15-Minute Review Path

CISO and security architect review without the artifact maze

SMERC is recoverability-aware runtime permission infrastructure. This page gives a serious reviewer the fastest path from claim to proof: product boundary, MCP Gateway, GitHub Actions pilot, replay evidence, and a shadow-mode pilot decision.

Timed Review

What to inspect in 15 minutes

Each step points to a repo-backed artifact. The purpose is to decide whether a bounded shadow-mode pilot is worth a conversation.

0-3

Claim And Limits

Understand the product claim, what exists, and what is not claimed.

Open start page
3-6

MCP Gateway

Inspect the runtime path where agents request tool calls and SMERC returns forward or block guidance.

Open gateway doc
6-9

First Pilot

Review the safest first customer path: one workflow family, observe mode, reviewer labels, and go/no-go criteria.

Open quickstart
9-12

Replay Evidence

Check how SMERC preserves posture, reason codes, controls, route behavior, and decision lifecycle evidence.

Open report
12-15

Pilot Decision

Decide whether the target workflow has side effects, trusted metadata, review ownership, and useful recoverability risk.

Open intake

Why A CISO Might Care

Authorization is not the same as recoverability

Identity, IAM, OPA, approvals, CI/CD checks, and monitoring remain necessary. SMERC adds a runtime question before side effects occur: if this action is wrong, unstable, poorly evidenced, or too broad, can the organization recover?

Action boundaryTool calls, deployments, data movement, workflow automation, and financial-action metadata.
Intermediate posture`THROTTLE`, `FREEZE`, and `ESCALATE` preserve useful automation without pretending every risk is binary.
Evidence loopReason codes, controls, replay IDs, route behavior, reviewer labels, and lifecycle records.
First pilotObserve only. Compare SMERC posture with reviewer judgment before enforcement.