# Workspace settings reference

> Manage workspace settings: members and roles, security and 2FA enforcement, SSO, billing, API tokens, webhooks, the audit log and white label branding.

| Page | What's there |
|---|---|
| **General** | Name, default timezone and currency, workspace id (`ws_…`), and **Delete workspace** (7-day soft delete) |
| **Members** | Members with role, site access, 2FA status and last activity. Invite, change role, remove, transfer ownership. See [Teams](/docs/teams) |
| **Roles** | Built-in roles and, on Business, [custom roles](/docs/teams/roles#custom-roles) |
| **Security** | Enforce 2FA (Business), allowed sign-in methods, session lifetime, IP allowlist for the app (Business), support access |
| **SSO** (Business) | [SSO](/docs/teams/sso) with SAML or OIDC, email domains and [SCIM](/docs/teams/scim) |
| **Billing** (sidebar) | Plan, usage meter with forecast and per-site breakdown, change plan, payment method, billing emails, tax id, invoices, cancel. See [Billing](/docs/billing) |
| **API tokens** | Create, view last use, revoke. See [Authentication](/docs/api/authentication) |
| **Webhooks** | Endpoints, events, signing secret, delivery log with retry. See [Webhooks](/docs/api/webhooks) |
| **Audit log** | Who did what, when. See [Audit log](/docs/teams/audit-log) |
| **White label** (Business) | Brand name, logo and accent color on shared dashboards, embeds and email reports, and an option to hide Privatus Analytics branding. See [White label](/docs/reports/white-label). Custom dashboard domains and email sender domains are not available |

The DPA, subprocessor list and SCCs are on the
[legal pages](/legal). See [Privacy & compliance](/docs/privacy).
