Documentation
Getting started: integrate Gateco in 9 steps
Gateco is the permission layer between your AI applications and your organization's knowledge. Your vectors stay in your database; Gateco becomes the policy-enforcing gateway your apps query instead of hitting the database directly. Steps 1 through 3 are the connect-and-configure path. Steps 4 through 7 scale with how much data and policy you bring. Step 8 is usually a one-line change in your application.

Prefer to watch? The full 9-step setup as a video walkthrough (3 min).
Before you start
Three things the nine steps assume. Each one cost a real first run time it did not need to.
- Python 3.10 or newer. The
gatecopackage declares 3.10, 3.11 and 3.12. The Python that ships with macOS is 3.9, whichpip install gatecorefuses; install a newer one with Homebrew, pyenv or uv first. - A vector index must already exist. Gateco writes into your index and never creates one. On Pinecone, create the index before step 2, with the dimension of your embedding model (1536 for text-embedding-3-small, the default) and the cosine metric.
- Which steps need which plan. Reaching a denied and a granted retrieval (steps 1 through 6 and 8) works on Free: add users under Directory with no identity provider, write an RBAC policy (ABAC and ReBAC policies and the policy templates start at Team), and retrieve through the SDK or CLI. Step 7, the Access Simulator, is Growth and above; on Free and Team, run the two retrievals through the SDK or CLI instead. Syncing an identity provider or provisioning users via SCIM in step 5 is Growth and above, but step 5 itself needs neither.
Create your organization and pick a plan
Sign up with email or Google/GitHub SSO. The Free tier is built for evaluation: 1,000 secured retrievals, one connector, and 100 ingested documents per month. Team unlocks batch and async ingestion. Growth adds vendor IAM sync, SCIM provisioning, and source connectors with permission import.
Connect your vector database
Your vectors stay in your database. Add a connector for pgvector, Supabase, Neon, Pinecone, or Qdrant to get the full ingestion experience, or Weaviate, Milvus, Chroma, OpenSearch, Azure AI Search, and Vertex AI for search-only governance. Credentials are envelope-encrypted against your organization's KMS binding, and the connection test confirms reachability before anything else depends on it.
Configure search
Tell Gateco which table or collection holds your embeddings, plus the embedding, id, and content columns. For Postgres-family connectors the schema introspector detects vector tables and fills this in for you. This step turns the connector from connected into search-ready. If you connected an existing corpus, also declare the embedding model it was built with in the search config. Text queries are embedded server-side, so they must use the same model your vectors came from, or search fails with a dimension mismatch.
Make your data policy-ready
Three routes, and most teams mix them:
- Existing vectors: run retroactive registration to register unmanaged vectors as gated resources, then apply classification suggestions in bulk. An admin reviews every suggestion before it applies.
- New documents: ingest through Gateco. Upload files in the UI, use the SDK for single or batch ingestion, or queue async jobs for large corpora (Team and above). Extraction runs self-hosted inside the deployment, so document content never leaves it.
- Living knowledge bases (Growth and above): connect Google Drive, SharePoint, Confluence, or Notion as a document source. Documents and their permissions sync on a schedule, deletions propagate, and access revocations follow automatically.
Add users or connect your identity provider
Every retrieval is evaluated against a real principal, so this is how policies get identities to reason about. On any plan, add users directly under Directory (Free 10, Team 100, Growth and above unlimited): no identity provider required. To mirror a real directory, sync principals and groups from Okta, Azure Entra ID, AWS IAM Identity Center, or GCP Cloud Identity, or provision users via SCIM (Growth and above).
Create and activate policies
Start from the seven policy templates or let the suggestion engine propose conservative drafts from your synced groups and classifications. RBAC, ABAC, and relationship-based (ReBAC) conditions are all supported. If you connected a document source, review the auto-generated draft policy and the ACL coverage report. Everything starts as a draft: nothing enforces until you activate it.
Simulate before you enforce
The Access Simulator answers the question that matters before go-live: what would this specific person see for this query? Dry runs evaluate policies against synthetic requests, and live preview executes a real retrieval and shows the allowed and denied results side by side.
Cut your applications over to Gateco
Install the SDK and replace direct vector database queries in your RAG application with a secured retrieval call:
pip install gateco
from gateco_sdk import GatecoClient
# Create the key under Settings > API Keys with the "retrieve" scope.
# Since SDK 1.9.0 the client defaults to https://api.gateco.ai.
client = GatecoClient(api_key="gck_...")
principal = client.principals.resolve(email="alice@yourco.com")
results = client.retrievals.execute(
connector_id="...",
principal_id=principal.id,
query="Q3 revenue forecast",
)A note on credentials. API keys carry explicit scopes: retrieve (secured retrievals, grounded answers, principal and connector lookup), ingest, relationships, and principals. A key does exactly what its scopes say and nothing else, on every plan, bounded by a per-plan key limit. Keys are the right credential for a service. A user session (login()) is for the console and for anything that manages the account, such as creating keys or editing policies.
Grounded Answers adds policy-aware answer synthesis with citations, and the MCP server plugs Gateco into Claude and other AI agents. Then close the loop on the security boundary: restrict direct database access so governed workloads can only reach the data through Gateco.
Operate: audit, usage, and sync
Every retrieval is recorded: who asked, what was allowed, what was denied, and which policy decided. Watch the audit log, track usage against plan limits, and let scheduled identity and source syncs keep principals and content fresh.
A Free-tier evaluation
A typical evaluation on the Free tier: connect one database, register or ingest a handful of documents, add a user under Directory, write one RBAC policy, and run a retrieval that returns one document and withholds another. No identity provider and no credit card required.
Start free