Skip to content
Aristo's read Grounded in page evidence

Tenant-owned settings and operator-held platform levers are shown as separate authorities.

Why it matters
A stored default, a customer-provided value and an unavailable configuration read must never look identical.
Recommended action
Confirm the seat-cost basis and quiet-mode state before changing either; the illustrative scenario remains read-only.

Settings

What this organisation has configured, what each setting changes, and every change anyone has made to them.

The seat cost is still the platform's $30 assumption, and every return figure in the product is multiplied by it — which is why each of them carries the assumption chip until a real number is provided here. provided

Copilot seat cost

The number every return figure in the product is multiplied by.

Assumed

Every return figure in this product is a multiple of this number. While it is the platform assumption, each of those figures carries the assumption chip — which is honest, and is also why replacing it with the real contracted rate is the highest-value thing on this page.

Stored now
$30 / seat / month
assumption

This is the illustrative organisation — it is never written to, so there is nothing here to set. In your own tenant this control writes the same field the classic settings screen writes, records the same audit action, and every surface that reads the setting moves with it.

Saved here or saved on the classic settings screen, this writes one field in one store and records one audit action. There is no second copy of the seat cost.

Quiet mode

Stop every proactive message organisation-wide, for a chosen number of days.

Running

For the weeks when an organisation has something harder going on than a Copilot programme. While it is on, every proactive message stops — nudges, digests, the lot — and Aristo answers only when it is spoken to. Nobody's pause is recorded against them, and the resume is silent: nothing held back during the pause is delivered afterwards.

State now
Running normally

This is the illustrative organisation — it is never written to, so there is nothing here to set. In your own tenant this control writes the same field the classic settings screen writes, records the same audit action, and every surface that reads the setting moves with it.

Settings this page deliberately does not duplicate

Every one of these is real, and every one is edited somewhere that shows more than a switch would.

Scroll sideways for the remaining columns.

Settings owned by another surface, their current stored state, why they are not duplicated here, and where to change them.
SettingStored nowWhy it is not a control on this pageGo
Monthly Cowork budget and its enforcement $320,000 a month · enforcement soft It has a workspace of its own, with the forecast beside it that tells you whether the cap you are about to set is one this organisation will actually hit. A second control here would write the same field and show none of that. Open budget planning
Who may open these workspaces 0 sponsors named, beside the Entra role The list is real and editable, and editing it means reading colleagues' addresses. No page in this shell has ever printed one, so this shows the count and hands you the screen that shows the list. The roles page below explains what each authority can actually do. See the role model
Connected systems, exports and credentials each with the state a real check returned Connection state belongs beside the other connections rather than in a list of switches. The classic settings screen is still where a SAS, a credits report or a subscription id is entered. Open integrations
Branding, logo, theme and the module switchboard unchanged on the classic screen These have not been rebuilt in this shell. Rather than render a partial copy of a working editor, this page names where the working one is. Open the classic settings

Availability and rollback

Three levers, three jobs, no overlap — and none of them writable from here. Shown because a governance surface that hides the switches above it is not a governance surface.

Scroll sideways for the remaining columns.

The three independent availability levers, their current state, and who holds each one. All read-only on this page.
LeverStateWhat it does and who holds it
This workspace exists On Set in the deployment environment, defaulting to on — a switch that must be set for the product to work is a switch somebody eventually forgets on a fresh deploy. Turning it off does not hide these pages behind a message: it stops registering the routes, so they answer with the same ordinary 404 as any unknown address. That is the cheapest rollback available and the only one with no second failure mode.
The platform-wide report kill Lifted A fleet-wide switch that returns every organisation to the previous report generation. It is held by the platform operator and cannot be set from any customer surface — which is the point of showing it here: you can see the lever exists and see that it is not yours.
This organisation's report generation Following the platform default A per-organisation pin, set through the engagement rather than through a checkbox somebody finds in a settings screen. Unset means this organisation follows whatever the platform currently defaults to.
Read-only, deliberately and permanently. A rollback lever a customer surface could flip is a rollback lever that gets flipped during an incident by the person least able to see the whole fleet.

How this page behaves

The parts of it that are decisions rather than omissions.

There is no filter bar and there is nothing here to filter: this is a short list of named settings, not a collection. There is no export, because a settings page's export is its audit trail and that has a page of its own. There is no loading state — every value is rendered by the server before the page is sent, so there is no moment at which a reader is looking at a control whose value has not arrived.

When a control may not be used it says so in words rather than vanishing or greying out silently. The sample organisation is never written to, and rather than hide its controls this page states what each one would do in a real tenant. A control that disappears for some readers teaches them the product cannot do it at all.

Every write here is a POST that redirects to a fresh read. The confirmation you land on is re-read from the store rather than echoed back from the form you submitted, which is the difference between evidence that a write happened and a receipt for having clicked. A browser refresh on the confirmation cannot re-apply the change.