$ neti demo --here --repo <path> -c <path>
[exit 0]
neti demo — measured on <path>

── 1. DISCOVER ─────────────────────────────────────────  read from this machine
   no MCP servers configured on this machine

── 2. REACH ────────────────────────────────────────────  MEASURED here, no traffic needed
   listening   filesystem                 32 objects
   dark        source control              — export NETI_GITHUB_TOKEN
   dark        database                    — export NETI_DATABASE_URL
   dark        object storage              — export AWS_ACCESS_KEY_ID
   dark        directory                   — export NETI_TENANT_ID
   listening   infrastructure              — reachable_max_requires_terraform_state
   no resolver shell                       — what a command would delete — a grammar, not a value (NC-09, NC-10)
   no resolver messaging                   — Slack, Teams, outbound email outside a directory
   no resolver SaaS records                — CRM objects, tickets, documents in a vendor's own store

   2 layer(s) listening · 4 dark for want of a credential · 3 with no resolver at all

   An agent working here reaches 32 objects, across 8 gated parameter(s).
   It bounds what one credential can address here; it does not measure any single call. Nothing in a permission system reports either number — it answers whether, not how many.

Acts 3-6 need traffic, and you have none yet.
   Install the hook and work normally for an afternoon:
     {"hooks": {"PreToolUse": [{"matcher": "*",
       "hooks": [{"type": "command", "command": "neti hook -c neti.yaml"}]}]}}
   Then run this again — acts 3 to 6 need traffic, and that is how you get it.

Measured on this machine. Every number above was produced by walking these files, through the same decision path the gate uses in production.

Nothing to wait for on the other half: `neti prove` runs one call through every door
this machine has and shows they all reach the same verdict, with a chain you can
re-check yourself.
