Skip to main content
Model Access rules are available on Business and Enterprise plans. To upgrade, contact sales. Members on any plan can open Model Access to see which models they can use. If you used the controls in Workspace Settings before, see What changed.
Model Access lets admins decide which AI models people can use in Krea. Organization admins can set rules for the whole organization, for each workspace, and for individual members. A standalone workspace sets rules for itself and its members.

Open Model Access

Open Manage ↗ and click Model Access in the sidebar. Organization owners and admins find it in the organization section. Everyone else finds it in the workspace section. The Model Access editor for an organization, with approved, blocked, and member-approved video models Your role decides what you can see and edit:

How access is decided

An organization has one policy, and each workspace can have its own. The organization policy applies in every workspace in the organization. A model is available to someone only when every policy that applies allows it. In an organization workspace, that means both the organization policy and the workspace policy.

Default access

Each policy has a Default access setting: The Default access menu with No restrictions, Approved models only, and All models except blocked
Switching a policy to Approved models only doesn’t approve anything for you. Until you approve models, every model is blocked for everyone the policy covers. Approve the models you want before you save. See Approve every model from one company.

Rules

A rule approves or blocks one model, for everyone the policy covers or for one member. Each rule names an exact model, so models Krea adds later start with no rules. Two things decide the result:
  • Blocks override. Within a policy, a block for everyone overrides any member approval.
  • Every policy must allow the model. An organization block, or a missing organization approval, overrides a workspace approval. The editor disables those approvals and shows Approve it for the organization first.

Edit rules

Changes stay in draft until you save. Discard changes restores the saved rules.
1

Choose whose rules to edit

Open Rules for at the top of the table. Organization admins can pick Organization, Workspace, or Member. Workspace admins can pick the workspace or Member.
2

Set default access

Pick a Default access setting. A dialog explains what the change does to existing rules. Switching to All models except blocked removes the policy’s approvals and keeps its blocks.
3

Approve or block models

Check Approve or Block next to each model. The Approve column appears only under Approved models only. To narrow the list, search or use Filter to pick a company, provider, or tool. To change every listed model at once, click Edit all N models next to the search field, then choose Approve all, Block all, or Clear all rules.
4

Review and save

Click Review changes to see each changed rule and how access changes for the people it covers. Then click Save all. Krea saves each policy separately.The Review changes dialog showing changes to an organization policy and a workspace policy
To see who can use a model, click its row. The expanded row lists each workspace and member with their result and the rule that decided it. You can add a workspace or member rule from there. An expanded model row listing each workspace and member, their result, and the rule that decided it

Workspace rules in an organization

Organization admins can give a workspace its own rules. Choose Rules for > Workspace, then pick the workspace. If the workspace follows organization access, Add rules for asks how its rules should work:
  • All models except blocked: members can use every model the organization allows, except ones blocked for this workspace.
  • Approved models only: members can use only models the organization allows and this workspace approves.
Workspace rules can only narrow what the organization allows.

Member rules

Choose Rules for > Member, pick the person, and approve or block models for them. In an organization, a member rule that an organization admin sets applies in every workspace of the organization. A member rule that a workspace admin sets applies only in that workspace. You can also open Model Access from a member’s ⋯ menu on the Members page.

Examples

Approve every model from one company

1

Switch to approved models only

Choose Rules for > Organization, then set Default access to Approved models only.
2

Filter by company

Click Filter > Company and pick the company.
3

Approve them all

Click Edit all N models next to the search field and choose Approve all. Then click Review changes and Save all.Models filtered to one company, with the Edit all menu open on Approve all
Models the company releases later still need your approval.

Block one model in one workspace

Choose Rules for > Workspace, pick the workspace, and check Block for the model. If the workspace was following organization access, it switches to All models except blocked with that one block.

Let a few people try a model

Under Approved models only, leave the model unapproved, then choose Rules for > Member and approve it for each tester. Pilots need Approved models only, since a block for everyone also covers your testers.

Block a model for one person

Choose Rules for > Member, pick the person, and check Block for the model.

What members see

Model pickers dim blocked models, and compact pickers group them under Restricted by your admins with a lock icon. Auto skips them. Picking a blocked model opens a dialog with up to three admins to contact and, when one exists, a suggested alternative. Admins who can change the rule see a Manage Model Access button in place of the contact list. The dialog a member sees for a blocked model, listing organization admins to contact Each member’s Model Access page shows why a model is blocked: A member's Model Access page showing allowed models and the reason each blocked model is blocked

Where rules apply

Krea checks access at the start of every generation, in every tool, the Krea API, and the Krea MCP server. Blocked API and MCP requests return HTTP 403 with FEATURE_RESTRICTED. Realtime checks on connect, then about once a minute.

Plan changes

Downgrading to a plan without Model Access pauses enforcement. Krea keeps the rules and applies them again when you upgrade.

What changed

Model Access replaces the Workspace Settings controls. Every workspace’s rules carried over, and every blocked model stayed blocked.
Some workspaces blocked a model for everyone while letting certain members use it. Krea switched these to Approved models only and approved every other model, so access stayed the same. New models now need approval there. To switch one back to All models except blocked, first block the models it used to block, or they open up to everyone.

Troubleshooting

Click the model’s row in the editor. The expanded row shows the result for each workspace and member, and the rule that decided it. Members can see the reason on their own Model Access page.
Another rule blocks it. Blocks override approvals, so look for a block that applies to everyone or to that member. In an organization, also check that the organization allows the model.
The Approve column appears only when the policy uses Approved models only. A workspace approval is disabled when the organization blocks the model or hasn’t approved it. Approve it for the organization first.
The policy has no approvals yet. Approve the models you want, or click Discard changes if you haven’t saved. See Approve every model from one company.
The policy uses All models except blocked, which makes new models available right away. Switch to Approved models only if you want to approve each new model first.
Model Access rules require a Business or Enterprise plan. Contact sales to upgrade.
Only organization owners and admins can edit organization rules. Ask one of them to make the change.
Another admin saved that policy while you were editing it, and Krea loaded their version. Make your changes again and save.
Every model Auto could use is blocked for you. Pick a model yourself, or ask an admin for access.
They moved to Model Access. See What changed.

Need help?

Enterprise support

Email our enterprise support team at support@krea.ai.

Sales team

Ask about Business or Enterprise plans at sales@krea.ai.