Policy playground
Nebula's safety boundary is deterministic code, not a prompt. Configure the fund-control policy and a proposed action below; the verdict is computed by the same pure function that guards the agent on-chain. The model proposes, this disposes.
Policy (NEBULA_POLICY_*)
Hard cap (MNT/tx)
Auto ceiling (MNT)
Max slippage (bps)
Autonomy
Token allowlist (comma-separated; empty = any)
Recipient allowlist (empty = any)
Proposed action
Kind
Amount (MNT)
Asset
Recipient
NEEDS APPROVALdeterministic verdict
Permitted, but material-risk — the agent pauses and asks for human approval before it broadcasts, even under YOLO. The deterministic floor sits beneath the session mode.