What it does today
- Time-bounded protection plans, scoped to applications or namespaces, mode-flagged audit or enforce.
- Nine built-in policy templates with parameterised inputs where the behaviour demands it.
- Live cluster-truth plan health with drift detection and a violations feed.
- Live application discovery, change classification, and snapshot-backed rollback as the operational floor.
- Passkey-first auth, Google SSO, and CRD-based RBAC.