Abu Enterprise

AI productivity for every employee.
Cost, data, and risk under control.

Centralize model access, knowledge permissions, policy audit, and usage budgets so the enterprise keeps cost, data, and risk under control.

Unified gateway Employees do not handle raw provider keys
Team controls Budgets, RPM limits, model allowlists, and ACLs
Knowledge loop Org, team, and personal KBs with retrieval
Private deployment Governance data stays in the enterprise control plane
Why Enterprise

Employees are already using AI. The organization needs to manage it.

The open-source edition helps individuals move faster. At team scale, enterprises need to manage cost, access, knowledge, and risk.

01

AI spend becomes opaque

When everyone brings their own model key, it is hard to see usage, spend, and over-budget teams.

Enterprise answer

Route model calls through the enterprise gateway, set team budgets and RPM limits, and review usage and cost in the console.

02

Access boundaries are unclear

Models, knowledge bases, Skills, MCP services, and file access cannot live only in personal settings.

Enterprise answer

Use organizations, departments, roles, ACLs, and client-side policy checks before tool, Skill, and MCP calls run.

03

Company knowledge stays buried

Policies, FAQs, product docs, project files, and meeting notes need to become trusted AI context.

Enterprise answer

Enterprise KBs ingest documents, chunk and embed them, retrieve with hybrid search, cite sources, and audit queries.

04

Tool risk is hard to trace

User-installed extensions and internal-system connections need source, permission, credential, version, and usage records.

Enterprise answer

Skills go through upload, scan, review, publish, and signature checks. MCP services go through catalog, review, ACL, and credential governance.

Product Shape

Not another client. A governance layer on top of Abu.

Employees use AI in the desktop client while administrators manage organization, models, knowledge, tools, and governance policies in a private console.

Employee side: familiar workflow

Employees keep using Abu to start tasks, call tools, and run Skills. After binding, the client uses enterprise models, knowledge bases, approved Skills, and transparency views.

Enterprise binding Enterprise models Enterprise KB Approved Skills

Admin side: central control

Admins manage departments, roles, models, budgets, knowledge bases, Skills, MCP services, policies, and audit so AI usage has boundaries and records.

Access control Cost governance Tool approval Audit trail
Core Capabilities

Identity, cost, knowledge, extensions, security, and operations

These are grouped around the practical enterprise questions buyers ask during rollout: what can be configured, distributed, controlled, and traced.

Identity

Identity and organization governance

Bring organizations, departments, employees, roles, and login methods into one control plane.

  • Password, Magic Link, OIDC SSO, and desktop Device Flow
  • Organization, department tree, users, roles, and permission matrix
  • Invites, pending approvals, sessions, and license seats
Gateway

Model gateway and cost controls

Centralize scattered model keys, providers, and AI spend in the enterprise control plane.

  • LiteLLM gateway, multiple providers, and encrypted provider-key storage
  • Team budgets, RPM limits, model allowlists, and connectivity tests
  • Token, spend, and call usage by user, team, and model
Knowledge

Enterprise knowledge bases

Turn internal documents into trusted context Abu can retrieve, cite, and audit.

  • PDF, Word, HTML, Markdown, and plain text ingestion
  • pgvector vector search + BM25 full-text search + RRF ranking
  • Org, team, and personal KB scopes with ACLs
Extensions

Trusted Skill and MCP extensions

Make internal capabilities and external tool connections publishable, authorized, signed, and traceable.

  • Skill upload, manifest parsing, security scan, review, and publish flow
  • Skill ACLs, signature verification, and client install records
  • MCP catalog sync, review, ACLs, and authorized credential access
Policy

Security policies enforced locally

Push org-level and team-level policies to the desktop client so sensitive actions are blocked or confirmed before execution.

  • Tool blacklist, tool confirmation rules, Skill/MCP blacklists
  • File path allowlists and blocklists
  • Enterprise policy hooks run before local tool calls
Ops

Audit, transparency, and operations

Admins see governance outcomes. Employees can inspect their own enterprise data and usage.

  • Admin audit logs, sensitive-field redaction, usage, and cost dashboards
  • Employee transparency: profile, tokens, audit, and usage
  • Quality feedback, diagnostic logs, diagnostic bundles, and self-hosted observability entry
Deployment

Start with a private single-host deployment for PoC and mid-sized rollout

The enterprise console is deployed separately. Enterprise desktop capabilities are delivered through enterprise builds and private modules, not through the public release package.

Delivery

Privately deployed control console

The standard deployment includes Console, Postgres/pgvector, LiteLLM, Nginx, Redis, MinIO, and optional observability or KB enhancement components.

Scale

50 to 2,000 seats

PoCs and 50-500 person teams can start with the default deployment. 500-2,000 seats should tune database, gateway, and observability resources. Larger environments need a dedicated HA design.

Compliance

Ready for private-environment adaptation

The database layer stays close to standard Postgres, images support amd64/arm64, and local model or private-provider paths can be validated for each customer environment.

Open Source vs Enterprise

Same client core. Enterprise adds organization-level governance.

The open-source edition is for individuals and small teams. Enterprise is for organizations that need centralized cost, access, knowledge, extension, and audit control.

Open Source

A full AI work assistant for one person

Local-first desktop app with user-managed model keys and local configuration. Best for individuals, developers, and small-team trials.

Free and open source · Local usage · Self-managed
Enterprise

A governable AI platform for a team

Employees keep using Abu while the enterprise controls people, models, budgets, knowledge, extensions, policies, and audit in a private console.

Private deployment · Seat license · PoC available
Area
Open Source
Enterprise
Core work capabilities: both editions share the same Abu client core
AI desktop work assistant
AvailableChat, task execution, tool calls, Skills, and local workspace collaboration.
InheritedSame desktop experience, plus enterprise binding and governance.
Local-first data model
IncludedConversations, memory, files, and projects stay local by default.
IncludedEnterprise configuration, authorization, audit, and usage flow to the private console.
Enterprise governance capabilities: added by the enterprise edition
Identity and login
Not includedNo enterprise identity, SSO, or member approval.
IncludedPassword, Magic Link, OIDC SSO, desktop Device Flow, and member approval.
Org, department, and role access
Not includedNo organization-level access control.
IncludedOrganization, department tree, users, roles, permission matrix, and resource ACLs.
Model keys and gateway
PersonalUsers manage their own provider keys and bills.
CentralizedRaw keys are encrypted in the console and calls use the enterprise gateway.
Budgets, rate limits, and model allowlists
Not includedNo organization-level controls.
IncludedTeam budgets, RPM limits, and allowed model ranges.
Usage and cost dashboards
Not includedNo centralized enterprise reporting.
IncludedToken, call, and cost reporting by user, department, and model.
Enterprise knowledge bases
Not includedLocal context and personal memory only.
IncludedOrg, team, and personal KBs with hybrid retrieval, citations, and ACLs.
Enterprise Skill marketplace
Not includedUsers can only install and maintain Skills themselves.
IncludedUpload, scan, review, publish, authorize, verify, and record installs.
Enterprise MCP governance
Not includedUsers can only configure local MCP services themselves.
IncludedCentral registration, sync, review, authorization, and credential governance.
Enterprise security policies
Not includedPersonal permission modes and local settings only.
IncludedTool blocks, confirmations, extension blocks, and file path policies.
Audit, transparency, and diagnostics
Not includedNo centralized enterprise audit or diagnostics.
IncludedAdmin audit, transparency, feedback, logs, and diagnostic bundles.
Deployment, licensing, and branding
Not includedOpen-source repository and public releases only.
IncludedPrivate console, enterprise builds, license, logo/color, and controlled delivery.

Note: enterprise MCP in the current client focuses on catalog browsing and authorized credential access, so organizations can centralize approved tools and credential scope first.

PoC / Demo

Want to see how Abu Enterprise fits your team?

Start with a demo or small PoC: deployment shape, login method, model providers, knowledge samples, and the first approved enterprise Skills.