
Build an organization allowlist
Select Set an org allowlist, then filter the catalog by any combination of these fields:
A model must match every field you set. Leave a field empty when you do not want
to filter on it. Blocked providers always take precedence.
The match counter updates as you edit. Select it to review the exact models that
will remain available before you save.

What model access covers
Model access applies to LLM and embedding calls. When a call requests a disallowed model, Opper returns an error that identifies the model and the rule it failed. Opper does not silently switch to a different model. Model access does not currently apply to:- Image, speech, and video generation. Use spend limits to bound their cost.
- Virtual and router models, which filter the variants they can use separately.
Route rules must point to a model that the same scope can
use. If an allowlist change would invalidate an existing route, Opper asks you
to resolve the conflict before saving.
Narrow access for a project
Select Narrow model access for a project to add an override. A project override intersects with the organization rule: it can remove access, but it cannot restore a provider, region, country, or model that the organization rule excluded. The override summary shows the effective result, not just the fields you added:
If older organization rules exist
The runtime uses only the newest enabled organization allowlist. Older organization allowlists have no effect and do not intersect with it. Rules shows the active allowlist and tells you when older rules are still present so you can remove them. Project overrides still intersect with the active organization allowlist.Model access under Zero Data Retention
When Zero Data Retention is enabled, model access is locked to providers with zero-retention agreements. The fields become read-only and the counter shows the models available from those providers.