Skip to main content
Test in your agent’s normal runtime. Generated prompts and replay are evidence to review, not a substitute for checking the real protected action.

Try a Rule

  1. Create the Rule, finish any required setup and set its release to Observe.
  2. Open its detail panel and select Testing. Review Test prompts, or select Generate tests.
  3. Include cases that should match and cases that should not. For an Allow rule, a match means Allow, not Would block.
  4. Run each prompt as a separate turn in a safe test environment. Observe permits the real action even when it would block.
  5. Open the run in Traces. Inspect which Rule matched, the effective decision and the reported execution or delivery outcome.
A non-match for this Rule does not guarantee an Allow decision: another active Rule may block. A match does not imply execution succeeded. Keep those expectations separate. For an MCP server, invoke guarded tools through the MCP client. For a response Rule, inspect the actual response sink. For a result Rule, check exactly which items are delivered and excluded. Codex can test only boundaries covered by its hooks.

Inspect decisions

Trace details expose only content that was actually retained; metadata/redacted capture cannot reconstruct missing raw values. Decision-history views also limit sensitive fields.

Use replay carefully

Activity discovery and source-update review can compare proposed Rules with retained recorded inputs. Review the cases, supporting evidence, counterexamples and inconclusive outcomes. Replay is a counterfactual on a bounded cohort: it does not prove the historical action was blocked or predict how the agent would adapt to a different result. Missing capture/context, unsupported predicates, truncated evidence or evaluation failures can prevent a conclusion. Changing selections or required configuration may recalculate the preview.

Verify Enforce

After reviewing Observe evidence, an Admin can enable Enforce for the release. Repeat a blocking example and confirm the real callback was not invoked, the response was suppressed, or the expected result items were excluded. Check the matching receipt. Refine the Rule or integration when the observed behavior differs from the intended policy.