Methodology
Define. Check. Retest.
A three-step cycle that turns access rules into evidence.
Define the rule
Write permission rules in plain language — naming the user, the data or tool, and the action. TokenVeto converts them into automated checks.
Explore this stepCheck the evidence
Checks run against a local copy of your app. Verdicts come from backend records and what each test user could actually reach — not from the agent's claims.
Explore this stepRetest the fix
After a repair, the same checks rerun and runs are compared: repaired failures, remaining failures, preserved passes and anything newly broken.
Explore this stepPaired controls
Every forbidden request that must be refused is paired with an allowed request that must still work. A fix that over-blocks a covered workflow fails instead of passing.
Local by design
Runs and evidence stay on your machine. The workbench listens only on localhost and exports JSON, HTML reports or SARIF 2.1.0.