Skip to main content
Who does what, per model. G = Galtea, C = Customer, G+C = shared, with the split described in the notes.

Models 1 to 3: Galtea operates the infrastructure

Models 4 and 5: you operate the infrastructure

Notes on the shared items

Network design in a private tenant. Galtea designs and operates the tenant network. You decide how your side reaches it (VPN client, site-to-site routing peer, private link, or peering) and which of your IP ranges are allowed. Galtea implements what you decide. Group-to-role mapping in federated mode. You own the groups in your directory. Galtea owns which product permissions each role carries. The mapping between them is agreed once and then driven entirely by your directory: a membership change on your side takes effect at the user’s next sign-in. LLM provider configuration in a private tenant. Galtea configures the gateway. You decide whether inference runs on Galtea’s provider accounts or on yours, and whether the model set is restricted to an approved subset. Egress allowlist in a private tenant. You tell Galtea which of your endpoints the platform must call. Galtea adds them to the allowlist. Nothing else is reachable. Product bugs in a self-hosted install. Galtea fixes bugs and ships a version regardless of model. In a self-hosted install Galtea cannot see your environment, so reproducing the bug depends on the logs and version information you provide, and applying the fix depends on you upgrading.

The one-sentence version

In models 1 and 2 you manage users and test data, and nothing else. In model 3 you additionally decide the network and identity boundary while Galtea still operates everything. In model 4 you operate a platform that Galtea builds and supports.