Trust center
Every gate that stands between a finding and an outbound letter, in the open: the authorization policies, what they deny and why, the engine's own scorecard, and the exact reference-data versions behind every citation.
Cedar authorization policies
Rendered for gateway — (a placeholder ARN for this demo). Source: policies/src/countercharge_policies/templates/*.cedar.tmpl.
Deny matrix
Each row is a scenario the gateway is built to refuse, and which layer catches it.
| Scenario | Layer | Result | Why |
|---|
A real denial, verbatim
The literal response returned by the live AgentCore Gateway when a tool call has no policy statement permitting it (denied by default):
{"jsonrpc":"2.0","error":{"code":-32002,"message":"Tool Execution Denied: Tool call not allowed due to policy enforcement [No policy applies to the request (denied by default).]"}}
Engine scorecard
loading…
| Rule | TP | FP | FN | Precision | Recall |
|---|
Source: evals/results/engine-scorecard.json, run against 45 corpus cases.
Reference data versions
Every citation in a finding names one of these datasets, at this exact version.
| Dataset | Version | Rows | Retrieved | Source |
|---|
Source: engine/data/REFDATA.md.