One compatible endpoint
Point existing OpenAI or Anthropic-compatible clients at the broker and select governed model aliases instead of vendor-specific endpoints.
PRODUCT 01 / AGENT ACCESS MANAGER
Authorization: Bearer sk-virtual-keykey / budget / guardrail / route / meterorg / team / project · RPM / TPM · PII / secret policycall_8F21ACONTROL OUTCOMES
Point existing OpenAI or Anthropic-compatible clients at the broker and select governed model aliases instead of vendor-specific endpoints.
Issue vendor-agnostic keys that can be scoped, revoked, suspended, and expired while master vendor credentials remain encrypted at rest.
Map aliases to several deployments, translate provider formats, spread load, track health, and fall back across vendors on failure or budget pressure.
Apply scoped budgets, RPM/TPM limits, request and response guardrails, and durable call-level usage and audit records.
REFERENCE ARCHITECTURE
Store each vendor endpoint, protocol, and encrypted credential in the on-prem catalog.
Map a stable model alias to one or more real upstream models for load balancing and fallback.
Issue revocable application credentials scoped to an organization, team, or project with budgets and rate limits.
Authenticate, guard, route, stream, meter, and record the provider, model, tokens, cost, and final outcome.
PRODUCT SPECIFICATION
A Spring Modulith architecture keeps the operational path simple while separating access, routing, governance, and analytics responsibilities.
POST /admin/providersPOST /admin/deploymentsPOST /admin/keysPOST /admin/budgetsRegister vendors and model aliases, encrypt provider credentials, mint application keys, and configure scoped controls.
POST /v1/chat/completionsPOST /v1/responsesPOST /v1/messagesPOST /v1/embeddingsUse existing OpenAI or Anthropic-compatible clients with a broker-issued virtual key; streaming is supported.
iamVirtual keys and /v1 authentication
catalogProviders, deployments, encrypted credentials
directoryOrganizations, teams, and projects
providersOpenAI, Anthropic, Gemini, and Vertex adapters
routingLoad balancing, health, and fallback
gatewayOpenAI-compatible request pipeline
analyticsPostgres call audit and usage records
billingBudgets, spend, RPM, and TPM
guardrailsPII, secret, and denylist policy
siemOptional OpenSearch event projection
soarOptional reversible abuse containment
sharedEvents and common value types
ON-PREM FIRST / POSTGRES SYSTEM OF RECORD / OPTIONAL OPENSEARCH + VALKEY + KEYCLOAK
TRUST ARCHITECTURE
Map virtual-key access, encrypted provider credentials, guardrail decisions, and audit evidence to the controls your enterprise already operates.
Architecture supports evidence collection for access, change, and monitoring controls.
Map credential, access, policy, and audit practices to ISMS control objectives.
Operational visibility across governed model access, guardrails, usage, and provider outcomes.
Control-alignment statements describe product architecture and are not claims of EnvisionAI certification.
TECHNICAL EVALUATION
Map the architecture to your providers, application clients, governance scopes, data boundaries, and operating requirements.