Policy Impact Simulation
Assess the effect a policy change would have across the governed estate before publishing it.
Policy Impact Simulation is meant to answer "what happens across my whole estate if I publish this rule" — the blast-radius question — which is a different job from Gateway Test's single-invocation check. The page renders a What-If form (principal type and ID, action, resource type and ID, environment) plus four view modes over the result: Full AI Graph, Blast Radius (only nodes that would not be allowed), Role-Centric, and Resource-Centric, with the graph colored per node by simulated decision and an impact summary showing blast radius percentage and allow/deny/conditional/unaffected counts.
Running a simulation posts the What-If parameters to the policy's simulate endpoint and expects back a result containing the graph nodes and edges plus a per-node decision, matched rule, and reason. As of this writing that endpoint has no registered handler anywhere in the Data Plane's router — the only server-side policy routes are the CRUD set under /api/policies and the real-time /evaluate path described under Policy Evaluation. The simulation UI is built and wired to call it, but a run against a real tenant will not currently return a populated result.
The view modes are real client-side logic, ready to operate on whatever a populated result contains: Blast Radius filters down to nodes whose decision isn't ALLOW; Role-Centric walks from role nodes through the applications and models they reach; Resource-Centric starts from tables, datasets, and resources and pulls in whatever connects to them.

Docs