Design-Partner Pilot
Design-Partner Pilot
Section titled “Design-Partner Pilot”A good pilot proves one governed capability. It should not turn V1 into a broad agent platform, LLM gateway, plugin marketplace, managed MCP host, Terraform/operator project, or full DLP product.
Audience
Section titled “Audience”- Design partners evaluating fit.
- Security and platform buyers scoping a first proof.
- DAC operators preparing a pilot plan without publishing private GTM material.
What is this?
Section titled “What is this?”This page is the public pilot framing. The design-partner path proves that one approved public target in managed mode, or one private target in self-hosted mode, can move through policy-filtered discovery, credential-safe routing, metadata-only audit, revocation, and deployment evidence.
When do I use it?
Section titled “When do I use it?”Use it after a buyer can name:
- one concrete private MCP server or API source;
- allowed and denied access cases;
- a non-production identity model or accepted simulation;
- a credential binding reference or accepted mock;
- audit/export expectations;
- a deployment posture to review.
What happens?
Section titled “What happens?”The public pilot frame tracks:
| Track | Early proof | Closeout proof |
|---|---|---|
| Capability | One private MCP server or API source. | One governed capability and one denied or hidden capability. |
| Identity | Non-production actor context or accepted simulation. | Buyer-approved identity model for the pilot surface. |
| Policy | One allow rule and one deny rule. | Versioned policy and simulation output accepted by security. |
| Credentials | Binding reference or accepted mock. | Secret-store integration path or customer-approved opaque handle model. |
| Routing | Direct private endpoint or connector-mode route. | Route health, disable, and revoke behavior accepted. |
| Audit | Local metadata-only audit proof. | SIEM/export path or accepted artifact. |
| Deployment | Helm render or sandbox install path. | Managed or self-hosted checklist completed. |
The demo path should show inventory, policy-filtered discovery, governed MCP call, selected API-to-MCP import, credential routing, session revoke, audit/export, and managed or self-hosted readiness.
What can go wrong?
Section titled “What can go wrong?”- The pilot tries to cover too many capabilities before one governed path works.
- The customer needs production data migration, certified air-gapped packaging, local STDIO governance, managed MCP hosting, Kubernetes operator, Terraform module, ClickHouse, NATS, Kafka, Redpanda, full DLP, or prompt-injection detection. Those are outside the V1 pilot unless separately agreed and sourced.
- Security cannot accept metadata-only evidence. That blocks the pilot because retained artifacts cannot contain raw payloads or secret material.
- A public page exposes private account research, direct outreach copy, commercial terms, partner-specific content, or unreviewed claims. Keep that material out of public docs.
Source truth
Section titled “Source truth”- Read What Is Enterprise MCP Gateway? for product boundary.
- Read Quickstart for local proof before pilot scoping.
- Read Managed And Self-Hosted for deployment expectations.
Type set in Geist, Source Serif 4, and Departure Mono.