Organization & security
The organization settings gather the decisions that apply to your whole workspace: identity, security, and billing. This page covers who your organization is to the outside world, how you protect your account, and how plan billing and sales payouts work.
How settings are organized
The settings panel uses a full-screen shell with grouped navigation on the left: an Account section per user and, for anyone administering the organization, Organization, Integrations, and Developer sections. The administrative sections only appear for those with an organization owner or admin role.
- Account settings — profile, appearance, and security — belong to your account and travel with you across organizations.
- Organization, Integrations, and Developer settings belong to the active organization and require an owner or admin role (the
requireOrgAdmingate).
Organization identity
The general area at /dashboard/settings/organization holds the name, identifiers, and institutional information. This data can appear on public pages, communications, and integrations, so changes here have a broad reach.
- The organization logo and team logos are uploaded as images and normalized by the avatar endpoint (resized to 256px and converted to WebP), just like the user photo.
- Free-text bios exist at three levels — user, organization, and team — to describe who is responsible for what.
Keep these fields up to date: an outdated logo or an empty bio weakens the public catalog page and the identity of your offerings.
Analytics & tracking
Analytics is the Google capability under /dashboard/settings/integrations/google. An administrator connects one Google identity through OAuth, discovers accessible resources by name, and activates either direct GA4 or Google Tag Manager. Organization rows contain no tracking identifiers; Google is the only analytics provider.
The safe active projection is read from the integration record on public pages. Consent and minor-safety rules decide whether it loads; it never runs in the dashboard or on the canonical platform host. See Integrations for setup, managed GTM review, and event delivery.
Learner sign-in on the school host
Learners use one Cursare identity across schools, but each school gets an isolated
session for its exact host. Sign-in and account security stay on cursare.com; a
consent screen names the school and the identity fields it receives before the
learner returns to study there. School sessions cannot open the dashboard, REST
API, MCP, another school, or the learner's global account. See Custom domain and
white-label for lifetimes, logout, scripts, and DNS revocation.
Security
The Security area at /dashboard/settings/security covers your account's authentication: password management, two-step verification (TOTP-based 2FA), and passkeys.
- Password — create, change, or set a password for the account.
- 2FA (TOTP) — enabling a second factor generates a QR code for your authenticator app and a set of backup codes, shown only once.
- Passkeys — register a device passkey to sign in without a password. Each passkey is named automatically from the browser and operating system that created it (for example, "Chrome on macOS"), and can be removed from the same card.
Billing
Your organization chooses a plan when it is created and starts with a free 14-day trial. The Billing screen at /dashboard/settings/billing shows the trial end date, current plan, included features, usage limits, and any active-learner overage.
Nothing is charged automatically when the trial ends. If no paid contract is activated, plan-protected actions pause while the organization's data remains preserved. See Plans, trial & billing for the complete behavior.