Short answer: For supported surfaces, an authorized administrator can supply provider credentials; this is not yet a global processor-selection or AI-disable control.
The configuration resolves in this order:
- workspace-specific provider, model and API-key override;
- partnership-level configuration; then
- Frepi's platform default when no customer override is set.
Supported configuration can route some AI requests through the
customer's own OpenAI, Anthropic or xAI account. If a selected
provider lacks a usable key, the resolver can select another
configured provider. Analysis Studio classification can use a
separate platform provider and model. Removing an override moves
the workspace back to inherited Frepi configuration. API keys are
masked in responses, but masking is not encryption and complete
application-level encryption of these keys remains open work.
Bring-your-own-key affects routing and billing on supported paths;
it is not a tenant boundary or proof that every AI feature uses the
same account. Frepi still orchestrates requests, and enabled
background features may process content without a contemporaneous
user prompt. Customers needing a single provider or no AI processing
should require a feature-by-feature configuration and contract term.