Deployment strategies

Put the gateway where the action happens.

Route tool and API calls through AgentSafe. Choose where the gateway and authority run, then use network and identity controls to make that route the required path.

Choose where each part runs

A hosted authority works with a gateway in your own network. Choose a managed gateway when you also want Decionis to operate the request relay.

On premises or private cloud

Your gateway, hosted authority

Shadow → enforcement

Operate the gateway beside your APIs on a host, in Docker or in your Kubernetes cluster. Decionis supplies the decision service.

Data boundary

The full request follows your local relay path. Intent, context and configured JSON fields reach the hosted authority.

Set up your gateway

Your approved network

Your gateway, private authority

Shadow → enforcement

Connect your gateway to a separately provisioned, compatible Decionis authority inside your approved environment.

Data boundary

Relay and policy data can stay within that environment. Authority installation, licensing and service connectivity are separate.

Configure the authority

Managed cloud

Decionis-managed gateway

Shadow only

Use an assigned tenant gateway to observe policy on calls to an API you control. Decionis operates the relay.

Data boundary

The full request, including upstream credentials, traverses the cloud relay. A public HTTPS API and operator onboarding are required.

Set up the managed gateway

On-premises placement alone does not make the flow offline. Review what the authority receives, who holds credentials and which approval services the deployment needs.

One controlled path to the API

The platform controls who can connect. Decionis decides whether the exact action may proceed. AgentSafe enforces that decision at dispatch.

  1. 01

    Agent tool

    Calls the configured gateway URL

  2. 02

    TLS ingress or mesh

    Admits the workload identity

  3. 03

    AgentSafe

    Binds the request and claims before dispatch

  4. 04

    Protected API

    Performs the action and owns its outcome

Decionis authority ↔ AgentSafe

The authority evaluates policy and supplies bound grants. AgentSafe records the decision, claim and execution evidence.

In enforcement, BLOCK stops dispatch and ESCALATE holds the action for the configured approval journey. The platform denies the agent's direct route to the API. In shadow, admitted requests execute while decisions are observed.

Put existing tool calls through it

When the tool exposes a base-URL setting, this is a configuration change. Apply it to the client that performs the action; changing a model endpoint does not capture separate payment, CRM or infrastructure calls.

Addressed reverse proxy

Run one gateway per protected upstream. Keep the original API as gateway.upstream and point the tool at the gateway's TLS URL.

Tool calls
https://agentsafe.bank.example/payments
Gateway forwards to
https://payments.bank.example/payments

Preserve the API method, path and business idempotency key. Configure redirects explicitly and test authentication that signs the host or URL.

Docker Compose and TLS ingress

Transparent interceptor

When a base URL cannot change, place agentsafe intercept beside the workload and redirect supported outbound traffic in its network namespace.

Governing HTTPS requires an interception CA trusted by the workload. Configure governed hosts and unlisted destinations; observation alone does not enforce a decision.

The agent must not control the redirect rules or use the exempt interceptor identity. Handle other ports and UDP/QUIC separately; pinned certificates and provider mTLS need another integration.

Sidecar setup and limits

The generic gateway relays caller credentials. For privileged credentials the agent must never hold, or verified proposer/operator roles, use the trusted executor. HTTP proxy settings do not turn the gateway into a CONNECT or raw database proxy.

Make bypass fail at the platform

Combine the gateway with controls at the agent and the upstream. Use the patterns that match your environment; review effective rules on the deployed workloads.

Pod network

Kubernetes

Install the gateway Helm chart in front of the API. Allow the agent namespace to reach DNS and the gateway; admit only the gateway to the protected API.

Use an enforcing CNI and inspect all policies. NetworkPolicies add their permissions together; the chart alone does not close the direct path.

NetworkPolicy example

Workload identity

Istio service mesh

Route calls to the gateway, require strict mTLS and authorize the agent at the gateway. At the API, admit the gateway's service-account identity.

Apply rules to the destination workloads and keep network confinement. A mesh policy does not reroute calls or verify an AgentSafe principal header.

mTLS and authorization examples

Security groups

AWS VPC

Separate agent, TLS gateway and upstream security groups. Remove broad agent egress and allow only the required gateway, authority and API paths.

Inspect every group attached to the workload: their allow rules combine. Shared EKS node groups need additional pod-level enforcement.

AWS rule matrix

Network security groups

Azure VNet

Associate NSGs with the intended NICs or subnets. Allow gateway, resolver and authority traffic as needed, followed by explicit denies for other paths.

Override default VNet access as well as Internet access. An Internet-only deny leaves internal bypass paths open; AKS also needs pod-level controls.

Azure rule priorities

Set up the path you selected

Operate your own gateway

  1. Provision a workspace and policy for the intended actions. Mount the workspace key as DECIONIS_API_KEY_FILE.
  2. Pin an approved image digest. Configure the upstream, authority endpoint and route-to-action mapping; start in shadow.
  3. Put TLS ingress or a mesh in front of the HTTP listener. Keep status, metrics and approval-resume access on appropriate operator paths.
  4. Point tool clients at the gateway, close direct API access and run the acceptance checks below.
  5. Promote the tested workflow to enforcement with fail closed. Plan held-request routing, evidence retention and capacity before scaling.

Runtime YAML, Docker and Helm setup

Use the managed cloud gateway

  1. Arrange the tenant workspace and public HTTPS upstream with Decionis. Agree traffic, retention and operator access.
  2. Complete origin verification using the supplied token at /.well-known/agentsafe-upstream.
  3. Receive the assigned tenant URL and ingress key through a secret channel.
  4. Set the tool base URL and supply AgentSafe-Tenant-Key from trusted configuration. Keep the upstream credential separate.
  5. Use approved test traffic and confirm SHADOW / PASSTHROUGH. Current hosting observes decisions while requests execute.

Hosted onboarding and limits

Policy lives in the authority. AgentSafe uses documented runtime or Helm configuration; it does not load a local policy file or a multi-upstream proxy map. A forwarded identity header remains an unverified claim unless the surrounding trust boundary establishes it.

Prove the boundary, then promote it

Test from the real agent network and identity against an approved test API. Correlate gateway evidence with API receipts so a response code is never the only proof.

  • Allowed action

    A valid decision and claim produce exactly one test effect at the API.

  • Refusal or hold

    BLOCK, an unresolved ESCALATE and an authority outage under fail closed produce zero effects.

  • Attempted bypass

    Direct calls, alternate endpoints and spoofed identities fail at the intended platform or identity control.

A timeout may be a DNS error or dead service. A 401 or 403 can come from an application that is still directly reachable. Require a working gateway-path control probe and evidence from the control that rejected bypass. During rollback, halt the workflow or restore its approved gateway configuration.

Acceptance checks and pipeline probe

Implementation reviewed 6 October 2026. Guides link to reviewed source 2190cbe. Verify the capabilities and digest of the build you deploy.