Triagic docs
Administration

AI providers

Bring-your-own-key LLM credentials for the whole organization, and how to choose between providers.

AI Providers is org-admin only. One credential set per provider, shared organization-wide and pulled down by every desktop install.

Nothing in Triagic investigates without one of these configured.

The providers

ProviderCredentialsEmbeddingsTypical default models
Azure OpenAIEndpoint, API key, deployment, API versionYesgpt-5.5
OpenAIAPI key, optional base URL and TLS optionsYesgpt-5.5, gpt-5.5-mini
AnthropicAPI key, optional base URL and TLS optionsNoclaude-sonnet-5, claude-opus-5
Google (Gemini)API keyYesgemini-2.5-pro, gemini-2.5-flash
OpenRouterAPI keyNoopenai/gpt-5.5, anthropic/claude-sonnet-5
OllamaHost (defaults to http://localhost:11434), optional API key and TLS optionsYesllama3.3:70b

Embedding support is not optional in practice

Similar-ticket search is a vector search over past investigations, and it needs embeddings. Without an embedding-capable provider it degrades gracefully rather than failing, but you lose one of the things that makes Triagic improve with use. If your preferred chat provider has no embeddings, configure a second provider that does.

Azure OpenAI specifics

The deployment field is the deployment name on your Azure resource, not a canonical model id: against the Foundry surface, the API's model field carries the deployment name. Prune your model registry to deployments that actually exist on your resource; an override for a model that is not in the registry falls through rather than failing.

Sending OpenAI or Anthropic somewhere else

OpenAI and Anthropic each take an optional Base URL. Leave it empty and the key goes to the vendor. Fill it in and the same key goes to whatever speaks that API at that address instead: LiteLLM, vLLM, an Azure AI or Cloudflare AI gateway, or a proxy of your own.

FieldRequiredWhat to put
Base URLnoThe gateway's root, including the version path OpenAI clients expect: https://llm.acme.internal/v1. Empty means https://api.openai.com/v1 (or https://api.anthropic.com).
CA certificate pathnoOnly when the gateway's certificate is signed by a private CA. An absolute path on the machine running Triagic to that CA's PEM bundle.
Verify TLS certificateno, defaults onTurn off only for a self-signed gateway you cannot supply a CA bundle for.

The model names you configure have to be the ones the gateway itself accepts. A gateway usually renames or namespaces them, and Triagic passes yours through unchanged.

A base URL is where your API key goes

The key you saved is sent to this address on every call. It is refused if it points at a loopback or private-IP literal, which is what stops a URL field from being used to make this server probe its own network. An internal hostname is accepted, because that is what an on-premise gateway actually uses, so make sure the name resolves to the host you think it does.

Ollama specifics

Ollama runs on the member's machine, not here. The host you configure is resolved locally by each desktop install, so http://localhost:11434 means each member's own Ollama. This is the only provider where a shared configuration does not mean a shared endpoint.

FieldRequiredWhat to put
Hostno, defaults to http://localhost:11434Where Ollama listens, from the member's machine.
API keynoOllama has no authentication of its own. Fill this in only when it sits behind a reverse proxy that demands a token; the value is sent as Authorization: Bearer.
CA certificate pathnoFor an https:// host whose certificate comes from a private CA, the usual shape once a reverse proxy is in front. An absolute path on the member's machine to that CA's PEM bundle.
Verify TLS certificateno, defaults onTurn off only for a self-signed proxy you cannot supply a CA bundle for.

Secrets and validation

Saved keys come back masked as •••. Saving with the mask untouched keeps the stored value; typing over it replaces it.

The portal does not test-call a provider; there is no long-lived process here to make the round trip from. Cards show:

Validated by your desktop app after sync.

A wrong key surfaces the first time an investigation runs on a member's machine. If runs start failing right after a credential change, that is the first place to look.

Choosing a model, and where

This page holds credentials. Which model is actually used is decided on the desktop:

  1. A per-thread override picked in the Console composer.
  2. The install's runtime default, set on the Usage page.
  3. The configured fallback.

Background triage and the playbook classifier always follow the runtime default and never a per-thread override.

Cost control

Model choice is the biggest lever on spend, and it is not set here. See Spending for the cap that actually stops runs, and History and usage for where the numbers live.

Two things worth knowing when you compare providers:

  • An investigation is several calls, not one. Agent iterations dominate; the classifier and metadata extraction are small but run on every ticket.
  • Cheaper models make more iterations. A model that needs twelve tool calls where a better one needs four is not necessarily cheaper, and it is definitely slower.

Audit

Every provider create, update and delete writes an audit entry. See Audit log.

On this page