Contact Us 1-800-596-4880

Viewing Service Details in the Portfolio

View scanner read policies, deployments, monitoring, and conformance for a service from one detail page in Portfolio. Open any service, including an API, agent, MCP server, Model Proxy, or gateway, to review current status, cost, and relationships. Use this page to validate applied controls and track changes without switching contexts.

Before You Begin

Before getting started, make sure you have:

  • An Anypoint Platform account.

  • One of these permissions:

    • Exchange: Exchange Viewer

    • Exchange: Exchange Contributor

    • Exchange: Exchange Administrator

    For more information, see Enhanced Experience Permissions.

Service Detail Tabs

The page is organized into tabs. The table lists tabs, what they show, and whether they appear on the detail page for each catalog type:

  • Yes means the tab appears in typical configurations.

  • No means the tab is omitted or you use another area of the experience for the same job (see the note after the table).

Labels and fields inside a tab can differ by service type and release. For end-to-end portfolio tasks that reference these tabs, see Enhanced MuleSoft Experience Overview. tab can differ by service type and release. For end-to-end portfolio tasks that reference these tabs, see Enhanced MuleSoft Experience Overview.

Tab What You See API Agent MCP Server Model Proxy Gateway

Overview

Short summary of what the service does and its specification.

Yes

Yes

Yes

Yes

Yes

Instances

Deployed instances, environments (for example production or sandbox), and gateways when that catalog type supports instances. When Akamai API Security is enabled and scan data is available for this service, the table also shows a Security Risk column with a color-coded risk level per instance (Low, Medium, High, or Critical). Risk levels are per-instance — the same API can show different risk levels across environments.

Yes

Yes

Yes

Each Model Proxy is exactly one instance so there is no Instances tab.

No

Policies

Governance policies attached to the service or its instances (access, data, performance, compliance, and related domains your organization uses). For APIs discovered by scanners, this tab shows read policies from Amazon API Gateway, Google Apigee, Azure API Management, and Kong Gateway. If the instance uses a Kong gateway, the listed policies are gateway-level policies (plugins). Other service-level policies (plugins) can also apply.

Yes

Yes

Yes

Yes

No

Monitoring

Runtime metrics and analytics for health and usage when the system surfaces them for the service or gateway you are viewing.

Yes

Yes

Yes

Yes

No

Conformance

Compliance score and rule-level analysis for conformance reporting where that tab is available. When Akamai API Security is enabled, the tab includes an Akamai section with a risk score overview, a findings table (endpoint-level vulnerabilities with severity, OWASP API Top-10 tags, and compliance framework tags), and an incidents table (aggregated security incidents). Select a finding to view details and see recommended remediation policies you can apply directly from this page.

Yes

Yes

Yes

No

No

  • Instances tab is available on Agents, MCP Servers, and APIs; Model Proxies and Gateways do not include an Instances tab. See Enhanced MuleSoft Experience Overview.

  • Conformance on the detail page aligns with Agents, APIs, and MCP Servers; for gateways, compliance work is framed through Governance and related flows at the scope the system supports. See Enhanced MuleSoft Experience Overview.

Open a Service Detail Page

  1. In Portfolio, open the catalog for the service type (for example APIs or Agents).

  2. Use the search box to find the service by name or description, or scan the list or grid.

  3. Select the service card to open its detail page.

View Read Policies Discovered by Scanners

If a provider scanner has policy-read scopes configured, the Policies tab shows discovered policy entries for that API instance. The tab lists policy names and mapped governance context, such as category and apply level, when the provider returns that metadata. For providers that expose policy status, the tab also shows whether a policy is enabled so teams can validate scanner coverage and conformance inputs from the latest scan snapshot.

  1. In Portfolio, open APIs and select an API discovered by a provider scanner.

  2. Open the Policies tab on the service detail page.

  3. Review read policies imported from Amazon API Gateway, Google Apigee, Azure API Management, or Kong Gateway.

  4. Use the policy list to confirm applied controls before governance reviews or conformance analysis.

Policy visibility depends on the last successful scanner run, not on a live provider query. If required provider scopes or roles are missing, policy results can be incomplete or unavailable. Policy fields such as status, apply level, and detail can vary by provider. If expected policies are missing, check scanner run status and history in Providers.