Demo environment · simulated telemetry. Every recorded action states its initiator, reason, evidence, policy, confidence and result.
09:04:37Defense action
Revoke OAuth token · Stale ledger OAuth grant (m.chen → svc-ledger-prod)
Executed
A never-expiring OAuth grant was used from an unrecognised network path to assume a privileged service identity. Result: Path from m.chen to svc-ledger-prod no longer traversable. Residual paths remain via the ledger secret. Rollback: Re-consent flow; user re-authorises the integration.
Level 2 enrichment triggered by a privileged-identity assumption outside the change window. Result: Investigation handed to the policy engine; no environment change made.
Signing key read by a service identity that had just been assumed through the revoked grant. Result: Payments-api signing healthy after 38 s. One failed signature retried successfully. Rollback: Restore prior key version from the secret store (available for 24 h).
Restrict AI agent scope · Finance Assistant (agt_fin_4b19)
Executed
Observed behaviour outside the declared purpose: payroll read attempt and vendor bank-detail writes. Result: No further out-of-scope calls observed. Two invoice drafts queued for human completion. Rollback: Restore previous agent policy version (v7).
Disable an employee account · m.chen (Finance Operations)
Awaiting approval
Identity is the origin of the confirmed path. Disabling would remove the remaining human entry point. Result: Pending human decision. Rollback: Re-enable the account; group membership is preserved.
Predicted next step on the modelled path is a bulk read of the customer vault. Result: Pending human decision. Rollback: Remove the temporary deny rule.
Remove a specific permission · crm.bulk_export on the support-agent role
Awaiting approval
Pre-emptive narrowing on a predicted enumeration path toward customer records. Result: Pending human decision. Rollback: Re-grant from the recorded prior role binding.
Quarantine production workload · ledger-primary (production database)
Blocked by policy
Candidate containment generated by the simulator for a suspected data-staging pattern. Result: Downgraded to a recommendation for the incident commander.
Revoke active session · d.osei — session from an unrecognised device
Rolled back
Impossible-travel signal between two sign-ins 11 minutes apart. Result: User confirmed the Frankfurt sign-in was their own corporate VPN. Action reversed. Rollback: User signs in again; no state is lost.
Petavora recommended removal; the integration held an unused write scope on the vendor database. Result: Integration disabled; no service impact reported. Rollback: Re-enable the integration and replay the queued jobs.