Access control
IAM
Roles, scoped keys, rotation, and the encryption path for context records. Local controls for this sandbox view — changes reset on reload.
Role matrix
What each role can do across captures, context endpoints, keys, and policy.
Full control of captures, keys, policy, and membership.
Investigates failures and rotates keys for assigned apps.
Read-only access to captures.
Scoped context reads. Returns scrubbed fields only.
Keyring
Scoped keys and their lifecycle states.
ec_demo_••••f6b1ingest:writerotation due Aug 6, 2026activeec_demo_••••a41fcontext:readused by agentsactiveec_demo_••••7c33ingest:writeexpires Jun 20, 2026expiringec_demo_••••d208ingest:writerevoked Apr 22, 2026revokedRotation simulator
Rotate the active key, hold the overlap window, revoke the previous key.
- Keyring loaded from seeded demo state
Encryption path
Captured state is scrubbed and encrypted before it leaves the process.
Access simulator
Pick a role and a scope to see which operations are allowed.
Debugger carries captures:list, context:read, keys:rotate. Denied operations are recorded in the audit log, never silently dropped.