ModulesSAI-240
SAI-240 table of contents
Identity, AI Gateways, and Egress Control
Propagate identity and enforce inspection, DLP, routing, endpoint, and response policies at controlled AI boundaries.
Learning outcomes
What you should be able to do
- Design identity propagation across AI services
- Define local-first and approved-egress policy
- Place prompt, file, tool, and response inspection controls
Curriculum
Work through 5 sections in order.
The chapters are individually addressable documentation pages. You can link directly to a concept from another program, architecture decision, or implementation guide.
Gateway foundations
Understand the boundary, assets, actors, and policy decisions around AI requests.
Introduction to identity and AI gateways
Treat the gateway as a controlled decision and evidence boundary, not only a reverse proxy.
Trust boundaries and data flows
Map where trust changes and where data, artifacts, requests, identities, tools, and evidence cross a boundary.
AI assets and attack surfaces
Inventory the data, models, prompts, artifacts, identities, tools, interfaces, infrastructure, and evidence that require protection.
Identity and authorization
Carry trustworthy identity and permission context through every decision.
Identity propagation and policy decisions
Preserve user, workload, service, and tool identity across AI boundaries and make policy decisions explicit.
Identity propagation, delegation, and service trust
Preserve actor context while constraining workload, service, and delegated authority.
Permission-aware data access
Enforce source permissions through ingestion, indexing, retrieval, caching, generation, and evidence handling.
Policy and egress
Control prompt, file, tool, route, endpoint, egress, and response behavior.
Gateway policy, inspection, and DLP
Apply allow, deny, redact, transform, rate, route, and approval decisions to AI traffic.
Egress, routing, and response controls
Make external access, endpoint choice, response inspection, and failure behavior explicit and testable.
Write effective control objectives
Translate sovereignty goals into testable statements of what must be allowed, prevented, approved, observed, retained, and recovered.
Release and assurance
Test policies, observe decisions, retain evidence, and control policy change.
Evaluation and release gates
Turn acceptance criteria into repeatable promotion decisions with recorded evidence and rollback conditions.
Observability and operational evidence
Design signals that explain service health, AI behavior, policy outcomes, change, and incidents without leaking sensitive content.
Evidence by design
Design evidence alongside controls so important decisions, releases, configurations, and operating events can be verified.
Controlled change and versioning
Version complete AI behavior, assess change impact, approve promotion, support rollback, and retire superseded assets.
Apply and assess
Produce and evaluate a gateway policy package.
Practical completion package
- Identity and delegation flow
- Gateway policy decision table
- Inspection and DLP test suite
- Egress and routing policy
- Policy decision and release evidence
Current release boundary
This curriculum describes policy architecture and testing. It does not provide production DLP rules, guarantee detection of sensitive content, or approve external endpoints. Product integrations and rule packs require separately versioned validation.