Skip to content
MAF Learning Hub
Intermediate Govern Duration: 30 min

Govern with Omni Gateway policies

Prerequisites: discover-and-catalog-agents

Discovery makes agents findable; Govern makes them safe. The MuleSoft Omni Gateway enforces security, compliance, and cost controls in motion across agents, brokers, LLMs, and MCP servers - the capability that turns an agent network into an enterprise-grade one.

What you will learn

  • What the Omni Gateway is and how it relates to Flex Gateway.
  • The included policies you can apply to A2A and MCP traffic.
  • How a policy is attached to a governed asset.

The Omni Gateway

The Omni Gateway evolves from the Flex Gateway and adds first-class support for the A2A and MCP protocols, so agent-to-agent and agent-to-tool traffic is governed by the same control point as your APIs (Securing Agent Interactions with Omni Gateway).

Included policies

Out of the box, the gateway ships policies you apply without writing code (Included Policies):

  • A2A: Agent Card, PII Detector, Prompt Decorator, Quality Evaluation, Schema Validation.
  • MCP: attribute-based access control (ABAC) over MCP servers.
  • Cross-cutting: Rate Limiting, Spike Control, Message Logging.

Zero-Trust in motion

Because policy is enforced at the gateway, controls like PII detection and ABAC apply consistently no matter which agent initiates the call.

Attaching a policy

Policies bind to the cataloged asset (from the previous lesson). Conceptually:

# policy binding (excerpt)
target:
  asset: customer-mcp-server   # cataloged in Exchange
policies:
  - type: mcp-abac
    config:
      allow:
        - role: support-agent
          actions: [search, read]
  - type: rate-limiting
    config:
      requestsPerMinute: 120

Forward-looking

The policy-binding YAML is illustrative; confirm exact policy identifiers and configuration schema against the official Included Policies directory before use.

Where to go next

You have completed Track 3 and practiced Orchestrate, Discover, and Govern. Continue to Track 4: Runtime & Connectors to deploy governed agents on CloudHub 2.0 through the Omni Gateway and observe them at runtime.

References