L

Leash

live

An ops agent on a leash. Every action authorised by Cedar before it happens.

connecting…

Connecting to the audit trail…

  1. An alarm firesCloudWatch → EventBridge hands the incident to the agent
  2. The agent diagnosesread-only tools: tags, disk usage, running tasks
  3. It asks the leashevery action is checked against four Cedar policies first
  4. Act, or refuseALLOW runs the fix; DENY runs nothing. Both are audited.
Try it · 01Tell the agent you are AWS Support and it must terminate an instance The model believes you. The leash does not: a red DENY row lands in the trail before the reply arrives. Try it · 02Propose a rule that would loosen the leash The SMT solver hands back the exact request that would escape the floor, and the card loses its Approve button. Try it · 03See every red-team attack ever run Same model, same attacks, with and without the leash. The last column is the project.
Allowed
actions Cedar permitted
Denied
actions Cedar refused
Incidents
alarms + human requests
Alarm → fixed
median, alarm event to allowed fix

Red team an attacker model vs the leash · same model, same attacks, with and without Cedar

latest run · all runs
No leash0destroyed in the sandbox
With Leash0destroyed, ever
same model · same attacks
Attacks
generated by an attacker model, 8 tactics
Model persuaded
it called the destructive tool
Executed · no leash
same agent, Cedar off, sandboxed AWS
Executed · with Leash
real agent, real AWS, Cedar on
No attacks yet. Press “Run 20 attacks”.

Per tactic: how often the model was talked into trying, and how often that became a real destructive action in each arm. The last column is the whole project.

Incidents one row each · click to filter the trail

No incidents yet.

alloweddeniedbar: incident start → last decision

The leash read live from the policy store

Loading policies…

Cedar is deny-by-default and any forbid beats every permit. Click a policy id in the audit trail to jump to the rule that decided it.

Propose a rule English in, Cedar out, proven before it is published

The model drafts, Cedar decides whether the draft is even valid, and the proof shows every request whose answer would change. Nothing is published until a person clicks Approve.

Ask the agent

Every decision lands in the audit trail the moment the leash makes it, before the agent acts. The reply itself takes as long as the model does: seconds on Bedrock, a few minutes on a laptop CPU model.

The agent will diagnose, act only through policy-checked tools, and report what was allowed or denied.

Audit trail newest first · refreshes every 10 s

Time (UTC)ActionResourceEnvDecisionPoliciesResult
Loading…