← All articles

Settings

Institution administrators configure notifications, security, compliance templates, LMS connections, API keys, and (on free trial) a demo sandbox from Settings.

Overview

Open Settings from the main navigation. Tabs you may see:

  • Demo Sandbox (free trial only)
  • Notifications
  • Security (MFA and Enterprise SSO)
  • Compliance
  • LMS Connections
  • REST API
  • Logs (when enabled for your institution)

Notifications

Set how HealthTasks emails your team about:

  • Compliance alerts — expired or soon-to-expire items (choose the look-ahead window)
  • Low seats alerts — when student seats are running low
  • Point of contact — one admin who receives summary alerts

Keep low-seat alerts on during enrollment season so you can add seats in Billing before students are blocked.

Security (MFA and SSO)

On Security:

  • Require multi-factor authentication for selected roles (student, preceptor, faculty, admin). Users without MFA are guided through authenticator-app setup on login.
  • Configure Enterprise SSO when your institution has the Enterprise add-on (identity provider sign-in and related options).

For SSO setup details, see Enterprise-SSO. Subscribe or manage the add-on from Billing if Enterprise is not active yet.

Compliance templates

On Compliance:

  • Edit the standard template and create custom templates.
  • Enable the requirements each group must meet; add custom requirement names when needed.
  • Toggle AI auto-rejection and AI auto-approval for uploaded documents.

Assign templates to people on Users. Day-to-day uploads and approvals are covered in Compliance.

LMS Connections (Canvas)

Connect Canvas with your institution base URL and an access token, then save. Use the on-page help for where to create a Canvas token. Keep tokens private and rotate them if staff change.

Demo Sandbox (free trial)

On free trial, Demo Sandbox can create sample classrooms, users, and logs for demos or training, and Reset removes that demo data. Use it only on trial data you are willing to replace.

REST API

Create and revoke institution API keys on REST API. Prefer one key per integration and store secrets on your servers only.

For setup, scopes, and security guidance, see REST-API. Full endpoint reference: https://developers.healthtasks.ai

Logs

When the Logs tab is available, review authentication and related security audit activity for your institution. See Security-Audit-Logs for how to read and use that history.

Tips

  1. Require MFA for admins at minimum.
  2. Assign a compliance contact who monitors weekly digests.
  3. Configure templates before clinical onboarding peaks.
  4. Revoke REST API keys you no longer use.

Troubleshooting

Missing a tab
Some tabs depend on plan, trial status, or role. Confirm you are an institution administrator.

Users not prompted for MFA
Ensure their role is checked on Security and that settings saved.

Canvas connection fails
Recheck the base URL and that the access token is current and has API access.

Need SSO or API depth
Use Enterprise-SSO or REST-API rather than expanding this page.

  • Users: Assign compliance templates and manage seats
  • Compliance: Profile uploads and admin document review
  • Billing: Seats, Sims credits, Agents, and Enterprise SSO
  • REST-API: API key overview and integration patterns
  • Enterprise-SSO: SSO connection details
  • Security-Audit-Logs: Interpreting the Logs tab

Support

For settings or access questions: [email protected]