Workshop session
Participant Lab Console
Netskope AI Gateway Workshop & CTF All in one

AI Gateway Lab Console

Run workshop prompts, compare secured versus direct routing, and inspect how policy controls affect AI traffic.

Workshop command view

Dashboard

Monitor workshop readiness, live CTF status, leaderboard performance and participant activity from one overview.

Workshop readiness
Leaderboard
Participant Activity
Participant Prompts Used Capture the Flag Points ⇅
Progress Secured Direct
Workshop roster

Participants

Provision accounts, monitor usage and track CTF progress.

All participants
Participant ⇅ Token Group Prompts Used Capture the Flag Policies in Netskope Delete
Progress Secured Direct Reset Progress Detail Reset Add Delete
Shared prompt catalogue

Prompt Library

Maintain reusable workshop prompts that participants can open from the chat experience and send without typing manually.

All prompts
SEQ Prompt text Actions
Edit Delete Visible
Live workshop operations

Control Center

Run the CTF session, control participant-facing visibility, manage registration and tune workshop limits from one operational surface.

Capture the Flag
Status —
Leaderboard
Participants —
Registration
Status —
CTF TIMER
--:--:--
No timer set — the clock runs only while Capture the Flag is on Run.
--
Registration Code
—
Workshop Limits
Set retries to 0 for unlimited attempts. Hint penalty is the points deducted when a participant reveals a hint (default 5).
Capture the Flag content

Challenges

Create and manage CTF exercises and completion rules.

All challenges
SEQ Challenge Actions
Edit Delete Visible
Netskope tokens

AI Gateway Tokens

Review AI Gateway token groups, token values, assignment status and expiry for the participant access layer.

All tokens
Token Group ⇅ Token Name Token Value Status Assigned to Expires
Interaction audit

Conversations

Inspect participant conversations, message counts and last activity without entering the participant chat experience.

All conversations
Participant ⇅ Conversation Activity Actions
Conversations Messages Last activity Detail Delete
Administration

Admin access management

Create and manage instructor accounts with full control panel access.

Add admin A random password and API token are generated automatically on creation.
All admins
Username Display name Status Actions
Token Password Disable Delete
Tool access

MCP Servers

Sync MCP servers from your Netskope tenant and decide which tools are visible to workshop participants.

MCP Servers in Netskope tenant
Name Host Type Actions
Visible
Workshop configuration

Global operating settings

Configure cloud template sources and local maintenance controls for this lab environment.

Workshop identity

How this CTF presents itself to participants: its name, color, icon and watermark. By default the color is picked automatically (random, but stable for this CTF) so nobody mistakes it for another one.

Shown on the login screen, the participant portal and the admin panel.
Live preview · participant portal
—
AI Gateway Workshop
Challenge #1Find the transaction
Cloud Template URLs
Demo Data

Generate participants, prompts, conversations and challenge activity for a complete workshop preview.

Danger zone

Destructive maintenance

Use these actions only when preparing the lab for a new run or cleaning a completed workshop.

Clear Database

Deletes participants, conversations, challenges, completions and prompt library entries. API keys, providers and settings are kept.

This will permanently delete:
  • All participant accounts (admin preserved)
  • All conversations and messages
  • All challenges, completions and point penalties
  • All prompt library entries
API keys, providers and settings are kept.
Factory Reset

Runs the full workshop reset flow and prepares the environment for the next group.

Netskope Tenant

AI Gateway

Configure tenant API connectivity and the shared gateway URL used by participants.

Netskope Tenant
Netskope AI Gateway
Public URL. Shared with all participants.
Private URL. Used only to look up the AI Gateway Status. Untick "Same" to use a different value.
Saved!
AI Gateway Status
Open this section to load appliance status.
AI catalogue

AI Providers

Sync tenant providers, manage visibility and configure model access.

AI Providers in Netskope tenant
No providers yet. Click "↻ Sync from Netskope" to load.
Netskope AI Gateway

About

Made with love, coffee, and a suspicious number of “just one last tweak” moments. Built by humans who care about the details, even the tiny ones nobody notices… until they do.

Platform Netskope AI Gateway
Built by Netskope Iberia team
Purpose Workshop & Training
Participant provisioning
Provider visibility controls
MCP server management
Workshop monitoring
Maintenance Open API references, inspect release notes, or check whether a newer build is available.
☕
Fuel for the team

If this lab helped your workshop run smoother, the Netskope Iberia team accepts thanks in coffee, cold beers, Bitcoin, or a good conversation at the next meetup.

Reference rate: 1 good conversation = 1 coffee. Premium challenge stories may qualify for beer tier. ₿
Help

Overview

Welcome to Workshop & CTF All in One. This portal runs a hands-on lab where participants interact with LLMs in two modes: routed through Netskope's AI Gateway (Secured), or directly to the provider (Direct).

📊
Dashboard
Workshop readiness at a glance. 6 status indicators, a live challenge podium (top 3 participants), and a participant activity table.
👥
Participants
Create and manage participant access codes. Track prompt usage, challenge progress, and Netskope policies per participant.
🎛️
Control Center
Run the live session: CTF state (Stop / Standby / Run), registration, leaderboard visibility, registration code, plus quick actions — Award Ceremony and fullscreen Leaderboard.
🏆
Challenges
Create CTF challenges backed by Netskope event queries (or a keyword). Participants complete them by triggering the right AI Gateway events. Import, export, or sync from the cloud template.
🔑
GW Tokens
Netskope AI Gateway tokens auto-created per participant on registration. Used for per-user attribution in the gateway.
🤖
AI Providers
Providers synced from the Netskope tenant (OpenAI, Claude, DeepSeek, etc.). Toggle visibility and set API keys for Direct mode.
🔧
MCP Servers
Model Context Protocol servers available in the workshop. Toggle which ones participants can access from the chat UI.
📄
Prompt Library
Pre-load prompts for workshop exercises. Participants access them from a slide-in panel in the chat interface.
💬
Conversations
Monitor all participant conversations in real time. Click any conversation to read the full exchange.
First time setup? Use the Setup Wizard (available from the Dashboard) to configure your tenant, retrieve providers and tokens, and get the workshop ready in minutes.

Netskope AI Gateway

The Netskope AI Gateway is a proxy between the chat portal and LLM providers. It enforces DLP policies, logs all AI traffic, and provides per-user visibility in the Netskope tenant console.

Secured mode

Participant
Chat Portal
→
This
Server
→
Netskope
AI Gateway
→
LLM
Provider

All traffic passes through the Netskope AI Gateway. Policies, DLP, and guardrails are enforced. The participant's GW token attributes the traffic to that user in the tenant console.

Direct mode

Participant
Chat Portal
→
This
Server
→
LLM
Provider

The gateway is bypassed entirely — no policies apply. Participants toggle between Secured and Direct from the chat header. The contrast is the core of the workshop demo.

GW Token attribution

Each participant's GW token is sent as the Authorization header in Secured mode. This lets Netskope attribute traffic per participant, apply user-level policies, and show individual usage in the tenant console.

The gateway URL must be reachable from the server's network — not the participant's browser. All AI requests are proxied server-side.

Dashboard

The Dashboard is the control center for the workshop. It shows at a glance whether everything is ready, who is leading the challenges, and overall participant activity.

Status

The Status card has two semaphore tiles and five readiness rows. The semaphores open Control Center; clicking a light changes state inline without leaving the dashboard. Each readiness row jumps to its section.

  • Capture the Flag (semaphore) — current CTF state: Stopped, Standby, or Run.
  • Registration (semaphore) — open or close participant self-registration.
  • Participants — green when at least one participant exists.
  • Prompt Library — green when at least one prompt is visible.
  • Challenges — green when at least one challenge is visible.
  • MCP Servers — green when at least one server is enabled.
  • AI Providers — green when at least one provider is visible.

Leaderboard

The live ranking of all participants by total points (wrong attempts cost −5; hint usage costs the configured hint penalty, −5 by default). Click any participant to open their challenge-detail sidebar. The header has two actions: Award ceremony (the fullscreen prize reveal) and Expand (fullscreen ranking with autorefresh).

Participant Activity Table

A quick summary of every participant: prompt usage (progress vs quota, secured vs direct), Capture the Flag progress, and total points. Useful for monitoring during the workshop without leaving the dashboard.

Setup Wizard — the Setup wizard button in the page header runs an 8-step wizard to configure the tenant, set the AI Gateway URL, retrieve providers and MCP servers, sync the Prompt Library and CTF templates, and get the workshop ready in minutes.

Participants

This section shows all registered workshop participants. Each participant has their own prompt quota, challenge progress, GW token, and conversation history tracked independently.

How participants join

Participants register themselves from the portal login screen. In Control Center open registration, set the Registration Code, and share it with participants — they click Register here to create their account. Their profile appears in this table immediately after registering.

Participant table columns

  • Token Group — the Netskope AI Gateway token group assigned to this participant.
  • Prompts Used — Progress — prompts sent vs. the global quota (e.g. 3/100).
  • Prompts Used — Secured / Direct — breakdown by mode: routed through AI Gateway vs. sent directly to the provider.
  • Prompts Used — Reset — clears the prompt counter for this participant.
  • Capture the Flag — Progress — number of challenges completed out of total visible.
  • Capture the Flag — Detail — opens a breakdown of which challenges were completed and any failed attempts.
  • Capture the Flag — Reset — resets all CTF progress for this participant: completions, penalties, and hints.
  • Policies in Netskope — Add / Delete — creates or removes the sample policy set for this participant in your Netskope tenant.
  • Delete — permanently removes the participant, all conversations, and all challenge data. Cannot be undone.

Bulk actions

Icon buttons in the column headers act on all participants at once:

  • Reset all prompt counters — clears prompt counts for every participant.
  • Reset all CTF progress — clears all challenge completions, penalties, and hints for all participants.
  • Delete all participants — removes all participants, conversations, and completions.
  • Create all policies in Netskope — runs policy creation for every participant in one operation.
  • Delete all policies in Netskope — removes all participant policies from the tenant.

Netskope sample policies

When you click Add policies for a participant, the portal creates three policy sets in your Netskope tenant, all scoped to that participant's GW token group. Names are derived from the participant's code (e.g. alice):

  • Access Control (alice) — restricts which AI providers the participant can reach.
  • Guardrails (alice Guardrails) — blocks crimes, PII, and jailbreak prompts on prompt and response.
  • DLP (alice DLP) — enforces GDPR and PCI-DSS profiles on upload, prompt, and response.

All policies are deployed automatically after creation. Operations are idempotent — running Add again updates existing policies in place.

The global prompt limit is set in Settings → Prompt Limit. Admin accounts are not subject to limits.
⚠ Netskope API actions — Add policies, Delete policies, Create all, and Delete all make live calls to your Netskope tenant. These operations are not local-only and cannot be undone from this portal.

Control Center

The cockpit for running the live session. From here you govern the game state, registration, what participants can see, and the climax actions — without touching configuration.

Control cards

  • Capture the Flag — semaphore for the global CTF state: Stop (challenges hidden from participants), Standby (visible but submissions paused), Run (active). The card background turns red / amber / green to match. Also mirrored on the Dashboard.
  • Registration — open or close participant self-registration. When closed, the registration code stops working.
  • Leaderboard — show or hide the leaderboard for participants. When hidden, their leaderboard button disappears; you (admin) always keep full access on the Dashboard and in the ceremony.
  • Registration Code — the shared code participants enter to register. Copy it or edit it inline.

Quick actions

  • 🏆 Launch Award Ceremony — a fullscreen, music-synced ranking reveal for the prize-giving moment. The runners-up appear one by one, then the podium is revealed 3rd → 2nd → 1st with confetti. Use the on-screen Start / Stop / Replay controls.
  • Open Leaderboard — the live ranking in fullscreen, ideal to project during the workshop. Includes an autorefresh toggle.
  • Reset CTF progress — clears every participant's completions, points and penalties. Asks for confirmation and cannot be undone.
The leaderboard ranks all participants — those with no completions appear at the bottom with their penalty-adjusted score.

Challenges

Challenges are the CTF exercises participants complete by triggering specific events in the Netskope AI Gateway — or by sending a specific keyword. The portal checks completion automatically when a participant clicks Check. The live game state (Stop / Standby / Run) is controlled from Control Center.

Challenge types

  • Access Control (also DLP and AI Guardrails) — query the Netskope event API. Completion requires a real AI Gateway event matching the configured Activity, Gateway Action, and Transaction Type within the lookback window.
  • Text — checks if the participant has sent a message containing the configured keyword. No Netskope connection needed — useful for offline or local-only workshops.

Creating a challenge

1
Title — short name shown to participants.
2
Description — what the participant needs to do to complete it.
3
Type — Access Control, DLP, AI Guardrails, or Text. Switching the type shows the relevant config fields.
4
Config (event types) — Activity (Prompt/Response, Upload, Download), Gateway Action (Allow, Block, etc.), and Transaction Type (Access, DLP, Guardrails).
4
Text key (Text type) — the exact keyword the participant must send in chat.
5
Lookback / Points — lookback window in minutes (10–60, default 30) and points awarded on completion (10–500, default 50).
6
Hint — optional text participants can reveal. Using a hint costs points (−5 by default, configurable by the admin).

Scoring and penalties

Total score = points earned − penalties. Each failed Check attempt deducts −5 points. Revealing a hint deducts the configured hint penalty (−5 by default; set in Control Center → Workshop Limits). Already-completed challenges are not re-checked.

Import / Export / Sync

Export downloads the full challenge list as CSV. Import bulk-loads challenges from a CSV file. Sync template from cloud replaces all current challenges with the pre-built workshop template — existing challenges will be deleted.

Delete all removes every challenge and all participant completions. This also runs automatically during a Factory Reset.

GW Tokens

Read-only view of the AI Gateway tokens linked to current participants. Tokens are managed automatically — no manual action is needed here during normal workshop operation.

How it works

When a participant registers, the portal automatically creates a dedicated token group and token in your Netskope tenant using the participant's username as the mnemonic (e.g. Participant-Group-ALICE / Participant-Token-ALICE). The token is stored locally and linked to that participant.

When a participant is deleted, their token and token group are automatically deleted from Netskope and removed from this table.

Token table

Shows all tokens currently linked to a participant. Columns: Token Group, Token Name, Token Value (truncated + copy button), Status, Assigned to, Expires.

Sync from Netskope

Imports tokens from your Netskope tenant into the local DB. Use this to reconnect the portal to an existing tenant after a fresh install or data migration where tokens already exist in Netskope.

Factory Reset deletes all tokens from both the local database and the Netskope tenant. Use it at the end of a workshop run to clean up.

AI Providers

AI Providers are the LLM backends available in the participant chat — OpenAI, Anthropic, DeepSeek, Mistral, and others. Synced from your Netskope tenant.

Sync from Netskope

Imports the providers configured in your AI Gateway tenant. Warning: syncing overwrites your current provider configuration — existing tokens, model selections, and visibility settings will be reset.

Row actions

  • Edit (models) — opens a modal listing all models available for that provider. Check or uncheck models to control exactly which ones participants can select in the chat dropdown.
  • API Token — shows Configured or Not set. Click to add or update the provider's API key used in Direct mode. Includes a Test button to verify the key works.
  • Visible — toggles the provider on/off for participants. Use the eye icon in the column header to show all at once.

MCP Servers

MCP Servers extend the participant chat with tool-calling capabilities — web search, file access, code execution, and more. The list is a local cache synced from your Netskope AI Gateway tenant on demand, so the page loads instantly and never stalls if the tenant is unreachable.

Sync from Netskope

Fetches the current server list from your Netskope tenant and stores it locally. Run it once at setup, and again whenever you add or remove MCP servers in the tenant. Visibility settings for servers that still exist are preserved.

Table columns

  • Name — the MCP server name as configured in Netskope.
  • Host — the server's host address.
  • Type — the server type (e.g. streamable-http).
  • Visible — toggles the server on/off for participants. Only visible servers appear in the participant's MCP dropdown. Use the eye icon in the column header to enable all at once.
MCP mode always routes through the gateway — the participant's GW token is used for attribution regardless of the Secured/Direct setting.

Prompt Library

The Prompt Library is a shared set of prompts pre-loaded by the admin. Participants access it from the chat interface to quickly send workshop exercises without typing manually.

Header buttons

  • Import — bulk-load prompts from a CSV file. Columns: text, visible.
  • Export — download all prompts as a CSV file. Columns: seq, text, visible.
  • Sync template from cloud — replaces all existing prompts with the workshop template. A confirmation is shown before proceeding.

Adding a prompt

Click the + button in the card header to open an inline row. Type the prompt text and click Create to save it.

Table columns

  • Drag handle — drag rows up or down to reorder. Participants see prompts in this sequence.
  • SEQ — current position in the list.
  • Prompt text — the message that will be inserted into chat.
  • Edit — opens the row inline to update the text. Click Save to confirm.
  • Delete — removes that prompt immediately. Use the trash icon in the column header to delete all prompts at once.
  • Visible — hidden prompts are preserved in the DB but not shown to participants. Use the eye icon in the column header to toggle all at once.
Participants open the Prompt Library from the chat header. Clicking a prompt inserts it directly into their chat input. Changes take effect immediately.

Conversations

Monitor all participant conversations in real time. Useful for live facilitation, spotting issues during the workshop, and post-session review.

Two-level navigation

1
Participant list — shows every participant with at least one conversation, their total conversation count, message count, and last activity time. Click Detail to drill in.
2
Conversation list — shows all conversations for that participant: title, message count, and timestamp. Click Detail to open the full transcript in a modal. Use ← Back to return to the participant list.

Transcript modal

Opens a modal showing every message in the conversation — role (user / assistant), content, and timestamp.

Delete actions

  • Delete all (column header, participant list) — permanently deletes every conversation from every participant.
  • Delete (per-participant row) — deletes all conversations for that participant.
  • Delete all (column header, conversation list) — deletes all conversations for the participant you are viewing.
  • Delete (per-conversation row) — removes that single conversation and its messages.
Conversations are stored locally in data.db and are never sent outside the configured AI provider.

Admins

Manage admin accounts for the workshop. Admins have full access to this panel, bypass the prompt quota, and are not visible to participants.

Creating an admin

1
Username — 5–12 characters, auto-uppercased (e.g. ALICE). This is the login code.
2
Display name — optional label shown in the table (e.g. Alice Smith).
3
Click Create. A popup shows the username, a randomly-generated password, and the API token. Save them immediately — the password is not stored in plain text and cannot be recovered.

Row actions

  • View token — shows the admin's API token for copying.
  • Reset password — generates a new random password and displays it once.
  • Enable / Disable — disabled accounts cannot log in. The row is dimmed. Not available for ADMIN-2026.
  • Delete — permanently removes the account. Not available for ADMIN-2026.

Bulk actions

  • Disable all — disables every admin except ADMIN-2026. Useful at the end of a session.
  • Delete all — permanently deletes every admin except ADMIN-2026.
ADMIN-2026 is the built-in default account and cannot be deleted or disabled. To replace it, create a new admin and use Disable all to lock out the default.

Global Settings

Core configuration for the workshop. Changes take effect immediately.

Netskope Tenant

Your tenant hostname (e.g. yourcompany.goskope.com) and REST API token. Required for syncing GW tokens, AI providers, and MCP servers from your Netskope console, and for creating or deleting participant policies. Use Test to verify before saving.

Minimum API token permissions required:
  • Read/Write — AI Gateway policies + AI Guardrails profiles
  • Read — Settings > Security Cloud Platform > AI Gateway
  • Read — Skope IT + Incidents

Netskope AI Gateway

The Gateway URL all Secured-mode requests are forwarded to (e.g. http://aigateway.lab:8080). Must be reachable from the server — all AI requests are proxied server-side, not from the participant's browser. Use Test to verify reachability before saving.

Cloud Template URLs

The remote URLs the portal fetches when you click Sync template from cloud in the Prompt Library or Challenges sections. Two separate fields: one for the Prompt Library template and one for the CTF challenges template. Use Test to verify both URLs are reachable, or Reset to default to restore the built-in values.

Workshop Limits

Prompts per participant (default: 100) — when reached, the participant sees a quota message and cannot send more. Admins are exempt. Reset individual counters from Participants, or reset all at once with the bulk reset button there.

Retries per challenge (default: 5) — max failed attempts before a 5-minute cooldown. After the cooldown the counter resets, but each new failure still deducts 5 points. Set to 0 for unlimited retries with no cooldown.

Demo Data

Creates 10 demo participants (DEMO-01 to DEMO-10) with pre-set challenge completions, 10 demo challenges, and 8 demo prompts — so you can preview the ranking and podium without a live workshop. Additive: existing participants and challenges are not overwritten.

Clear Database

Removes all workshop data from the local database without touching the Netskope tenant. Use this when the Netskope side is already clean or not applicable.

Deleted: participants, conversations, challenges, completions, prompt library.

Preserved: admin accounts, settings, GW tokens (unassigned but kept), AI providers, MCP servers.

Factory Reset

Full wipe of all workshop data — also cleans up the Netskope tenant. Only admin accounts are preserved.

  • Deletes all participants, conversations, and messages.
  • Deletes all challenges and completions.
  • Deletes all GW tokens from the local DB and from the Netskope tenant.
  • Deletes AI providers, MCP servers, and the prompt library.
  • Resets all settings to defaults (gateway URL, tenant, API token, prompt limit, CTF state).
Factory Reset is irreversible. Use it at the end of a workshop run to prepare for the next group.
—
Challenge progress
Activity timeline