Pilot phase

Route, approve and account for every AI request.

Know who uses which AI, for what, and at what cost. Marshal is a private control plane for enterprise AI: approved access, scoped keys, quotas, and reports your CIO, FinOps and auditors can rely on, deployed in your data center or VPC.

The problem

AI use grows from the bottom up.

Personal accounts, shared keys, tools nobody registered. When finance asks what it costs, or audit asks who approved it, there's no single answer.

What Marshal does

Access with approval chains

  • Staff request a model and a quota.
  • The request goes through your approval chain: as many levels as your organization needs, in your order.
  • Once approved, a scoped key is issued with quota and expiry.
  • Every step is recorded.

Usage intelligence

  • Usage by project, department, provider and model: tokens, cost, latency.
  • Work versus personal or unclassified use.
  • Reports for management, FinOps, security and audit.

Policy that fails closed

  • Requests outside the allowed provider, model, region or quota are denied, with a clear reason.
  • No silent fallback to something unapproved.

Private by default

  • Runs in your environment.
  • Provider keys stay in your secret store; applications never see them.
  • Prompts and responses are not stored unless your policy says so.
One request, start to finish

From request to key, on the record.

The same object that was requested and approved is the one that gets metered and reported. So "who approved this" and "what was used under it" have one answer.

  • Access requested: model + monthly quotasubmitted
  • Team managerapproved
  • IT securityapproved
  • FinOpsapproved
  • Scoped key issued, with quota and expiryrecorded
  • Later request uses a model outside the approvaldenied · reason logged

Example. Levels and order are set by your organization.

Reports

Answers for each person who asks.

Reports use metadata and aggregates, so they don't need copies of sensitive content.

CIO / ITWhich providers, connections and models are in use, by which projects?
FinOpsWhat does it cost, by department and project, against quota and budget?
Security / AuditWho requested, who approved, when, and what was used under that key?
Department headsWhat is my team using, and is it within what we approved?
Marshal + Legwork

Bottom-up use, top-down view.

Employees use Legwork to get more from the AI they already have. Marshal shows IT what it's used for and what it saves.

Fits how your organization approves things

Approval chains with as many levels as your process needs, in your order. Reports shaped to your departments and projects. Our implementation team configures it with you, without custom code forks.

Designed for standard interfaces

Built around OpenAI- and Anthropic-compatible APIs, MCP and OpenTelemetry, so it governs the tools you already run instead of replacing them.

Pilot phase

Start with a pilot in your environment.

A time-boxed pilot with acceptance criteria agreed up front. We run a small number at a time.