b1ea9196f7
Four surfaces list Nous models, and none of them was filtered. All four seed from the docs-hosted curated manifest and union the Portal's `recommended-models` endpoint; neither source is authenticated, so org policy had no effect on the model a user picks — which is the model they then use. The Portal endpoint compounds it, serving one globally CDN-cached payload for the whole platform, invalidated only by admin pricing edits and never by a policy change, so it can put a hidden model straight back into a list. Narrow all four against the authenticated catalog: - `_login_nous`, which chooses the model the session starts on - `_model_flow_nous`, the `hermes model` picker - `list_authenticated_providers`, the `/model` picker - `/api/model/recommended-default`, dashboard onboarding The list stays curated and curated-ordered — the policy set only ever subtracts. Replacing a list with the catalog's keys would swap a curated agentic list for a large alphabetical dump of vendor-prefixed models, which is the regression the picker's nous branch already exists to avoid. The `/model` picker's filter sits outside the try that wraps the Portal union, so a Portal outage still yields a policy-filtered curated list. `_login_nous` and `_model_flow_nous` also narrow their unavailable lists, so a policy-hidden model is not offered as a free-tier upsell either. For an org with no policy — the common case — the filter is a no-op and every list is what it was. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>