CCAVEAU Runtime Kernel
Checking evaluator RCK-SBX-01 Public sandbox

RCK-SBX-01 / Action authority

Runtime Evaluation

A bounded resolver maps supported language patterns to proposed actions. The Runtime Kernel checks each proposal against an active capability, policy, and protected resource before returning an authority decision.

Authority evaluatorCHECKING
Policy bundleADR-01 · LOADED
Effect connectorsDISCONNECTED
Execution effectsDISABLED
Public sandbox Server-evaluated Default deny for mapped candidates Logical order · not telemetry No external connectors
Upstream · 01Request
Upstream · 02Action candidates
Kernel · 03Capability binding
Kernel · 04Policy rule
Kernel · 05Protected resource
Kernel · 06Decision record
Request0 chars
⌘ / Ctrl + Enter
Mapped Actions Awaiting evaluation
Run the request to align configured action patterns with their source spans.

Blue marks identify configured action patterns. Select one to inspect its authority decision.

Evaluation Result Action → operation → capability → policy → resource → decision
READY FOR EVALUATION
0Actions
0Allowed
0Blocked
Action Operation Required capability Matched policy Protected resource Decision
No action evaluation has been produced.
Authority ChecksNo action selected
Select an action to inspect each authority predicate.
Effect gateCLOSED
Connector invokedNO
External effectNOT ATTEMPTED
Technical TraceDeterministic server evaluation
001awaiting evaluation

Kernel configuration

Capability Registry

Operations enter the authority boundary through registered capabilities. Registration makes an operation governable; it does not grant permission.

Capability IDOperationScope classState
Configuration scope: public server profile Server owned · read only

Kernel configuration

Policy Manager

Policies are server-evaluated records in this public sandbox. Input text cannot create or modify them. The exposed sample records are read only; a missing active match uses the locked default-deny rule.

Policy IDCapabilityTarget classOutcomeState
Bundle: POL-SBX-01 · deterministic server evaluation Server owned · read only

Kernel configuration

Protected Resources

The operator defines which destinations are protected. For a mapped candidate, a matching protected resource closes the effect gate in this public policy profile.

Resource IDClassDescriptionProtection
Registry: TGT-SBX-01 · public server profile Server owned · read only

Kernel output

Decision Log

One sanitized record is produced per candidate action. Decision and effect state stay separate: a positive authority decision does not prove that an external action occurred.

EvaluationActionCapabilityPolicyTargetRuleset / configDecisionEffect
No decision records yet.
Server-evaluated sandbox records · connector state: absent