What Is Gatekeeper?
Gatekeeper controls which AI services your organisation can access. It enforces your default policy and any explicit exceptions, allowing or blocking services as people work. It is your access control layer for AI.How It Works
Gatekeeper is built from two simple parts: a default rule that applies to every service, and a list of exceptions for the services you want to treat differently. When someone reaches an AI service, Gatekeeper checks it against your policy and acts at once. You define the policy on each Gatekeeper. The organisation default applies everywhere, unless a workspace is assigned a different Gatekeeper.Choose Your Default Rule
- Allow all services
- Block all services
All AI services are allowed unless you explicitly block them. You then add the services you want to block as exceptions. This suits organisations that want broad access with a few clear exclusions.
Add Exceptions
Search the service catalogue and select the services to block or allow. Everything else follows your default rule. You can adjust the list at any time, and changes take effect on the next trace.Recommended Services
A block does not have to be a dead end. Turn on Recommended services on a Gatekeeper configuration and pick approved alternatives from the catalogue. When someone reaches a blocked service, Gatekeeper can point them to an option you already allow. Recommended services are per Gatekeeper, so a workspace assigned a different Gatekeeper can suggest different alternatives.Access Requests
When Gatekeeper blocks a service, the person can ask for access and give a reason. The request lands on that Gatekeeper configuration. From the User exceptions panel you can:- Accept the request, which grants that device an exception
- Decline it
- Revoke a granted exception later
Block Message and Language
You can edit the message people see when a service is blocked, including per language. A live preview shows the notification as it appears in the browser. Language follows Settings → Agents; see Configuring agents.Common Setups
Open with a blocklist
Open with a blocklist
Keep AI broadly available, but block a handful of services you do not trust or have not approved. Good for teams early in their AI adoption.
Locked down with an allowlist
Locked down with an allowlist
Block everything by default and allow only the services that have passed your review. Good for regulated work and strict vendor policies.
Suggesting an approved alternative
Suggesting an approved alternative
When someone reaches a blocked service, point them to an approved alternative that meets the same need.
Working Alongside the Other Agents
Gatekeeper and Data Protector review each trace independently. A trace can pass Gatekeeper’s service check and still be caught by Data Protector for sensitive content. Coach is separate: it guides people; it does not allow or block a service.Service catalogue
Browse the AI services Velatir can detect.
Configuring agents
Defaults, extra Gatekeepers, and workspace assignment.