AI Workspace Admin Checklist: Set Up Insulin

Two of Insulin's admin settings fail closed, the spending limit blocks rather than warns, and the wrong org role stops a new member from starting a chat. Nine steps, in the order that keeps each one from breaking the next.

Max Ma
Max Ma
Oct 8, 2026

An AI workspace admin checklist is the ordered list of decisions an organization admin makes before the team starts. In Insulin it runs to nine steps, and the order matters: two settings fail closed, the spending limit blocks rather than warns, and the wrong org role stops a new member from starting a chat.


Insulin asks nothing of an admin before it works: the built-in assistant runs on Fours-hosted models out of the box. That is exactly why the admin’s decisions belong first. Until someone lists providers in the AI Model Policy, every connected provider may serve your organization’s prompts, the Fours-hosted pool included. Until someone checks roles, part of the team may be unable to chat at all. And the two settings that tighten model access both fail closed: a gap in either stops work instead of falling back.

Every one of these decisions is documented, but across several Settings tabs and documentation pages. This checklist puts them in order. Each step says where it is set, what breaks if you skip it, and which post or doc section covers it in depth.

What should an admin set up before inviting the team?

Nine steps, in this order: roles, organization integrations, the AI Model Policy, the platform-key decision and billing; then the organization’s own agents, channels and knowledge bases and how they are shared; and last, two things to know rather than set.

#StepWhereWhat breaks if you skip it
1Give each person the org role they needSettings → Organization → Users & RolesA VIEWER can’t start a chat, an EDITOR can’t create organization-level resources, and every ADMIN can change organization settings
2Connect organization integrationsSettings → Integrations (Organization group)An organization agent can’t use anything connected only at user level
3Set the AI Model PolicySettings → Organization → AI Model PolicyAn empty list allows every connected provider; a list without Fours Hosted (DeepInfra) drops the hosted models
4Before going bring-your-own-key (BYOK) only, connect your keys and an embedding providerThe same tab: Allow Fours platform keyNothing falls back to Fours, and a BYOK-only organization with no embedding provider can’t create a knowledge base
5Set the billing guardrailsSettings → BillingAutomatic top-up can’t be switched on without a payment method, and a spending limit blocks rather than warns
6Build what only an admin canThe Organization option when creating an agent, channel or knowledge base; Marketplace’s Organization storeNobody else can create organization agents, channels, knowledge bases or Organization-store skills
7Share with safe defaultsEach resource’s sharing controlsOrganization agents, channels and knowledge bases start private, and org admins get no automatic access to channels or knowledge bases
8Know what runs on its ownSettings → Organization → SandboxesNothing to set: organization sandboxes provision themselves, and jobs stay private to their creator, admins included
9Tell each member what to connectSettings → Integrations → User Integrations; Inbox Settings → AccountInbox rules need the member’s own integrations, and an organization connection doesn’t satisfy them

Why does the order matter?

Because five settings depend on something set before them, and out of order each one blocks rather than degrades. Each of these pairs has to run in this direction:

  • Organization integrations before organization agents. An organization agent can’t reach a system connected only at user level.
  • Your own keys before BYOK-only. With the platform key off, the policy’s top row must be a provider you’ve connected and verified, and an allowed provider with no key fails closed.
  • An embedding provider before BYOK-only. The switch takes Fours-hosted embedding models out of the knowledge-base picker for everyone, so without an embedding provider of its own, the organization can’t create a knowledge base.
  • A payment method before automatic top-up. The top-up switch is disabled until one is saved.
  • Organization agents before organization channels. An organization channel can include only organization-level agents.

The AI Model Policy goes before people start for a different reason: until you list providers, there is no restriction at all (step 3).

1. Roles: which org role does each person need?

Give VIEWER only to people who should read, not chat: a VIEWER can view shared agents and channels but cannot start a chat. Every member’s org role decides what they can do across Insulin, and the Organization Roles reference defines three standard ones:

  • ADMIN creates organization-level resources, manages settings and manages organization integrations. Only an ADMIN can act at the organization ownership level.
  • EDITOR creates and manages their own agents, channels, jobs and skills, has read-only access to settings, and cannot create organization-level resources.
  • VIEWER can view shared agents and channels but can’t create, edit or delete them, and can’t start a chat.

Roles are set under Settings → Organization → Users & Roles: adding someone with New User asks for a role along with the email, and Edit changes it later. Check the roles people in your Fours organization already hold, too. The console’s own role guide recommends VIEWER for finance, accounting and executives, and in Insulin that role can’t start a chat.

Keep ADMIN to the people who should own organization settings. Every ADMIN can change the AI Model Policy and the organization’s integrations, which the next three steps set.

2. Integrations: what does the organization need to connect?

Every system an organization agent will use, because an organization agent can’t reach anything connected only at user level. Organization-level agents use organization-level integrations only, and the docs say to configure them before you create the agent.

Organization integrations sit under Settings → Integrations, in the Organization group. Any member can view the list, but only an org ADMIN can connect or disconnect them, and they power organization-level resources. Three kinds belong here:

  • The business systems your organization agents will act on. Only an org admin can change an organization agent’s integrations later, so nobody else can quietly widen what a shared agent reaches.
  • Your own AI provider keys. Organization agents prefer them over the hosted models, and step 4 requires them.
  • An embedding provider, if you will go BYOK-only: OpenAI, Gemini, OpenRouter, DeepInfra, Fireworks or Together, on your own key.

One limit shapes which documents can become shared knowledge: organization knowledge bases support only the Google Drive connector. GitHub and ClickUp connectors are available on user knowledge bases.

3. AI Model Policy: which providers may serve your prompts?

Decide it before people start, because an empty policy means no restriction: every connected provider is allowed, the Fours-hosted pool included. The policy’s Allowed AI integrations list is ordered, and its top row, badged Default, is the organization default for any feature without a model picker of its own.

A non-empty list must include Fours Hosted (DeepInfra), or the Fours-hosted models stop being offered. Every hosted model resolves through that one integration, and an integration missing from a non-empty list fails closed. Save a first row without it, and turns that relied on hosted models have only your own providers left. Adding the entry keeps the pool and pins no particular model.

What each row admits, and what each choice changes for agents, knowledge bases and Inbox, is the subject of Insulin’s AI model allowlist and which vendors see your prompts.

4. Platform key: should the organization be BYOK-only?

Only once every allowed provider has a connected key and an embedding provider is connected, because turning off Allow Fours platform key removes every fallback to Fours. With it off, the organization is bring-your-own-key only: every AI call must use one of your own connected keys, and an allowed provider with no key fails closed. The AI Model Policy reference calls the switch “a guarantee, not a preference.”

Three things change the moment it is off:

  • The policy’s top row must be connected and verified. If it isn’t, Save is disabled or refused.
  • Fours-hosted embedding models leave the picker for everyone. A BYOK-only organization with no embedding provider connected cannot create a knowledge base. Pick the embedding model you expect to keep, because changing it later re-embeds every document.
  • Members need providers of their own. The built-in assistant and personal agents never use the organization’s keys (step 9).

5. Billing: how do you keep spend from stopping work?

If work must not stop, save a payment method and turn on automatic top-up; set a monthly spending limit only as a hard stop, because it blocks rather than warns. All three controls are on Settings → Billing:

  • Payment method. Insulin doesn’t need one to run, but the automatic top-up switch is disabled without one, and removing the method later silently disarms top-up.
  • Automatic top-up. The top-up must be larger than its trigger. A top-up that lands back on its own trigger would fire again at once, so the console refuses to save it.
  • Monthly spending limit. Reaching it pauses AI requests for the rest of the month and stops automatic top-up. There is no warn-only setting, and adding credit doesn’t clear it.

Two more facts to know before anyone arrives. Going BYOK-only doesn’t take the organization off its balance: on pay as you go, a zero balance pauses AI requests on your own key too, because Fours’ per-unit fee is still owed. And any member can see Settings → Billing: it isn’t restricted to administrators and has no admin-only view.

When AI does pause, a banner on that page names the reason, and the four reasons Insulin pauses AI each have a different fix.

6. Organization resources: what can only an admin build?

Organization agents, organization channels, organization knowledge bases and Organization-store skills. An EDITOR can create only personal versions, and only organization agents can be shared: a personal agent’s Share button is disabled.

Build the first three in order, because each one uses the one before:

  1. Organization knowledge bases. Creating one requires org admin access, and its embedding model comes from the organization’s connected providers, or from the Fours-hosted models while the platform key is on.
  2. Organization agents, after their integrations (step 2), attaching those knowledge bases. The Organization ownership option is disabled for anyone who isn’t an org admin.
  3. Organization channels, which can include only organization-level agents. A channel’s ownership type (Personal or Organization) can’t be changed after it’s created, so choose Organization at the start.

Organization-store skills can come at any point. Marketplace’s Organization store is shown only to org admins, an install there is visible to the whole organization, and deleting an org skill removes it for everyone.

You become the OWNER of each agent, channel and knowledge base you create. Ownership of an organization agent or channel can pass only to a current org ADMIN, and only while you are still one yourself, so hand over shared agents before your own role changes.

7. Sharing: which defaults are safe?

Share organization-wide at the lowest role that does the job, usually USER, and grant editing to named people. Organization agents and channels are private by default, and an organization knowledge base starts visible only to its creator; only Organization-store skills reach everyone on install. The org-wide roles each resource offers:

ResourceOrg-wide roles offeredWhat they allow
AgentEDITOR or USERUSER chats with the agent and changes nothing; EDITOR also edits its prompt, model and knowledge bases. Agents have no VIEWER role
ChannelEditor, User or ViewerViewer reads but can’t send; User sends messages; Editor can also change the channel’s agents
Knowledge baseEditor or UserUser searches and reads; Editor also adds and syncs content

No org-wide share grants ADMIN, for any resource.

Admin access isn’t automatic either. Org admins don’t become channel admins, even an org admin can’t open an organization knowledge base they weren’t shared on, and managing an agent’s shares takes ADMIN on that agent, not just the org ADMIN role. Why running and editing should stay separate privileges is covered in who can run what in an AI workspace.

8. What runs on its own?

Organization sandboxes, and everything members own themselves. Neither needs an admin setting.

  • Organization sandboxes are provisioned automatically the first time an organization-owned agent runs a job, so there is nothing to create. Settings → Organization → Sandboxes, a tab only org admins see, lists them with Start, Stop and Destroy. A stopped sandbox still bills storage until it is destroyed.
  • Five things are self-owned: desktop, memory, jobs, skills and sandboxes. Any member manages the ones they created, whatever their org role.
  • Jobs stay private to their creator, org admins included. An admin can’t see, run or delete another member’s jobs, so each owner manages their own.

9. What does each member connect themselves?

Their own accounts and, in a BYOK-only organization, their own AI provider, because personal agents, the built-in assistant and Inbox don’t use the organization’s connections.

  • Personal connections such as Gmail, Google Calendar, Google Drive and Gong are per person, and an organization agent can’t use them.
  • AI providers. The built-in Insulin assistant and personal agents add only the providers each person connected, never the organization’s keys. While hosted models are allowed, they work with nothing connected; in a BYOK-only organization, a member with no provider of their own gets “I can’t chat yet — your account doesn’t have an LLM provider connected.” A personal knowledge base likewise needs an embedding provider the member connected.
  • Inbox. Each member enables it on their own Gmail or Outlook connection, one mailbox at a time. A rule won’t save until its prerequisites are connected, and those are user-level integrations: an organization-level connection doesn’t satisfy them.

Frequently asked questions

What should an admin set up before inviting the team to Insulin?

Check each person’s org role, connect organization integrations, set the AI Model Policy, decide whether to go bring-your-own-key only, and set billing guardrails. Then build and share organization agents, channels and knowledge bases, and tell each member what to connect themselves.

Why can’t a new member start a chat in Insulin?

Check their org role first: a VIEWER can view shared agents and channels but cannot start a chat. If the role is right and your organization is bring-your-own-key only, the built-in assistant needs an AI provider the member connected themselves.

Can we create knowledge bases with the Fours platform key turned off?

Only with an embedding provider of your own. With the key off, Fours-hosted embedding models leave the picker, so an organization knowledge base needs an embedding provider the organization connected, and a personal one needs a provider the member connected.

Can an org admin open every channel, knowledge base and job?

No. Organization admins don’t automatically get access to organization channels, can’t open an organization knowledge base they weren’t shared on, and can’t see another member’s jobs. Channel and knowledge-base access comes from membership, a share or org-wide sharing.

Does Insulin’s monthly spending limit warn before it stops AI?

No. It blocks when it is reached, pausing AI requests for the rest of the month and stopping automatic top-up, and adding credit doesn’t clear it. Raise or remove the limit to resume; automatic top-up is the control that keeps credit from running out.

Who can see Insulin’s billing page?

Any member of your organization. Settings → Billing is not restricted to administrators and has no admin-only view within it, and the Settings app on the Insulin desktop shows the same Billing tab as the console.

Takeaways

  • Roles come first. A VIEWER can’t start a chat, an EDITOR can’t create organization-level resources, and every ADMIN can change organization settings.
  • Connect before you restrict. Organization integrations come before organization agents, and your own keys and an embedding provider come before turning Fours’ platform key off.
  • Two settings fail closed. A non-empty AI Model Policy without Fours Hosted (DeepInfra) drops the hosted models, and BYOK-only leaves an allowed provider with no key nothing to fall back on.
  • The spending limit blocks; it doesn’t warn. Automatic top-up needs a saved payment method and a top-up larger than its trigger.
  • Share on purpose. Organization agents, channels and knowledge bases start private, admins get no automatic access to channels, knowledge bases or jobs, and members connect their own accounts.

Billing is the one step with money attached. Before you pick a limit and a top-up, see how Insulin’s usage-based pricing meters AI models, sandboxes and storage.

Sources

Primary sources for the platform rules cited above. Last verified October 8, 2026. Cloud providers change fees, eligibility, and program terms without notice — check the source before relying on a figure.

  • Insulin Getting Started — Fours Doc — Adoption Path: organization integrations under Settings → Integrations, visible to every member but connected or disconnected only by an org ADMIN, and personal connections such as Gmail, Google Calendar, Google Drive and Gong per user; Settings: Users & Roles among the Organization tabs, most of which only an org ADMIN can change; AI Model Policy: the ordered Allowed AI integrations list, an empty list meaning no restriction with the hosted pool allowed, the top row as the organization default, a non-empty list without Fours Hosted (DeepInfra) losing the hosted pool, and Allow Fours platform key off making the organization bring-your-own-key only, failing closed, with the top row required to be connected and verified; Selecting a Model: the built-in assistant working out of the box on Fours-hosted models; Sandboxes (Organization): an org-admin-only tab, provisioned automatically the first time an organization-owned agent runs a job, with Start, Stop and Destroy; Organization Roles: what ADMIN, EDITOR and VIEWER can do, including that a VIEWER cannot start a chat; Your own things are not role-gated: desktop, memory, jobs, skills and sandboxes, and a job visible and runnable only to its creator, admin or not; Ownership Levels and Resource Roles: organization agents and channels private by default, and ownership transferred only to a current org ADMIN; Sharing Constraints: org-wide shares never granting ADMIN, agents without a VIEWER role, and org admins without automatic access to every organization channel
  • Get Started Account — Fours Doc — Invite a New Team Member: Settings > Users & Roles, where New User takes a Role (Admin, Editor or Viewer) with the email; Manage Users: Edit to update a role; the standard-role table recommending VIEWER for finance, accounting and executives
  • Insulin Agents — Fours Doc — The Organization ownership option disabled for members who are not org admins; org-level agents using only org-level integrations, to be configured before the agent is created; editing an organization agent's integrations requiring org admin access; only Organization agents can be shared, with a personal agent's Share button disabled; org-wide sharing as EDITOR or USER, never ADMIN; managing shares requiring ADMIN on the agent itself; the built-in assistant and personal agents adding only the providers each person connected, never the organization's keys, and the reply a member gets when no model is left
  • Insulin Knowledge Bases — Fours Doc — Creating an organization knowledge base requires org admin access; Fours-hosted embedding models offered only while the platform key is allowed; organization knowledge bases using the organization's connected providers and personal ones the member's; a bring-your-own-key organization with no embedding provider connected cannot create a knowledge base; changing the embedding model re-indexes every document; organization knowledge bases support only the Google Drive connector; an org role alone grants no access, org-wide sharing is as Editor or User, an organization knowledge base starts visible only to its creator, and even an org admin cannot open one they were not shared on
  • Insulin Channels — Fours Doc — Creating an Organization channel requires org admin access; organization channels include only org-level agents; ownership type (Personal or Organization) cannot be changed after a channel is created; org-wide sharing as Viewer, User or Editor, with ADMIN not offered; a VIEWER reads but cannot send; editing a channel's agents requires EDITOR or higher; org admins do not automatically become channel admins
  • Insulin Marketplace — Fours Doc — The Organization store shown only to org admins; an Organization-store install creating an org-shared copy visible to the whole organization; Organization-store skill changes requiring org admin access, and deleting an org skill removing it for everyone
  • Insulin Jobs — Fours Doc — How Jobs Are Created: a job is private to its owner, who alone can see, run, edit or delete it, and being an org admin does not give you someone else's jobs
  • Insulin Inbox — Fours Doc — Connecting a Mailbox: Inbox reuses the member's Gmail or Outlook connection from Integrations, one mailbox at a time; Describing a rule: Save fails when a prerequisite is missing, and the prerequisites are user-level integrations that an organization-level connection does not satisfy
  • Insulin Payment, Limits, and Top-Ups — Fours Doc — The three controls on Settings → Billing; no payment method needed to use Insulin; the monthly spending limit pausing AI requests for the rest of the month and stopping automatic top-up, with added credit not resuming service; the automatic top-up switch disabled without a saved payment method, and silently disarmed if the method is removed; the top-up required to be larger than its trigger, and why
  • Insulin Billing FAQ — Fours Doc — Settings → Billing not restricted to administrators, with no admin-only view, and the same Billing tab in the Insulin desktop's Settings app; no limit that warns without blocking; a zero balance pausing AI requests on pay as you go on your own key too, because the per-unit fee is still owed; a stopped sandbox still billed for storage until it is deleted

Browse every post on the Insulin Blog

Stay Updated

New posts, product updates and marketplace strategy are shared on LinkedIn as they publish.

Follow Fours on LinkedIn