LxLex
Reads your policy like a lawyer reads a contract. Explains any rule in plain language and finds the conflicts and shadow rules that piled up over the years. No matter if for SWG, firewall, ZTNA or any other service.
Your policy is a contract. Lex has read all of it.
Every mature environment carries years of accumulated policy: rules nobody dares to touch, exceptions whose reason left the company, objects referenced in three places and understood in none. Lex is the specialist that has actually read it all. He explains any rule in plain language and knows what every change would touch.
More than that, he finds what should not be there: the conflicts, the shadow rules, the exception that quietly swallowed the rule below it. The cleanup nobody had time for becomes a conversation.
Plain language
Any rule explained the way a lawyer reads a contract clause.
Conflicts found
Shadow rules, dead exceptions and redundant entries, surfaced.
Every service
SWG, firewall, ZTNA and beyond, read as one body of law.
What Lex learns.
- Your full policy set, across SWG, firewall, ZTNA and every other service, as one body of law
- 35 years of policy work: how rules age, conflict and accumulate in real environments
- What each rule actually does on the wire, tied to live evidence, not just its comment field
Plain language in, clean policy out.
- Explains any rule, section or policy in plain language
- Finds conflicts, shadow rules and dead exceptions that piled up over the years
- Shows exactly which rules reference an object, before you change it
- Works across services: SWG, firewall, ZTNA and beyond, one specialist for all of it
Read the policy like a contract.
Lex reads your whole policy set as one document, explains any part of it, and finds what should not be there.
1 - Parse every service
Ingests firewall, ZTNA and SWG rules, sections, objects and comments as one connected policy.
2 - Build the rule graph
Maps how rules order, reference objects and overlap, so shadowing and redundancy become visible.
3 - Explain in plain language
Turns any rule, section or object into a sentence you can act on, with what it does on the wire.
4 - Flag and fix
Surfaces conflicts and dead exceptions, and shows the safe clean-up with what each change would touch.
A rule, and what it really does.
Representative output. Every line links to the underlying records in the portal.
Grounded in your rule base.
| Policy across services | Firewall, ZTNA and SWG rules, sections, objects and comments. |
|---|---|
| Reference graph | Where every object and address is used, so nothing changes blind. |
| Live behaviour | Hit counts and matched traffic, to tell a live rule from a dead one. |
| Change history | How the policy accumulated, to explain why a rule is there. |
Reports to Lucy. You talk to her.
You never address Lex directly. Ask Lucy "what does this firewall rule actually do?" and she consults him behind the curtain, then answers in one voice, with Lex named as the source. He works alongside the rest of the team:
Autonomous, not autonomous-washing.
Grounded
Every explanation cites the actual rule and its live behaviour, not free-form generation.
Bounded autonomy
Lex explains and recommends; any policy change still runs through propose, approve, act.
Human accountability
Level-3 engineers own every critical call. No L1, no L2.
Sovereign-aware
Scoped to your tenant, region-pinned, with the evidence to prove it.
Go deeper.
Maturity: Rolling out. Lex ships with Lucy: no extra tool, no separate console, no additional contract. Your policy gets a voice inside the conversation you already have.
See the operators run your SASE.
Watch the agents diagnose, decide and act, with Level-3 engineers owning every critical call.
Book a demo →