Enterprise gateway product direction

One governed endpoint for enterprise AI.

Route each request to an approved, cost-effective model. Apply company policy before sensitive data leaves or tools execute. Retry safely without repeating side effects. Preserve evidence end to end.

agentaction.gatewaypolicy attached
MODEL
Classify → constrain → route

Approved provider · qualified model · budget · company context

ACTION
Authorize → execute once → assure

Exact payload · approval · durable state · provider evidence

01 / The enterprise gap

Inference control is not action authority.

Model gateways optimize cost and availability. IAM controls access. AgentAction adds the missing runtime decision for the exact tool call, payload, job state, approval, data boundary, and prior execution.

02 / Product promise

Route efficiently. Act deliberately.

The gateway packages the AgentAction boundary for enterprise adoption. It does not turn prompts into security policy or replace provider-side authorization.

Product direction

Risk-aware routing

Choose the least expensive approved model that meets task, quality, tool-use, privacy, region, and risk requirements.

Foundation available

Company policy

Apply provider, model, tool, resource, destination, data, budget, and versioned system-context controls from one governance plane.

Available now

Safe action replay

Bind idempotency to the exact request and return the prior provider result without repeating a refund, send, write, or deploy.

Available now

Action evidence

Link selection, authorization, approval, execution, replay, observation, and assessment without treating model output as authority.

03 / Company onboarding

Observe first. Enforce with evidence.

Start with one team, one workflow, and one consequential action class. Expand only after the policy and operating evidence are understood.

  1. 01

    Connect

    Bring an enterprise identity provider and existing model or tool credentials.

  2. 02

    Observe

    Discover models, tools, costs, data flows, repeated calls, and consequential actions without blocking traffic.

  3. 03

    Apply policy

    Start from a company baseline, then scope stricter rules to teams, workflows, models, tools, and destinations.

  4. 04

    Enforce

    Challenge or deny high-risk actions, route eligible work, and export correlated evidence.

04 / Deployment

Use the boundary where your traffic already flows.

Managed gateway

A hosted enterprise endpoint with tenant policy, durable state, approvals, and evidence.

Customer-controlled runtime

Run the enforcement data plane in a customer cloud or VPC while using a shared governance plane.

Existing gateway integration

Connect AgentAction as the decision and evidence service behind an MCP, API, or inference gateway.

05 / Proof, not promises

The boundary exists. The product surface is next.

Public code, fixtures, and tests remain the source of truth. Planned gateway capabilities stay labeled until an end-to-end demonstration exists.

Available now
  • Hosted authorization, approvals, JIT grants, and tenant manifests
  • PII and destination controls
  • Idempotent provider-result replay
  • Signed provider receipts and middleware
  • MCP reference adapter and local guard mode
Product direction
  • Production gateway packaging and lifecycle
  • Risk-aware inference routing and evaluation
  • Managed, versioned company system context
  • Customer-controlled deployment options
  • Broader model, MCP, and agent-protocol compatibility

06 / Compatibility

Reuse the standards enterprises already trust.

AgentAction profiles established interfaces before proposing new vocabulary. Emerging work is tracked without presenting drafts as adopted standards.

Launch compatibility

Model interfaces
OpenAI Responses and Chat Completions; Anthropic Messages
Agent tools
MCP 2026-07-28 with versioned compatibility
Identity and access
OAuth, OpenID Connect, and MCP authorization
Policy decisions
OpenID AuthZEN Authorization API 1.0
Telemetry
W3C Trace Context and OpenTelemetry GenAI conventions
Evidence
JOSE JWS/JWKS, canonical request digests, and stable correlation
Enforcement seams
Envoy external authorization and agentgateway ExtMCP processors

Design compatibility

A2A 1.0
Agent-to-agent delegation and task governance
WIMSE and SPIFFE
Executing workload identity across trust domains
ID-JAG and transaction tokens
Downscoped human, agent, and transaction context
Shared Signals
Revocation, risk change, and kill-switch propagation
Gateway API Inference Extension
Customer-managed and self-hosted model routing
SCITT and COSE Receipts
Optional transparency for durable evidence

Compatibility describes an implementation target, not certification by OpenID, IETF, W3C, CNCF, the MCP project, A2A, or Kubernetes.

Start with one consequential workflow.

Help shape the enterprise action gateway.