Skip to main content

Configuration reference

Configuration exists at three levels: deployment configuration controls licensed runtime behavior; Tenant/Workspace configuration controls customer-owned resources; project/run configuration controls a particular measurement program. Keep these boundaries separate.

Configuration topology​

Deployment environment variables​

Product and internal runtime​

VariableRequiredPurpose
THYRIS_LICENSE_GEO_SERVICESDeployment-dependentExplicit GEO product license override
GEO_INTERNAL_WORKER_TOKENProductionShared internal bearer credential for BFF, workers and GEO runtimes
GEO_CONTROL_PLANE_URLWorker runtimesInternal control-plane base URL
GEO_SERVICE_KEYEach domain runtimeSelects the single advertised domain capability
GEO_SERVICE_ADDRNoListen address; default :8080
GEO_WORKER_INTERVALNoWorker poll interval; minimum 1s, default 15s

Use a long random internal token from a secret. Do not use the token as a customer API key and do not expose internal worker routes publicly.

Domain service URLs​

VariableDefault service
GEO_CORE_SERVICE_URLhttp://geo-core-service:8080
GEO_COMPONENT_SERVICE_URLhttp://geo-component-service:8080
GEO_OBSERVATION_SERVICE_URLhttp://geo-observation-service:8080
GEO_INTELLIGENCE_SERVICE_URLhttp://geo-intelligence-service:8080
GEO_KNOWLEDGE_SERVICE_URLhttp://geo-brand-knowledge-service:8080
GEO_CONTENT_SERVICE_URLhttp://geo-content-service:8080
GEO_CHANNEL_SERVICE_URLhttp://geo-channel-service:8080
GEO_SIMULATION_SERVICE_URLhttp://geo-simulation-service:8080
GEO_ACTION_SERVICE_URLhttp://geo-action-service:8080
GEO_REPORTING_SERVICE_URLhttp://geo-reporting-service:8080
GEO_TRACKING_SERVICE_URLhttp://geo-tracking-service:8080
GEO_ATTRIBUTION_SERVICE_URLhttp://geo-attribution-service:8080
GEO_ENTITY_SERVICE_URLhttp://geo-entity-service:8080
GEO_CITATION_GRAPH_SERVICE_URLhttp://geo-citation-graph-service:8080
GEO_PROMPT_DEMAND_SERVICE_URLhttp://geo-prompt-demand-service:8080
GEO_NARRATIVE_SERVICE_URLhttp://geo-narrative-service:8080
GEO_EXPERIMENT_SERVICE_URLhttp://geo-experiment-service:8080
GEO_AUTOPILOT_SERVICE_URLhttp://geo-autopilot-service:8080

Service URLs must resolve through internal service discovery. The control plane validates capability responses before relying on a runtime.

Connector safety overrides​

VariableDefaultGuidance
GEO_CONNECTOR_ALLOW_INSECURE_HTTPfalseDevelopment only; production endpoints should use HTTPS
GEO_CONNECTOR_ALLOW_PRIVATE_NETWORKfalseEnable only for reviewed private integration networks

Endpoints containing URL credentials are rejected. Loopback, private, link-local and internal host destinations remain blocked unless the explicit policy allows them; resolved addresses are also checked to reduce DNS-based SSRF bypass.

Provider configuration​

FieldValidation and behavior
ProfileActive platform profile or custom
NameWorkspace display name, 2–255 characters
Typeopenai_compatible, anthropic_compatible, perplexity_compatible, or custom_agent
Endpoint URLValid safe URL; profile default may apply
ModelRequired model identifier, maximum 255 characters
API keyEncrypted when stored; never returned after save
Credential secret referenceOptional server-side reference such as env://GEO_PROVIDER_API_KEY
DefaultOne default active provider per workspace
CapabilitiesVision, JSON mode and tool support flags
Web searchAvailable only for eligible direct OpenAI, Anthropic, Perplexity, and Gemini profiles; may add provider charges
Input price per millionNon-negative workspace-provider rate used for estimates
Output price per millionNon-negative workspace-provider rate used for estimates
Web-search price per requestNon-negative rate applied to provider-reported search requests
Pricing currencyThree-letter currency stored with each usage event
ConfigurationProvider-specific JSON object
StatusDraft, active, degraded or disabled

Use either an encrypted API key or secret reference according to deployment policy. When deleting the default provider, the oldest remaining active provider becomes default; confirm that fallback is acceptable before deletion. Provider rates come from the workspace owner's contract and are not credentials. Zero rates without a provider-reported total produce unpriced usage rather than a confirmed free-cost claim.

Observation connector configuration​

Observation connectors can represent fixture, openai_compatible, anthropic_compatible, perplexity_compatible, custom_agent, mcp, rag, or workflow execution.

FieldPurpose
ComponentOptional link to a workspace-owned AI component
Endpoint URLRequired for executable connectors except fixture/MCP/RAG cases where configuration supplies the execution contract
Secret referenceServer-side credential reference
Terms URL/acceptanceProvider terms and retention acknowledgement
Retention daysConnector evidence policy, 1–365 days
Store raw responseExplicit raw-response retention choice
Configuration JSONAdapter-specific request/version/options
StatusDraft, active, degraded or disabled

Executable non-fixture connectors cannot become active without required terms acceptance. Raw-response storage should remain off unless there is a documented purpose and access/retention policy.

Monitoring schedule configuration​

LabelCronExecution
Hourly0 * * * *Start of the next UTC hour
Daily0 9 * * *09:00 UTC daily
Weekly0 9 * * 1Monday 09:00 UTC
Monthly0 9 1 * *Day 1 at 09:00 UTC

A schedule also declares project, prompt sets, provider IDs, optional target IDs, repetitions, maximum requests, maximum cost, timezone metadata, status and next-run state. Only the supported schedules above are accepted by the current scheduler contract.

Tracking-site configuration​

FieldContract
HostnameCanonical site host
Allowed originsOne or more allowed HTTPS origins/hosts
Consent moderequired, granted, denied, or not_required
Retention days1–730 days
Site tokenOne-time shown, hashed at rest, revocable and optionally expiring
StatusActive/inactive operational state

Sessions use a retention cap appropriate to pseudonymous continuity, while events follow site/workspace retention policy. Test the actual cleanup worker before production collection.

API key configuration​

Choose account, workspace or custom-workspace scope and only the permissions required:

PermissionCapability
geo:readRead authorized datasets, reports, graph and MCP read tools
geo:signals:writeSend approved signal/event data where supported
geo:draftCreate draft resources without approval/execution authority
geo:approveRecord governed approvals where policy permits
geo:executeExecute approved actions where policy and route permit
geo:writeCurrent mutation and MCP approval-request operations

Set an expiration, rotate keys, and revoke before deletion. A key scope never overrides workspace membership or product access.

Environment checklist​

ConfigurationDevelopmentStagingProduction
Database and object storageIsolated localIsolated stagingHA/backup and restore-tested
Provider credentialsTest/low-limitSandbox/stagingProduction, least privilege
Channel destinationsFixture/local where safeStaging workspace/siteApproved production destination
Tracking tokensDevelopment originStaging originProduction origins only
Connector HTTP/private overrideMay be explicitly enabledPrefer disabledDisabled unless formally reviewed
Worker budgets/concurrencySmallProduction-like boundedMonitored and alerting
RetentionShort test policyAcceptance policyApproved privacy policy

Configuration acceptance​

After a configuration change:

  1. Verify workspace/account ownership and actor permission.
  2. Validate endpoint, JSON and secret reference without logging the secret.
  3. Run health/capability or preview test.
  4. Confirm audit event and redaction.
  5. Execute a bounded representative operation.
  6. Inspect failure behavior and rollback/revocation path.
  7. Record owner and review date.