Eight real actions: compile + activate a Policy Compiler policy (deny or require review), archive an MCP-server/tool asset, suspend a Control Plane key that's gone dormant, hold a system out of production, add a control to the Controls Register, or re-run the reassessment daemon for one system. Each does exactly what it says against your actual stored data.
Closed-loop automation (off by default): at automation level 2+, before a candidate applies itself it's projected against real data first — revoke MCP server / disable tool checks the real AI Inventory dependency graph (any production system still depending on it holds it for you); add policy check / add approval gate backtests the candidate policy against your real Control Plane ledger history and only proceeds if the blast radius is under your configured cap. Block deployment, add test case, and re-run evaluation are already narrowly scoped by their own detector, so they apply directly once enabled — same posture Autopilot already gives its one auto-appliable action. Every auto-applied (or held-back) candidate shows its projection in the feed below, and nothing bypasses the Policy Compiler either way.
Not built here, deliberately: Jira/ServiceNow tickets, pull-request generation, credential rotation, or CI/CD-pipeline integration (GitHub Actions, GitLab CI, Terraform, Kubernetes admission control…) — those need real third-party credentials this project doesn't have, the same reason Shadow AI Detection's ~26 connectors weren't built either.
Scanning proposes candidates from five real signals: a failing control on a production system; a high deny/review rate for one agent+tool pair in the Agent Control Plane ledger; an asset whose Control Plane key is already suspended/revoked but the inventory record isn't archived to match; a Continuous Swarm finding that today's policies would let a representative attack through; and a Control Plane key that's gone dormant (active but unused for 30+ days). You can also propose any action manually below.