ControlSpec
ControlSpec + OpenShell / Experimental integration

Before an
agent acts.

A permitted connection is one part of the decision. Inspect the exact action, its approval, and the evidence it leaves behind.

Open-source controls. Inspectable results.
01
Network boundaryOpenShell policy and request routing
02
Exact-action controlControlSpec decision, binding, and approval
03
Target evidenceSynthetic effect and recorded receipt
Recorded lab

This page replays recordings. Scripted inputs exercise the real ControlSpec evaluator through an authenticated gRPC fixture and a synthetic service. No live agent or real transactions run in this browser. Test operator approvals are simulated.

One request. Three control paths.

Synthetic purchase service

Inspect the exact scripted request
01 · Intent02 · Decision03 · Effect04 · Evidence

Each path reports its own observed state. An unavailable run is not a pass, a denial, or a zero.

What was actually verified

OpenShell pin
Runtime run
Runtime detail
Verification
Source revision
Recorded

Read the boundaries, too.

    Inspect the selected scenario’s raw trace

    Requests, decisions, target state, and available evidence are displayed as recorded. The full download includes provenance and every scenario.

    Download all recorded traces ↓

    This is a bounded experimental complement to NVIDIA OpenShell, with no implied endorsement. OpenShell itself supports body-aware controls; the value of this example is its explicit action binding, approval path, and evidence. Inspect the configuration before comparing outcomes.

    Challenge the boundary ↗