Explore the control plane
Four interactive product views using one consistent set of calculated sample decisions.
Sample data · no real customer records
1. Policy list
Rules are checked in order and the first match decides. Built-in packs run first, custom rules next, and anything unmatched is denied.
| Order | Rule | Type | Reason | Action |
|---|---|---|---|---|
| 1 | secret-protection | Built-in pack | The call targets or contains secret material. | DENY |
| 2 | restricted-production | Built-in pack | Destructive or write actions against production are denied. | DENY |
| 3 | financial-actions-require-approval | Custom rule | Production refunds need a qualified reviewer. | APPROVAL_REQUIRED |
| 4 | internal-app-access-requires-approval | Custom rule | Internal admin apps need a qualified reviewer. | APPROVAL_REQUIRED |
| 5 | developer-safe-defaults | Built-in pack | Read-only development calls are allowed by safe defaults. | ALLOW |
| 6 | default-deny | Built-in pack | No active policy allowed this tool call. | DENY |
2. Tool-call decision log
Each decision names the rule that produced it. The risk score is recorded alongside as reviewer context.
| Time | Agent | Tool | Decision | Matched rule | Risk context |
|---|---|---|---|---|---|
| 09:41:00 | sample-coding-agent | shell.exec | DENY | restricted-production | 100 |
| 09:41:05 | sample-coding-agent | postgres.query | DENY | restricted-production | 80 |
| 09:41:10 | sample-coding-agent | github.read_file | ALLOW | developer-safe-defaults | 10 |
| 09:41:15 | sample-coding-agent | stripe.refund | APPROVAL_REQUIRED | financial-actions-require-approval | 70 |
| 09:41:20 | sample-coding-agent | browser.navigate | APPROVAL_REQUIRED | internal-app-access-requires-approval | 60 |
3. Approval review
Sample data · browser-only simulation
Rules are checked in the same order as the production engine: built-in packs, then custom rules, then default deny. The first matching rule decides; the risk score is recorded as context for reviewers.
Inspect a tool call
{
"id": "postgres",
"tool": "postgres.query",
"environment": "production",
"sensitivity": 30,
"arguments": {
"query": "UPDATE example_invoices SET status = 'reviewed' WHERE id = 42"
},
"flags": [
"write"
]
}Ready to inspect a sample call.
- Run the inspection to see which rules are checked.
No rule evaluated yet.
Risk context: / 100
- Run the inspection to see each contributing factor.
Approval expiry starts only for decisions requiring review.
Scenario audit evidence
[]
First protected call! Your sample decision is recorded.
Compare all five scenarios and matched rules
| Tool | Environment | Matched rule | Decision | Risk context |
|---|---|---|---|---|
| shell.exec | production | restricted-production | DENY | 100 |
| postgres.query | production | restricted-production | DENY | 80 |
| github.read_file | development | developer-safe-defaults | ALLOW | 10 |
| stripe.refund | production | financial-actions-require-approval | APPROVAL_REQUIRED | 70 |
| browser.navigate | production | internal-app-access-requires-approval | APPROVAL_REQUIRED | 60 |
4. Audit review and export
5 sample events
[
{
"id": "scenario-1",
"time": "09:41:00",
"agent": "sample-coding-agent",
"tool": "shell.exec",
"decision": "DENY",
"rule": "restricted-production",
"risk": 100,
"synthetic": true
},
{
"id": "scenario-2",
"time": "09:41:05",
"agent": "sample-coding-agent",
"tool": "postgres.query",
"decision": "DENY",
"rule": "restricted-production",
"risk": 80,
"synthetic": true
},
{
"id": "scenario-3",
"time": "09:41:10",
"agent": "sample-coding-agent",
"tool": "github.read_file",
"decision": "ALLOW",
"rule": "developer-safe-defaults",
"risk": 10,
"synthetic": true
},
{
"id": "scenario-4",
"time": "09:41:15",
"agent": "sample-coding-agent",
"tool": "stripe.refund",
"decision": "APPROVAL_REQUIRED",
"rule": "financial-actions-require-approval",
"risk": 70,
"synthetic": true
},
{
"id": "scenario-5",
"time": "09:41:20",
"agent": "sample-coding-agent",
"tool": "browser.navigate",
"decision": "APPROVAL_REQUIRED",
"rule": "internal-app-access-requires-approval",
"risk": 60,
"synthetic": true
}
] 