frontend/src/lib/guidedDemo.tsFIELD-OFF IMPACT PATH
- 1ungoverned_agent
read_file · frontend/src/lib/guidedDemo.tsThe same proposed action proceeds unchanged. The allowed tool call proceeds as proposed.
none
THE LIVING FIELD
The gateway evaluates each proposed tool call before execution; policy precedence determines how far that intent can travel.
SCROLL TO THE FIELD INSTRUMENTS
INSTRUMENT I · THE LINES OF FORCE
Read from the outside inward: the strongest precedence is outermost, and a particle falls until one decisive line claims it.
INSTRUMENT II · RECORDED STORMS
Open a plate to inspect the exact proposal, recorded rule evidence, and measured verdict behind its trajectory.
frontend/src/lib/guidedDemo.tsALLOW · ALLOWOPEN OBSERVATIONfrontend/src/hooks/useGuidedDemo.tsALLOW · ALLOWOPEN OBSERVATIONbackend/app/runtime_bridge.pyALLOW · ALLOWOPEN OBSERVATIONgrep runtime_unavailable backend/appALLOW · ALLOWOPEN OBSERVATIONgit status --shortALLOW · ALLOWOPEN OBSERVATIONfrontend/src/lib/guidedDemo.tsREQUIRE_APPROVAL · HOLDOPEN OBSERVATIONcd frontend && npm run buildREQUIRE_APPROVAL · HOLDOPEN OBSERVATIONDEPLOYMENT.mdREQUIRE_APPROVAL · HOLDOPEN OBSERVATIONbackend/DockerfileREQUIRE_APPROVAL · HOLDOPEN OBSERVATIONgit commit -m 'deploy config'REQUIRE_APPROVAL · HOLDOPEN OBSERVATION.envDENY · DENYOPEN OBSERVATIONCANONICAL DENIED OBSERVATION
../vaultline/src/vaultline/store.pyDENY · DENYOPEN OBSERVATIONbackend/DockerfileDENY · DENYOPEN OBSERVATIONbackend/app/context_firewall.pyDENY · DENYOPEN OBSERVATIONfrontend/dist/index.htmlDENY · DENYOPEN OBSERVATIONbackend/app/context_firewall.pyDENY · DENYOPEN OBSERVATIONINSTRUMENT III · IF THE FIELD FELL
The proposal is measured input; each impact path is a deterministic projection from the recorded shadow timeline and was never executed.
DERIVED · DETERMINISTIC, NOT OBSERVED · NEVER EXECUTEDfrontend/src/lib/guidedDemo.tsread_file · frontend/src/lib/guidedDemo.tsThe same proposed action proceeds unchanged. The allowed tool call proceeds as proposed.
nonefrontend/src/hooks/useGuidedDemo.tsread_file · frontend/src/hooks/useGuidedDemo.tsThe same proposed action proceeds unchanged. The allowed tool call proceeds as proposed.
nonebackend/app/runtime_bridge.pyread_file · backend/app/runtime_bridge.pyThe same proposed action proceeds unchanged. The allowed tool call proceeds as proposed.
nonegrep runtime_unavailable backend/appgrep · grep runtime_unavailable backend/appThe same proposed action proceeds unchanged. The safe read-only command proceeds as proposed.
nonegit status --shortgit_status · git status --shortThe same proposed action proceeds unchanged. The safe read-only command proceeds as proposed.
nonefrontend/src/lib/guidedDemo.tswrite_file · frontend/src/lib/guidedDemo.tsThe same proposed action proceeds without waiting for approval. The approval-gated action changes state without review.
mediumcd frontend && npm run buildrun_check · cd frontend && npm run buildThe same proposed action proceeds without waiting for approval. The approval-gated action changes state without review.
mediumDEPLOYMENT.mdwrite_file · DEPLOYMENT.mdThe same proposed action proceeds without waiting for approval. The approval-gated action changes state without review.
mediumbackend/Dockerfilewrite_file · backend/DockerfileThe same proposed action proceeds without waiting for approval. The approval-gated action changes state without review.
mediumgit commit -m 'deploy config'git_commit · git commit -m 'deploy config'The same proposed action proceeds without waiting for approval. Repository history changes without waiting for approval.
medium.envnetwork_exfil · .envThe same proposed action proceeds despite the denial. The action reaches a secret-bearing target without the governed boundary.
critical../vaultline/src/vaultline/store.pyread_file · ../vaultline/src/vaultline/store.pyThe same proposed action proceeds despite the denial. The action crosses the repository boundary and reaches a sibling repository.
highbackend/Dockerfilegit_push · backend/DockerfileThe same proposed action proceeds despite the denial. The push reaches remote history without a governance checkpoint.
highbackend/app/context_firewall.pydelete_path · backend/app/context_firewall.pyThe same proposed action proceeds despite the denial. The destructive command removes the targeted files or state.
criticalfrontend/dist/index.htmlwrite_file · frontend/dist/index.htmlThe same proposed action proceeds despite the denial. Generated dependency, cache, or build material is mutated directly.
mediumbackend/app/context_firewall.pynetwork_exfil · backend/app/context_firewall.pyThe same proposed action proceeds despite the denial. The network action crosses the governed network boundary.
criticalINSTRUMENT IV · AIM ONE PARTICLE
Choose verb, resource, and context from the table dimensions; launch reads the one exact precomputed row at their intersection.
The card below is the table row’s canonical proposal; no client policy is evaluated here.
task.context_match · scope.in_repo · tool.allowed · risk.low_allowed
DECISIVE LINE · MEASUREDtool.allowedThe proposal uses a tool listed in the session's allowed-tool policy. This supports an allow only when no stricter rule applies.
Read context as quadrant-wind, verb as sector, and resource as ring; choose any trajectory to aim the launcher at that same row.