Specify Work · Security
Stop the commands you name before they run.
Security is the planned policy gate for agent commands: deploys, secret rotation, force-pushes and destructive operations will be checked against your policy on the machine, denied or escalated, with every decision on the record. Enforcement needs the Guard adapter on each machine; Work will show the record of decisions. Memory opens first; Security follows.
See it in Security
Example content, not a live workspace. Some illustrated features are not available yet.
Denied and escalated
What ran
- 1
deploy 24.3 --env productionDenied · escalatedrotate secret payments-webhookException · 08:50git push --delete origin hotfix-24.2Declined · Monread incident-logObserved · 09:18
Escalation · for D. Marsh
Deploy 24.3 to production
- Denied
- 09:44 · Production changes · logged
- Requested by
- M. Reyes · plan step 4 · still working
- Evidence
- verify log 09:41 · 212 tests passed · brief reviewed
- Retries since
- None
The decision lands on the approved log with this evidence. A retry passes only after that.
Decision example
The sample record shows a command and its policy decision. It does not report activity from your devices.
Exception example
The illustration places the request beside the event that prompted it. It is not a live approval control.
Simulation example
The comparison uses sample events. User-facing simulation requires separately enabled Security access.
The planned command gate
Cover
Connect the machine.
Install the Guard adapter and verify coverage for the enabled client integration.
Check
Apply the named policy.
The gate checks covered commands against a policy revision before execution.
Decide
Deny or review an exception.
An authorized exception applies only to its defined action and authority.
Record
Keep the reason with the decision.
Work will show the decision record. Execution needs its own result evidence.
What the product handles
Command policy
The planned gate checks covered deploys, secret rotation, force-pushes and destructive operations against named rules.
Denials and exceptions
A denied command and a scoped exception keep their policy revision and reason together. Runtime enforcement depends on installed coverage.
Decision records
Work is intended to show what was allowed, denied or escalated. A policy decision is evidence of a check, not proof that a command completed.
Limits
- Command coverage
- Command enforcement requires a separately installed adapter. Signing in does not install Guard or intercept commands in your agent client.
- Security rollout
- Adapter coverage, simulation and exports depend on enabled services and installed integrations. Check coverage before relying on command enforcement.
Read the security boundaries.
Sign-in, policy decisions and event records have different responsibilities. These notes explain their limits.
Start the record.
Create your account now. Memory opens first; you will see each product as it becomes available.
Create your accountSee what is open now