would reach the strict workspace too. Being a member of a relaxed workspace does not buy anyone a password.
  • Owning a workspace elsewhere is not a way around it. The owner exception applies only to someone who owns every workspace that requires SSO of them.

A refused sign-in tells the user which workspace is asking, which provider to use, and the link to use — they do not have to go and ask.

Removing the connection deletes the stored client secret and drops enforcement with it, so a workspace can never be left requiring a provider it no longer has.

There is no session or idle-timeout policy. Sessions last 7 days and there is nothing to configure.

API Keys#

Setup → API Keys.

Owner or admin. Others see Only organization owners and admins can manage API keys. An owner can also close it to admins via Member permissions, in which case they see The owner has removed your access to this organization's API keys. Revoking only Create and revoke API keys leaves the list and its logs readable without the Create key, Edit scopes, and Revoke controls.

Create org-scoped keys for the REST API at /api/v1. Edit scopes anytime without rotating the secret. An API documentation button links to the API reference.

Creating and managing a key

Create key asks for a Name and at least one ScopeName and at least one scope are required.

The dialog then flips to Save your API key with Copy this key now. It will not be shown again. Afterwards the list shows only a masked prefix…last4.

ActionBehaviour
Edit scopesChanging scopes takes effect immediately for subsequent requests. The secret itself is unchanged.
RevokeRevoke this API key? This cannot be undone.

There is no rotation. To replace a key you revoke and create a new one, which means a brief overlap has to be managed on your side — create the new key first, migrate, then revoke the old one.

Each row shows the name, masked key, scopes, and Last used, which is the quickest way to find a key nothing is calling any more.

Scopes

Read and write are separate, per area: Chat widgets, Call widgets, Knowledge bases, CRM, Conversations, Call logs (write is manual reinitiate only), Analytics (read only), Meta Lead Ads integrations, Outbound triggers, Data collections, and Email integrations.

Grant read where you only need read. Scopes are editable later, so starting narrow costs nothing.

Usage and logs

API usage & logsRolling 30-day summary, errors, and recent request logs, with Refresh.

Metrics: Requests, Successful, Errors, Rate limited, Last 24 hours, Avg. latency.

Log table: Time, Key, Request, Client IP, Status, Duration, filterable to All logs or Errors only and by key. Empty: No API errors recorded for this filter. / No API requests recorded yet.

Using a key from an AI coding agent or the terminal

mcp/flogpt-mcp/ in the repository ships two front ends over the same API:

  • An MCP server, so Claude Code, Cursor, Codex and other MCP clients can operate the workspace directly. The client spawns it locally and talks over pipes, so nothing listens on a port and the key never leaves your machine.
  • A CLI (flogpt), with the same commands, so you can reproduce by hand whatever an agent just did.
export FLOGPT_API_KEY=fg_live_...
flogpt whoami
flogpt call-logs --status failed --limit 20 --table

Scope the key to what the agent should be allowed to do — the scopes you tick here are exactly the ceiling on what it can reach. A refused request names the missing scope rather than failing vaguely.

About seventeen commands cover the endpoints an agent actually reaches for; flogpt request handles everything else. See mcp/flogpt-mcp/README.md.

Usage History#

Setup → Usage History.

Anyone with an organization. Subscription Usage HistoryBilling period breakdown of token and message consumption.

Summary cards: Latest Period, LLM Tokens Used, Messages Sent.

Table: Billing Period, LLM Tokens, Messages, Last Updated, Invoice. The active period is badged Current, and the invoice column offers Download PDF where an invoice exists.

This page shows consumption, not limits. For usage against your plan's allowances, use the Usage Statistics panel on Subscription.

Empty: No usage history yetUsage data will appear here once your subscription is active.

Subscription#

Subscription, with Usage Statistics.

Hidden from agents and supervisors.

Current plan

Current Plan with a status pill (active, trialing, past_due, canceled), a Billed via Shopify pill where applicable, and Annual billing / Monthly billing.

Details: Period Start, Period End, Next Billing. Trial ends on {date} appears while a trial is running, and Subscription will cancel on {date} after you cancel.

Choosing a plan

Choose Your PlanSelect the plan that fits your needs. A currency toggle (USD, INR, EUR, subject to the lock described above) and a Monthly / Yearly switch sit above the grid.

Plan cards show the price, a Save X% pill on annual, the feature list with each limit (or Unlimited), and pills for Most Popular and Current Plan. Plans and their limits are defined by the platform, so what you see depends on your billing currency.

Upgrading or downgrading means picking another card and completing the payment dialog; proration is handled for you. Cancelling is at period end — You'll continue to have access until the end of your billing period. This action can be reversed by resubscribing.

Some plans carry a one-time setup fee (Chat setup, Call setup), shown in the payment dialog and skipped if already paid.

Usage Statistics

Your consumption against the active plan's limits. Bars for LLM Tokens, Messages, Chat Widgets, Workflows, Knowledge Bases, and Data Collections, each showing used against limit, or Unlimited.

This is the panel to check before a launch. Hitting a widget or workflow limit fails at creation time, which is a bad thing to discover mid-campaign.

Shopify billing

If FloGPT was installed through Shopify, this page replaces the plan grid, billing portal, and card dialog with Billing is managed in Shopify and buttons for Open Shopify Billing and Open Shopify Admin.

Your plan and your metered add-ons — phone numbers, call minutes, SMS — are charged on your Shopify invoice. Saved cards under Payment Methods play no part. See FloGPT for Shopify.

INR subscriptions are completed through Razorpay rather than the inline card form: You'll be redirected to Razorpay to securely complete your INR subscription.

Payment Methods#

Manage cards saved to your organization. Add Card opens New card details.

Cards list with brand, last four digits, expiry, and a Default badge, with actions to set default or remove.

Deleting a card is blocked while a subscription is activeCannot delete a payment method while an active subscription exists, with the note Card deletion is disabled while an active subscription is running. Cancel first, or add a replacement and make it default.

Shopify-billed organizations see Billed through Shopify — no card needed here.

Referrals#

Referrals → My Referral Links.

Hidden from agents and supervisors. Two tabs.

Stat cards: Total Clicks, Signups, Conversions, Total Earnings, Pending Payout.

Generate Link opens Generate Referral Link:

FieldNotes
Custom Code (optional)3–20 characters, letters, numbers, hyphens, underscores. Blank auto-generates
Label (optional)A label helps you track which campaign this link belongs to

The result is a link of the form /signup?ref={code}. The table lists Label / Code, Clicks, Signups, Conversions, Earnings, Status, Actions, with copy, pause or activate, and delete per row.

Generate a separate link per channel and label it. There is no other way to attribute where a signup came from.

Payouts

Stripe Connect handles payout onboarding. Statuses are Stripe Account Connected, Verification Pending, Account Restricted, and No Account Connected, with Connect Stripe Account, Complete on Stripe, Refresh Status, and Resolve in Stripe Dashboard as appropriate.

The Referral Earnings tab lists Converted Referrals with Referee, Link, Status, Earned, Converted, and an expandable Payout History per row showing Amount, Status, Transfer ID, Requested, Paid, with a rejection reason where one applies.

Two honest caveats. The commission rate is set by the platform, not shown or chosen here — you see the resulting earnings only. And although the onboarding copy mentions requesting a payout from the Earnings tab, there is no self-service request button: payouts are initiated and approved by the FloGPT team, and this tab is read-only. Contact your account manager to chase one.

Troubleshooting#

SymptomUsual cause
Organization, Reports, or Escalation missingThose three are owner-only — an admin cannot see them
Cannot find where to invite peopleTeam management is in the Users section — the Admins / Agents / Supervisors pages, not here
Scheduled report arrives at the wrong hourTimezone on the Organization page is wrong
Reports enabled but nothing arrivesRecipients are chosen by role — check a role is ticked and has members
No monthly insights emailScheduled reports are disabled for the organization
Support requests sit pending overnightExpected with Business Hours Restriction on — they wait for the next window
Business hours on but nobody ever picks upThe schedule has no slots; an empty schedule blocks every hour
PII still visible in stored transcriptsRedaction governs AI, dashboard, and trigger matching; raw transcripts persist until retention expires
Cannot change billing currencyLocked by an active subscription, or fixed by the platform
Cannot delete a cardBlocked while a subscription is active
Lost the API keyIt is shown once only; revoke it and create a new one
API returns 403 after a scope changeScopes apply to subsequent requests only; check the right scope is ticked
Cannot enforce org-wide 2FAEnable 2FA on your own account first
Looking for SSO or session timeoutNeither exists
Alert preferences say no WhatsApp accountConnect WhatsApp Business under Integrations → Meta Messaging
Plan grid missing, Shopify notice insteadThe workspace is billed through Shopify
No payout request buttonPayouts are team-initiated; the tab is read-only