Methodology

Define. Check. Retest.

A three-step cycle that turns access rules into evidence.

01

Define the rule

Write permission rules in plain language — naming the user, the data or tool, and the action. TokenVeto converts them into automated checks.

Explore this step
02

Check the evidence

Checks run against a local copy of your app. Verdicts come from backend records and what each test user could actually reach — not from the agent's claims.

Explore this step
03

Retest the fix

After a repair, the same checks rerun and runs are compared: repaired failures, remaining failures, preserved passes and anything newly broken.

Explore this step

Paired controls

Every forbidden request that must be refused is paired with an allowed request that must still work. A fix that over-blocks a covered workflow fails instead of passing.

Local by design

Runs and evidence stay on your machine. The workbench listens only on localhost and exports JSON, HTML reports or SARIF 2.1.0.