Providers and models
Under Governance → Access, the Project access panel controls:- Providers: which connected providers this project may route to.
- Models: one model per line. Leave it empty to allow every model. Use exact names (
gpt-4o-mini), provider-qualified names (anthropic:claude-*), wildcards, orcave-autofor automatic routing.
Example model allowlist
Project request limits
Key-level Requests / min, Tokens / min, and Parallel limits apply on top of these, so a single runaway key cannot exhaust the project’s capacity.
Guardrails
Governance → Guardrails blocks secrets, masks PII, denies patterns, or calls your own service before a prompt reaches the provider.
Turn on Use as a project default to run a rule on every request. When it is off, only keys that name the guardrail run it.
Use Test your rules to try input against your rules before publishing. Testing never changes configuration. A saved rule is published as a policy version that the gateway applies on the next request; re-read state after publishing to confirm delivery.
Who can change access
Owners, Admins, and Engineers can edit access policy and guardrails. Viewers and Billing contacts can view them but not change them. Every change is recorded in Governance → Audit.Project access control is part of the Boost package and above. See Billing.