Admin Guide

Prev Next

AI CTRL Administrator Guide

Administrator-specific controls for the AI CTRL multi-model gateway.

About this guide

This guide assumes you have read the AI CTRL User Guide and covers only the administrator-specific controls. It is a base-level guide; the Workspace and compliance platforms are covered in separate sessions.

Roles and Access

AI CTRL has three roles:

  • User: standard, everyday access. You decide which features and models each user receives.
  • Admin: full system access, including everything in this guide.
  • Pending: a holding state that freezes functionality.

Granting admin access. An existing admin opens the user's profile, changes the role to Admin, and saves. The user refreshes their screen to see the admin panel. There is no tier above admin, and you can promote as many admins as you need.

User Management

Standard users are managed inside AI CTRL, separately from your identity provider's app assignments.

  • Automatic provisioning. With SSO, accounts are created automatically on first login. This is the recommended path for standard users.
  • Removing access. Removing a user from the group or app registration in your identity provider blocks their authentication. Their AI CTRL profile and any owned assets persist until an admin reassigns those assets and deletes the account to free the seat.
  • Manual creation. Supported mainly for service accounts that need direct email and password access, such as for an API integration. Give these accounts the User role, not Admin.
  • Bulk import. A CSV template is available to pre-populate seats, useful when you want groups assigned up front rather than waiting for first-login provisioning.

Permissions: The Two-Tier Model

Default permissions apply to every base user from day one: this is your lowest-common-denominator baseline. They control things such as:

  • Whether users can create custom models, knowledge collections, and prompt templates in the Workspace.
  • Chat-level actions such as deleting chats or deleting individual message versions.
  • Feature access: memories, image generation, web search, folders, notes, channels (internal messaging), and API key generation.
  • Interface customization.

Group-based permissions layer on top for elevated or specialized access.

Recommended Defaults

  • Leave Workspace creation off by default unless broad self-service model-building fits your rollout. Most organizations are not ready to train everyone on custom assets on day one.
  • Leave API key generation off by default; enable it only for groups that genuinely need programmatic access.
  • Consider restricting chat delete so users do not accidentally remove work; they can always archive instead.

A useful approach. Decide the baseline every user should have, then decide what is restricted and who should get it back through groups.

Groups

Create groups with + New Group. Two strategies work well together:

  • By department: cluster users, such as an "IT Staff" group, so it is easy to share assets to them, without necessarily granting extra permissions.
  • By elevation: a group such as "Workspace Moderators" that grants broader rights: Workspace creation, sharing, and possibly API access.

Sharing scope per group controls who may share assets to that group: anyone with sharing rights, members only, or admins only.

Permissions are additive at the highest permissible level. A user in multiple groups inherits the most permissive setting across all of them, so if any one group grants a model or feature, they have it.

Two tiers of sharing rights apply when you enable sharing: standard sharing lets a user share to groups they belong to; public sharing also lets them make an asset available to all authenticated users through the "public" tag.

On identity-provider group inheritance. While it is technically possible, there is no exact one-to-one mapping between your provider's groups and AI CTRL's permission structure, so managing permissions directly within AI CTRL is generally recommended.

Analytics and Evaluations

Analytics (beta). Tracks message volume and model usage per user and per model, useful for measuring adoption and comparing usage across base and custom models. Token counts here are not accurate; precise usage lives in the compliance platform.

Evaluations. An optional thumb-up/thumbs-down and feedback mechanism, off by default. It is most valuable once you build custom models, because it surfaces gaps (for example, an HR agent missing a company-holiday document), so you can iterate.

Functions

Functions are Python-based capabilities attached to chat interactions, in three categories.

Actions

These are the export buttons on a response.

  • PDF, Word, and Excel are enabled by default.
  • PowerPoint is off by default and requires configuration before it appears: set the client name, logo, base color, and accent color. It then auto-generates a title slide, content slides split by headers, and a closing slide. Recommended rollout: enable and test on a single model first, then set it Global to make it available across all models.

Filters

Filters run automatically before a response is generated.

  • PII filter (off by default) uses Microsoft's Presidio library to detect and redact sensitive patterns (Social Security numbers, emails, IP addresses, and so on) by keyword, phrase, or regex, before the prompt reaches the model. Review and configure which data types to redact for your organization. It is Python-based, so expect some configuration effort; you can have a model help draft it.
  • Thinking indicator replaces a pulsing dot with a "thinking" status during longer processing so the app does not look frozen.

Pipelines

Pipelines are background subroutines.

  • Deep research pipe keeps long-running deep-research queries alive by polling periodically, so they do not hit the default timeout of roughly 300 seconds. Safe to disable if your organization will not use deep-research models.
  • Smart Model Router is implemented here as a pipeline. It evaluates each prompt and the requesting user's available models, then selects the best fit. Disable it globally if you do not want to offer it.

Model Management: Your Primary Workspace

This is where most administrator time goes. The per-model controls:

Control What it does
Enable / Disable Fully removes access. Use Disable when a model reaches end-of-life to prevent errors. Providers can deprecate with little warning, so review this page periodically.
Enable + Hide Keeps a model technically active, so existing integrations and custom models that reference it keep working, but removes it from the user-facing drop-down.
Public All authenticated users can select the model.
Private Only admins can use the model by default.
Private + Access Grant specific groups or individuals access.

Recommended strategy. Keep only your intended baseline models public, set everything else to private, then grant access by role and use lightweight, low-cost models for general staff; more capable, more expensive models for specialized or technical roles.

Custom-Model Access Parity (Important)

A custom model inherits the access requirements of its base model. If you build a custom model on a private base model but publish the custom model to everyone, users who lack access to that base model will not be able to use it. Keep base-model and custom-model access aligned.

The Task Model

A lightweight task model runs backend jobs such as chat-title generation and tool handoffs. Disabling it entirely can break those functions. If you simply do not want users selecting it directly, hide it rather than disable it, so backend processes keep working.

Defaults and Ordering

Set the platform-wide default model for first-time users, or default to the Smart Model Router, and choose which models are pinned on first login. Reorder the drop-down by drag-and-drop; changes apply immediately. These set the first-run experience; once a user changes their default or pins, their choice persists.

Global Settings

Most environment settings and API keys are pre-configured for you. The key global toggles:

Setting Behavior
API keys Master switch. If off, no one can access the gateway programmatically, regardless of group permissions.
Channels Internal messaging, off by default. It will not function until enabled globally, even if a group has permission.
Memories Can be disabled organization-wide.
Message rating Global toggle for the thumbs-up/thumbs-down feedback loop.
Web search / image generation Global toggles. Keys are pre-registered, and sub-features such as image editing can be disabled independently.
Structured data tool Enabled for everyone by default; restrict it for users who will not work with spreadsheets.
Chat title generation Uses the task model; title rules, such as "no emojis," are editable.

What Other Sessions Cover

The Workspace (custom models, knowledge collections, prompt templates, and skills) and compliance (full auditing and accurate token and usage data) each have their own dedicated sessions. Agentic capabilities (MCP server integrations for simple live actions, and a separate automation and workflow platform for complex handling) sit outside the front-end offering and can be demonstrated on request.

Administrator FAQ

Is there a role above admin?
No. User and Admin are the two functional roles; Pending is a frozen holding state.

A user was removed from our identity provider but still shows in AI CTRL. Why?
Blocking authentication does not delete the AI CTRL profile. Reassign their owned assets, then delete the account to free the seat.

Where do I get accurate token usage?
The compliance platform, not the analytics pane.

Why did chat titles stop generating?
The task model was likely disabled. Hide it instead of disabling it.