Nine roles
Owner down to viewer, from fifty-two separate permissions. A person sees only what their role opens, and a denial always beats a grant.
For companies
A flat fee covers everybody who works here. Model usage is billed on top at what it cost us plus 20% — the lowest markup we sell anywhere — with the number on every answer. Here is what a twenty-person company actually pays in a normal month.
Everybody included · single sign-on and SCIM at no extra charge · no seat fee, ever.
A month · 20 people
Enterprise plan — everybody at the company included$99.00
3 people who build every day$41.20
9 people who only ask questions, about 40 each$1.44
8 people who opened it twice$0.84
Total$142.48
The same twenty people on a $60 seat
$1,200.00 a month, whether or not anybody opens it.
The same twenty people here
$142.48 — 8× less, because nine of them only asked questions.
What the company gets
Owner down to viewer, from fifty-two separate permissions. A person sees only what their role opens, and a denial always beats a grant.
Set one for the company and one for each person. At 80% they are warned; at the limit they are stopped and can ask for more from inside the product.
Who did what, when, and by what authority. Refusals are kept in full and unsampled, and the record outlives the person who made it.
OpenID Connect for Okta, Microsoft Entra and Google Workspace, plus SCIM. Deactivate somebody there and their sessions end here immediately.
Projects, deployments and spending history belong to the company. A leaver never deletes anything and nobody can lock you out of your own repositories.
Every model at what it cost us plus 20%, shown per turn. Work that is not urgent goes to the overnight queue, where it costs half.
The arithmetic
A twenty-person company on a per-seat AI subscription pays the same for the person who opens it twice a month as for the person who lives in it. Here the fee is flat and the usage is metered, so the quiet ones cost almost nothing.
How people join and leave
Nobody files a ticket at either end. Your directory is the source of truth, and both directions are included rather than sold as an upgrade.
Requiring single sign-on never applies to an owner. If your identity provider has an outage on a Saturday, somebody can still get in — that is deliberate, and it is not something you have to remember to switch on.
The line between work and their own
Everybody has two. A picker in the sidebar says which one they are in, and it is deliberately loud.
Admins see all of it. It is the company's work, on the company's money.
Not visible from the company side, not on your invoice, and not something an admin can switch into.
What it costs and where it went
Every turn shows what it cost. At the end of the month the same numbers add up by person, by project, by model and by day, and download as a CSV your finance team can bill a department from.
The same 20% on every model, and it is the lowest markup on any plan we sell.
At 80% they are warned; at the limit they are stopped and can ask for more from inside the product, with a reason, rather than by going to find somebody. Open requests are the first thing on an admin's overview.
Spending by employee, project, model and day. Anything we could not attribute to a project is shown as unattributed with its total, rather than folded into the largest bucket.
A rule can send anything above a threshold you choose to the overnight queue, where the same work costs half. It is the control that makes the bill smaller rather than just visible.
Who may do what
Fifty-two separate permissions, grouped into roles that match the jobs people actually have. A denial always beats a grant, at every level — so “this contractor must never touch secrets” stays true whatever anybody grants them next month.
Runs the company. The only role that can make another owner, and the only one that cannot be locked out by your identity provider.
Everything except changing what the company pays or dissolving it.
The budgets and the invoice. Explicitly cannot read source code, data or secrets — the person with the card does not need them to approve a number.
The record of what happened, and nothing that happened. No exports, no secrets, no data.
Single sign-on, domains, suspending people, roles and policy. Not the card.
Their team's spending and budget requests, so those do not all queue behind one admin.
The default. Their own projects, on the company's account.
Nothing by default. Access arrives per project, and always with an end date.
For CI. A token rather than a login, and it survives the person who set it up leaving.
Rules, and the record
Three hundred models only saves you money if you can say no to one. Name the models that may run, cap what a single turn may cost, and send anything above a threshold to the overnight queue automatically. When somebody is stopped they are told which rule stopped them, what it costs, and who can change it — not a policy code.
Every denial is recorded, unsampled. Ordinary reads are recorded once per person per project per hour, and the export says so — a log that quietly samples is worse than one that admits it.
Somebody leaving does not erase what they did, and the address on the row is the one they had at the time rather than whatever it is now.
Freeze a person or a project against the retention sweep, with a reason that has to be written down. Placing and releasing a hold are themselves recorded.
Export is NDJSON with a manifest naming the range, the row count and any filter applied, plus a checksum. If your auditors need the authoritative copy somewhere we cannot reach, we will stream it to your own storage — ask.
The price
Billed annually. $119 a month if you would rather pay monthly — both are founding prices for the first hundred companies, and both are yours permanently for as long as you keep the plan. What it costs after the first hundred is not set yet. Everybody at the company is included whatever the headcount. Usage is billed on top at cost plus 20%.
Hosted apps that run continuously are limited to five, because they hold a slot on real hardware whether or not anybody is using them. Sites, projects and storage are not — those are cheap and are not what we ration. Need it in your own cloud, with data residency, a named contact or an uptime agreement? Those are conversations rather than a checkout page — talk to us.
If you are the person who has to write this up for somebody else — what an enterprise AI platform for your employees actually gives the company, how sign-in and budgets work, and what the security review will ask — that is the page to send them.
Start on your own account, invite one colleague, and watch where the money goes for a week before you decide. Nothing about that first week costs a seat.
Single sign-on and SCIM included · nine roles · the audit log from day one
Questions
$99 a month billed annually, or $119 a month billed monthly. Both are founding prices for the first hundred companies and both are theirs permanently; what it costs after the first hundred is not set yet. Everybody at the company is included; there is no per-seat charge. Model usage is billed on top at what it costs us plus 20%.
No. The flat fee covers everybody at the company. That is the whole point: a per-seat AI subscription charges you the same for the person who uses it twice a month as for the person who lives in it.
Yes, and deliberately. Every person has their own personal space that the company cannot see and does not pay for, and they switch between it and the company's with a picker. Anything they do in the company's workspace is fully visible to admins; anything in their own is theirs and billed to their own card.
Deactivate them in your identity provider and their access ends immediately — not at the end of a session, and not in sixty days. Their work stays with the company and their spending stays in the record, because a departure should not delete the thing they built or the history you bill a department from.
Yes — OpenID Connect, which covers Okta, Microsoft Entra and Google Workspace, plus SCIM for automatic provisioning and deprovisioning. Both are included rather than sold as an enterprise upgrade.
Yes. It is the same builder, the same models and the same machines, with the company layer around it — oversight, budgets, policy and the audit record.