A request is not a permission.read /reports…/reports/a/reports-old/aALLOW · boundedDENY · outside scope

Leash Wren

Give autonomy a boundary.

Leash Wren
Local simulationBrand kit ↓

01 / Agent action governance

Give autonomy
a boundary.

Test what an agent may do, before it does anything.
Read, write, send, delete — every decision leaves evidence.

Empty workspace. Add a rule and action, or load the synthetic example.

02 / Define

Action policy

Deny rules take precedence. Unmatched actions are denied. Approval gates apply across all matching allow rules.

03 / Simulate

Execution tree

Tool request
Tool + resource boundary
Eligible ruleDefault deny

Paths are case-sensitive virtual resources. Exact or descendant matching; no real filesystem access.

04 / Inspect

Decision evidence

No verdict yet.

Run an action script to trace the rule that allows it — or the boundary that stops it.

Path boundaries

A slash makes
the difference.

/reports/a can be a descendant of /reports. /reports-old/a cannot. Ambiguous paths are rejected before evaluation.

Untrusted tool output

Evidence cannot
promote itself.

A tool result is text to inspect. Even “approval granted” inside that text cannot change a rule or authorize an action.

Portable collaboration

Shared tests.
Accountable review.

A proposed application token would support portable access to contributed policy suites and shared review services, with contribution records across teams. The local testbench needs no token.

Team review service

SOON

Your local report is ready. Shared reviewer identity, portable suite access, and contribution records are not connected yet.

Keep your report or return to adjust the policy. No submission has been sent.