Station70 · DevRel proposal
Gatekeeper
The policy engine is built. The developer on-ramp was never poured.
opencolin · collin@dabl.club · dabl.club (~85,000 developers) · 2026-07-17
A finished product with no front door.
0
That's how many ways a developer can try Gatekeeper today without booking a sales call. The strongest policy engine on the market is invisible to the people who would wire it in.
Deep product, sealed off.
3
integrated components: a policy engine, a zero-knowledge secrets vault, and an MCP gateway
12
conditions a policy rule can check — who's asking, what it costs, what time it is, whether a human approved
24
integrations already listed on the site — GitHub, Slack, Stripe, AWS, and more
0
public quickstarts, SDKs, or API docs — the missing front door
One thing you won't find in this deck: revenue, traction, or customer counts. None are public, so none are claimed — the pilot exists to measure the first real number.
Why now: two clocks, one window.
- The product is ready. I ran the live gateway myself — it governs real agent traffic today.
- The demand is arriving. AI agents are moving from demos into production, and Europe's MiCA and DORA rules became enforceable July 1, 2026 — regulators are "no longer asking for the plan… asking for proof it ran."
- The missing piece is the on-ramp. The engine is ready and the buyers are coming — but the developers who would wire agents through it have no way in.
Whoever publishes the first credible agent-governance quickstart becomes the default. That slot is still open.
Gatekeeper is telling two different stories right now.
- The main Station70 site still describes the old Gatekeeper: a crypto transaction firewall built with Cyvers.AI, co-signing for Fireblocks customers.
- The new gatekeeper.station70.com describes something else entirely: "The Credential Layer for AI" — a credential firewall where the AI never sees the secret.
- A prospect gets a different pitch depending on which page they land on.
That's not a criticism — it's the opening. The new story doesn't have an owner yet. This proposal is an offer to write it.
The wedge: connected is not the same as allowed.
Every request an agent makes gets checked against policy in real time — who's asking, on what resource, at what spend, needing whose approval. The secret leaves the vault only for that one approved call, and every decision lands in an audit trail.
That's what raw OAuth tokens, tool gateways, and hand-rolled scripts don't do — and in Station70's own words, what password managers and enterprise PAM can't retrofit: "built for AI, not retrofitted from humans."
I didn't just read about the product. I ran it.
- My first real call came back
policy denied — on a service I had just connected with broad permissions. The security is correct; the onboarding is missing. - When a call needs a human, the agent isn't kicked out with an error — it gets a structured "approval needed" response, waits, and resumes automatically once someone says yes. This was genuinely designed for agents.
- The moment a policy allowed it, a real query went through — secret never exposed, decision fully logged.
The demo writes itself: agent oversteps → blocked → human approves → done.
The honest read.
- Strong: security credibility most startups can't buy — zero-knowledge architecture, a Trail of Bits cryptography audit, SOC 2 Type 2.
- Weak: no docs, no SDK, a first-run experience that dead-ends at "denied," and logos on the site but not one written customer story.
- Open: nobody owns the agent-governance tutorial space yet, and the growing MCP ecosystem is untapped distribution.
- Risk: developer-tool gateways already have the mindshare, and the big platforms may ship "good enough" guardrails for free.
This is a trust product. Being this honest about it is the marketing.
The one number that matters.
Weekly active agents making calls through Gatekeeper that pass policy and complete — counted with extra weight when the call needed a human approval or a spend cap.
In plain terms: are real agents doing real, governed work every week? What we refuse to count: signups, connectors configured, page views, GitHub stars. And we won't quote a target until we've measured a baseline.
Seven programs, one job each.
- 1 · The proof series — public, re-runnable security demos: watch an agent get denied, approved, and logged.
- 2 · The five-minute quickstart — connect your first service through Gatekeeper, fast.
- 3 · Framework-native distribution — meet agent developers inside the tools they already use.
- 4 · Reference architectures — one worked example per agent framework, per service.
- 5 · Office hours and build-in-public — a place where stuck developers get unstuck.
- 6 · Design-partner cohort — white-glove onboarding traded for written, named customer stories.
- 7 · MCP registry and marketplace listings — be where agents look for tools.
The three that carry the weight.
- The proof series — public, re-runnable security tests: real denials, real approvals, real logs. A skeptical security team can verify every claim themselves.
- The quickstart — fixes the wall I hit myself. How long from signing up to a first successful governed call? Today that path dead-ends at "denied." Making it five minutes is the pilot's whole job.
- The cohort — twelve weeks, 8–10 companies, white-glove help, each committing up front to a written case study, a quotable result, and a public demo day.
Three phases, six releases.
- Fix & Activate — establish the real baseline, then prove the wedge with the quickstart and the proof series.
- Scale the Loop — SDKs, framework integrations, and the first design-partner cohort.
- Monetize & Compound — enterprise controls and managed services. This phase starts only once a paid tier or self-serve signup exists — a date we need from Station70.
Every release has one success number and a gate to clear before the next one starts. Nothing ships on vibes.
DevRel that feeds sales instead of replacing it.
This isn't an awareness play. It's a factory for the three things enterprise deals are missing today.
- A champion — the developer inside the account who has already used Gatekeeper and wants it.
- A reference — a named customer story the sales deck can finally point to.
- Traceable pipeline — a click from dabl.club, to a named account, to their first governed call, to a sales conversation. Every step logged.
Developers don't replace the enterprise sale. They walk it in the door.
Two ways to buy, kept deliberately separate.
- Start small (the ask): a $6K one-month pilot → $36K for three months → $90K for six. Option to swap up to ~30% of the fee for pay-per-result.
- Go big (when ready): hire the function — full-time Head of DevRel, a 90-day paid trial that converts (≈ $155K), or ongoing fractional ownership.
For scale: a full year-one DevRel build runs ≈ $1.6M; a leaner ramp ≈ $900K–1M. Managed services can make the whole motion pay for itself.
An audience on day one.
85k
developers at dabl.club, the audience I've built and run for years. Distribution most startups spend a year buying, available from week one — with every click traceable to an outcome.
Why Colin.
- The audience — dabl.club, just met: built over years, owned outright, ready on day one.
- The playbook — this same program, already written and run for Tenki, AISA, Nebius, and Coral, and shipped for CrewAI, Memori, Glean, and Perplexity.
- The homework — this proposal was built by actually using the live Gatekeeper gateway: real denials, real approvals, real completed calls.
Any conflicts get disclosed before they start, and fees are always quoted separately from program budget. No surprises.
The ask: one small yes.
A one-month, $6,000 pilot: wire up the measurement, ship the five-minute quickstart, and report one honest number — how many developers actually got to a working governed call.
Small enough to approve without a committee. If the number is bad, you walk away with the data. If it's good, everything bigger is a renewal decision. First step: one 30-minute call.
Connected ≠ allowed. Let's pour the on-ramp.
collin@dabl.club · github.com/opencolin
Gatekeeper DevRel proposal · Station70 · 2026-07-17