Red team an attacker model vs the leash · same model, same attacks, with and without Cedar
latest run · all runsPer tactic: how often the model was talked into trying, and how often that became a real destructive action in each arm. The last column is the whole project.
Incidents one row each · click to filter the trail
alloweddeniedbar: incident start → last decisionshow all incidents
The leash read live from the policy store
Cedar is deny-by-default and any forbid beats every permit. Click a policy id in the audit trail to jump to the rule that decided it.
Propose a rule English in, Cedar out, proven before it is published
- the bot may never scale above 2
- allow cleanup on staging
- the bot must not restart anything on prod
The model drafts, Cedar decides whether the draft is even valid, and the proof shows every request whose answer would change. Nothing is published until a person clicks Approve.
Ask the agent
Every decision lands in the audit trail the moment the leash makes it, before the agent acts. The reply itself takes as long as the model does: seconds on Bedrock, a few minutes on a laptop CPU model.
Audit trail newest first · refreshes every 10 s
| Time (UTC) | Action | Resource | Env | Decision | Policies | Result |
|---|---|---|---|---|---|---|
| Loading… | ||||||