Rolling out AI across a team creates two seemingly opposite jobs for admins: respecting each person's privacy, and protecting the company's information. Prompt Flow Studio is built so both can coexist, as a standard part of a multi-AI workspace.
Questions? Contact us.
Checking how authentication and access control work.
Checking what's captured in audit logs and how to retrieve it.
Checking how data is stored and how runaway costs are prevented.
Conversations and generated artifacts belong to the people in them, and whoever they're shared with. What admins see day to day is team usage and cost — PFC consumption and storage usage. Members control who a thread is shared with, through access control lists (ACLs).
Every action is recorded as an audit event: who, when, what. Query it via API, export it as CSV/JSONL with a SHA-256 checksum, or browse it in the admin viewing UI, any time. Legal holds for litigation or investigations, and long-term retention, are available to discuss through the Enterprise program.
Security Filter detects and masks sensitive or personal information before it's sent, then restores it in the response, as a standard capability (Team: detect and warn, Business: auto-mask and restore, Business+: contextual detection and mask-event audit review). Custom detection rules, bring-your-own detection dictionaries, and an org-wide enforced policy are available to discuss through Enterprise. Model catalog governance, letting admins control which AI models the organization can use, is included as well.
This reflects day-to-day operation. Shared threads and legal processes (such as Legal Hold, through the Enterprise program) change what's visible.
| 項目 | Visible | Not visible (day to day) |
|---|---|---|
| Team usage & PFC consumption | ○ | — |
| Contracted seat count | ○ | — |
| Audit event metadata (who, when, what) | ○ | — |
| The content of conversations and artifacts | — | ○ |
When employees sign up for ChatGPT, Claude, and others individually, usage logs and access controls end up scattered across services the company can't see.
Bringing multiple AI providers into a single workspace puts authentication, permissions, and audit logs in one place — which is what makes cross-cutting governance possible in the first place.
Login runs through Onion SSO.
Thread sharing is governed by an access control list.
Actions are recorded as audit events and available through a query API.
Generated artifacts and uploaded knowledge documents are stored in S3.
Execution stops before your PFC balance runs out, preventing unintended overuse.
Security Filter comes standard on Team, Business, and Business+ (Team: detect and warn, Business: auto-mask and restore, Business+: contextual detection and mask-event audit review). Custom detection rules, bring-your-own detection dictionaries, and an org-wide enforced policy that individual users can't opt out of are available to discuss through the Enterprise program.
Tamper-evident audit logs (hash chain) come standard on Business and above. Legal holds for litigation or internal investigations, GDPR erasure, and 7-year audit retention (statutory retention, linked to Legal Hold) are available to discuss through the Enterprise program.
Generated artifacts and uploaded knowledge documents are stored in S3.
For a direct conversation, use the contact form.
Start with the free plan and try all four modes.
Start free