One key, many models, same identity. Provider, model, and exact version are bound to your IGLKey.
Whose AI account runs the call?
Demo mode (start here). Your IGLKey works immediately against IGL's shared provider accounts, so you can try governed chat the moment you finish signup.
Your own accounts (BYOK). When you're ready, connect your own OpenAI, Anthropic, Google, or other provider account. Your provider key rides with each request, is used for that one call only, and is never stored by IGL. The audit receipt records whose account ran the call: yours or the demo pool.
Where IGL actually enforces
Through your IGLKey (IGL Chat, Claude Desktop, Cursor via MCP): full enforcement. Identity, authority, and exact model version are checked before every call, and every call gets a receipt.
Native apps like chat.openai.com or claude.ai in a plain browser tab: identity overlay. The model runs on the provider's own servers, so IGL can't gate that call. The browser extension injects your identity context and tracks your sessions there instead.