Configuration and source analysis
Read-only review within the supplied scope. Record source provenance and avoid copying unnecessary sensitive values.
Defensive planning for authorized work
Define permission, checkpoints, evidence, budgets, and recovery before an audit agent spends its first token.
Every required boundary stays visible before local simulation begins.
State the permission boundary in plain language.
Stop before uncertainty consumes the remainder.
The run will pause before the review threshold.
Save enough state to resume safely.
Attach provenance without leaking secrets.
Preview redaction locally before export.
Redacted output appears here.
These categories plan review and evidence only. They never execute security actions.
Read-only review within the supplied scope. Record source provenance and avoid copying unnecessary sensitive values.
Any active validation must be separately authorized, manually reviewed, and performed outside this planner using approved organizational procedures.
Collect only what is necessary, use test data where possible, redact evidence, and follow the selected retention policy.
Exploit execution, bypass attempts, destructive testing, persistence, credential attacks, evasion, and out-of-scope scanning are excluded.
A useful checkpoint explains what was authorized, what evidence was captured, what consumed the budget, why the next step stopped, and exactly what a reviewed resume may do next.
Complete authorization to make the plan ready.
Record one before sensitive or expensive work so a reviewed resume starts from known state.
The export contains the plan, redacted evidence, checkpoints, budget snapshots, policy decisions, and state transitions.