an L1 tech asks the AI for the firewall rules?
The call runs under their own PAN-OS account. The firewall returns what their role allows, which for L1 is nothing. Gate logs the attempt either way.
HR asks the AI for someone's salary?
The HR system is called as that HR user, with their own login. If they may see it at the console, the AI may; if not, not. Finance asking the same gets a deny, and both attempts are in the chain.
someone asks the AI to summarize a file on the Finance share?
Gate opens it as that person, and only if it sits under a drive Group Policy maps for them. If NTFS says no, the AI is told the file isn't there, and the attempt is in the chain. The share permissions you set years ago keep working, now for AI too.
someone asks the AI "anything about layoffs?"
The search runs with their own permissions. Folders they can't open are left out of the results, names included, so a folder called "Layoffs 2027" never reaches the model. The trail records "hidden: 1", never the name.
some of our PCs and apps can't do Kerberos?
Turn on NTLM for them. Gate accepts NTLMv2 only, requires relay protection by default, has a domain controller check every answer, and marks each NTLM sign-in in the trail so you can see who still needs it.
someone skips the chat UI and hits the API directly?
They reach Gate, not the tools. Policy is enforced at the gateway, not in the interface, and their token is still their identity.
a document contains a prompt injection?
Tool output is data, never instructions. Writes and executes are staged for an approver by policy, so a tricked model still can't change anything alone.
the auditor asks who saw what?
It is already in your SIEM, and the chain exports as NDJSON. Every row carries the user, their groups at that moment, the policy version in force, the identity the call ran as, the arguments and the result. Verify proves nothing was edited.
our model runs on our own box, not in a cloud?
Gate runs beside it. Open WebUI, the model and Gate stay inside the building; the prompt, the data and the credentials never leave. Same guardrails, same chain as the cloud AI your other teams use.
the SIEM is down for an hour?
AI calls keep working; delivery is off the request path. The destination shows its last error in the console, every row is still in Gate's own chain, and the collector can page what it missed by cursor when it is back.
how does Gate know an action needs approval?
It doesn't guess. You write the rule, like change control: finance writes, firewall commits, or every write not explicitly allowed. A matching call is staged with its exact arguments; an approver sees them, enters an authenticator code, and it runs as the person who asked.