Identity that fits
SSO/SAML, SCIM, role mapping. Spaces inherit org identity at the OS level — no per-Space onboarding.
Enterprise
The free Construct your team uses, hardened for the constraints your org actually has. SSO, audit, policy, air-gap, private distribution — all at the operating layer, not bolted onto a single Space.
Org admin view — left rail: Members, SSO, Policies, Audit, Spaces. Main pane shows a policy editor: model routing rule, capability allowlist, autonomy ceiling per Space. Audit log strip at the bottom with the last 3-4 actions and which model ran them. Reads as governance, not consumer.
/shots/enterprise-admin.pngWhat you get
SSO/SAML, SCIM, role mapping. Spaces inherit org identity at the OS level — no per-Space onboarding.
Org-wide model routing, capability allowlists, autonomy ceilings, and per-Space overrides where you need them.
Every action the Operator takes is logged with who, what, where, and which model. Exportable, queryable, kept.
Run Spaces with local models only. The same SDK, the same Operator, the same UI — without a single byte leaving the perimeter.
Build internal Spaces for the workflows nobody outside your org will ever see. Distribute privately, not to the public marketplace.
Dedicated SLAs, named contacts, priority routing on incidents, and quarterly reviews on what the Operator is doing for your team.