Allowed Models
Amp Enterprise workspace admins can choose which models the members of their workspace can use. Open the workspace settings page, go to “Model Routing”, and then open “Allowed Models”.
Allowed Models is rolling out to Enterprise workspaces. If the page says it is not enabled for your workspace yet, contact support.
Default Policy
Every model starts enabled. On the “Default Policy” tab, turn off the models you do not want members to use and press Save.
Members cannot pick a disabled model in the mode picker, in Tune Modes, or in the CLI, and Amp refuses to run a thread on it. A thread that was already using a model when you disabled it stops at its next message, and the CLI shows “Model Not Available” with a link to the list of models.
Locked Models
Some models cannot be disabled because a built-in mode currently uses them. Amp locks every model
that low, medium, high, ultra, Puck, or a built-in subagent routes to in your workspace, so a
change on this page can never break a mode. The page lists these models with the roles that use
them.
To disable a locked model, open Mode Dial in workspace settings and pin a different model for every role that uses it. Then return to Allowed Models. See Tune the Modes. A workspace pin to a model that is disabled keeps that model enabled for everyone while the pin exists.
Group Access
If your workspace has directory sync enabled (via WorkOS SCIM), the “Group Access” tab lists the groups from your identity provider. You can give the members of a group models that are disabled for everyone else. Press Choose Models on a group, select the models, and save.
Grants only add access. A member of several groups gets every model that any of their groups grants. When you enable a model for everyone, its grants are removed. When a group is deleted in your identity provider, its grant is listed under “Groups No Longer in Your Directory”, and you can remove it there.
Group Access uses the same directory groups as Directory Group Entitlements.
Personal Pins
A member can still pin models for their own modes in Mode Dial. A personal pin to a disabled model is ignored, and the role uses the workspace pin or Amp’s default model instead. The pin is kept, so it works again if you enable the model later.