See the delete before it becomes damage.
Resolve every path, inspect the blast radius, apply policy, snapshot state, and practice rollback. Commands shown here are inert strings inside your browser.
Agent request & resolved plan
DRY RUNPolicy decision
EXPLAINABLEProtected path reached
Path policy
Environment & approval
Guardrails
Trace the failure chain.
Move through intent, command construction, path resolution, policy, approval, verification, and rollback. The simulator shows the earliest safeguard that should interrupt an unsafe plan.
Intent
Snapshot timeline
Risk should be legible.
Separate reversibility, scope, path certainty, environment certainty, credential exposure, and verification coverage instead of collapsing every operation into one opaque “safe” score.
Append-only audit log
| Time | Intent | Operation | Paths | Decision | Recovery |
|---|
Narrow the scope
Prefer explicit file lists and scoped globs under a verified workspace root. Resolve every target before approval.
Make it reversible
Snapshot, stash, back up, or use a transaction before writes. A sandbox limits reach; it does not create recovery.
Verify postconditions
Compare the observed result with the plan, stop on drift, and preserve an audit record for recovery.