Govern

Runtime Response
Controls Delivered in Validated Stages

Audit is available today. Other modes become available only after host protocol, latency, and rollback gates pass.

Five-Tier Policy Modes

From log-only to force deny, the table separates current capability, coming soon, and roadmap states.

ModeBehaviorUse CasePhaseStatus
AuditLog only, no blockingDefault on launchPhase 1Available
WarnAlert + notify, no blockingRisk education periodPhase 2Coming Soon
ApproveRequires manual approvalMedium-high risk actionsPhase 2Coming Soon
SoftBlockPause action, temporary bypass allowedHigh risk with business continuity needsPhase 3Roadmap
HardBlockForce deny executionConfirmed malicious or high-risk boundary breachPhase 3+Roadmap

Four Response Action Families

AIDR's target response surface spans identity, data, execution, and remediation, with a separate delivery state for each family.

Identity Enforcement

Session termination, token revocation, and privilege reduction through IdP and Agent identity context.

Integration target

Data Protection

Masking and sensitive-path observation are available; content blocking depends on host rewrite protocols.

Partially available

Execution Controls

Audit is available; Approve, SoftBlock, and HardBlock ship through host-specific gates.

Staged

Remediation Orchestration

Send investigation evidence and recommended actions into SIEM/SOAR or enterprise response workflows.

Integration target

Enforcement Trigger Conditions

Initial set of recommended high-risk trigger scenarios.

Sensitive File Boundary Breach

Access to private keys, credentials, critical system configs

New Endpoint + High-Risk Tool Combo

Unknown domain + shell/network toolchain

Permission Decision Oscillation

High-frequency deny→allow→deny pattern

MCP High-Risk Cross-Domain Call

Non-whitelisted server/tool combination

High-Risk Rule Hit

OWASP Agentic high-risk action match

Design Principles

Transparent Availability

Roadmap controls are never presented as current

Controlled Latency

Online enforcement meets low-latency thresholds

Recoverable Blocks

All paths have bypass/rollback options

Local-First Execution

Client-side fast judgment to avoid timeouts