docs: present AI Governance as included with Premium (#27545)

## Summary

AI Governance is now included with Premium licenses instead of being
sold as a separate per-user add-on. This updates `docs/` to describe the
new packaging, removes "Add-On" from AI Governance references, and
refreshes the editions architecture diagram.

## Changes

- **`docs/ai-coder/ai-governance.md`**: title is now "AI Governance";
rewrote the licensing statements (previously "a separate, per-user
license... not included with a Premium subscription and must be
purchased separately") to state it is included with Premium. The
usage-pool section now attributes the shared Agent Workspace Build pool
to Premium deployments.
- **Repeated admonition (28 files under `ai-coder/agent-firewall/` and
`ai-coder/ai-gateway/`)**: replaced "requires the AI Governance Add-On /
as of Coder v2.32, deployments without the add-on..." with "is part of
AI Governance, which is included with a Premium license." The v2.32
add-on gate no longer applies; the gate is now Premium vs. Community.
- **`docs/ai-coder/index.md`, `security.md`, `tasks.md`,
`usage-data-reporting.md`, `admin/licensing/index.md`,
`install/releases/esr-2.29-2.34-upgrade.md`,
`ai-gateway/ai-gateway-proxy/setup.md`,
`ai-gateway/clients/claude-code.md`**: reworded add-on references to
Premium inclusion.
- **`docs/manifest.json`**: nav title "AI Governance Add-On" → "AI
Governance", updated two descriptions, and swapped the 25 `"state": ["ai
governance add-on"]` badges to `["premium"]` so the sidebar badge reads
"Premium" instead of "AI Governance Add-On".
- **`docs/images/single-region-architecture.png`**: refreshed the
diagram in the **Community and Premium editions** tab on
[Architecture](https://coder.com/docs/admin/infrastructure/architecture).
Also deleted the unreferenced `single-region-architecture.svg` copy.

## Follow-ups outside this PR

- The `"ai governance add-on"` doc-state badge is defined in
`coder/coder.com` (`src/utils/docs/state.ts`). After this merges, no
manifest entry uses that key, so it becomes dead config and can be
removed there.
- `enterprise/coderd/license/license.go:564-572` still warns admins that
"The AI Governance add-on is required to use AI Gateway." That backend
string will contradict these docs once shipped.

## Verification

- `pnpm run lint-docs`: 0 errors across 504 files
- `make lint/emdash`: clean
- Vale on the changed Markdown files: 0 errors; remaining warnings are
pre-existing gerund headings on untouched lines
- `docs/manifest.json` validated as JSON
- Confirmed the deleted SVG had no references anywhere in the repo

---

PR generated with Coder Agents on behalf of @mattvollmer.
This commit is contained in:
Matt Vollmer
2026-07-29 08:45:20 -04:00
committed by GitHub
parent fb30674806
commit 4987afada7
39 changed files with 113 additions and 364 deletions
+2 -3
View File
@@ -7,9 +7,8 @@ autonomous programs, such as AI agents, can access and use.
of Agent Firewall blocking a process.
> [!NOTE]
> Agent Firewall requires the [AI Governance Add-On](../ai-governance.md).
> As of Coder v2.32, deployments without the add-on will not be able to
> access Agent Firewall.
> Agent Firewall is part of [AI Governance](../ai-governance.md), which is
> included with a Premium license.
>
> Agent Firewall was previously known as "Agent Boundaries". Some
> configuration options and internal references still use the old name
+2 -3
View File
@@ -1,9 +1,8 @@
# landjail Jail Type
> [!NOTE]
> Agent Firewall requires the [AI Governance Add-On](../ai-governance.md).
> As of Coder v2.32, deployments without the add-on will not be able to
> access Agent Firewall.
> Agent Firewall is part of [AI Governance](../ai-governance.md), which is
> included with a Premium license.
landjail is Agent Firewall's alternative jail type that uses Landlock V4 for
network isolation.
@@ -1,9 +1,8 @@
# nsjail on Docker
> [!NOTE]
> Agent Firewall requires the [AI Governance Add-On](../../ai-governance.md).
> As of Coder v2.32, deployments without the add-on will not be able to
> access Agent Firewall.
> Agent Firewall is part of [AI Governance](../../ai-governance.md), which is
> included with a Premium license.
This page describes the runtime and permission requirements for running Agent
Firewall with the **nsjail** jail type on **Docker**.
+2 -3
View File
@@ -1,9 +1,8 @@
# nsjail on ECS
> [!NOTE]
> Agent Firewall requires the [AI Governance Add-On](../../ai-governance.md).
> As of Coder v2.32, deployments without the add-on will not be able to
> access Agent Firewall.
> Agent Firewall is part of [AI Governance](../../ai-governance.md), which is
> included with a Premium license.
This page describes the runtime and permission requirements for running Agent
Firewall with the **nsjail** jail type on **Amazon ECS**.
+2 -3
View File
@@ -1,9 +1,8 @@
# nsjail Jail Type
> [!NOTE]
> Agent Firewall requires the [AI Governance Add-On](../../ai-governance.md).
> As of Coder v2.32, deployments without the add-on will not be able to
> access Agent Firewall.
> Agent Firewall is part of [AI Governance](../../ai-governance.md), which is
> included with a Premium license.
nsjail is Agent Firewall's default jail type that uses Linux namespaces to
provide process isolation. It creates unprivileged network namespaces to control
+2 -3
View File
@@ -1,9 +1,8 @@
# nsjail on Kubernetes
> [!NOTE]
> Agent Firewall requires the [AI Governance Add-On](../../ai-governance.md).
> As of Coder v2.32, deployments without the add-on will not be able to
> access Agent Firewall.
> Agent Firewall is part of [AI Governance](../../ai-governance.md), which is
> included with a Premium license.
This page describes the runtime and permission requirements for running Agent
Firewall with the **nsjail** jail type on **Kubernetes**.
+2 -3
View File
@@ -1,9 +1,8 @@
# Rules Engine Documentation
> [!NOTE]
> Agent Firewall requires the [AI Governance Add-On](../ai-governance.md).
> As of Coder v2.32, deployments without the add-on will not be able to
> access Agent Firewall.
> Agent Firewall is part of [AI Governance](../ai-governance.md), which is
> included with a Premium license.
## Overview
+2 -3
View File
@@ -1,9 +1,8 @@
# Version Requirements
> [!NOTE]
> Agent Firewall requires the [AI Governance Add-On](../ai-governance.md).
> As of Coder v2.32, deployments without the add-on will not be able to
> access Agent Firewall.
> Agent Firewall is part of [AI Governance](../ai-governance.md), which is
> included with a Premium license.
## Recommended Versions
@@ -1,9 +1,8 @@
# AI Gateway Proxy
> [!NOTE]
> AI Gateway Proxy requires the [AI Governance Add-On](../../ai-governance.md).
> As of Coder v2.32, deployments without the add-on will not be able to
> access AI Gateway Proxy.
> AI Gateway Proxy is part of [AI Governance](../../ai-governance.md), which is
> included with a Premium license.
AI Gateway Proxy extends [AI Gateway](../index.md) to support clients that don't allow base URL overrides.
While AI Gateway requires clients to support custom base URLs, many popular AI coding tools lack this capability.
@@ -5,7 +5,7 @@ Once enabled, `coderd` runs the AI Gateway Proxy in-process and intercepts traff
**Required:**
1. AI Gateway must be enabled and configured (requires the [AI Governance Add-On](../../ai-governance.md)). See [AI Gateway Setup](../setup.md) for further information.
1. AI Gateway must be enabled and configured (requires a Premium license, which includes [AI Governance](../../ai-governance.md)). See [AI Gateway Setup](../setup.md) for further information.
1. AI Gateway Proxy must be [enabled](#proxy-configuration) using the server flag.
1. A [CA certificate](#ca-certificate) must be configured for MITM interception.
1. [Clients](#client-configuration) must be configured to use the proxy and trust the CA certificate.
+2 -3
View File
@@ -1,9 +1,8 @@
# Auditing AI Sessions
> [!NOTE]
> AI Gateway requires the [AI Governance Add-On](../ai-governance.md).
> As of Coder v2.32, deployments without the add-on will not be able to
> access AI Gateway.
> AI Gateway is part of [AI Governance](../ai-governance.md), which is
> included with a Premium license.
AI Gateway groups intercepted requests into **sessions** and **threads** to show
the causal relationships between human prompts and agent actions. This
+2 -1
View File
@@ -1,7 +1,8 @@
# Authentication
> [!NOTE]
> AI Gateway requires the [AI Governance Add-On](../ai-governance.md).
> AI Gateway is part of [AI Governance](../ai-governance.md), which is
> included with a Premium license.
AI Gateway authenticates clients with the same Coder API token
that a user already uses against the rest of the Coder API.
@@ -1,9 +1,8 @@
# Claude Code
> [!NOTE]
> AI Gateway requires the [AI Governance Add-On](../../ai-governance.md).
> As of Coder v2.32, deployments without the add-on will not be able to
> access AI Gateway.
> AI Gateway is part of [AI Governance](../../ai-governance.md), which is
> included with a Premium license.
Claude Code can be configured using environment variables. All modes require a **[Coder API token](../../../admin/users/sessions-tokens.md#generate-a-long-lived-api-token-on-behalf-of-yourself)** for authentication with AI Gateway.
@@ -82,7 +81,7 @@ module "claude-code" {
workdir = "/path/to/project" # Set to your project directory
ai_prompt = data.coder_task.me.prompt
# Route through AI Gateway (AI Governance Add-On)
# Route through AI Gateway
enable_ai_gateway = true
}
```
+2 -3
View File
@@ -1,9 +1,8 @@
# Cline
> [!NOTE]
> AI Gateway requires the [AI Governance Add-On](../../ai-governance.md).
> As of Coder v2.32, deployments without the add-on will not be able to
> access AI Gateway.
> AI Gateway is part of [AI Governance](../../ai-governance.md), which is
> included with a Premium license.
Cline supports both OpenAI and Anthropic models and can be configured to use AI Gateway by setting providers.
+2 -3
View File
@@ -1,9 +1,8 @@
# Codex CLI
> [!NOTE]
> AI Gateway requires the [AI Governance Add-On](../../ai-governance.md).
> As of Coder v2.32, deployments without the add-on will not be able to
> access AI Gateway.
> AI Gateway is part of [AI Governance](../../ai-governance.md), which is
> included with a Premium license.
Codex CLI can be configured to use AI Gateway by setting up a custom model provider.
+2 -3
View File
@@ -1,9 +1,8 @@
# GitHub Copilot
> [!NOTE]
> AI Gateway requires the [AI Governance Add-On](../../ai-governance.md).
> As of Coder v2.32, deployments without the add-on will not be able to
> access AI Gateway.
> AI Gateway is part of [AI Governance](../../ai-governance.md), which is
> included with a Premium license.
[GitHub Copilot](https://github.com/features/copilot) is an AI coding assistant that doesn't support custom base URLs but does respect proxy configurations.
This makes it compatible with [AI Gateway Proxy](../ai-gateway-proxy/index.md), which integrates with [AI Gateway](../index.md) for full access to auditing and governance features.
+2 -3
View File
@@ -1,9 +1,8 @@
# Factory
> [!NOTE]
> AI Gateway requires the [AI Governance Add-On](../../ai-governance.md).
> As of Coder v2.32, deployments without the add-on will not be able to
> access AI Gateway.
> AI Gateway is part of [AI Governance](../../ai-governance.md), which is
> included with a Premium license.
Factort's Droid agent can be configured to use AI Gateway by setting up custom models for OpenAI and Anthropic.
+2 -3
View File
@@ -1,9 +1,8 @@
# Client Configuration
> [!NOTE]
> AI Gateway requires the [AI Governance Add-On](../../ai-governance.md).
> As of Coder v2.32, deployments without the add-on will not be able to
> access AI Gateway.
> AI Gateway is part of [AI Governance](../../ai-governance.md), which is
> included with a Premium license.
Once AI Gateway is setup on your deployment, the AI coding tools used by your users will need to be configured to route requests via AI Gateway.
@@ -1,9 +1,8 @@
# JetBrains IDEs
> [!NOTE]
> AI Gateway requires the [AI Governance Add-On](../../ai-governance.md).
> As of Coder v2.32, deployments without the add-on will not be able to
> access AI Gateway.
> AI Gateway is part of [AI Governance](../../ai-governance.md), which is
> included with a Premium license.
JetBrains IDE (IntelliJ IDEA, PyCharm, WebStorm, etc.) support AI Gateway via the [third-party model configuration](https://www.jetbrains.com/help/ai-assistant/use-custom-models.html#provide-your-own-api-key) feature.
@@ -1,9 +1,8 @@
# Kilo Code
> [!NOTE]
> AI Gateway requires the [AI Governance Add-On](../../ai-governance.md).
> As of Coder v2.32, deployments without the add-on will not be able to
> access AI Gateway.
> AI Gateway is part of [AI Governance](../../ai-governance.md), which is
> included with a Premium license.
Kilo Code allows you to configure providers via the UI and can be set up to use AI Gateway.
+2 -3
View File
@@ -1,9 +1,8 @@
# Mux
> [!NOTE]
> AI Gateway requires the [AI Governance Add-On](../../ai-governance.md).
> As of Coder v2.32, deployments without the add-on will not be able to
> access AI Gateway.
> AI Gateway is part of [AI Governance](../../ai-governance.md), which is
> included with a Premium license.
Mux makes it easy to run parallel coding agents, each with its own isolated workspace, from your browser or desktop; it is open source and provider-agnostic.
+2 -3
View File
@@ -1,9 +1,8 @@
# OpenCode
> [!NOTE]
> AI Gateway requires the [AI Governance Add-On](../../ai-governance.md).
> As of Coder v2.32, deployments without the add-on will not be able to
> access AI Gateway.
> AI Gateway is part of [AI Governance](../../ai-governance.md), which is
> included with a Premium license.
OpenCode supports both OpenAI and Anthropic models and can be configured to use AI Gateway by setting custom base URLs for each provider.
+2 -3
View File
@@ -1,8 +1,7 @@
> [!NOTE]
> AI Gateway requires the [AI Governance Add-On](../../ai-governance.md).
> As of Coder v2.32, deployments without the add-on will not be able to
> access AI Gateway.
> AI Gateway is part of [AI Governance](../../ai-governance.md), which is
> included with a Premium license.
VS Code's native chat can be configured to use AI Gateway via the **Custom Endpoint** language model provider (VS Code 1.122+, Stable). GitHub sign-in is not required, so this works in air-gapped or restricted environments.
+2 -3
View File
@@ -1,9 +1,8 @@
# Zed
> [!NOTE]
> AI Gateway requires the [AI Governance Add-On](../../ai-governance.md).
> As of Coder v2.32, deployments without the add-on will not be able to
> access AI Gateway.
> AI Gateway is part of [AI Governance](../../ai-governance.md), which is
> included with a Premium license.
Zed IDE supports AI Gateway via its `language_models` configuration in `settings.json`.
+2 -3
View File
@@ -18,9 +18,8 @@ AI Gateway solves 3 key problems:
use.
> [!NOTE]
> AI Gateway requires the [AI Governance Add-On](../ai-governance.md).
> As of Coder v2.32, deployments without the add-on will not be able to
> access AI Gateway.
> AI Gateway is part of [AI Governance](../ai-governance.md), which is
> included with a Premium license.
>
> AI Gateway was previously known as "AI Bridge". Visit [Rebranding Migration](./rebranding-migration.md) for details.
+2 -3
View File
@@ -1,9 +1,8 @@
# MCP
> [!NOTE]
> AI Gateway requires the [AI Governance Add-On](../ai-governance.md).
> As of Coder v2.32, deployments without the add-on will not be able to
> access AI Gateway.
> AI Gateway is part of [AI Governance](../ai-governance.md), which is
> included with a Premium license.
<!-- -->
+2 -3
View File
@@ -1,9 +1,8 @@
# Monitoring
> [!NOTE]
> AI Gateway requires the [AI Governance Add-On](../ai-governance.md).
> As of Coder v2.32, deployments without the add-on will not be able to
> access AI Gateway.
> AI Gateway is part of [AI Governance](../ai-governance.md), which is
> included with a Premium license.
AI Gateway records the last `user` prompt, token usage, model reasoning, and every tool invocation for each intercepted request. Each capture is tied to a single "interception" that maps back to the authenticated Coder identity, making it easy to attribute spend and behaviour.
+2 -1
View File
@@ -1,7 +1,8 @@
# Provider Configuration
> [!NOTE]
> AI Gateway requires the [AI Governance Add-On](../ai-governance.md).
> AI Gateway is part of [AI Governance](../ai-governance.md), which is
> included with a Premium license.
Providers are deployment-scoped and managed from the dashboard or the
[AI Providers API](../../reference/api/aiproviders.md). See
+2 -3
View File
@@ -1,9 +1,8 @@
# Reference
> [!NOTE]
> AI Gateway requires the [AI Governance Add-On](../ai-governance.md).
> As of Coder v2.32, deployments without the add-on will not be able to
> access AI Gateway.
> AI Gateway is part of [AI Governance](../ai-governance.md), which is
> included with a Premium license.
## Implementation Details
+15 -25
View File
@@ -1,4 +1,4 @@
# AI Governance Add-On
# AI Governance
Coder Workspaces already lets teams run AI tools like
[Cursor](https://registry.coder.com/modules/coder/cursor) and
@@ -7,10 +7,8 @@ development environments. As adoption grows, many enterprises also need
observability, management, and policy controls to support secure and auditable
AI rollouts.
The AI Governance Add-On is a separate, per-user license for Premium customers.
It is not included with a Premium subscription and must be purchased separately.
Each user with the add-on gets access to a set of features
that help organizations safely roll out AI tooling at scale:
AI Governance is included with a Premium license. Each Premium user gets access
to a set of features that help organizations safely roll out AI tooling at scale:
- [AI Gateway](./ai-gateway/index.md): LLM gateway to audit AI sessions, central
MCP server management, and policy enforcement
@@ -18,13 +16,13 @@ that help organizations safely roll out AI tooling at scale:
agents, restricting which domains can be accessed by AI agents
> [!NOTE]
> As of Coder v2.32, the AI Governance Add-On is required to use AI Gateway and Agent Firewall.
> Deployments without the add-on cannot access these features.
> AI Gateway and Agent Firewall require a Premium license.
> Community deployments cannot access these features.
## Who should use the AI Governance Add-On
## Who should use AI Governance
The AI Governance Add-On is for teams that want to extend the Coder platform to
support AI-powered IDEs and coding agents in a controlled, observable way.
AI Governance is for teams that want to extend the Coder platform to support
AI-powered IDEs and coding agents in a controlled, observable way.
It's a good fit if you're:
@@ -37,7 +35,7 @@ It's a good fit if you're:
If you already use other AI Governance tools, such as third-party LLM gateways
or vendor-managed policies, you can continue using them. Coder Workspaces can
still serve as the backend for development environments and AI workflows, with
or without the AI Governance Add-On.
or without Coder's AI Governance features.
## Use cases for AI Governance
@@ -79,10 +77,9 @@ rates, and usage patterns to inform decisions about AI strategy.
## GA status and availability
Starting with Coder v2.30 (February 2026), AI Gateway and Agent Firewall are
generally available as part of the AI Governance Add-On.
generally available as part of AI Governance.
To learn more about enabling the AI Governance Add-On, pricing, or trial
options, reach out to your
To learn more about AI Governance, pricing, or trial options, reach out to your
[Coder account team](https://coder.com/contact/sales).
## How Coder Tasks usage is measured
@@ -128,9 +125,9 @@ deployments include 1,000 Agent Workspace Builds, primarily for proof-of-concept
use and basic workflows. Community deployments do not have access to
[AI Gateway](./ai-gateway/index.md) or [Agent Firewall](./agent-firewall/index.md).
Our [AI Governance Add-On](./ai-governance.md) includes a shared usage pool of
Agent Workspace Builds for automated workflows, along with limits that scale
proportionately with user count. Usage counts are measured and sent to Coder via
Premium deployments include a shared usage pool of Agent Workspace Builds for
automated workflows, along with limits that scale proportionately with user
count. Usage counts are measured and sent to Coder via
[usage data reporting](./usage-data-reporting.md). Coder Tasks and other AI
features continue to function normally even if the limit is breached. Admins
will receive a warning to [contact their account team](https://coder.com/contact)
@@ -149,7 +146,7 @@ entitlement limits in the Licenses page.</small>
## Identifying AI seat consumers
When the AI Governance add-on is licensed, the **Users** table and
When AI Governance is licensed, the **Users** table and
**Organization Members** table display an **AI add-on** column that shows
whether each user is consuming an AI seat:
@@ -160,10 +157,3 @@ A user consumes an AI seat when they use AI features such as AI Gateway or
Tasks. The column helps administrators identify which users contribute to
the organization's AI seat count, making it easier to manage seat
allocations and stay within license limits.
The **AI add-on** column only appears when the deployment has an active
`ai_governance_user_limit` entitlement. If the entitlement is not present
or the license has expired, the column is hidden.
> **Tip:** Hover over the **AI add-on** column header for a tooltip
> describing what the column represents.
+4 -4
View File
@@ -31,14 +31,14 @@ interact with agents through the web UI or the REST API.
[Learn more about Coder Agents](./agents/index.md) for architecture details,
supported LLM providers, and how to get started.
## Govern AI activity with the AI Governance Add-On
## Govern AI activity with AI Governance
AI coding tools are quickly becoming core to how engineering teams ship
software. As adoption grows, platform teams want a clear picture of how AI is
being used, consistent guardrails across teams, and predictable cost controls
so they can confidently scale AI tooling to the whole organization.
The [AI Governance Add-On](./ai-governance.md) is a per-user license that adds
[AI Governance](./ai-governance.md) is included with a Premium license and adds
observability, management, and policy controls for AI tooling across your
Coder deployment. It includes:
@@ -51,5 +51,5 @@ Coder deployment. It includes:
- Expanded Agent Workspace Build allowances for teams running AI-driven
background work at scale.
[Learn more about the AI Governance Add-On](./ai-governance.md) for use cases,
entitlements, and how to enable it in your deployment.
[Learn more about AI Governance](./ai-governance.md) for use cases, entitlements,
and how to enable it in your deployment.
+2 -2
View File
@@ -1,7 +1,7 @@
> [!NOTE]
> Features mentioned on this page, such as AI Gateway and Agent Firewall,
> require the [AI Governance Add-On](./ai-governance.md). As of Coder v2.32,
> deployments without the add-on will not be able to access these features.
> are part of [AI Governance](./ai-governance.md), which is included with a
> Premium license.
As the AI landscape is evolving, we are working to ensure Coder remains a secure
platform for running AI agents just as it is for other cloud development
+1 -1
View File
@@ -22,7 +22,7 @@ The Task details view shows the user's complete chat, workspace status and, buil
![VS Code IDE Extension Details View](../images/guides/ai-agents/vs_code_tasks_extension_details.png)
> [!NOTE]
> Both Community and Premium deployments include 1,000 Agent Workspace Builds for proof-of-concept use. Community deployments do not have access to [AI Gateway](./ai-gateway/index.md) or [Agent Firewall](./agent-firewall/index.md). To scale beyond the 1,000 build limit or enable AI Governance features, the [AI Governance Add-On](./ai-governance.md) provides expanded usage pools that grow with your user count. [Contact us](https://coder.com/contact) to discuss pricing.
> Both Community and Premium deployments include 1,000 Agent Workspace Builds for proof-of-concept use. Community deployments do not have access to [AI Gateway](./ai-gateway/index.md) or [Agent Firewall](./agent-firewall/index.md). To scale beyond the 1,000 build limit or use AI Governance features, [AI Governance](./ai-governance.md), included with a Premium license, provides expanded usage pools that grow with your user count. [Contact us](https://coder.com/contact) to discuss pricing.
## Supported Agents (and Models)
+1 -1
View File
@@ -1,6 +1,6 @@
# Usage Data Reporting
The [AI Governance Add-On](./ai-governance.md) requires reporting usage data to Tallyman, a Coder-managed server for billing and reporting purposes. Coder only captures and sends the following information, related to your deployment ID:
[AI Governance](./ai-governance.md) requires reporting usage data to Tallyman, a Coder-managed server for billing and reporting purposes. Coder only captures and sends the following information, related to your deployment ID:
- number of agent workspace builds consumed
- number of AI Governance seats consumed