Doctor
See what changed, what became reachable, and what to fix first.
Read-only metadata becomes signed access evidence. Traffic and payloads stay private.
Nockset reads bounded access metadata and never requests provider traffic payloads.
Establish a signed observation before simulating credential misuse.
Recent checkups
Encrypted on this deployment and signed by Doctor.
Preview only. Nothing here can execute or change provider state.
Contain with explicit authority
Select a typed action, approve the signed plan, then spend its one-use capability.
The plan is signed, time-bounded, and cannot execute until approved.
Trace effective access
Choose a possible compromise root. Doctor simulates reachable risk from the encrypted signed observation.
Select an identity, device, workload, or credential to test.
No checkup has run on this device
Run a checkup to compare effective access with the previous signed observation.
New risks
Findings introduced since the last signed observation.
Access changes
Exact principals, grants, credentials, and resources that changed.
Attack paths
New paths from a compromise root to sensitive resources.
Resolved
Risk removed since the previous observation.
Evidence and attestation
- Snapshot
- Connector
- Request