RCK-SBX-01 / Action authority
Runtime Evaluation
A bounded resolver maps supported language patterns to proposed actions. The Runtime Kernel checks each proposal against an active capability, policy, and protected resource before returning an authority decision.
Blue marks identify configured action patterns. Select one to inspect its authority decision.
| Action | Operation | Required capability | Matched policy | Protected resource | Decision |
|---|---|---|---|---|---|
No action evaluation has been produced. | |||||
Kernel configuration
Capability Registry
Operations enter the authority boundary through registered capabilities. Registration makes an operation governable; it does not grant permission.
| Capability ID | Operation | Scope class | State |
|---|
Kernel configuration
Policy Manager
Policies are server-evaluated records in this public sandbox. Input text cannot create or modify them. The exposed sample records are read only; a missing active match uses the locked default-deny rule.
| Policy ID | Capability | Target class | Outcome | State |
|---|
Kernel configuration
Protected Resources
The operator defines which destinations are protected. For a mapped candidate, a matching protected resource closes the effect gate in this public policy profile.
| Resource ID | Class | Description | Protection |
|---|
Kernel output
Decision Log
One sanitized record is produced per candidate action. Decision and effect state stay separate: a positive authority decision does not prove that an external action occurred.
| Evaluation | Action | Capability | Policy | Target | Ruleset / config | Decision | Effect |
|---|---|---|---|---|---|---|---|
No decision records yet. | |||||||