The BFF provides a governed, OpenAI-compatible /chat/completions endpoint. It authenticates users, authorizes via PDP (AuthZEN), enforces preflight rules (model allowlist, guardrails, redaction, token caps), pins egress, manages budget holds/settlements in Redis, proxies to the provider, and emits tamper-evident receipts. An optional journaling pipeline can persist masked prompts and feed sanitized analytics to ClickHouse.
What: How the BFF gates and governs /chat/completions using PDP (AuthZEN) constraints and obligations, then enforces preflight rules, egress, budgets, streaming caps, and emits receipts.
Who: Software developers and architects; cloud and AI security architects; product and technical product marketing managers.
Status: Implemented for OpenAI; Anthropic is a roadmap extension.