Sloth-ninja gives firms the keys without sidelining lawyers
JessicaOSS now lets a firm fund shared AI-provider access while preserving each member's personal choice.
Firm administrators can now manage a shared set of provider keys for the whole firm. A member's own key still takes priority, while self-hosted setups without firm accounts continue as before.
- Shared provider access: admins can provision firm-wide access without exposing the underlying key material.
- Member management: admins can view members and change roles within their own firm, with a safeguard against removing the final administrator.
- Stronger controls: changing keys or roles requires an extra MFA check.
- Clear boundaries: members can see when a firm supplies access, while the new policies area is explicitly a preview rather than a promise of enforcement.
The work is tested across key precedence, encryption, access control and the new admin journeys.
Spotted something wrong? Or know the PR text has fresher detail than the writeup above?