Security, auditability, and legal compliance come standard, the reason teams choose Prompt Flow Studio as their AI workspace.
Rolling out AI to a team creates two jobs that pull in opposite directions. We make both work.
Conversations and generated artifacts belong to the author and whoever they're shared with. What admins see day to day is team usage and cost — PFC consumption and storage.
Every action is recorded as an audit event. Query it via API, export as CSV/JSONL with SHA-256 checksums, or view it in the admin console (Business+ and above).
Security Filter — detect and mask sensitive data before it's sent, then restore it in the response — comes standard (Team: detect & warn only, Business and above: auto-mask & restore). Contextual detection and mask-event audit viewing are available on Business+ and above. Custom detection rules, bring-your-own detection dictionaries, and an org-wide enforced policy that people can't opt out of are available on Enterprise.
Business steps up to Business+ and on to Enterprise. Here we only cover the capabilities that make a real difference for organization-wide rollout. For the full common-feature comparison, see the pricing page.
| 項目 | Business | Business+ | Enterprise |
|---|---|---|---|
| SAML SSO | Yes | Yes | Yes |
| SCIM auto-provisioning (create, update, deprovision) | Yes | Yes | Yes |
| Group-to-role auto-assignment | Yes | Yes | Yes |
| Break-glass emergency access (fully audited) | Yes | Yes | Yes |
| Signed webhook verification for integrations | Yes | Yes | Yes |
| Secret-variable masking | Yes | Yes | Yes |
| Security Filter (PII auto-mask & restore) | Yes | Yes | Yes |
| Contextual detection + mask-event audit view | — | Yes | Yes |
| Custom detection rules | — | — | Yes |
| Org-wide enforced policy (no individual opt-out) | — | — | Yes |
| Bring-your-own detection dictionary (BYO) | — | — | Yes |
| 項目 | Business | Business+ | Enterprise |
|---|---|---|---|
| Audit event log & query API | Yes | Yes | Yes |
| Audit log viewing in the admin console | — | Yes | Yes |
| Audit export (CSV/JSONL with SHA-256 checksums) | — | Yes | Yes |
| Tamper-evident audit log (hash chain) | Yes | Yes | Yes |
| Draft-branch retention | Auto-cleaned after 30 days | Auto-cleaned after 30 days | Configurable retention policy; freeze with Legal Hold |
| Legal Hold (freeze data for litigation or investigation) | — | — | Yes |
| GDPR erasure | — | — | Yes |
| Audit-log retention period | 1 year | 1 year | 7 years (statutory retention, linked to Legal Hold) |
| Billing ledger integrity (enforced recording, daily reconciliation, real-cost reconciliation) | Yes | Yes | Yes |
| Team budgets & usage alerts | Yes | Yes | Yes |
| Model governance (org-controlled model availability) | Yes | Yes | Yes |
| Data residency (choose the storage region) | — | — | Yes |
| CMEK (customer-managed encryption keys) | — | — | Yes |
| Dedicated shard | — | — | Yes |
| SLA (uptime guarantee) | — | — | Yes |
| Dedicated CSM | — | — | Yes |
| Invoice billing | — | — | Yes |
| Priority support | — | Yes | Yes |
Yes = available. — = not applicable. Business+ and Enterprise always include everything from the tier below.
Detects sensitive and personal data before it's sent. Automation and scope grow with the plan.
| 項目 | Team | Business | Business+ | Enterprise |
|---|---|---|---|---|
| Detect and warn | Yes | Yes | Yes | Yes |
| Secret-variable masking | — | Yes | Yes | Yes |
| Auto-mask and restore | — | Yes | Yes | Yes |
| Contextual detection + mask-event audit view | — | — | Yes | Yes |
| Custom detection rules, BYO dictionaries & org-wide enforcement | — | — | — | Yes |
From audit trails to long-term retention, we answer what legal and compliance teams ask for.
Every action — who, when, what — is recorded and available via a query API, CSV/JSONL export with SHA-256 checksums, or the admin console.
Tamper-evident audit logs (hash chain) come standard on Business and above. Data freezes for litigation or investigation (Legal Hold), GDPR erasure, and 7-year audit retention (statutory retention, linked to Legal Hold) are available on Enterprise.
Beyond the query API and exports, you can search and browse audit logs directly in the admin console (Business+ and above).
Share threads and personas across the team.
Single sign-on with your IdP (Business and above).
Automated user provisioning (Business+ and above).
Query audit events via API, or export as CSV or JSONL with SHA-256 checksums.
See this month's PFC consumption and cost for your team.
Control which AI models the organization is allowed to use.
Business plans include everything in Team. See the team page for collaboration details.
Prices are per seat. Minimum seat counts apply.
| 項目 | Team | Business | Business+ | Enterprise |
|---|---|---|---|---|
| Monthly (per seat) | $60 | $95 | $150 | Custom quote |
| Annual (per month) | $50 | $79 | $125 | Seats + PFC usage |
| Minimum seats | 5 | 10 | 25 | Custom |
| Monthly PFC (per seat) | 4,000 | 4,500 | 5,000 | Usage-based |
| Storage | 15GB | 25GB | 40GB | Custom |
Tell us what you need and roughly how many people will use it.
We work out whether you need SSO, how many seats, and your target start date.
We issue accounts and your team gets started.
SAML SSO is available on Business and above. SCIM is available on Business+ and above.
Learn more:
Ready to talk? Reach us through the contact form.
Start with one piece of work you're already doing.
Start free