The three tiers
Every model, at every reasoning effort it supports, belongs to one tier:
Tiers are cumulative. Granting Up to Balanced also grants Cost efficient. Granting Up to Premium grants everything, which is the default for every workspace.
A tier applies to a model and a reasoning effort, not to a model alone. The same model can sit in two tiers: for example a mid-size model at Light effort can be Cost efficient, at Medium effort Balanced, and at High effort Premium. A frontier model is Premium at every effort.
Set the workspace ceiling
- Go to Admin > Usage.
- In the Models tier section, set Workspace access to the highest tier your members may select.
- The change applies to every member who has no group or personal override.
Override for a group
On the same Usage page, the groups table lets you set a tier per group. A group set to Inherited from workspace follows the workspace ceiling. Group overrides are how you give a specific team access to Premium models while the rest of the workspace stays on Balanced.Override for a member
The members table on the Usage page lets you set a tier for one member. Leaving a member on Inherit makes them follow their groups, or the workspace if they have no group override.How the ceiling is resolved
Dust resolves one ceiling per member, in this order:- Member override, if set. It wins over everything else.
- Group overrides, if the member belongs to at least one group with an override. When a member is in several such groups, the highest of those tiers applies.
- Workspace access, otherwise.
Let members run published agents above their tier
Restricting a member also restricts the agents they can run: if an agent is configured on a model above the member’s ceiling, the run is blocked with Model tier not enabled. That is often too strict, because a well-built shared agent may deliberately use a strong model. In the Models tier section, enable Published agents to let every member run published agents whatever the agent’s model tier, while still capping what they can select themselves. With Published agents enabled:- Published (shared) agents run normally for everyone.
- Unpublished and personal agents remain restricted to the member’s ceiling.
- Creating or editing an agent on a model above the member’s ceiling remains blocked.
What members see
- In the model picker, models and reasoning efforts above their ceiling are visible but locked, with a tooltip telling them to contact their administrator.
- When they try to run an agent above their ceiling, they get a Model tier not enabled message naming the agent.