# Govern Gemini CLI's models, tools, and cost with Barndoor

Enable your team to use Gemini CLI and build AI agents, governed by Barndoor so every tool, model, and token Gemini CLI touches is scoped, approved, and logged.

## How Gemini CLI connects through Barndoor

Barndoor gives you one universal endpoint to your MCP servers for Gemini CLI — connect once, use with all connected MCP servers and approved models.

1. **IT connects your tools at the org level.** Authorize Gemini CLI once in Barndoor.
2. **IT or security define the policy.** Which tools, people, and agents; what needs approval; what data is masked; what models are accessed; virtual keys, metering, token budgets.
3. **Point Gemini CLI at the Barndoor endpoint.** One connection governs every tool, model, and agent action.
4. **Give your teams an approved catalog.** Of the AI clients and models they’re approved to use.

## Why govern Gemini CLI with Barndoor

Barndoor is the AI Gateway, helping every business use AI and agents securely, reliably, and with control. It governs what Gemini CLI can access, what it can do with that access, and which models it runs on.

- **No shadow AI.** Every MCP server Gemini CLI connects to is approved and provisioned by IT, not configured ad hoc.
- **Centralized AI access.** Which MCP servers, which tools, which people, which agents, what needs approval, is all defined once at the org level, so access never drifts person to person or agent to agent.
- **Runtime enforcement.** Every MCP tool call and model call Gemini CLI makes is checked, scoped, and logged as it happens.
- **Full visibility.** One audit-ready log of every MCP tool action and every model call Gemini CLI makes.

## Popular MCP servers to connect with Gemini CLI

MCP\  
**Atlassian** \  
Project & Task Management\  
34 toolsBarndoor hosted](/content/integrations/atlassian/index.html)

MCP\  
**Google Mail** \  
Google Workspace\  
17 toolsBarndoor hosted](/content/integrations/google-mail/index.html)

MCP\  
**Notion** \  
File & Document Management\  
14 toolsOfficial Remote](/content/integrations/notion/index.html)

MCP\  
**Salesforce** \  
CRM, Sales & Marketing\  
69 toolsBarndoor hosted](/content/integrations/salesforce/index.html)

MCP\  
**Slack** \  
Communication & Collaboration\  
21 toolsBarndoor hosted](/content/integrations/slack/index.html)

MCP\  
**Zoom** \  
Communication & Collaboration\  
16 toolsBarndoor hosted](/content/integrations/zoom/index.html)

## Frequently asked questions

**How do I add a new MCP server for Gemini CLI after initial setup?**  
IT or security adds the new MCP server to the approved catalog and sets its policy, and it becomes available to Gemini CLI and every other connected AI client immediately, no per-client reconfiguration needed.

**Why do I need an AI gateway if I already have Gemini CLI?**  
Gemini CLI handles the model interaction, but it doesn't enforce org-wide policy, cost limits, or audit logging on its own. That's what a gateway adds in front of it. Without one, every person or agent using Gemini CLI is a separate, ungoverned point of access to whatever models and tools they can reach. An AI gateway makes that access centrally scoped, approved, and logged instead.

**How does Barndoor protect against unapproved models or tools?**  
It blocks the request at the gateway before it reaches the model or tool, rather than Gemini CLI itself deciding to allow or deny it.

## Ready to connect Gemini CLI with Barndoor?
