Gateway Test
Simulate an AI Actor attempting an action and inspect the expected governance outcome.
Gateway Test lets someone pick a subject — an agent, human, or service — and a target tool or resource from the live catalog, then preview the governance outcome before it happens for real. It is scoped to one invocation at a time, which is what distinguishes it from Policy Impact Simulation's blast-radius view across many targets.
Both buttons on the page drive the identical code path real traffic uses: Gateway.Invoke and Gateway.Check are the same process() function with one flag flipped. Check (dry run) calls the /gateway/check endpoint, which evaluates policy for the chosen subject and target and returns the decision without recording any telemetry or calling the real MCP server. Invoke (record) calls /gateway/invoke, which runs the identical evaluation but, if allowed, proxies the call to the real MCP endpoint (or reports a simulated result if the server has none configured) and writes an invocation and decision log row exactly like production traffic does.
Inside that evaluation: the MCP server's policy mode (observe, simulate, or enforce) is looked up, a blocked actor is denied before any rule runs, the target tool or resource is resolved for context, and — for a tool call with arguments — every resource or column the arguments resolve to is evaluated too, with the most restrictive result winning.
The result panel shows Allow or Deny, the evaluator's plain-language explanation, the matched rules with their effect, and — for an actual Invoke — the recorded invocation ID. The last eight runs on a given browser persist in a "Recent Tests" strip, and the Decisions Log's Replay button deep-links back into this page pre-filled with a past call's subject, subject type, action, and MCP server so it can be re-run against the current policy set.

Docs