Start from an example, or pick your own
Four setups already filled in. Load one to see what the tool does, then change it into yours — nothing is sent anywhere either way.
1 · Which agents do you actually run?
Pick as many as apply. A local agent and a hosted one are not two versions of the same thing — they have different shapes, and neither is safer.
Pick one and the rest of the page appears.
2 · What is actually on your machine?
These prune the graph. If there are no credential files, that branch should not be drawn — a picture of a machine that is not yours is not evidence about you.
3 · What that reaches
Every box says what stands in the way and who enforces it. Click any of them.
4 · What did you mean it to do?
Only what is actually reachable is offered — there is no point asking you to authorise something nothing you picked can do.
5 · The delta
6 · Controls
Not advice, and not a to-do list. These are the things that remove capability — tick what is already true and watch the numbers above move.
Where any of this goes
Nowhere. There is no backend to send it to, so open your network panel and watch: this page asks for its stylesheet, its scripts and library.json, and that last one is us sending you something. The claim is architectural rather than operational — a property, not a promise.
What is stored, and the rule underneath it
A completed assessment describes which agents you run, on which machine, holding which credentials, with which containment. Individually unremarkable; assembled, dated and ranked, it is a serviceable plan for attacking you — and we would have asked you to write it down. So this page stores your choices, never your answers: identifiers from a public library, fixed options, and nothing else.
There is no free-text box anywhere on this page. That is the rule made checkable rather than promised. It is also why there is no risk-acceptance step here and no place to name a person — a name is a fact about your organisation, and this page has nowhere safe to put one.
Per browser, per device, per origin. Cleared with site data and when a private window closes. No recovery. Readable by any script on this origin, which is the reason for references-only rather than an argument against storing anything. Losing it costs you almost nothing, by design.
Everything stored, as bytes
(nothing stored yet)
Library version …. Every value is an identifier from
that file, a fixed option, or derived from one.
If it is wrong, that is the most useful thing you have
The trees are pre-computed claims, dated, with the method published beside each one. Every one of them is derived from what a surface architecturally is — that a command-line agent running under your account reaches what your account reaches is a fact about command-line programs, not a claim about whoever wrote one. Where a node comes from something stronger, it says so. Browse the whole library, disagree with it, and send the disagreement to comms — there is no feedback box here, because a feedback box is a text box.