strazactl policy simulate
Ask what a call would do for a subject, against the live policies
On this page
Synopsis
Evaluate one event for one subject against the policies live right now, optionally with a PolicySet from a local file overlaid in place of its same-named stored set (a preview of what publishing would produce).
Exactly one of --user (real roles, resolved server-side) or --roles (a hypothetical) is required. --event defaults to tool.pre. Any other event field goes in --event-json, a file that holds the whole event object. The verdict is the answer, not an enforcement result: simulate exits 0 on every verdict.
strazactl policy simulate [flags]
Examples
strazactl policy simulate --user dana --tool shell.exec --command "rm -rf /home/dana/work/build"
strazactl policy simulate --roles local-tools --tool shell.exec --command "kubectl apply -f deploy/app.yaml"
strazactl policy simulate --user dana --event-json recorded-event.json
Options
--app string mcp.call: the MCP server's name
--attestation string subject attestation: none, advisory, or managed (default none)
--command string shell.exec: the raw command line
--event string event kind (default "tool.pre")
--event-json string read the full event object from a JSON file (excludes the per-field event flags)
-f, --file string PolicySet YAML to overlay on the live policies
--path stringArray file.*: affected path (repeatable)
--roles strings simulate a hypothetical subject holding these roles (comma-separated)
--tool string tool id (e.g. shell.exec, mcp.call, file.write)
--tool-name string mcp.call: upstream tool name
--user string simulate this user (real roles, resolved server-side)
Options inherited from parent commands
--server string strazad base URL (overrides $STRAZA_SERVER and the server you logged into)
See also
- strazactl policy: Validate and manage PolicySets