← All Articles
Technical 10 min read

Agent Gateway: A New Era of Governed AI Agents Interactions

Agent Gateway introduces new capabilities that enable trusted, governed, and accountable AI agent interactions across connected ecosystems.

Anja Obradovic & Michael Yih

Today, we’re introducing a major upgrade to Agent Gateway that helps organisations establish trust, enforce governance, and maintain accountability across increasingly connected agent ecosystems.

Already used by organisations to govern interactions between AI agents, users, services, and external systems, Agent Gateway now introduces new capabilities that make governance more visible, interoperable, and operationally scalable. Built around open standards, these enhancements enable teams to embed trust and policy controls directly into the flow of agent interactions, helping them move from experimentation to production with greater confidence.

This upgrade introduces Agent Surfaces, a visual governance framework for managing agent interactions, alongside new operational capabilities that improve interoperability, observability, and accountability.

A New Way to Govern Agent Interactions

At the core of this upgrade is Agent Surfaces.

Agent Surfaces provide a workflow-based approach to configuring and governing how requests move between agents and the systems they interact with. Supporting both Agent-to-Agent (A2A) and Model Context Protocol (MCP) interactions, Agent Surfaces allow organisations to define governance controls at critical decision points throughout the lifecycle of an agent request and response.

Rather than building governance logic into every individual application or service, organisations can define controls once and apply them consistently across agent interactions.

Three capabilities introduced in this upgrade form the foundation for governed agent interactions.

Agent Surface

Caller Context & Credential Delegation: Preserving Identity Across Agent Interactions

Agent interactions often involve multiple parties. An agent may be acting on behalf of a user, another application, or even another agent.

Before policy decisions can be made, systems need to understand who initiated the request.

The new Caller Context capability captures and preserves authentication and identity context from inbound requests before governance controls are evaluated. This enables the original caller’s identity to travel with the request, allowing agents to inherit and present the context of the human on whose behalf they are acting. In Gateway-to-Gateway interactions, this portable identity helps downstream services and organisations make decisions based on the original caller, rather than only the immediate requesting agent or system.

Building on this identity context, Credential Delegation enables credentials received through source authentication to be securely propagated to downstream services. This allows agents to act on behalf of users while maintaining governance controls, accountability, and visibility into how delegated authority is exercised across systems. The capability also includes support for masking personally identifiable information where appropriate, helping organisations balance usability with privacy requirements.

Together, Caller Context and Credential Delegation create a more secure and transparent model for agent-driven interactions. By preserving identity and delegated authority throughout the interaction flow, organisations gain better visibility, stronger accountability, and greater trust across agent-driven processes, even when interactions span multiple gateways, systems, and organisational boundaries.

Trust Registry: Establishing Trust Before Interaction

As agent ecosystems expand across organisations, platforms, and partners, trust can no longer be assumed.

The new Trust Registry capability enables Agent Gateway to verify whether an individual, partner, application, or agent has been authorised to perform a specific action on a particular resource before a request is allowed to proceed. Rather than relying solely on static integrations or pre-configured allowlists, organisations can make decisions using verifiable trust and authorisation records.

This provides a trusted way to answer questions such as:

  • Has Company A authorised Agent B to perform Action X on Resource Y?
  • Does Company X recognise Agent B as having the authority to approve or authorise Action X on Resource Y?

By making authorisation and delegation verifiable across organisational boundaries, Trust Registry helps organisations reduce fraud, strengthen inter-organisational trust, improve auditability, and enable secure partner ecosystems where delegated authorities can be recognised and trusted with confidence.

Auditability by Design

As AI agents take on more responsibility, organisations need more than operational monitoring. They need verifiable record of how decisions were made, what policies were enforced, and who was authorised to act.

The Audit capabilities in Agent Gateway provide end-to-end traceability across agent interactions, governance controls, delegated credentials, and trust verification processes. Audit records allow teams to demonstrate which policies allowed or denied a request, investigate which credentials were used and when, and trace how identity, authorisation, and governance decisions flowed through the system.

By correlating audit events through shared trace IDs, organisations can connect interactions across gateways, services, and external systems. This supports compliance audits, security investigations, policy debugging, credential lifecycle tracking, and Trust Registry verification, while providing a stronger foundation for accountability through verifiable and tamper-evident records.

Audit Log

Start Building Governed Agent Interactions

Ready to explore what’s new in Agent Gateway? Log in to the Affinidi Portal to discover the latest capabilities, experiment with Agent Surfaces, and start building trusted and governed agent experiences today.

Get access to Agent Gateway: https://portal.affinidi.com/agent-gateway

Learn how to create your first Agent Surface: https://docs.affinidi.com/products/affinidi-trust-fabric/agent-gateway/get-started/create-first-surface/

AI AgentsDigital IdentityAgent GatewayAgent GovernanceDigital IdentityTrust RegistryCredential DelegationAI SecurityInteroperability

Build with Affinidi

Start building trust infrastructure with our open-source tools and developer-friendly APIs.

Cookie Preferences

We use cookies to enhance your experience. You can manage your preferences below. For more information, read our Cookie Policy.

Strictly Necessary Always Active

These cookies are essential for core website functions such as security, session integrity, and cookie preference storage. They cannot be disabled.

  • _cf_bm: Distinguishes humans from bots (Cloudflare) · 30m
  • _cfuvid: Ensures secure browsing (Cloudflare) · Session
  • __hs_initial_opt_in: Prevents HubSpot's banner · 7 days
  • _gtm_debug: GTM debug mode (testing only) · Session
Analytics

These cookies help us understand how visitors interact with the site so we can improve content and performance. All data is aggregated and anonymous.

  • _ga, _gid, _gat: Google Analytics · Session – 2 years
  • __hstc, hubspotutk, __hssrc: HubSpot visitor tracking · 13 months
  • __hs_opt_out: HubSpot opt-out preference · 6 months
Marketing & Targeting

These cookies allow us and our partners to serve personalised ads and measure campaign performance.

  • _gcl_au, _gcl_dc: Google Ads conversion tracking · 90 days
  • IDE: Google Display Network personalisation · 1 year
  • _fbp: Meta / Facebook remarketing · 90 days
  • li_gc, _li_fat_id, bcookie: LinkedIn tracking · 1–24 months
  • guest_id, personalization_id: Twitter/X analytics · 2 years