Skip to main content
Your workspace is the isolated tenant that holds everything Clarion knows about your security stack — issues, agents, skills, monitors, integrations, and members. Settings → Workspace is where you configure the things that apply to every agent in it.
Changes here are workspace-wide and take effect on the next agent run. Editing them requires the Edit workspace settings permission — see Roles & permissions.
Agent behavior (formerly workspace instructions), the read-only system prompt, severities that escalate, and skills live under Settings → Agents.

Domains

Your company’s top-level domains. Detections use them to tell internal from external: an account outside these domains reporting agent telemetry, a login from a non-company identity, an email-auth change on a domain you own. Subdomains count as internal automatically — list only the top-level domains (example.com, not mail.example.com). An agent can also propose domains it discovered during investigations for you to confirm.

Human input and messaging

These settings decide what happens to an agent’s approval and clarification requests, and how far its Teams messages can reach. Which severities page your team is set in Severities that escalate.

Deny unanswered tool approvals

Decides what happens when nobody answers an agent’s request to run a gated tool. Tools set to auto-decide in Settings → Tools are unaffected: they are judged individually rather than denied outright.

Anyone can respond to human input

Controls who may answer an agent’s approval and clarification requests. Either way, the audit log records who unblocked the agent.
With this on, Microsoft Teams responders need the Clarion app installed for everyone in your tenant. Otherwise Teams blocks the card buttons before the response ever reaches Clarion.

AI provider credentials

Available when your workspace is enabled for bring-your-own-key (BYOK). Paste an Anthropic or OpenAI API key and Clarion infers the provider from the key prefix. A workspace with its own usable key runs only on that key: no cross-subsidy, and no tenant data through Clarion’s provider account. See Models & runtime for how that interacts with tiers and failover.

Elsewhere in Settings

Members

Invite teammates and set how Clarion reaches them.

Roles & permissions

The role × permission matrix Clarion enforces.

Agents

System prompt, agent behavior, severities that escalate, and skills.

Models

Model tiers, failover, and your own providers.

SSO

Enforce single sign-on through Microsoft Entra ID.

MCP access

Connect Claude Code, Cursor, or scripts to the workspace.

General

Settings → General holds the workspace-level actions you rarely need:
  • Demo data — load or clear a sample dataset for evaluating Clarion.
  • Health checks — run Clarion’s own integration and monitor health checks on demand.
  • Delete workspace — permanent, and removes every issue, agent, and integration in it.