Self-hosted gateways usually allow deeper policy-as-code, custom routing logic, and environment-specific access controls because the organisation runs the stack itself. Managed gateways usually offer dashboard-driven controls, built-in billing, and simpler policy settings with less infrastructure work. The trade-off is depth of control versus speed of adoption and ongoing operational effort.
Why Governance Controls Differ Between Self-Hosted and Managed Gateways
The difference is not just where the gateway runs. It is where control responsibility sits, how much policy can be tailored, and how much operational discipline the organisation can sustain. Self-hosted gateways are usually chosen when teams need stronger policy-as-code, custom routing, and environment-specific guardrails. Managed gateways are usually chosen when teams want faster rollout, simpler administration, and less infrastructure overhead.
That trade-off matters because governance is not static once agents, integrations, and secrets start moving through the gateway. NHI governance only works when the gateway can enforce the right level of access, logging, and approval at the point of execution. The NHI Lifecycle Management Guide is useful here because gateway choice affects provisioning, rotation, and retirement as much as it affects request flow. For the broader control context, the NIST Cybersecurity Framework 2.0 remains a practical reference point for governance, access control, and monitoring expectations.
In practice, many teams discover the difference only after a custom policy, audit requirement, or incident response need cannot be expressed cleanly in the managed product they selected.
How Governance Controls Work in Practice
Self-hosted gateways let security teams define and enforce controls closer to the workload. That usually means policy-as-code, custom rate limits, tenant-specific routing rules, secret handling rules, and tighter integration with internal identity systems. It also makes it easier to align gateway enforcement with the organisation’s own change control and approval workflows.
Managed gateways shift more of that responsibility to the provider, so governance is often expressed through dashboards, prebuilt policy toggles, role-based admin settings, and billing boundaries. This is faster to adopt, but it can reduce the precision of controls when a team needs request-level conditions, specialised logging, or routing exceptions for regulated data flows. The question is not which model is “more secure” in the abstract. It is which model can actually enforce the controls the organisation needs without creating operational blind spots.
Common control differences include:
- Policy expression: code-driven rules versus simplified admin settings
- Identity binding: direct integration with internal IAM versus provider-managed abstractions
- Change approval: org-owned release gates versus vendor feature rollout
- Audit evidence: custom logs and traces versus standard dashboards and exports
- Runtime flexibility: conditional routing and exceptions versus narrower configuration paths
For teams still maturing their NHI governance, the Top 10 NHI Issues is a useful companion because it highlights the recurring failure patterns that gateway controls need to absorb. When governance must prove who accessed what, under which policy, and with which secret, self-hosted gateways usually give more evidence depth; managed gateways usually give less design burden. These controls tend to break down in highly regulated environments with custom data residency rules because provider defaults rarely match the full policy surface.
Common Variations and Edge Cases
Tighter gateway control often increases engineering and operations overhead, so organisations have to balance governance depth against deployment speed and support burden.
There is no universal standard for this yet, and best practice is still evolving. Some organisations use a managed gateway for the default path and a self-hosted gateway for privileged, regulated, or experimental traffic. Others use managed services only for low-risk internal workloads and reserve self-hosted control planes for environments that need bespoke routing, internal certificate authority integration, or detailed forensic logging.
Edge cases usually appear when one of three things happens: the organisation needs hard tenant isolation, the gateway must enforce policy across multiple cloud environments, or compliance teams require evidence that a vendor dashboard cannot produce. In those cases, the governance question becomes less about convenience and more about whether the control plane can support auditability, revocation, and exception handling without workarounds. The Ultimate Guide to NHIs — Regulatory and Audit Perspectives is relevant when teams need to translate gateway design into evidence for auditors.
Where managed gateways tend to fall short is in environments that need frequent policy changes, strong local control over secrets, or deep inspection of AI and automation traffic. Where self-hosted gateways tend to fall short is in organisations that do not have the staff to maintain patching, monitoring, availability, and policy hygiene consistently.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10, CSA MAESTRO and OWASP Agentic AI Top 10 address the attack and risk surface, while NIST CSF 2.0 and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AC-4 | Gateway governance is fundamentally about access enforcement and least privilege. |
| OWASP Non-Human Identity Top 10 | NHI-03 | Gateway controls affect NHI credential lifecycle, rotation, and exposure risk. |
| CSA MAESTRO | GOVERN | Gateway choice changes who owns policy, approval, and operational accountability. |
| NIST AI RMF | AI RMF supports risk-based governance for automated and semi-autonomous traffic. | |
| OWASP Agentic AI Top 10 | Agentic workloads often traverse gateways and need runtime controls, not static rules. |
Apply AI RMF governance to document risk, control intent, and monitoring for gatewayed workflows.
Related resources from NHI Mgmt Group
- What is the difference between managed and self-hosted AI agent governance?
- What is the difference between self-hosted and managed MCP governance?
- What is the difference between a self-hosted AI gateway and a broader enterprise AI control plane?
- What is the difference between a self-hosted private vault and a managed vault with customer-managed keys?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 1, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org