pip install. The Gateway needs a base URL you can
change. The egress node needs neither, which makes it the answer to the
two workloads every security team eventually finds: the Go binary
nobody documented, and the vendor container you cannot open.
It is a forward proxy you run on your own network. Point a workload at
it with the environment variables it already understands and every
model call it makes shows up in EgisAI.
Setting one up
Mint a workload token under Connect → Egress, then run the container on the network your agents already use:Two modes
Observe is the default and the mode to leave it in for a while. It tunnels every connection without opening it, and reports the destination only. That turns “4,000 connections to 172.64.x.x” into “this workload is talking to Anthropic” without the node ever being able to read a request. Rows written in observe mode carryenforcement_status = "advisory"
and inspection = "metadata_only", because a node that never opened
the tunnel did not gate anything and could not have read anything.
Enforce lets the node refuse a call that breaks a policy. To do
that it has to read what was sent, so it terminates TLS — for model
vendors only. Everything else your workloads talk to stays a tunnel
it cannot see into.
What enforce mode requires
The node generates its own certificate authority on first start. The private key is written with0600 permissions and never leaves the
node — not to us, not to another node in the same fleet.
Workloads have to trust that CA before they can talk to a model vendor
through an enforcing node. A workload that doesn’t will fail its
handshake to those vendors rather than quietly going ungoverned, and
the errors show up on the Egress page.
The dashboard shows the CA’s SHA-256 fingerprint next to each node.
Check it against the node itself before you distribute anything:
Streaming
When no response-phase policy is active the node streams the response straight through, so first-token latency is unchanged. When one is, the response is buffered, evaluated, and then released or refused — which is the only way a response policy can mean anything, and is the reason to keep response-phase rules narrow.Running the SDK and a node together
They co-exist without double-governing. The SDK stampsX-Egis-Decision: governed on requests it has already evaluated, and
the node skips those — one call, one audit row, whichever control saw
it first.
Failure posture
Fail open, loudly. If the node cannot reach the control plane it keeps forwarding traffic and queues what it saw; if it cannot evaluate a policy it forwards rather than refusing. A governance product that takes a customer’s product down when our backend has a bad day is not a governance product anybody keeps. The one exception is the handshake in enforce mode, which fails closed by construction: a workload that does not trust the node’s CA cannot reach the vendor at all.What’s next
Coverage
Where this fits among the five surfaces.
Gateway
The in-line alternative when you can change a base URL.