TL;DR — Key Takeaways
– Postman’s Fabric Gateway is now generally available, providing a centralized control plane for managing interactions among AI agents, LLMs, MCP servers, APIs and tools.
– The gateway applies authentication, authorization, classification, logging and identity-based governance policies to AI interactions.
– Fabric Gateway can route requests across AI model providers using fallback chains and circuit breakers, potentially helping organizations balance reliability and model costs.
Postman today made a control plane for governing artificial intelligence (AI) agents, large language models (LLMs) and Model Context Protocol (MCP) servers generally available.
The Fabric Gateway provides IT teams with a protocol-agnostic control plane for governing interactions between AI agents and applications and the application programming interfaces (APIs), tools and other AI agents.
Designed to route, govern, and observe LLMs, MCP servers, agents, and internal APIs that can be deployed anywhere, Fabric Gateway uses a built-in context graph to authenticate, authorize, classify, and log every interaction before it happens to create an auditable trail. It can also be used to design workflows and apply governance policies based on identity using a single unified registry that tracks every interaction.
Additionally, the gateway will route requests to another AI model provider using fallback chains and circuit breakers that can be invoked based on how robust the AI services being delivered are or in the event they are offline.
The overall goal is to centralize the management of AI interactions in a way that makes it possible to first discover interactions and then apply least privilege policies and controls accordingly, says Postman CEO Abhinav Asthana. In the absence of that capability, it becomes all but inevitable that there will be multiple security and compliance incidents involving AI agents, he adds.
It’s not clear at what pace organizations are deploying multiple AI models, but it’s clear that as costs continue to rise many of them will be looking for alternatives to the most advanced AI models. As powerful as those AI models may be, the fact remains that most business processes don’t require the latest AI model to be automated. In many cases, for example, a lower cost open weight or open source model that is less costly to invoke is more than sufficient for the task at hand. The challenge is finding a way to achieve that goal in the least disruptive way possible.
In the meantime, most organizations should assume they have already deployed more AI agents than they realize, notes Asthana. “There are already a lot more agents than most IT and platform teams realize,” he adds.
Managing what will become fleets of autonomous AI agents that are asynchronously performing tasks at scale requires a gateway through which AI interactions can be centrally managed, says Asthana. Keeping track of all those interactions is beyond the cognitive capability of any human, so the only way to practically enforce any type of control mechanism is via a gateway, he adds.
Ultimately, IT teams will require multiple gateways that, while optimized to manage specific workflows, are all federated in a way that makes it simpler to centrally enforce policies to prevent AI agents from performing any rogue actions, says Asthana.
In the meantime, IT teams should start creating an inventory of the AI agents and applications that have already been deployed. After all, while individual business units may have deployed those AI agents, it’s only a matter of time before they ask an IT or platform team to manage, secure and audit them on their behalf.


