APEX / Governed Enterprise AI Gateway

Enterprise AI
without unrestricted
enterprise access.

AI agents, MCP servers, and workflow tools are gaining access to enterprise systems. Without a governance layer, a prompt-injected or rogue capability can reach data, files, email, and internal systems far beyond its intended scope.

APEX mediates every AI capability call through policy, identity, RBAC, and audit. Default-deny. Working software on Azure.
AI governance is the door that lets enterprises say yes to AI safely, productively, and at scale.
Governed AI Access
Zero Trust Architecture
MCP Gateway
Policy Enforcement
Identity & RBAC
Audit Trail
Azure APIM
Managed Identity
Default Deny
EU AI Act Article 50
Governed AI Access
Zero Trust Architecture
MCP Gateway
Policy Enforcement
Identity & RBAC
Audit Trail
Azure APIM
Managed Identity
Default Deny
EU AI Act Article 50
5
Governance Layers per Call
0
Credentials in the Model
100%
Calls Audited
Aug 2
EU AI Act Transparency Duties
The Problem

Rogue vs. governed.

Without a governance layer, any AI capability source can reach your entire data plane. APEX enforces what each source is allowed to do before it touches any resource.

Rogue / Ungoverned
AI connected directly to enterprise systems
Credentials, tokens, or broad permissions are reachable by the model or unmanaged toolchain. Blast radius if prompt-injected: entire data plane. No audit trail.
raw_sql
list_all_blobs
read_all_secrets
send_external_email
post_to_web
Governed
AI calls approved tools only
APEX mediates access through policy-bound tools, managed identity, and RBAC. Every call checked, scoped, and logged.
customer_lookup
read_approved_document
policy_status
audit_log
The Architecture

Five layers. Every call.

A single tool call is checked five times before it touches data. Defense in depth, not defense by one prompt rule.

1
APIM
Who is calling?
Subscription key, JWT signature, token expiry, rate limit, allowed operation
2
Gateway Policy
Should this tool run?
Tool allowlist, risk tier check, time-window rules, input shape validation
3
Managed Identity
No secrets in code.
Token request to Entra ID, scoped to resource audience, short-lived
4
Resource RBAC
Even if 1-3 fail?
SQL: db_datareader. Blob: Blob Reader. KV: Secrets User. Network ACL. VNet boundary.
5
Audit
What happened?
Tool name, resource, identity context, access model, timestamp, result, status
This public page contains no APIM keys, JWTs, client secrets, or live admin credentials.
Enterprise Value

Enable AI without enabling risk.

Without governance, AI is either blocked by security or deployed with hidden risk. APEX is the layer that lets the enterprise say yes.

Prevent AI data breaches
Default-deny capability access for unregistered AI systems and rogue tools.
Default-deny on every capability source
Satisfy audit requirements
Persistent records of tool calls, resources, policies, and outcomes.
SOC 2, HIPAA, SOX, EU AI Act ready
Ship AI capabilities faster
Approved capability sources deploy through a registration workflow, not security review backlog.
Weeks to days for new AI tooling
Control AI consumption
Per-source quotas, rate limits, and policy tiers prevent runaway LLM and data costs.
Spend visibility per agent, tool, and policy
Delivery Track Record

Working software. Not slideware.

APEX is a working Azure reference architecture. Here is what we have delivered to production.

Manufacturing Enterprise: Governed AI over Epicor ERP
7 weeksDelivery Timeline
1 architect + 2 devsTeam Size
Azure + PythonStack
3 environmentsDev / Test / Prod

A manufacturing enterprise's AI initiative had stalled after months of effort. We architected and delivered a governed natural language interface over live ERP data. Deterministic orchestration handles flow. NLP maps user intent to stored procedures. LLM summarizes results. Zero Trust throughout.

Industry Benchmark
8-15 specialists, $1.5M-$4.5M
Our Delivery
1 architect, 2 part-time devs, 7 weeks
Major Credit Union: Public-Facing AI Chat Turnaround
Code RedStatus on Entry
8-person teamCross-Functional
ProductionFinal Status
Millions savedAnnual Impact

On the verge of cancellation. Led a cross-functional team across business, technology, and executive stakeholders and delivered to production. The system is now saving the organization millions annually.

Resources

Go deeper.

Live Controls Walkthrough
Step through three running governance controls: security-trimmed retrieval, the DLP boundary, and deterministic data access with database-enforced permissions.
Open Walkthrough
Technical Brief
Full architecture overview including governance layers, APIM enforcement, audit model, and enterprise value proposition.
Download PDF
Enterprise Agent Skills
Browse quality-assured operating methods for AI governance, MCP control, governed RAG, deterministic data access, and executive review.
Browse Skills
Technical Briefing
Review enterprise AI governance posture, capability surfaces, MCP/agent risk, and APEX deployment options with your security team.
Schedule
Demo Narrative
Short walkthrough of the APEX governance architecture, rogue-vs-approved server model, policy enforcement, and audit flow.
Contact

Enterprise AI without governance
is enterprise risk without controls.

APEX is a working Azure reference architecture built by NPM Technologies for governing AI capability access. Technical briefings available for CISOs, CIOs, and security teams.

paulh@npmit.com
(855) 676-8324
Paul Hasselbring  ·  Founder & Principal Architect  ·  NPM Technologies  ·  Fort Lauderdale, FL

linkedin.com/in/paulhasselbring