local-first · v0.1

Policy Explorer

The OS security kernel: given an approved computer plan, should each action be permitted? Advisory decisions only — the runtime executes nothing. Read-only.

9
Evaluations
46
Actions judged
16
Need approval
8
Denied
Cross-surface enforcement (POLICY-EXT)74 subjects14 denied34 approve
filesystem:fs-pipelinerequires_approval
compliance-strict · enforce · 5 subjects · checksum 87f5ebdf
4 allow1 approve

Policy "compliance-strict" (enforce) on filesystem "fs-pipeline": 4 allowed, 1 need approval, 0 denied (0 unresolved, fail-closed) → requires_approval. Advisory until the Broker exists.

filesystem:fs-archiverequires_approval
restricted-analyst · enforce · 5 subjects · checksum 7a7e823c
0 allow5 approve2 destructive

Policy "restricted-analyst" (enforce) on filesystem "fs-archive": 0 allowed, 5 need approval, 0 denied (0 unresolved, fail-closed) → requires_approval. Advisory until the Broker exists.

The Policy Runtime owns approval rules, RBAC/org permissions, token/monetary budgets, rate limits, compliance regimes, maintenance windows, dry-run/simulation, emergency stop, rollback and secret requirements — and returns decisions only. It never executes. POLICY-EXT (ADR-0079) extends the same kernel to judge MCP, Terminal, and Filesystem sessions as normalized policy subjects; unresolved references fail closed; decisions remain advisory until the future Vault → Approval → Broker chain makes allow binding.