Teams

Govern the shared layer. Leave the developer loop alone.

Sofia Cloud gives organizations control over identity, models, money, capabilities, and policy while the coding session remains local by default.

SSOOIDC + SAML
SCIMusers + groups
MCPscoped access
Auditorganization events
Access

Model access follows the team.

Team grants are evaluated when inference and capabilities run, so changing a group or policy changes real runtime access.

Identity

Provision from the IdP.

Use OIDC or SAML for sign-in and SCIM for users and groups. SCIM groups map to Sofia teams and their grants.

Models

Grant by organization or team.

Make low-cost models broadly available, reserve expensive models for specific teams, and combine grants with daily or monthly budgets.

Capabilities

Share tools without sharing credentials.

Connections and MCP-backed capabilities can be exposed through Sofia’s gateway with scopes and revocable OAuth access.

Desktop policy

Set the operating envelope.

Manage versions, required settings, provider rules, and organization defaults without reimplementing policy in the desktop client.

Budgets

Spend policy is enforced before the call.

Organization, team, user, model, per-request, daily, monthly, and concurrency limits participate in inference admission. Prepaid accounts reserve expected cost before streaming starts.

policy evaluationallowed
organization   Ruut Engineering
team           Platform
model          sofia/claude-sonnet

per request    $0.42 / $1.00
team today     $18.21 / $50.00
member month   $74.09 / $120.00
concurrency    3 / 8

✓ reserve $0.42 and continue
Enterprise

Controls that map to operating questions.

The enterprise layer exists to answer who can access what, how much can it cost, which identity established access, and what happened afterward.

Authentication

OIDC and SAML with tested-before-enforced SSO configuration to avoid organization lockouts.

Provisioning

SCIM users and groups feed memberships and teams so access changes follow the organization directory.

Audit

Model grants, policy changes, connection changes, provisioning events, and administrative actions enter one audit stream.

Billing

Central prepaid or postpaid accounts, subscription entitlements, included credits, and usage-level reconciliation.

One policy layer, no mandatory model.

Centralize identity and governance while developers keep the provider and interface flexibility that made Sofia useful in the first place.