GIOS Studioalpha · read-only
Policy Explorer
The OS security kernel: given an approved computer plan, should each action be permitted? Advisory decisions only — the runtime executes nothing. Read-only.
9
Evaluations
46
Actions judged
16
Need approval
8
Denied
Web research (allow)allowed
default-enforce · enforce · 6 actions
6 allowrisk low
Web form (approval)requires_approval
default-enforce · enforce · 6 actions
2 allow4 approverisk high
Terminal (RBAC deny)denied
restricted-analyst · enforce · 3 actions
1 allow2 denyrisk critical
Filesystem (compliance)requires_approval
compliance-strict · enforce · 4 actions
2 allow2 approverisk high
Desktop (dry-run)requires_approval
default-enforce · dry_run · 5 actions
2 allow3 approverisk high
Vision + OCR (allow)allowed
default-enforce · enforce · 4 actions
4 allowrisk low
Input gestures (emergency stop)denied
emergency-stop · enforce · 6 actions
0 allow6 denyrisk medium
Web research (budget)requires_approval
tight-budget · enforce · 6 actions
3 allow3 approverisk low
Web form (simulation)requires_approval
default-enforce · simulation · 6 actions
2 allow4 approverisk high
Cross-surface enforcement (POLICY-EXT)74 subjects14 denied34 approve
The Policy Runtime owns approval rules, RBAC/org permissions, token/monetary budgets, rate limits, compliance regimes, maintenance windows, dry-run/simulation, emergency stop, rollback and secret requirements — and returns decisions only. It never executes. POLICY-EXT (ADR-0079) extends the same kernel to judge MCP, Terminal, and Filesystem sessions as normalized policy subjects; unresolved references fail closed; decisions remain advisory until the future Vault → Approval → Broker chain makes allow binding.