Skip to main content

AI Subscriptions

/subscriptions is the register of company AI tool subscriptions: Cursor, Claude and ChatGPT / Codex accounts. It records who is assigned to each account, what each account costs, and the usage that organization APIs report automatically. The dated financial report is the Subscriptions view in FinOps Analytics.

Open the page​

Select AI Subscriptions in the main sidebar (Subs in the collapsed rail), or open /subscriptions. Admins also have an AI subscriptions shortcut on the Dashboard. The selected tab is kept in the URL, for example /subscriptions?tab=billing.

Who can see and do what​

  • Organizations: you see accounts in organizations you belong to. Platform admins see every organization. Selecting an organization in the header limits the page to it.

  • Accounts: within those organizations you see:

    • accounts you created
    • accounts assigned to your linked identity
    • organization-shared accounts in organizations you administer
    • organization-shared accounts assigned to teams you administer

    Archived accounts are hidden.

  • Company-only mode: by default (SUBSCRIPTION_COMPANY_ONLY not set to false), the page tracks only company-paid accounts shared with organization admins.

  • Managers: organization admins, and platform admins with write access, manage the organizations they administer. They can add and edit accounts, import the register, assign and map employees, record invoice items, archive accounts, and connect, sync or disconnect organization APIs.

  • Account creators: when company-only mode is off, they can also edit, bill and archive the accounts they created.

  • Read-only roles: they can browse and export but cannot change anything.

Tabs, filters and exports​

The tabs are Overview, Accounts, Employees, Usage, Billing and Connections.

On every tab except Connections, you can narrow the accounts in view:

  • My accounts: accounts you created or are assigned to.
  • Search employees, accounts or plans.
  • Provider: All providers, Cursor, Claude or ChatGPT / Codex.
  • Clear filters resets all three.

The header also has these actions:

  • Export register downloads a CSV of every account and assignment you can see. It ignores the on-screen filters.
  • Download produces the current tab as a PDF or PowerPoint report. Preview last report shows the most recent export.
  • Refresh reloads the data.

Overview​

  • Verified monthly commitment: verified recurring charges of resolved accounts that employees do not pay for themselves, per currency. Yearly prices are divided by 12, and shared accounts are counted once.

  • Automatic collection coverage, plus counts of Accounts, Employees, Accounts mapped and Need review.

  • Connect a provider (managers) and View FinOps report. With no accounts yet, managers see Import employee register.

  • Executive analysis: break the portfolio down by two dimensions.

    • Group by and Then by: provider, department / team, plan, organization, account ownership or collection status.
    • Measure: monthly commitment, active accounts or linked employees.
    • Money currency: the currency for money measures.
    • Filters for provider, department and plan.

    View accounts lists a group's accounts. Export breakdown downloads every matching group as CSV.

  • Next actions: accounts to review. These have an unresolved relationship, an unverified or missing price, or collection that needs attention.

  • Collection health: recent connection status. Manage → opens Connections.

Accounts​

Add subscription account opens a form with these fields:

  • Organization
  • Provider
  • Account label
  • Recorded plan
  • Actual login email
  • Billing contact email
  • Account relationship: UNRESOLVED, DEDICATED or SHARED
  • Paid by
  • One account's recurring charge
  • Currency
  • Billing interval: monthly or yearly
  • Renewal date
  • Charge verified against billing
  • Company account visible to organization admins, which is required in company-only mode. Otherwise the field reads Share account metadata with organization admins.

The Account register lists each account with its plan, assigned employees, recurring charge and collection status. Collection status is one of:

  • Not connected
  • First sync pending
  • Collecting
  • Sync delayed: no successful sync for more than two hours
  • Needs attention
  • Disconnected

Select an account to open Account details:

  • Login, Billing contact and Account charge (marked unverified until checked).
  • Reported quotas, when a source provides them.
  • Edit account and reconcile recurring cost.
  • Assign an employee: name, ZeaLLM identity, team, and an optional recorded monthly allocation.
  • Archive account: revokes the account's collectors and keeps historical records.
  • Open billing ledger.

Employees​

Managers can use Import register to load an existing spreadsheet export:

  1. Export the sheet as CSV or TSV with the headers Tool, User Name, Name, Cost, Plan. The file can be up to 500 KB with 1–500 rows. Cost accepts values such as 20 or $20/m.
  2. Choose the organization, then upload the file or paste the text.
  3. Select Preview import, check the rows, then select Import N assignments.

Each new row creates an assignment on a provisional account. The User Name becomes the account's billing contact, not a confirmed login. Identical rows are skipped when imported again.

The assignments table shows each employee, whether a ZeaLLM identity is linked, the company account and the recorded allocation. The allocation is a reference only and is not an invoice. Managers can use these actions:

  • Map to actual account / employee: choose the actual account (same organization and provider), the ZeaLLM employee identity and the team. The team is the department used in executive breakdowns.
  • End assignment.

Usage​

Usage activity lists provider-reported intervals for the accounts in view. Columns cover account and product, the reporting period in UTC, and these measures:

  • tokens
  • requests or turns
  • sessions or threads
  • credits
  • reported usage, estimate and overage

Unavailable metrics show as —. Usage costs and estimates are not verified invoices. Analytics & full exports → opens the FinOps Subscriptions view.

Billing​

Choose a Billing account to see its recurring charge, verification status, renewal date and invoice items. Managers record invoices with Record or correct invoice item, which has these fields:

  • Unique invoice / line reference
  • Charge type: SUBSCRIPTION, OVERAGE or CREDIT
  • Amount
  • Currency
  • Service period starts and Service period ends (exclusive)
  • Verified against invoice

Enter credits as positive amounts; they are shown and counted as deductions. Saving the same reference on the same account corrects that item. A new reference adds a separate item.

Recurring charges and invoice items stay separate measures. Per-employee allocations are not additional charges, and a shared account has one recurring charge.

Connections​

Organization APIs are collected server-side on a schedule; employees install nothing. The Automatic usage collection card shows Scheduler configured or Worker setup needed. Company individual plans without a supported organization API stay inventory-only.

Connect an organization API asks for:

  • ZeaLLM organization
  • Connector:
    • Cursor team Admin API
    • Claude Code Analytics (Console)
    • Claude Enterprise Analytics
    • Codex workspace analytics
  • Connection name
  • Claude organization ID / Codex workspace UUID / Cursor team reference
  • Admin / Analytics API key (encrypted at rest)

Saving again with the same organization, connector and identifier updates the existing connection. Use this to rotate a key.

Each connection shows its status, Last success, Next allowed sync, any last error, and Recent synchronization history.

  • Sync runs a collection now, unless one is already running or the next allowed poll has not arrived.
  • Disconnect stops collection and erases the stored credential. It keeps historical records and does not revoke the key at the provider.

Supported providers & access requirements lists what each connector collects, the credential it needs and its limits.

Device collectors​

Device collection is off by default. It is available only when SUBSCRIPTION_COMPANY_ONLY=false and SUBSCRIPTION_DEVICE_COLLECTION_ENABLED=true.

  1. On an account you created or are assigned to, select Enroll my collector and enter a device name.
  2. Copy the One-time collector token shown once, and save it in ZEALLM_COLLECTOR_TOKEN on the device.

The token expires after 90 days and only uploads metadata for that account. Revoke disables a collector.

Relationship to FinOps Analytics​

  • AI Subscriptions maintains the register: accounts, employees, prices, invoices and connections.
  • FinOps Analytics → Subscriptions reports a date range. It shows verified charges allocated over service periods, the current monthly commitment and provider usage, with Cost CSV and Provider usage CSV downloads. Its Manage accounts & connections button returns here.
  • Gateway spend and subscription charges are separate ledgers and are never added together.
  • Reducing subscription quota use does not reduce fixed monthly fees. For gateway applications, use Tokenomics to analyze token efficiency and metered cost.