Settings

14 articles

The Settings area in Flowtly is where administrators configure the core behavior of the platform to match their organization's requirements. It covers a wide range of options, from basic organization profile details to advanced security and integration settings.

Organization settings include company information, default currency, fiscal year configuration, and localization preferences. These foundational settings influence how data is displayed and processed throughout the entire platform, so it is important to configure them correctly during initial setup.

Security and authentication settings allow administrators to enforce single sign-on (SSO) through Google Workspace or Microsoft (Entra ID / Teams) — no other SAML/OIDC provider is currently supported. While an organization enforces SSO, its members cannot reset or set a password in Flowtly and sign in only through the organization's identity provider. The Security settings page itself carries the organization-wide controls over how people sign in and what is recorded about it — see Security settings. There are no password-policy or session-timeout settings. When MFA enforcement is on, a member who has not set up an authenticator yet is taken through setup on the sign-in screen — scan the code, enter the six digits, save the recovery codes — and is signed in straight after. Turning enforcement on therefore locks nobody out, and nobody has to ask an administrator to get started.

Widget configuration lets administrators customize the dashboard experience organization-wide by turning individual summary panels, charts, and quick-access links on or off for the home screen (this applies to all users, not per role). Administrators also set the organisation's default widget order there: a short list of the widgets that lead, with everything else keeping the product's own order underneath. It applies to anyone who has never rearranged their own home screen — once someone rearranges theirs, theirs wins, and they can return to the organisation's order at any time. On a phone, rearranging happens through the home screen's Arrange option, using move-up and move-down controls. A card there, Unavailable team members: which absences count, decides which absence types the dashboard's Unavailable team members widget lists: a ticked type appears, an unticked one does not. Every type the organisation has is listed, including ones it created itself, and a type added later starts ticked. By default everything except remote work is ticked, which is what the widget always showed — untick a type such as business travel when people on it are still working and reachable. The card appears when the Holidays module is on, and it applies to everyone in the organisation. Invoicing configuration covers default payment terms, numbering schemes, tax settings, and templates that apply to all invoices generated within the platform.

Settings shows only the tabs that hold at least one page your role can open. A tab with nothing in it for you is left out, and following a link to a hidden tab opens the first tab you can use.

Organization settings

Under Settings → Organization you configure the foundations of your workspace:

People settings

Under Settings → People you manage HR-related configuration:

Advanced settings

Under Settings → Advanced you'll find organization-wide options for power users:

  • Billing rates — default attribute prices used in billing
  • Asset settings — enable utility meters and other asset behavior
  • List columns — choose extra columns shown on project, asset, and budget lists

Security settings

  • Security settings — the organization-wide controls on the Security page, including how much of a sign-in IP address is stored
  • Multi-factor authentication — a second factor at sign-in, recovery codes, trusted devices, and the organization-wide requirement

Example use cases

  • Configure SSO integration with Google Workspace or Microsoft to streamline employee access.
  • Set the organization's default currency and fiscal year start date during initial platform setup.
  • Turn dashboard widgets on or off organization-wide to declutter the home screen.
  • Put the widgets your organization cares about first, so a new member's home screen opens on what matters rather than on the default order.
  • Stop listing people on business travel as unavailable on the dashboard, when they are still working and reachable.
  • Define default invoicing templates, payment terms, and numbering sequences for consistent billing.
  • Enforce MFA organization-wide to meet your organization's security standards — members who have not set up an authenticator are taken through setup the next time they sign in.

Connection map

Refers toPart ofFulfils
Documented hereDocumented elsewhere
audit-log records person. setting defines attribute. org-document access governed by setting. subscription gates setting. setting requires second-factor. second-factor held by person. recovery-code stands in for second-factor. trusted-device waives second-factor.recordsdefinesaccess governed bygatesrequiresheld bystands in forwaivesAAudit trail — The record of who did what and when. It is how a user action is investigated after the fact, and what compliance is demonstrated from.Audit trailPPerson — An employee. The central record the rest of the workforce data hangs off — profile, documents, leave, benefits, rates.PersonSSetting — Platform-wide configuration — behaviours, permissions, security.SettingAAttribute — A custom data field defined once and collected across the platform, so an organisation can record what Flowtly does not ship a field for.AttributeDDocument — An organisational file, stored with control over who can reach it.DocumentSSubscription — The plan the organisation is on, and what it is billed for.SubscriptionSSecond factor — The extra proof of identity asked for at sign-in on top of the password — a six-digit code from an authenticator app, changing every 30 seconds.Second factorRRecovery code — One of ten single-use codes issued when an authenticator is confirmed. Each stands in for a code from the app once, for the day the phone is gone.Recovery codeTTrusted device — A browser a person has chosen to trust, which is not asked for a second factor again for 30 days. Per browser, not per person.Trusted device

Related terms