Policies

Governance rules · read-only view

Demo environment · simulated telemetry. Policy modes are edited in the Autonomy Center. Destructive actions are locked to never-automatic at every level.

CS-AUTO-01SAFEAutomatic

Petavora may automatically revoke suspicious OAuth tokens.

Action
Revoke OAuth token
Minimum level
Level 3
Confidence floor
85%
Scope
Third-party grants on non-admin identities
Approvers
Not required
Rollback
Re-consent flow; user re-authorises the integration.
CS-AUTO-02SAFEAutomatic

Petavora may automatically expire sessions showing impossible-travel or token-theft signals.

Action
Revoke active session
Minimum level
Level 3
Confidence floor
80%
Scope
All human identities
Approvers
Not required
Rollback
User signs in again; no state is lost.
CS-AUTO-03CONTROLLEDAutomatic

Petavora may automatically narrow an AI agent to its declared purpose when drift is observed.

Action
Restrict AI agent scope
Minimum level
Level 4
Confidence floor
88%
Scope
Non-production agents and finance/support agents
Approvers
Not required
Rollback
Restore previous agent policy version.
CS-AUTO-04CONTROLLEDAutomatic

Petavora may rotate a credential whose exposure is confirmed by two independent signals.

Action
Rotate exposed credential
Minimum level
Level 4
Confidence floor
90%
Scope
Service credentials with an automated consumer refresh
Approvers
Not required
Rollback
Previous version retained for 24 h in the secret store.
CS-AUTO-05CONTROLLEDAutomatic

Petavora may isolate a device on confirmed hands-on-keyboard activity.

Action
Isolate endpoint
Minimum level
Level 4
Confidence floor
92%
Scope
Employee laptops; excludes clinical and OT devices
Approvers
Not required
Rollback
Release from isolation restores connectivity immediately.
CS-AUTO-06CONTROLLEDRequires approval

Petavora may remove a single over-broad permission on a predicted attack path.

Action
Remove a specific permission
Minimum level
Level 5
Confidence floor
93%
Scope
Non-break-glass roles only
Approvers
Security admin or resource owner
Rollback
Re-grant from the recorded prior role binding.
CS-AUTO-07HIGH RISKRequires approval

Petavora must request approval before blocking an east-west network path.

Action
Block network connection
Minimum level
Level 4
Confidence floor
90%
Scope
Production segments
Approvers
Network owner + security admin
Rollback
Remove the temporary deny rule.
CS-AUTO-08HIGH RISKRequires approval

CyberShield must request approval before disabling employee accounts.

Action
Disable an employee account
Minimum level
Level 4
Confidence floor
95%
Scope
All human identities
Approvers
Security admin + people-ops on record
Rollback
Re-enable the account; group membership is preserved.
CS-AUTO-09HIGH RISKRequires approval

Petavora must request approval before disabling a business application integration.

Action
Disable application integration
Minimum level
Level 4
Confidence floor
90%
Scope
All first- and third-party integrations
Approvers
Application owner
Rollback
Re-enable the integration and replay the queued jobs.
CS-AUTO-10DESTRUCTIVENever automatic

CyberShield must never automatically delete or tear down production resources.

Action
Quarantine production workload
Minimum level
Level 5
Confidence floor
100%
Scope
Production cloud resources and databases
Approvers
Incident commander, executed by a human
Rollback
No reversal path
CS-AUTO-11HIGH RISKRequires approval

Petavora must request approval before revoking a shared API key used by more than one consumer.

Action
Revoke API key
Minimum level
Level 4
Confidence floor
90%
Scope
Shared keys; single-consumer keys fall under CS-AUTO-04
Approvers
Service owner
Rollback
Issue a replacement key; the old key cannot be restored.

AI agent control plane

Agent action policies

Open agents ↗
Restrict permissionNarrows a granted scope without stopping the agent.CS-AGENT-03 · pre-authorisedPre-authorised
Revoke toolRemoves a tool from the agent's allowed list immediately.CS-AGENT-03 · pre-authorisedPre-authorised
Require human approvalEvery subsequent sensitive action waits for a named approver.CS-AGENT-05 · pre-authorisedPre-authorised
Revoke credentialInvalidates the agent's service credential; dependent jobs fail until reissued.CS-PROD-07 · named approvalApproval required
Pause agentStops new agent runs. In-flight work completes.CS-PROD-07 · named approvalApproval required
Quarantine agentIsolates the agent identity from every downstream system.CS-PROD-07 · named approvalApproval required
Restore previous policyRolls the agent policy back to its last known-good version.CS-AGENT-08 · change-owner approvalApproval required