Platform AI and the model catalog
The two pages that used to be Madebook's and are now the account service's — the keys the platform runs on, and the models customers are offered.
Madebook no longer has these pages. It holds no AI provider key at all.
The platform's own keys, the models it runs on and the catalog it offers organizations are one set of settings for the whole ecosystem, kept once at the Bookbag account service. Madebook had its own copies; keeping them would have meant two tables, two screens and two ways for a key to get out.
The admin sidebar's The platform brain group is now two links out:
| Link | Where it goes | What it holds |
|---|---|---|
| Models & providers ↗ | the account service's /admin/ai |
The keys and models the platform itself runs on. The platform's bill. |
| Model catalog ↗ | the account service's /admin/model-catalog |
The models an organization can approve for its own agents, and be managed by. |
Both open at the account service, in its own admin area, under a group also called What it thinks with. Getting in there needs a platform administrator account at the account service — being a Madebook platform admin is not by itself enough, and the two are worth keeping straight.
These are still the pair most worth never confusing. One is what the platform pays for; the other is what it offers. They sit together because they are one subject, and they are separate entries because they are opposite sides of it.
And a third page, with no link to it
The account service also holds AI tokens at /admin/tokens: the token allowance every account is metered against, across all three products. That is where a platform admin sets the default allowance, whether it turns over monthly or weekly, what a generated image costs, and any per-account exception — and where the ledger of every managed run lives.
Madebook's admin sidebar does not link to it. Openbook's and Bookbag's do. Until that is fixed, go to the account service's own admin area and open it from there. What it controls is described in The token allowance.
Models & providers
The keys and models the platform itself runs on. The starred default is what runs when nothing more specific is chosen.
This is the platform's bill, separate from each organization's own configuration. It answers two things:
- Work that belongs to no customer — a product's own background work, paid for by the platform.
- Every organization in managed mode — they run on this key and these models, and configure nothing themselves.
Provider keys
Checked against the provider before they are stored, then encrypted. Only the last four characters are ever shown. Adding a key for a provider replaces the one it already has.
Six providers can hold a key: OpenAI, Anthropic, DeepSeek, xAI (Grok), Google (Gemini) and Azure OpenAI — plus an OpenAI-compatible server of your own, addressed by base URL. A key is verified live against the provider before it is stored; a rejected key never reaches storage.
Adding a key for a provider replaces the one that scope already had. Removing a key removes the models bound to it — they could never work again.
Keys are encrypted and there is no plaintext fallback: with no encryption key configured on the account service, the store refuses to save and says so on every read.
Models
Browse models asks the provider for its live catalog, minus what is already there. It needs a key first. There is also an add-by-identifier path for anything the provider does not list, including a model on a server of your own.
The models table renames, activates, stars and prices. The starred default is what runs when nothing more specific is chosen, and it must support tools, or an agent cannot be briefed through it. There is one default per kind; starring a model clears every other star of that kind and activates the new one.
What a platform key affects, in Madebook's terms. Nothing here approves anything. An organization's allow-lists still decide whether a provider or a model may be used — including in managed mode. A platform default the customer has not approved is refused, with the reason stated.
Default model per product
Under the Models table, Default model per product lists every registered product — Bookbag, Madebook, Openbook — with a select of the platform's active chat models. A product is known from the client credential it calls the account service with, so when one calls for a completion without naming a model, its own default answers; Platform default means the starred model above. Madebook reads whole repositories, Openbook drafts short prose, Bookbag builds apps — the right model for one is the wrong bill for another. A product default only wins when it can do what the request needs (tools, say); otherwise the star serves. Choosing a model here also activates it. Organizations on their own provider key are untouched: this is what the platform pays for.
The model catalog
The models an organization can approve for its own agents. This is not the platform's AI configuration — customers never see that.
Reference data. It holds no key and can call nothing. It does two jobs:
- It is where the model chips on every organization's Governance page come from — the models somebody can approve without typing an identifier.
- It is what an organization sees under The platform catalog when it chooses managed mode, so it can see what it is getting.
Entries carry a provider, a name, an identifier, a kind (chat, embedding, image, stt, tts or realtime) and optional notes, and are either offered or retired. Search and paging are server-side, and the kind filter is how a screen that wants an image model offers only the rows that can draw.
The identifier cannot be edited
It is what an organization's approval is recorded against, so changing it would leave them holding an approval for a model the row no longer describes. Retire the entry and add the new identifier instead.
Approving is by exact identifier, so an entry whose identifier is a near-miss is a model that silently never matches. That is the single most important property of this page.
Retiring, not deleting
Retiring stops an entry being offered. Organizations that already approved it keep their approval — this catalog suggests, it does not govern. Deleting an entry has the same property.
This catalog is never read when a model is gated. The gate checks the organization's own approvals. This list is a convenience, never a constraint.
The starter catalog
An empty catalog offers to load a starter list of well-known models across the providers, after which you edit it freely. It refuses over a non-empty catalog. Azure OpenAI and self-hosted ship zero rows on purpose — a deployment name is chosen by whoever created the deployment, and no catalog can know what you called yours.
Until this catalog has entries and a usable default key exists, Managed by us is greyed out on every organization's AI page: "Nothing is on offer yet — the platform has no model configured."
What changed, and why you might still expect these here
Until this consolidation Madebook kept its own /admin/ai and /admin/model-catalog, its own provider-key table and its own model table. All three are gone: the tables were moved to the account service and then dropped, and the pages were replaced by the two links above. There is no Anthropic or OpenAI key anywhere in Madebook.
One thing did not move: governance. The account service knows which models an organization has configured; only Madebook knows which of them that organization has approved its agents to use. See Providers, models and clients.
Related
- AI configuration — what an organization sets for itself
- Providers, models and clients — the allow-list, which did not move
- The platform admin area