Skip to main content

Development trial ยท sample information only

Configure security, data and AI settings

What you'll achieve

You will review organisation-wide security, retention, backup, privacy and AI settings, make only approved changes and verify the resulting control state.

Who this is for

This guide is for an Organisation Administrator with the permission or assigned action described below. If the navigation or action is missing, check the selected organisation, effective account level, feature state and role before assuming the product is unavailable.

Before you start

Check that you have:

  • A documented security, privacy or AI decision.
  • Technical owners for identity, network ranges and data recovery.
  • Retention and deletion requirements.
  • Approved AI mode, provider route and data-handling conditions.

1. Review security controls

Open Settings > Organisation > Security. In Authentication & Session Management, review Require 2FA for all users, Session Timeout (minutes) and Maximum Concurrent Sessions. Review enabled social sign-in providers and the organisation login URL. Use Save Security Settings for the authentication and session changes, then reload the page.

2. Change network access cautiously

Add an IP range only after validating it with the network owner. Keep a tested recovery route; a wrong range can lock out legitimate users. Remove obsolete ranges promptly but with change evidence.

3. Review data settings

Open Data. Review retention periods and document-version retention, export format and compression, then privacy preferences. Choose Save Data Settings and reload to check the saved values. These are configuration settings: a saved value alone does not demonstrate that a retention job, export anonymisation or encryption control has run. Confirm operational enforcement with the platform owner before relying on it.

4. Arrange a backup through the operational route

The reviewed development build's Trigger Manual Backup Now button displays an acknowledgement but does not start a backup operation. Do not use it to evidence a completed backup. Ask platform operations for the approved backup and restore route.

5. Configure AI mode and provider

Open AI. Choose Disabled, Bring Your Own Key or Platform Credits. Bring Your Own Key requires the approved provider connection; Platform Credits uses the organisation credit pool. Review Advisory Report AI separately, then the AI Features switches. Select Save AI Settings, reload, and check that the selected routes persist. Keep provider keys out of screenshots and support messages.

6. Verify after saving

Reload each page, confirm the saved state, and run an agreed low-risk validation. For security changes, ask an unaffected administrator to confirm access before closing the change.

Check it worked

  • Security settings reload exactly as approved.
  • Retention and backup settings have an accountable owner.
  • The chosen AI route matches the organisation's approved data boundary.
  • A recovery path remains available after any access-control change.

If something goes wrong

What you see What to do
A security change could lock everyone out Stop and arrange a tested second-admin or support recovery route before saving.
An AI provider test fails Keep the previous approved route, verify credentials and endpoint configuration through a private channel.
A retention value is unclear Do not guess. Ask the privacy, legal or records owner.
A backup action succeeds but evidence is missing Keep the change open until operational evidence is recorded.

Human judgement, security and privacy

These settings express organisational policy. Backstory can enforce or record a choice, but it cannot decide the lawful retention period, acceptable AI use or correct identity boundary for you.

What's next

Schedule periodic reviews with security, privacy and AI owners and repeat a recovery check after material changes.

Need help?

Use your organisation's approved Backstory support route. Include the organisation, page and action that failed, but do not include passwords, invitation links, secret keys or unnecessary personal or confidential content.

Was this article helpful?