M ManySignal

Product Tour

Response — Contain Threats with Human Oversight

Step 4 of 8

app.manysignal.io/cases/cas_00142/response

Respond Agent — Proposed Action Plan

okta.suspend_user completed

root@acme.com (Okta)

User suspended in 0.4s

aws_iam.deactivate_access_key completed

AKIAIOSFODNN7EXAMPLE

Access key deactivated

aws_iam.delete_user approval required

attacker-backdoor (IAM)

Awaiting security-lead approval (47 min remaining)

crowdstrike.isolate_host blocked

DESKTOP-CORP-EXEC-01

Guardrail blocked: entity tagged executive-device. Manual action required.

Pending Approval

Delete IAM backdoor user

The Respond Agent proposes deleting the attacker-created IAM user attacker-backdoor. This user has AdministratorAccess. Deleting it revokes all access keys and removes persistence.

Guardrails passed

Entity is not executive

Action not run in last 1h

Blast radius < 80 for this action

1

Graduated autonomy

Different action types run at different autonomy levels. Low-risk actions (suspend user) run supervised. High-risk actions (delete IAM user) wait for explicit approval. Each action's autonomy level is configurable per action type.

2

Guardrails before every action

Before any action executes, the guardrail stack runs: executive-device check, blast-radius threshold, idempotency guard, and change-window check. Blocked actions are logged with the reason.

3

Full verdict card

Every action execution — success, failure, blocked, or approved — generates a verdict card with the agent's reasoning, guardrail results, and action outcome. This is part of the immutable case audit trail.