Tensic is an AI middleware platform. It sits between the models that do the inference and the apps or agents that use them, and adds what a production app needs: budgets, scoped API keys, failover, guards, memory, tools, knowledge bases and logs. This guide explains the concepts. The other guides cover the steps.
What Tensic is and what it is not
The AI stack has three layers:
- Inference, the bottom layer: the models themselves, served as an API.
- Middleware, the middle layer: Tensic. It orchestrates the apps above it and uses the inference layer below it.
- The agentic layer on top: your apps, agents and workflows, built on the middleware.
An app can call a model directly. The problem comes when something changes, such as a new model or a retired one: every piece of code that calls the model has to change. With Tensic the app calls a project, and the project decides which model answers. You can change the model in Tensic without changing your code.
Tensic does more than an AI gateway. A gateway only passes inference through. Tensic adds per-project budgets, API keys scoped to one project, model failover, input and output guards, agent memory and tools, RAG knowledge bases, and logs of everything that runs.
Tensic is meant to be consumed by machines. It is the production layer that delivers AI features to your own products. It is not a ChatGPT or Claude alternative for end users, although you can build an app like that on top of it. The web interface is for configuring, testing and monitoring projects. Your apps talk to Tensic through its APIs.
Your Tensic instance and who manages it
Each customer gets their own Tensic instance, which is a separate installation of the platform (also called Tensic core). Your provider (team.blue or a partner) creates the instance and manages it from Tensic Manager, a control plane that you do not see. When the instance is created, you receive the platform admin role and the full admin view of the instance.
The provider controls these settings for your instance:
- Available models. The models you can use come from the provider's model catalog and appear on your instance automatically. They are read-only: you can open a model and look at its details, but you cannot change it. Depending on your plan, you may also be allowed to add your own model connections, such as frontier-model APIs.
- Sandbox placement. This setting decides where agent sandboxes run (see below).
- Features and limits that are included in your plan.
A new instance works out of the box, with models, policy and sandbox already set up.
Tenancy: instance, teams and projects
Tensic organises everything on three levels:
- Instance. This is your whole installation. The platform admin manages it: users, authentication (SSO) and platform settings.
- Teams. Users belong to teams. A user can be a member of several teams and can be team admin of several teams. Access, sharing, invitations and budgets are all scoped to a team. Nothing is shared between teams.
- Projects. Every project belongs to exactly one team. A project inherits its team's model access and budget, and it does not interact with other projects unless you connect them.
There are three roles:
| Role | What they see and do |
|---|---|
| Platform admin | Everything on the instance, including all teams, users and settings. There is normally one. |
| Team admin | The teams they administer and the members of those teams. |
| User | Their own projects and the projects they have been invited to. A user cannot browse the team's user list. They add people to a project by sending an invitation. |
These three levels fit most org charts without becoming as complex as an ERP permission system. Organisations with thousands of users and hundreds of teams have been mapped this way.
The four project types and when to use each
The project is the core building block of Tensic. When you create a project, you choose one of four types. You cannot change the type after the project is created.
| Type | What it is | Use it when |
|---|---|---|
| Agent | A model with a system prompt, plus optional tools, short-term and long-term memory, secrets and integrations. The agent keeps state across a session. | You need an assistant that remembers the conversation, calls tools, runs code in a sandbox or works towards a goal. |
| RAG | A knowledge base that answers questions from documents you upload. | You want answers grounded in your own documents. Your app can query it directly, or an agent can use it as its knowledge base. |
| Inference | A stateless, OpenAI-compatible endpoint that serves the models you allocate to it: LLMs, embeddings, image generation, speech-to-text and text-to-speech. | You already have an app or tool that speaks the OpenAI (or Anthropic) API and you want to point it at Tensic with budgets, scoped keys and failover. See Inference projects. |
| Router | A flow that you build visually. It routes a request through other projects based on logic. It needs no model of its own. | You want to chain projects, for example translate, then classify, then send to a support agent. |
When you create a project, you can start from scratch or from a template. A template is a project with a system prompt and type already filled in, so you have a starting point.
Everything is a project
Tensic reuses projects as building blocks for other features:
- An input guard checks what a user or app sends before the model sees it. An output guard checks what the model returns before your app sees it. Each guard is itself a project, usually an agent. It answers "okay" or "not okay", and the protected project blocks or warns and returns a fallback answer that you set.
- A RAG project can serve as the knowledge base of an agent.
- A router connects projects into one flow.
Because each building block is an ordinary project, you configure, test, budget and monitor it the same way as any other project. You can also reuse one guard or knowledge base in many projects.
Sandboxes for agents
An agent that has the terminal tool gets a computer: it can write and run code, fetch URLs and inspect files. That work runs inside a sandbox, which is an isolated container.
- There is one sandbox per session, not per message. A new session starts a fresh sandbox.
- Everything the agent does through the terminal runs inside the sandbox, never on the platform itself.
- By default, sandboxes run on the provider's shared infrastructure. Your provider can set up your instance so that sandboxes run inside your own infrastructure instead, for example a VDC you already have. This option is aimed at larger customers.
Three ways to control Tensic
You can do the same work, such as creating or updating projects and managing users, in three ways:
- Browser. Use the web interface of your instance.
- Tensic API. Use the platform's own REST API to automate it. There is a Swagger link in the side menu. Every project also has an API tab with ready-to-copy examples.
- MCP server. Connect an AI assistant or agent to the instance's MCP server and let it manage projects for you. To see the available tools, open MCP Server in the side menu.
Your apps use the project endpoints to consume AI features. Admin tasks go through the Tensic API or the MCP server.
Common questions
Is Tensic a ChatGPT replacement for our staff?
No. Tensic is a middleware platform that your apps and agents use through APIs. You can build a chat assistant on it, but the product itself is the layer behind the app.
Can I edit the models on my instance?
No. Models that your provider supplies are read-only. If your plan allows it, you can add your own model connections. Otherwise the option to add a model is hidden.
Can I change a project from Inference to Agent later?
No. The project type is fixed when you create the project. To use a different type, create a new project.
Can two teams share a project?
No. Each project belongs to one team, and nothing is shared between teams. A user who needs access to both can be a member of both teams.
What is the difference between an Inference project and an Agent project?
An inference project is stateless and does not remember earlier messages. An agent keeps memory for the session, can call tools and can run code in a sandbox.
Where do agents run code?
In a sandbox, which is an isolated container that is created for each session. Your provider can place sandboxes inside your own infrastructure if you need that.
Can I manage Tensic from an AI assistant?
Yes. Connect the assistant to the instance's MCP server, which provides tools for tasks such as creating and updating projects.