Configuration
This page covers the tenant-level settings that an admin or owner manages — what they configure, where, and how the configuration interacts with the rest of TensorCost.RBAC and members
TensorCost ships three built-in roles. Custom roles are on the roadmap; today the three cover most needs.
Manage members under Settings → Members. SSO (SAML / OIDC) is configured per tenant under Settings → SSO and short-circuits the password flow.
Role gating in the UI and API
Both the shell and the gateway check the same@tensorcost/rbac primitive. A member who hits an admin-only REST route gets 403; the same user’s MFs hide the navigation entries they cannot use. RBAC is also enforced in the MCP server — every tool call is scope-checked at dispatch.
Tag mapping
TensorCost attribution depends on mapping your existing AWS / Azure / GCP cost-allocation tags to four canonical dimensions:
Configure under Settings → Tag mapping. Drag-and-drop UI; the mapping applies to GPU agent metrics, Bedrock CUR rows, Azure OpenAI billing exports, Vertex billing, OpenAI / Anthropic API metadata, and any future managed-inference adapters.
If a tag is missing on a row, the row rolls up under
untagged. The savings methodology PDF (linked from the dashboard) explains how untagged is allocated when you set a “default owner” rule.
Budgets and burn-rate alerts
Budgets are hierarchical:burn-rate-alerts-enabled flag.
Notification channels
Alerts and policy events deliver through pluggable channels. Configure under Settings → Notification channels.Per-channel filtering
Test button
Every channel has Test that delivers a sample notification through the same code path as a real alert — including the signature header for webhooks.Alert rules
Define monitoring thresholds under Alerts → Rules. Field reference:Enforcement policies
Automated remediation rules. Three execution modes — start in Notify only and graduate.Templates
Pre-built policies you can clone:Composite conditions
active_hours, active_days, timezone) and maintenance-window suppression apply.
Maintenance windows
Schedule periods where alerts and enforcement are suppressed. Useful for deploys, reboots, and known-noisy events.Branding and custom domain
Settings → Customization → Branding.
Custom domain — set under Customization → Domain. Provide your CNAME target, point DNS at it, wait for propagation; ACM provisions SSL automatically.
Data retention
Data older than the configured window is archived and deleted nightly. Tenant offboarding follows a 30-day soft-delete window before hard delete; audit-trail rows are preserved per the SOC 2 readiness guide.
Cloud-account configuration
AWS
We use STS AssumeRole with external ID. The CFN onboarding stack creates the role; you paste the ARN back into the wizard. Temp credentials are 15-minute, never persisted. In Organization mode, the same role assumesOrganizationAccountAccessRole (or AWSControlTowerExecution if that’s what your Landing Zone provisioned) into each member account on demand. SCP-aware: configurable role-path prefix for OUs that restrict IAM creates.
Azure
Service principal with Reader + Cost Management Reader. UseDefaultAzureCredential for local testing; in production, prefer Managed Identity on the agent host.
GCP
Service account with Compute Viewer + BigQuery Data Viewer (for billing export). Application Default Credentials are honored.Managed-inference providers
All provider credentials are stored encrypted with a per-tenant KMS-derived key in
integration.connection_secret (RLS-enforced). Rotation is supported via POST /v1/integration/connections/:id/rotate-secret.
Feature flags surface
Tenant-visible feature flags appear under Settings → Feature flags for admins. The full pattern — LaunchDarkly +useFeature() + the quarterly stale-flag cleanup ritual — is documented in feature flags.
Audit trail
Every config change writes to the cross-tenant audit ledger:- Who (user ID + email)
- What (resource + before/after diff)
- When (UTC timestamp)
- Where (IP, user agent)
- Why (free-text reason for high-severity changes)
GET /v1/identity/audit?format=csv.