Service

Access control

Who may call which model. You decide, we enforce.

What we set up

Define which users, teams, applications, and service identities can access which models and capabilities, across cloud and on-premise.

  • Identity integration for people and services
  • Model allow-lists per team and application
  • Key management and rotation
  • Environment separation: development, staging, production
  • One central policy, consistent across providers

Deliverables

  • Entitlement model mapped to your organization
  • Access policies live at the gateway
  • Key lifecycle runbook
  • Documentation and handover

Gateways

Kong · LiteLLM · Unity AI Gateway · Snowflake Cortex · Amazon Bedrock

Does this cover self-hosted models?

Yes. The same identities and allow-lists govern cloud providers and locally hosted models.

How do service accounts fit in?

Service identities get scoped keys and model entitlements like any team, so machine traffic is governed and attributable too.