Backflipt logo, agentic AI governance by Backflipt LumenBackflipt

Lumen A2A Gateway: See Every Agent. Decide What It Reaches.

AI agents are arriving from every platform you own, and they talk to each other and to your applications directly. The Lumen A2A Gateway is the control point for that traffic: the calls agents make to the A2A agents and MCP servers that front your enterprise applications. It discovers the agents and the resources they call, scores their risk, contains them in PeerGroups, and applies Smart Policies that monitor and control the intent of every interaction, with a full log of every transaction and access decision. Inline on your existing network, in your VPC.

WHO THIS PAGE IS FOR

Four Questions, One Gateway

CISO

"How many agents are running, and what did they do last night?"

Discovery finds every agent and ranks it by risk. The interaction and access logs answer the second question: every approval and denial, with the PeerGroup requirement and Smart Policy that decided it.

CIO

"Every platform shipped its own agents. Where is my record of what they transact?"

One gateway federates the native governance of every platform, applies one policy model, and writes one log of the agent transactions crossing your network.

Chief AI Officer

"How do I scale agent adoption without a security incident ending the program?"

PeerGroups give every new agent a contained, approved path to the resources it needs. Adoption speeds up because containment is the default.

Application Owner

"Which agents are touching my application, and what are they doing to it?"

Only agents in your application's PeerGroup can reach it, every interaction is checked against declared intent, and the log shows you exactly who did what.

The Challenge

Agents Talk Below Your Controls

An AI agent is a new kind of worker. It holds credentials, calls applications, delegates to other agents, and never sleeps. Most enterprises are onboarding hundreds of them without an interview, a badge, or a manager.

The traffic is the blind spot. Agents speak to each other over the A2A Protocol and reach applications through MCP servers. Your firewall sees the packets but not the participants. Your identity stack sees a service account, not the agent behind it, and certainly not its purpose. Shadow agents, spun up by a business team on a SaaS platform, never appear in any inventory at all.

And nothing writes a log. When the CISO asks what agent transactions crossed the network last night, or the CIO asks which agents touched the ERP, there is no record to pull. Existing controls were built for people and for machines that do one thing forever. Agentic AI is neither. The conversation between agents and your enterprise resources needs its own control point, and its own log.

How It Works

Discover. Score. Contain. Check.

Four controls, applied in order, turn an unknown agent population into a governed one. The same sequence works whether you have twelve agents or twelve hundred.

1

Discover

The gateway finds the AI agents operating in your environment and the enterprise resources they call: the A2A agents and MCP servers that front your applications. Shadow agents nobody registered come into view.

2

Score

Every discovered agent and resource gets a risk score based on what it can reach and how it behaves. The ranked inventory tells you what to address first.

3

Contain

Administrators assign approved agents and resources into PeerGroups. Only agents inside a PeerGroup reach the resources assigned to it. Everything else is blocked at the boundary and logged.

4

Check

Smart Policies attached to each PeerGroup map the agent's declared purpose to allowed operations, then monitor and control intent on every interaction, inline, as it happens.

Core Capabilities

What the Gateway Does

Agent and Resource Discovery

Finds the AI agents in your environment and the resources they call: the A2A agents and MCP servers that front your enterprise applications. Shadow agents come into view without anyone registering them.

Risk Scoring

Every discovered agent and resource is ranked by exposure and behavior. Remediation starts with the score of 92, not an alphabetical list.

PeerGroups

Microsegmentation at the agent layer. Only approved agents inside a PeerGroup reach the resources assigned to it. Everything else stops at the boundary.

Smart Policies: The PDP and PEP for Intent

The gateway is the policy decision point and enforcement point for intent in A2A and agent-to-MCP conversations. Smart Policies, applied per PeerGroup, map declared purpose to allowed operations and decide and enforce every interaction inline.

Inline Inspection on Your Network

A2A and agent-to-MCP traffic is inspected in the path, riding the networking and proxy infrastructure you already run over ICAP (RFC 3507). No forklift, no new appliances.

Admin Console and Approvals

Human oversight stays in the loop. Approve discovered agents, assign PeerGroups, watch live traffic, and review violations from one console.

Interaction and Access Logging

A detailed log of every interaction, plus PeerGroup-driven access logs: each approval and denial recorded with the PeerGroup requirement that applied and the Smart Policy that evaluated intent. External AI firewall verdicts, such as Lakera and CalypsoAI, join the same trail.

Agent Identity: SPIFFE, Attestation, and mTLS

Works with SPIFFE-driven workload identity infrastructure to register and identify agents by their SVIDs. No SPIFFE yet? Built-in AI agent and MCP server registration with cryptographic attestation. Either way, every session with the gateway runs over mTLS with clear identification.

Federated IAM for Agents

AI agents rarely exist in your IdP. The gateway authenticates and authorizes registered agents and issues bearer tokens in line with enterprise security policy, interoperating with Microsoft Entra agent identity blueprints and RFC-based OAuth deployments on Okta.

Lumen SDK and Open Standards

Built on the A2A Protocol and MCP. A lightweight SDK in Python, Node.js, and Java lets teams publish, discover, and invoke agent skills through the gateway.

Smart Policies

Intent Control That Keeps Up With Your Agents

An agent is not a static thing. It acquires skills. Every new tool it can reach widens what it can do, and every model upgrade changes how it reasons about doing it. The agent you approved in March is not the agent running in September, even if nobody touched a line of its code.

The industry has converged on the same conclusion. The OWASP agentic AI risk list puts intent breaking and goal manipulation, tool misuse, and rogue agents drifting from their objectives near the top, and its guidance is to re-validate intent before high-impact actions and monitor continuously for goal drift. Researchers call the underlying problem a capability-intent mismatch: the agent's tool access outgrows its purpose. Notice what these have in common. The credential was valid every time. Identity alone never catches it.

Smart Policies attach to PeerGroups and do two jobs.They monitor intent: observed behavior is compared continuously against the agent's declared purpose, so drift shows up as data in the decision log, not as an incident. And they control intent: when an agent picks up a new tool, learns a new skill, or starts running on a more capable LLM, the Smart Policy holds its intent envelope steady. New capability does not silently become new permission. The interaction either stays within declared purpose, or it stops and escalates to a human before it executes.

Clear Lines

Where the Gateway Ends and the Broker Begins

Two decision points govern every agent interaction, and each has its own PDP and PEP. For intent, the A2A Gateway decides and enforces: which agents may talk to which resources, and whether each A2A or agent-to-MCP conversation matches declared purpose, per PeerGroup Smart Policy. For credentials, the Lumen POET Credential Broker decides and enforces: which role, which user, which group, for how long. They deploy together or separately, and neither pretends to do the other's job.

Lumen A2A Gateway

  • Discovery with risk scoresFinds AI agents and the enterprise resources they call, and ranks both by risk.
  • PeerGroupsOnly approved agents reach the resources assigned to their group. Agent-layer microsegmentation.
  • PDP and PEP for intentSmart Policies on each PeerGroup decide and enforce intent in A2A and agent-to-MCP conversations: declared purpose mapped to allowed operations, monitored for drift, controlled inline.
  • Inline inspectionA2A and agent-to-MCP traffic inspected on your existing network over ICAP.
  • Agent identity and loggingSPIFFE or attestation-based registration with mTLS, federated IAM with bearer tokens, and full interaction and access logs.

The gateway holds the PDP and PEP for intent. Credential and role decisions have their own PDP and PEP in the broker. Clean separation, on purpose.

Lumen POET Credential Broker

  • PDP and PEP for credentialsThe policy decision point and enforcement point for credential and role decisions: role, user, and group.
  • Just-in-time tokensTime-bound and workload-bound tokens issued at the moment of action. Zero standing privileges as the default.
  • Vault-anchoredStanding credentials never leave your PAM vault. Agents carry nothing permanent.
  • Integrated MCP layer Policy management through a built-in MCP layer, alongside no-code MCP server and A2A agent generation by Lumen POET.

Explore Lumen POET for the full credential story.

Policy Framework

One Policy Model for the Agent Layer

This is AI security done as policy, not as alerts: MCP security, A2A agent security, and NHI governance expressed as rules the gateway enforces. Policies apply globally and per agent, across every connected platform, in four families.

Security Policies

Who may talk to whom, and about what. PeerGroup membership, intent boundaries, and inline inspection protect agent identities and interactions across platforms, so an agent compromised on one platform cannot wander into another.

Compliance and Privacy Policies

Data handling rules ride the same inspection path: automatic redaction and DLP checks on agent traffic, with per-agent rules for regulated workloads. The decision log becomes the evidence your auditors ask for.

Business and Risk Policies

Routine agent decisions proceed on their own. High-stakes scenarios escalate to a human based on global triggers and per-agent thresholds, so autonomy grows without risk tolerance being decided by accident.

Operational Assurance Policies

Quality gates, continuous monitoring, and consistency checks keep a growing agent population reliable. Smart Policies surface intent drift as data in the decision log, so you see an agent leaving its lane before your customers do.

Native Integrations

Every Platform's Agents, One Governance Model

Connectors pull agent metadata from the platforms where your agents already live. The gateway federates each platform's native governance and applies one policy model across all of them, without vendor lock-in.

Salesforce Agentforce & AgentExchange
ServiceNow AI Agent Orchestrator
Snowflake Cortex Agents
Microsoft Azure AI Foundry Agent Service
Google Cloud Vertex AI Agent Engine
AWS Bedrock Agents
Atlassian Rovo & Jira Service Management
Zendesk AI Agents
Deployment

Your VPC, Your Network, Your Scale

Run It Where You Want

Managed cloud service or self-hosted on Kubernetes in your own VPC. Cloud-agnostic by design, and it scales to thousands of agents per tenant.

No Forklift

Inline inspection rides the networking and proxy infrastructure you already operate, over industry-standard ICAP (RFC 3507). Your network team keeps their tools and their runbooks.

Built for Your Compliance Program

Discovery inventories, intent policies, and immutable decision logs map to the evidence expected by programs aligned to the EU AI Act, NIST AI RMF, GDPR, CCPA, and ISO/IEC 42001.

Why It Pays Off

The Case in Four Cards

Business

Agent adoption speeds up because every new agent has a governed path on day one. Teams stop waiting on one-off security reviews.

Security

Shadow agents become visible, scored, and contained. Anything outside a PeerGroup is blocked at the boundary and logged, not discovered in a postmortem.

ROI

One gateway replaces a per-platform governance build for every agent platform you adopt. The connector does the work your team would otherwise repeat eight times.

No Forklift

Existing network infrastructure carries the inspection over ICAP. No agent rewrites, no new appliances, no re-architecture project before value shows up.

Features at a Glance

The Full Feature List, One Table

FeatureWhat It DoesWhy It Matters
Agent and Resource DiscoveryFinds the AI agents in your environment and the A2A agents and MCP servers they call, including shadow agents nobody registered.You cannot govern what you cannot see.
Risk ScoringRanks every discovered agent and resource by exposure and behavior in a live inventory.Remediation starts where risk is highest.
PeerGroupsAgent-layer microsegmentation: only approved agents inside a PeerGroup reach the resources assigned to it.Containment is the default; the blast radius is bounded before anything goes wrong.
Smart Policies (PDP and PEP for Intent)Decides and enforces intent per interaction in A2A and agent-to-MCP conversations, applied per PeerGroup, with drift monitoring.New capability never silently becomes new permission.
Inline InspectionInspects agent traffic in the path, riding your existing networking and proxy infrastructure over ICAP.No forklift, no new appliances, no agent rewrites.
Agent IdentityRegisters and identifies agents through SPIFFE-driven infrastructure (SVIDs), or through built-in AI agent and MCP server registration with cryptographic attestation. All gateway sessions run over mTLS.Every agent is clearly identified before it says a word.
Federated IAM for AgentsAuthenticates and authorizes agents that never appear in your IdP, issuing bearer tokens in line with enterprise security policy.Agents become first-class IAM citizens without rebuilding your identity stack.
Interaction and Access LoggingLogs every interaction in detail, and every PeerGroup access decision: approvals and denials with the PeerGroup requirement that applied.The answer when the CISO asks what agent transactions crossed the network last night.
Admin Console and ApprovalsApprove discovered agents, assign PeerGroups, watch live traffic, and review violations from one console.Human oversight stays in the loop as the population grows.
SDK and Open StandardsBuilt on the A2A Protocol and MCP, with a lightweight SDK in Python, Node.js, and Java.Build on standards. No vendor lock-in.
FAQ

Questions We Hear Most

Ready to See Your Agent Population?

Start with a discovery run in your environment. Most teams learn something in the first hour, usually about an agent nobody knew they had.

Also see: Lumen Solutions, the deployment playbook·Trust No Agent, the joint solution with IBM and Fortinet

Topics: #Backflipt · #LumenA2AGateway · #A2AGateway · #AgenticAI · #AIAgents · #AISecurity · #AIAgentSecurity · #AgenticAISecurity · #MCPServerSecurity · #NHIGovernance · #AIPolicies · #AIGovernance · #ZeroTrust · #ZTNA · #MCP · #MCPSecurity · #A2A · #AgentDiscovery · #PeerGroups · #IntentChecking · #SmartPolicies · #GoalDrift · #ShadowAI · #NonHumanIdentity · #NHI · #WorkloadIdentity · #WorkloadIAM · #MachineIdentity · #RuntimeAuthorization · #SPIFFE · #mTLS · #FederatedIAM · #AuditLogs · #ICAP · #EnterpriseAI · #AgentReady · #CyberSecurity