Governed chat
Kavros Chat gives employees productive access to LLM providers through the same governance plane that watches your agents: approved models, DLP on prompts and responses, per-team budgets, and retention you control. Providers are yours (BYOK) — Kavros routes and governs, and your provider keys never leave your deployment.
Providers and routing
- Bring your own keys. Configure your own provider accounts (OpenAI, Anthropic, and others); Kavros stores the routing, not your vendor relationship.
- Model allowlists decide which models employees can reach at all.
- Automatic fallback keeps chat working when a provider degrades, and cost-aware routing can prefer the least-expensive approved model that satisfies the request.
- Per-model daily spend caps keep a runaway workflow or a viral prompt from becoming a surprise invoice.
DLP on prompts and responses
Every chat message and completion passes the same DLP inspection the egress path uses. Rules are org-configurable; matches are blocked or flagged with the rule name recorded, and hit counts feed each team's risk view. PII patterns, custom regexes, and secret patterns all work the same way as agent-side DLP.
Quotas, budgets, and visibility
- Org-wide budgets with alert thresholds, per-team quotas, and per-user limits —
- token and dollar metering per conversation, roll up into the same usage views as agents,
- usage dashboards show which teams are spending what, on which models.
Privacy and retention
Chat retention is configurable — keep everything, keep a window, or keep summaries. Privacy lanes control what is stored versus inspected-and-discarded, and the configuration is part of the deployment's governed settings, not a per-user toggle.
Access and identity
Chat respects your identity stack: SSO for login, team and org structure for quotas and visibility, and admin-configurable auto-approval policies for low-risk actions. Employee chat and agent governance share one audit story — the same export, the same hash chain.