The policy engine, running in your browser.
Pick an agent and an action. The same deterministic evaluation GeraGuard applies at enforcement points runs here: hard restrictions first, then approval requirements, then allow rules. Every decision produces an evidence record.
1 · Agent session
2 · Proposed action
Blocked: raw secret retrieval
The agent tried to read .env.production. Under policy protect-secrets, agents never receive raw production credentials — they request brokered operations instead. This is a hard deny; no approval path exists for raw reads.
Identity resolved
Session bound to maya@acme.co · Claude Code · task scope "fix auth bug". Missing identity would deny by default.
Hard deny: raw secret retrieval
Resource ".env.production" is classified SECRET. Policy protect-secrets denies raw retrieval. The agent must request a brokered, scoped credential instead.
session_id ag_8f2c1e41 agent Claude Code policy coding_session_v1 policy_rev rev 17 · signed action Read .env.production resource .env.production operation read decision DENY rule protect-secrets approval n/a (hard deny) digest sha:7d11…c4
This demo evaluates the same rule order as the production policy engine: explicit deny first, approval requirements second, allow rules last. Missing identity or a stale approval never silently becomes an allow. See the full policy library →