Policy replay
AvailableTest governance changes against reality before deploying them.
Replay historical actions under a proposed policy to see what would remain allowed, require approval, or be blocked.
Lucidrail sits between AI agents and consequential actions. Every call is attributed to an identity, evaluated against policy and live context, and allowed, held or blocked — then verified and recorded.
Every agent is a first-class principal with an organization, a role, a declared purpose, a tool set, limits and a responsible human. Decisions and evidence attach to that identity — not to a shared API key.
Policies govern what agents may do with each system. The same rule can resolve differently depending on the agent’s capability, the task’s provenance, the argument values and current spend.
# illustrative policy syntax policy external-comms/contaminated-trajectory when action = email.send and recipient.domain ∉ org.domains and task.provenance = contaminated then require_approval(agent.responsible_human) evidence task.sources, draft, recipients
Reviewers see the exact proposed action and the evidence behind the hold. They can approve, reject, edit, ask the agent to explain, or inspect sources. The decision is bound to that action — and to the tool schema it was approved against.
Try the approval queue →Action provenance records the information sources, tool outputs and external inputs that preceded each action, their trust state, and the downstream actions that depend on them. Lucidrail works from observable inputs and outputs; it does not claim access to a model’s hidden reasoning.
Every consequential action produces a structured record you can query, export and hand to a reviewer.
Cryptographic signing of records is applied only where a deployment’s key management supports it; we document exactly which records are signed.
Also: tool spend, per-transaction limits, rate limits and escalation thresholds. Illustrative data.
Lucidrail records what the agent claimed separately from what the system confirmed. Mismatches are surfaced to the responsible human and count against the agent’s performance signal.
For each control, Lucidrail shows whether it is configured, whether it is in the path and evaluating, how often it triggered, and the most recent evidence. A control that has never produced evidence is flagged — not assumed to work.
See control effectiveness in the console →