Overview
When enterprises use AI platforms, they need to solve two problems at the same time: “Who can access what resources” and “How to attribute, control and audit call costs”. ZGI integrates organizations, departments, workspaces, members, role permissions, API Keys, workspace quotas, wallets, AI points, subscription packages and billing flows to help teams build a scalable AI governance system.Governance Objectives Allow enterprises to allocate resources based on organizational structure, grant permissions based on roles, control quotas based on workspaces and calling credentials, and accurately accumulate AI consumption into trackable bills.
Organization and workspace
Roles and permissions
ZGI supports two levels of permissions: organization role and workspace role. The organization layer includes owner, admin, normal and other roles; the workspace layer can be configured with owner, admin, normal and custom roles. Each role consists of a set of permission codes, which the system will verify before the user accesses pages, creates resources, uploads files, performs tests and other actions.Member management process
- The organization administrator enters the organization management page, creates departments and maintains department hierarchies.
- Add members by direct addition or invitation. You can specify email address, name, department and whether to send emails.
- Create or select a role, configure role name, description and permission set
- Join members to one or more workspaces and assign them workspace roles
- Update roles or move workspaces when a member’s responsibilities change; remove from the organization or workspace when a member leaves the organization
Cost center composition
Billing and quota control
The back-end billing service supports pre-call limit check, withholding, post-call settlement and dual-track cost calculation. A model call can record the organization, model, supplier, channel, request ID, account, application, IP, User-Agent, whether it is streaming, Token usage, response time, status and error information.- Before calling — Check whether the account or organization balance is sufficient, and withhold the estimated points.
- Calling — The model gateway completes routing and request forwarding, and records the request ID and channel information.
- After call — Settlement based on prompt_tokens, completion_tokens, total_tokens, model unit price and actual status
- Exception handling - If the actual consumption is lower than the withholding, the difference can be refunded; if it fails, error information will be recorded for tracking
- Dual-track billing — Simultaneously calculates point costs and USD costs, compatible with platform points and enterprise self-pay models
API Key security configuration
- Create API Keys separately by system, application or integration party. It is not recommended that multiple systems share the same Key.
- Set model scope for production keys to avoid low-risk systems calling high-cost or sensitive models
- Configure expiration time and status, and support life cycle management such as active, inactive, revoked, etc.
- Configure an IP whitelist to restrict calls to trusted network sources only
- Configure the upper limit and remaining limit to prevent abnormal calls from causing costs to get out of control
Budget strategy suggestions
- Set the monthly quota according to the work area. Start with a smaller quota in the initial stage of the launch and adjust after observing the actual consumption.
- Use different API Keys for production systems and test systems, and set quotas and model ranges respectively.
- Whitelist high-cost models to only allow calls to specific workspaces, roles, or API Keys
- Export bill flow regularly and review cost structure by workspace, application, model and call voucher
- Separately monitor private channel funds to avoid enterprise account arrears affecting business continuity
Security
Typical usage scenarios
ZGI Governance Advantages
- Unified management of organizations, departments, workspaces and role permissions, adapting to the real collaboration structure of the enterprise
- Permission granularity covers core resources such as workspaces, agents, knowledge bases, databases and files
- Quota control covers workspace and API Key, and can restrict people, applications and system integration at the same time
- Fees Center covers subscriptions, wallets, AI points, private channel funds, transaction flow and monthly statistics
- The model gateway is linked with the billing service to form a complete link from calling, deduction to tracking**