Only the models you approved.
Every organisation is now running models somebody chose, on accounts somebody connected, at prices somebody agreed to, and most of them cannot say which. You can. One list of what is allowed to run, where each one was made, and who said yes to it.

One list, and it belongs to the organisation
The models that may run are one list, kept for the whole organisation rather than per project. A team can be narrowed to fewer of them, and narrowing is all a team rule can do: nothing below the organisation can add a model back. The model that answers when a request does not name one has to be on the list too, and the platform refuses to set a default that is not on it.
- A project can record which models it means to use. That is a statement of intent, and it is not the fence: the organisation's list is what a call is checked against.
- Approving and removing are one write with a check on the version underneath, because two humans approving at once used to erase each other.
Enforced, or advice, and the switch is on the record
Enforcement is a switch, and it starts on. While it is on, a request for a model nobody approved is turned down before anything reaches the model, and an organisation that has approved nothing calls nothing rather than quietly falling back to something. Turn it off and the list becomes advice: anything in the catalogue can be called. Turning it off is written to the same record as everything else, with the name of the administrator who did it.
- A refusal is recorded like an action, with a reason a machine can read, so the calls that did not happen are countable too.
- Only an administrator can move the three switches: enforcement, whether humans may bring their own provider account, and whether models on your own machines are allowed.
Approving is a permission, not a promise
An approved model can still be unable to answer, and the honest thing is to say which. It may need a provider account nobody has connected. It may not be a model that writes text at all. The list carries a state and a reason for every entry, checked against the catalogue rather than assumed, so a broken entry is found here instead of by the human whose message failed.
- When the catalogue cannot be reached, the list says the entries were not checked. It does not show them as fine.
- An approved id that is not in the catalogue at all has no row anywhere else, which is why this list shows everything rather than only what works.
Where each model was made
A model's id tells you which model ran. It does not tell you who made it or where. Every model resolves to a maker, a country and a region, and one of the checks a project is measured against is that every model it runs has an origin that resolved. An id nothing can be traced to is reported as untraced, never guessed from its name, and a project carrying one fails that check by name rather than passing quietly.
- The names that route a model are kept apart from the names that made it, so a service that only carries a model is never reported as its maker.
- The check is mapped to the clauses it partly answers, along with what it does not answer. Origin is not the whole of a supplier obligation and the mapping says so.
Whose account it runs on
Some models are included and billed by use, with nothing to set up. Others run on a provider account you bring, and there are two ways to bring one. Connect the provider and the key is held in the vault of the sign-in service and used for each call without being kept here; disconnecting stops every call at once. Register one from the command line instead and it is kept here, opened only inside the call it serves, and returned by no page and no interface.
- What a human can see either way is the provider's name and the last four characters. There is no screen anywhere that shows a key back.
- Whether humans may bring their own account at all is one of the three switches, and it is an administrator's to set.
What one call leaves behind
Every call writes one line: which model, who made it, which project it belonged to, how many tokens went in and came out, how long it took, what it cost at the price published that day, and whether it ran on your own account or ours. The call is assigned to a named human, or to a named AI agent together with the human it was acting for. The project is stamped from the caller's own binding and cannot be set by whoever is calling.
- The words are not kept. No prompt and no answer is stored on this record, and the table it feeds has no column one could be put in.
- A model with no published rate reads as unpriced, never as nothing. A figure nobody can stand behind is worse than an absence.
- The prices carry the date they were last checked, and the product says so when they are getting old.
Who approved it, and when
Each model has a record of its own: what it is, what it costs per million words-worth, which projects have called it in the last thirty days and how much, who called it last, and every time somebody approved it or took it off, assigned to them with the time. Taking a model off stops new calls to it straight away. That history is the same record everything else on this platform lands on, sealed in windows so that a later edit to it shows.

An AI agent is a model with a brief and a ceiling
A named AI agent is a brief, the tools it may use, and a model to run on, picked from the approved list. Give it a cheaper model to fall back to and the expensive one is only asked when it is needed, and give it a monthly ceiling of its own so a bad afternoon has a floor under it. Every run is kept step by step: each model turn and each tool call, with its own tokens and its own elapsed time, and the times are the real ones rather than tidied up for the picture.
- A new AI agent does not run until somebody approves it, which is a separate decision from approving the model underneath it.
- The refusal happens when the call is made, not when the AI agent is written down. A brief naming a model nobody approved is refused at the call, with the reason.
What is outside this, and it matters
Models running on your own machines are outside all of it: those calls are not measured and not checked against the list, which is why permitting them is a switch an administrator sets and the platform writes down. Work done in somebody else's chat window leaves no trace here either. This record describes the calls that came through this platform, not every call your organisation made, and the page that shows it does not pretend otherwise.
Bring the list of models you allow, and we will show you the record behind it.
Also in Governance
- ApprovalsAnything that cannot be undone is assigned to a human.Read the page
- Audit trail and evidenceWho did what, on a sealed record, exported when someone asks.Read the page
- AI agent securityA name, a limit, and somebody who can stop it.Read the page
- AI agent identityA human lets an AI agent in, and can stop it again.Read the page
- What an AI agent may doIt never reaches further than the human it works for.Read the page
- AI agent sign-insA sign-in expires sooner the more it can do.Read the page
- Scans and approved packagesApproved packages at the exact version, checked when used.Read the page