SovAIHub
ModulesSAI-240
SAI-240 table of contents
PublicDraftSAI-240 · v1.0.0Last content review: 2026-08-03

Identity, AI Gateways, and Egress Control

Propagate identity and enforce inspection, DLP, routing, endpoint, and response policies at controlled AI boundaries.

15 chapters31 min read

Learning outcomes

What you should be able to do

  • Design identity propagation across AI services
  • Define local-first and approved-egress policy
  • Place prompt, file, tool, and response inspection controls

Curriculum

Work through 5 sections in order.

The chapters are individually addressable documentation pages. You can link directly to a concept from another program, architecture decision, or implementation guide.

01

Gateway foundations

Understand the boundary, assets, actors, and policy decisions around AI requests.

02

Identity and authorization

Carry trustworthy identity and permission context through every decision.

03

Policy and egress

Control prompt, file, tool, route, endpoint, egress, and response behavior.

04

Release and assurance

Test policies, observe decisions, retain evidence, and control policy change.

05

Apply and assess

Produce and evaluate a gateway policy package.

Practical completion package

  • Identity and delegation flow
  • Gateway policy decision table
  • Inspection and DLP test suite
  • Egress and routing policy
  • Policy decision and release evidence

Current release boundary

This curriculum describes policy architecture and testing. It does not provide production DLP rules, guarantee detection of sensitive content, or approve external endpoints. Product integrations and rule packs require separately versioned validation.