Demo data is simulated for security. No live gate or external actions.

THE MEMBRANE OPERATOR AUDIT
READ ONLY← Home

OBSERVE. DON'T OVERRIDE.

Every boundary, visible.

Only verified calls are allowed. Everything else is stopped at the gate. Read-only visibility, no write access.

UNKNOWN

Starting stream

THE AUTHORIZATION BOUNDARY

One gate. Every attempted crossing.

Traffic from six agent identities. Only verified calls cross the gate; the rest are stopped at it.

6 agent identities0 crossed0 stopped at the gate
Authorization boundary mapSix agent identities make a continuous stream of chat and tool attempts. Allowed attempts cross the membrane to an action boundary. Denied attempts are stopped at the membrane. Destinations are illustrative action categories, not verified services. REQUESTING IDENTITIESMEMBRANEACTION BOUNDARIES AUTHORIZATION GATE Agent identitiesbilling-agentsupport-triagecode-review-botdata-sync-jobresearch-agentrelease-bot 00 CHAT · 0 crossedTOOL · 0 crossed 0 stopped0 stopped Chat channel Tool boundary
Paths through the membraneSix agent identities make a continuous stream of chat and tool attempts. Allowed attempts cross the membrane. Denied attempts are stopped at the gate. Agent identities010203040506 MEMBRANE · AUTHORIZATION GATE 00 0 stopped0 stopped ChatTool 0 crossed0 crossed

Waiting for the first decision.

Only verified calls cross the gate; the rest stop at the boundary.

Gate liveness

Unknown

No checkpoint data

Decisions retained

-

Rolling decision buffer

Deny rate (last 60s)

-

Rolling 60-second window

Observed since start

-

Decisions since page load

Decision log

Newest first. Rule codes, not request bodies. Latest 5 shown, 30 retained.

Time (local)DecisionRule matchedActionGate identity / scope
No decisions yet.

Loaded policy

Policy registry. Configuration stays in files.

VIEW ONLY
Source
Waiting for policy

The registry is one authorization layer. Signed per-request IAC scopes can restrict it further; this is not a view of every agent's effective permissions.