Control which models people use
Set the default model and limit which models Claude Code and Codex can run, for the whole organization or one team.
The Models page sets two things for each coding agent: which model new sessions start on, and which models people are allowed to run. You set an organization baseline, then override it for specific teams. The Tokenize desktop app applies the rules on each person's computer.
Who can do this: Admins. Everyone else sees a read-only view of the models their organization allows them to run.
How the page is laid out
Go to Models. There is one card per agent: Claude Code and Codex. Each card has:
- Default model: the model new sessions start on. Choose Provider default to let the agent pick its own model.
- Limit models: when on, devices can run only the models you allow. When off, devices can run any model for that agent.
- A list of models, each with an on/off switch, shown when Limit models is on. A model is allowed when its switch is on.
When Limit models is on, the default has to be one of the allowed models.
Set the organization baseline
- Go to Models. Make sure the scope picker at the top right says Organization.
- On each agent's card, choose a Default model.
- Turn Limit models on if you want to restrict models. Then turn each model's switch on or off.
- Click Save changes. To undo edits you haven't saved, click Discard.
Organization settings apply to every team unless a team overrides them.
Override a team
- In the scope picker, choose the team. Teams come from your directory. See SSO and directory sync.
- Change the Default model or the allowed models. Anything you change shows an Override badge.
- Click Save changes.
A team without its own setting inherits from its parent team, then from the organization. Limit models can only be turned on or off at the organization level. On a team, it shows as Limited or Open.
To remove all of a team's overrides, choose the team and click Reset to organization, then Save changes.
When changes take effect
Changes reach devices in about 15 minutes. Once a device has the new rules:
- Claude Code: sessions already open keep their old settings. Start a new session to pick up the change.
- Codex Desktop: quit and reopen the app. Closing the window isn't enough, because Codex keeps running in the background.
- Codex CLI: each new command picks up the change.
People who don't have the Tokenize desktop app installed aren't affected. See Install on your computer.
Troubleshooting
"Team scopes are unavailable — listing teams needs usage access, which your role does not have." Your role can edit models but can't read the team list. You can still edit the organization baseline. Ask an admin to add usage access to your role.
"Someone else saved this policy — it was reloaded and your changes re-applied; review and retry." Another admin saved while you were editing. Check the page, then click Save changes again.
A team can't choose Provider default. A team can only choose Provider default if neither the organization nor a parent team has chosen a default model.