# What an Agentic Control Plane is not

An ACP is not an LLM gateway, not an agent framework, not a traditional API gateway, and not an enterprise agent platform. Here's how it fits in your stack.

<div class="acp-section">
  <div class="acp-container">
    <div class="acp-card acp-card-pad" style="text-align:center;padding:48px 32px;">
      <h1 class="acp-hero-h1">What an ACP is not</h1>
      <p class="acp-subtitle" style="max-width:640px;margin:16px auto 0;">
        An Agentic Control Plane occupies a distinct layer in the AI stack. It complements — not replaces — your existing infrastructure.
      </p>
    </div>
  </div>
</div>

<!-- Not an LLM gateway -->
<div class="acp-section">
  <div class="acp-container">
    <div class="acp-card acp-card-pad">
      <h2 class="acp-section-title">Not an LLM routing gateway</h2>
      <p class="acp-muted" style="max-width:680px;">
        Tools like Portkey, LiteLLM, and OpenRouter focus on <strong>model selection and load balancing</strong> — routing prompts to the cheapest or fastest LLM provider.
      </p>
      <p class="acp-linkcard-desc" style="margin-top:12px;">
        An ACP doesn't choose which model to use. It sits between the LLM and your backend to enforce <strong>who</strong> can use it, <strong>what</strong> they're allowed to do, and <strong>whether</strong> the request complies with your policies. LLM gateways optimize cost and latency. An ACP enforces trust and control.
      </p>
      <p class="acp-linkcard-desc" style="margin-top:8px;">
        <strong>Use both:</strong> Route through your LLM gateway for model selection, then through your ACP for identity, policy, and audit.
      </p>
    </div>
  </div>
</div>

<!-- Not an agent framework -->
<div class="acp-section">
  <div class="acp-container">
    <div class="acp-card acp-card-pad">
      <h2 class="acp-section-title">Not an agent framework</h2>
      <p class="acp-muted" style="max-width:680px;">
        LangChain, CrewAI, AutoGen, and similar frameworks help you <strong>build</strong> agents — defining tool chains, memory, reasoning loops, and orchestration.
      </p>
      <p class="acp-linkcard-desc" style="margin-top:12px;">
        An ACP doesn't build agents. It <strong>governs</strong> them. When your LangChain agent calls a tool, the ACP verifies the user's identity, checks authorization policies, enforces rate limits, and logs the action. The agent framework decides <em>what</em> to do. The ACP decides <em>whether it's allowed</em>.
      </p>
      <p class="acp-linkcard-desc" style="margin-top:8px;">
        <strong>Use both:</strong> Build your agent with any framework. Route its tool calls through your ACP for control.
      </p>
    </div>
  </div>
</div>

<!-- Not a traditional API gateway -->
<div class="acp-section">
  <div class="acp-container">
    <div class="acp-card acp-card-pad">
      <h2 class="acp-section-title">Not a traditional API gateway</h2>
      <p class="acp-muted" style="max-width:680px;">
        Kong, Apigee, and AWS API Gateway handle <strong>HTTP traffic management</strong> — routing, rate limiting, TLS termination, and basic auth.
      </p>
      <p class="acp-linkcard-desc" style="margin-top:12px;">
        Traditional API gateways don't understand the three-party problem. They can verify a token, but they can't bind LLM-forwarded requests to the originating user. They can rate-limit by IP, but not by verified user identity. They can log requests, but not attribute AI actions to specific people with policy context.
      </p>
      <p class="acp-linkcard-desc" style="margin-top:8px;">
        <strong>Use both:</strong> Your API gateway handles TLS, global rate limits, and routing. Your ACP handles identity binding, per-user policies, and AI-specific control.
      </p>
    </div>
  </div>
</div>

<!-- Not a sandbox -->
<div class="acp-section">
  <div class="acp-container">
    <div class="acp-card acp-card-pad">
      <h2 class="acp-section-title">Not a sandbox</h2>
      <p class="acp-muted" style="max-width:680px;">
        Sandboxes — Docker and gVisor, micro-VMs, cloud execution environments, and the sandboxes built into coding harnesses — contain <strong>where agent code runs</strong>: an OS boundary around files, processes, and network on one host.
      </p>
      <p class="acp-linkcard-desc" style="margin-top:12px;">
        A sandbox has no opinion about actions made with valid credentials through legitimate channels. The agent that merges the wrong PR, emails the wrong customer, or deletes cloud resources with your own key does all of it through channels the sandbox correctly lets through. An ACP sits at the tool-call and model-call seam and decides each action by policy — allow, ask, or deny — with the decision logged and the cost metered.
      </p>
      <p class="acp-linkcard-desc" style="margin-top:8px;">
        <strong>Use both:</strong> the sandbox bounds the unauthorized — exploits, runaway code, filesystem blast radius. The ACP decides the authorized. Run the agent inside whatever sandbox you like, with the control plane in its call path. <a href="/blog/sandboxes-and-control-planes">Why they compose &rarr;</a>
      </p>
    </div>
  </div>
</div>

<!-- Not an identity provider -->
<div class="acp-section">
  <div class="acp-container">
    <div class="acp-card acp-card-pad">
      <h2 class="acp-section-title">Not an identity provider</h2>
      <p class="acp-muted" style="max-width:680px;">
        Okta, Auth0, and Entra now issue <strong>identities and credentials to AI agents</strong> — agent SSO, short-lived scoped tokens brokered at connection time, discovery and revocation of agents across the enterprise.
      </p>
      <p class="acp-linkcard-desc" style="margin-top:12px;">
        That layer decides whether an agent should <em>hold a credential</em>. It never sees the tool call the credential is used for — a routine update and a prompt-injected destructive write carry the same valid token, in the same granted scope. An ACP sits one layer later, on the runtime call path, and decides each action by policy — allow, ask, or deny, on the tool and its arguments — with the decision logged. Its audit trail records actions, not authentications.
      </p>
      <p class="acp-linkcard-desc" style="margin-top:8px;">
        <strong>Use both:</strong> Your IdP establishes who the agent is; that identity flows into the ACP as the verified principal on every call. One issues the badge, the other watches the hands. <a href="/identity-plane-vs-control-plane">Where the identity plane ends &rarr;</a>
      </p>
    </div>
  </div>
</div>

<!-- Governance beyond one vendor -->
<div class="acp-section">
  <div class="acp-container">
    <div class="acp-card acp-card-pad">
      <h2 class="acp-section-title">Control that works across every model</h2>
      <p class="acp-muted" style="max-width:680px;">
        Some platforms bundle control into a single model provider's ecosystem — identity, policy, and audit that only work with their models.
      </p>
      <p class="acp-linkcard-desc" style="margin-top:12px;">
        An ACP gives you one control layer for <em>all</em> of them — OpenAI, Anthropic, Google, Mistral, open-source, or your own fine-tune. Same identity binding, same policies, same audit trails, regardless of which model is behind the agent. Deploy in minutes, not months, with no vendor-specific deployment team required.
      </p>
      <p class="acp-linkcard-desc" style="margin-top:8px;">
        <strong>Why it matters:</strong> Your team already uses multiple models. Your control shouldn't break when you add another one.
      </p>
    </div>
  </div>
</div>

<!-- DIY vs purpose-built -->
<div class="acp-section">
  <div class="acp-container">
    <div class="acp-card acp-card-pad">
      <h2 class="acp-section-title">DIY OAuth vs. purpose-built control plane</h2>
      <p class="acp-muted" style="max-width:680px;">
        You can build identity and control yourself. Here's what that looks like compared to using your IdP's built-in features or adopting an Agentic Control Plane.
      </p>
      <div class="acp-table-wrap">
        <table class="acp-table">
          <thead>
            <tr>
              <th>Capability</th>
              <th>DIY (roll your own)</th>
              <th>IdP only (Auth0 Actions, etc.)</th>
              <th>Enterprise agent platform</th>
              <th>Agentic Control Plane</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td>JWT verification</td>
              <td class="acp-faint">Manual JWKS setup</td>
              <td class="acp-faint">Built-in</td>
              <td class="acp-faint">Built-in (single vendor)</td>
              <td><strong>Built-in</strong></td>
            </tr>
            <tr>
              <td>Per-tool scope enforcement</td>
              <td class="acp-faint">Custom middleware</td>
              <td class="acp-faint">Limited</td>
              <td class="acp-faint">Built-in (single vendor)</td>
              <td><strong>Declarative allowlists</strong></td>
            </tr>
            <tr>
              <td>User context injection</td>
              <td class="acp-faint">Manual header mapping</td>
              <td class="acp-faint">Not available</td>
              <td class="acp-faint">Built-in (single vendor)</td>
              <td><strong>Automatic</strong></td>
            </tr>
            <tr>
              <td>PII detection &amp; redaction</td>
              <td class="acp-faint">Not included</td>
              <td class="acp-faint">Not included</td>
              <td class="acp-faint">Varies</td>
              <td><strong>Built-in</strong> &mdash; detection on Free, redaction as a policy you enable</td>
            </tr>
            <tr>
              <td>Budget &amp; rate limiting</td>
              <td class="acp-faint">DIY Redis</td>
              <td class="acp-faint">Not included</td>
              <td class="acp-faint">Platform-scoped</td>
              <td><strong>Per-user, cost-aware</strong></td>
            </tr>
            <tr>
              <td>Audit trail</td>
              <td class="acp-faint">Custom logging</td>
              <td class="acp-faint">Auth logs only</td>
              <td class="acp-faint">Built-in (single vendor)</td>
              <td><strong>Structured, per-request</strong></td>
            </tr>
            <tr>
              <td>Time to production</td>
              <td class="acp-faint">Days to weeks</td>
              <td class="acp-faint">Hours</td>
              <td class="acp-faint">Months</td>
              <td><strong>Minutes</strong></td>
            </tr>
          </tbody>
        </table>
      </div>
    </div>
  </div>
</div>

<!-- How it fits -->
<div class="acp-section">
  <div class="acp-container">
    <h2 class="acp-section-title">How an ACP fits in your stack</h2>
    <div class="arch-diagram">
      <div class="arch-row">
        <div class="arch-node">
          <div class="arch-node-title">user</div>
          <div class="arch-node-sub">authenticates via SSO / OAuth</div>
        </div>
        <div class="arch-arrow">&rarr;</div>
        <div class="arch-node">
          <div class="arch-node-title">LLM runtime</div>
          <div class="arch-node-sub">ChatGPT, Claude, custom agent</div>
          <div class="arch-pill-row">
            <span class="arch-pill">agent framework</span>
            <span class="arch-pill">MCP / Apps SDK</span>
          </div>
        </div>
        <div class="arch-arrow">&rarr;</div>
        <div class="arch-node arch-node-gateway">
          <div class="arch-node-title" style="color:rgba(129,140,248,1);">agentic control plane</div>
          <div class="arch-node-sub">identity &middot; policy &middot; safety &middot; limits &middot; routing &middot; audit</div>
          <div class="arch-pill-row">
            <span class="arch-pill">ACP</span>
          </div>
        </div>
        <div class="arch-arrow">&rarr;</div>
        <div class="arch-node">
          <div class="arch-node-title">your backend</div>
          <div class="arch-node-sub">APIs, databases, tools</div>
          <div class="arch-pill-row">
            <span class="arch-pill">API gateway</span>
            <span class="arch-pill">LLM gateway</span>
          </div>
        </div>
      </div>
      <div class="arch-caption" style="text-align:center;">
        The ACP sits between the LLM and your backend. It complements your API gateway and agent framework.
      </div>
    </div>
  </div>
</div>

<!-- Feature comparison -->
<div class="acp-section">
  <div class="acp-container">
    <div class="acp-card acp-card-pad">
      <h2 class="acp-section-title">Feature comparison</h2>
      <div class="acp-table-wrap">
        <table class="acp-table">
          <thead>
            <tr>
              <th>Capability</th>
              <th>LLM gateway</th>
              <th>Agent framework</th>
              <th>API gateway</th>
              <th>Enterprise agent platform</th>
              <th>Agentic Control Plane</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td>Model routing &amp; fallback</td>
              <td><strong>Yes</strong></td>
              <td class="acp-faint">No</td>
              <td class="acp-faint">No</td>
              <td class="acp-faint">No</td>
              <td class="acp-faint">No</td>
            </tr>
            <tr>
              <td>Agent orchestration</td>
              <td class="acp-faint">No</td>
              <td><strong>Yes</strong></td>
              <td class="acp-faint">No</td>
              <td class="acp-faint">Single vendor only</td>
              <td class="acp-faint">No</td>
            </tr>
            <tr>
              <td>TLS &amp; global rate limiting</td>
              <td class="acp-faint">Some</td>
              <td class="acp-faint">No</td>
              <td><strong>Yes</strong></td>
              <td class="acp-faint">Platform-managed</td>
              <td class="acp-faint">No</td>
            </tr>
            <tr>
              <td>Three-party identity binding</td>
              <td class="acp-faint">No</td>
              <td class="acp-faint">No</td>
              <td class="acp-faint">No</td>
              <td class="acp-faint">Single vendor only</td>
              <td><strong>Yes</strong></td>
            </tr>
            <tr>
              <td>Per-user policy enforcement</td>
              <td class="acp-faint">No</td>
              <td class="acp-faint">No</td>
              <td class="acp-faint">Limited</td>
              <td class="acp-faint">Single vendor only</td>
              <td><strong>Yes</strong></td>
            </tr>
            <tr>
              <td>PII detection &amp; redaction</td>
              <td class="acp-faint">No</td>
              <td class="acp-faint">No</td>
              <td class="acp-faint">No</td>
              <td class="acp-faint">Varies</td>
              <td><strong>Yes</strong></td>
            </tr>
            <tr>
              <td>Per-user budget &amp; spend caps</td>
              <td class="acp-faint">No</td>
              <td class="acp-faint">No</td>
              <td class="acp-faint">No</td>
              <td class="acp-faint">Platform-scoped</td>
              <td><strong>Yes</strong></td>
            </tr>
            <tr>
              <td>Agent runaway prevention</td>
              <td class="acp-faint">No</td>
              <td class="acp-faint">Some</td>
              <td class="acp-faint">No</td>
              <td class="acp-faint">Single vendor only</td>
              <td><strong>Yes</strong></td>
            </tr>
            <tr>
              <td>Identity-attributed audit trails</td>
              <td class="acp-faint">No</td>
              <td class="acp-faint">No</td>
              <td class="acp-faint">Generic logs</td>
              <td class="acp-faint">Single vendor only</td>
              <td><strong>Yes</strong></td>
            </tr>
            <tr>
              <td>MCP / Apps SDK native support</td>
              <td class="acp-faint">No</td>
              <td class="acp-faint">Partial</td>
              <td class="acp-faint">No</td>
              <td class="acp-faint">Proprietary SDK</td>
              <td><strong>Yes</strong></td>
            </tr>
            <tr>
              <td>Model-agnostic control</td>
              <td class="acp-faint">No</td>
              <td class="acp-faint">No</td>
              <td class="acp-faint">No</td>
              <td class="acp-faint">No</td>
              <td><strong>Yes</strong></td>
            </tr>
            <tr>
              <td>Self-serve setup</td>
              <td class="acp-faint">No</td>
              <td class="acp-faint">Yes</td>
              <td class="acp-faint">Yes</td>
              <td class="acp-faint">No</td>
              <td><strong>Yes</strong></td>
            </tr>
          </tbody>
        </table>
      </div>
    </div>
  </div>
</div>

<!-- CTA -->
<div class="acp-section">
  <div class="acp-container">
    <div class="acp-card acp-card-pad" style="text-align:center;padding:48px 32px;">
      <h2 class="acp-section-title">See the reference implementation</h2>
      <p class="acp-muted" style="max-width:520px;margin:8px auto 0;">
        ACP is a hook in the agent harness plus a gateway that records every tool call and applies your rules before it runs. The harness plugins are open source, MIT licensed.
      </p>
      <div class="acp-btn-row" style="justify-content:center;margin-top:24px;">
        <a href="/reference-architecture" class="acp-btn acp-btn-primary" data-track="Comparison CTA: Architecture">Architecture deep dive</a>
        <a href="https://github.com/agentic-control-plane" class="acp-btn" data-track="Comparison CTA: GitHub">View on GitHub</a>
      </div>
    </div>
  </div>
</div>
