Resources · Blog
Enterprise notes from the ForgeCrux architecture practice
Architecture
One control plane for APIs, models, tools, and agents
Why enterprises are collapsing four gateway consoles into ForgeCrux One—and what stays in Git vs what stays in the data plane.
Security
MCP default-deny: treat tools like production APIs
Virtual catalogs, argument-level RBAC, and vault injection so IDEs and agents never hold SaaS or database keys.
Governance
Put AI policy in the request path, not the quarterly review
Classification, residency, and eval gates that execute before the model sees data—and land as SIEM evidence.
Modernization
Dual-run cutover without rewriting consumers
Shadow traffic, payload diffs, and weighted DNS so partner keys and hostnames survive the move off legacy API management.
Operations
A single trace ID from app to MCP to system of record
OpenTelemetry collectors, service maps, and PagerDuty payloads that include the full gateway hop list.
Agents
Production agents need identity, hop limits, and a kill switch
Supervisor–specialist topologies that only call models and tools through ForgeCrux—and pause when evals fail.
Enterprise data
Uses, installation, setup, and security—the same operating model as the platform and solutions pages.
Enterprise uses
What this library is for—not a consumer changelog.
- Architecture decision records for platform and security forums
- Cutover and dual-run patterns for API modernization programs
- Governance mappings for SOC 2, ISO 27001, HIPAA, and GDPR
- FinOps views of tokens, MCP calls, and API products
- SRE runbooks for SLO burn, policy hits, and agent pause
- Integration notes for IdP, SIEM, ITSM, and GitOps
Security & compliance notes
Topics we publish for GRC and security architecture.
- Workload identity vs human SSO on the control plane
- PII redaction in prompts, traces, and MCP arguments
- Retention, legal hold, and residency for audit lakes
- Break-glass, dual control, and time-boxed waivers
- Default-deny MCP catalogs and HITL for mutating tools
- Evidence packs: who changed policy, who approved, who replayed
Want this as an architecture workshop?
We run working sessions on dual-run cutover, AI policy-in-path, and zero-trust MCP.