Access Statuses
Each model can be set to one of three statuses:| Status | Behavior |
|---|---|
| Allowed | Model can be used in the given context |
| Blocked | Model is blocked. API calls return an error; Playground shows an access control message. |
| Inherit | Uses the parent organization’s setting (child teams only) |
Blocked models still appear in the Model Gallery and API documentation. Access controls only affect execution.
Organization Inheritance
When access controls are enabled, rules set at the org level flow down to all child teams by default. Child teams default to Inherit and follow the org’s rules, but they can override specific models when they need different access.Enterprise Ready Models
fal designates certain models as “Enterprise Ready” based on licensing, compliance, and reliability criteria. By default, any model marked Enterprise Ready is automatically allowed and you only need to manage exceptions by blocking specific models you don’t want. For stricter control, you can switch to Require Explicit Approval mode where all models are blocked by default and must be individually approved, even Enterprise Ready ones. You can opt in to receive email notifications when new models are designated as Enterprise Ready, so you can review and approve them promptly.What Happens When a Model Is Blocked
| Context | Behavior |
|---|---|
| API call | Returns an error indicating the model is restricted for your account |
| Playground | Model appears but execution is blocked with an access control message |
| Sandbox | Model appears but cannot be included in comparison runs |
Model Access Controls are available on enterprise plans. Contact sales to enable this feature for your organization.
Managing Teams
Configure org-wide policies and member management