Settings holds your account, the institution every surface opens against, your alert routing, and — on Institutional and above — the workspace controls: seats, examiner access, and your own CAMELS ratings.
Account and security
Your email is your sign-in address and where password resets and invitations are sent. Below it sit your plan and your data vintage, both read-only and both labelled with where they came from.
Security is two controls: change your password, and turn two-factor authentication on or off. Two-factor is an authenticator app generating a six-digit code — there is no text-message option.
Your primary institution
One certificate, set here, and every institution surface opens against it. Changing it changes what the rail, the board lenses and the reports are about.
Alert channels — provisioned, not self-serve
The page shows the channels configured on your account and how many there are. It does not offer a control to create one: routing is provisioned with your account. Ask for a destination to be added or changed and it takes effect on the next run of the alert job.
This matters for Monitor: the daily threshold sweep reads tracked institutions but sends only to accounts that have a channel. With none configured, nothing is dispatched.
Concentration policy limitsInstitutional and above
Your institution's own internal limits, entered here. They are shown alongside the supervisory levels inside the audit engine — and they never replace a regulatory threshold. They are yours, marked as internal, and treated as such everywhere.
Team and seatsInstitutional and above
Five roles: account admin, admin, power user, regular user and read only. The seat register names members, pending invitations and remaining seats — and when the invite control is unavailable it says why rather than failing on click.
Examiner guests are not seats. They hold a scoped, expiring token rather than a membership.
Transferring the account admin role is its own deliberate flow: you type a confirmation word, a link is sent to the current admin's own email, and it expires within a day. It is the only way that role moves.
Examiner accessInstitutional and above
An examiner invite is a scoped, expiring token. Four scope templates exist — BSA/AML, IT and cybersecurity, CRA, and fair lending — each with its own history window, and you set the access window in days.
What the examiner can see, stated plainly:
- Your structured posture, within the template's scope.
- The titles of in-scope documents — and no file contents.
- Nothing outside the template, and nothing from another institution.
It is revocable at any moment, and every session is logged. Including restricted documents in a scope asks you to confirm, because restricted covers ratings and supervisory correspondence.
Your CAMELS ratingsInstitutional and above
Ratings you record for your own workspace. The page states the boundary before the form: MDRM IQ does not access confidential supervisory data. Every rating here is one your institution typed, it is used only inside your own workspace, and cross-institution analysis using it is not active. Data that leaves the workspace leaves the audit trail with it.
Sign in with your email and password. If two-factor is enabled, the form then asks for the six-digit code from your authenticator app. Accounts created without a password — a demonstration account, for instance — can use the "email me a sign-in link instead" option on the same form. A password reset link is a separate, much shorter-lived thing.