Protect / non-human identity
Access decision simulator
A local demonstration of how a request is evaluated in order. It is not a live enforcement endpoint. Missing or stale evidence yields deny or unknown, never allow.
Request
Evaluation
- 1. Credential & trust bundlePass
X.509-SVID validated for spiffe://prod.zeroshield.example/ns/support/sa/support-agent (authentication only — grants nothing)
Evidence: X.509 chain to local trust bundle; URI SAN matches expected SPIFFE ID; Validity window
- 2. Agent binding & delegationPass
Bound to Support Copilot; delegated user Maya Chen
Evidence: ev-nhi-501 (delegation fixture)
- 3. Policy grants & conditions (authorization)Pass
pol-support-read grants read (delegated user in Support group)
Evidence: pol-support-read@r17
- 4. Data ACL & freshnessPass
Source ACL acl-88 current
Evidence: acl-88 · fixture 2026-09-24T06:15:00Z
A passing credential step only authenticates the workload. Authorization is decided by the later policy and data steps.