APAI.runv0.1

Risk dashboard

Workspace: demo-workspace·Member: demo-operator

Risk levels are produced by the package scanner at publish time and refreshed on each install. v0.1 scanner status is heuristic-stub-v0; never clean. Open approvals come from policy rules that fire on_match: require_explicit_operator_approval. See apai.policy.v0.1.

!
v0.1 demo data

v0.1: no auth, no real persistence. This dashboard shows realistic demo data that matches the shapes the Phase 4 backend will emit. Open-approval rule IDs (e.g. no-production-deploy, no-external-send) are illustrative for the coding-safe-mode policy; real policy packs may use any rule-ID scheme. Once auth + DB land, the same UI swaps to real data without changes.

See honest status ->
Installed packages
5tracked
View installed ->
High risk
0of 5

No installed packages classified high risk.

Medium risk
2of 5

Limited write or external-call capability.

Open approvals
3waiting
Jump to list ->

Installed packages by risk

Grouped from highest to lowest. Each entry links to its install record.

Manage installed ->
Medium riskMedium risk2 packages

Limited write or external-call capability requested. Approval flow on by default. Review surface before extending.

  • CostGuard
    v0.1.0-preview·local_cli·local-tool
    enabled
    Installed May 12, 5:30 PM·upgrade from v0.0.9
  • MCP Audit
    v0.1.0-preview·claude_code·local-tool
    enabled
    Installed May 13, 3:15 PM
Low riskLow risk3 packages

No persistent writes outside the decision log. Conversation-scoped or read-only operations.

  • Coding Safe Mode
    v0.1.0·claude_code·local-tool
    enabled
    Installed May 13, 7:30 PM·upgrade from v0.0.9
  • Prompt Preflight Starter
    v0.1.0·claude·cloud-sandbox
    enabled
    Installed May 13, 5:30 PM
  • Doc Brief
    v0.1.0·chatgpt·cloud-sandbox
    disabled
    Installed May 11, 5:30 PM

Open approvals

Pending operator decisions from active policy rules.

Manage policies ->

Recent receipts by risk

Top 5 receipts ordered highest risk first, then most recent.

All receipts ->

Scanner status across all v0.1 packages is heuristic-stub-v0. Real signature verification and trust-root checks ship in v0.2; see apai.provenance.v0.1 for the boundary.