AI Data Gateway Control Center

Productionv0.14.0
✓
System HealthChecking runtime...
↗
⌁
Gateway Health—Waiting for authentication
▰
Couchbase—ai_gateway
▱
MinIOReservedai-data-gateway
◎
Active Data Sources0Across 0 systems
⌘
Management Connectors0Gateway → system
◷
Last Reload—Generation —
⇣

Inbound Data Sources

SystemEnvironmentDirectionTransportData CapabilitiesStatus
Authenticate to load targets
0 data sources
⇣

Inbound Data Flow

100%75%50%25%0%
Production—
Staging—
Development—
⇣

Connection Direction

⇣

No data source selected

Select a source to inspect who connects to whom and what data it may send.

◇

Security & Auth

API Key Auth—
JWT / JWKS Auth—
Permissions
data.readbuild.readbuild.mutategateway.admin
Default DenyEnabled
◫

Audit Activity

No activity loaded yet
▱

Infrastructure

Couchbase
Bucket
ai_gateway
Scope
core
Collections
audit, control
MinIO
Bucket
ai-data-gateway
Region
us-east-1
Credentials
Server managed
DATA PLANE · SOURCE → GATEWAY

Data Sources

Register systems that push or sync operational data into the Gateway. Source identity defines tenant/system/environment; payloads cannot override that scope.

Source IDSystemEnvironmentDirectionTransportCredentialData CapabilitiesManaged ByLast SyncStatus
MANAGEMENT PLANE · GATEWAY → SYSTEM

Management Connectors

Outbound connectors are only for design, validate, plan, approval and apply. DWF Builder MCP lives here and is never used for Data Plane query/RAG.

GOVERNED DATA ACCESS

Query, Schema & Knowledge

Structured operational queries and knowledge retrieval share the same tenant/application policy boundary. Semantic retrieval is optional and always falls back to lexical evidence if degraded.

TRACEABILITY

Audit Logs

Recent in-process gateway activity. Capability arguments and secrets are never stored in audit metadata.

GATEWAY INFRASTRUCTURE

Infrastructure

Shared infrastructure with dedicated Gateway buckets and scoped credentials.

COUCHBASE

Connected

Gateway catalog, canonical data, schema, events, documents and audit persistence.

Bucket
ai_gateway
Scope
core
Collections
audit, control, schemas, records, events, documents
Credential
Dedicated bucket-scoped account
MINIO

Provisioned

Active Knowledge Data Plane object store for original source documents and re-processing.

Bucket
ai-data-gateway
Region
us-east-1
Endpoint
Configured
Credential
Server-managed runtime secret
GOVERNANCE & SECURITY

Security

Verified AI identity, application scope, fail-closed capability policy, and server-managed secrets.

◇

Authentication

API key and optional JWT/JWKS providers are verified before any protected gateway operation is accepted.

RequiredProduction authentication
⊘

Default Deny

Unknown or incomplete downstream safety metadata is classified as mutation.

EnabledFail-closed classification
◇

Exactly-Once Forwarding

Mutation calls are forwarded exactly once. Gateway does not automatically retry them.

EnforcedMutation delivery
▣

Credential Isolation

System catalog stores credential IDs only. Raw downstream secrets never appear in Admin responses.

Server ManagedSecret boundary
RUNTIME SETTINGS

Settings

Operational values visible to administrators. Secret-bearing settings remain server-managed.

Catalog refresh interval—
Connector drain windowConfigured by server
Admin permissiongateway.admin
Persistence drivercouchbase
Secret editingDisabled in browser