Workspace & account settings
Manage invitation domains and future payload collection, and confirm your current account identity.
On this page
Workspace settings define your organization's identity and collection preferences. Account settings show your current user identity and role. These screens serve different purposes from the CLI's device enrollment.
Edit workspace identity
Open Workspace → Identity & data collection. Owners and administrators can edit the workspace name and settings. The name accepts 2–60 characters. Other members with workspace-read access see the configuration without editing controls.
The page displays the workspace ID and creation date. Use the ID, rather than a mutable display name, when coordinating operator-managed connections such as MDM.
Restrict invitation domains
Enter allowed domains as a comma-separated list, for example company.com, subsidiary.com. Leave the field empty to allow any domain.
Changing the list does not remove existing members. Pending invitations outside a newly tightened restriction are revoked. Review both existing membership and pending invitations when changing the organization's access boundary.
Choose payload collection
Store full event payloads controls future workspace ingestion. Summaries and findings are still collected when it is disabled. The preference does not delete previously stored payloads or clear the device's local history.
Coordinate collection preferences with your organization's data handling requirements. Recognized-secret redaction is useful but cannot classify every confidential sentence or code fragment. Review exports before sharing them.
Check account identity
Open Account to see the account ID, name, email, and current workspace role. Use Sign out to end the browser session. This screen does not provide a full profile-editing, MFA, or enterprise SSO management flow.
Browser sign-out does not disconnect every enrolled CLI device. Use beam whoami and beam account on the machine, and the Agents page in the workspace, to verify device identity separately.
Verify a change
After saving a workspace setting, reopen the page and check the administrative audit log. Test an invitation with the intended domain boundary or inspect a newly ingested record to verify future collection behavior. Historical records should not be assumed to change retroactively.