Blocks.ai publishes this comparison and sells in this market. Every claim about another product links to a public source.
Kong AI Gateway vs Workday Agent System of Record
Kong AI Gateway
Gateway that governs LLM, MCP, and agent-to-agent traffic
Workday Agent System of Record
Workday system of record to find, add, register, configure, monitor, and manage AI agents
Short answer
Kong AI Gateway is a gateway that governs LLM, MCP, and A2A traffic; Workday’s guide says ASOR, set up in each Workday tenant, lets a customer find, add, register, configure, monitor, and manage its AI agents.Source 1, Source 2, Source 3, Source 4, Source 5 Kong can authenticate callers before forwarding to agents’ upstream URLs; ASOR gives each agent a unique Workday identity.Source 6, Source 7
Where each one sits
Six layers of running AI agents at a company, and what each product’s own public sources say it covers.
These aren’t the same kind of product
Kong AI Gateway
- Build agents: Not publicly documented
- Host and run agents: Not publicly documented
- Agents across organizations: Not publicly documented
Workday Agent System of Record
- Build agents: Not publicly documented
- Host and run agents: Not publicly documented
- Agents across organizations: Not publicly documented
At a glance
What each one is
Kong AI Gateway
Kong AI Gateway is one gateway for LLM, MCP, and agent-to-agent (A2A) traffic, with shared authentication, observability, and policy features.Source 1, Source 2 In 2.x, an agent is added as an AI Agent entity, which exposes it at a gateway endpoint and can carry policies.Source 6, Source 19
Workday Agent System of Record
Workday Agent System of Record (ASOR) is where a Workday customer finds, adds, registers, configures, monitors, and manages its AI agents.Source 4 Each agent has a unique Workday identity, using Agent System User accounts, and its permissions come from Workday security policies and security groups.Source 7, Source 9
The differences that matter
How access is decided
Kong AI GatewayCallers can be required to pass API key or OpenID Connect authentication, then a per-agent allow or deny list, before reaching the agent.Source 6
Workday Agent System of RecordWorkday security groups and policies set what an agent can reach; an Agent Interaction Policy sets who may use its delegate-mode skills.Source 9, Source 20
Kong can also attach per-agent policies such as input validation and rate limits; a delegated ASOR agent gets only what both it and the person may do.Source 6, Source 7
Keeping track of agents
Kong AI GatewayIn 2.x, each AI Agent entity is scoped to one gateway instance; Konnect Catalog’s organization-wide agent inventory is in beta, not for production.Source 2, Source 6, Source 12
Workday Agent System of RecordThe Agent Registry lists Workday-built, partner-built, and self-built agents; external agents are currently registered only through the ASOR API.Source 4, Source 11
Workday says some agents, including HiredScore and Evisort ones, aren’t part of ASOR; in Konnect Catalog, in beta, agents are added by pasting an A2A card.Source 4, Source 12
Logs and analytics
Kong AI GatewayA2A audit logs record task IDs, method calls, latencies, and errors; A2A telemetry can flow to Konnect analytics, logging plugins, and OpenTelemetry.Source 6, Source 8
Workday Agent System of RecordAn audit trail report covers agent transactions; per-agent analytics reports cover Workday-built agents only.Source 4, Source 10
Kong’s logging policies can route logs to external systems such as log aggregators.Source 21 For ASOR, SIEM export is not publicly documented.
For security teams
What a security review asks, answered from each vendor’s public documentation.
Full comparison
18 criteria in five groups. Every cell links to its source, or says no public source answers it.
| Kong AI Gateway | Workday Agent System of Record | |
|---|---|---|
| What it is | ||
| What it is and who it’s for | Gateway for LLM, MCP, and A2A traffic.Source 1, Source 2 All three run through one data plane, with shared authentication, observability, and policy features.Source 2 | Workday’s place to find, register, configure, monitor, and manage AI agents, which it describes as an agent analytics hub for IT and business leaders.Source 4, Source 31 |
| Maturity | Version 2.0 announced generally available on 1 September 2026; 2.2.0 released 30 September 2026.Source 17, Source 32 The agent inventory in Konnect Catalog is in beta.Source 12 | Announced in February 2025; generally available since February 2026.Source 18, Source 33 |
| Control | ||
| Agent registry and discovery | In 2.x, each AI Agent entity is scoped to one gateway instance.Source 2, Source 6 An organization-wide agent inventory in Konnect Catalog is in beta.Source 12 | The Agent Registry lists Workday-built, partner-built, and self-built agents with their status.Source 4 Some, such as HiredScore and Evisort agents, aren’t in ASOR.Source 4 |
| Identity and access control | An agent can require callers to pass API key or OpenID Connect authentication, and an allow or deny list enforced before traffic reaches it.Source 6 | Each agent has a unique Workday identity.Source 7 Access rests on Workday security groups; a delegated agent gets only what both it and the user may do.Source 7, Source 9 |
| Ownership, policy, and revocation | Agent policies include input validation, logging, and rate limits.Source 6 Kong’s AI PII Sanitizer scrubs requests to AI models: a Plus add-on, included on Enterprise.Source 15, Source 34 | Workday describes an agent lifecycle of register, configure, activate, and deactivate.Source 31 Agent accounts and OAuth clients stay disabled until activation.Source 9 |
| Audit log and observability | A2A audit logs record task IDs, method calls, latencies, and errors.Source 8 Konnect’s own audit logs (Enterprise) go to a webhook and are kept 7 days in Konnect.Source 15, Source 27 | An audit trail report covers agent transactions; delegated actions record the agent and the user.Source 7, Source 10 Per-agent analytics cover Workday-built agents only.Source 4 |
| Connection | ||
| How agents connect | In 2.x, data plane nodes you run forward allowed traffic upstream, including to each agent’s URL.Source 2, Source 6 An outbound-only path for agents is not publicly documented. | Third-party agents reach Workday APIs through Agent Gateway, a single regional endpoint.Source 13 Outbound-only use is not publicly documented. |
| Agents across organizations | Not publicly documented (checked 2 October 2026) | Partner-built agents are supported; a definition can carry an ID locating each in the partner’s system.Source 4, Source 35 Partner-held controls are not publicly documented. |
| Protocol support | Detects A2A over JSON-RPC and REST bindings and rewrites agent-card URLs.Source 6 Can proxy MCP servers or turn REST APIs into MCP tools.Source 2 | API registration is based on the A2A Agent Card.Source 35 Outside assistants can call the Self-Service Agent over A2A, and tool search can filter by SOAP, REST, or MCP.Source 36, Source 37 |
| Frameworks, models, and clouds supported | Proxies A2A agents and plain HTTP agents at their own URLs.Source 6 Kong says it governs A2A traffic without changing how agents are built.Source 38 | Workday-built, partner-built, and self-built agents.Source 4 Registering Azure AI Foundry and Copilot Studio agents was announced in 2025.Source 39 |
| Operations | ||
| Deployment options and data residency | 2.x: a Konnect-managed control plane in a region you choose, data plane nodes you run.Source 2, Source 40 Kong also sells Kong-managed Dedicated Cloud and serverless gateways.Source 15, Source 41, Source 42 | Set up in each Workday tenant.Source 5 Agent Gateway has public endpoints in eight regions, including the US and EU.Source 13 A self-hosted option is not publicly documented. |
| Compliance attestations | From 2.2, FIPS mode uses only FIPS 140-3 approved algorithms; not submitted for NIST validation.Source 28 Kong lists ISO 27001, SOC 2, and PCI DSS for Kong Inc.Source 29 | Workday says its SOC 2 report covers Workday Enterprise Products and its ISO 42001 certificate covers Workday Platform; ASOR isn’t named.Source 30 |
| Support and SLA | Konnect targets 99.9% availability; Dedicated Cloud Gateways list a 99.99% SLA, serverless gateways none.Source 15 Enterprise support SLAs: 30 min to 2 hours.Source 15 | Workday says its company-wide support is 24/5, with severity 1 cases 24/7/365, or 24/7/365 with Success Plans.Source 43 An ASOR uptime SLA is not publicly documented. |
| Time and effort to get running | A quickstart script creates a Konnect control plane and a local Docker data plane; you then add each agent as an AI Agent entity and attach policies.Source 3, Source 19 | Enable the ASOR functional area and set its security policies.Source 5 Registering an external agent includes finding the IDs of the Workday APIs it will use.Source 11 |
| Pricing model and public prices | Plus: from $25 a month plus usage; per control plane, $200 hybrid, $500 Dedicated Cloud, $25 serverless.Source 15 Enterprise: custom, billed annually.Source 15 | No additional specific SKU for ASOR.Source 4 Workday-built agents in production need a Flex Credits policy opt-in.Source 4 A credit’s price is not publicly documented. |
| Building | ||
| Agent building tools | AI MCP Server can turn REST APIs into MCP tools.Source 1, Source 2 Tools for building agents in Kong AI Gateway are not publicly documented. | You supply an external agent’s definition through an API.Source 4 Workday says its separate Workday Build opened Developer Agent to early access in June 2026.Source 44, Source 45 |
| Model access | One API to providers including OpenAI, Anthropic, Gemini, Amazon Bedrock, Mistral, and Ollama, with your own credentials.Source 2, Source 3, Source 46 | Workday’s AI agents use large language models.Source 4 Which models ASOR supports or includes is not publicly documented. |
| Integrations and ecosystem | A Policies Hub of policies and integrations.Source 25 AI Vault resolves secrets from backends such as AWS, GCP, Azure, and HashiCorp Vault.Source 2 | In February 2026, Workday said more than 65 partners were connecting agents to ASOR.Source 18 Workday says partner agents have been on its Marketplace since June 2025.Source 47 |
Which to choose
Choose Kong AI Gateway if
- You want one gateway for LLM, MCP, and A2A traffic, with shared authentication, observability, and policy features.Source 2
- You want per-agent controls at the gateway: allow or deny lists, input validation, and rate limits.Source 6
- You’d rather run the data plane yourself: Kong’s control plane never carries your data traffic, and nodes keep proxying if it’s unreachable.Source 2
- You want one API to model providers such as OpenAI, Anthropic, Gemini, and Amazon Bedrock, switching or combining them without rewriting integrations.Source 3, Source 46
Choose Workday Agent System of Record if
- Your agents work with Workday data, and you want each one to have a unique Workday identity under your security groups.Source 4, Source 7, Source 9
- You want an agent acting for a person held to that person’s permissions and its own skills, with audit naming both.Source 7
- You want assistants outside Workday, such as the Gemini Enterprise app, to call Workday’s Self-Service Agent over A2A.Source 36
- You want Workday-built, partner-built, and self-built agents in your tenant’s Agent Registry, with no additional specific SKU for ASOR itself.Source 4
Questions buyers ask
Do Kong AI Gateway and Workday Agent System of Record support MCP and A2A?
Kong AI Gateway detects A2A over JSON-RPC and REST, and can proxy or combine MCP servers.Source 2, Source 6 ASOR’s API registration is based on the A2A Agent Card, outside assistants can call Workday’s Self-Service Agent over A2A, and its resource search lists MCP as a tool type.Source 35, Source 36, Source 37
How is each one priced?
Can either one govern agents from other companies?
Does either one help build agents?
Kong AI Gateway can turn REST APIs into MCP toolsSource 1, Source 2; tools for building agents in it are not publicly documented. ASOR takes external agents’ definitions through an API.Source 4 Workday announced early access to Developer Agent in Workday Build, a separate developer platform, in June 2026.Source 44, Source 45
How we compare
Read the full methodEvery claim on this page links to a public source. Where none answers a question, the page says so.
We re-check every fact at least every 90 days. This page was last checked .
Something wrong or out of date? Tell us and we’ll correct it.
Sources
52 public sources, each with the date we checked it. Every one opens in a new tab.
Source 2: AI Gateway architecture - Kong Docs Back:abcdefghijklmnopqrstuv
Source 4: About Workday Agents (Workday Administrator Guide) Back:abcdefghijklmnopqrstuvwxyz
Source 5: Set Up Agent System of Record (Workday Administrator Guide) Back:abcd
Source 6: AI Agents - Kong AI Gateway docs Back:abcdefghijklmnopqrstuv
Source 7: Concept: Agent Security (Workday Administrator Guide) Back:abcdefghijklmn
Source 8: Route A2A traffic through AI Gateway - Kong Docs Back:abc
Source 9: Setup Considerations: Agent Security (Workday Administrator Guide) Back:abcdefg
Source 10: FAQ: Agent Security (Workday Administrator Guide) Back:abc
Source 11: Register External Agents (Workday Administrator Guide) Back:abc
Source 13: Concept: Workday Agent Gateway (Workday Administrator Guide) Back:abcde
Source 17: Kong AI Gateway 2.0 Is Now GA - And It's Already Moving Faster Back:ab
Source 18: The Workday Agent System of Record Is Now Generally Available Back:abc
Source 19: Route A2A agent traffic through AI Gateway - Kong Docs Back:ab
Source 20: Concept: Agent Interaction Policy (Workday Administrator Guide) Back to text
Source 21: AI Gateway audit log reference - Kong Docs Back to text
Source 22: Configure External Agents (Workday Administrator Guide) Back to text
Source 23: AI Auth Strategies - Kong AI Gateway docs Back to text
Source 24: Concept: External Agent ASU Considerations (Workday Administrator Guide) Back to text
Source 26: Request Termination - Configuration Reference - Policy | Kong Docs Back to text
Source 27: Konnect and Dev Portal audit logs - Kong Docs Back:ab
Source 28: FIPS 140-3 compliance in AI Gateway - Kong Docs Back:ab
Source 31: Workday Agent System of Record | Workday US Back:ab
Source 32: Kong AI Gateway changelog - Kong Docs Back to text
Source 33: The Next Generation of Workforce Management is Here - Workday Unveils New Agent System of Record Back to text
Source 34: AI PII Sanitizer - Policy | Kong Docs Back to text
Source 35: ASOR API Documentation v1.2 (Workday/asor on GitHub) Back:abcd
Source 36: Connect External Agents to Workday Using A2A (Workday Administrator Guide) Back:abc
Source 37: Concept: ASOR Agent Resource Search API (Workday Administrator Guide) Back:ab
Source 38: The Agent Gateway for Secure, Observable Agent-to-Agent Communication (Kong) Back to text
Source 39: Workday and Microsoft to Deliver Unified AI Agent Experience for the Enterprise Back to text
Source 41: Dedicated Cloud Gateways - Kong Docs Back to text
Source 45: Workday Launches New Tools for Developers to Build, Connect, and Verify AI Agents For HR, Finance, and IT Back:ab
Source 47: Workday Announces New AI Agent Partner Network and Agent Gateway Back to text