Put sensitive agent actions under review.
Give security a connected view of agent requests, approvals, revocation, execution outcomes, and the boundary of gateway coverage.
An action. A decision.
Permission is evaluated before a tool runs.
Pressure-test the boundary.
Choose a scenario to see Durin’s policy decision in the public simulator and follow the governed request path.
A former employee makes a request.
Current membership is checked before an action can proceed.
Run this scenario →Approval requiredAn agent asks to change a system.
Put an independent, exact approval between the request and the write.
Run this scenario →AllowedAn approved user reads an allowed resource.
Let useful work through with the identity and decision attached.
Run this scenario →Move from alert to answer.
Connect identity, policy, approval, dispatch, and outcome evidence so a review can answer who asked, what was allowed, and what happened next.
An access decision should be inspectable before it becomes an incident. Durin makes the review explicit, with the requested system and purpose in the same place.

Control the request. Preserve the outcome.
Make risky access explainable
A missing membership, unsupported capability, stale grant, or unknown resource stays blocked. Reviewers can see which boundary made the decision instead of inferring it from a single allow.
Put a second set of eyes on writes
Sensitive actions can require an independent approver and an exact, expiring grant tied to the request arguments, policy version, resources, and execution count.
Know where your visibility ends
Durin explains requests routed through its gateway. Security teams can then test the paths outside it, including direct APIs, browsers, shells, unmanaged agents, and model-provider handling of returned results.
Connect policy decisions to evidence.
Create an account to manage identity attribution, approvals, denial behavior, revocation, and execution outcomes.
Create an accountProduction connections use provider setup and trust review.