Skip to content

Blocks.ai publishes this comparison and sells in this market. Every claim about another product links to a public source.

Kong AI Gateway vs Workday Agent System of Record

Kong AI Gateway

Gateway that governs LLM, MCP, and agent-to-agent traffic

Workday Agent System of Record

Workday system of record to find, add, register, configure, monitor, and manage AI agents

Short answer

Kong AI Gateway is a gateway that governs LLM, MCP, and A2A traffic; Workday’s guide says ASOR, set up in each Workday tenant, lets a customer find, add, register, configure, monitor, and manage its AI agents.⁠Source 1, Source 2, Source 3, Source 4, Source 5 Kong can authenticate callers before forwarding to agents’ upstream URLs; ASOR gives each agent a unique Workday identity.⁠Source 6, Source 7

Where each one sits

Six layers of running AI agents at a company, and what each product’s own public sources say it covers.

These aren’t the same kind of product

Where they overlap
Both can set access rules for agents and keep records: Kong with allow or deny lists and A2A audit logs, ASOR with Workday security policies and an audit trail report.⁠Source 6, Source 8, Source 9, Source 10
Where they differ
Kong forwards allowed LLM, MCP, and A2A traffic to upstream services.⁠Source 2 ASOR gives each agent a unique Workday identity, and for agents working with Workday, tools are Workday APIs.⁠Source 4, Source 7
Running both
Kong proxies to agents registered as upstream URLs, and agents built outside Workday are registered in ASOR through its API.⁠Source 6, Source 11 Neither vendor publicly documents using the two together.
Public sources · checked 2 October 2026
  • Offered
  • Preview
  • Not publicly documented

Kong AI Gateway

  • Build agents: Not publicly documented
  • Host and run agents: Not publicly documented
  • Identity and access: OfferedPer-agent allow or deny lists⁠Source 6
  • Registry and governance: PreviewKonnect Catalog agents⁠Source 12
  • Traffic between agents, tools, and models: OfferedGateway for LLM, MCP, A2A⁠Source 1
  • Agents across organizations: Not publicly documented

Workday Agent System of Record

  • Build agents: Not publicly documented
  • Host and run agents: Not publicly documented
  • Identity and access: OfferedAgent System User per agent⁠Source 7
  • Registry and governance: OfferedAgent Registry in Management Hub⁠Source 4
  • Traffic between agents, tools, and models: OfferedAgent Gateway for Workday APIs⁠Source 13
  • Agents across organizations: Not publicly documented

At a glance

TopicKong AI GatewayWorkday Agent System of Record
What it managesLLM, MCP, and A2A traffic, through one data plane with shared authentication, observability, and policy features.⁠Source 1, Source 2AI agents built by Workday, by partners, or by your own teams, each with its status in the Agent Registry.⁠Source 4
Where it runsIn AI Gateway 2.x, Kong runs the control plane in Konnect, and you run the data plane nodes that carry traffic.⁠Source 2Inside Workday: a functional area you enable and configure in each tenant.⁠Source 5
Identity and accessCallers can be identified by API key or OAuth credentials; an agent can carry an allow or deny list of identities.⁠Source 6, Source 14A unique Workday identity per agent, using Agent System User accounts governed by Workday security policies and groups.⁠Source 7, Source 9
Pricing modelAI Management Plus from $25 a month plus usage; control planes are $200 a month hybrid, $500 Dedicated Cloud, or $25 serverless.⁠Source 15 Enterprise is custom, billed annually.⁠Source 15No additional specific SKU for ASOR.⁠Source 4 Workday-built agents in production need a Flex Credits policy opt-in; credits depend on each agent’s skills.⁠Source 4, Source 16 The price of a Flex Credit is not publicly documented.
Generally availableKong announced version 2.0 as generally available on 1 September 2026.⁠Source 17 The agent inventory in Konnect Catalog is in beta.⁠Source 12Generally available since February 2026.⁠Source 18

What each one is

Kong AI Gateway

Kong AI Gateway is one gateway for LLM, MCP, and agent-to-agent (A2A) traffic, with shared authentication, observability, and policy features.⁠Source 1, Source 2 In 2.x, an agent is added as an AI Agent entity, which exposes it at a gateway endpoint and can carry policies.⁠Source 6, Source 19

Workday Agent System of Record

Workday Agent System of Record (ASOR) is where a Workday customer finds, adds, registers, configures, monitors, and manages its AI agents.⁠Source 4 Each agent has a unique Workday identity, using Agent System User accounts, and its permissions come from Workday security policies and security groups.⁠Source 7, Source 9

The differences that matter

  1. How access is decided

    Kong AI Gateway

    Callers can be required to pass API key or OpenID Connect authentication, then a per-agent allow or deny list, before reaching the agent.⁠Source 6

    Workday Agent System of Record

    Workday security groups and policies set what an agent can reach; an Agent Interaction Policy sets who may use its delegate-mode skills.⁠Source 9, Source 20

    Kong can also attach per-agent policies such as input validation and rate limits; a delegated ASOR agent gets only what both it and the person may do.⁠Source 6, Source 7

  2. Keeping track of agents

    Kong AI Gateway

    In 2.x, each AI Agent entity is scoped to one gateway instance; Konnect Catalog’s organization-wide agent inventory is in beta, not for production.⁠Source 2, Source 6, Source 12

    Workday Agent System of Record

    The Agent Registry lists Workday-built, partner-built, and self-built agents; external agents are currently registered only through the ASOR API.⁠Source 4, Source 11

    Workday says some agents, including HiredScore and Evisort ones, aren’t part of ASOR; in Konnect Catalog, in beta, agents are added by pasting an A2A card.⁠Source 4, Source 12

  3. Logs and analytics

    Kong AI Gateway

    A2A audit logs record task IDs, method calls, latencies, and errors; A2A telemetry can flow to Konnect analytics, logging plugins, and OpenTelemetry.⁠Source 6, Source 8

    Workday Agent System of Record

    An audit trail report covers agent transactions; per-agent analytics reports cover Workday-built agents only.⁠Source 4, Source 10

    Kong’s logging policies can route logs to external systems such as log aggregators.⁠Source 21 For ASOR, SIEM export is not publicly documented.

For security teams

What a security review asks, answered from each vendor’s public documentation.

TopicKong AI GatewayWorkday Agent System of Record
Network exposureIn 2.x, data plane nodes you run proxy to each agent’s URL and authenticate to Kong’s control plane over mTLS.⁠Source 2, Source 6Third-party agents call Workday APIs via Agent Gateway; delegate skills need a Redirect URI callback.⁠Source 13, Source 22 Private networking isn’t publicly documented.
IdentityCallers can be required to pass API key or OpenID Connect authentication (Okta, Azure AD, Google, or any OIDC provider).⁠Source 6, Source 23Unique Workday identity per agent.⁠Source 7 External agents use OAuth 2.0 or signed JWTs; third-party (self-built) agents’ tokens last 4 hours.⁠Source 7, Source 24
Access changes and revocationEach agent has an enabled switch; Request Termination or deny lists block callers.⁠Source 6, Source 25, Source 26 Nodes keep their last config without Konnect.⁠Source 2Deactivating an agent hides it from users; Workday says the change can take up to a minute at Agent Gateway.⁠Source 4, Source 13
Audit trailKonnect telemetry omits request and response bodies by default.⁠Source 2 Platform audit logs (Enterprise): webhook delivery, kept 7 days in Konnect.⁠Source 15, Source 27Delegated actions log the agent as By User and the person as On Behalf Of User.⁠Source 7
Compliance2.2+ FIPS mode: FIPS 140-3 algorithms only, not NIST-validated.⁠Source 28 Kong Inc. lists ISO 27001 and SOC 2 (report under NDA).⁠Source 29Workday says its SOC 2 report covers Workday Enterprise Products; ASOR isn’t named.⁠Source 30

Full comparison

18 criteria in five groups. Every cell links to its source, or says no public source answers it.

Kong AI Gateway and Workday Agent System of Record compared on 18 criteria
Kong AI GatewayWorkday Agent System of Record
What it is
What it is and who it’s forGateway for LLM, MCP, and A2A traffic.⁠Source 1, Source 2 All three run through one data plane, with shared authentication, observability, and policy features.⁠Source 2Workday’s place to find, register, configure, monitor, and manage AI agents, which it describes as an agent analytics hub for IT and business leaders.⁠Source 4, Source 31
MaturityVersion 2.0 announced generally available on 1 September 2026; 2.2.0 released 30 September 2026.⁠Source 17, Source 32 The agent inventory in Konnect Catalog is in beta.⁠Source 12Announced in February 2025; generally available since February 2026.⁠Source 18, Source 33
Control
Agent registry and discoveryIn 2.x, each AI Agent entity is scoped to one gateway instance.⁠Source 2, Source 6 An organization-wide agent inventory in Konnect Catalog is in beta.⁠Source 12The Agent Registry lists Workday-built, partner-built, and self-built agents with their status.⁠Source 4 Some, such as HiredScore and Evisort agents, aren’t in ASOR.⁠Source 4
Identity and access controlAn agent can require callers to pass API key or OpenID Connect authentication, and an allow or deny list enforced before traffic reaches it.⁠Source 6Each agent has a unique Workday identity.⁠Source 7 Access rests on Workday security groups; a delegated agent gets only what both it and the user may do.⁠Source 7, Source 9
Ownership, policy, and revocationAgent policies include input validation, logging, and rate limits.⁠Source 6 Kong’s AI PII Sanitizer scrubs requests to AI models: a Plus add-on, included on Enterprise.⁠Source 15, Source 34Workday describes an agent lifecycle of register, configure, activate, and deactivate.⁠Source 31 Agent accounts and OAuth clients stay disabled until activation.⁠Source 9
Audit log and observabilityA2A audit logs record task IDs, method calls, latencies, and errors.⁠Source 8 Konnect’s own audit logs (Enterprise) go to a webhook and are kept 7 days in Konnect.⁠Source 15, Source 27An audit trail report covers agent transactions; delegated actions record the agent and the user.⁠Source 7, Source 10 Per-agent analytics cover Workday-built agents only.⁠Source 4
Connection
How agents connectIn 2.x, data plane nodes you run forward allowed traffic upstream, including to each agent’s URL.⁠Source 2, Source 6 An outbound-only path for agents is not publicly documented.Third-party agents reach Workday APIs through Agent Gateway, a single regional endpoint.⁠Source 13 Outbound-only use is not publicly documented.
Agents across organizationsNot publicly documented (checked 2 October 2026)Partner-built agents are supported; a definition can carry an ID locating each in the partner’s system.⁠Source 4, Source 35 Partner-held controls are not publicly documented.
Protocol supportDetects A2A over JSON-RPC and REST bindings and rewrites agent-card URLs.⁠Source 6 Can proxy MCP servers or turn REST APIs into MCP tools.⁠Source 2API registration is based on the A2A Agent Card.⁠Source 35 Outside assistants can call the Self-Service Agent over A2A, and tool search can filter by SOAP, REST, or MCP.⁠Source 36, Source 37
Frameworks, models, and clouds supportedProxies A2A agents and plain HTTP agents at their own URLs.⁠Source 6 Kong says it governs A2A traffic without changing how agents are built.⁠Source 38Workday-built, partner-built, and self-built agents.⁠Source 4 Registering Azure AI Foundry and Copilot Studio agents was announced in 2025.⁠Source 39
Operations
Deployment options and data residency2.x: a Konnect-managed control plane in a region you choose, data plane nodes you run.⁠Source 2, Source 40 Kong also sells Kong-managed Dedicated Cloud and serverless gateways.⁠Source 15, Source 41, Source 42Set up in each Workday tenant.⁠Source 5 Agent Gateway has public endpoints in eight regions, including the US and EU.⁠Source 13 A self-hosted option is not publicly documented.
Compliance attestationsFrom 2.2, FIPS mode uses only FIPS 140-3 approved algorithms; not submitted for NIST validation.⁠Source 28 Kong lists ISO 27001, SOC 2, and PCI DSS for Kong Inc.⁠Source 29Workday says its SOC 2 report covers Workday Enterprise Products and its ISO 42001 certificate covers Workday Platform; ASOR isn’t named.⁠Source 30
Support and SLAKonnect targets 99.9% availability; Dedicated Cloud Gateways list a 99.99% SLA, serverless gateways none.⁠Source 15 Enterprise support SLAs: 30 min to 2 hours.⁠Source 15Workday says its company-wide support is 24/5, with severity 1 cases 24/7/365, or 24/7/365 with Success Plans.⁠Source 43 An ASOR uptime SLA is not publicly documented.
Time and effort to get runningA quickstart script creates a Konnect control plane and a local Docker data plane; you then add each agent as an AI Agent entity and attach policies.⁠Source 3, Source 19Enable the ASOR functional area and set its security policies.⁠Source 5 Registering an external agent includes finding the IDs of the Workday APIs it will use.⁠Source 11
Pricing model and public pricesPlus: from $25 a month plus usage; per control plane, $200 hybrid, $500 Dedicated Cloud, $25 serverless.⁠Source 15 Enterprise: custom, billed annually.⁠Source 15No additional specific SKU for ASOR.⁠Source 4 Workday-built agents in production need a Flex Credits policy opt-in.⁠Source 4 A credit’s price is not publicly documented.
Building
Agent building toolsAI MCP Server can turn REST APIs into MCP tools.⁠Source 1, Source 2 Tools for building agents in Kong AI Gateway are not publicly documented.You supply an external agent’s definition through an API.⁠Source 4 Workday says its separate Workday Build opened Developer Agent to early access in June 2026.⁠Source 44, Source 45
Model accessOne API to providers including OpenAI, Anthropic, Gemini, Amazon Bedrock, Mistral, and Ollama, with your own credentials.⁠Source 2, Source 3, Source 46Workday’s AI agents use large language models.⁠Source 4 Which models ASOR supports or includes is not publicly documented.
Integrations and ecosystemA Policies Hub of policies and integrations.⁠Source 25 AI Vault resolves secrets from backends such as AWS, GCP, Azure, and HashiCorp Vault.⁠Source 2In February 2026, Workday said more than 65 partners were connecting agents to ASOR.⁠Source 18 Workday says partner agents have been on its Marketplace since June 2025.⁠Source 47

Which to choose

Choose Kong AI Gateway if

  • You want one gateway for LLM, MCP, and A2A traffic, with shared authentication, observability, and policy features.⁠Source 2
  • You want per-agent controls at the gateway: allow or deny lists, input validation, and rate limits.⁠Source 6
  • You’d rather run the data plane yourself: Kong’s control plane never carries your data traffic, and nodes keep proxying if it’s unreachable.⁠Source 2
  • You want one API to model providers such as OpenAI, Anthropic, Gemini, and Amazon Bedrock, switching or combining them without rewriting integrations.⁠Source 3, Source 46

Choose Workday Agent System of Record if

  • Your agents work with Workday data, and you want each one to have a unique Workday identity under your security groups.⁠Source 4, Source 7, Source 9
  • You want an agent acting for a person held to that person’s permissions and its own skills, with audit naming both.⁠Source 7
  • You want assistants outside Workday, such as the Gemini Enterprise app, to call Workday’s Self-Service Agent over A2A.⁠Source 36
  • You want Workday-built, partner-built, and self-built agents in your tenant’s Agent Registry, with no additional specific SKU for ASOR itself.⁠Source 4

Questions buyers ask

Do Kong AI Gateway and Workday Agent System of Record support MCP and A2A?

Kong AI Gateway detects A2A over JSON-RPC and REST, and can proxy or combine MCP servers.⁠Source 2, Source 6 ASOR’s API registration is based on the A2A Agent Card, outside assistants can call Workday’s Self-Service Agent over A2A, and its resource search lists MCP as a tool type.⁠Source 35, Source 36, Source 37

How is each one priced?

Kong’s AI Management Plus starts at $25 a month plus usage, with $200 a month per hybrid control plane; Enterprise is custom.⁠Source 15 ASOR needs no additional specific SKU; Workday-built agents in production need a Flex Credits policy opt-in.⁠Source 4 A credit’s price is not publicly documented.

Can either one govern agents from other companies?

Kong AI Gateway proxies to agents by URL⁠Source 6, but a cross-organization trust model is not publicly documented. ASOR supports partner-built agents, whose definitions can carry an ID from the partner’s system⁠Source 4, Source 35; controls held by the partner are not publicly documented.

Does either one help build agents?

Kong AI Gateway can turn REST APIs into MCP tools⁠Source 1, Source 2; tools for building agents in it are not publicly documented. ASOR takes external agents’ definitions through an API.⁠Source 4 Workday announced early access to Developer Agent in Workday Build, a separate developer platform, in June 2026.⁠Source 44, Source 45

How we compare

Read the full method

Every claim on this page links to a public source. Where none answers a question, the page says so.

We re-check every fact at least every 90 days. This page was last checked .

Something wrong or out of date? Tell us and we’ll correct it.

Sources

52 public sources, each with the date we checked it. Every one opens in a new tab.

  1. Source 1: Kong AI Gateway product page Kong · checked Back:abcdefg

  2. Source 2: AI Gateway architecture - Kong Docs Kong · checked Back:abcdefghijklmnopqrstuv

  3. Source 3: Kong AI Gateway | Kong Docs Kong · checked Back:abcd

  4. Source 4: About Workday Agents (Workday Administrator Guide) Workday · checked Back:abcdefghijklmnopqrstuvwxyz

  5. Source 5: Set Up Agent System of Record (Workday Administrator Guide) Workday · checked Back:abcd

  6. Source 6: AI Agents - Kong AI Gateway docs Kong · checked Back:abcdefghijklmnopqrstuv

  7. Source 7: Concept: Agent Security (Workday Administrator Guide) Workday · checked Back:abcdefghijklmn

  8. Source 8: Route A2A traffic through AI Gateway - Kong Docs Kong · checked Back:abc

  9. Source 9: Setup Considerations: Agent Security (Workday Administrator Guide) Workday · checked Back:abcdefg

  10. Source 10: FAQ: Agent Security (Workday Administrator Guide) Workday · checked Back:abc

  11. Source 11: Register External Agents (Workday Administrator Guide) Workday · checked Back:abc

  12. Source 12: Agents in Catalog - Kong Docs Kong · checked Back:abcdef

  13. Source 13: Concept: Workday Agent Gateway (Workday Administrator Guide) Workday · checked Back:abcde

  14. Source 14: AI Consumers - Kong AI Gateway docs Kong · checked Back to text

  15. Source 15: Kong Pricing & Plans Kong · checked Back:abcdefghijk

  16. Source 16: Workday Flex Credits | Workday US Workday · checked Back to text

  17. Source 17: Kong AI Gateway 2.0 Is Now GA - And It's Already Moving Faster Kong · checked Back:ab

  18. Source 18: The Workday Agent System of Record Is Now Generally Available Workday · checked Back:abc

  19. Source 19: Route A2A agent traffic through AI Gateway - Kong Docs Kong · checked Back:ab

  20. Source 20: Concept: Agent Interaction Policy (Workday Administrator Guide) Workday · checked Back to text

  21. Source 21: AI Gateway audit log reference - Kong Docs Kong · checked Back to text

  22. Source 22: Configure External Agents (Workday Administrator Guide) Workday · checked Back to text

  23. Source 23: AI Auth Strategies - Kong AI Gateway docs Kong · checked Back to text

  24. Source 24: Concept: External Agent ASU Considerations (Workday Administrator Guide) Workday · checked Back to text

  25. Source 25: Kong AI Gateway Policies - Kong Docs Kong · checked Back:ab

  26. Source 26: Request Termination - Configuration Reference - Policy | Kong Docs Kong · checked Back to text

  27. Source 27: Konnect and Dev Portal audit logs - Kong Docs Kong · checked Back:ab

  28. Source 28: FIPS 140-3 compliance in AI Gateway - Kong Docs Kong · checked Back:ab

  29. Source 29: Trust Center - Kong Inc. Kong · checked Back:ab

  30. Source 30: Workday Compliance | Workday US Workday · checked Back:ab

  31. Source 31: Workday Agent System of Record | Workday US Workday · checked Back:ab

  32. Source 32: Kong AI Gateway changelog - Kong Docs Kong · checked Back to text

  33. Source 33: The Next Generation of Workforce Management is Here - Workday Unveils New Agent System of Record Workday · checked Back to text

  34. Source 34: AI PII Sanitizer - Policy | Kong Docs Kong · checked Back to text

  35. Source 35: ASOR API Documentation v1.2 (Workday/asor on GitHub) Workday · checked Back:abcd

  36. Source 36: Connect External Agents to Workday Using A2A (Workday Administrator Guide) Workday · checked Back:abc

  37. Source 37: Concept: ASOR Agent Resource Search API (Workday Administrator Guide) Workday · checked Back:ab

  38. Source 38: The Agent Gateway for Secure, Observable Agent-to-Agent Communication (Kong) Kong · checked Back to text

  39. Source 39: Workday and Microsoft to Deliver Unified AI Agent Experience for the Enterprise Workday · checked Back to text

  40. Source 40: Geographic regions - Kong Docs Kong · checked Back to text

  41. Source 41: Dedicated Cloud Gateways - Kong Docs Kong · checked Back to text

  42. Source 42: Serverless Gateways - Kong Docs Kong · checked Back to text

  43. Source 43: Workday Support | Workday US Workday · checked Back to text

  44. Source 44: Workday Build | Workday US Workday · checked Back:ab

  45. Source 45: Workday Launches New Tools for Developers to Build, Connect, and Verify AI Agents For HR, Finance, and IT Workday · checked Back:ab

  46. Source 46: AI Gateway providers - Kong Docs Kong · checked Back:ab

  47. Source 47: Workday Announces New AI Agent Partner Network and Agent Gateway Workday · checked Back to text

  48. Source 48: Your company's private network Blocks.ai · checked Back to text

  49. Source 49: Network requirements Blocks.ai · checked Back to text

  50. Source 50: Solutions: Agent sprawl Blocks.ai · checked Back to text

  51. Source 51: Solutions: Partner networks Blocks.ai · checked Back to text

  52. Source 52: Pricing Blocks.ai · checked Back to text