00 2026 Fact check

MeterPlane governs every provider call before key access

Identity, permissions, approvals, budgets, and audit evidence live in the runtime path.

Evidence metric 5 layers

Governance path before and around provider invocation

Identity, authorization, approval, spend control, and audit
MeterPlane control Before key read

Credential access happens after Layers 1-4 pass

Audience Founders, security buyers, platform teams, investors

Layer 1 / Layer 2 / Layer 3 / Layer 4 / Layer 5

Case sequence

What happened

Total duration: Single routed provider call

  1. 01

    Agent calls POST /v1/services/{provider}/{operation} with an ag_ gateway key.

  2. 02

    Identity verifies the key, tenant, provider status, and target operation.

  3. 03

    Authorization evaluates permissions, risk level, lifecycle, rate limit, and kill switches.

  4. 04

    Approval pauses risky actions before credential access.

Control mapping

Direct path vs. governed path

Each case maps public facts to a MeterPlane control that runs before provider credentials are read.

Step Direct path MeterPlane control
Layer 1Credential boundary Agent or app holds the raw provider key. Agent holds an ag_ gateway key; provider key remains vaulted.
Layer 3Risky action Destructive, publish, deploy, or money-moving calls execute immediately. High-risk operations return pending until an approver blesses execution.
Key insight

MeterPlane gives every agent action a control point before the provider credential is read.

Scope

How to read this case

This product architecture study defines the control model used to interpret the ten public case studies.

All Case Studies