THE MEMBRANE OPERATOR AUDIT
Simulated traffic / synthetic data← Home

OBSERVE. DON'T OVERRIDE.

Every boundary, visible.

What a gate looks like in the field: a steady stream of decisions, most allowed, a few stopped. Simulated traffic, no controls, no write access.

UNKNOWN

Starting simulation

THE AUTHORIZATION BOUNDARY

One gate. Every attempted crossing.

Simulated traffic from six invented agent identities. Allowed calls cross the gate; denied calls are stopped at it. Not a network inventory.

6 simulated identities0 crossed0 stopped at the gateSIMULATED TRAFFIC / NOT A LIVE GATE
Simulated authorization boundary mapSix invented agent identities make a continuous stream of simulated chat and tool attempts. Allowed attempts cross the membrane to an action boundary. Denied attempts are stopped at the membrane. Destinations are illustrative action categories, not verified services. REQUESTING IDENTITIESMEMBRANEACTION BOUNDARIES AUTHORIZATION GATE Simulated agentsbilling-agentsupport-triagecode-review-botdata-sync-jobresearch-agentrelease-bot 00 CHAT · 0 crossedTOOL · 0 crossed 0 stopped0 stopped Chat channel Tool boundary
Simulated paths through the membraneSix invented agent identities make a continuous stream of simulated chat and tool attempts. Allowed attempts cross the membrane. Denied attempts are stopped at the gate. Simulated agents010203040506 MEMBRANE · AUTHORIZATION GATE 00 0 stopped0 stopped ChatTool 0 crossed0 crossed

Waiting for the first simulated decision.

Simulated live traffic. No agent is running and no requests are sent.

Gate liveness

Unknown

No checkpoint data

Decisions retained

-

Rolling buffer of simulated decisions

Deny rate (last 60s)

-

Simulated window

Observed since start

-

Simulated since page load, not real traffic

Decision log

Newest first. Rule codes, not request bodies. Simulated decisions, newest 30 shown.

Time (local)DecisionRule matchedActionGate identity / scope
No verified decisions yet.

Loaded policy

Registry loaded by the running gate. Configuration stays in files.

VIEW ONLY
Source
Waiting for gate

The registry is one authorization layer. Signed per-request IAC scopes can restrict it further; this is not a view of every agent's effective permissions.