Transcript: one controlled boundary
AI Gateway HQ sits between the tools that ask for AI and the model providers that answer. It gives the person responsible for the account one place to control what happens.
For a small team, that means fewer scattered keys and fewer surprise bills. For an enterprise, the same boundary adds ownership, permissions, budgets, policy, and audit evidence.
Provider access and controlled routing
Start by connecting a provider account you already control, or, when eligible, activate prepaid managed Bedrock. Provider secrets are encrypted and are never displayed back in the console.
Next, give applications a stable name such as “quality” or “fast.” The route decides which approved provider and model can serve that name, and which eligible fallback can take over.
Health circuits, quota cooldowns, compatibility checks, capacity, policy, and budget all narrow the list before a request leaves the gateway. If nothing is eligible, the gateway stops instead of improvising.
Policy, guardrails, and hard budgets
Policies begin in Observe mode, where you can see the decision without blocking work. After review, enforcement can allow, deny, or redirect only within the routes you approved.
Guardrails inspect request, response, tool, and MCP boundaries. You choose the rollout mode and the signals that should be observed, redacted, or blocked.
A hard budget is checked before dispatch. Strict limits reserve conservative exposure first, then reconcile supported provider usage afterward, so a warning is not your only defense.
If you use managed inference, purchased credit and a reusable card authorization are required. Automatic reload stays off until you choose a threshold, reload amount, and monthly cap.
Evidence, insights, and the first request
Every result becomes reason-coded operational evidence: who called, which route and provider were selected, what the policy decided, how long it took, and what it cost. Prompt and response bodies are not written to this ledger by default.
Insights use retained metadata to surface missing controls, unhealthy concentration, and possible routing improvements. They suggest changes; administrators keep approval.
For an eligible route, an authorized administrator can review one exact, version-bound cost-routing change, approve it, and restore the prior version. No change is silent, and modeled comparisons are not promised savings.
The shortest safe path is simple: connect or activate one provider, create one route, add a hard budget, issue a workload key, and send a test request. The learning center walks through each step.