Your team's favourite models.
With enterprise controls.

Pick the models. Set the caps. Manage AI usage and spend. Your team keeps the tools they already use.

ModelTeam
01 · Model access

Control which models your teams use.

Allow models for the whole organization, one team, or one person. New models stay blocked until you approve them.

model check · dana@acme enforce
model
organization Approved catalog14 model ids · deny *-preview
team Platformnarrowed to 6 · lead marcus@acme
member dana@acmenothing set for this member
resolving

Blocked at the top means blocked everywhere.

dana@acme · weekly hosted$0.00 / $25

rolling 7 days, not a calendar week

429 weekly_budget_exhausted
"Weekly hosted-inference budget reached."
admin · requests1 open
Dana R.requests $100/wk · platform

Approve all of it, or just some.

02 · Caps and requests

Set caps that hold.

Weekly caps per person, per team, and org-wide. Hosted requests stop at the cap. People ask for more; you approve in one click.

One subscription · billed by live member count
Plus · $25 a month$25 a week included
Max · $100 and $200$100 and $200 a week
Ultra · $500 a month$1,000 a week
Past the allowanceprepaid, at cost, no markup
See the tier ladder →
03 · The ledger

See every dollar.

Who ran what, on which model, and what it cost. One view.

whoran an agent today
which modeland under whose policy
how muchthis week, per person
whose keypaid for the run
usage · acme · $0
7d30d
through our gateway $0on your own keys $0measured, not estimated
Spend by member

Same week, by provider, model, or team.

Dashboard, CSV, or a scoped API token. Your FinOps stack plugs straight in.

04 · The gateway

Your team keeps their tools.

Continuum speaks the OpenAI and Anthropic APIs, streaming included. Codex, Claude Code, and the official SDKs just work.

Every member gets their own key, so caps and usage attach to a person.

dana@acme — zsh
$
$
$
POST /v1/responses200 claude-opus-5
policy allowed · team platform
spend $0.31 → dana@acme · hosted

No SDK swap, no proxy config, no code change. One variable.

provider keys · acme org scope
Anthropic verified
sk-ant-admin-••••
sealed · fingerprint a41f c9
OpenAI verified
sk-admin-••••
sealed · fingerprint 7b02 3e

Sealed on arrival. Never shown back.

05 · Your enterprise keys

Your keys, or ours.

Bring your Anthropic and OpenAI keys as a pass-through, or use ours. Same controls either way.

06 · Model activity

See everything your agents touch.

Every tool call, every file, every URL. On the record.

Org-wide allow and block lists come with Enterprise.

session activity · dana@acme network rules · Enterprise

Logged today. Block lists with Enterprise.

Platform
$1,400
Product
$960
Data
$620
Growth
$280

Four teams, one weekly dollar axis, $3,260 total. Each tick is that lead's ceiling: $2,000, $1,500, $1,000, $600.

3roles, no custom tiers
1team per member
2numbers bound a lead
WorkOSsign-in and invites
07 · Roles and provisioning

Admins, leads, members.

Invite people, appoint leads, set their limits. Leads approve within them.

Offboarding cuts access, keys, and devices in one step.

08 · Where the line is

Your data stays yours.

Direct traffic runs laptop to provider. We see usage, not content.

Remote control is end-to-end encrypted. Everything stored is encrypted and scoped to your organization. Security

forced RLSevery tenant table
AES-256-GCMtranscripts at rest
XChaCha20owned-device relay
hashedevery key we store
PATH 01 · HOSTED

We are in the path

Your key, our route. Policy and budget are checked before the request leaves, which is what makes the cap hard.

PATH 02 · DIRECT / BYOK

We are not in the path

Your keys, your subscriptions, laptop to provider. We see usage, and we act inside your Anthropic and OpenAI accounts. Real control, and a smaller kind of it.

09 · Plans
Team

$25 / member / month

Hosted. The base weekly allowance.

Seats

5 seats × $25 = $125 / month

Get Team Everything in the personal plans, plus:
  • Model policy by team and person
  • Weekly caps and approvals
  • Usage and spend, one view
  • OpenAI- and Anthropic-compatible APIs
  • Your keys or ours
  • One subscription, billed by member count
Enterprise

Let's talk

Book a demo Everything in Team, plus:
  • Dedicated account management
  • Highest priority support
  • On-prem deployment
  • Custom inference, including GPU installation and management
NVIDIA AMD Instinct Cerebras
10 · Questions

Questions.

Short answers here. The long ones are in the docs.

Yes. Policy runs organization, then team, then member, with allowlists and deny patterns at each scope. A lower scope can narrow access but never re-open what a higher scope denied, and new models stay blocked until an admin reviews them.

No. One subscription, billed by your live member count, with an included weekly allowance per tier: $25 a week on Plus, up to $1,000 a week on Ultra. Past the allowance, overage is prepaid at cost with no markup, and a member with overage switched off simply stops at the cap.

No, not today. Sign-in and invitations run on WorkOS AuthKit, with Google and Apple login, and there is no screen for federating your own provider or syncing a directory. Removing someone in WorkOS is what triggers offboarding: provider access blocked, devices and tokens revoked, content key destroyed.

Yes on hosted, no on direct. Hosted proxies content through our gateway on purpose, because that is what makes a cap enforceable. Direct and BYOK sessions run machine to provider and send us usage only. Transcript sync, if you turn it on, stores pages encrypted at rest under a per-member key. Encrypted, not zero knowledge.

No. Hosted cap decisions are admin-only by design. A lead can approve a subscription request from their own team, up to their ceiling, and set budgets within the ceiling an admin gave them; past that the backend refuses.

Yes. An admin adds your Anthropic and OpenAI admin keys; each is verified before storage, sealed under its own data key, and never shown again beyond a fingerprint. Provisioning and enforcement act through those keys, so the contract stays yours.

No, not as a self-serve setting today. Every session captures the tool calls an agent made and the URLs it fetched; org-wide allow and block lists are scoped as part of an Enterprise engagement.

Yes, as a scoped Enterprise engagement rather than a download. One offer scopes a private deployment of the same single-tenant stack we run in production. The other adds the hardware: we spec, purchase, and deploy a GPU cluster on NVIDIA, AMD Instinct, or Cerebras, then commission your gateway on it.

11 · Begin

Put your team on it.

One subscription, billed by your live member count. Set the models, the caps, and the roles once your people are in.

or book a demo

model policy · weekly caps · approvals · compatible apis · enterprise engagements