Workspace settings
A Yekar.AI organization is structured by domains - bounded contexts that hold agents and flows, connections, and the people allowed to touch them. Teams own their own domains: Customer Support's agents, accounts, and members are separate from Finance's.

Domains
Open Settings → Domains. Each domain lists its members, its agents and flows, and your role in it. Select New domain to create one; open a domain to manage its members, its team-account connections, its approval policy, and any per-domain budget cap.

What lives in a domain:
- Agents & flows - every Agent and Flow belongs to exactly one domain.
- Team accounts - the domain's service connections, which agents and flows set to Team account act through.
- Members - the people whose domain role decides what they may do there.
- Approval policy - Who approves here: a minimum domain role, or a named list of domain members. Every member can see who qualifies; a domain Owner changes it with Edit approvers. See How approvals are layered.
Domain roles
The four roles are Viewer (domain member), Operator, Editor and Owner. All can inspect configuration and run published agents and flows. Operators add collaboration in teammates' sessions, trigger and webhook management, and approval eligibility. Editors add authoring, publishing, Builder, knowledge management and evaluations. Owners add shared connections, membership and domain settings.
See Roles and permissions for the complete organization and domain matrices, session ownership rules, and approval-policy exceptions. Organization roles and domain roles are independent.
Users
Open Settings → Users → Invite user to choose an organization role (Member, or Admin when invited by an organization owner), then use Add access to select domains and their roles. Organization Owners/Admins can assign any domain role; domain Owners can manage existing organization members within their own domains. Review the access before sending, or leave the access list empty to assign it later. Member + domain Editor is enough to build agents. Organization admins manage org-wide settings; domain roles govern day-to-day work inside each domain. See Teams and offboarding for role assignment and user status controls.

Your own account
Settings → Account is where each person manages themselves - their name, their password, their sign-in email, and the workspaces they belong to. One sign-in can hold memberships in several workspaces and switch between them without a second password.
Changing the sign-in email is a two-step flow, because an address you have not proved is an address you could be taking from somebody else. Change email sends a confirmation link to the new address; the link works once and expires in an hour, and your sign-in address stays the old one until you open it. The old address gets a notification of its own, with nothing to click. Until then you can send the link somewhere else instead.

Single sign-on
Where the workspace has it enabled, Settings → Single sign-on connects your SAML identity provider so people sign in through your own directory. Nobody is created by signing in - the membership must already exist. See Single sign-on.
Support sessions
If you ask Yekar.AI for help, Settings → Support sessions is your record of it: every time a Yekar.AI engineer was granted access to your workspace, what they were allowed to do, and when it ended. Access is time-boxed and revocable from this page.

Organization defaults and budgets
Settings → AI settings → Defaults applies to every agent and flow in the organization:

- Context window - a token budget per agent turn; rules, knowledge, and history are trimmed to fit. Empty uses each model's full window. What a turn does when it runs out of room - dropping the oldest messages, summarizing them, and eliding old tool results mid-turn - is described in Long conversations.
- Maximum execution age - calendar lifetime for new Flow runs and Agent turns, including queued and parked time.
- Monthly token budget - an enforced org-wide cap on AI tokens per calendar month. At 80% admins are alerted; at 100% new model calls pause until the month rolls over. Domain owners can set a tighter per-domain cap on the domain page.
- Monthly cost cap (USD) - enforced on managed providers, where new model calls pause over the cap; advisory on your own keys, where spend is an estimate and admins are alerted instead.
Settings → Plan & usage → Cost reports what was spent - by window, by domain, and by agent, as charged actuals on managed providers and as an estimate on your own keys - so a budget is something you set from evidence rather than a guess. Cost & budgets explains what is counted and how.

See AI providers for the provider and model controls beside them, and Plan & usage for the capacity those budgets run inside.