Skip to content

feat(ui): policy-aware provider picker + dev nav - #3339

Merged
smakosh merged 3 commits into
developer-models-compliance-visibilityfrom
compliance-policy-picker
Jul 31, 2026
Merged

smakosh merged 3 commits into
developer-models-compliance-visibilityfrom
compliance-policy-picker

Conversation

@smakosh

@smakosh smakosh commented Jul 31, 2026

Copy link
Copy Markdown
Member

Summary

Stacked on #3335 (base branch is developer-models-compliance-visibility; GitHub will retarget to main when that PR merges — only the last two commits are new here).

Completes the remaining asks from the enterprise customer report that #3335 addressed:

1. "How can I tell which providers meet my compliance requirements when adding an allowed provider?"

The provider dropdowns on the compliance page are now policy-aware:

  • A green shield marks providers that meet every active certification, data-policy, and headquarters requirement; a red shield marks providers that don't, with the exact failing requirements listed under the name (e.g. "May log prompts · Headquartered in China, which is not an allowed country").
  • A "Only providers that meet policy requirements" toggle at the top of the dropdown hides incompatible providers — the customer's "show only compatible providers" request.
  • The indicators deliberately evaluate the requirements only and ignore the allowed/blocked lists themselves, so an active allow list (the customer's exact situation: only their custom provider allow-listed) no longer makes every candidate look blocked while choosing what to add.
  • The org's custom providers are evaluated against their self-attested posture; ones without an attestation show "No compliance attestation on file".
  • Selected chips that fail the policy get a small warning shield.

2. "What do the different colors represent?"

The unexplained dot in the picker was the provider's brand color and carried no compliance meaning. In the compliance context it is replaced by the meaningful shield indicators with an in-dropdown legend, and the docs now spell out what every indicator/color means (impact chips, shields, brand dots elsewhere).

3. Developer-role discoverability (follow-up to #3335's read access)

#3335 made the custom-models catalog readable for developers, but their sidebar had no path to it. Developers now get an Organization → Custom Models entry pointing at the read-only catalog, and the docs recommend this as the way for developers to see available providers/models without extra permissions.

Also fixes the Provider Impact counter to include custom providers ("0 of 45 providers meet this policy… Requests will be blocked" previously showed even when the org's allow-listed custom provider was fully compliant; it now reads "0 of 45 catalogue providers meet this policy. 1 of 2 custom providers comply." and the empty state says only compliant custom providers can serve requests).

The MultiProviderSelector changes are backward-compatible: options without meetsPolicy render exactly as before (brand-color dot, no toggle/legend), so the API-keys and IAM usages are unaffected.

Testing

  • pnpm test:unit — 208 files, 3457 tests pass.
  • pnpm build — all 17 tasks pass.
  • pnpm format clean.
  • Verified end-to-end against a seeded enterprise org reproducing the customer scenario (policy with no-training/no-logging + FR/GB/US countries + only a custom provider allow-listed): recorded a demo video showing the owner flow (blocked reasons, picker shields, compatible-only filter, allow-listing a compliant provider) and the developer flow (new sidebar entry → read-only catalog).

https://claude.ai/code/session_01Vd3toRu4u6fU9quL7XjbC3

smakosh added 2 commits July 31, 2026 17:21
The compliance page's provider dropdowns now show whether each
provider meets the policy's certification, data-policy, and
headquarters requirements (green/red shield + the exact failing
requirements), with a toggle to hide incompatible providers.
Indicators deliberately ignore the allow/block lists themselves so
an active allow list doesn't paint every candidate red.

The Provider Impact counter now includes custom providers, and the
allowed-empty state no longer claims all requests will be blocked
when a compliant custom provider exists.

Project-scoped developers get an Organization > Custom Models
sidebar entry pointing at the read-only catalog view.

Claude-Session: https://claude.ai/code/session_01Vd3toRu4u6fU9quL7XjbC3
@coderabbitai

coderabbitai Bot commented Jul 31, 2026 •

Copy link
Copy Markdown
Contributor

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: d2f898d7-c182-471e-b0db-54f92be71e2e

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Native span[title] tooltip on the selected-chip warn shield instead
of an svg <title> child, a policy-specific empty state when the
compatible-only filter hides everything, and narrowed types instead
of non-null assertions.

Claude-Session: https://claude.ai/code/session_01Vd3toRu4u6fU9quL7XjbC3
@smakosh
smakosh merged commit 047d7e5 into developer-models-compliance-visibility Jul 31, 2026
8 checks passed
@smakosh
smakosh deleted the compliance-policy-picker branch July 31, 2026 15:46
pull Bot pushed a commit to soitun/llmgateway that referenced this pull request Aug 5, 2026
## Problem

The July traffic report showed revenue concentrating in two places we
under-serve:

1. **The DevPass dashboard is the #1 converting surface** (354 payers
last month), and Reset Passes sold 42 units in month one with zero
targeting — but the agreed follow-up from theopenco#3093 (a real cap-hit
analytics event) never shipped, and the dashboard shows the same
ResetPassCard at 0% and 100% usage. No contextual offer exists at the
moment of highest intent.
2. **Compliance content converts payers at ~5%** (soc2-type-ii: 158
readers → 8 payers) but enterprise leads are flat at 4/month — the post
never presents the enterprise path. Meanwhile the weekly report shows
organic momentum fading, with the proven "[X] alternatives" and Kimi K3
playbooks sitting unshipped.

## What this ships

### DevPass: cap-hit funnel + contextual offer

- **`devpass_premium_cap_rejected`** captured server-side in the gateway
when the weekly premium-cap 402 fires
(`assertDevPlanPremiumCapNotExceeded`), with `devPlan`, `model`,
`msUntilReset`, and org group. This is the follow-up agreed in theopenco#3093:
`devpass_weekly_cap_hit_viewed` only counts users who open the
dashboard, but most cap hits happen inside coding agents that swallow
the 402 — demand was undercounted. Adds a `posthog-node` client to
`apps/gateway` (mirrors `apps/api/src/posthog.ts`; disabled without env,
no hot-path cost).
- **`CapHitResetOfferDialog`** on the DevPass dashboard: a visa-stamp
dialog (border-control stamp, MRZ strip — house DevPass brand) that
appears the moment the weekly premium cap is hit, driven by the existing
5s status poll. It mirrors the server's purchase/redeem gates (never
offers an action the API would 400), stays quiet when the monthly pool
is exhausted (that state belongs to `AllowanceExhaustedCard`), snoozes
per cap-window via cookie, and emits
`devpass_cap_hit_offer_shown/dismissed/clicked`. The CTA scrolls to the
ResetPassCard rather than duplicating the purchase surface.
- **`/ingest` PostHog proxy for `apps/code`** (mirroring apps/ui and
apps/playground) — DevPass dashboard events were ad-blocker-droppable
until now, so July's 500 cap-hit views were an undercount. Expect an
event step-up after deploy.

<img width="1080" alt="Cap-hit Reset Pass offer demo: dialog appears at
100% weekly usage, CTA scrolls to the ResetPassCard, redeem restores the
allowance"
src="https://raw.githubusercontent.com/theopenco/llmgateway/cc22b375431e6148e4889e403c4635327095fc0c/cap-hit-reset-pass-demo.gif"
/>

([MP4
version](https://raw.githubusercontent.com/theopenco/llmgateway/cc22b375431e6148e4889e403c4635327095fc0c/cap-hit-reset-pass-demo.mp4))

### Compliance/enterprise content cluster

- `soc2-type-ii` gains a **provider compliance policies** section (the
theopenco#3339 policy-aware picker, fail-closed requirements, 403-before-egress),
a proper enterprise CTA block, and links into the new cluster.
- Three sibling posts feeding the same funnel: **`llm-data-retention`**,
**`gdpr-compliant-llm-routing`**, and **`llm-compliance-checklist`** —
all fact-checked against
`apps/docs/content/features/{data-retention,compliance}.mdx` and the
routing docs (region example uses a real catalogue mapping,
`aws-bedrock/claude-sonnet-4-6:eu-west-2`).
- New **`BlogCta variant="enterprise"`** (→ `/enterprise#contact` +
`/enterprise/compliance`) used by all three.

### Organic pipeline refill

- **`portkey-alternatives`** and **`helicone-alternatives`** listicles —
the two SERP gaps left open after the litellm/openrouter/copilot
listicles proved the pattern. Facts per the verified June-2026
competitor landscape (Portkey→Palo Alto/Prisma AIRS; Helicone→Mintlify
maintenance mode; Langfuse/LangSmith claims re-verified this week).
Internal links added from `/compare/portkey`, the vs-Portkey post,
best-ai-gateways, and both existing listicles' "skip" sections.
- **Kimi K3 spokes**: `kimi-k3-open-weights` (weights shipped Jul 26 on
HF under a custom **"Kimi K3 License"** — not the Modified MIT press
predicted, so the post and pillar deliberately point at the LICENSE file
instead of summarizing terms) and `kimi-k3-api` (the "kimi k3 api"
query; reasoning_effort semantics, cached-input economics, sticky
sessions). Pillar updated: weights-release facts corrected, spokes
interlinked.
- **`/rankings` interlinks** from the `/models` SEO copy and `llms.txt`
(it had no entry there).
- 7 OG images generated in the house circuit-board style with the
composited wordmark.

## Verification

- `pnpm format`, full `pnpm build`, and `dev-plans-reset-passes.spec.ts`
(32/32) pass.
- Demo recorded against the local stack with the real seed org: staged
cap-hit via SQL (millisecond-truncated `dev_plan_premium_week_start` for
the CAS), dialog fired, CTA scrolled to the card, redeem zeroed
`devPlanPremiumCreditsUsed` and consumed the included pass server-side.

## Notes for review / follow-ups

- The census dialog and the new cap-hit dialog can theoretically stack
(both Radix dialogs; census mounts globally, cap-hit on the main
dashboard page). In the wild both firing together should be rare; if we
care, a simple priority gate in `DashboardShell` would fix it.
- The premium-cap 402 still has no machine-readable `code`
distinguishing it from out-of-credits — agents can't react
programmatically. Left out deliberately (error-shape compatibility);
worth its own PR.
- Blog listicles ship FAQ sections but blog posts emit no FAQPage
JSON-LD (model pages do). Separate SEO follow-up.
- dev.to syndication for the new listicles is intentionally not part of
this PR (staggering per the syndication policy).

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_018NeUff4XEsqAVuJRZ8KuvS

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **New Features**
- Added a dashboard offer for eligible users who exhaust weekly premium
usage, including reset-pass redemption and purchase options.
- Added links to live model rankings and expanded enterprise compliance
calls to action.
- Added guidance for Kimi K3, GDPR-compliant routing, LLM compliance,
data retention, and gateway alternatives.

- **Documentation**
- Updated model, compliance, licensing, and comparison content with new
articles, refreshed links, and recommendations.

- **Bug Fixes**
- Improved analytics loading, routing reliability, and shutdown
handling.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Luca Steeb <contact@luca-steeb.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant