insights

Notes from the control plane

Engineering writing from the Kimss team — how to govern, isolate, and audit enterprise AI on Azure AI Foundry without rebuilding the plumbing yourself.

Articles

ArchitectureKimss guide

Azure AI Foundry agent gateway

Separate execution from workspace identity, routing, Kimss Credits, and auditable usage.

Read the guide
API migrationKimss guide

Move from Assistants to /v1 agents

A compatibility-first path from legacy assistant routes to the preferred universal gateway.

Read the guide
GovernanceKimss guide

AI credit governance for teams

Connect workspace pools, group budgets, and usage attribution without hiding the Azure economics underneath.

Read the guide
DevelopersKimss guide

Python SDK + MCP quickstart

Install the supported SDK, authenticate a workspace, and understand the focused MCP tool surface.

Read the guide
CompareKimss guide

Compare Kimss to Foundry, Copilot Agents, LangGraph, and more

High-intent evaluation pages: control plane versus execution plane, frameworks, and cloud-parallel alternatives.

Open comparisons
GovernanceKimss guide

Shadow AI: find it, govern it, replace it

Why unsanctioned LLM usage creates security and spend risk—and how a paved control plane eliminates it.

Read the guide
ArchitectureKimss guide

AI gateway & AI API gateway patterns

Auth, routing, metering, and audit at the edge of model and agent traffic on Azure.

Read the guide
Architecture Jun 29, 2026 5 min read LinkedIn

Why Your AI App Needs a Control Plane (And Why Raw Azure AI Foundry Isn't Enough)

Integrating the model is the easy part. The real engineering challenge is governance, tenant isolation, and multi-tenant management. We break down four things raw Foundry can't do for a B2B SaaS — token quotas vs. infrastructure telemetry, agent-level RBAC, identity translation, and actionable vs. raw audit logs — and why a Day-1 control plane beats six months of custom plumbing.

Read on LinkedIn

Stop rebuilding the control plane

Let your engineers focus on your AI product, and let Kimss handle the gateway — secure, multi-tenant, day one.