Inbound Data Sources
| System | Environment | Direction | Transport | Data Capabilities | Status |
|---|---|---|---|---|---|
| Authenticate to load targets | |||||
Inbound Data Flow
Connection Direction
No data source selected
Select a source to inspect who connects to whom and what data it may send.
Security & Auth
Audit Activity
Infrastructure
- Bucket
- ai_gateway
- Scope
- core
- Collections
- audit, control
- Bucket
- ai-data-gateway
- Region
- us-east-1
- Credentials
- Server managed
Data Sources
Register systems that push or sync operational data into the Gateway. Source identity defines tenant/system/environment; payloads cannot override that scope.
| Source ID | System | Environment | Direction | Transport | Credential | Data Capabilities | Managed By | Last Sync | Status |
|---|
Management Connectors
Outbound connectors are only for design, validate, plan, approval and apply. DWF Builder MCP lives here and is never used for Data Plane query/RAG.
Query, Schema & Knowledge
Structured operational queries and knowledge retrieval share the same tenant/application policy boundary. Semantic retrieval is optional and always falls back to lexical evidence if degraded.
Audit Logs
Recent in-process gateway activity. Capability arguments and secrets are never stored in audit metadata.
Infrastructure
Shared infrastructure with dedicated Gateway buckets and scoped credentials.
Connected
Gateway catalog, canonical data, schema, events, documents and audit persistence.
- Bucket
- ai_gateway
- Scope
- core
- Collections
- audit, control, schemas, records, events, documents
- Credential
- Dedicated bucket-scoped account
Provisioned
Active Knowledge Data Plane object store for original source documents and re-processing.
- Bucket
- ai-data-gateway
- Region
- us-east-1
- Endpoint
- Configured
- Credential
- Server-managed runtime secret
Security
Verified AI identity, application scope, fail-closed capability policy, and server-managed secrets.
Authentication
API key and optional JWT/JWKS providers are verified before any protected gateway operation is accepted.
Default Deny
Unknown or incomplete downstream safety metadata is classified as mutation.
Exactly-Once Forwarding
Mutation calls are forwarded exactly once. Gateway does not automatically retry them.
Credential Isolation
System catalog stores credential IDs only. Raw downstream secrets never appear in Admin responses.
Settings
Operational values visible to administrators. Secret-bearing settings remain server-managed.
gateway.admin