Trust Zone / Segmentation Map
Every agent, tool and backend system is pinned to a trust zone. A call may only reach a tool at or below the calling agent's clearance — anything else is flagged and blocked at the gateway.
Internet-facing surfaces. No customer data, no write paths.
none
none
none
Non-production experimentation. Synthetic data only.
none
none
Colleague-facing systems and read-only operational data.
Commercial and billing data. Masked by default.
Regulated identity and core records. Predicate answers only.
none
Cross-zone attempts
Requests that tried to reach above their clearance
No cross-zone attempts in the buffer
Use 'Attempt cross-zone call' — the dev-zone sandbox agent will reach for a restricted identity tool.
Call trail
Select any call in the live stream to open its full trail
No call selected
Click a row in the live MCP flow to inspect identity, policy decision, token and result.
Clearance matrix
Agent clearance vs tool zone — ✕ marks a call the gateway will refuse
| Agent | Clearance | public | dev | internal | confidential | restricted |
|---|---|---|---|---|---|---|
| Salesforce Agentforce — Service Copilot | confidential | ✓ | ✓ | ✓ | ✓ | ✕ |
| Microsoft Copilot — Workplace Agent | internal | ✓ | ✓ | ✓ | ✕ | ✕ |
| Custom Care Orchestrator | confidential | ✓ | ✓ | ✓ | ✓ | ✕ |
| OpenShift NetOps Agent | confidential | ✓ | ✓ | ✓ | ✓ | ✕ |
| Internal Finance Analyst Agent | restricted | ✓ | ✓ | ✓ | ✓ | ✓ |
| Internal Ops Runbook Agent | internal | ✓ | ✓ | ✓ | ✕ | ✕ |
| Sandbox Prototype Agent | dev | ✓ | ✓ | ✕ | ✕ | ✕ |