Connection types
AI apps connect to approved tools and knowledge without changing their existing model. Software connects to company models with a separate OpenAI-compatible API key.
| Type | Purpose | Credential |
|---|---|---|
| AI app | Approved tools and knowledge; the app keeps its existing model | User OAuth |
| Model API | Smart, Fast, Low cost, and approved custom aliases | One-time gateway key |
- Recipes are available for Claude, Codex, OpenClaw, Hermes, and other supported hosts.
- The ChatGPT recipe reports current workspace-plugin availability.
- Model API keys use all enabled aliases by default; Advanced can limit a key to selected aliases.
- Model API keys do not receive MCP tool access.
| Field | Value |
|---|---|
| App | Human-readable connection name |
| Person | Optional accountable workspace user |
| Environment | Production, development, interactive, or a custom label |
| Workflow | Optional process such as incident triage or weekly reporting |
Budgets
The managed service allowance is the outer ceiling. A company can add a lower company guardrail, shared department budgets, personal budgets, and connection limits. The strictest applicable limit wins and blocks the next request once reached.
Reports and activity records
The workspace summarizes spend, remaining allowance, request volume, success rate, model aliases, connections, tool actions, decisions, outcomes, and typical latency. Prompts, responses, tool inputs, and tool results stay out of these records.
Security delivery
Download activity as CSV or configure a signed SIEM destination for metadata-only tool events. Delivery failures remain visible without exposing credentials.
Connection diagnostics
Diagnostics identify the failing layer and the action required to restore a connection.
- Workspace configuration
- Client authorization
- Provider sign-in
- Runtime reconciliation
- Upstream provider health