Use case
Enterprise AI Governance
Enforce guardrails, track usage, manage projects, and observe all AI operations from a single control plane.
- Stack Console + Agent SDK
- Pattern Platform · Governance
- Read ~7 min
Overview
Enterprise AI deployments need governance: who can access what, how much they're spending, what the AI is actually saying, and whether it's staying within policy. Cognipeer provides this through Console's observability layer and Agent SDK's runtime guardrails.
This guide covers setting up enterprise-grade governance across your AI infrastructure.
When to reach for this use case
If your team needs the capabilities described above and you would rather build on proven primitives than wire one from scratch — this is the shape to start from.
Architecture
Console provides the control plane: project management, API key scoping, usage tracking, tracing, and dashboard-level observability.
Agent SDK adds runtime-level governance with input/output guardrails, content filtering, and approval workflows.
1. Project-Scoped API Keys
Console organises resources into projects. Each project gets its own API keys, models, and usage quotas.
// Each project has isolated API keys
// Configure via Console dashboard:
//
// Project: "Customer Support"
// - API Key: cp_support_xxx
// - Allowed models: gpt-4o, claude-3.5-sonnet
// - Rate limit: 100 req/min
//
// Project: "Internal Tools"
// - API Key: cp_internal_xxx
// - Allowed models: gpt-4o-mini
// - Rate limit: 500 req/min
// In your application, use the project-scoped key
const client = new ConsoleClient({
apiKey: "cp_support_xxx", // Scoped to "Customer Support"
baseURL: "https://your-console.example.com",
});2. Agent SDK Guardrails
Apply input and output guardrails in Agent SDK to control what agents can say and do before and after a response is generated.
import { createSmartAgent } from "@cognipeer/agent-sdk";
const governedAgent = createSmartAgent({
name: "GovernedAssistant",
model,
tools: [/* ... */],
guardrails: {
input: [
// Block prompt injection attempts
{ type: "injection_detection", config: { sensitivity: "high" } },
// Filter inappropriate content
{ type: "content_filter", config: { categories: ["hate", "violence"] } },
],
output: [
// Mask personal information
{ type: "pii_filter", config: { mask: true, types: ["email", "phone", "ssn"] } },
// Enforce response length
{ type: "length_limit", config: { maxTokens: 2000 } },
],
},
// Require human approval for sensitive actions
humanInTheLoop: {
requireApproval: ["send_email", "delete_record", "update_account"],
},
tracing: { enabled: true },
});3. Console Guardrail Evaluation
Use Console guardrails when you want tenant-managed policies that can also be evaluated outside the agent runtime, for example at API boundaries or batch moderation steps.
import { ConsoleClient } from '@cognipeer/console-sdk';
const client = new ConsoleClient({
apiKey: process.env.COGNIPEER_API_KEY!,
baseURL: 'https://console.example.com',
});
const moderation = await client.guardrails.evaluate({
guardrail_key: 'support-output-policy',
text: 'Please share the customer password reset token here.',
target: 'output',
});
if (!moderation.passed) {
console.log(moderation.action, moderation.findings);
}4. Observability & Tracing
Console traces every request through the system — from API call to provider response. Use the tracing API to ingest agent-level traces too.
// Console SDK tracing integration
await client.tracing.ingest({
sessionId: 'sess_governance_1',
threadId: 'thread_customer-support',
source: 'custom',
status: 'success',
startedAt: new Date(Date.now() - 800).toISOString(),
endedAt: new Date().toISOString(),
durationMs: 800,
agent: {
name: 'governed-assistant',
version: '1.0.0',
model: 'gpt-4o-mini',
},
summary: {
totalInputTokens: 450,
totalOutputTokens: 180,
totalCachedInputTokens: 0,
totalBytesIn: 9000,
totalBytesOut: 4200,
eventCounts: { ai_call: 1, tool_call: 1 },
},
events: traceEvents,
errors: [],
});
// View in Console dashboard:
// - Session timeline with all events
// - Token usage and cost per session
// - Tool call success/failure rates
// - Guardrail trigger frequencyResult
You now have enterprise AI governance that:
- Isolates projects with scoped API keys and quotas
- Applies runtime guardrails inside Agent SDK
- Evaluates centrally managed guardrails through Console APIs
- Requires human approval for sensitive operations
- Traces every request, tool call, and decision
- Dashboards usage, cost, and compliance metrics
Products used
This pattern combines 2 Cognipeer products.
Console
Self-hosted AI control plane — routing, embeddings, vectors, files, guardrails, and tracing.
Agent SDK
Deterministic TypeScript agent runtime — planning, tools, guardrails, sub-agents, and human-in-the-loop.
Related use cases
Quota-Aware LLM Gateway
Run application traffic through Console with project-scoped quotas, model routing, and request-level visibility for cost control.
Vector RAG Operations Control Plane
Operate RAG pipelines through Console by combining file ingestion, vector index management, embeddings, and chat retrieval in one control surface.
PromptOps And MCP Tool Gateway
Use Console as the control plane for prompt versioning, secure config storage, and converting OpenAPI specs into MCP and tool endpoints.
AI-Powered Applications
Integrate AI capabilities into existing applications with OpenAI-compatible APIs, provider routing, and type-safe SDKs.
See every pattern on the use case index, or browse all Cognipeer libraries.

