PandaOS for Enterprise

Everyone in the team on AI. The company at the wheel.

Your teams work with AI in PandaOS every day. PandaOS for Enterprise comes with a governance layer: you decide which models, tools and permissions each team gets, and every rule applies the moment you publish it.

PandaOS ConsoleIT admin
Sets sending email to Ask for the Sales team.
PandaOS appJonas, Sales
Before the follow-up goes out, Jonas checks it and allows it.
1 / 4

Ten AI tools. Ten contracts. No oversight.

You cannot steer what you cannot see.

Ten sets of terms

Each vendor sets its own retention and hosting.

Ten bills

None of them says what a team actually costs.

No single rule

Nobody can enforce which AI may touch which data.

Private sign-ups

Personal accounts the company never sees.

One workspace for the team. One set of rules for you.

Every employee gets one AI workspace. The company gets one place to shape it.

Share

What compounds

A company library

Publish skills, agents, rules and starters to the teams that need them. Mark a skill as required and it is in every chat from the next session on.

Starters with your setup built in

New projects begin with your conventions, your rules and your house style.

Knowledge that stays

What your teams work out becomes shared knowledge, with every claim traced to its source.

Govern

What you control

Permissions per team

Files, shell, browser, apps and MCP tools, each set to run automatically, read-only, ask first or blocked.

Approved models only

Every call goes through the PandaOS gateway. Each team sees the models you allowed and nothing else.

Spend that stops at the limit

Monthly allowances per team and per member, enforced at the gateway. A member at the limit stops, rather than overspending and being invoiced later.

The console behind it

One place for your IT team. Every change is versioned and reaches every seat the moment you publish it.

SalesCustom settings, 1 field
Tool permissions
The most a member may allow. They can always choose something stricter.
File reads
Reading files in a project
AutoAskOff
File writes
Creating and editing files
AutoAskOff
Shell commands
Terminal commands the agent runs
AutoAskOff
Browser
The embedded browser tools
AutoAskOff
App tool callsCustom
Tools of the allowed PandaOS Apps, such as Gmail or HubSpot
AutoAskOff
MCP tool calls
Tools of the allowed MCP servers
AutoAskOff

Permission matrix

One grid for the whole company. Lock a rule for everyone, or let a team go further where it needs to.

Models
Your keys, your models. Each one tagged with where it runs.
Claude Opus 5.5Google Vertex AI keyHigh
Claude Sonnet 5.5Google Vertex AI keyMedium
GPT-6.1 SolOpenAI keyHigh
Gemini 3.1 ProGoogle Vertex AI keyMedium
Mistral LargeAzure AI Foundry keyLow
Kimi K3Fireworks AI keyUtility

Models and keys

Bring your own keys for OpenAI, Anthropic, Azure OpenAI, Azure AI Foundry, Google Gemini, Google Vertex AI, Fireworks AI, Together AI or OpenRouter. Choose the models, pin them to tiers and decide which team may use which.

TeamsMembersService accounts
Resets on 1 November
MemberTeamUsed this monthMonthly allowance
Anna Klein
a.klein@northwind.eu
Finance
$112
Raised$250
Jonas Weber
j.weber@northwind.eu
Sales
$74
$120
Lea Moreau
l.moreau@northwind.eu
Support
$41
$80
Sophie Lang
s.lang@northwind.eu
Marketing
$96
$120
Markus Faber
m.faber@northwind.eu
Engineering
$184
$300

Limits and usage

See spend by team, member and model. Set monthly allowances and raise them for one person where it makes sense.

Catalog servers
Members can connect the allowed ones. Tool rules apply on top.
HubSpot
Sales, Marketing
Deleting: Off
Atlassian
All teams
Writes: Ask
Google Drive
All teams
Sharing: Ask
Zendesk
Support
Auto
Salesforce
Not allowed

MCP control

Allow the servers you trust, block the rest, and decide tool by tool which actions need a human.

MembersInvites
MemberTeamRoleSeat
Anna Klein
a.klein@northwind.eu
FinanceMemberPro
Jonas Weber
j.weber@northwind.eu
SalesMemberPro
Lea Moreau
l.moreau@northwind.eu
SupportMemberPro
Sophie Lang
s.lang@northwind.eu
MarketingAdminPro
Markus Faber
m.faber@northwind.eu
EngineeringMemberPro

Members and seats

Invite people by email and assign seats and teams. Offboard someone in one step. Keys are revoked and the seat is freed.

Rolled out in three steps

Your IT team sets it up once. Your people keep working in the tool they already know.

Create your organization

Add your provider keys, invite your people and sort them into teams.

Set the rules

Choose models, permissions and limits per team, and publish the skills and agents everyone should have.

Your teams open PandaOS

No extra installs and no new tool to learn. The rules are already in place, and every later change reaches everyone automatically.

Built for the security review

The questions your IT, data protection officer and works council will ask, answered up front.

Keep data in the EU

Mark every model by where it runs, and keep a team or the whole company on models hosted inside the EU.

Optional guardrails for sensitive data

Switch on per team: credentials are blocked and personal data is redacted before a prompt leaves the machine.

Versioned policies

Every policy is versioned. Compare any two versions and roll back in one click.

Offboarding in one step

When someone leaves, one step is enough. Keys are revoked and the seat is freed.

Your keys, your contracts

Bring the provider accounts you already have. PandaOS never uses your data to train models. With your own keys, your provider agreement applies.

Agents never get more rights than people

An agent works with the permissions of the person who starts it. What that person may not do, the agent may not do either.

Built in beats bolted on

Other tools sell governance on its own: a dashboard watching tools it does not control. PandaOS is the workspace the work happens in, with governance built in.

Rules inside the work, not beside it

Policies apply in the workspace your teams already use every day. Nobody has to remember them, and nobody can route around them.

Built once, used by every team

A skill, an agent or a starter written for one team reaches everyone who needs it, and improves for all of them.

Works with the models you already pay for

Bring your keys for OpenAI, Anthropic, Azure OpenAI, Azure AI Foundry, Google Gemini, Google Vertex AI, Fireworks AI, Together AI or OpenRouter. You stay their customer, and PandaOS decides who may use what.

Put the company at the wheel.

Tell us how many people and teams you have. We set up your organization together with you.

FAQ

Where is our data processed?

Model traffic runs through our gateway in Frankfurt. You choose which models each team may use, including models hosted only in the EU.

Can we use our existing AI contracts?

Yes. Add your own keys for OpenAI, Anthropic, Azure OpenAI, Azure AI Foundry, Google Gemini, Google Vertex AI, Fireworks AI, Together AI or OpenRouter, and PandaOS uses them under your policy.

What does the company see about individual employees?

Usage and spend per member, and which policy applied. Prompts and responses are not stored, so there is nothing to read back.

What do employees notice?

The same PandaOS, with only the models, tools and skills you approved. Where an action needs approval, they are asked directly in the chat.

How quickly does a policy change apply?

As soon as you publish it. Every seat picks up the new version automatically.

How is it priced?

Per seat, and each seat carries a PandaOS plan. Talk to us and we will put together an offer for your teams.

Do you train on our data?

No. PandaOS never uses your data to train models. With your own keys, your provider agreement applies.