05 ·Agnidoot Gateway· Enterprise
Your people are already using AI, and nobody can tell you what it costs, what's being sent out of the building, or whether any of it is worth the money. Gateway is the control plane and the observability platform that answers all three — enforced at the server, where an application cannot argue with it.
Of requests priced
and attributed to a person
Requests refused
before reaching a model
Ordinary prompts stored
hash and lengths only
Then blocked content
is erased automatically
The problem
In most companies of 50–500 people, staff started using AI on their own. The tools are useful, so nobody wants to switch them off — but three questions have no answer, and they're the three a finance director and a security officer will both ask.
Subscriptions on personal cards, API keys in a dozen projects, no line item anyone can defend at a board meeting.
A customer contract pasted into a chat window. A spreadsheet with card numbers. Nobody finds out, because nothing is watching.
Spend with no attribution can't be judged. Which team, which use, which model — without that, ROI is a guess.
Gateway's answer isn't "ban it". It's to put every AI request in your organisation through one governed path — so the tools your people already like keep working, and you get control, cost attribution and an audit trail as a side effect.
Four questions, four controls
Each is enforced server-side. A client cannot negotiate with any of them, because the decision is made before the request reaches a model.
AI access becomes a permission you grant, not a tool people find for themselves. Identity comes from your own provider, so joiners and leavers are handled where you already handle them.
An unusual control, and a genuinely useful one: budgets carry day-of-week and time-of-day windows, enforced timezone-aware. AI can be available during working hours and simply unavailable outside them.
Why it matters: out-of-hours automated traffic is where runaway spend usually happens — a loop nobody notices until the invoice. A window closes that door without anyone having to watch for it.
Spend caps at the level you actually manage money: the organisation as a whole, and each individual person. Teams carry their own policy alongside. When a cap is reached, work stops cleanly.
This is the control that stops the incident. Each request is checked against your policy before any model sees the content — so sensitive material never leaves the building at all, rather than being discovered in a log afterwards.
Proven at volume: on our own stack this gate has refused 7,263 requests — every one of them stopped before a model was called.
Full observability
Control without measurement is a policy document. Every request that passes through Gateway — allowed or refused — leaves a row you can query, attribute and export.
The data is complete; the packaged dashboards are not. Every request is priced and attributed, and that record is queryable and exportable today — so cost-per-team and cost-per-person are answerable right now.
What we deliberately do not ship is the built-in cost dashboard. An earlier version of it returned plausible invented figures behind real authentication, so we disabled it rather than let anyone make a budget decision on a number the system made up. It returns an explicit "not available" until the analytics are wired properly. Given what this product is for, we'd rather hand you nothing than something untrue.
Privacy
Observability usually means retention, and retention is its own liability. Here it doesn't: every request is inspected and measured, and ordinary prompt text is never kept.
The details
The gate is real, server-side and proven at volume — 7,263 requests refused before reaching a model on our own stack. It refuses rather than redacts, so nothing sensitive leaves the building.
What you configure into that gate is per tenant: your own keywords and patterns (card formats, account numbers, project code names), category rules, and built-in PII and prompt-injection detection, with a block message you write.
Stated precisely: the enforcement path is verified and carries real traffic. The PII-specific detectors are configuration we have not yet exercised end to end in QA — so we'll configure them on your tenant and demonstrate them against your own patterns during the assessment, rather than ask you to take a data-loss claim on trust.
Two enforced levels today, plus scheduling on each:
Teams sit alongside this, carrying their own policy — model, guardrails, permitted tools and channels — and every request is attributed to a person and their team, so cost by team is answerable from the record even where the enforced cap is set per person. If you need a hard cap enforced at team level specifically, raise it in the assessment and we'll be straight about where that sits.
The AI step halts and the person sees a plain sentence: "Your organisation's AI budget for this period has been used up… your administrator can raise the limit." No error code, no stack trace. Work stops cleanly, nobody's card is surprised, and the administrator can see which team spent it.
A request outside an allowed time window, or outside permitted use, is refused the same way — before a model is called, with the attempt recorded.
The identity hub proves who is calling — an OIDC token verified against the hub's live signing keys. The bridge then maps that identity to a credential it already holds, so a durable Odoo API key never travels over the network.
Verified against a live hub: a real token for a registered person resolved to their own Odoo login; a token for an unregistered person failed closed; and the shared service credential was unreachable in both paths.
The honest cost: an administrator registers each person's Odoo login once. It isn't zero-config.
Read this carefully before you design your teams: a person in two teams receives the union of both teams' capabilities, not the intersection. Adding someone to a second team widens their access.
Gateway governs beside the execution path, never in front of it. No Odoo request is routed through a Gateway process. AI traffic flows through it for model, budget, schedule and policy; identity comes from the hub; the bridge emits usage and audit to it. Approvals, risk tiers and the ERP write path stay exactly where they were.
That was deliberate: the bridge models more about an ERP action than a general AI gateway can, so execution stays with the component that understands it. Governance is added, never substituted.
The platform behaves byte-for-byte as it did before the tier existed. That is the acceptance criterion for the whole enterprise tier, and proving it is itself a test case in our QA suite. Upgrading — and downgrading — is a decision, not a migration.
No penetration test and no compliance certification (SOC 2, ISO) has been performed. Claims about what is stored are verifiable from the schema and are made above; claims about what is secure we don't make. We'll hand your security tester the code instead of a PDF.
Four specifics a careful buyer should know: capability and tool policy is client-enforced, not server-side authorization — real authorization lives in entitlement and in the bridge's risk tiers; team permissions union rather than intersect; packaged cost dashboards are disabled for the reason given above; and there is no request rate limiting on the gateway endpoint yet — budgets and schedules are the spend control, not throttling.
We also don't offer sentiment or tone analysis of your team's AI conversations. It isn't built — and given that ordinary prompt text is never stored, it would mean reversing the privacy property this page is built on. If monitoring communication tone is a requirement, tell us and we'll say plainly whether it's something we'd build.
Every plan includes
No obligation, no card, no lock-in. And what comes with your plan isn't a discount — it's what it takes to make an ERP actually land.
Not months. Your implementation is underway in your first week.
A full year included with every plan — not a paid add-on.
We come to you and train your team in the room, on your data.
A hundred hours of our engineering, built into every plan.
◆ No card to start · ◆ No obligation · ◆ Cancel any time in the three months · ◆ Your data stays yours
Questions
We'll route it through Gateway and show you who spent it, on what, and what got stopped on the way out — live, on your own tenant.
Thirty minutes, your paperwork, your questions. We will show you what it does — and, just as importantly, what it refuses to do.