Gamut Gateway
The control point before AI agents act.
Gamut Gateway is the zero-trust enforcement point between AI intent and consequential action. It binds every governed action to approved purpose, exact parameters, current resource state and short-lived execution authority, then records the outcome as tamper-evident evidence.
Book a callThink anywhere. Act through Gateway.
An agent may use its own reasoning model or orchestration framework. Security depends on complete mediation of the actions that matter: tool calls, protected data access, connector use, governed model egress and state-changing operations must pass through Gateway. If policy, identity, approval, state or execution evidence cannot be verified, the action fails closed.
Reasoning is not authority
A prompt, model output or another agent cannot grant permission. Runtime authority comes only from active Gamut policy and cryptographically bound Gateway artefacts.
Every action is re-evaluated
Gateway checks the complete tool, action, resource, purpose, data class and environment tuple at the runtime boundary.
Failure is a control outcome
Missing, expired, changed, replayed or unverifiable authority is rejected and recorded rather than silently downgraded.
Why Gateway exists
Agentic AI changes the risk equation. A traditional AI system may generate an answer. An agent can call a tool, retrieve data, update a system, send a message, create a ticket, invoke a model or trigger a workflow. Gateway is designed to create a decision point between AI intent and business action.
Do not trust action by default
An agent should not act simply because it can. Actions need policy checks, boundaries and approvals before execution.
Separate decision from execution
Gateway decides whether an action is allowed, blocked, logged or escalated before Claw or a workflow proceeds.
Make control evidence defensible
Security-relevant decisions and execution outcomes are recorded with cryptographic lineage for assurance, audit and incident review.
Gateway enforcement coverage
Gateway applies a defence-in-depth control stack. No single check is treated as sufficient, and a valid approval cannot override identity, tenant, lifecycle, policy, connector, data, state or execution constraints.
Identity and tenant isolation
Authenticate the calling service and agent, bind the request to its workspace and reject cross-tenant or mismatched identity context.
Agent lifecycle and readiness
Confirm that the agent, assessment, policy and required controls are active and runtime-ready before authority is issued.
Exact intent enforcement
Evaluate the full permitted capability tuple: tool, action, resource, purpose, data class and environment. Prompt injection cannot expand that authority.
Tool and connector access
Route approved calls through configured connectors with endpoint validation, path allowlists, bounded payloads and response controls.
Model-provider egress
Control model invocation through a governed egress path rather than allowing execution workers to call providers directly.
Payload-locked approvals
Bind human approval to a SHA-256 digest of the exact request and tool parameters. Any post-approval change invalidates the authority.
Data boundaries
Enforce data classification, permitted access, redaction, retention and bounded request and response handling.
Execution authority and replay defence
Use short-lived, request-bound warrants, leases and atomic idempotency controls to prevent duplicated or altered execution.
State and dependency integrity
Verify required live resource state and security-relevant dependency snapshots before a state-changing operation proceeds.
Multi-agent delegation
Constrain child authority, delegation lineage, budgets, handoffs, memory access and recursive revocation across collaborating agents.
Rate, budget and runtime limits
Apply action, concurrency, financial, task and time boundaries so valid authority still operates within controlled limits.
Tamper-evident runtime evidence
Journal decisions, denials, approvals, leases, connector outcomes and security failures in cryptographically linked records.
Execution-integrity controls
These controls protect the transition from an allowed policy decision to an actual operation. They operate inside the broader Gateway enforcement stack above; they do not replace its identity, tenancy, lifecycle, connector, data, budget or audit controls.
| Protection | How Gateway enforces it |
|---|---|
| Payload-locked consent | An approval warrant is bound to the exact request hash, action and parameters. Modified requests must be evaluated and approved again. |
| Strict purpose boundaries | Runtime Access Policies permit exact capability tuples rather than broad combinations of independently allowed values. Missing dimensions and sensitive wildcards fail closed. |
| Replay-resistant execution | Short-lived execution leases, one-time warrants and idempotency keys are claimed atomically. Concurrent reuse, altered reuse and duplicate execution attempts are rejected. |
| State-snapshot integrity | Certified state-changing backends compare the live resource state with its authorised version, ETag or SHA-256 precondition as part of the mutation and return a signed execution receipt. |
Gateway-mediated action patterns
- Governed model invocation where model egress is placed behind Gateway
- RAG search and retrieval with bounded, cited and redacted output
- MCP tool calls through approved server boundaries
- SIEM and SOAR security actions through approved connectors
- Read-only database queries under strict query policy
- Configurable HTTP API requests
- Webhook sends to approved destinations
- Code repository actions under scoped repository permissions
- Gamut writeback for approved findings and evidence requests
- Escalation when policy, data class or risk state requires review
Secure multi-agent collaboration without shared authority
Multi-agent workflows are allowed, but authority does not automatically flow from one agent to another. Gateway treats delegation as an explicit, bounded and revocable security operation.
- Immutable parent-to-child delegation grants
- Child capabilities restricted to a literal subset of parent authority
- Cryptographically verified delegation lineage at final execution
- Atomic tool-call, financial, concurrency and child-count budgets
- Short-lived, single-use agent-to-agent handoffs
- Purpose- and lineage-bound cross-agent memory access
- Recursive revocation of descendant grants and runtime authority
- Untrusted agent output never becomes permission or instructions
Connector, execution and evidence safeguards
Gateway combines preventive controls at the connector boundary with cryptographic proof of the authority, state and dependencies used for execution.
| Control | Why it matters |
|---|---|
| Environment-backed credential references | Raw customer secrets are not stored in Gamut tables and are not handed directly to Claw. |
| Endpoint and origin validation | Connector calls are restricted to approved endpoints and cannot escape to another origin. |
| Path allowlists | HTTP, webhook and repository connectors can be limited to approved route patterns. |
| Bounded request and response sizes | Payloads and responses are size-limited to reduce abuse, data leakage and uncontrolled execution. |
| Response redaction | Connector output can be redacted before storage, workflow use or display. |
| Execution dependency binding | Authority is tied to fresh digests of policy, Gateway build, service identity, target state, tool registration and connector configuration. |
| Signed execution receipts | Certified state-changing backends attest to the exact request, authorised state, resulting state and one-time lease used. |
| Hash-chained security journal | Gateway security events are written to an append-only journal before optional SIEM or SOAR forwarding, without recording raw secrets, payloads or warrants. |
| Audit evidence | Gateway decisions, connector use, replay outcomes, delegations, approvals and enforcement failures become evidence for assurance and incident review. |
What Gateway helps you prove
- Which agents attempted which actions
- Which actions were allowed, blocked or escalated
- Which policies and approvals applied
- Whether the exact approved payload reached execution unchanged
- Which tools, systems and connectors were involved
- Which data boundaries were enforced
- Which delegation chain and execution lease authorised the action
- What runtime evidence was captured
- What incidents or exceptions require review
- What control improvements are needed next
How Gateway fits into the Gamut operating stack
Gamut Assure is the system of record. Agentic CISO defines agent identity, purpose, risk, permissions and approval policy. Gateway independently evaluates and authorises each runtime action. Claw or an approved bring-your-own runtime executes only within those boundaries. Together, they turn governance policy into enforceable, evidence-producing control.
Explore agentic AI governance · See Claw · View the 30-day sprint
Control before execution
Make policy the authority—not the prompt.
Use Gamut Gateway to bind agent actions to exact intent, approved parameters, live state and one-time execution authority before they affect data, systems, customers or operations.
Book a call