Skip to content

Models

A model is the underlying AI an agent uses to think. Your organization is granted a set of models it's entitled to use, and every agent is assigned one from that set — see Key concepts.

Owners and admins manage that set from Organization → Models.

Turning models on and off

The Models page lists every model available to your organization — models your platform operator has made available to everyone, plus anything granted to your organization specifically, all subject to your plan. Each row shows:

  • Name and Provider — which vendor or hosting path serves the model.
  • Global — the model's platform-wide status (active, experimental, or disabled). This is set by your platform operator, not by you.
  • Enabled — a switch for your organization. Flip it off to stop an agent from being assigned that model; flip it on to make it available again.

A model your platform operator has disabled or deprecated shows its switch locked off — that's a platform-wide decision your organization can't override. If a model you expect to see is missing entirely, ask your platform operator to grant it to your organization.

Turning a model off here doesn't change what any agent is doing right now; it stops the model from being offered the next time someone assigns a model to an agent.

Assigning a model to an agent

Model assignment happens per agent, from that agent's Settings page (owners and admins only) — pick any model your organization currently has enabled. See Working with agents.

Bringing your own key (BYOK)

Below the models table, Provider credentials lets you connect your own API key for a model provider — OpenAI, Anthropic, Google, Mistral, Cohere, OpenRouter, or AWS Bedrock — so agents can call that provider under your own account and billing instead of the platform's.

  1. Click Add credential and pick a provider.
  2. Most providers just need a single API key. AWS Bedrock instead asks for an access key ID, a secret access key, and a region, since Bedrock authenticates differently from the others.
  3. Save. The credential is encrypted at rest and never shown again — if you need to change it, remove it and add a new one.

You can remove a saved credential at any time from the same list. Every model call — whether it's billed to the platform or to a BYOK credential — is still routed through our guardrails layer, so your guardrail settings keep applying either way.

See also