Kimss is the Model-Agnostic Enterprise Gateway: one API key for chat and agents, Entra SSO, tenant isolation, spend controls, and audit-ready telemetry. Route to your own OpenAI-compatible endpoint or Azure AI Foundry.
You keep the runtime. Kimss adds governance, billing, and a single developer surface — the secured multi-tenant control plane your platform team would otherwise build on top of Foundry or BYO models.
Kimss does not replace your model provider. It is the product layer that turns Foundry, OpenAI-compatible BYO, or mixed fleets into a governed, multi-tenant AI platform.
| Capability | Model account alone | Kimss gateway |
|---|---|---|
| Model & agent execution | Native Foundry projects and deployments | Foundry, vaulted custom:*, or mixed — Kimss routes per workspace |
| Multi-tenant workspaces | Build and operate yourself | Built-in PostgreSQL row-level isolation + workspace model |
| Identity (Entra SSO, SCIM) | Wire Entra and provisioning yourself | Entra SSO, admin consent, optional SCIM 2.0 (Identity & SSO) |
| One key: chat + agents | Separate integration paths per modality | One gateway — Studio to build, Gateway to integrate |
| Spend control | Ad-hoc or per-project budgets | Governed-request meters, kill switch, FinOps estimated spend |
| Usage & chargeback | Custom metering and exports | Trust-labeled meters, execution logs, per-tenant reporting |
| Audit trail for procurement | You design the logging sink | Optional APIM gateway logs to Log Analytics (compliance architecture) |
| Time to embed agents in product | Weeks to months of orchestration work | Script-tag widget in minutes, or pip install kimss for backend - embed guide |
| Procurement | Foundry billing only | Azure Marketplace Kimss Enterprise PAYG + invoice options |
Evaluating vendors? Read the full Kimss vs Azure AI Foundry comparison or browse all evaluation pages at /compare. For Shadow AI risk, see /shadow-ai.
Six reasons platform and security teams choose Kimss on top of Foundry - not instead of it.
Using AI to write code is not the same as shipping governed agents in your product. Kimss is the orchestration layer you would otherwise staff with platform engineers.
Do not prototype on raw APIs then scramble for identity, metering, and audit. Start with the control plane; ship features on a governed foundation.
Chat inference and full agentic flows - tools, retrieval, code interpreter - on one Kimss key. Foundry routing per workspace, not separate vendor stacks.
Workspace visibility and execution logs answer “who changed that prompt?” without a crisis email. Govern agents like production software.
Gateway logs to Log Analytics, admin audit trail, and security questionnaire evidence. Formal attestations available under NDA during procurement.
Make a first call and watch live telemetry light up. Secure chat embed (UI-in-a-Box), endpoint registration, and links to Usage, Audit, and Product integrations - your control plane demo in one console.
Managed Identity, Entra, dedicated Foundry mapping per tenant - the same stack your CISO already approved. Procure via Azure Marketplace.
Kimss sits between your applications and Foundry - auth, governed requests, and routing before models run.
See the full interactive system spec: Kimss Architecture →
Every worker uses
- worksfusion Digital Employee fleet on Kimss · Read the story →kimss.KimssClientfor chat and agents. No direct OpenAI or Azure AI SDK calls in application code - a runtime guard enforces that policy.
Share this page with your platform team, or dive into the full documentation.