Reading Time: 8 minutes

San Francisco – In September, 2026, MuleSoft announced Governance for Federated API Gateways with a new Open policies capability that allows enterprise API and security teams to discover, apply, and enforce policies across multi-vendor gateways through Agent Fabric’s Omni Gateway. Open policies eliminate the need for teams to navigate separate policy systems for each gateway vendor. 

The problem is real, and it compounds

Most enterprises run more than one API gateway. MuleSoft manages the experience APIs, Kong handles one department. Apigee came with an acquisition. Azure APIM is locked in because the cloud team owns it. AWS arrived with the microservices migration. Each does its job, but  they do not share a policy model that is consistent across gateways.

So when security says “all finance APIs should accept traffic only from defined IPs,” someone translates that requirement into Kong’s traffic rules, Apigee’s access control config, and Azure’s inbound policy XML, separately, from scratch, in consoles most teams haven’t opened in months. That’s before verifying it applied correctly, and doing it again when something changes, and before finding the APIs that weren’t in scope the first time.

The result: a one-sentence security requirement becomes a month-long coordination project, struggling to maintain consistent security and governance.

How Open Policy solves this problem

Start by bringing your API assets into Agent Fabric using Scanners which automatically discovers and catalogs your API gateways within Agent Registry. API scanners not only bring the API metadata but also bring any existing policy metadata across your assets. Once your scanners for Azure, Apigee, or Kong are configured, API teams express a policy intent once, and Agent Fabric handles the rest.

You choose a protection type from the policy library such as IP allowlist, JWT validation, rate limiting. You configure it once, select the APIs you want covered across vendors, and click apply. Agent Fabric auto-translates to the correct configuration for each gateway and applies it. 

Applying an IP Allowlist across 8 APIs on three different API gateways takes under two minutes, the manual path would have taken over a week. Open policies solve one of the most stubborn security problems in enterprise API management: applying consistent governance  across multiple gateways without learning the policy system of each one.

Two ways to govern, pick the one that fits your team

  • From the UI, you can configure Governance Strategies and apply policy across APIs deployed on other gateways with a simple guided flow.
  • From an agentic surface: Describe the intent in plain language in your AI IDE, “apply IP filtering to all APIs tagged finance, allow traffic from these two IPs only”, and Ågent Fabric identifies every matching API across your federated gateways, finds the applicable protection, and applies it. (Example of headless experience below)
Prompt: "Is there any governance to ensure open IP filtering for my 
finance APIs? Apply any available protection. IPs: 10.0.0.1, 10.0.0.2"

→ Identified 8 APIs tagged [finance] across Azure, Apigee, Kong
→ Mapped to required configurations

→ Applied across all APIs

Discover now, enforce when ready

If you are operating in regulated industries handling sensitive workloads, Agent Fabric provides the flexibility of choosing how to use gateway federation and open policies. You don’t have to start with permissions allowing direct policy updates on API gateways. API Scanner offers a read-only visibility layer. With read-only permissions, scanners bring in all the applied policies from Apigee, Azure, Kong, and AWS into a single view. With this unified metadata across your vendors you can see what’s enforced where and track your organization’s security posture using governance strategies. Later on you can expand the scanner credentials to enable, disable, or delete vendor policies using Agent Fabric, without logging into each vendor’s console.

With this you get full visibility, and the ability to then enforce from one place.

Track your governance continuously.

Applying a policy is an action, governance is a posture. New APIs get deployed, teams make changes in vendor consoles, but with scanners these new changes surface automatically that would have otherwise gone unnoticed.

Governance Controls let you define a consistent enforcement requirement. They generate alerts, mark the API non-conformant, and trigger an email notification. You don’t have to check. It checks for you.

Ready to unify your API security? 

Don’t let multi-gateway complexity slow down your governance  posture. Start your free trial of the Agent Fabric today, or explore the Open policies on your already configured federated gateways.

Get Started