August 2026 product release
AI Gateway platform updates
AgentProfile to end reliance on human credentials and hidden costs
Earlier this month, Barndoor announced a new capability that ties each agent’s profile, credentials, and spend to a single governed record. This is the first step for organizations toward governing the entire agent lifecycle from provisioning to deprovisioning access.
August’s release now adds owner and contact fields, secrets rotation, and an activity view that breaks down each agent’s LLM traffic and error rate on its own page. By giving each agent its own profile instead of inheriting a human’s credentials and permissions, you can control exactly what an agent is allowed to access, see what it’s spending, regardless of who built it.
These latest updates brings more operational control:
- If an agent’s client secret is compromised, you can rebuild without needing to start over with the agent itself
- Barndoor will now block binding the same LLM key to two agents by mistake
- The agent’s LLM audit history will persist, even after an agent’s LLM key is unbound or rotated
- The agent’s own detail page now shows 24 hours of activity, as well as traffic and error-rate breakdowns
Real-time alerts and notifications for events that need your attention
Barndoor now provides real-time, in product alerts for events across the Barndoor AI Gateway. A bell icon in the header opens an inbox of events. For example, an LLM budget exceeded threshold, an MCP tool change, a policy update, and more – these are tagged by severity, with actionable alert links that then allow you to drill into the alerted issue. Admins can also configure these alerts to be sent to a specific email address, Slack channel, Microsoft Teams channel, or a generic webhook, depending on your team’s uses.
MCP Governance updates
Barndoor Terraform provider
Barndoor now ships an official Terraform provider. This way, infrastructure teams can configure Barndoor as code, applying policies, MCP connectors, agent configurations, and log export settings. Now, policies and configuration can be version controlled instead of living in the UI.
Install from the Terraform Registry (barndoor-ai/barndoor) and start with the guides at docs.barndoor.ai/terraform.
Control localhost MCPs in early access
An engineer using an MCP server locally on their own laptop could be shadow AI that gateway solutions can’t see or help make safe to use. Barndoor Bridge solves this by running as a background agent on the engineer’s machine, deployed through your MDM. This background agent sits between the local MCP server and what it’s about to do. It evaluates those actions against Barndroor access policies you can control. Instead of worrying about engineers using ungoverned MCP servers, Barndoor Bridge ensures that governance exists by default.
Are you managing local agents? Or concerned about shadow AI? Co-founder and CTO Tim Stacey demonstrated how to bring these agents under centralized controls with an AI Gateway. Watch the replay here.
Barndoor Bridge is in the early access program. If interested, reach out to Barndoor.
Policy revision history shows what changed, when, and who changed it
Barndoor retains a full revision history of every MCP policy. Now, the policy revision history is visible directly in the access control center. This means that when a policy changes, admins can see the full historical record. Each revision captures what, when, and who changed a policy.
Granular confirmations in access control center
Previously, confirmations, the approval step before an agent takes an action, could only be configured for an entire agent at once, the same for every user and tool.
Now, an admin can configure this per tool, and scope it by user group or role. Each action can be set to Always Allow, Needs Approval, or Blocked, so the same agent can behave differently for different people (eg. automation users get Always Allow, everyone else gets Needs Approval).
Admins can also set quick defaults for all Read or Write/Delete tools, then override individual tools or groups as needed.
New MCPs for Cloud66 and DigitalOcean
Barndoor now includes Cloud66 and the DigitalOcean stack. Agents that provision infrastructure or manage networking through these tools are now under the same policies, confirmations, and audit trail as governed connectors within your organization.
The new connectors include
- Cloud66 for deployment and app management
- DigitalOcean Droplets for VM provisioning and lifecycle
- DigitalOcean Networking for VPCs, firewalls, load balancers
- DigitalOcean Spaces for object storage
- DigitalOcean Insights for usage and performance monitoring
- DigitalOcean App Platform for app deployment and scaling
- DigitalOcean Accounts for account and billing management
LLM Gateway updates
Deeper agent reporting in LLM Gateway
While AgentProfile is scoped to one agent, each with its own detail page, the LLM Gateway usage dashboard provides a wider view of traffic, cost, and error rate broken down per agent, user, organization, group, and API key.
Instead of guessing spend from a bill at the end of the month, admins can see which agent or model is driving cost or errors in real time, and combine that visibility with budget caps and automatic fallbacks.
Sign up for a demo
Ready to empower your knowledge workers with governed AI at scale? Book a demo or start a free trial to see Barndoor in action.
Note to customers: If any of the features above aren’t visible in your account yet, reach out to your account executive and we’ll get them turned on for you.

