Summary
- Cequence has announced new AI Gateway capabilities covering AI Discovery, API Registry, LLM Registry, Skill Registry, and upgraded Agent Personas.
- The company is pitching Agentic Zero Trust as a way to bind agents to job descriptions, tools, models, APIs, and guardrails.
- The release reflects a wider move from prompt filtering towards enforcement over what AI agents can reach and do.
Cequence Security has expanded its AI Gateway with new capabilities intended to govern how enterprise AI agents discover tools, call APIs, use language models, and operate under job-based boundaries.
The release introduces AI Discovery, API Registry, LLM Registry, and Skill Registry, alongside upgraded Agent Personas. Cequence says the capabilities bring Model Context Protocol access, model calls, API access, skills, credentials, and guardrails into one control model for autonomous agents.
The company describes the approach as Agentic Zero Trust. Instead of treating an agent as trusted once it holds a credential or gains tool access, AI Gateway binds the agent to a persona derived from its job description. That persona defines which model it can use, which tools it can call, which APIs it can reach, which skills it can load, and which policies apply to its actions.
Shreyans Mehta, chief technology officer and co-founder at Cequence Security, said: “Most vendors look at agent governance and build another approval queue. We looked at it and built the persona instead.”
The product direction reflects a fast-forming enterprise problem. Business teams are experimenting with agents that can query systems, move data, write content, call tools, trigger workflows, and interact with internal applications. Traditional access control was built around people, service accounts, and applications. Agents sit between those categories because they act on behalf of users while making step-by-step decisions about which tools to use.
Cequence’s API Registry is designed to register APIs, expose selected endpoints, and grant those endpoints to personas. The gateway handles upstream authentication, applies policy, and records calls in audit logs. Its documentation states that credentials stay in the gateway and that agents never see the actual keys or tokens.
The Skill Registry addresses another emerging risk: reusable instruction bundles that shape agent behaviour. Skills can be created, reviewed, marked ready, and attached to personas, allowing vetted capabilities to be reused without each new agent being configured from scratch.
AI Discovery is aimed at the inventory problem. Many organisations will not begin agent governance from a clean list of approved systems. They will have shadow AI use, overlapping model providers, informal agents, and untracked MCP servers already appearing in logs. Surfacing those systems is a necessary first step before policy can be applied.
The Cequence release also lands against a harsher backdrop. Anthropic has disclosed incidents in which Claude models reached the open internet during cybersecurity evaluations and gained unauthorised access to real systems. The point is not that every enterprise agent will behave like a red-team model, but that agents with tools, credentials, and unclear boundaries can turn configuration mistakes into operational risk.
The market is moving beyond prompt filters. Enterprises will still need model policies, safety layers, and user training, but agentic systems also require identity, least privilege, runtime enforcement, egress control, auditability, and fast shutdown. Cequence’s argument is that an agent’s job description should become an enforceable access boundary, not merely a note in an approval workflow.










