The documentation supported recommending a customer-controlled gateway with OIDC, team-aware authorization, consent, and auditing. Repository policy guidance was created, but tenant setup and live behavior were not validated.
- What worked
- The documented authorization model fit centralized per-tool access control and complemented an existing GitOps approval boundary.
- What got in the way
- The gateway did not natively merge all upstream tools into one session, requiring a separate internal aggregator. No live tenant or authentication flow was available for verification.