Policy by workload
Current policies distinguish workload key, environment, client mode, data class, model, risk signal, and signed attributes. Provider-region enforcement and approval workflow are still required.
The current baseline provides OIDC, built-in authorization, model policy, hard budgets, encrypted BYOK, reason-coded decisions, and hash-chained change metadata. It is not yet certified or validated for regulated production.
The current baseline can constrain models, workloads, request cost, rate, and signed context while recording reason-coded outcomes. It does not replace model-risk management, vendor due diligence, approvals, recordkeeping policy, or regulated deployment validation.
Model eligibility, user/workload identity, provider account, budget, environment, and evidence retention need named owners.
Expose approved aliases and tested routes rather than unconstrained provider catalogs.
Distinguish interactive, planning, CI/CD, and unattended agent activity using signed attributes.
Define approval and evidence requirements outside the gateway until native workflow is implemented.
Use explicit workload and data-class context; never infer authorization from a model name alone.
Limit eligible providers, models, credentials, and telemetry before the request can leave the gateway.
Run the tested rule in Observe, Shadow, or Enforce according to the approved rollout stage.
Retain metadata evidence and administrative change history for authorized operational review.
Scope, action, rollout mode, and priority stay visible next to the dry-run decision simulator.
Scope, action, rollout mode, and priority stay visible next to the dry-run decision simulator.
Each control has an operating path, an owner, and evidence that can be reviewed without collecting prompt bodies by default.
Current policies distinguish workload key, environment, client mode, data class, model, risk signal, and signed attributes. Provider-region enforcement and approval workflow are still required.
Reason-coded decisions record which current control applied while gateway code avoids prompt persistence.
The API exposes evidence today; native SIEM, on-call, ticketing, and cloud-operations delivery are not currently included.
Hash-chained configuration metadata can reveal breaks in sequence; it is not described as a tamper-proof external archive.
Review security boundaries and current statusClear answers for buyers, administrators, and security reviewers.
No general claim is made. A financial institution must complete its own risk, vendor, model, cybersecurity, resilience, recordkeeping, and legal review for the exact use.
Current metadata records the requested model, selected target, applicable policy reasons, timing, configured estimate, and outcome for authorized review.
Native multi-party approvals are not yet shipped. Approval requirements must remain outside the gateway or be enforced through pre-established policy during a pilot.
Connect a provider credential, create a workload key, and begin in Observe mode. Move a tested rule to Enforce when your team is ready.