Security and risk teams
You need to know what AI is running, enforce a control that genuinely blocks, prove it works against a named framework, and hand someone the evidence.
Start hereThe gateway does 1 thing: it sits between your applications and your AI services and gives you control over what crosses. What you care about first depends on which side of that you own.
You need to know what AI is running, enforce a control that genuinely blocks, prove it works against a named framework, and hand someone the evidence.
Start hereYou need it to be boring: 1 process to deploy, a latency budget it respects, blast-radius control when a provider misbehaves, and metrics without writing instrumentation.
Start hereYou need client auth to configure itself, tools scoped to what the agent actually calls, PII kept out of the provider, and a spend limit that stops a runaway loop.
Start hereThese are not tier-gated or role-specific. They are how the gateway works.
All 3 paths begin the same way: download it, start it, and create 1 proxy.