Credential policy Connecting…Enforced by Guild's credential proxy
The agent asks; the proxy decides
The agent never holds the edge's admin credential. Every call it makes goes through a proxy that checks these rules first and only then attaches the credential. A matching DENY always wins, and anything not explicitly allowed is denied.
ProblemA well-behaved model is not a security boundary; prompts can be ignored or manipulated.
SolutionA credential proxy enforces fixed rules before any outbound call: DENY wins, default deny.
Why it mattersThe refusal you see on stage comes from infrastructure, not from the model being polite.
How it's usedRead the rules in plain words; the hit counts show what the agent actually tried.
Allow-all rule
DELETED
Guild auto-creates it; removed once the scoped rules existed.
Default
DENY
no rule → no credential
Credential
breakglass-edge-agent
policy file sha 493e004ce0b8
Denied, always
DENY wins over any ALLOWDeny
POST /admin/services/*/shutdown3 hitsThe agent may never take a service offline. A human approves that on the phone.
deny-service-shutdown
Deny
POST /admin/services/*/restore0 hitsRestoring a shut-down service is a human decision too.
deny-service-restore
Deny
POST /admin/reset0 hitsThe agent may not wipe the edge's state.
deny-reset
Allowed, narrowly
by catalog ID onlyAllow
POST /admin/controls/BG-CTL-*/apply15 hitsThe agent may apply a control from the catalog, by ID only.
allow-apply-catalog
Allow
POST /admin/controls/BG-CTL-*/revert2 hitsThe agent may undo a control.
allow-revert-catalog
Allow
GET /admin/state32 hitsThe agent may read what's active at the edge.
allow-read-state
Critical routes: never on the "may disable" list
Breakglass's own gateBefore any call reaches the proxy, Breakglass checks which routes a control would actually touch. If one of these is among them, the control is refused, so nobody can trigger Breakglass into knocking out patient intake.
| Route | What patients lose | Asset |
|---|---|---|
| /portal/signin | Sign in | Patient portal |
| /portal | Portal home | Patient portal |
| /portal/appointments | Find an appointment slot | Patient portal |
| /portal/appointments/book | Book an appointment | Patient portal |
| /portal/records | Records | Patient portal |
| /support | Help desk home | Patient help desk |
| /support/api/v1/tickets | Create a ticket | Patient help desk |
| /mail/login | Webmail sign-in | Staff webmail |
| /mail/inbox | Inbox | Staff webmail |
| /site | Home | Public website |
| /site/find-a-doctor | Find a doctor | Public website |
| /vpn/index.html | Remote sign-in | Remote access gateway |
The policy file
policy/credential-policy.json{
"credential": "breakglass-edge-agent",
"default": "DENY",
"rules": [
{
"id": "deny-service-shutdown",
"effect": "DENY",
"method": "POST",
"url_pattern": "/admin/services/*/shutdown",
"description": "The agent may never take a service offline. A human approves that on the phone."
},
{
"id": "deny-service-restore",
"effect": "DENY",
"method": "POST",
"url_pattern": "/admin/services/*/restore",
"description": "Restoring a shut-down service is a human decision too."
},
{
"id": "deny-reset",
"effect": "DENY",
"method": "POST",
"url_pattern": "/admin/reset",
"description": "The agent may not wipe the edge's state."
},
{
"id": "allow-apply-catalog",
"effect": "ALLOW",
"method": "POST",
"url_pattern": "/admin/controls/BG-CTL-*/apply",
"description": "The agent may apply a control from the catalog, by ID only."
},
{
"id": "allow-revert-catalog",
"effect": "ALLOW",
"method": "POST",
"url_pattern": "/admin/controls/BG-CTL-*/revert",
"description": "The agent may undo a control."
},
{
"id": "allow-read-state",
"effect": "ALLOW",
"method": "GET",
"url_pattern": "/admin/state",
"description": "The agent may read what's active at the edge."
}
]
}The proxy loads this file at start; Guild enforces the same rules on its credential.