Skip to main content
← Demo index

Sandbox replay · anonymized placeholders · no production claims

An agent evidence run, staged safely against a static target.

This page is a labeled replay workspace for demos. The target, personas, artifacts, checksums, control mappings, and package state are synthetic examples for showing the operating model.

Demo boundary: no live CMS Hub, IdM, exchange, broker, consumer, or production tenant is used here. These routes exist only so an agent can navigate a safe sandbox and produce clearly marked placeholder evidence.

8sandbox pages7controls touched12artifactsReviewpackage state
Planplanner-agent
Browsebrowser-agent
Capturepolicy-agent
Manifestevidence-agent
Reviewhuman gate
Exportblocked

01Sandbox target

SBX-RUN-2026-05-18-001 · simulated browser
https://sandbox.controlframe.invalid/demo-target/security-settings
Security settings

Reference tenant policy posture

The agent captures visible security posture signals from this static screen and links them to placeholder control mappings.

Run ID SBX-RUN-2026-05-18-001
MFA requirement
Required for workforce users

Authenticator app or hardware key placeholder

Password policy
14 characters minimum

Lockout after 5 failed attempts

Audit logging
Security events enabled

Retention shown as 365 days

Encryption
Managed keys shown

Rotation placeholder every 90 days

Evidence capture plan
IA-2
User identification and authentication
MFA settings, login policy, role-based access sample
AC-2
Account management
Anonymized users table and privileged role review note
AC-7
Unsuccessful login attempts
Password lockout policy and session timeout settings
AU-2
Event logging
Sandbox audit logging route with event classes and retention
Agent observation

Browser agent records what was visible, not what is true in any production environment. The human reviewer must decide whether an artifact is sufficient before export.

Target classstatic sandbox
Personademo-admin@example.invalid
Networklocal route only
Secretsnone captured

02Agent event stream

6 events · 01:35 elapsed
00:00
planner-agent
Loaded sandbox run plan

Scoped to anonymized CMS EDE security evidence demo target. Production systems were not contacted.

00:14
browser-agent
Authenticated with placeholder persona

Visited /demo-target/login and confirmed the page is labeled as a non-production sandbox.

00:39
policy-agent
Captured security settings posture

Recorded MFA, session timeout, password policy, and audit logging controls from static target pages.

01:07
evidence-agent
Built artifact manifest

Added synthetic screenshot, DOM note, config summary, and reviewer memo placeholders with demo checksums.

01:22
review-agent
Stopped at human review gate

Package marked review-required until sufficiency, redaction, and source mapping are approved by a human.

01:35
package-agent
Package readiness blocked

Export controls remain disabled in this demo because artifacts are illustrative placeholders only.

03Evidence artifacts

reviewer controlled · placeholder evidence
sandbox-browser-capture.pngScreenshot by browser-agent
sha256:demo-6f31Needs review
security-settings-summary.jsonConfig summary by policy-agent
sha256:demo-912cNeeds review
audit-log-sample.jsonLog extract by evidence-agent
sha256:demo-a044Needs redaction review
human-review-notes.mdReviewer memo by review-agent
sha256:demo-f8e1Waiting for reviewer

04Human review gate

export stops here

The agent assembles; a person approves.

The agent can assemble evidence, but a person must approve sufficiency, source mapping, and redaction before any package can be marked ready. Until then, the record stays unsealed.

PENDING2550ba9a
Artifact sufficiencyHuman review required
PII and secret redactionHuman review required
Source mappingDemo mapping only
Package exportBlocked in sandbox

82%

Collection coverage

42%

Review completion

0%

Export eligibility

05Controls touched

demo mappings stay visibly provisional
IA-2
User identification and authentication

MFA settings, login policy, role-based access sample

AC-2
Account management

Anonymized users table and privileged role review note

AC-7
Unsuccessful login attempts

Password lockout policy and session timeout settings

AU-2
Event logging

Sandbox audit logging route with event classes and retention

SC-13
Cryptographic protection

Encryption at rest, transit, and key rotation placeholders

IR-4
Incident handling

Incident response escalation and exercise history placeholders

ControlFrame Sandbox Agent Evidence Run