Give each surface one job
Keep the website, application, management API, and MCP gateway distinct. Tenant, credential, job, mail, and provisioning work stays behind the authenticated operating boundary.
Give platform teams a repeatable way to configure connections, review policy changes, preserve tenant boundaries, and move governed access toward production trust.

Keep product teams focused on the workflow. Durin provides the shared place to check identity, evaluate access, and record what happened.
Approved MCP clients
Authenticated employees
Scoped workflows
Identity · policy · approvals
Decision + execution evidenceReviewed tools
Scoped credentials
Approved connections
Illustrative architecture. Governance applies to requests routed through Durin.
Keep configuration, connection review, policy, execution, and evidence legible as separate platform surfaces so teams can own the right part of the route.
Keep the website, application, management API, and MCP gateway distinct. Tenant, credential, job, mail, and provisioning work stays behind the authenticated operating boundary.
Keep connection drafts, tool mappings, policy versions, and schema changes explicit. Reviewers can see what will change before a connection moves toward activation.
Track account permissions, tenant resources, identity, billing, email, private connectivity, client versions, retention, and recovery as separate checks with clear owners.
Try a permitted read, an approval-required write, and revoked access. Then bring the same questions to your team’s first connection.
Create an account to manage connection onboarding, reviewed capabilities, policy changes, and uncertain writes.
Create an accountProduction connections use provider setup and trust review.