Sandbox replay · anonymized placeholders · no production claims
An agent evidence run, staged safely against a static target.
This page is a labeled replay workspace for demos. The target, personas, artifacts, checksums, control mappings, and package state are synthetic examples for showing the operating model.
Demo boundary: no live CMS Hub, IdM, exchange, broker, consumer, or production tenant is used here. These routes exist only so an agent can navigate a safe sandbox and produce clearly marked placeholder evidence.
01Sandbox target
Reference tenant policy posture
The agent captures visible security posture signals from this static screen and links them to placeholder control mappings.
Authenticator app or hardware key placeholder
Lockout after 5 failed attempts
Retention shown as 365 days
Rotation placeholder every 90 days
Browser agent records what was visible, not what is true in any production environment. The human reviewer must decide whether an artifact is sufficient before export.
02Agent event stream
Scoped to anonymized CMS EDE security evidence demo target. Production systems were not contacted.
Visited /demo-target/login and confirmed the page is labeled as a non-production sandbox.
Recorded MFA, session timeout, password policy, and audit logging controls from static target pages.
Added synthetic screenshot, DOM note, config summary, and reviewer memo placeholders with demo checksums.
Package marked review-required until sufficiency, redaction, and source mapping are approved by a human.
Export controls remain disabled in this demo because artifacts are illustrative placeholders only.
03Evidence artifacts
04Human review gate
The agent assembles; a person approves.
The agent can assemble evidence, but a person must approve sufficiency, source mapping, and redaction before any package can be marked ready. Until then, the record stays unsealed.
82%
Collection coverage
42%
Review completion
0%
Export eligibility
05Controls touched
MFA settings, login policy, role-based access sample
Anonymized users table and privileged role review note
Password lockout policy and session timeout settings
Sandbox audit logging route with event classes and retention
Encryption at rest, transit, and key rotation placeholders
Incident response escalation and exercise history placeholders