AgentGate Labs
Menu

Explore the control plane

Four interactive product views using one consistent set of calculated sample decisions.

Sample data · no real customer records

1. Policy list

Rules are checked in order and the first match decides. Built-in packs run first, custom rules next, and anything unmatched is denied.

OrderRuleTypeReasonAction
1secret-protectionBuilt-in packThe call targets or contains secret material.DENY
2restricted-productionBuilt-in packDestructive or write actions against production are denied.DENY
3financial-actions-require-approvalCustom ruleProduction refunds need a qualified reviewer.APPROVAL_REQUIRED
4internal-app-access-requires-approvalCustom ruleInternal admin apps need a qualified reviewer.APPROVAL_REQUIRED
5developer-safe-defaultsBuilt-in packRead-only development calls are allowed by safe defaults.ALLOW
6default-denyBuilt-in packNo active policy allowed this tool call.DENY

2. Tool-call decision log

Each decision names the rule that produced it. The risk score is recorded alongside as reviewer context.

TimeAgentToolDecisionMatched ruleRisk context
09:41:00sample-coding-agentshell.execDENYrestricted-production100
09:41:05sample-coding-agentpostgres.queryDENYrestricted-production80
09:41:10sample-coding-agentgithub.read_fileALLOWdeveloper-safe-defaults10
09:41:15sample-coding-agentstripe.refundAPPROVAL_REQUIREDfinancial-actions-require-approval70
09:41:20sample-coding-agentbrowser.navigateAPPROVAL_REQUIREDinternal-app-access-requires-approval60

3. Approval review

Sample data · browser-only simulation

Rules are checked in the same order as the production engine: built-in packs, then custom rules, then default deny. The first matching rule decides; the risk score is recorded as context for reviewers.

Inspect a tool call

{
  "id": "postgres",
  "tool": "postgres.query",
  "environment": "production",
  "sensitivity": 30,
  "arguments": {
    "query": "UPDATE example_invoices SET status = 'reviewed' WHERE id = 42"
  },
  "flags": [
    "write"
  ]
}

Ready to inspect a sample call.

  1. Run the inspection to see which rules are checked.

No rule evaluated yet.

Risk context: 0 / 100
  • Run the inspection to see each contributing factor.

Approval expiry starts only for decisions requiring review.

Scenario audit evidence

[]
Compare all five scenarios and matched rules
ToolEnvironmentMatched ruleDecisionRisk context
shell.execproductionrestricted-productionDENY100
postgres.queryproductionrestricted-productionDENY80
github.read_filedevelopmentdeveloper-safe-defaultsALLOW10
stripe.refundproductionfinancial-actions-require-approvalAPPROVAL_REQUIRED70
browser.navigateproductioninternal-app-access-requires-approvalAPPROVAL_REQUIRED60

4. Audit review and export

5 sample events

[
  {
    "id": "scenario-1",
    "time": "09:41:00",
    "agent": "sample-coding-agent",
    "tool": "shell.exec",
    "decision": "DENY",
    "rule": "restricted-production",
    "risk": 100,
    "synthetic": true
  },
  {
    "id": "scenario-2",
    "time": "09:41:05",
    "agent": "sample-coding-agent",
    "tool": "postgres.query",
    "decision": "DENY",
    "rule": "restricted-production",
    "risk": 80,
    "synthetic": true
  },
  {
    "id": "scenario-3",
    "time": "09:41:10",
    "agent": "sample-coding-agent",
    "tool": "github.read_file",
    "decision": "ALLOW",
    "rule": "developer-safe-defaults",
    "risk": 10,
    "synthetic": true
  },
  {
    "id": "scenario-4",
    "time": "09:41:15",
    "agent": "sample-coding-agent",
    "tool": "stripe.refund",
    "decision": "APPROVAL_REQUIRED",
    "rule": "financial-actions-require-approval",
    "risk": 70,
    "synthetic": true
  },
  {
    "id": "scenario-5",
    "time": "09:41:20",
    "agent": "sample-coding-agent",
    "tool": "browser.navigate",
    "decision": "APPROVAL_REQUIRED",
    "rule": "internal-app-access-requires-approval",
    "risk": 60,
    "synthetic": true
  }
]