Click a switch this is exactly how admins enable or restrict a model in the registry per department enforced on the very next request.
Model allowlisting
- IT and security teams choose which models are approved company-wide in the admin model registry.
- PixSpace enforces the allowlist automatically at the request level every chat and API call passes a model-access check before it runs, so no manual policing is required.
Team-level permissions
- Different departments (legal, engineering, marketing) can be given access to different model sets based on data sensitivity and use case.
- Access changes take effect immediately, with no engineering ticket needed.
- Employees request access to additional models in-app; admins approve or reject from the console no email chains.
Usage visibility
- Every model call is logged, so leadership can see which models are actually being used, by whom, and how often with token counts and computed cost per request, so spend is attributable down to the person.
Where this fits
Frequently asked questions
Can access rules differ by department?
Yes. Each department can be given a different set of approved models based on their data sensitivity and use case.
Does blocking a model require an engineering change?
No. Admins toggle access centrally in the console and it applies immediately, with no code or ticket required.
Can we see which models are actually being used?
Yes. Every request is logged, giving leadership visibility into real usage by model, team, and person including token volume and cost.
Which model providers are supported?
Models are served through AWS Bedrock inside your own AWS account Anthropic Claude and Amazon Nova today, with the registry built to enable additional Bedrock models as you adopt them. Prompts never leave your account or train any model.
