Skip to main content
Settings holds your organization’s configuration. Five tabs, each carried in the URL as ?tab=.

What’s on the page

Tabs

Provider API Keys

The model providers you bring your own keys for, so Unbound can reach them on your behalf. Separate from the key a developer uses to connect a coding tool, which is on Configure.

Devices

Import Devices brings in a list of machines in one step, such as an export from your MDM. The file is CSV or Excel (.csv, .xlsx, .xls), up to 10 MB, dropped on the dialog or browsed for. Header names are matched loosely — capitalization, spaces and dashes make no difference, so Serial Number, serial-number and serial_number all work. A header spelled any other way is not recognized, and its values do not arrive. A row without a serial and a valid email address is skipped, and only the first sheet of an Excel workbook is read. The dialog previews the first five rows with the total, so you can confirm the file read correctly before anything is imported — Change File goes back. Importing reports N devices added, N devices updated and, where they occur, the devices that could not be reached and the ones skipped, each skipped row listed with its reason. Retry N Failed re-runs just the rows that did not land.

Integrations

Connects Unbound to the tools around it, split into Connected and Available: A connected card shows when it last synced. Okta adds a Sync button and an attribute mapping you can edit, and the first import runs as soon as you connect.
While an MDM integration is connected, device owners come from it. A serial JumpCloud does not know appears in Users as a placeholder row named after that serial — importing the device list on the Devices tab does not cover it. Before you connect, confirm JumpCloud knows every serial you are rolling out to, or expect serial-numbered rows in Users for the ones it does not.

What Okta sync does

If the API token is revoked or expires, the card shows the integration as Inactive and syncing stops. Reconnect with a fresh token and it resumes at the next sync.

Policy Enforcement

If Unbound is unreachable decides what your agents do when the policy check cannot run: The choice is staged until you press Save — an Unsaved changes badge marks the gap, and leaving the page first prompts you.

Webhooks

Sends Unbound events to your own systems — a SIEM, a chat channel, or anything accepting an HTTP POST. Each endpoint carries its own signing secret to reveal and copy, can be enabled or disabled, and keeps a delivery history you can read alongside a Send test event control.

Filters and controls

Search events… finds events when subscribing a webhook endpoint. The Devices and Provider API Keys tables each have their own search.

What you can do

Every tab but Provider API Keys needs Admin or Analytics Viewer to read. Every action below is an Admin action — an Analytics Viewer, and a Manager on the one tab they reach, see the contents without the controls that change them.
If Unbound is unreachable is the most consequential setting here. Running as usual keeps developers productive through a network problem; denying operations keeps enforcement absolute. Organizations with strict compliance obligations generally choose to deny.
Budgets are not set here — they are cost policies, under Policies → Usage.

Messages you may see