Demo
It is a deployment, not a screenshot.
Agents run on it every day, ask for authority, get refused, and the evidence is sealed. Nothing on it was inserted. Every record came from a program running through the published SDK against the real API — and a test fails the build if any demo script constructs a governed record directly.
Access
Read-only, and we will know it was you.
A work address, one click, and you are signed in as auditor —
the role that reads everything, exports evidence packs, and changes
nothing. It cannot write because it is absent from the platform's write
roles, not because a setting says so. That is the same reason an audit
cannot alter what it audits.
The link works once and lasts 24 hours · What we do with the address
Four things worth ten minutes
A refusal, and why
Open a trajectory that ends in a refusal and read what each of the
nine gates did. The interesting ones stop at budget
because an ancestor grant was exhausted — the agent was inside
its own ceiling and the tree was not.
The red-team grid
Our own identifier detector, attacked, with the cells it fails published and classified as defect or residual. Computed live when you load the page, so it cannot be a stale claim.
observed →Readiness, scoped to a regime
Two instruments scored and two listed but marked unselected, with the sentence explaining whose determination that is. A number scoped to the regime rather than to everything we happen to map.
observed →A grant that was renewed
Authority runs down as agents use it. When it does, a named person re-issues it over OIDC — the API refuses a service principal on that route — and both grants are on the page with the spend intact.
observed →What it is not
It is a demo instance with synthetic tickets, invented companies and no real personal data anywhere. The agents are real, the decisions are real and the evidence is real; the business is fictional. Every identifier used to test the detector is synthetic and checksum-valid, and no real one is used, stored or transmitted.