Skip to main content

Overview

Settings combines personal account controls with organization and platform administration. The navigation items you see depend on your role, organization, permissions, and enabled platform capabilities.

Account settings

Profile

Manage your name, avatar, password, and multi-factor authentication.

Organizations

Configure organizational structure, governance, and administrators.

Teams

Manage teams, classification, membership, escalation, and shared notification channels.

Members

Review users and administer invitations, roles, and team assignments.

Notifications

Review your inbox and configure personal notification preferences.

API Keys

Create scoped credentials and manage their operational lifecycle.

Platform settings

Integrations

Connect CaseBender with security, collaboration, and infrastructure services.

Workflows

Build automated workflows for security operations.

AI

Configure supported AI capabilities and providers.

Custom Fields

Define structured fields for supported entities.

Observable Types

Manage the observable types used during investigations.

Attack Patterns

Maintain MITRE ATT&CK-aligned attack-pattern data.

Alert Statuses

Configure the statuses used throughout the alert lifecycle.

Case Statuses

Configure the statuses used throughout the case lifecycle.

Templates

Create reusable structures for supported records.

Branding

Customize the visual identity of your CaseBender instance.

Access control

  • Personal settings are available to authenticated users.
  • Organization and team management require scoped administrative permissions.
  • Sensitive operations can require step-up authentication.
  • Read-only roles can inspect permitted settings without changing them.
  • Server-side authorization remains authoritative even when the interface hides an action.
See Access Control for the role and permission model.

Change-management recommendations

  1. Use least privilege. Grant only the permissions required for each administrator and integration.
  2. Test safely. Validate workflow, integration, notification, and governance changes outside production when possible.
  3. Document ownership. Record who owns each organization, team, integration, and API credential.
  4. Review regularly. Audit memberships, elevated roles, credentials, notification destinations, and retention settings.
  5. Plan rollback. Understand how to reverse a configuration change before applying it to production.
Settings can affect access, data handling, automation, and incident delivery. Coordinate high-impact changes with the relevant security, privacy, legal, and platform owners.