Security approach
A decision is not enforcement.
Gated’s intended architecture separates evaluating policy from controlling whether a sensitive action can proceed.
The intended boundary
A sensitive action must pass through a trusted Gated-controlled integration, broker, tool, proxy, wrapper, delegated credential path, or another verified enforcement point. Policy evaluation alone does not enforce a result.
Inside the intended model
Explicit request context, scoped authority, policy evaluation, an enforcement consequence, and a decision record.
Outside the intended model
Actions taken with credentials or paths that bypass the trusted enforcement point.
Model connections
Connecting a model provider does not give Gated control of everything that model does.
Network coverage
Gated does not imply that all network traffic automatically passes through it.
What is verified today
The private staging pilot has verified exact GitHub branch creation through a Gated-controlled GitHub App path, with policy checks, passkey approval, replay protection and audit receipts. Codex and Claude Code use explicit downloaded skills and CLI routing; they do not automatically intercept other tools. Only non-critical pilot use is in scope. Encrypted off-primary backups and failure alerts have been tested; timer-triggered backup acceptance and full replacement-service recovery remain open. Gated does not claim production readiness, certifications, a DPA, an SLA, guaranteed support or universal provider coverage.
