Product Tour
Response — Contain Threats with Human Oversight
Step 4 of 8
Respond Agent — Proposed Action Plan
okta.suspend_user completed root@acme.com (Okta)
User suspended in 0.4s
aws_iam.deactivate_access_key completed AKIAIOSFODNN7EXAMPLE
Access key deactivated
aws_iam.delete_user approval required attacker-backdoor (IAM)
Awaiting security-lead approval (47 min remaining)
crowdstrike.isolate_host blocked DESKTOP-CORP-EXEC-01
Guardrail blocked: entity tagged executive-device. Manual action required.
Pending Approval
Delete IAM backdoor user
The Respond Agent proposes deleting the attacker-created IAM user attacker-backdoor. This user has AdministratorAccess. Deleting it revokes all access keys and removes persistence.
Guardrails passed
Entity is not executive
Action not run in last 1h
Blast radius < 80 for this action
Graduated autonomy
Different action types run at different autonomy levels. Low-risk actions (suspend user) run supervised. High-risk actions (delete IAM user) wait for explicit approval. Each action's autonomy level is configurable per action type.
Guardrails before every action
Before any action executes, the guardrail stack runs: executive-device check, blast-radius threshold, idempotency guard, and change-window check. Blocked actions are logged with the reason.
Full verdict card
Every action execution — success, failure, blocked, or approved — generates a verdict card with the agent's reasoning, guardrail results, and action outcome. This is part of the immutable case audit trail.