Organizations, roles, audit logs, and spend limits
The controls available today, each labeled live, in progress, or roadmap.
What teams get today
- Orgs with owner / admin / member / viewer roles
- Email invites with expiring tokens, audit-logged
- Per-user spend limits and analytics opt-out
- API keys stored hashed, rotatable from /api-keys
- Shared org agent feed: every run across the team
capabilities
Feature status
Live means it works now. Roadmap means we are building it, and we will scope timelines with you.
Organizations, roles, and RBAC
Owner, admin, member, and viewer roles per organization. Invite by email, change roles, remove members; every change lands in the audit log.
Audit logs
Settings changes, invites, role changes, and membership removals are recorded per user and per org, queryable from the API and settings.
Spend limits
Per-user spend limits are live in settings. Per-workspace limits, capping every member under one budget, are roadmap.
API key management
Scoped, rotatable keys, plus bring-your-own provider keys for the gateway. Keys are stored hashed; plaintext is shown once.
SSO / SAML + SCIM
Google and GitHub sign-in are live. SAML SSO and SCIM directory sync are roadmap for the contact-sales tier. Talk to us if this is a blocker.
Private networking
Dedicated network segments and private egress between your apps, addons, and agents. Roadmap; today each container is isolated with scoped credentials.
Data residency
A default GPU region (US or EU) is selectable in settings. Hard residency guarantees that pin data and inference to a jurisdiction are roadmap.
BAA / DPA
A standard DPA is available on request. Healthcare BAAs are handled case by case on the contact-sales tier.
compliance posture
Compliance status
| Item | Status | Detail |
|---|---|---|
| SOC 2 Type II | in progress | Controls are being implemented and evidence collected; no report yet. We will not claim certification before it exists. |
| Data processing agreement (DPA) | on request | Standard DPA covering GDPR processor obligations, available for any paid plan via [email protected]. |
| Data export and deletion | live | Export or delete your account from settings; both are audit-logged. |
| Subprocessor list | live | Published on the security page, kept current as infrastructure changes. |
Security questionnaires, DPAs, and scoped pilots go to [email protected] — the people who run the infrastructure.
Start with an organization
Create an org, invite your team, and tell us which roadmap item you need.