Capabilities By Product

This page organizes Eden capabilities by the product surface that owns the operator experience. Product pages describe the outcome, feature pages describe the controls, guide pages explain setup, and API pages document the callable surface.

Product Boundaries

Eve features govern endpoints and gateway runtime. Eve can be used for AI when the requirement is governed endpoint access to a model provider: endpoint onboarding, credentials, RBAC, endpoint-level security, native protocol listeners, VPN access, templates, APIs, workflows, masking, route evidence, and endpoint telemetry. Endpoint masking applies to supported interlay request surfaces; Adam owns the built-in LLM PII scanner and template lookup.

Adam features govern AI working against endpoints. Use Adam when the product surface is the Eden LLM interface or tool-calling runtime: a user, agent, or gateway API key asks questions, invokes tools, summarizes data, or runs workflows against Eve endpoints with governance. Adam can use the same PII and masking controls, but its differentiator is governed AI over endpoints and model traffic. Seat and API-key entitlements are governed by the applicable Eden license.

Eve

Eve owns governed access to database, LLM, application, server/API, platform, and agent endpoint categories, plus native protocol listeners. Its capabilities start with endpoint ownership and extend through RBAC, templates, APIs, workflows, masking, private transport, and route evidence.

Access And Identity

  • Endpoint Governance: the release surface for endpoint RBAC, credential isolation, endpoint-level security, templates, APIs, workflows, masking, audit, and route evidence.
  • Access And Policy: how Eve combines human users, agents, organizations, endpoint grants, data grants, and endpoint-level security.
  • External Identity And Third-Party Auth: OIDC provider presets for Okta, Microsoft Entra ID, Google, Auth0, AWS Cognito, Keycloak, OneLogin, and PingOne.
  • RBAC APIs: grant, inspect, and revoke control-plane and data-plane access.

Endpoint Runtime

  • Endpoints Guide: endpoint creation and operation across databases, LLMs, applications, servers and APIs, platforms, and agents.
  • Endpoint Management APIs: create, update, list, read, write, transact, and inspect endpoint metadata.
  • Endpoint Backend Profiles: separate production and development lanes with profile-specific routing and pool controls.
  • Traffic Masking: endpoint-scoped masking rules for supported native gateway request surfaces.
  • PII Redaction And Dictionaries: Adam LLM-gateway PII scanning and dictionaries, alongside Eve endpoint masking.
  • Template-Based PII Lookup: template-derived PII terms for requests that need data-backed redaction before upstream egress.

Approved Operations

  • Template APIs: define approved read, write, and transaction shapes instead of arbitrary backend access.
  • Published APIs: expose approved workflow or template-backed API shapes to application clients.
  • Workflow APIs: compose multi-step operations with controlled endpoint access.

Private Transport And Native Gateway

  • Eden VPN: WireGuard peer management for private routes into Eden-managed gateway listeners.
  • VPN API: create, inspect, rotate, and revoke VPN peers and routes.
  • Traffic Mirroring: mirror eligible native protocol traffic to secondary endpoints for validation and compatibility evidence.
  • Interlays API: manage native protocol listeners and runtime state.

Evidence And Operations

Adam

Adam owns governed AI ingress, model routing, AI tool use, endpoint access through AI, and promptless evidence for each licensed user, agent, or gateway API key. It uses shared Eve governance controls such as PII and masking, but its product-owned capability is the LLM interface and tool-calling runtime over governed endpoints.

Gateway Ingress And Routing

  • AI Governance: the product-level governance model for Adam workloads.
  • AI Gateway Governance: OpenAI-compatible gateway policy, model routing, egress controls, telemetry, and fail-closed behavior.
  • Model Routing And Orchestration: route selection, provider configuration, cost controls, and fallback behavior.
  • LLM Providers: configure OpenAI-compatible, Ollama, and local model endpoints.
  • LLM And Agent APIs: gateway keys, providers, policy resources, traces, simulations, and agent routes.

Policy Composition

  • Content Policy Profiles: reusable profiles for regulated or sensitive AI work.
  • Policy Bindings: assign governance profiles to subjects, keys, endpoints, routes, and metadata.
  • Access Boundaries: promptless deny rules for matching subject/resource combinations before model, provider, or tool egress.
  • Tool Calling: governed tool execution through Eden endpoint and workflow surfaces.
  • Governed Querying: query and response controls for AI-assisted data access.

Evidence And Replay

Exodus

Exodus owns migrations and migration validation. It uses Eve endpoints as source and target assets, then layers planning, data movement, write-log replay, validation runs, and cutover workflows on top.

Plan

Move, Replay, And Validate

Operate

Shared Platform

These docs are not owned by one product, but every product depends on them.

How To Use This Page

Start with the product section that matches the workload, then follow the capability group:

  1. Use product docs to understand the operator workflow.
  2. Use feature docs to understand enforcement semantics and telemetry guarantees.
  3. Use guide docs to configure the resource.
  4. Use API docs to automate the same workflow.

Feature controls are additive. A request can pass through RBAC, endpoint security, masking, template constraints, external permission checks, PII controls, route policy, and telemetry capture together. Routes, templates, profiles, and provider settings do not grant access by themselves; they run inside Eden identity and permission checks.

Last updated: July 10, 2026