/opt/tools/execution-broker

Controlled Lab · Simulation Only

The model proposes. The broker decides.

Explore how scope, identity, side effects, approval, and recovery change an AI pentest tool decision. This lab runs entirely in your browser. It has no target connectivity, credentials, shell, cloud API, or directory integration.

Control plane

Reasoning is not authorization

The model never receives a general-purpose privileged session.

  1. 01ProposalOperation, target, reason
  2. 02ResolveScope, identity, objects
  3. 03ClassifyRead, reversible, destructive
  4. 04DecideAllow, hold, or deny
  5. 05RecordCapability or explicit denial
Interactive policy

Execution decision workbench

Choose a proposal, change one control, and observe the policy result.

Resolved proposaldirectory.object.inspect
Deterministic gates
L1ALLOW

Bounded read capability issued

One short-lived audit reader capability, limited to 50 objects.

Policy reasons
  • READ_ONLY_BOUNDED — scope, identity, worker isolation, and result cap passed policy.
Evidence record
  • Original proposal and resolved operation
  • Policy decision with reason codes
  • Engagement, scope, identity, and object count
  • Short-lived capability ID and expiry
  • Worker result plus independent verification
Generated locally. No proposal leaves the browser.
Field kit

Take the controls into an engagement

Start with the contract and evidence record, then adapt them to the authorized environment.

These artefacts are templates, not authorization. Adapt them to written rules of engagement, validate every identity and target locally, and keep destructive or Domain Admin execution outside the autonomous path.

Source basis

Protocol guidance informs the lab; policy still belongs to the operator.