Learning center

AI Gateway HQ: the control boundary in under three minutes

Watch the working product turn provider access, routes, failover, policy, hard budgets, managed billing, and evidence into one understandable operating path.

For Potential customers, first-time administrators, small teams, and non-technical decision-makers · Updated August 10, 2026
Working product walkthrough

Watch, listen, or read.

The screens come from the sanitized working sandbox. No customer data, credentials, prompt bodies, or provider responses appear in the recording.

  • English captions and transcript
  • No autoplay or third-party video tracker
  • Reviewed 2026-08-10

Transcript: one controlled boundary

AI Gateway HQ sits between the tools that ask for AI and the model providers that answer. It gives the person responsible for the account one place to control what happens.

For a small team, that means fewer scattered keys and fewer surprise bills. For an enterprise, the same boundary adds ownership, permissions, budgets, policy, and audit evidence.

Provider access and controlled routing

Start by connecting a provider account you already control, or, when eligible, activate prepaid managed Bedrock. Provider secrets are encrypted and are never displayed back in the console.

Next, give applications a stable name such as “quality” or “fast.” The route decides which approved provider and model can serve that name, and which eligible fallback can take over.

Health circuits, quota cooldowns, compatibility checks, capacity, policy, and budget all narrow the list before a request leaves the gateway. If nothing is eligible, the gateway stops instead of improvising.

Policy, guardrails, and hard budgets

Policies begin in Observe mode, where you can see the decision without blocking work. After review, enforcement can allow, deny, or redirect only within the routes you approved.

Guardrails inspect request, response, tool, and MCP boundaries. You choose the rollout mode and the signals that should be observed, redacted, or blocked.

A hard budget is checked before dispatch. Strict limits reserve conservative exposure first, then reconcile supported provider usage afterward, so a warning is not your only defense.

If you use managed inference, purchased credit and a reusable card authorization are required. Automatic reload stays off until you choose a threshold, reload amount, and monthly cap.

Evidence, insights, and the first request

Every result becomes reason-coded operational evidence: who called, which route and provider were selected, what the policy decided, how long it took, and what it cost. Prompt and response bodies are not written to this ledger by default.

Insights use retained metadata to surface missing controls, unhealthy concentration, and possible routing improvements. They suggest changes; administrators keep approval.

For an eligible route, an authorized administrator can review one exact, version-bound cost-routing change, approve it, and restore the prior version. No change is silent, and modeled comparisons are not promised savings.

The shortest safe path is simple: connect or activate one provider, create one route, add a hard budget, issue a workload key, and send a test request. The learning center walks through each step.

Put it into practice

See the working controls behind the guide.

Run a bounded provider simulation without a login, card, key, or model charge. Create a workspace only when you are ready to save controls or connect live traffic.

Create a free workspace Try the Test LabTalk with us