← All posts

July 7, 2026 · 7 min read · Buying and renewals

What each AI vendor's admin console actually exposes

Before you can tie a dollar of AI spend to a team, you have to know what the vendor will tell you. The answer varies a lot. It is a contract term almost nobody negotiates for.

By Spendassay Research

What you get ranges from a named seat with a last-used date, down to one account total you cannot split at all. A seat is a paid license for one person. GitHub and Cursor will name a seat. Anthropic and OpenAI will name a key or a project. Whether that maps to a human is your problem. Amazon Bedrock will name a tagged workload and nothing else. Microsoft 365 Copilot will name a user, unless your own admin setting has stripped names out of the report.

That spread is why "just tie AI spend to teams" is harder than it sounds. It is not one integration problem. It is seven data models, each with its own idea of who a user is.

It is also why this goes wrong so often. KPMG's Global AI Pulse, Q2 2026, covering 2,145 C-suite leaders, found 42% can only partly see what they spend on AI. CloudBees' 2026 State of Code Abundance found firms can tie only about one-third of AI spend to specific business outcomes. Neither is a discipline problem. It is what happens when the source systems disagree about what a unit of usage is attached to.

Below is the matrix we keep. It is dated, and it is patchy in places. We would rather say so than fill a cell with something that merely sounds right.

The matrix — as of July 2026

| Vendor | Who it can name | Last activity per seat | Token use tied to | Export path | Reporting lag | |---|---|---|---|---|---| | GitHub Copilot (Business / Enterprise) | Per seat for who holds a license; usage numbers are org and team totals, not per person | Yes — a last-used date per seat, from the Copilot seats API | Included usage is not shown per person. Extra premium-request and credit charges appear in billing at a level of detail that varies by plan — verify in your own console | REST API plus CSV billing export | Metrics usually refresh daily; billing usage lags further — verify in your own account | | Cursor (Business / Enterprise) | Per member on Business and Enterprise, through the admin dashboard and Admin API; detail on lower plans varies by plan — verify | Yes on Business and Enterprise team analytics | Per-member usage and spend on Business and Enterprise | Admin API plus CSV | Roughly daily — verify | | Anthropic (Console + Admin API) | Per API key and per workspace for usage; per member for the org roster through the Admin API | Key activity is available. A key's last use is not the same fact as a person's — map keys to owners yourself | An API key, a workspace and a model. A person only if you enforce one key per human | Usage and Cost Admin API plus CSV | Usage near-daily; cost reporting lags usage — verify | | OpenAI (platform + ChatGPT Enterprise) | Platform: per project and per key, with some grouping by user. ChatGPT Enterprise: per-member admin reporting, varies by plan — verify | Enterprise member activity shows in admin reporting; exact fields vary by plan | A project, a key and a model. Per user only where that grouping is supported | Usage and costs API plus CSV; Compliance API on Enterprise | Usage near-daily; cost lags — verify | | Google Gemini Code Assist | Per-seat license assignment through the admin console; how much usage detail you get varies by edition — verify in your own console | Varies by edition — verify | Seat-priced editions show no per-person token line. Usage sent through Vertex AI bills to a Cloud project, not a person | Cloud Billing export to BigQuery for project-level cost; per-seat export varies | Billing export roughly daily | | Amazon Bedrock | Account, region, model, and whatever you tagged. No human name unless you set up that tracking yourself | None | A tagged workload or an inference profile. Never a person by default | Cost and Usage Report to S3/Athena; Cost Explorer API | CUR refresh commonly ~24h or more | | Microsoft 365 Copilot | Per-user usage reports in the M365 admin center — but one org-wide admin setting can strip user names out of every report | A last-activity date per user, subject to that same setting | Seat-priced, so no per-person token line. Detail on agent usage varies — verify | Microsoft Graph reports API plus CSV | Reports typically lag a day or more |

Three columns do most of the work here. Who it can name tells you whether tying spend to a team is possible at all. Export path tells you whether it can be automated or is a monthly manual chore. Lag tells you whether the number is usable in a renewal talk happening this week.

The three ways this breaks

Account totals and nothing under them. Bedrock is the clearest case. You get an exact dollar figure for a workload and no way to say which team caused it. Not unless someone set up cost tags before the money was spent. You cannot add them after the fact. If tagging is not in place today, your first clean month starts the day you fix it.

Key-level detail with no key owner. Anthropic and OpenAI will tell you exactly what a key used. They will not tell you who holds it. Most firms find out at audit time that a few shared service keys account for most token spend. A token is the unit AI vendors bill for, roughly a few characters of text. Often nobody has owned those keys since the person who made them changed teams. The fix is a people fix, not a technical one. One key per human or per named service, enforced when the key is created. That is the core of attributing API costs to teams.

Seat activity with no depth behind it. A last-used date tells you a seat was touched. It does not tell you whether the engineer took three suggestions or shipped four agent-driven pull requests. Both count as "active." Seat use counted that way overstates real take-up. That is exactly how idle seats survive renewal. An idle seat is a paid seat nobody has used lately.

How much detail you get about who spent what is a buying decision. Almost nobody negotiates for it.

Ask for the detail in the contract

Price is the term everyone negotiates. Data access is the term that decides whether you can ever judge the price. Four clauses are worth putting to a vendor before you sign an annual commit.

Per-seat usage export. Not a dashboard. A machine-readable export of per-seat activity and consumption, with a set format, plus a promise not to cut the detail during the term.

Usage broken out by the same identity. If the product bills for tokens or credits, the usage record should carry the same ID as the seat record. A vendor that reports seats per user and usage per key hands you a join you cannot finish.

A stated refresh time. "Near real time" is not a term. Ask for a maximum lag and get it written down.

History kept. Twelve months at least. A renewal case built on 30 days of data is a case about a sample, and renewal negotiations run on evidence, not on a screenshot from last Tuesday.

None of this costs the vendor much. It is almost always granted when asked, and almost never asked for. Skipping it shows up later as a surprise. Zylo's 2026 SaaS Management Index reports 78% of IT leaders hit unexpected AI or usage charges, with spend on AI-native apps up 108% year over year. A charge is only a surprise if the reporting was too coarse to see it coming.

This is a working matrix and we want corrections

Every cell above reflects what we could stand behind in July 2026. Several are hedged. The honest answer is that the feature varies by plan tier and changes without notice. Admin consoles ship changes monthly. Plan gating moves. Endpoints get retired.

If a cell is wrong for your account — or right in a way we hedged too hard — send it to hello@spendassay.com with the plan tier and the date you checked. We will update the matrix and say what changed.

The honest caveats

This matrix is a snapshot, not a spec. Several cells are hedged on purpose, because what a console can do varies by plan tier, region and enterprise agreement. We would rather print "verify in your own console" than invent a feature. Vendors ship admin changes monthly and rarely announce it when they give you less detail. None of this replaces opening your own admin panel and checking. Two limits apply whatever the vendor. No console shows you usage from before you turned reporting on. And no console can tell you whether the usage was worth the money. That takes vendor data joined to delivery data, which no vendor will do for you.

Find your recoverable AI spend

Spendassay reads these consoles for you. Read-only, and only counts, dates and names — never the contents. It puts seven identity models into one format, so a seat in Cursor and a key in Anthropic land on the same team. The read-only and minimum team size limits are the reason engineering will let you connect it.

`Start free` → /login?src=blog_ai-vendor-attribution-matrix

Find your recoverable AI spend

Spendassay turns this from an afternoon of spreadsheets into a live, proof-level audit with the recovery attached.

Practical, evidence-first notes on AI spend. A couple a month. No spam, unsubscribe anytime.