Skip to content

Settings

Settings is the admin screen for deployment-wide platform configuration.

Only admins can load or save settings.

The Licensing section shows the active release channel, edition, license state, product limits, current usage, support tier, term end, and enabled licensed features.

Roster can run as:

EditionSummary
FreeNo license key required. Limited to 20 resolvable humans and 5 active human team members. Model Runs are available; Audit Events and PostgreSQL database support are not.
ProRequires a valid license key. Uses the purchased resolvable-human cap. Model Runs are available; Audit Events and PostgreSQL database support are not.
EnterpriseRequires a valid license key. Uses the negotiated resolvable-human cap as an exact limit. Model Runs, Audit Events, and PostgreSQL database support are available.

AI agents and service accounts do not count toward the Free active human team-member limit.

Admins see warnings in Settings when a paid license is near expiration, in its grace period, no longer active, or when usage is above the active edition’s included cap. Roster continues to operate while over the included cap, but writes that would add more resolvable humans or active human team members are blocked at the applicable write limit.

Settings supports two sign-in access methods:

MethodBehavior
Any authenticated userAny valid Roster Auth or configured identity-provider user can sign in and receive an identity profile.
Only invited team membersUsers must already exist as team members before sign-in is allowed.

If your organization provisions team members through an upstream SCIM process, manage those users as invited team members inside Roster and document the upstream provisioning source separately.

Admins can also disable username/password login after identity-provider login is ready. Roster allows this only when at least one active admin can already sign in through an enabled identity provider. If a deployment is accidentally locked out, run the database recovery script from the deployment environment, then restart Roster if the server was already running:

Terminal window
node /app/packages/db/scripts/enable-password-login.mjs

Invite email delivery is optional and applies to IDP-only team member invites.

Supported providers:

  • SMTP
  • Resend

Common fields include from email, from name, reply-to email, provider, and provider-specific secret material. Secrets are retained by leaving the secret field blank and can be cleared from the UI.

The Agents section configures the resolver agent:

  • Provider
  • Model
  • Reasoning effort
  • Max tokens
  • Input cost per million tokens
  • Cached input cost per million tokens
  • Output cost per million tokens
  • API type: Responses or Chat Completions
  • URL

Deployment secrets and provider defaults are still managed outside this screen. See Model Providers for provider credentials and supported provider families.

Rate limiting can be enabled or disabled globally. Each rule has its own enabled state, limit, and window in seconds.

Default rules are:

RuleDefault limitDefault window
HTTP requests by IP30060 seconds
Authenticated REST and MCP actor12060 seconds
Resolve LLM calls203,600 seconds

HTTP IP rate limits skip static asset paths. REST and MCP actor limits use API token IDs, OAuth identities, or identity IDs. Resolve LLM limits use the API token, OAuth principal, identity, client IP, or unknown fallback.

Rate-limited clients receive HTTP 429 with Retry-After, X-RateLimit-Limit, X-RateLimit-Remaining, and X-RateLimit-Reset headers.

Retention settings accept positive integers in days or no limit:

  • Resolve requests
  • Audit events
  • Model runs

Roster automatically enforces finite model-run retention when the platform starts and then hourly. Expired model runs and their tool-call records are permanently removed.

Worker journal retention is configured in the PII section under Worker journals.

PII settings control which fields are retained or shown in:

  • Audit events: IP address, user agent, personal-looking metadata fields
  • Model runs: actor name, actor email, input/output, tool payloads, error details. Disabling tool payloads also removes function-call data embedded in new stored model output.
  • Resolve requests: actor name, actor email, actor credential details, query text
  • Resolve result fields: user ID, display name, email, title, labels, metadata, memberships, delegation details, participant names, project IDs
  • Operational logs: error details, model developer notes, connector identifiers
  • Worker journals: retention days

For principles and erasure workflow guidance, see Privacy and Data Retention.

The About panel shows deployment version information and links to third-party notices for open-source license review.