What this is

Zero-Trust Policy Forge is a local-only authorization laboratory. Choose a deterministic request or compose your own from modeled identities, devices, resources, actions, and context; then walk the ordered policy stack predicate by predicate until the first match decides—or the implicit final rule denies it. Edit, reorder, duplicate, tighten, or widen rules and the sixteen-case corpus, rule reachability, weighted blast radius, and least-privilege score all recalculate from the same evaluator.

Why this is mind-blowing

“Least privilege” usually survives as a diagram and a promise. Here it is executable, falsifiable, and portable: an unmanaged tablet, stale session, off-hours administrator, or attested service call leaves a visible trace; a careless grant immediately becomes an over-permission count and a larger blast radius; a duplicated rule reveals itself as shadowed. The policy does not merely say what should happen—it proves what will happen.