Purpose
Use this template to evaluate a control plane for agentic AI traffic — not a proxy in front of model providers.
The questions that decide whether you can put agents into production are who authorized this call, what data did it reach, what did it cost, and can you prove it a year from now. This template puts those first and model routing where it belongs.
How to score. Ask for a live demonstration of policy enforcement, not a dashboard. A refusal you can watch — with the reason it names — is worth more than any feature matrix, including this one.
| ✓ Supported | Shipped, in the product today |
| ◗ Partial | Some of this; the row says what is missing |
| 🔗 Integrates | Delivered through a named third party |
| ○ Roadmap | Committed, not shipped |
| — Not offered | Deliberate; the row says why |
The ten categories
Fifty-five criteria across ten categories, each with a priority and an honest answer for Magertron. The full matrix is in the PDF.
Questions to ask every vendor, including us
Independent of the matrix. The answers are more revealing than the checkmarks.
- Show me a refused call. Not a dashboard — a refusal, and the reason it gives. Does it name which check failed, which principal and which rule?
- Show me an allow record. Then ask it to reconstruct the permissions that were in force when that call happened.
- An agent acts for a person. Show me both identities on the record — and what happens when the person’s permissions are narrower than the agent’s.
- A tool’s vendor changes its schema overnight. What happens to the next call?
- Where does the component that authorizes calls run, and what data leaves my perimeter?
- What on this sheet would you mark partial? A vendor who cannot name one is either not listening or not telling you.