Managing Bohm — for IT teams
Bohm reads administrator policy from the registry key HKLM\SOFTWARE\Policies\iyulab\Bohm. Set the values with Group Policy (Preferences › Registry), Intune or an install script — people without administrator rights cannot change them. A value that is absent leaves the default in place. Bohm reads the values when it starts.
Values
| Value | Effect |
|---|---|
CompanyModelsREG_SZ | The AI servers and models on your network that people choose from — one line of JSON, up to 16 KiB (see below). Takes precedence over the two values below. When absent: People connect a server themselves. |
CompanyModelEndpointCompanyModelREG_SZ | One AI server: its OpenAI-compatible base address (http://ai.example:8000/v1) and the model name it serves. Both are needed — one alone is ignored. When absent: People connect a server themselves. |
RemotePageReadingAllowedREG_DWORD | 0: when an online AI service someone connected answers in the chat, it reads no web page at all. A server on your network and a model on the PC still read pages. When absent: Only the sites below and addresses inside your network are held back. |
RemotePageExcludedSitesREG_MULTI_SZ | Sites never sent to an online AI service, one per line — a host name (covers its subdomains), *.example.com or an IP address. Private addresses and single-label or .local names are held back without being listed. When absent: Only addresses inside your network are held back. |
DiagnosticsAllowedREG_DWORD | 0: no crash and error reports and no daily “started” note are recorded or sent. When absent: Sent. |
UsageSharingAllowedREG_DWORD | 0: the “Also send the usage record” switch is not offered — the record can only be saved to a file. When absent: People choose (off by default). |
FeedbackAllowedREG_DWORD | 0: “Tell us” (report a problem, get news) is not shown. When absent: Shown. |
UpdateCheckAllowedREG_DWORD | 0: Bohm does not ask for the number of the newest public release, so it does not tell people when a new version is out. When absent: Asked once a day. |
To keep anything from going to iyulab, set FeedbackAllowed, DiagnosticsAllowed and UsageSharingAllowed to 0.
The model list
{"providers": {
"gpu": {"baseUrl": "http://ai.example:8000/v1", "api": "openai-completions",
"models": [{"id": "qwen3-32b", "name": "Qwen3 32B", "contextWindow": 32768, "maxTokens": 8192, "reasoning": true},
{"id": "qwen3-8b", "name": "Qwen3 8B", "contextWindow": 32768, "maxTokens": 4096}]},
"vision": {"baseUrl": "http://vision.example:8000/v1",
"models": [{"id": "qwen2.5-vl", "input": ["text", "image"]}]}
}}- Server names (
gpu,vision) are up to 64 characters, without/. People choose among the listed models; the first model of the first server is the default. baseUrlis the OpenAI-compatible base address.apimay be left out, or beopenai-completions,openai-compatibleoropenai— a server with any other value is skipped.- Each model needs
id(the name the server uses).nameis shown to people;contextWindowandmaxTokensare in tokens;reasoning: truemarks a model that thinks first;inputliststextandimage. - Do not put keys in the registry — every user of the PC can read it, and Bohm ignores an
apiKey. If a server needs a key, people enter it in Bohm's settings, where it is kept in the Windows credential store. - Anything unusable (a malformed address, a model without
id, a repeated name) is skipped and the rest is used. If nothing is usable, Bohm starts without the policy.
What Bohm itself connects to
| Address (HTTPS) | For | Turned off by |
|---|---|---|
*.in.applicationinsights.azure.com | Diagnostics, and the usage record if someone turns it on | DiagnosticsAllowed, UsageSharingAllowed |
api.iyulab.com | “Tell us”, only when someone presses Send | FeedbackAllowed |
github.com | The number of the newest public release, once a day | UpdateCheckAllowed |
Blocking any of them at the firewall does not stop a feature: reports wait and are dropped after seven days, a message that cannot be sent can be mailed or copied instead, and the update check simply skips that day. Bohm does not download or install anything by itself — new versions come by replacing the installer.