Model constraints
Allow or block families, specific models, and premium tiers by organization, sub-org, or employee.
Claude / GPT / GLM / DeepSeek / KimiEnterprise controls / P0
One identity-aware policy layer for model access, token consumption, and cost across providers, sub-orgs, teams, and individual employees.
Why a separate control plane
Provider-native consoles are useful inside their own boundary. Rispn adds the missing enterprise boundary across the models and coding tools an employee actually uses.
Policy inheritance
Policies flow from the enterprise to sub-orgs and employees. A more specific rule can narrow access, lower a limit, or grant an explicit exception with a visible audit trail.
What administrators control
Allow or block families, specific models, and premium tiers by organization, sub-org, or employee.
Claude / GPT / GLM / DeepSeek / KimiSet monthly or periodic token envelopes and define what happens as an employee approaches the boundary.
Alert / restrict / blockCap provider-reported spend, aggregate it across approved providers, and stop spend before the next request leaves Rispn.
Observed cost stays distinct from estimatesEnforcement path
Identity, privacy, audit
Enterprise SSO maps requests to policy. Normal hosted traffic retains structured operational metadata without storing exact prompt text or snippets by default. Administrative changes and request decisions remain auditable.