Percidian Gateway
The governed model edge for business-aware AI.
One place to control which applications and model endpoints may receive enterprise context — provider and model allowlists, customer-managed keys, request and budget controls — with the identity, purpose, and evidence of every request travelling with it. New AI experiences inherit the same standard without rebuilding governance inside each one.
Approved destinations receive governed context · Unapproved destinations receive nothing · Every delivery leaves a record
Percidian Gateway
One destination policy, one delivery path — identity, permissions, and evidence travel with the request.
- Commercial assistants
- Internal agents
- Embedded applications
- Automated workflows
- APIs and MCP
What the Gateway is
Put policy between every application and every model — once.
Every AI system your organization runs needs the same decision made about it: may it receive enterprise context, from which sources, for which people, through which model. The Percidian Gateway is where that decision is made and enforced. Approve a destination and it receives the governed context ACE assembled for the request — facts, sources, permitted actions, memory, and evidence, scoped to the person asking. Leave it unapproved and it receives no context, no summary, and no metadata.
The route can change; the authorization cannot. Models are constrained by provider, model, key, budget, and request class; inference runs on customer-approved endpoints with customer-managed credentials; and each request is recorded with who asked, what governed it, and where it went — so security and compliance review delivery from one control point instead of inside every tool.
It sits in the request path rather than beside it. Policy is evaluated at the edge, so governance costs a hop instead of a round trip to a central service, and what leaves the Gateway already carries what the call needs — the context ACE assembled for this request and the tools that destination is permitted to use. The application does not fetch context, then fetch tools, then ask.
Approve a destination
What an approved destination receives — and what an unapproved one does not.
Approve a destination and it receives governed context for the request, with identity, permissions, and evidence intact. An unapproved destination receives no context, no summary, and no metadata.
Destination policy
4 of 5 approved
One policy; every request to an approved destination inherits it.
- Commercial assistantThe tool people already open
Receives · governed context for the request
- Identity
- Permissions
- Destination policy
- Provenance
- Internal agentRuns the work for a person and a task
Receives · governed context for the request
- Identity
- Permissions
- Destination policy
- Provenance
- Embedded applicationAn AI feature inside your software
Receives · governed context for the request
- Identity
- Permissions
- Destination policy
- Provenance
- Automated workflowLong-running, unattended
Receives · governed context for the request
- Identity
- Permissions
- Destination policy
- Provenance
- New AI toolNot yet reviewed
Receives nothing — no context, no summary, no metadata.
4 approved destinations receive governed context, scoped to the requester. 1 not approved receives nothing.
Controls
The route can change. The authorization cannot.
Runtime controls sit behind the governance decision, not in front of it.
Approved destinations and model policy
Provider and model allowlists per destination; the model serving a workflow can change without changing what context it may receive.
Customer-managed credentials
Inference runs against customer-approved endpoints with the customer’s own provider keys — never through a shared credential.
Request and budget controls
Request classes, rate and budget limits per application, team, or model, applied at the edge before a token is spent.
Telemetry and the record
Tokens, cost, latency, and outcomes per request, alongside the access record — reviewable by security and compliance from one place.
Delivery, governed.
The Gateway delivers ACE’s governed understanding. It is never the identity or evidence authority: it carries the decision ACE made, and it makes no new one of its own.
- Customer policy decides every destination and model
- Customer credentials on every inference call
- Customer data never trains third-party models
- Every delivery leaves a record
“What are our obligations under the Northwind agreement?”
- who
- Priya Raman · Associate
- sources
- 3 permitted
- context
- scoped to the task
- evidence
- every fact linked to source
- destination
- Microsoft Copilot · approved
- logged
- 09:42:07 · reviewable
Reviewable by security and compliance from one control point.
At a glance
Percidian Gateway
- Destinations
- Assistants, agents, applications, workflows, APIs and MCP
- Approved per destination; unapproved receive nothing
- Policy
- Provider, model, key, budget, request class
- Set once; every new experience inherits it
- Routing
- Evaluated at the edge, in the request path
- Policy is a hop, not a detour through a central service
- In the call
- Assembled context and permitted tools
- Delivered with the request rather than fetched separately
- Credentials
- Customer-managed
- Customer-approved endpoints only
- Training
- Customer data never trains third-party models
Bring your business into every AI decision
Give every approved AI system the context to do its best work.
Connect the knowledge your organization already has. Preserve what it learns. Apply the permissions it already trusts. Make that understanding available wherever people and agents work.