System is where you manage org-level platform infrastructure: who you are
(organization identity), what you spend (budgets), how config moves between
scopes (backup & restore), per-group capability toggles, model guidance,
outbound webhooks, usage quotas, alert rules, the full advanced settings
catalog, bring-your-own-key encryption, and SIEM audit-stream fan-out. In the
admin console it is one of the five sidebar groups, and Organization is
pinned to the top.
Admin console → System → OrganizationCapture pending — Citadel synthetic data on a non-production Arbitex demo instance. Never client data.
Each panel below maps 1:1 to a tab in the console’s System group.
Organization comes first (it is pinned there deliberately); the rest follow the
console’s own ordering.
OrganizationRead-only org and principal identity, editable org settings, and the staff-managed retention policy (read-only).
BudgetAuthor org budget sub-allocations. Enforcement pending — today the authored limit only powers the Monitoring spend-vs-limit view.
Config Backup & RestoreSnapshot and download a scope's config, or upload a bundle, preview a structured diff, and replay it into a target scope.
Group FeaturesPer-group feature (multimodal) toggles. Enforcement pending — no projector consumes these yet.
GuidanceAuthor per-group system-prompt guidance, revisioned and IDOR-safe.
WebhooksRegister webhook endpoints, subscribed events, retry policy, and a signing secret.
QuotasCap request and token usage by user, group, app, or provider/model.
AlertsDefine alert rules on usage, cost, latency, error, and DLP metrics, and review fire history.
Advanced SettingsThe full typed system_config catalog, grouped by domain and deep-linkable.
KMS / BYOKBring your own envelope-encryption key with a pre-save connectivity test.
SIEM ConnectorsFan out your audit stream to Splunk, Sentinel, Elastic, Datadog, Sumo Logic, Cortex XSIAM, or QRadar.
Email DLP configuration is authored on Security & DLP, not here — see
Email DLP configuration. System
intentionally cross-references that page instead of re-authoring the same
domain in two places.