---
title: "Govern AI & Agent Access | Zuplo"
description:
  "Give every team AI access safely. One gateway in front of the MCP servers and
  LLM providers you approve — per-team dollar budgets, per-tool access, and
  every call audited per user, with the IdP you already run."
canonicalUrl: "https://zuplo.com/solutions/govern-ai-access"
sourceUrl: "https://zuplo.com/solutions/govern-ai-access"
pageType: "use-case"
generatedAt: "2026-07-22"
---

# Give your teams AI access. Keep every call accountable.

> One gateway in front of the MCP servers and models you approve. Teams sign in
> with your IdP, budgets keep spend in bounds, and every tool call is audited
> per user — on the same policy engine that runs your APIs.

## Why one gateway

Your teams want Claude, Cursor, and ChatGPT wired into real systems, and your
apps are calling models in production. The job isn't to slow any of that down —
it's to give it a front door you control.

- **Approve once, publish one gateway** — Vet an MCP server or model provider
  once, put it behind the gateway, and every team connects to the same governed
  endpoint. Saying yes gets faster, not riskier.
- **Budgets, not surprises** — Per-team dollar budgets and spend caps on LLM
  traffic. Teams experiment freely inside limits you set — and the bill never
  outruns the plan.
- **Every call has a name on it** — Every tool call and completion is attributed
  to the person behind the agent. When someone asks who did what, you answer
  from a dashboard, not a shrug.

## How it works

### 01 — Put the gateway in front

Add the MCP servers you approve — Linear, GitHub, Stripe, or your own internal
ones — as routes on one gateway deployment, and route LLM traffic through the AI
Gateway alongside them.

### 02 — Teams sign in with your IdP

Claude, Cursor, and ChatGPT connect through standard MCP OAuth backed by Okta,
Microsoft Entra ID, Auth0, or any OIDC provider. Any client, any IdP, any auth
method — and no shared keys in desktop apps.

### 03 — Policies do the governing

Per-tool allow-lists, rate limits, dollar budgets, and audit logging run on
every call — written once, enforced at the edge, versioned in your repo like the
rest of your gateway config.

## Both kinds of AI traffic

Agent tool calls and LLM completions run through the same gateway and the same
policy pipeline — one place to set the rules, one place to see what happened.

### MCP — The MCP servers your teams use

Front approved MCP servers from one deployment — one route per upstream. The
gateway brokers credentials for you: per-user OAuth tokens encrypted at rest
with automatic refresh, or a shared connection where a service account fits
better. Curate exactly which tools each route exposes.

[Explore MCP Gateway](/mcp-gateway)

### LLM — The models your apps call

Route traffic across model providers in config, not code, with per-team dollar
budgets and spend caps attached. Compose prompt-injection detection and secret
masking as policies on the same pipeline.

[Explore AI Gateway](/ai-gateway)

## Controls that hold up

### Per-tool access, enforced at the gateway

Capability filtering allow-lists the tools, prompts, and resources each route
exposes — and blocks hidden tools even when a client invokes them by name. Go
finer-grained with OpenFGA, AuthZEN, or Okta FGA integrations, or custom
TypeScript authorization.

### Audited per user, not per key

Every tool call carries the user's identity, client, capability, outcome, and
latency. Slice it by team or upstream in Zuplo's analytics, or forward it to
Datadog, Splunk, or New Relic next to the rest of your telemetry.

## Works with the identity provider you already run

Teams sign in with the accounts they already have. Eleven first-class identity
provider integrations, plus generic OIDC for everything else.

- Okta
- Microsoft Entra ID
- Auth0
- Google
- Clerk
- WorkOS
- Amazon Cognito
- Keycloak
- Logto
- OneLogin
- PingOne
- Any OIDC provider

## FAQ

**How do teams connect Claude, Cursor, or ChatGPT through the gateway?**

You publish gateway endpoints for the MCP servers you approve; employees add
them to their client and sign in through a standard OAuth flow backed by your
identity provider. No shared API keys pasted into desktop apps — the gateway
issues its own short-lived tokens and keeps upstream credentials encrypted at
rest.

**Can I control which tools a team can use?**

Yes. Capability filtering allow-lists the tools, prompts, and resources each
gateway route exposes — and blocks hidden tools even if a client invokes them by
name. For finer-grained rules, integrate OpenFGA, AuthZEN, or Okta FGA, or write
custom authorization logic in TypeScript.

**How do LLM budgets and spend caps work?**

Route LLM traffic through the AI Gateway and assign dollar budgets per team,
project, or environment. When a team hits its cap, requests stop at the gateway
instead of showing up on next month's bill — and you can see spend by team in
real time.

**Does this work with our identity provider?**

Yes — any client, any IdP, any auth method. There are eleven first-class
integrations (Auth0, Okta, Microsoft Entra ID, Clerk, WorkOS, Amazon Cognito,
Google, Keycloak, Logto, OneLogin, PingOne) plus generic OIDC support for
everything else.

**What shows up in the audit trail?**

Every MCP request and tool call is recorded with the user behind it, the client
they used, the capability invoked, the outcome, and latency — plus auth events
like token issuance and consent. View it in Zuplo's MCP analytics or forward
everything to Datadog, Splunk, New Relic, and other logging platforms.

## Next steps

- [Start for free](https://portal.zuplo.com/signup) — The MCP Gateway and AI
  Gateway are included in every plan.
- [Book a demo](/schedule-call) — Talk to the team about governing AI and agent
  access in your organization.
- [Explore MCP Gateway](/mcp-gateway) — Front approved MCP servers with per-user
  auth and tool-level controls.
- [Explore AI Gateway](/ai-gateway) — Route model traffic with budgets, spend
  caps, and prompt-injection detection.
