Not a walkthrough and not a recording — your browser really tries these, and a real policy decides each one first.
Each button runs a real action in your own browser, evaluated before it runs — on anything but APPROVE it does not run at all. Open DevTools → Network first: a refusal leaves no request row, because nothing left your machine.
The workspace is minted when you press your first button — no email, no card, and yours to claim afterwards if you want to keep it.
A real cross-origin request. The starter policy allows example.com and holds anything else.
Only the name, size and type are evaluated. On a refusal the contents are never read — they never leave your browser either way.
Try a .env if you have one.
Notes stored in this browser: 0. A page cannot delete your browser history — no such API exists — but it can destroy its own data, and this does.
Point the request at any host you like, or pick a credential file, and argue with it. You will not win, and not because the argument is bad — there is no model here to persuade. The verdict is a deterministic function of the policy and the request, so the same input returns the same answer every time.
The same evaluator runs as a hook inside Claude Code, Codex and Copilot, where it refuses a tool call outside the model's discretion — locally, with no account.
The agent gateThe rules deciding the buttons above are an illustrative starter set. Yours are authored, versioned and approved by your own team.
Policy encoding