Govern every read and write, down to the datapoint
Resolve every request to the real caller and enforce their own permissions across the model, the tools, and your live systems.
Govern every point in the request
Tame governance sprawl with one centralized governance platform, enforcing policy and identity for every request across the caller, the tools, and the actions taken.
Resolve the real caller.
Passthrough identity resolves each request to the individual person and enforces their own permissions in every source system. The agent inherits exactly what they can see—no shared service account standing in for everyone.
Scope what each agent can reach.
The MCP Gateway exposes only the tools and toolkits an agent may call, bounded to a workspace. Third-party MCP servers authenticate under the same identity model, so nothing reaches beyond its scope.
Validate the action before it lands.
The write rules live in the tool, checked server-side before any record commits. Rate limits and guardrails cap what an agent can do, so a wrong write never reaches production—and there is nothing to undo.
Manage policy in one place. Enforce it from the model to the datapoint
The caller's identity, the governed action, and each source's own security meet in one layer. Every policy is managed from one place and enforced end to end, with no seams between products where control can drop.
Govern which models run.
The Model Gateway registers providers and sets which models each team may use, with failover—so access is decided before the model, not after it.
Expose only the right tools.
The MCP Gateway and workspaces scope exactly which tools and toolkits each agent can call, so one function’s agent cannot reach another’s systems.
Enforce source security.
Connectivity runs every query as the individual caller with their own permissions applied at the source—governance down to the row, on live data.
Zero unauthorized writes across 22 models—once the guardrails lived in the tool, not the model.
When models were given direct write access, all 22 wrote records they shouldn't have. The worst wrote 250 records when only 21 were correct. When the tool checked every write first, every model wrote exactly the right records and nothing else.
Read the StudyWhat end-to-end governance gets you
Resolve the caller, bound the action, and prove every request — from one gateway.
Illustrative. Per-user permissions enforced at query time through passthrough identity.
On raw write access, all 22 models inserted unauthorized records in at least one run; the worst wrote 250 where 21 were asked for. CData benchmark. Based on internal testing by CData Software (Q3 2026). No independent third-party verification. Actual cost gaps varied among models, testing conducted using sandbox accounts containing known data sets that mirror production account structures. Results may not be representative of performance in live production environments, and results may vary. Organizations should conduct their own independent testing before making purchasing or implementation decisions.
FAQ
Questions security teams ask first.
- How does an agent respect each user’s permissions?
- What stops an agent from writing bad records?
- Do we have to rebuild our existing access controls?
- How do third-party MCP servers fit in?
- What does the audit trail capture?
- Where is governance enforced—and can we cut off access fast?
- Will this pass our security and compliance review?
People and agents, on every system, under control
One gateway resolves the caller, governs the action, and logs every request across hundreds of systems, down to the datapoint.