Four integrations decide how much of Gatehouse works. Each one below shows what it is doing right now, what you get for turning it on, and exactly what happens if you don't — nothing here is required, and nothing degrades silently.
New policy
Entity reference
Principals
principal in Group::"contractors"
Actions
Action::"UsePrompt"
Action::"UseModel"
Action::"UseTool"
Action::"AttachFile"
Action::"UseApplication"
Resources
Application::"claude-code"
Model::"claude-opus-5"
Tool::"Bash"
Context
context.detectors.secrets_found
context.detectors.regulated_found
context.detectors.injection_found
context.hour_of_day
context.weekday
context.source
context.transcript_bytes
Cedar denies when nothing permits, so Gatehouse always evaluates a base
permit alongside your policies. Write forbid rules; an
organization with no policies is never blocked by the engine merely
being switched on.
New upstream
A new upstream starts in shadow. Its verdict is recorded and never binding, which is how you find out what enforcing it would cost before it costs anything.
What the upstreams answered
last 24 hoursNo forwarded verdicts recorded yet.
Directory provisioning
Provisioning calls
most recent first · bodies are never stored| When | Call | Status | Took |
|---|
Nothing has arrived yet. Once your IdP runs its first sync, every call it makes appears here.
Runtime
set at startupAnalysis layer
Gatehouse's own model usage
| Task | Calls | Input | Cached | Output | Avg latency |
|---|
No analysis calls in the last 24 hours.
Hot-topics digest
Rendered by exactly the code that posts, so this is what the channel gets. Cadence and timing live under Settings → Notifications.
Loading…