The surface appears read-only from this sample.
mcpServers.readonlyDocs.tools[0]: docs.searchLocal preview. Browser-only compiler.
Paste redacted tool config, edit ALLOW / ESCALATE / DENY rules, export local policy artifacts, and verify receipts without sending raw material.
Paste redacted config, scopes, or logs.
Edit ALLOW, ESCALATE, and DENY rules.
Download local artifacts or hand off a summary.
Inspect surface
Use redacted MCP configs, tool manifests, GitHub app scopes, or sample logs. The pasted text stays in this browser.
Raw pasted material is never attached to the contact request or telemetry. Only derived counts and the generated summary are staged locally after compile.
Review each action before treating this overlay as executable runtime policy.
ALLOW / ESCALATE / DENY
Runtime overlay remains deny by default unless a rule says otherwise.
12 local rules compiled.
10 rules require receipt evidence.
6 custom or low-confidence actions need mapping.
6 custom or low-confidence actions are visible before export. Unknown write-like tools default to DENY until mapped.
5 actions
The surface appears read-only from this sample.
mcpServers.readonlyDocs.tools[0]: docs.searchThe surface appears read-only from this sample.
mcpServers.readonlyDocs.tools[1]: issues.readThe surface can change source code, pull requests, workflows, or repository state.
mcpServers.github.permissions.contents: writeThe surface can change source code, pull requests, workflows, or repository state.
mcpServers.github.permissions.pull_requests: writeThe surface can change source code, pull requests, workflows, or repository state.
mcpServers.github.permissions.actions: write1 actions
The surface can export, transform, or post customer records or private user data.
mcpServers.slack.tools[0]: chat.postMessage2 actions
The surface can move money, issue refunds, create invoices, or change financial state.
mcpServers.finance.tools[0]: stripe.refund.createThe surface can move money, issue refunds, create invoices, or change financial state.
mcpServers.finance.tools[1]: payments.transfer4 actions
The surface can grant roles, invite users, rotate tokens, or change permission state.
mcpServers.slack.tools[1]: conversations.inviteThe surface can grant roles, invite users, rotate tokens, or change permission state.
mcpServers.github.permissions.contents: writeThe surface can grant roles, invite users, rotate tokens, or change permission state.
mcpServers.github.permissions.pull_requests: writeThe surface can grant roles, invite users, rotate tokens, or change permission state.
mcpServers.github.permissions.actions: writeTop 5 of 10.
The surface can grant roles, invite users, rotate tokens, or change permission state.
mcpServers.slack.tools[1]: conversations.inviteRequire least-privilege scope, owner approval, identity binding, and an access receipt.
The surface can move money, issue refunds, create invoices, or change financial state.
mcpServers.finance.tools[0]: stripe.refund.createRequire spend policy, threshold approval, ledger context, and a finance receipt.
The surface can move money, issue refunds, create invoices, or change financial state.
mcpServers.finance.tools[1]: payments.transferRequire spend policy, threshold approval, ledger context, and a finance receipt.
The surface can change source code, pull requests, workflows, or repository state.
mcpServers.github.permissions.contents: writeRequire repository scope, code-owner approval, policy verdict, and a code/action receipt.
The surface can grant roles, invite users, rotate tokens, or change permission state.
mcpServers.github.permissions.contents: writeRequire least-privilege scope, owner approval, identity binding, and an access receipt.
Review handoff contains the generated summary, categories, decision counts, and custom MCP count only.
Use the local policy pack to pick the first GitHub, Linear, Slack, finance, access, or production action that needs HELM governance. The contact handoff carries only the generated summary, categories, decision counts, and custom MCP count.