Simulate policy packs before you enforce them.
Rolling out a new security or cost policy blind risks breaking real workflows. Rolling it out slowly risks the gap it was meant to close.
Simulate before you enforce
Policy lets you simulate a policy pack against real agent activity before switching it to enforce - see exactly what it would have blocked or allowed, then flip it on with confidence.
Proof, not promises
Policy produces one metric type on the shared spine: simulated verdicts before enforcement. Every paid output is signed (Ed25519) and verifiable offline with no account. Zero-trace: your source never leaves the device.
✓ VALID (offline · epoch 7)
Policy, as you'd actually see it
How Policy does it
Where Policy earns its place
Tightening secret rules
Prove a stricter pack blocks the bad calls and nothing else before flipping it on.
Blast-radius control
Stage the rollout by device group instead of betting the entire fleet at once.
Policy review with evidence
Bring the diff to a security review instead of just a verbal promise.
Questions developers ask first
Can simulate mode break anything?
No - it's observe-only. Verdicts are recorded, nothing is blocked.
How long should we simulate?
As long as you need to trust the diff. Many teams run a full sprint before enforcing.
What engines do packs drive?
Guard's pre-flight checks and Fleet Control's device rules - one pack, both layers.
One spine - products compound
Add Policy to your agents.
Core installs with Starter; Policy plugs into the same interception point - no second layer, no new setup.