| Agentless network routing | Organization-wide coverage through a firewall, SASE platform, or secure web gateway | Supported AI traffic is routed automatically; users keep using their existing applications and workflows | Content-aware policy through the LLM and MCP Gateways, session evidence, and centralized control |
| Native network enforcement | Broad allow and block controls at the network edge | Traffic stays on its existing network path | Policies compiled to the network platform, plus inventory and access evidence |
| Forge on managed devices | Off-network devices, local applications, and endpoint attribution | Supported traffic is routed automatically from enrolled Windows and macOS devices | Gateway enforcement, device health, local AI inventory, and Fleet operations |
| Explicit gateways | Developer APIs, services, and MCP clients that can be configured directly | Applications use an organization gateway endpoint | Central credentials, model and tool access, budgets, policy, and observability |