Supported protocols
See Protocols for client behavior and explicit
limits.
Two access paths
Both paths use the same Resource definition, identity resolution, destination credential, Resource Policies, approval grants, and activity records.
Automatic routing changes the network path before a connection opens. Forge
cannot govern one SQL command on a database connection that otherwise bypasses
Forge; the entire connection must first use one of these paths.
How the pieces fit
- A Resource defines the protocol and destination.
- A Resource gateway runs in a customer network that can reach it.
- A credential assignment determines how Forge authenticates upstream for the caller.
- A Resource Policy evaluates the connection and each supported operation.
- Live → Resources records safe evidence and policy outcomes.
- Responses handles approval requests, decisions, and short-lived grants.