Home / Governance & console
Governance & Console

Built for the person who runs everything else.

The Freehold console is designed for the IT administrator who runs Google Workspace, Okta, or the M365 admin center. It speaks in people, groups, applications, and alerts, and it translates the GPU physics into human terms, so a generalist can answer their manager's questions on the spot.

Four objects carry the whole mental model.

People belong to groups. Groups are permitted applications. Applications point at models. Everything the console governs hangs off that chain, in the vocabulary your team already uses.

People

Budgets and allowances

Federated from your identity provider. Each person carries a per-minute budget and, where you allow external models, a windowed allowance. Consumption is metered individually.

Groups

Where policy lives

A group is a governance scope: which applications are permitted, aggregate caps, and how consumption divides among members. The org chart stays an org chart; groups govern usage.

Applications

Named, versioned products

Real products from the catalog, publisher-labelled and updated across the fleet, each pointing at the model that powers it, with observed adoption shown next to status.

Models

Hosted, or under your key

Hosted models come from the curated menu and occupy measured capacity. External models run under your own provider keys through the same gateway, with the data boundary labelled.

The split that keeps sizing sane: granting an application to a group costs nothing, hosting a model occupies real GPU capacity, and each person's consumption is metered. The console keeps the three apart, so an access decision never masquerades as a capacity decision.

Decisions, previewed

Every choice arrives with its consequences computed.

The console offers decisions with the outcome attached, and it only offers options that fit:

  • Hosting a model answers both capacity questions in one dialog: does it fit, measured in GPU-units, and will it hold up, measured in throughput.
  • Every change previews its effect in plain language before it applies, then lands as versioned, signed configuration that the platform reconciles continuously.
  • A refused action explains itself and names the alternatives that would work.

The screens are designed as golden paths for the jobs you'll actually do: give a team an AI application, handle "the AI is slow," handle "we need model Y," offboard a person and prove it, pass an audit.

Enforcement is a cap at the gateway.

When a request would exceed its limits, the gateway declines it before any model sees it, with a message that explains. Simple to reason about, visible in the audit, and free of scheduler mysteries.

Per-person budgets

Enforced before serving

Requests and tokens per minute, checked at the gateway on every call. Group-level caps aggregate the same mechanism. Usage totals accumulate from the same audit stream your reports read.

Allowances

Premium while it lasts, sovereign after

Route a group to a frontier model under your own key, capped by a per-person windowed allowance. When it's spent, the app falls back automatically to your hosted model and the data-boundary label updates to match.

Promise, meet observation

Committed next to observed

For every model, the console pairs the demand you've committed through grants with the peak actually observed. Right-sizing becomes something you read off the screen, per model, per group.

Hard guarantees come from walls. A group that needs physical isolation or a strict latency promise gets a dedicated model instance of its own. Shared serving stays governed by caps your team can read at a glance.

The audit trail

Content-free by construction.

Every model call writes an audit line: identity, group, application, model, decision, timestamp, token counts. Message content is never recorded, and the audit layer is built without a place for it to go.

A compliance officer can sign off on that: complete enough to answer "who used what, when, and how much," and structurally incapable of becoming a surveillance log of what your employees wrote.

More on the data boundary →
Identity

Your identity provider is the source of truth.

Members and groups federate from your IdP over OIDC. Access follows your existing joiner-mover-leaver process, and offboarding is provable: remove a person once, and the console shows you every app and model that access no longer reaches.

Roles in the console are scoped for real organizations: setting budgets and approving egress changes can sit with different people.

Numbers you can take to a meeting.

GPU tools love bare percentages. The console shows where every number comes from and what it's made of:

The applied-change record

Every action is a configuration change, versioned and signed.

Changing a model, granting a group, raising a cap: each lands as a signed change with a diff, an author, and an applied timestamp, and the deployment loop carries it fleet-wide in seconds.

The history reads like a ledger. Rollback is a change like any other, and the same record that satisfies an auditor explains last Tuesday to your own team.

Put your IT lead in front of it.

The fastest way to evaluate Freehold is to walk the console with the person who'd run it. Bring your Workspace or M365 admin; they'll be at home in minutes.

Request a walkthrough