Agent Firewall

Security control plane

version
depth policy
decision source
Local inspection console. Read-only view of the existing authorization implementation. It makes no security decisions of its own — every verdict below is returned by the SDK. Cryptographic material is withheld. No authentication; bind to loopback only.

North Star pipeline

Ordered gates read from _authorization_gate_phases() — not a hardcoded diagram.

passed denied not reached

    Decision

    awaiting request

    Delegation authority

    Risk & security posture

    Capabilities

    Signatures and public keys are withheld by the projection layer.

    Lifecycle & evidence

    Append-only event record, newest first.

    Authorization trace

    Canonical SecurityDecision as returned.

    Security flight recorder v1.8

    Portable, cryptographically verifiable security history. The artifact records what happened and why; verification, replay, and the graph are derived from recorded events only.

    Agent security timeline

    Every event is inspectable: from timeline to event to decision to authority chain to evidence.

    Security trajectory

    How posture changed, and the evidence for every transition.

    Security relationship graph

    Derived from recorded authority and decisions. Why could this agent do this? What could it reach?

    Containment

    Explicit state transitions, audited. Mutations go through the control plane.

    Replay laboratory

    Ask what would have happened under a different policy. Replay runs the real authorization pipeline in throwaway workspaces.