AI Model Allowlist: Which Vendors See Your Prompts

An AI model allowlist decides which providers may serve your prompts. In Insulin it fails closed — and one missing row removes Suger's hosted models.

Sophia Faria
Sophia Faria
Sep 19, 2026

An AI model allowlist is the list of AI providers your organization permits to serve its prompts. In Insulin it sits beside a second switch — whether Suger’s own keys may be used at all — and both fail closed.


“Which AI vendors will see our prompts?” is usually a security reviewer’s first question about an AI workspace; the second is whether everything can run on the organization’s own keys. Insulin answers both with a setting rather than a promise: Settings → Organization → AI Model Policy, which only an org ADMIN can change.

What the AI Model Policy controls

The AI Model Policy is the organization setting that decides which AI providers may serve your organization, and in what order. It holds two controls:

ControlThe question it answersDefault
Allowed AI integrationsWhich vendors may see our prompts?Empty: “No restriction — every connected provider is allowed.”
Allow Suger platform keyMay Suger’s own keys be used at all?On

Add providers from the Add integration dropdown, order them with Move up and Move down, and Save. AI features may use only the integrations listed, and the top row, badged Default, is the organization default for any feature without a model picker of its own. The AI Model Policy reference covers the tab in full.

Does connecting your own key keep prompts off hosted models?

No. Connecting your own provider makes its models preferred, not exclusive. They take priority, but the Suger-hosted models remain what the documentation calls “the fallback the turn degrades to” when your providers fail. That keeps work moving on a provider’s bad day — and it is exactly what an “only vendors we contract with” policy rules out.

The row that keeps the hosted pool

A non-empty allowlist must include Suger Hosted (DeepInfra), or the Suger-hosted models stop being offered. Every hosted model resolves through that one integration, and an integration missing from a non-empty list fails closed. Add the entry to keep the pool — “it admits the pool, and nothing more” — or leave it off to drop it.

Rows are integrations, not models

Each row admits an integration, so review it as a vendor relationship. A row can be a model provider such as Anthropic or OpenAI; an open-source model aggregator such as OpenRouter, Baseten or Together AI, which can expose hundreds of models behind that one row; or Suger Hosted (DeepInfra), the hosted pool on Suger’s key, which is not the same thing as connecting your own DeepInfra key.

The allowlist decides which providers receive requests, not what a provider does with one. That sits in each provider’s terms.

What turning off Suger’s key changes

Turning off Allow Suger platform key makes the organization bring-your-own-key (BYOK) only. Left on, Suger’s shared keys can serve an allowed provider you have not connected your own key for. Off, every AI call must use one of your own connected keys, and an allowed provider without one fails closed rather than falling back to Suger. The documentation calls that “a guarantee, not a preference.”

The fallback it removes reaches beyond chat: an organization knowledge base whose provider is unavailable at its first index can fall back to a hosted model, and Inbox uses hosted models as its last resort.

Ownership decides whose keys remain. The built-in Insulin assistant and personal agents use each person’s own connections and never reach the organization’s keys; organization agents use the organization’s.

When the hosted pool steps down a tier

The Suger-hosted tier step-down is a spend threshold, not a setting. Once your organization’s spend on Suger’s key passes about $300 in a billing period, the hosted pool withholds its Tier 1 quality model for the rest of that period and serves its lighter Tier 2 models, with no banner and nothing refused. Suger sets the figure; your organization cannot configure it. Own-key usage is not counted, and connected providers are always preferred, so an organization on its own keys never meets it. The model resolution chart puts all three checks in order.

Which setting matches your goal?

Pick the row for your goal; the last column is what comes with it.

Your goalSet thisWhat else changes
Any connected provider, hosted pool as fallbackNothing; these are the defaultsHosted turns get Tier 1 until the step-down, then Tier 2
Named vendors, hosted pool keptList them plus Suger Hosted (DeepInfra)The top row becomes the default. Saving an agent with a Default model on an unlisted provider is refused for AI policy. The app builder hides Suger’s key rows from unlisted providers; Your key rows on them still show but are rejected when the app runs
Named vendors, no hosted poolList them without Suger Hosted (DeepInfra)As above, and no turn reaches the hosted pool. For an own-key guarantee, also turn the platform key off
Every call on our own keysTurn Allow Suger platform key offHosted models leave the pickers, embeddings included, so a BYOK-only organization with no embedding provider cannot create a knowledge base. Allowed providers without a connected key fail closed

What people see when no model is left

Chat stops with a message; Inbox just goes quiet.

  • The built-in Insulin assistant, in a one-on-one chat, replies “I can’t chat yet — your account doesn’t have an LLM provider connected,” whatever emptied the list.
  • Any other agent, one-on-one, shows an error card naming the cause. With hosted models disabled, it reads “No model available for your account: your organization has disabled Suger’s hosted models and you have no personal AI provider connected.”
  • In a channel, one agent without a model stops the whole turn.
  • Inbox shows no error. It “simply looks quiet,” and a rule’s Preview names the missing model first.

What to check before turning Suger’s key off

Line up keys, embeddings and people first, because after the switch every gap fails closed.

  1. Match every row to a key. A row marked not connected has no organization key behind it.
  2. Put the default on top. It serves every feature without a model picker of its own.
  3. Connect an embedding provider — OpenAI, Gemini, OpenRouter, DeepInfra, Fireworks or Together — for the organization, and per person for personal knowledge bases.
  4. Decide about knowledge bases on hosted models. The default embedding model is the Suger-hosted BGE-M3. Change model re-embeds every document, at provider time and spend, and a document is missing from search until it is re-embedded.
  5. Give each person a model. The built-in assistant, personal agents and Inbox need a provider of the person’s own; an organization agent shared with them runs on the organization’s keys instead.
  6. Review agent Default models. The policy check on save runs only when the model changes, so an excluded pin survives unrelated edits.

Frequently asked questions

What is an AI model allowlist?

An AI model allowlist is the list of AI providers an organization permits to serve its prompts. In Insulin it is the ordered Allowed AI integrations list under Settings → Organization → AI Model Policy. An empty list means no restriction.

Does adding a provider to the allowlist remove Suger-hosted models?

Yes, unless Suger Hosted (DeepInfra) is on the list too. Every hosted model resolves through that one integration, and an integration missing from a non-empty list fails closed. Adding the entry admits the pool without pinning a model.

What does turning off the Suger platform key do?

It makes the organization bring-your-own-key only. Every AI call must use one of your own connected keys, and an allowed provider with no connected key fails closed instead of falling back to Suger.

Why can the built-in assistant stop working when the platform key is off?

It never draws on keys the organization connected. The built-in assistant and personal agents run on providers each person connects, so with the platform key off, someone with none connected has no model to run on.

Does the Tier 1 step-down apply to our own keys?

No. Only spend on Suger’s key counts toward it, and connected providers are always preferred over the hosted pool, so an organization running on its own keys never meets it.

Takeaways

  • The allowlist decides which providers may serve you; the platform key decides whether Suger’s keys may be used at all.
  • Your own key is preferred, not exclusive, until the policy removes the fallback.
  • A non-empty list without Suger Hosted (DeepInfra) drops the hosted pool.
  • BYOK-only is a guarantee with side effects, so run the checklist before you switch.

The policy draws the boundary, and each agent picks its model inside it. For choosing by risk, see AI model governance by workflow risk; for the commercial side, BYOK vs managed models; for failover, who picks the model. Scoping each agent starts on the Insulin agents page.

Sources

Primary sources for the platform rules cited above. Last verified September 19, 2026. Cloud providers change fees, eligibility, and program terms without notice — check the source before relying on a figure.

Browse every post on the Insulin Blog

Stay Updated

Get the latest Cloud GTM insights, product updates, and marketplace strategies delivered to your inbox.