Users and teams
Create users, group them into teams, and use teams as notification recipients.
Contact methods
Define the contact fields users can fill in, and how a media type picks one of them to decide where each person's notification goes.
Roles and permission matrix
Built-in roles, custom roles, and which menu and API operations each grants.
Business group authorization
Add teams to a business group with read or write rights, and see the effect on rules and targets.
Tokens and credential rotation
Personal tokens, service accounts for MCP and the API, and rotating them without downtime.
SSO / external identity integration
OIDC, OAuth2, LDAP, CAS, DingTalk and Feishu login, and mapping external groups to roles.
Site and user variable settings
Site-wide settings and encrypted variables that templates and integrations can reference.
Network and TLS hardening
Terminate TLS, restrict the write endpoints, and which ports must not face the internet.
Secret management
Keep database passwords, channel tokens and LLM keys out of config files.
Security checklist
The short list to run before exposing Nightingale to a wider audience.