Settings
Instance
Customer
Active Directory Sync (LDAP)
Customers
| Name | DNS Domain | DNS IP | Description | Assets | |
|---|---|---|---|---|---|
No customers defined yet. Add a customer to start assigning assets.
Users & Access
| Username | Role | Groups | Customers | Active | Last Login | |
|---|---|---|---|---|---|---|
| ✕ | All No access |
My Two-Factor Authentication
TOTP is not enabled for your account.
Monitoring
When enabled, the server automatically pings all monitored assets at the configured interval.
How old an asset's last successful check may be before its status displays as Unknown on the Assets and Live Monitor pages. Leave 0 for automatic (2× the ping interval). Increase this if healthy assets briefly flip to Unknown because a full check sweep takes longer than the automatic window. Display-only — alerting is not affected.
Tune ping behavior for LAN and WAN (VPN/Tailscale) environments.
Check SSH, RDP, and WinRM port availability on computer assets. Runs independently from ICMP ping.
Identity Verification
Enable or disable each verification component independently. All off = classic behavior (no identity checks).
Management Protocols
Configure remote execution protocols. Disabled protocols are hidden from all UI menus and the worker falls back to SSH.
SNMP Collector
Connection and tuning for the SNMP switch collector. Poll cadence is per-task — schedule an SNMP Walk task in the Scheduler to control when and how often each switch is polled.
When off, no switch is ever polled and the collector makes no outbound SNMP.
Default UDP port for new devices (per-device overrides).
Per-request (per-PDU) SNMP timeout.
Max time for one full table walk.
Max time budget per switch per cycle.
Discovery & events
Consecutive polls before an unknown MAC is queued to discovery.
Per-(MAC,switch) port-change event dedup.
Ports below this feed the Ports Below Speed Floor alert attribute (e.g. 1000 = alert on sub-gigabit links).
A port with more learned MACs than this is auto-treated as an uplink/trunk — its devices are shown as transit, not mapped to it (0 = off). Mark specific uplink ports per-switch on the asset's SNMP Monitoring card.
Monitored switches
SNMP monitoring is now configured on each switch asset. Open a switch on the Assets page, link its SNMP credential on the Credentials tab, then enable monitoring and choose the MAC/ARP roles + port on the Overview SNMP Monitoring card. Schedule polling with an SNMP Walk task in the Scheduler.
Backup Collector
The backup collector reads the job history of a Veeam Backup & Replication server (script windows/veeam-vbr-collect.ps1, scheduled as a task that targets computers whose Veeam Backup Server attribute filter equals true) and writes the result onto the protected computers and the backup server. It only reads from Veeam. Help ▸ Backup Collector has the full setup steps.
There is no schedule to set here: the collector runs as a scheduled task (Scheduler page), and a backup counts as overdue when Veeam's own job schedule says a run is late. The rows shown on the Backup jobs tab are deleted after the number of days set in Maintenance ▸ Backup job history (days) (default 90).
Alerts
Notification Destinations
Used by the legacy email/Telegram channel. Per-rule notification channels are configured in the Alert Center page.
Alert Center
Operational controls for the Alert Center engine (oct-alert-worker). Per-asset toggles live on the asset edit modal; per-rule config is in the (future) Rules editor.
Attribute Definitions
Define which fields are collected and displayed for each asset type. Auto-approve means collector data is applied immediately, including removals (when the source reports a value is gone — e.g. an M365 license unassigned — the attribute is cleared); otherwise both updates and removals go to the pending queue for review.
| Key | Label | Type | Asset Type | Auto-approve | |
|---|---|---|---|---|---|
No attribute definitions found.
Access Credentials
Centrally managed credentials. Link them to assets from the asset detail view.
Account Providers
The account types operators can attach to user assets. Each provider's attributes are defined in Settings ▸ Attributes (its asset-type selector includes every provider) and shown here read-only.
| PROVIDER | KEY | FIELDS | ACCOUNTS | STATE | |
|---|---|---|---|---|---|
M365 Connectors
Connect Microsoft 365 / Entra tenants for account & device collection — one connector per customer. Octotor generates the certificate; you upload the public half to your Entra app registration. Step-by-step guide: Help ▸ M365 Connectors.
| CUSTOMER | TENANT | THUMBPRINT | CERT | TEST | STATE | |
|---|---|---|---|---|---|---|
No connectors yet. Add one, download its certificate, upload it to your Entra app, then run Test.
Hover a row to see its last keygen/test detail. Test requires the master switch ON.
Jump Hosts
SSH bastions the worker tunnels through to reach an asset it can't connect to directly (segmented VLANs, bastion-only appliances). Attach one to an asset from the asset's Overview. Each is linked to a customer and an SSH credential.
| NAME | HOST | CUSTOMER | CREDENTIAL | ASSETS | STATE | |
|---|---|---|---|---|---|---|
No jump hosts yet. Add one, then attach it to an asset from the asset's Overview panel.
Groups & Permissions
How permissions work:
• Admins have full access to everything — groups have no effect on them.
• Viewers have fixed read-only access (Dashboard, Assets, Logs) — they cannot be added to groups.
• Operators start with full access to all scripts and protocols. Create custom groups to narrow their access to specific pages, scripts, and protocols.
• Once an operator is added to any custom group, they only see the scripts and protocols granted by that group — not everything.
• To change a user's role (viewer/operator/admin), edit the user under Users & Access.
No groups found.
AI Configuration
AI Status
Cloud AI Access
AI Features
Security
Verify Identity
This section requires verification to access.
Action Passwords
Action passwords are separate from your login password. They protect sensitive toolkit and scheduler operations even if your session is compromised.
This key bypasses rate limiting and lockout. Use it if you forget your master action password or get locked out. Store it in a password manager or print it.
Per-Action Overrides
| Action | Password |
|---|---|
|
|
Script Signing
Signed scripts are cryptographically verified to ensure they haven't been tampered with since creation.
Coming soon
API Tokens
API tokens allow programmatic access to Octotor. Use them for integrations, agents (Goose), and automation.
Requires API Tokens in your license| Name | Owner | Scopes | Expires | Last Used | Created | |
|---|---|---|---|---|---|---|
| No API tokens created yet. | ||||||
Network Address Translation (NetMap)
Map customer LAN subnets to Tailscale-routed subnets when customers have overlapping IP ranges. Translation is applied at runtime — stored asset IPs remain the real LAN addresses.
| # | Customer | Original Network | Mapped Network | Notes | ||
|---|---|---|---|---|---|---|
| → |
Software Updates
Status
octotor-upgrade.sh one-liner on the host — see Help ▸ Software Updates for the exact command.
Check Settings
Once a day Octotor fetches the published version list to learn whether a newer release exists. Nothing about this installation is sent — it is a plain read of a static file. Turning it off stops the daily check; the Check now button always works.
Support
Diagnostic Bundle
Generates one downloadable archive of this installation's diagnostic state for troubleshooting with support. Nothing is sent anywhere — the file downloads to your computer and you send it to support yourself, by email or your own file share. There is no upload feature.
- Version, migration level, service heartbeats
- License state summary (tier, expiry — no key material)
- Recent failed jobs (metadata only) + alert counts
- Error entries from the action log
- Settings with secret-looking values masked
- Credentials or credential data
- Encryption keys, JWT secrets, API tokens
- .env contents
- Job outputs or commands (can embed secrets)
Database Maintenance
Data Retention
Configure how long each type of data is kept. Applied by scheduled maintenance or manual prune.
Scheduled Maintenance
Automatically prune old data and vacuum the database on a schedule. Database backups run separately via host cron (daily at 2:00 AM) — see Backup Status below.
0 2 * * * daily 2AM · 0 3 * * 0 Sunday 3AM · 0 */6 * * * every 6h
crontab -e
Backup & Optimization
Create database backups, optimize performance, or reclaim disk space.
Backups run via host cron (daily at 2 AM).
Runs VACUUM ANALYZE — reclaims space from deleted rows and updates query planner statistics. Safe to run anytime, no locks, no downtime.
Runs VACUUM FULL — rewrites all tables for maximum disk reclaim. Locks all tables during operation. Users may see errors.
Manual Data Cleanup
Manually delete old records from a specific table. Select the table, enter how many days of data to keep, click Preview to see how many rows will be deleted, then confirm.
Database State
| # | Table | Rows | Size | Dead Tuples | Last Vacuum | |
|---|---|---|---|---|---|---|
Click "Refresh All" to load database statistics.
Backup Files
| # | Filename | Size | Created | |
|---|---|---|---|---|
| Download |
No backup files found. Backups run daily at 2 AM via host cron.
Recent Activity
| # | Time | Action | Operator | Detail | Status |
|---|---|---|---|---|---|
No maintenance activity yet.
System
System-wide policies and limits.