Settings — Account Configuration & Security
ES Reference: Phase 0 (INTOS-ES-P0-001) Account & Security · Phase 4 (INTOS-ES-P4-001) Tenancy & Permissions, Section 4
Overview
The Settings area centralizes your account preferences, security configuration, notification settings, privacy controls, workspace management, and integration connections. Phase 4 adds tenancy management, granular permission controls, SSO readiness, and workspace switching configuration.
Key Principles
- Individual ownership is always visible — you can always see what's yours vs. what's shared
- Workspace context is clear — personal and organization settings are visually and functionally distinct
- Privacy controls are granular — you choose defaults, not the platform
- Security events are transparent — all account activity is logged and reviewable
Screens in This Feature Area
1. Settings Home (/settings)
Main settings dashboard with categorized sections.
Buttons & Actions:
| Button | Behavior |
|---|---|
| Save | Persist settings changes per section |
| Reset | Revert to default settings for a section |
Settings Categories:
| Category | What's Configured |
|---|---|
| Account | Email, display name, account type, connected accounts |
| Workspace | Active workspace, workspace switching defaults, organization membership (Phase 4) |
| Security | Password, MFA, active sessions, login activity |
| Notifications | Email and in-app notification preferences per category |
| Privacy & Sharing | Data sharing defaults, coach access defaults, analytics opt-out, search visibility |
| Appearance | Theme preference (light/dark/system), accessibility preferences |
| AI Preferences | Model preferences, generation defaults, language/style preferences |
| Integrations | Calendar, LinkedIn, webhook configuration, API access (Phase 4) |
| Data Management | Data export, account deletion, retention preferences |
2. Security & Activity (/settings/security/activity)
Account security configuration and login activity monitoring.
Security Settings:
| Setting | Description |
|---|---|
| Change Password | Update your account password |
| Enable MFA | Set up multi-factor authentication (TOTP or security key) |
| Recovery Codes | Generate/view backup recovery codes |
| Trusted Devices | Manage devices that bypass MFA |
Activity Monitoring:
| Section | Description |
|---|---|
| Active Sessions | See all currently logged-in devices/locations |
| Login History | Recent login attempts (successful and failed) with location and device |
| Account Changes | Password changes, email changes, MFA changes |
| Connected Apps | Third-party applications with account access |
| Data Exports | History of data export requests |
| Security Events | Suspicious activity alerts |
Buttons & Actions:
| Button | Behavior |
|---|---|
| Revoke Session | Sign out a specific device |
| Revoke All Other Sessions | Sign out everywhere except current device |
| Download Activity Log | Export full account activity history |
| Report Suspicious Activity | Flag unrecognized events for security review |
3. Privacy & Sharing Controls
Granular control over data sharing defaults and visibility.
| Setting | Options | Description |
|---|---|---|
| Default Evidence Sharing | Private / Shareable with coach / Shareable with org | Default visibility for new evidence items |
| Default Story Sharing | Private / Shareable with coach / Shareable with org | Default visibility for new stories |
| Default Kit Sharing | Private / Shareable with coach | Default visibility for new kits |
| Practice Data Sharing | Never / Ask each time / Per-session consent | Whether practice data can be shared |
| Offer Data | Always private | Offers are never shareable by default |
| Analytics Opt-out | On / Off | Disable product usage analytics collection |
| Search Visibility | Not searchable / Searchable by email | Whether other users can find you by email |
| Aggregate Learning Consent | Opt in / Opt out | Whether your anonymized data contributes to learning models |
| Data Retention | Default / Custom | Override default data retention periods |
4. Tenancy & Workspace Management (Phase 4)
Manage your personal workspace, organization memberships, and workspace switching.
Workspace Settings:
| Setting | Description |
|---|---|
| Default Workspace | Which workspace opens on login (personal or specific org) |
| Workspace List | All workspaces you belong to with roles |
| Leave Organization | Exit an organization workspace (preserves personal data) |
| Workspace Notifications | Per-workspace notification preferences |
Buttons & Actions:
| Button | Behavior |
|---|---|
| Switch Workspace | Change active workspace context |
| Set Default | Choose default workspace for login |
| View Organization Policies | See what data an organization can access |
| Leave Organization | Exit with clear explanation of what happens to your data |
5. Access Grants Management
View and manage all access grants you've made (coaches, advisors, institutions).
Buttons & Actions:
| Button | Behavior |
|---|---|
| View Active Grants | All currently active access grants |
| View Grant Detail | Scope, permissions, expiry, and purpose of each grant |
| Modify Grant | Change scope or permissions |
| Revoke Grant | Immediately terminate access |
| View Grant History | Expired and revoked grants with audit trail |
6. Notification Preferences
Control which notifications you receive and how.
| Category | Channels |
|---|---|
| Interview Preparation | Email, In-app |
| Application Updates | Email, In-app |
| Coach Activity | Email, In-app |
| NBA Recommendations | In-app only |
| Product Updates | |
| Billing & Account | Email (mandatory) |
| Practice Reminders | Email, In-app |
7. Integrations (Phase 4)
Manage external service connections.
| Integration | What It Does |
|---|---|
| Calendar | Connect Google/Outlook calendar for interview scheduling (explicit narrow consent) |
| Import profile data (optional, user-initiated) | |
| API Keys | Manage personal API keys for custom integrations |
| Webhooks | Configure outbound webhooks for your account |
Integration Principles:
- All integrations require explicit, narrow consent
- Calendar integration only for interview/reminder workflows
- API access is default-deny; scopes must be explicitly granted
- Integration access can be revoked instantly
8. Data Management
Export, retention, and deletion controls.
Buttons & Actions:
| Button | Behavior |
|---|---|
| Request Data Export | Generate complete export of your data (all categories, configurable) |
| Download Export | Download a completed export (link expires) |
| Delete Account | Permanently delete your account and all data (with dependency validation and cooling-off period) |
| Configure Retention | Set per-category retention preferences |
| View Data Inventory | See what data categories you have and their volume |
9. SSO & Account Linking (Phase 4 readiness)
Configure enterprise single sign-on and account connections.
SSO Settings (organization-managed):
- Domain mapping for organizational SSO
- Linked identity providers
- Account linking rules (prevent SSO takeover via email/domain collision)
Workspace Visual Distinction
When in an organization workspace:
- Visual indicator in sidebar header, mobile nav, and settings showing active workspace
- Settings are scoped — personal settings vs. organization-managed settings are clearly separated
- Organization-managed settings are labeled with the managing organization
Related ES Requirements
| ID | Requirement |
|---|---|
| P0 Settings | Account, security, notifications, privacy controls |
| P4-E01 | Individual, coach, and institutional contexts with scoped grants |
| P4 Tenancy | Personal workspace context; unchanged access for existing users |
| P4 SSO | Domain mapping, invitation policy, safe account linking; prevent email/domain collision |
Related Docs
- [[profile]] — Your candidate profile is a separate section from account settings
- [[billing]] — Billing and subscription management is a separate section
- [[admin]] — Platform-level admin operations (separate from personal settings)
- [[organization]] — Organization-level policies and workspace management
- [[legal]] — Terms, privacy policy, and legal documents
- [[coach]] — Coach access grants are managed here and in the Coach workspace