Myra AI Workspace
Document type: Online Help
Version history
| Version | Date | Reason for change |
|---|---|---|
| 1.8 | 2026-10-07 | Weekly delta sync against the product changes since version 1.7. Corrected two pages that had become wrong — View as user now refuses a member's private content and is read-only, rather than showing the workspace as that member, and partner payouts now run through the SEPA + Gutschrift export flow (no longer "display-only") — and the self-contradictory plan_model_copy_enabled default (off) and the stale brand-stripped model-name example. Documented the privacy-relevant PII internal-delivery tenant toggle (default on), the one-click sign-in link, the workflow Connector step, code-interpreter default-on gateways, the signup-abandonment reminder enabled platform-wide, the member-reactivation card on the Dashboard and Cost analytics, the Health plan-aware-taglines counter, the My feedback user view, the agent/schedule delivery-failure surfacing, the chat wallet top-up and PDF embedded-image attachment, and the signup_reminder_* and ask_docs_unconfigured reference entries. |
| 1.7 | 2026-08-31 | Delta audit of the manual against every product change since version 1.6 (more than 1,900 commits). Integrated the residual gaps found against the source: the model picker's resolved-Auto label and the friendlier chat-start error message; the collapsible spreadsheet attachment chip and the jump-to-latest control; five-language read-aloud (German, English, French, Dutch, Spanish) with spoken-form pronunciation normalization; Markdown, HTML, XML, and YAML code-interpreter input files; routing-rule matching on request headers and metadata; the tabbed tenant editor with its unsaved-changes guard and the add-a-user-from-tenant action; group member and grant removal confirmations; per-tenant compliance reports; the human-in-the-loop tool gate extended to MCP-connector and sub-agent tools with the egress floor re-asserted on resume; the out-of-range PII-threshold rejection; the self-service account-name edit and the My access page; installing the app on a phone or tablet; the sign-in code Resend control; and the Premium upgrade teaser for Agents, Workflows, and Scheduled tasks. Corrected the gateway settings popup section names, the routing-rules collapsed-on-load steps, and the Commands navigation path. |
| 1.6 | 2026-07-27 | Added the Capabilities catalog — a single feature map that groups every capability by what it lets you do and links into each detail page, so image and scanned-document ingestion via OCR is now discoverable from the top level. Documented the scheduled-task failure notifications, and expanded the context-window chapter with incremental streamed compaction, partial-answer synthesis on budget exhaustion, and the handling of long and data-file turns. |
| 1.5 | 2026-07-27 | Full-corpus source re-verification (eight-area audit of every page against the current code) and screenshot regeneration. Corrected accuracy defects found across the manual, including: the IP-allowlist client-IP match (leftmost X-Forwarded-For, with IPv6 support); the Vertex AI authentication method (OAuth2 Bearer from a service-account key); the Presidio default action and the German PERSON/LOCATION thresholds; the code-fence guardrail signal count; the HTTP 429 retry/fallback behaviour; the OpenRouter fallback pre-condition; the project org-share role (viewer); the My Account page's five cards; several API endpoint roles, response shapes, and the audit-log timestamp unit; and numerous label and default corrections. Regenerated every screenshot and added captures for the Prompt library and Config approvals views. |
| 1.4 | 2026-07-27 | Documentation sweep against the current product: added the Prompt library and Config approvals administration chapters; documented the per-answer Read-aloud control, the follow-up suggestion chips, the memory accept/edit/reject review, the masking-preview analyzer-outage warning, and the served-model disclosure on Auto data-file turns in Chat; documented the website knowledge source and the tenant exit-export and request-log retention controls; added the agent run-history and gateway-audit, conversation-image, MCP catalog and OAuth-start, and tenant shared-commands API endpoints and the workflows_disabled error code; corrected the provider count to 21, the Anthropic 1-hour cache-write tier, and the KI-Manager administration visibility. |
| 1.3 | 2026-07-19 | Full documentation sweep against the current product: added the Governance chapter (dashboard, template management, compliance report) and dedicated Myra and Mistral provider pages; documented the annual billing option in self-serve sign-up, the native Mattermost slash commands in Chat bridge, the file-upload field in the workflow form builder, the Salesforce connector, the Agent approvals review inbox, the tool-incapable-model behaviour in Agents and Chat, project members granted through groups, and workflow schedule health; corrected the guardrail verdict names and the My account page heading; regenerated every screenshot; and brought the changelog current. |
| 1.2 | 2026-07-12 | Full documentation sweep against the current product: added the Agents, Workflows, My Approvals, Chat bridge, Groups, and Code interpreter chapters and the EU data residency concept; corrected the sign-in chapter to cover single sign-on alongside email one-time codes; documented the guardrail-block, citation, and privacy states in Chat; extended the self-serve sign-up chapter with the in-app billing and cancellation surfaces; wired the previously unlisted API pages into the navigation; regenerated every screenshot; and brought the changelog current. |
| 1.1 | 2026-06-26 | Documentation refresh against the current product: added My PII configuration, My MCP Connectors, Health dashboard, and Inference API (/v1) pages; documented the chat export, transcription, PII-keyword, and MCP-credential endpoints; corrected the provider list (Myra replaces the retired vLLM provider), the web-search provider matrix, and the compat provider-resolution rules; added the missing inference error codes; brought the changelog current. |
Product description
Myra AI Workspace (AIWS) is a secure AI work environment that combines the security and governance of an AI gateway with the productivity and adoption tools of an AI adoption platform — so every employee can work with AI safely, without compromising sensitive data. It provides a single, secure endpoint for enterprise access to 21 AI providers. Built upon the Global Myra Security CDN, it sits between your applications and upstream AI provider APIs and enforces rate limits, budgets, guardrails, and audit logging across all AI requests. All policy enforcement runs in-process within Myra's certified EU infrastructure, ensuring consistent low-latency enforcement with no external sidecar required for core functions.
Where to start
Pick the path that matches what you want to do.
- I want to chat with an AI (you were given an account) → Chat. Sign in at
/easy, type a message, and send. See Signing in first if you have not signed in yet. - I administer the gateway (set up tenants, gateways, keys, budgets, guardrails) → Getting access, then the Settings and Account chapters (for example Gateways and User management).
- I integrate the API into my application (drop-in OpenAI-compatible endpoint) → Quick start for a first request, then the Inference API reference.
New to the product? Read What is Myra AI Workspace for the overview, browse the Capabilities catalog for everything the product can do, and see the Glossary for any unfamiliar term.
Purpose of this document
This document is the Online Help for Myra AI Workspace. It describes how to configure and use the product. It serves three audiences: end users who chat through the gateway, administrators and tenant administrators who configure it, and developers who integrate the API.
Features and limitations
| Feature | Limitation |
|---|---|
| Support for 21 AI provider integrations, including OpenAI, Anthropic, Google Gemini, Vertex AI, AWS Bedrock, Azure OpenAI, Mistral, Groq, Together AI, Fireworks, Cerebras, DeepSeek, OpenRouter, Perplexity, SambaNova, xAI, NVIDIA NIM, Cloudflare Workers AI, Cohere, HuggingFace, and Myra | Streaming responses are not cached; the exact-match cache applies only to non-streaming requests |
| Unified OpenAI-compatible endpoint that resolves the provider automatically based on the model name | The exact-match cache is on by default; semantic caching is optional and requires an external embedding endpoint to be configured |
| Exact-match response caching that serves repeated identical prompts from cache, saving cost and latency | IPv6 addresses are not supported in the IP allowlist; only IPv4 CIDR ranges are accepted |
| Sliding-window rate limiting at the gateway level and per authentication token, enforced before any upstream call | Tier 2 guardrail sidecars (NLP PII Detector, Prompt Guard, PII Protector) must be separately deployed; they are not included in the base gateway installation |
| Three-tier budget enforcement (per token, per tenant, per gateway) with automatic period resets (daily, monthly, or lifetime total) | Cost tracking requires model pricing data in the internal model pricing table of the gateway; requests for models without a known price are not tracked for spend |
| Two-tier guardrail pipeline: Tier 1 in-process checks at sub-millisecond latency; Tier 2 sidecar-based NLP checks within Myra's certified EU infrastructure | Per-provider 4xx responses are not retried and do not trigger fallback chains |
| BYOK key vault with provider API keys encrypted at rest using AES-256 | — |
| Routing rules engine that rewrites provider and model, distributes traffic by weight, and chains fallback providers | — |
| Automatic fallback chains that retry failed requests against secondary providers transparently | — |
| Per-provider circuit breaker that stops routing to failing providers for a configurable cooldown period | — |
| IP allowlist enforcement per gateway | — |
| Structured audit logging for every request, including provider, model, tenant, token counts, cost, cache status, and all guardrail verdicts | — |
| Request tracing with per-phase latency breakdown | — |
Prometheus metrics exposed at /metrics |
— |
| Web-based admin UI with dashboard, live monitor, cost analytics, request log, playground, and persistent multi-turn chat | — |
| SIEM event streaming to Splunk HEC, Elasticsearch, OpenSearch, Vector HTTP source, and Syslog (CEF or RFC 5424) | — |
| Multi-tenancy with isolated budgets, policies, authentication tokens, and analytics per tenant | — |