---
title: "AI Model Allowlist: Which Vendors See Your Prompts"
url: https://www.insulin.dev/blog/ai-model-allowlist/
canonical: https://www.insulin.dev/blog/ai-model-allowlist/
type: Blog
description: "An AI model allowlist decides which providers may serve your prompts. In Insulin it fails closed — and one missing row removes Suger's hosted models."
---

# AI Model Allowlist: Which Vendors See Your Prompts

> Canonical HTML version: https://www.insulin.dev/blog/ai-model-allowlist/

1.  [Home](/)
2.  /
3.  [Blog](/blog/)
4.  /
5.  AI Model Allowlist: Which Vendors See Your Prompts

# AI Model Allowlist: Which Vendors See Your Prompts

An AI model allowlist decides which providers may serve your prompts. In Insulin it fails closed — and one missing row removes Suger's hosted models.

![Sophia Faria](/authors/sophia-faria.jpg)

Sophia Faria

Sep 19, 2026

 ![AI Model Allowlist: Which Vendors See Your Prompts](/images/blog/ai-model-allowlist/hero.png)

Explore AI Summary

 [![](/logos/company/openai.svg)](https://chat.openai.com/?q=Read%20and%20summarize%20https%3A%2F%2Fwww.insulin.dev%2Fblog%2Fai-model-allowlist%2F%2C%20then%20cite%20the%20source.%20Focus%20on%20what%20it%20says%20about%20Trust%2C%20Security. "Summarize with ChatGPT")[![](/logos/company/anthropic.svg) ](https://claude.ai/new?q=Read%20and%20summarize%20https%3A%2F%2Fwww.insulin.dev%2Fblog%2Fai-model-allowlist%2F%2C%20then%20cite%20the%20source.%20Focus%20on%20what%20it%20says%20about%20Trust%2C%20Security. "Summarize with Claude")[![](/logos/company/gemini.svg)](https://www.google.com/search?udm=50&aep=11&q=Read%20and%20summarize%20https%3A%2F%2Fwww.insulin.dev%2Fblog%2Fai-model-allowlist%2F%2C%20then%20cite%20the%20source.%20Focus%20on%20what%20it%20says%20about%20Trust%2C%20Security. "Summarize with Gemini")[](https://www.perplexity.ai/search/new?q=Read%20and%20summarize%20https%3A%2F%2Fwww.insulin.dev%2Fblog%2Fai-model-allowlist%2F%2C%20then%20cite%20the%20source.%20Focus%20on%20what%20it%20says%20about%20Trust%2C%20Security. "Summarize with Perplexity")

Table of Contents

-   [What the AI Model Policy controls](#what-the-ai-model-policy-controls)
-   [Does connecting your own key keep prompts off hosted models?](#does-connecting-your-own-key-keep-prompts-off-hosted-models)
-   [The row that keeps the hosted pool](#the-row-that-keeps-the-hosted-pool)
-   [What turning off Suger’s key changes](#what-turning-off-sugers-key-changes)
-   [When the hosted pool steps down a tier](#when-the-hosted-pool-steps-down-a-tier)
-   [Which setting matches your goal?](#which-setting-matches-your-goal)
-   [What people see when no model is left](#what-people-see-when-no-model-is-left)
-   [What to check before turning Suger’s key off](#what-to-check-before-turning-sugers-key-off)
-   [Frequently asked questions](#frequently-asked-questions)
-   [Takeaways](#takeaways)

_An AI model allowlist is the list of AI providers your organization permits to serve its prompts. In Insulin it sits beside a second switch — whether Suger’s own keys may be used at all — and both fail closed._

* * *

“Which AI vendors will see our prompts?” is usually a security reviewer’s first question about an AI workspace; the second is whether everything can run on the organization’s own keys. Insulin answers both with a setting rather than a promise: **Settings → Organization → AI Model Policy**, which only an org **ADMIN** can change.

## What the AI Model Policy controls

**The AI Model Policy is the organization setting that decides which AI providers may serve your organization, and in what order.** It holds two controls:

Control

The question it answers

Default

**Allowed AI integrations**

Which vendors may see our prompts?

Empty: _“No restriction — every connected provider is allowed.”_

**Allow Suger platform key**

May Suger’s own keys be used at all?

On

Add providers from the **Add integration** dropdown, order them with **Move up** and **Move down**, and **Save**. AI features may use only the integrations listed, and **the top row, badged Default, is the organization default** for any feature without a model picker of its own. The [AI Model Policy reference](https://doc.suger.io/insulin/getting-started/#ai-model-policy) covers the tab in full.

## Does connecting your own key keep prompts off hosted models?

**No. Connecting your own provider makes its models preferred, not exclusive.** They take priority, but the Suger-hosted models remain what the documentation calls “the fallback the turn degrades to” when your providers fail. That keeps work moving on a provider’s bad day — and it is exactly what an “only vendors we contract with” policy rules out.

## The row that keeps the hosted pool

**A non-empty allowlist must include Suger Hosted (DeepInfra), or the Suger-hosted models stop being offered.** Every hosted model resolves through that one integration, and an integration missing from a non-empty list fails closed. Add the entry to keep the pool — “it admits the pool, and nothing more” — or leave it off to drop it.

### Rows are integrations, not models

**Each row admits an integration, so review it as a vendor relationship.** A row can be a model provider such as Anthropic or OpenAI; an open-source model aggregator such as OpenRouter, Baseten or Together AI, which can expose hundreds of models behind that one row; or Suger Hosted (DeepInfra), the hosted pool on Suger’s key, which is not the same thing as connecting your own DeepInfra key.

The allowlist decides which providers receive requests, not what a provider does with one. That sits in each provider’s terms.

## What turning off Suger’s key changes

**Turning off Allow Suger platform key makes the organization bring-your-own-key (BYOK) only.** Left on, Suger’s shared keys can serve an allowed provider you have not connected your own key for. Off, every AI call must use one of your own connected keys, and an allowed provider without one fails closed rather than falling back to Suger. The documentation calls that “a guarantee, not a preference.”

The fallback it removes reaches beyond chat: an organization knowledge base whose provider is unavailable at its first index can fall back to a hosted model, and Inbox uses hosted models as its last resort.

Ownership decides whose keys remain. The built-in Insulin assistant and personal agents use each person’s own connections and never reach the organization’s keys; organization agents use the organization’s.

## When the hosted pool steps down a tier

**The Suger-hosted tier step-down is a spend threshold, not a setting.** Once your organization’s spend on Suger’s key passes about $300 in a billing period, the hosted pool withholds its Tier 1 quality model for the rest of that period and serves its lighter Tier 2 models, with no banner and nothing refused. Suger sets the figure; your organization cannot configure it. Own-key usage is not counted, and connected providers are always preferred, so an organization on its own keys never meets it. The [model resolution chart](https://doc.suger.io/insulin/chat/#how-a-turn-resolves-to-a-model) puts all three checks in order.

## Which setting matches your goal?

**Pick the row for your goal; the last column is what comes with it.**

Your goal

Set this

What else changes

Any connected provider, hosted pool as fallback

Nothing; these are the defaults

Hosted turns get Tier 1 until the step-down, then Tier 2

Named vendors, hosted pool kept

List them **plus** Suger Hosted (DeepInfra)

The top row becomes the default. Saving an agent with a Default model on an unlisted provider is refused for **AI policy**. The app builder hides **Suger’s key** rows from unlisted providers; **Your key** rows on them still show but are rejected when the app runs

Named vendors, no hosted pool

List them without Suger Hosted (DeepInfra)

As above, and no turn reaches the hosted pool. For an own-key guarantee, also turn the platform key off

Every call on our own keys

Turn **Allow Suger platform key** off

Hosted models leave the pickers, embeddings included, so a BYOK-only organization with no embedding provider cannot create a knowledge base. Allowed providers without a connected key fail closed

## What people see when no model is left

**Chat stops with a message; Inbox just goes quiet.**

-   **The built-in Insulin assistant**, in a one-on-one chat, replies _“I can’t chat yet — your account doesn’t have an LLM provider connected,”_ whatever emptied the list.
-   **Any other agent**, one-on-one, shows an error card naming the cause. With hosted models disabled, it reads _“No model available for your account: your organization has disabled Suger’s hosted models and you have no personal AI provider connected.”_
-   **In a channel**, one agent without a model stops the whole turn.
-   **Inbox** shows no error. It “simply looks quiet,” and a rule’s **Preview** names the missing model first.

## What to check before turning Suger’s key off

**Line up keys, embeddings and people first, because after the switch every gap fails closed.**

1.  **Match every row to a key.** A row marked **not connected** has no organization key behind it.
2.  **Put the default on top.** It serves every feature without a model picker of its own.
3.  **Connect an embedding provider** — OpenAI, Gemini, OpenRouter, DeepInfra, Fireworks or Together — for the organization, and per person for personal knowledge bases.
4.  **Decide about knowledge bases on hosted models.** The default embedding model is the Suger-hosted BGE-M3. **Change model** re-embeds every document, at provider time and spend, and a document is missing from search until it is re-embedded.
5.  **Give each person a model.** The built-in assistant, personal agents and Inbox need a provider of the person’s own; an organization agent shared with them runs on the organization’s keys instead.
6.  **Review agent Default models.** The policy check on save runs only when the model changes, so an excluded pin survives unrelated edits.

## Frequently asked questions

### What is an AI model allowlist?

An AI model allowlist is the list of AI providers an organization permits to serve its prompts. In Insulin it is the ordered Allowed AI integrations list under Settings → Organization → AI Model Policy. An empty list means no restriction.

### Does adding a provider to the allowlist remove Suger-hosted models?

Yes, unless Suger Hosted (DeepInfra) is on the list too. Every hosted model resolves through that one integration, and an integration missing from a non-empty list fails closed. Adding the entry admits the pool without pinning a model.

### What does turning off the Suger platform key do?

It makes the organization bring-your-own-key only. Every AI call must use one of your own connected keys, and an allowed provider with no connected key fails closed instead of falling back to Suger.

### Why can the built-in assistant stop working when the platform key is off?

It never draws on keys the organization connected. The built-in assistant and personal agents run on providers each person connects, so with the platform key off, someone with none connected has no model to run on.

### Does the Tier 1 step-down apply to our own keys?

No. Only spend on Suger’s key counts toward it, and connected providers are always preferred over the hosted pool, so an organization running on its own keys never meets it.

## Takeaways

-   The allowlist decides which providers may serve you; the platform key decides whether Suger’s keys may be used at all.
-   Your own key is preferred, not exclusive, until the policy removes the fallback.
-   A non-empty list without **Suger Hosted (DeepInfra)** drops the hosted pool.
-   BYOK-only is a guarantee with side effects, so run the checklist before you switch.

The policy draws the boundary, and each agent picks its model inside it. For choosing by risk, see [AI model governance by workflow risk](/blog/ai-model-governance-by-workflow-risk/); for the commercial side, [BYOK vs managed models](/blog/byok-vs-managed-models-for-enterprise-ai/); for failover, [who picks the model](/blog/who-picks-the-model/). Scoping each agent starts on the [Insulin agents page](/agents/).

## Sources

Primary sources for the platform rules cited above. Last verified September 19, 2026. Cloud providers change fees, eligibility, and program terms without notice — check the source before relying on a figure.

-   [Suger docs: Getting Started — AI Model Policy](https://doc.suger.io/insulin/getting-started/) — The ordered Allowed AI integrations list and its top-row default, the empty-list 'No restriction' state, the Suger Hosted (DeepInfra) fail-closed rule, and what the Allow Suger platform key switch does on and off
-   [Suger docs: Chat — Model Selection](https://doc.suger.io/insulin/chat/) — How a turn resolves to a model, the hosted pool as the fallback a turn degrades to, whose keys each kind of agent reaches, and what a user sees when no model is left
-   [Suger docs: Knowledge Bases — Choosing an embedding model](https://doc.suger.io/insulin/knowledge-base/) — Hosted embedding models leave the picker when the platform key is off; a bring-your-own-key organization with no embedding provider cannot create a knowledge base; the automatic hosted fallback; Change model re-embeds every document
-   [Suger docs: Agents — When a Default model is refused on save](https://doc.suger.io/insulin/agents/) — The bring-your-own-key providers and open-source model aggregators; a Default model refused on save for AI policy, re-checked only when the model changes
-   [Suger docs: Custom Apps — Choose the AI model](https://doc.suger.io/insulin/custom-apps/) — How turning off the hosted fallback and restricting providers each change the builder's Suger's key and Your key rows
-   [Suger docs: Payment, Limits, and Top-Ups — The Suger-hosted tier step-down](https://doc.suger.io/insulin/billing/spend-controls/) — Tier 1 withheld once spend on Suger's key passes about $300 in a billing period; Suger sets the figure; own-key usage is not counted
-   [Suger docs: Inbox — AI Model](https://doc.suger.io/insulin/inbox/) — Hosted models as Inbox's last resort, and Inbox looking quiet when no model is available

## Keep reading

-   [TrustAI Agent Risk Assessment: A Reusable Business Workflow TemplateAug 20, 2026](/blog/ai-agent-risk-assessment/)
-   [TrustEnterprise AI Data Privacy: A Practical Guide for Business TeamsAug 19, 2026](/blog/enterprise-ai-data-privacy-a-practical-guide-for-business-teams/)
-   [TrustIs Your Company Data Used to Train Models?Aug 16, 2026](/blog/is-your-data-used-to-train-models/)
-   [SecurityDoes an AI Email Assistant Store Your Email?Sep 19, 2026](/blog/does-an-ai-email-assistant-store-your-email/)

[Browse every post on the Insulin Blog](/blog/)

### Stay Updated

Get the latest Cloud GTM insights, product updates, and marketplace strategies delivered to your inbox.
