Specify Work · Security

Stop the commands you name before they run.

Security is the planned policy gate for agent commands: deploys, secret rotation, force-pushes and destructive operations will be checked against your policy on the machine, denied or escalated, with every decision on the record. Enforcement needs the Guard adapter on each machine; Work will show the record of decisions. Memory opens first; Security follows.

See it in Security

Example content, not a live workspace. Some illustrated features are not available yet.

Specify Work › Security › What ranPlanned

Denied and escalated

What ran

1 escalation open
  1. deploy 24.3 --env productionDenied · escalatedM. Reyes · Production changes
  2. rotate secret payments-webhookException · 08:50J. Okafor · Secrets
  3. git push --delete origin hotfix-24.2Declined · MonA. Lind · Branch protection
  4. read incident-logObserved · 09:18J. Okafor · Observed only

Escalation · for D. Marsh

Deploy 24.3 to production

Denied
09:44 · Production changes · logged
Requested by
M. Reyes · plan step 4 · still working
Evidence
verify log 09:41 · 212 tests passed · brief reviewed
Retries since
None
If this policy had applied for 30 days4 denials · 2 exceptions · 0 sessions blocked
Grant exceptionDecline

The decision lands on the approved log with this evidence. A retry passes only after that.

  1. Decision example

    The sample record shows a command and its policy decision. It does not report activity from your devices.

  2. Exception example

    The illustration places the request beside the event that prompted it. It is not a live approval control.

  3. Simulation example

    The comparison uses sample events. User-facing simulation requires separately enabled Security access.

The planned command gate

  1. Cover

    Connect the machine.

    Install the Guard adapter and verify coverage for the enabled client integration.

  2. Check

    Apply the named policy.

    The gate checks covered commands against a policy revision before execution.

  3. Decide

    Deny or review an exception.

    An authorized exception applies only to its defined action and authority.

  4. Record

    Keep the reason with the decision.

    Work will show the decision record. Execution needs its own result evidence.

What the product handles

  • Command policy

    The planned gate checks covered deploys, secret rotation, force-pushes and destructive operations against named rules.

  • Denials and exceptions

    A denied command and a scoped exception keep their policy revision and reason together. Runtime enforcement depends on installed coverage.

  • Decision records

    Work is intended to show what was allowed, denied or escalated. A policy decision is evidence of a check, not proof that a command completed.

Limits

Command coverage
Command enforcement requires a separately installed adapter. Signing in does not install Guard or intercept commands in your agent client.
Security rollout
Adapter coverage, simulation and exports depend on enabled services and installed integrations. Check coverage before relying on command enforcement.

Read the security boundaries.

Sign-in, policy decisions and event records have different responsibilities. These notes explain their limits.

Start the record.

Create your account now. Memory opens first; you will see each product as it becomes available.

Create your accountSee what is open now