Enforcement — Guard

Policy, enforced at the boundary.

Security is active, continuous and policy-driven.

Guard enforces policy at the boundary: identity, tenant and workspace isolation, privileged activity control, secure execution limits and automatic response to anomalous behaviour.

Policy enforcement

Policy is evaluated on the request path, not reconciled afterwards. A decision that cannot be evaluated is refused rather than allowed pending review.

Identity boundaries

Every action carries an authenticated actor. Guard resolves that actor to a scope before the work is admitted, so an unscoped credential cannot act by default.

Tenant and workspace isolation

Tenant boundaries are enforced at the data path. A credential scoped to one workspace cannot read, write or enumerate across another, and an attempt is raised as an event.

Privileged activity control

Privileged sessions are time-bound, attributed and observable. Issuance outside a change window is a detection, not a log line.

Secure execution boundaries

Automated and agent-initiated work runs inside explicit limits on scope, duration and reach. The boundary is enforced by the platform, not requested of the caller.

Anomaly response

Guard can revoke a session, constrain an actor or narrow a scope on detection, and records the action with its justification in the same write.

Posture

Enforcement is continuous, or it is decorative.

A control that is evaluated once at configuration time tells you what was true then. Guard evaluates on every request, records every decision to Ledger, and exposes the current enforcement state through Pulse — so the question “is this policy actually in force right now” has an answer.