C1 TRANSFORM: A conference for leaders building the agentic enterprise

Introducing C1 LLM Gateway: Your models, your routing policy

Connect applications and agents to approved models through one endpoint, with identity, policy, and usage context attached.

Share

Introducing C1 LLM Gateway: Your models, your routing policy

An AI application’s choice of model is also a decision about where a request goes, which provider handles it, and who pays for the work. As teams add models and providers, those decisions become harder to manage across individual application integrations.

Day 4 of Launch Week introduces C1 LLM Gateway: one policy-controlled endpoint for routing inference across supported public, private, and customer-controlled model deployments.

C1 LLM Gateway brings provider choice under company policy. Teams can define which routes a workload is eligible to use, select among those approved options, and retain the context needed to understand usage and cost.

A workload hits its monthly spend limit, its call is denied, then a lower-cost route resolves the block.

Put policy into the routing decision#

Different workloads have different requirements. A request involving sensitive business information may need a private deployment. Another workflow may be allowed to use an approved public provider. Even within an approved set of models, task requirements and cost can influence the right choice.

C1 LLM Gateway ties requests to the person, application, workload, or agent using the endpoint. Configured rules determine eligible routes based on factors such as provider, model, deployment, region, and data-handling requirements. Within that eligible set, supported capability, health, latency, and cost signals help determine the route.

For example, a team could configure a supported workflow to use a private model endpoint when its data-handling requirements demand that path, while allowing another workflow to use an approved public provider. The routing decision follows the configured policy and available request context.

A single traffic event showing the resolved policy decision for a call routed to claude-opus-5-5: the listener, principal, and destination, the ALLOW verdict and its policy reason, the attributed user, and the call's cost and token usage
A single call's resolved policy decision — allowed, attributed to its user, and priced by token usage.

Keep provider choice outside application code#

Changing a model provider should not require rebuilding every application integration.

With C1 LLM Gateway, applications use one C1 endpoint across the providers and deployments supported in their configured scope. Teams can move an approved workload to another supported route while preserving the application’s gateway integration.

Supported managed credential paths also help keep durable provider secrets out of application code. Teams can expand their approved routing options without embedding a separate provider credential for every route.

Make inference spend attributable#

A provider bill can tell you what was consumed. Understanding which team, application, or agent drove that consumption requires context.

C1 LLM Gateway retains identity and workload context so usage and cost can be attributed to the responsible owner, project, or business unit. Reporting brings together usage across approved providers, models, and deployments, giving teams a shared view of where inference spend originates.

A spend breakdown grouped by app, showing the highest-spending applications over the last 30 days as a bar chart, with a details table of calls, input/output/cached tokens, and cost per million tokens for each
Spend broken down by app, department, person, or model, with cost per million tokens.

Routing policy also gives teams a way to consider cost alongside workload requirements. Among eligible routes, teams can use supported selection signals to direct work to an approved model suited to the task and its price requirements.

Connect inference to your governance foundation#

C1 LLM Gateway uses the C1 Platform’s identity and policy foundation to govern inference routing. C1 MCP Gateway applies that foundation to supported MCP, tool, and API actions. Together, they address distinct decisions in an agent workflow: where inference runs and what actions the agent can take.

Your team owns the models and inference deployments. C1 governs the supported routes applications use to reach them.

Day 4 brings that control to the model layer: an accountable caller, an approved route, and usage context teams can act on.

Book a demo to explore C1 LLM Gateway for your applications and agents.

Ask AI to write a summary of this post

Stay in touch

The best way to keep up with identity security tips, guides, and industry best practices.