Active policy
See the policy now in force, plus preflight (hypothetical), canary (bounded live share), and rollback (emergency revert to a previous version). Writes use a server-issued policy write capability — there is no hidden URL to memorise.
This dashboard is for buyers and operators (CFO/CTO). Create your organisation, issue an API key for your app, add credits, and view reports.
How Sparse Guard works: your app asks for approval before an AI call (to prevent runaway spend), then reports back after the call (for accurate billing + audit).
Protect your first AI workload.
This guides the explanation you see next. It does not silently change security policy.
New organisations receive a server-configured opening credit (not purchased). The amount is set by Sparse Guard, cannot be chosen by the customer, and is recorded once as an opening credit. That balance is enough for a first governed request without an operator top-up.
Proxy integration is not currently enabled in this environment.
Point your OpenAI-compatible client at Sparse Guard. Guard governs, forwards and settles automatically.
Treat this key like a password. It is shown once after creation.
Ask Guard for approval, make the provider call yourself, then settle actual usage.
Advanced: /v1/govern/llm, /v1/settle, reservationId.
Onboarding completes after a real Guard decision is observed. This screen will not invent a successful event.
Your first AI request was governed successfully.
Decision: —
Is Guard connected? What has it controlled? Did anything get blocked? What did we spend?
Guard API / sidecar. Proxy integration is not currently enabled in this environment.
Sidecar: ask Guard, execute if allowed, record actual usage.
Current enforcement posture. These are not fake toggles.
See the policy now in force, plus preflight (hypothetical), canary (bounded live share), and rollback (emergency revert to a previous version). Writes use a server-issued policy write capability — there is no hidden URL to memorise.
Tenant credit remaining after the opening credit and any later funding. Job budgets appear when a job has a ceiling.
Budget preflight before execution. Credits are the usage mechanism.
Risky agent actions need a reservation-bound capability before webhook send, tool execute, or external fetch.
Agent Trap Guard blocks or quarantines dangerous actions before they run.
Distillation Guard blocks scraping / distillation campaigns. Avoided CO₂e is shown only from verified DG enforcement events.
DLP controls for secrets, PII and source leakage paths.
Cyber-context tightening when ingested risk context is high.
Capabilities
Scoped, expiring, replay-resistant tokens. Recent replay blocks appear in Developer → Capabilities when data exists.
ATG enforcement, DLP events and cyber events load from live statements when an API key is present. Empty means no events — not demo data.
Exact evidence for each governed request: the decision, the control that enforced it, and carbon that is measured, estimated, or verified avoided. Verified avoided CO₂e is shown only when a matching enforcement record exists.
Credits, carbon, ATG enforcement events and DG enforcement events are available when live data exists.
Measured and estimated carbon come from settled usage. Verified avoided CO₂e is only reported when actual enforcement occurred and an authoritative enforcement record exists.
No receipt selected.
This starts the existing verified erase flow. It cannot be undone through an old recovery snapshot.
Developer / Advanced — existing operator tools. OPERATOR / INTERNAL tools remain here.
Setup: Sign in → Create organisation → Create API key → Add credits
Operate: Your app uses the API key to get approvals and record usage
Report: Download credits and emissions reports for finance/audit
Confirms the service is online and responding.
Create an account or sign in to manage your organisation, billing, and reporting.
Create a tenant (org) using your JWT.
Create an API key for your app. This is the credential your workloads use to request approvals and record usage.
Credits are your AI budget. Add credits via Stripe, then Guard enforces usage against that budget.
Uses the clientSecret from your last Create intent. Enter card details, then Pay now.
Admin topup (optional). Works only if ALLOW_ADMIN_TOPUP=1. Uses ADMIN_TOKEN. Not part of the normal customer journey.
Signed governance receipts — receipts you can verify; verify before execute. Call POST /v1/verify with the signed_receipt object from POST /v1/govern or POST /v1/settle (Ed25519 signed; hybrid PQ optional).
Finance/audit view. Paste an API key to load credit spend and the emissions report (optional).
| Kind | Amount | Currency | Ref | Created |
|---|
| TS | Model | Tin | Tout | J | kWh | gCO₂e | Cost | ATG (verified) | Method |
|---|
Agents can’t be tricked into dangerous actions. Rows here are Quarantined actions and Denied actions from POST /v1/atg/gate (preflight) and enforced paths such as POST /v1/actions/webhook/send. Injection evidence is stored with each enforcement event’s reason codes and evidence fields. Hidden prompt injections get quarantined before they trigger tools, writes, or sends. Only verified ATG enforcement events with stored avoided grams of CO₂e count as verified avoided emissions — never claimed without a stored row.
| TS | Decision | Kind | Source | Name | Target | Reason / codes | gCO₂e |
|---|
Authoritative control-plane statement — remaining budget, active jobs, capability/ATG/DG enforcement, receipts, and verified carbon only.
Live GET /v1/statements/enforcement and GET /v1/evidence/enforcement/:id. Open #enforcement or #enforcement/<evidence_id>. Demo fallback enterprise_enforcement_demo / enforcement_evidence_demo. Avoided CO₂e is shown only from verified enforcement rows.
Select a row to inspect the authoritative record. Hash: #enforcement/<evidence_id>.
| When | Action | Control | Decision | Reason | Job | Prevented | Status | Evidence |
|---|
Signed receipts from POST /v1/govern, POST /v1/settle, and POST /v1/atg/gate include payload_hash, expires_at, and signatures. They are server-verifiable with POST /v1/verify — downstream systems should treat decision: "ACCEPT" and code: verify_ok as the execution gate.
High-risk paths such as POST /v1/actions/webhook/send accept optional guard_receipt (an atg_gate signed receipt). Invalid, expired, or tampered receipts are rejected before action execution.
Active signing keys — public material from GET /v1/public-keys (no API key).
Security events you can automate — Signed webhook events for SIEM/SOAR. Verify event signatures before acting.
Least privilege, enforced — approvals become scoped capabilities. Tenant-bound, scoped, expiring. Single-use enforcement for high-risk execution paths.
ATG ALLOW for risky actions can return a signed capability_token. Verify with POST /v1/capabilities/verify before executing. High-risk paths POST /v1/actions/webhook/send, POST /v1/actions/tool/execute, POST /v1/actions/http/fetch, and tool-bearing POST /v1/proxy/chat/completions require a reservation-bound capability. Live GET /v1/statements/capabilities; demo fallback capability_operator_demo.
Enforcement rows show action kind, scope, reason, reservation, and whether execution was prevented.
What was active — versioned tenant enforcement policy. One active version. System ATG, DG, and HIGH_RISK capability requirements cannot be switched off.
Live GET /v1/policies. Demo fallback policy_operator_demo.
| Version | Status | Hash | Reason | Created |
|---|
What would a candidate policy have done on recent tenant evidence. This is not actual enforcement. No budget, capability, ATG, DG, or carbon row is written as live action.
Hypothetical results only.
| Field | Active | Candidate |
|---|
Bounded live assignment of a preflighted candidate. Not an experiment dashboard. Assignment itself has no avoided carbon claim.
Start/stop below using a reservation-bound policy_write capability. The write scope is issued by the server.
Select an existing immutable historical version. Not Worker or deployment rollback. Rollback itself has no avoided carbon claim.
Rollback below using a reservation-bound policy_write capability.
Govern → ATG issues policy_write (server scope) → create / preflight / canary / activate / rollback. Capability enforcement is not bypassed.
write_capability: load live policy to discover
Paste an API key first. Each write reserves credit and consumes a single-use capability.
One hard ceiling per agent run — a job_id binds govern → settle to a durable cost, step, token, and expiry limit.
Live GET /v1/statements/jobs. Demo fallback /console/sample-results.json (job_budget_operator_demo) when the tenant has no jobs. Avoided CO₂e is shown only from verified job-budget deny rows.
| Job | Status | Remaining | Steps | Denied | Expires |
|---|
Know what agents are running — control-plane inventory for agents, apps, tools, connectors, and MCP-style integrations.
Governance coverage — GET /v1/assets/list with API key. Shadow / unknown assets surface when risky flows carry hints but the asset is not registered.
Owner, scopes, environment, last seen — each row is an operational record, not a CMDB dump.
Signed artifacts — Worker artifact attestations use dedicated purpose-separated Ed25519 artifact signing keys. Customer artifact registry manifests use a separate customer-artifact signing contract, also purpose-separated from receipt keys.
SBOM and provenance — GET /v1/artifacts/:id/sbom surfaces SBOM links and summaries. Gated promotion — dev → stage → prod only, with policy checks.
Verify before promote — POST /v1/artifacts/verify then POST /v1/artifacts/promote. Promotion decisions with receipt — audit rows under promotions.
Stop model scraping with verified enforcement. Live: GET /v1/statements/dg-blocks. Demo fallback: /console/sample-results.json.
| Time | Mode | Reason | Prompt family | RPM | TPM | Tokens avoided | CO₂e g |
|---|
No verified distillation campaigns detected yet until live DG enforcement events exist. Showing demo evidence until live enforcement data appears. Carbon: avoided CO₂e KPIs use verified DG enforcement events only, not suspicion flags.
Agents can’t be tricked into dangerous actions. Verified ATG enforcement — live GET /v1/statements/atg-blocks; demo fallback /console/sample-results.json (atg_operator_demo). Governed LLM proxy (POST /v1/proxy/chat/completions) is ATG-required: server-assembled sources, empty client atg_sources cannot bypass.
Receipts prove minimization.
Enforced action classes (pre-action gate + POST /v1/actions/webhook/send for webhook). Each path must call the gate before execution.
| Time | Decision | Action kind | Source kind | Reason codes | Actor | gCO₂e |
|---|
No verified ATG enforcement events detected yet. Showing demo evidence until live ATG enforcement data appears.
Tamper-evident external evidence replica. Hashes and chain status only — not tenant payloads, and not a control-plane.
Classification: tamper-evident external replica. Not WORM unless the store denies overwrite/delete.
Metadata only. Credentials are encrypted with a tenant-specific data-encryption key. This view never shows secrets, ciphertext, or keys. There is no reveal or copy-secret control.
| Name | Status | Version | Encrypted | DEK version | Scheme | Destination fingerprint |
|---|
Recommended — Guard API / sidecar: ask Guard, execute if allowed, then settle actual usage. Proxy integration is not currently enabled in this environment.
For webhooks, email sends, tool calls, memory writes, connector writes, deploys, and external fetches, call POST /v1/atg/gate before executing the action.
If decision=ALLOW, execute the action.
If decision=QUARANTINE or DENY, do not execute it.
Partner / primitive route POST /v1/govern — supply alpha, kappa, gamma, d, phi yourself.
Flows: Plain model calls: govern → provider → settle. Agent actions: govern → atg/gate → action → settle.
Signed receipts available. /v1/govern, /v1/settle, and /v1/atg/gate return signed receipts. Use POST /v1/verify to verify before executing high-risk downstream actions.
Signed event stream available. Use signed webhook events for SIEM/SOAR and verify event signatures before acting.