Runtime Response
Controls Delivered in Validated Stages
Audit is available today. Other modes become available only after host protocol, latency, and rollback gates pass.
Five-Tier Policy Modes
From log-only to force deny, the table separates current capability, coming soon, and roadmap states.
| Mode | Behavior | Use Case | Phase | Status |
|---|---|---|---|---|
| Audit | Log only, no blocking | Default on launch | Phase 1 | Available |
| Warn | Alert + notify, no blocking | Risk education period | Phase 2 | Coming Soon |
| Approve | Requires manual approval | Medium-high risk actions | Phase 2 | Coming Soon |
| SoftBlock | Pause action, temporary bypass allowed | High risk with business continuity needs | Phase 3 | Roadmap |
| HardBlock | Force deny execution | Confirmed malicious or high-risk boundary breach | Phase 3+ | Roadmap |
Four Response Action Families
AIDR's target response surface spans identity, data, execution, and remediation, with a separate delivery state for each family.
Identity Enforcement
Session termination, token revocation, and privilege reduction through IdP and Agent identity context.
Integration targetData Protection
Masking and sensitive-path observation are available; content blocking depends on host rewrite protocols.
Partially availableExecution Controls
Audit is available; Approve, SoftBlock, and HardBlock ship through host-specific gates.
StagedRemediation Orchestration
Send investigation evidence and recommended actions into SIEM/SOAR or enterprise response workflows.
Integration targetEnforcement Trigger Conditions
Initial set of recommended high-risk trigger scenarios.
Sensitive File Boundary Breach
Access to private keys, credentials, critical system configs
New Endpoint + High-Risk Tool Combo
Unknown domain + shell/network toolchain
Permission Decision Oscillation
High-frequency deny→allow→deny pattern
MCP High-Risk Cross-Domain Call
Non-whitelisted server/tool combination
High-Risk Rule Hit
OWASP Agentic high-risk action match
Design Principles
Transparent Availability
Roadmap controls are never presented as current
Controlled Latency
Online enforcement meets low-latency thresholds
Recoverable Blocks
All paths have bypass/rollback options
Local-First Execution
Client-side fast judgment to avoid timeouts