Feature

Model Access Controls

Choose which models and providers each organization, team, user, or key may call — and enforce that list from parent scopes so child keys cannot widen access on their own.

Log inRead docs
Model access

Allowed models and providers inherited from org or team policy.

Access

Model list

Scope

Org + key

Policy

Enforced

01

Default

Enabled

All models available unless restricted.

02

Override

Model blocked

Specific model disabled for a key.

03

Policy

Parent enforced

Child scope cannot relax access.

New capabilities

What your team gains with Concentrate

01

Set the default model list

Choose which models and providers are available by default, so teams build on an approved set instead of every model the providers happen to expose.

02

Allow or block per scope

Override the default for a specific team, user, or key — open up a model for one workload, or block one that's too expensive or not approved for sensitive data.

03

Lock it from a parent scope

Enforce model access at the organization or team level so a child key can't enable a restricted model on its own.

Who Concentrate is designed for

Approved models per team, key, and workload

Model access controls define which slugs and provider paths a scope may use. Security sets the default at the organization; teams and keys inherit or narrow it; parent-enforced policy stops a production key from enabling a model that was never approved.

Security and compliance

Block unaudited or overly expensive models from sensitive workloads.

Platform engineering

Publish an approved model list once instead of policing every repo for ad-hoc provider calls.

Team leads

Allow a pilot model for one key while the rest of the org stays on the default list.

Works with Universal API keys

Attach access policy to Universal API keys so each app inherits the right model list automatically.

Feature basics

Frequently asked questions

What are model access controls?
Model access controls decide which models and providers an organization, team, user, or key can call.
Can model access be enforced from a parent scope?
Yes. Organization or team settings can enforce model access so child keys cannot enable restricted models.
CONCENTRATE

One API for every major LLM provider — routing, spend, logs, and controls in one place.

New York

130 E 59th St, 17th floor

New York, NY 10022

Wilmington

1201 N. Market Street, Suite 200

Wilmington, DE 19801

LLM Gateway
  • LLM Gateway
  • Request Routing
  • Usage Monitoring
  • Spend Management
  • Data Security
  • Access Controls
Teams
  • AI Engineering
  • Engineering Leadership
  • Finance & Operations
  • Security & Compliance
Integrations
  • All Integrations
  • Migration Guides
Platform
  • Pricing
  • Model Fortress
  • Enterprise
  • Documentation
  • Status
Legal
  • Privacy Policy
  • Terms of Service
  • Data Processing Addendum
  • Acceptable Use Policy
Features
  • Universal API Keys
  • Spend Tracking
  • Token Allocation
  • Usage Analytics
  • Request Logs
  • Alerts
  • Data Redaction
  • Zero Data Retention
  • Audit Logs

LLM Gateway

  • LLM Gateway
  • Request Routing
  • Usage Monitoring
  • Spend Management
  • Data Security
  • Access Controls

Teams

  • AI Engineering
  • Engineering Leadership
  • Finance & Operations
  • Security & Compliance

Integrations

  • All Integrations
  • Migration Guides

Platform

  • Pricing
  • Model Fortress
  • Enterprise
  • Documentation
  • Status

Legal

  • Privacy Policy
  • Terms of Service
  • Data Processing Addendum
  • Acceptable Use Policy

Features

  • Universal API Keys
  • Spend Tracking
  • Token Allocation
  • Usage Analytics
  • Request Logs
  • Alerts
  • Data Redaction
  • Zero Data Retention
  • Audit Logs

Offices

New York

130 E 59th St, 17th floor

New York, NY 10022

Wilmington

1201 N. Market Street, Suite 200

Wilmington, DE 19801

© 2026 Concentrate AI. All rights reserved.

CONCENTRATE
Pricing
ModelsDocsRequest a Demo
CONCENTRATE
Log In
Log In