Blog The gateway 8 min read

One door for every tool.

Letting each team wire its own AI connections is the fastest way to start and the fastest way to lose the plot. The fix is boring, structural, and worth more than any individual integration.

The short version
  • Modern AI apps connect to your real systems (CRM, docs, tickets, finance) through connectors. Left alone, every team wires its own, to its own apps, with its own credentials.
  • That produces a mesh nobody can see: no usage, no cost, no access control, no audit, and no warning when a vendor changes a tool underneath you.
  • Capi puts one gateway in the middle. Every AI request for a tool or a capability goes through it.
  • Because there is one door, every request can be attributed, permitted, measured, and recorded, once, instead of thirteen times badly.
  • The gateway serves a frozen snapshot of each connector's tools. When the vendor changes theirs, that arrives as a reviewable change, not as behavior that silently shifts.
  • And the traffic through the door is the raw material for everything else: what people actually do with AI, and what they tried to do and could not.

How the mesh happens

Nobody decides to build a mess. It accumulates, and every single step is reasonable.

Sales connects their AI assistant to the CRM, because a rep asked and it took an afternoon. Support connects theirs to the ticketing system. Finance connects a different AI app to the data warehouse, using a service account somebody created in 2024. Marketing installs three connectors from a directory without telling anyone, because installing them required telling no one.

Six months in, you have five AI apps talking to nine internal systems through roughly forty separate wires, and the following questions have no answer:

  • Which systems can our AI tools reach, in total?
  • Who used which one, on whose behalf, and for what?
  • What is this costing us, per team?
  • If someone leaves today, what did we just fail to revoke?
  • When a vendor renamed a tool last Tuesday, what broke?

These are not AI questions. They are the questions any auditor asks about any system that touches customer data, and right now the honest answer is a shrug.

TEAM BY TEAM: A MESH AI apps Your systems Sales AI Support AI Finance AI Marketing Side project CRM Tickets Docs Warehouse Payroll Calendar ~40 wires, 5 credential stores no usage, no cost, no audit permissions live in 9 vendor consoles a vendor change lands with no warning ONE DOOR: A GATEWAY Sales AI Support AI Finance AI Marketing Anything new Capi gateway CRM Tickets Docs Warehouse Payroll Calendar one place to connect, one to revoke every request attributed and costed access rules enforced at the door vendor changes arrive as a review
Same apps, same systems, one structural difference. The right hand picture is not more capable than the left. It is the same capability, with a place to stand.

You cannot govern what has no chokepoint. Everything else is a dashboard built on guesses.

What a single request carries when it passes through a door

This is the part that sounds like plumbing and is actually the asset. When an AI app asks to create a page, pull a record, or read one of your approved capabilities, that request goes through the gateway. Which means the gateway can do six things at once, per request, for free.

It knows who is asking, because the request is authenticated to a real person rather than a shared service account. It knows which app they were in. It knows which capability they were following, if any. It checks whether that person is allowed to reach that system. It records the call, and it records what it cost.

And it keeps the request itself as evidence, which is the seed of the learning loop: the gateway sees how work actually gets done, not how a policy document says it should.

ONE REQUEST, PASSING THROUGH Dana, in an AI app “log the call I just had with Acme” Capi gateway the only way through CRM create activity record WHAT GETS WRITTEN DOWN, AUTOMATICALLY PERSON Dana Okafor Sales, EMEA APP Claude Desktop so you can compare apps CAPABILITY FOLLOWED Customer call brief v3.1 an approved way of working PERMISSION allowed checked here, not in the CRM TOOL CALLED crm.create_activity from the frozen toolset OUTCOME succeeded failures are counted too COST AND LATENCY attributed to Sales per team, per capability AND THEN kept as evidence this is how the loop learns
The ledger writes itself. None of these fields require anyone to fill in a form. They are a side effect of there being exactly one path.

The problem nobody sees coming: the vendor moves first

Here is a failure that only exists in the AI era. Your team builds a workflow on top of a connector. That connector belongs to a vendor. On a Tuesday, the vendor ships an update: two tools renamed, one removed, one that now takes different inputs.

With direct connections, your AI apps pick that up immediately. The workflow keeps running. It does not error. It just quietly starts doing something slightly different, built on assumptions that no longer hold. The same four days of slightly wrong as in the versioning note, with a cause that originated outside your company.

The gateway serves each connector as a frozen snapshot of its tools, taken at the moment you approved it. Your agents keep seeing exactly that. The gateway also keeps checking upstream, and when it sees the vendor has changed something, it files a change for review, listing exactly which tools moved and which of your capabilities depend on them.

Nothing changes for your teams until a human says yes. That is the entire difference between an integration and a governed integration.

WITHOUT A DOOR Vendor ships 2 tools renamed, 1 removed instantly Your agents see the new tools the same afternoon Behavior shifts, silently No error. No alert. Your workflow is now built on assumptions that no longer hold. WITH ONE DOOR Vendor ships the same change, on the same Tuesday Gateway notices compares upstream to the approved snapshot A change to review 2 renamed, 1 removed 3 of your capabilities depend on them You decide then it ships Meanwhile, all week: your agents keep using the frozen toolset and keep working. The vendor's release schedule stops being your incident schedule.
Drift becomes a decision. Your suppliers ship on their calendar. A gateway is what turns their calendar into your inbox instead of your outage.

Questions only a chokepoint can answer

Once every request goes through one place, a set of questions that used to require a consulting engagement becomes a page you look at on a Monday. Not because the reporting is clever, but because the data exists at all.

Two of these are worth calling out, because they are the ones nobody expects.

Ungoverned use. The gateway can see a system that half the company is reaching for, through connections nobody ever formally approved. That is not a violation to punish. It is a capability the org clearly needs and has not yet decided to own.

Searches that found nothing. Every time someone asks the library for an approved way to do something and it comes back empty, that miss gets recorded. A list of misses is a list of the capabilities your company should build next, written by the people who needed them.

WHAT BECOMES ANSWERABLE ON A MONDAY MORNING ADOPTION Which approved ways of working get used 412 248 61 SPEND What AI actually costs, per team Sales£4,210 Support£2,860 Finance£940 REACH Every system our AI can touch, in one list 9 systems, 61 tools 4 of them can write all revocable in one place RELIABILITY Which connections keep failing Warehouse7.4% failed Tickets0.9% failed and who was blocked by it UNGOVERNED USE A system half the company reaches for, that nobody ever approved Not a violation to punish. A capability you should own. SEARCHES THAT FOUND NOTHING “renewal risk review” “security questionnaire” “pricing exception” Your roadmap for what to build next, from the people who needed it.
The bottom two are the interesting ones. Anyone can build an adoption chart. Only a chokepoint can tell you what your company tried to do with AI and could not.

The exhaust from the gateway is the fuel for everything upstream of it.

Why the door is worth more than the integrations

An integration is worth a bit of time saved. A door is worth a category of decisions you can suddenly make.

Every request that passes through it is evidence of how work really gets done here. That evidence is what lets Capi notice a pattern three people repeat every week and turn it into a reviewed capability. It is what lets the system tell you a published guideline is being ignored. It is what makes the adoption numbers real instead of self reported.

The uncomfortable part

Consolidating on one door is a week of unglamorous work, and it competes with a demo that could ship on Friday. Almost every company chooses the demo, twice, before choosing the door.

The teams that choose the door early are the ones that can still answer questions about their AI eighteen months later.

Put one door in front of your AI.

We are opening a small founding design partner cohort, limited by how much hands on onboarding we can give each team.