AIControls sits between your team's AI tools and the models they call. One endpoint gives you identity, budgets, policy enforcement, and a complete audit trail — with zero changes to how developers work.
Every prompt, tool call, model, token, and policy decision — attributed to a person and recorded in one audit log you can search, export, and hand to an auditor.
Audit Log →Budgets per organization, team, or developer, enforced at request time. Warnings before the limit; hard stops, approvals, or model downgrades at it.
Cost Governance →CEL policies allow, deny, rewrite, or route a request to a human approver — evaluated inline, before anything reaches the model or an MCP server.
Policies →{
"env": {
"ANTHROPIC_BASE_URL":
"https://YOUR_ORG.aicontrols.dev",
"ANTHROPIC_AUTH_TOKEN":
"YOUR_ACCESS_TOKEN"
}
}One proxy, every control you need between your developers and their models.
Every tool call — bash, file access, kubectl, any custom server — intercepted, policy-checked, and logged with its arguments.
PII, secrets, and prompt-injection patterns detected inline. Block, warn, or audit — you pick the enforcement mode per policy.
High-risk operations pause for admin approval — in the dashboard or straight from Slack — and resume the second they’re approved.
Real-time spend per developer, team, tool, and model — plus context optimization that cuts the tokens behind the bill.
Every request tied to an authenticated identity. Behavioral baselines, anomaly detection, and risk scores per developer and agent.
Live mapping of your policies to the NIST AI Risk Management Framework, with audit-ready reports one click away.
Routes to Anthropic, OpenAI, Azure OpenAI, and Amazon Bedrock — how upstream routing works.
Connect your team with the guided wizard or manual setup.
How AIControls works — upstreams, identity, cost, security, policies, MCP.
Step-by-step guides for connecting tools and configuring governance.
Policy context fields, decision types, MCP tools, compliance controls.
Most teams finish onboarding in under ten minutes — one endpoint, workspace tokens, done.
Get started →