Policy enforcement
Policy is evaluated on the request path, not reconciled afterwards. A decision that cannot be evaluated is refused rather than allowed pending review.
Enforcement — Guard
Security is active, continuous and policy-driven.
Guard enforces policy at the boundary: identity, tenant and workspace isolation, privileged activity control, secure execution limits and automatic response to anomalous behaviour.
Policy is evaluated on the request path, not reconciled afterwards. A decision that cannot be evaluated is refused rather than allowed pending review.
Every action carries an authenticated actor. Guard resolves that actor to a scope before the work is admitted, so an unscoped credential cannot act by default.
Tenant boundaries are enforced at the data path. A credential scoped to one workspace cannot read, write or enumerate across another, and an attempt is raised as an event.
Privileged sessions are time-bound, attributed and observable. Issuance outside a change window is a detection, not a log line.
Automated and agent-initiated work runs inside explicit limits on scope, duration and reach. The boundary is enforced by the platform, not requested of the caller.
Guard can revoke a session, constrain an actor or narrow a scope on detection, and records the action with its justification in the same write.
Posture
A control that is evaluated once at configuration time tells you what was true then. Guard evaluates on every request, records every decision to Ledger, and exposes the current enforcement state through Pulse — so the question “is this policy actually in force right now” has an answer.