AI Gateway governance
Bring LLM spend under the same cost governance as cloud spend, using virtual keys, budgets, routing and the existing RBAC machinery.
5 lessons. 1 quiz.
Read in order, or jump to what you need.
What the AI Gateway governs
By the end of this lesson, you will be able to state what the AI Gateway controls and what it never touches, locate its surfaces in the product, and explain why it is fully removable.
Providers and model registration
By the end of this lesson, you will be able to connect an AI provider and register models, explain why credentials are verified at connect time, and describe how tenant isolation is enforced on a shared fleet.
Virtual keys and budgets
By the end of this lesson, you will be able to issue a per-team virtual key with a hard budget and model allow-list, explain the org ceiling above it, and reason about why keys are org-visible rather than personal.
Routing and spend reporting
By the end of this lesson, you will be able to explain how the complexity router picks a tier, dry-run a prompt against it, and read the AI Spend surface including its stale-over-zero behaviour.
AI RBAC and provider scoping
By the end of this lesson, you will be able to design AI access using the two first-class capabilities, explain why one is Admin-only to mutate and the other is not, and apply provider scoping as a third policy segment.
Module quiz.
Take it once the lessons are done.