Skip to main content
This page is the complete list of Devin Desktop settings that administrators can set for their members. Each control is listed once, under the surface that enforces it, with a pointer to the detailed guide where one exists. Devin Desktop has three enforcement surfaces. Use them together: team settings for anything that should follow the user’s account, device policies for anything that must hold before sign-in or on every machine.
“Windsurf” and “Devin Desktop” refer to the same product. Legacy Windsurf Enterprise customers manage team settings at windsurf.com/team/settings; Devin Enterprise customers manage the same settings in the Devin app. Both write the same team configuration, so a setting changed in one place appears in the other.

Team settings

Team settings are stored on the server and delivered to Devin Desktop with the user’s account status, so they follow members to every device they sign in on. Changing a team setting requires the Devin Desktop admin permission (account.windsurf.admin in Devin, TEAM_SETTINGS_UPDATE in the Windsurf dashboard). See RBAC role management for granting it. Unless noted, a team setting takes effect the next time Devin Desktop refreshes the user’s account status (at sign-in and periodically while running). Settings marked restart need Devin Desktop to be relaunched before they fully apply.

Organization overrides

Enterprises with several organizations set defaults once at the enterprise level. Where organization-level overrides are enabled, an admin viewing a child organization’s Devin Desktop settings page can override individual settings for that organization only; anything not overridden is inherited from the enterprise defaults. The enterprise page shows an Overridden in N orgs badge on each setting that has at least one override, and overrides can be reset back to the enterprise value from the organization’s page.

Features

Permissions & security

MCP & ACP

Codebase intelligence

Models

These settings live on the Models tab of the Devin Desktop settings page.

Data retention

Sharing

These settings live on the Sharing tab, alongside the lists of conversations and Codemaps members have shared.

Analytics & compliance

Legacy Cascade

These controls only affect the legacy Cascade agent.

Account administration

The Windsurf dashboard also hosts account-level controls that are not Devin Desktop settings but affect who can sign in and what they can do: SSO & SCIM, domain verification, roles and permissions, and service keys for the analytics API. In the Devin app these live under Settings → Administration.

Device policies (MDM)

Device policies are enforced by the operating system before Devin Desktop starts, so they apply whether or not the user signs in and cannot be changed from inside the editor. Deploy them with Windows Group Policy (registry path Software\Policies\Windsurf\Devin), a macOS configuration profile, or /etc/vscode/policy.json on Linux; see Enterprise Policies for the step-by-step setup on each platform. Policies take effect the next time Devin Desktop starts. The policies most relevant to Devin Desktop administration are: The sample policy.json, .mobileconfig, and ADMX files shipped in each release’s policies folder list every policy the installed version supports, including upstream VS Code policies not covered above.

How device policies and team settings combine

Where the same control exists on both surfaces:
  • Extension allowlist — the Extension policy team setting replaces the AllowedExtensions policy on the member’s machine when both are set. Use the team setting when the allowlist should follow the account; use the MDM policy for machines that may never sign in.
  • Extension marketplace URL — the ExtensionGalleryServiceUrl policy wins over the Extension marketplace URL team setting when both are set, and the team setting wins over the member’s own devin.marketplaceExtensionGalleryServiceURL setting. The Extensions view always names the marketplace actually in use.
  • Everything else is only configurable on one surface.

System-level files

Administrators can also deploy content files to a system directory that members cannot write to. For rules, workflows, skills, and hooks.json, Devin Desktop reads the Devin location first and falls back to the legacy Windsurf location (/Library/Application Support/Windsurf/, C:\ProgramData\Windsurf\, /etc/windsurf/) only if the Devin one is missing. The fallback is evaluated per subdirectory or file, and the two locations are never merged, so move each content type you migrate in full. system.json is read from the Devin location only. If your endpoint security or DLP tooling restricts file access, make sure these paths are permitted; see the directory reference in the FAQ.

What members see

When a control is enforced, Devin Desktop tells the member rather than failing silently:
  • Settings locked by a device policy show as managed by your organization in the Settings editor and cannot be edited.
  • Team settings that remove an option (for example a disabled feature or a model outside the allowlist) hide that option from the relevant picker or settings page.
  • The Extensions view shows a banner naming the marketplace in use and whether it was set by your organization; when an extension allowlist is enforced it also indicates that the setting is managed by your organization.