> For the complete documentation index, see [llms.txt](https://documentation.connexica.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://documentation.connexica.com/cxair-ai/administrator-configuration.md).

# 10. Administrator Configuration

## Providers

CXAIR currently contains provider integrations for:

| Provider                        | Configuration required                        |
| ------------------------------- | --------------------------------------------- |
| OpenAI / ChatGPT                | OpenAI API key                                |
| Google Gemini                   | Gemini API key                                |
| Amazon Bedrock                  | AWS access key, secret and region             |
| OpenAI-compatible Llama service | Base URL for the service; CXAIR appends `/v1` |

Provider credentials are entered through the AI provider administration page. Password fields display a placeholder rather than exposing an existing secret. Store and rotate credentials according to organisational policy.

## Models

Create saved model configurations through the AI models administration page. Model-specific fields can include:

* Provider and provider model identifier
* Display name
* Maximum documents
* Maximum file size
* Context window and maximum output tokens
* Reasoning effort, where supported
* Whether the model is used for image generation

Set appropriate limits for cost, latency, provider quotas and expected report sizes. Test each model with non-sensitive data before general release.

## Global AI settings

| Setting             | Purpose                                                                                                                                                                                                                   |
| ------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| System messages     | Adds organisation-specific instructions used in applicable AI interactions.                                                                                                                                               |
| Reserve tokens      | Reserves model context capacity for instructions and output; large files or reports may be truncated to fit.                                                                                                              |
| Temperature         | Controls model variability, subject to provider support.                                                                                                                                                                  |
| Maximum Tool Rounds | Caps the number of tool-use round trips the assistant can make while answering a single request (minimum 5, default 30). Lower values limit cost and response time; higher values allow more complex multi-step requests. |

## User access

* Confirm the deployment has an applicable AI licence.
* Grant **Use AI** only to approved users or groups.
* Configure a suitable default model where required.
* Decide whether a user's AI-triggered report changes should reload automatically.
* Test with representative non-administrator accounts; administrator access is not evidence of ordinary-user permissions.

## MCP deployment checks

* Confirm the externally advertised protocol, host and context path are correct.
* Require HTTPS for external clients.
* Allow the MCP endpoint only through approved network paths.
* Issue scoped, revocable bearer tokens and test their effective CXAIR access.
* Check server logs for the MCP startup message and endpoint URLs.
* Confirm temporary image storage is writable and is not treated as permanent storage.
