Back to areas of concern
Governed AI Call Lifecycle
A layered architecture diagram with clickable regions for consumer, edge security, gateway, governance, runtime, policy, observability, and backend systems.
Governed AI Call Lifecycle
Layers 1–4 are bidirectional control systems for inbound requests and outbound responses.
Observability
/
FinOps /
Audit /
Compliance
telemetry
across
all layers
1. Consumer Zone
apps · users · agents · APIs
All AI traffic
Secure response delivery
2. Edge / Perimeter Security
network protection · TLS · ingress / egress controls
Perimeter-validated traffic
Metered & routed response
3. API Gateway Enforcement
identity · routing · quotas · budgets · metering
backend calls
Policy / Control Plane
control-plane only
model entitlements · allow-lists ·
routing policy · tool approvals ·
access contracts
Entitled & metered request
Policy-approved AI response
4. Prompt, Data & Output Governance
prompt defense · data policy · output validation
Policy-cleared execution request
Unvalidated model / tool result
5. AI Runtime & Execution
runtime · deployed models · orchestration · MCP tools
6. Resource / Knowledge /
Backend Systems
backend systems · knowledge graph · curated data
MCP / tool calls
Hover preview