Skip to content

Synthetic demo · No customer connectors attached · Fixture snapshot 24 Sep 2026, 06:15 UTC

Protect / non-human identity

Access decision simulator

A local demonstration of how a request is evaluated in order. It is not a live enforcement endpoint. Missing or stale evidence yields deny or unknown, never allow.

Observed at 24 Sep 2026, 06:15 UTCStatus as of fixture 24 Sep 2026, 06:15 UTCSample data

Request

Evaluation

Result: ALLOW
  1. 1. Credential & trust bundlePass

    X.509-SVID validated for spiffe://prod.zeroshield.example/ns/support/sa/support-agent (authentication only — grants nothing)

    Evidence: X.509 chain to local trust bundle; URI SAN matches expected SPIFFE ID; Validity window

  2. 2. Agent binding & delegationPass

    Bound to Support Copilot; delegated user Maya Chen

    Evidence: ev-nhi-501 (delegation fixture)

  3. 3. Policy grants & conditions (authorization)Pass

    pol-support-read grants read (delegated user in Support group)

    Evidence: pol-support-read@r17

  4. 4. Data ACL & freshnessPass

    Source ACL acl-88 current

    Evidence: acl-88 · fixture 2026-09-24T06:15:00Z

A passing credential step only authenticates the workload. Authorization is decided by the later policy and data steps.