T3 Code is an excellent product with no commercial surface, which means no SSO, no audit log, no organization billing, no DPA, no SLA, and no vendor to hold accountable. If your review requires any of those, you are not looking for a better open-source workbench, you are looking for the same category with a contract attached. The realistic shortlist in August 2026 is Continuum, Conductor, Factory, and the first-party enterprise tiers from Anthropic and OpenAI, and they differ sharply on which controls are self-serve, which are an engagement, and which do not exist. This page scores them on the rows procurement asks about, and states plainly where Continuum fails a row.
- You are not replacing a product. You are adding a counterparty to a product category.
- Ten rows decide most reviews: SSO, provisioning, audit, billing, caps, model policy, data path, deployment, certifications, support.
- Conductor is the shortlist entry with SAML SSO and SCIM today. If SSO is a hard gate, start there.
- Factory brings the certification story: SOC 2 Type II, ISO 27001, ISO 42001, with airgapped deployment as a documented pattern.
- Continuum brings enforced caps and a spend ledger, and has no identity-provider federation today. Both halves of that sentence are load-bearing.
- Ask where each control is enforced, not whether it is listed. A cap that emails you is not a cap.
- The rows nobody asks about until late: who is on the hook when the agent does something expensive, and what the response time is.
What you are actually shopping for
The thing T3 Code does well is worth naming precisely, because the replacement has to do it too. It is a control plane: a single surface that runs several coding agents under the subscriptions you already hold, gives each conversation its own branch, and lets you review and ship the result. It is not a model, not an IDE, and not an autocomplete. If a vendor pitches you an IDE with an agent bolted on, they are answering a different question.
What T3 Code cannot do is be a party to an agreement. There is no company to sign a data processing agreement, no support tier with a response time, no audit export a compliance reviewer can read, and no billing relationship an organization can hold. Those absences are why the enterprise search exists. Everything else about the product is fine.
Two things follow. First, the shortlist is short, because most of the AI coding market sells editors or models rather than control planes. Second, the deciding rows are procurement rows, not feature rows. A product that runs agents slightly better and cannot pass your security review has lost before the pilot starts.
The procurement comparison
These are the rows a joint security and finance review works through. Every cell below reflects what each vendor publishes, checked against primary sources in August 2026. Where a control is an engagement rather than a switch, the cell says so, because that difference decides whether you can turn it on in week one or week twelve.
| Row | T3 Code | Continuum | Conductor | Factory |
|---|---|---|---|---|
| SSO | None | No federation today. WorkOS AuthKit sign-in, Google and Apple | SAML SSO in the Enterprise tier | Enterprise identity and policy enforcement across environments |
| Directory provisioning | None | Invite and role assignment. No SCIM | SCIM in the Enterprise tier | Organization model with service accounts |
| Audit and activity record | Local thread history | Per-session tool calls and fetched URLs, org-scoped | Admin portal in the Teams tier | Audit logging, OpenTelemetry export, analytics API |
| Organization billing | None | One subscription, billed by live member count | Centralized billing in Teams. Purchase orders at Enterprise | Enterprise agreement |
| Enforced spend caps | None | Weekly caps per person, team, and org. Hosted requests return a 429 at the cap | Not published as a cap control | Retention and managed settings. Cost reporting via analytics API |
| Model policy | None | Allow and deny at org, team, and member scope. New models blocked until reviewed | Not published | Enterprise controls and managed settings govern model access and MCP allowlists |
| Hosted inference included | No. Bring your own | Yes, with a weekly allowance per tier, or bring your own keys | Bring your own API keys on Free. Cloud workspaces on paid tiers | Model independent, with gateway and cloud provider routing |
| Deployment options | Self-host the control plane yourself | Hosted. On-prem as a scoped Enterprise engagement | Hosted | Cloud, hybrid, or airgapped patterns |
| Certifications | None published | None published | Custom security and privacy settings at Enterprise | SOC 2 Type II, ISO 27001, ISO 42001 |
| Support commitment | Issues and Discord | Highest priority support and dedicated account management at Enterprise | SLA and dedicated support channels at Enterprise | Enterprise support |
Two rows deserve a second look because vendors present them inconsistently. "Audit" ranges from a session record you can query to a full OpenTelemetry stream you can land in your own SIEM, and those are not the same purchase. "Spend caps" ranges from a dashboard alert to a request that is refused before it leaves. Ask for a demonstration of the refusal, not a screenshot of the setting.
The five questions T3 Code cannot answer
If you want to compress the evaluation, these are the questions that separate a governed control plane from a very good free one. They are also the questions that will arrive from your own security team whether or not you ask them first.
Who is the counterparty?
A DPA needs a company to sign it. An SLA needs someone to breach it. An indemnity needs a balance sheet. T3 Tools publishes terms, a privacy policy, and a security policy for T3 Code, and none of that is the same as a negotiated agreement with your organization. This question alone ends the evaluation for most regulated buyers, before any feature is discussed.
Where is the enforcement point?
For every control on your list, ask which component refuses the action. A model allowlist enforced in a managed settings file the user cannot override is a control. The same list in a wiki is a preference. A budget checked before a request leaves a gateway is a control. A budget checked nightly against yesterday’s usage is a report. Our governance guide works through the seven controls and where each is enforced.
What happens to credentials when someone leaves?
The honest answer for any bring-your-own-subscription tool is that the credential lives on the laptop and only the laptop can revoke it. Governed platforms differ in how much of that they can reach centrally. Ask specifically about provider access, device sessions, API tokens, and any stored content. Ask for the sequence, not the claim.
What can you show an auditor twelve months from now?
Retention is the part everyone forgets. A session record that exists but rolls off in thirty days does not answer a question asked in the following fiscal year. Ask for the retention window and the export format in the same breath.
Who pays when an agent runs away?
Every organization running coding agents eventually has the week where a loop burns a month of budget. Ask each vendor what stops it, at what threshold, and what the recovery path is. Then ask whether the answer is a cap that refuses or a notification that arrives. You can model the difference with the spend cap simulator before you sit in the meeting.
Where Continuum fits, and where it does not
Continuum is the entry on this list that is built around the money and the operating loop rather than around certification. That is a real position and it is not the right one for every buyer.
What it does well for an enterprise evaluation: model policy resolves at organization, then team, then member, where a lower scope can narrow access but never reopen what a higher scope denied, and a newly released model stays blocked until an admin reviews it. Weekly caps exist per person, per team, and organization-wide, and a hosted request past the cap is refused with a 429 rather than logged. Members can request more and an admin can approve part of the request in one click. One ledger shows who ran what, on which model, under whose key, and at what cost, across both gateway traffic and your own keys, exported as a dashboard, a CSV, or a scoped API token. Offboarding cuts provider access, revokes devices and tokens, and destroys the content key in a single step. Your own Anthropic and OpenAI contracts can sit underneath all of it as pass-through admin keys, verified on arrival, sealed, and never shown back beyond a fingerprint.
What it does not do, stated as plainly as the organizations page states it: there is no identity-provider federation and no directory sync today. Hosted cap decisions are admin-only by design, so a team lead cannot raise a hosted ceiling. Org-wide network allow and block lists are scoped as part of an Enterprise engagement rather than shipped as a self-serve setting. On-prem is an engagement, not a download. And there are no published third-party certifications, which for some buyers is the end of the conversation and for others is a question about roadmap.
| Tier | Per member, per month | Included hosted allowance, per week |
|---|---|---|
| Plus | $25 | $25 |
| Max 100 | $100 | $100 |
| Max 200 | $200 | $200 |
| Ultra | $500 | $1,000 |
One subscription, billed by live member count, with mixed tiers on the same organization. Past the included allowance, overage is prepaid at cost with no markup, and a member with overage switched off simply stops at the cap rather than accruing. Price your own headcount with the team cost calculator before comparing against a per-seat quote, because the shapes are different and a naive per-seat comparison usually flatters the wrong vendor.
Running the evaluation
A pilot that produces procurement evidence looks different from a pilot that produces developer enthusiasm. Run this one.
Gate on the eliminating rows first
Take your two or three non-negotiables from the procurement table, usually SSO, a certification, or a deployment pattern, and remove every vendor that fails them before anyone installs anything. This is a fifteen-minute exercise that saves a month.
Demand a refusal, not a setting
For each surviving vendor, ask them to demonstrate a request being blocked by a model policy and a request being refused by a spend cap, live. Watch for the error, not the dashboard. Many products in this category will pass the first and fail the second.
Run one real repository for two weeks
Same repository, same three engineers, same class of ticket, on each finalist. Anything shorter measures novelty. Track completion, review load, and whether the control plane got in the way of the review loop, which is where most of these products actually differ.
Pull the audit export and hand it to security cold
Do not narrate it. Give your security reviewer the raw export and ask whether they can answer "what did the agents touch in this repository last week" from it alone. If they cannot, the audit row is a marketing claim.
Run the offboarding drill
Pick a pilot participant, offboard them for real, and time how long it takes to prove every credential is dead. Do this before you sign, because after you sign it becomes an incident rather than a test.
Compare the total, not the seat price
Add the subscription, the inference, the administration time, and the migration cost. A free product with a day a month of reconciliation is not free, and a governed product that removes the reconciliation is not just a line item. The cost allocation guide has the model.
And keep the honest option on the table throughout: if none of your eliminating rows actually bind, the correct outcome of this evaluation is to keep using T3 Code and spend the money elsewhere. That happens more often than vendors like to admit, and it is a legitimate result. The teams page has the thresholds where it stops being the right answer, and the product comparison covers the places T3 Code wins outright.
Questions people ask
Does T3 Code have an enterprise version?
No. T3 Code has no paid tier of any kind. It is free and MIT licensed with no organization features, no SSO, no audit export, no DPA, and no support agreement. There is no enterprise edition to upgrade to.
Can we self-host T3 Code and add our own controls?
Yes, and it is a legitimate strategy. npx t3 serve runs the backend headless and the MIT license lets you fork it. You are then building and maintaining the identity, policy, audit, and billing layers yourself, which is a real engineering commitment rather than a configuration exercise.
Which alternative has SSO today?
Conductor publishes SAML SSO and SCIM as part of its Enterprise tier, alongside a DPA, purchase-order billing, and dedicated support channels. Factory documents enterprise identity and policy enforcement with SOC 2 Type II, ISO 27001, and ISO 42001. Continuum does not have identity-provider federation today.
Does Continuum have SSO?
No, not today. Sign-in and invitations run on WorkOS AuthKit with Google and Apple login, and there is no screen for federating your own identity provider or syncing a directory. Removing someone in WorkOS is what triggers offboarding: provider access blocked, devices and tokens revoked, and the content key destroyed.
Do our prompts pass through the vendor?
For Continuum it depends on the path. Hosted traffic proxies through the gateway on purpose, because that is what makes a cap enforceable. Direct and bring-your-own-key sessions run machine to provider and send usage only. Ask every vendor this question in exactly this form, because the answer determines what their controls can and cannot enforce.
Can we bring our own Anthropic and OpenAI contracts?
With Continuum, yes. An admin adds your Anthropic and OpenAI admin keys, each is verified before storage, sealed under its own data key, and never shown again beyond a fingerprint. Provisioning and enforcement act through those keys, so the provider contract stays yours.
Is on-prem deployment available?
Factory documents cloud, hybrid, and airgapped deployment patterns. Continuum offers on-prem as a scoped Enterprise engagement rather than a download, with an option that extends to specifying and deploying GPU hardware. T3 Code is self-hostable by anyone, with no vendor involvement of any kind.
What if we only need better cost control, not full governance?
Then buy the narrow thing. A gateway with per-person keys and enforced budgets solves the money problem without a governance programme attached. Our guides on AI spend management and cost allocation cover that path.
Sources
Every figure above was read from these pages on August 2026. Vendors reprice without notice; if you find a stale number, tell us.