FREE BROWSER TOOL / RELEASE-TO-RELEASE AUTHORITY
Authority changes faster than policy.
A new tool, a removed control or a wider identity can silently create a different agent. Compare the declared surface before the next release.
- LOCAL
- REPORTS STAY IN THIS BROWSER
- 0
- MODEL CALLS
- 0
- TOOLS EXECUTED
- 2
- LOCAL REPORTS COMPARED
AUTHORITY CHANGE CONTROL / LOCAL-ONLY
Compare two declared agent surfaces.
Accepts H/M Agent Scope and Agent Risk Atlas JSON exports. Source payloads, filenames and tool names are excluded from the comparison export.
KNOWN RELEASE
Baseline report
--
PROPOSED RELEASE
Candidate report
--
SYNTHETIC PAIR ACTIVEThis result does not describe a real deployment.
DETERMINISTIC RELEASE DIFF
Authority delta trace
--Two snapshots. One review boundary.
Load a baseline and candidate report, or open a clearly labeled synthetic pair.
- DECISION
- --
- CHANGES
- 0
- GATES VIOLATED
- 0
- NEW CRITICAL PATHS
- 0
- CONTROLS REMOVED
- 0
SOURCE-MINIMIZED EVIDENCE
Change ledger
SELECTED POLICY PACK
Release gates
Statuses report only what was observed in these declared inputs.
WHY SNAPSHOT REVIEW IS NOT ENOUGH
Security posture can drift without a new model.
Authority is assembled from tools, identities, data paths and external controls. Any one of them can change the effective system between releases.
- 01
Normalize authority
Reduce compatible reports to capability, control, path and aggregate gate signals.
- 02
Compare direction
Separate expansion, removal, regression and resolution instead of collapsing them into one score.
- 03
Apply explicit gates
Treat each policy as an observable release condition, never as a safety certificate.
- 04
Keep evidence minimal
Export hashes and normalized deltas without source payloads, filenames or tool names.
EXPLICIT LIMITS
A clean diff is not a safe deployment.
- Inputs are declared reports; runtime behavior and source integrity are not observed.
- Controls are compared as declarations and are not tested or verified.
- Different source schemas or methods can make authority comparisons incomplete.
- The path library is finite and cannot guarantee complete threat coverage.