End-to-end traces
Correlate gateway, policy, selected upstream, and outcome metadata without claiming a credential-broker span.
Evidence plane
Correlate the current discovery, authorization, upstream execution, and audit path while approval resume, credential use, and full telemetry remain roadmap work.
Product boundary
Capabilities
Status labels distinguish tested behavior from useful previews and the open roadmap.
Correlate gateway, policy, selected upstream, and outcome metadata without claiming a credential-broker span.
Record tenant-scoped, redacted identity, policy, target, and outcome metadata in a sequence/hash-linked chain.
Measure probe health, latency, error classes, saturation, and connector reliability.
Export audit configuration today; standards-based trace, metric, and SIEM delivery remains planned.
Operating flow
Assign a request identity and carry it through every internal and upstream boundary.
Record decision inputs, matched policy, route, approval state, and result metadata.
Stream standards-based telemetry without requiring payload collection.
Target control surface
These controls define the intended product boundary; the capability labels above are the current implementation record.
The managed cloud and Kubernetes paths are previews of one open codebase, with no intended capability gate or mandatory call-home path.