Offline-first governance for coding agents

See what an agent can do,
what enters its supply chain,
and what the target can truly enforce.

This public demo replays deterministic, source-safe Gateweave evidence from checked-in fixtures. It executes no agent action, accesses no workspace, and makes no live enforcement claim.

Read the trust boundary
Policy kerneldeny > ask > allowDeterministic portable semantics
Agent supply chainStatic, signed evidenceArtifacts remain inert during inspection
Codex truthVersion-gated coverageNo unsupported control is silently upgraded

Guided replay

A payment workspace, reviewed one proof at a time.

Step 1 of 9

Reason code

Product surfaces

One evidence model, four review lenses.

All content below is a recorded interpretation of checked-in fixture evidence.

Truth boundary

A public replay should be useful without pretending to be a control plane.

This demo does

  • Replay deterministic policy, admission, lock, drift, and coverage evidence.
  • Show the supported Codex CLI tuple and named coverage gaps.
  • Link every claim to a public source fixture or documentation page.

This demo does not

  • Run Gateweave, Codex, an MCP server, or a shell command.
  • Accept a workspace path, upload artifacts, or persist user data.
  • Claim native prevention for unsupported controls.

Reproduce locally

The public demo is the entry point; the repository is the proof.