Speaking twice at Dreamforce · Sept 15-17 →

Control plane

Every tool call and model call goes through one door.

The first week is in the org, reading what already exists. Identity on the hop, policy at the edge, and a trail that survives an audit. If an agent can reach a model or a tool without passing this plane, you do not have a control plane. The honest no: if the work is a software factory with a named delivery date, we are the wrong partner.

Get the written assessment

Certified Partner since 2010 · MVP Hall of Fame · 200+ agents in production · UAE and US desks

Flex Gateway

What it is

Four controls, one hop.

The control plane is the only path from a runtime to a model, a tool, or another agent. In the orgs we work in that is Flex Gateway at the edge and Agent Fabric as the plane above it.

Why it matters

Without it you cannot answer the only question that matters.

Your auditor, your CFO, and your incident review all ask the same thing: who wrote that record, under whose authority, and what did it cost? Four things have to be true before you can answer.

Model routing

One door in front of several models.

Routing is a control decision, not a feature of whichever SDK the last engineer liked. The gateway is where the choice, the budget, and the audit live together.

  1. 01

    High-stakes reasoning

    Legal, financial, and architectural judgement goes to a frontier model. We will name which, and why, in writing.

  2. 02

    High-volume extraction

    Classification and intermediate transforms go to a fast model. Paying frontier prices for a field lift is a design error.

  3. 03

    Sovereign workloads

    Open models such as Gemma or CodeGemma inside your own cluster when code or records cannot leave the perimeter.

  4. 04

    Numbers, not prose

    Forecasting belongs to time-series models such as Google TimesFM. A language model guessing at a trend is not a forecast.

Model routing behind the gateway. Frontier reasoning for high-stakes work, a fast model for high-volume extraction, a local open model where data cannot leave the perimeter, and a dedicated forecasting model for numbers.
Mermaid source
flowchart TD
  A["Agents and applications"] --> G["Gateway: identity, policy, budget, audit"]
  G --> F["Frontier reasoning: Claude, OpenAI, Gemini Pro"]
  G --> H["High-volume extraction: fast, low-latency models"]
  G --> L["Local and open models in your own perimeter"]
  G --> T["Time-series forecasting models"]

In an org

A bank or an insurer.

Regulated, multi-tenant, and audited. The control plane is the reason the programme is allowed to exist.

Questions

What we actually say.

Can we call the model directly from the agent?
You can. You will not be able to prove who spent the tokens or which policy applied. We will not sign that as production.
Is this only a MuleSoft answer?
No. The plane is the requirement. Flex Gateway and Agent Fabric are how we usually build it in a Salesforce estate. An API gateway you already run can hold the same controls if it can do identity exchange and audit.
How do you handle MCP tools?
As a catalogue with entitlements per caller, served through the gateway. We will build that pattern in your org: a tool gets a version, an owner, and a scope before an agent may call it.
Does the gateway slow every call?
It adds a hop. It also removes the incident where nobody can say which agent wrote a record. We measure the latency and tell you the trade honestly.

From the blog

Can you stop an agent in two hours?

UAE CIO data, what DIFC Regulation 10 adds, and a five-step stop drill.

The brief · one email

Show us what an agent can call today.

We will mark the hops with no identity, and the ones that should not exist.