01 / The operating case
What changes in a real workflow?
A security agent detects a suspected breach and proposes disabling a tenant-wide integration. Normal policy requires human approval, but the incident may be urgent.
- 01Authority origin
- 02Task and grant
- 03Current decision
- 04Observed outcome
02 / Decision contract
What the executor must check
Define qualifying triggers, who may activate the override, exact target and action, maximum duration, independent logging and post-use review. Keep the executor’s safety and tenant boundaries intact.
03 / Failure and evidence
What goes wrong, and what can be proven?
The agent flags its own request as an emergency and bypasses all policy indefinitely, or an override credential remains active after incident closure.
Record trigger source, initiator, incident, grant scope, activation and expiry, each decision, resulting state and reviewer disposition.
04 / Canonical scope
Why this reference stands alone
High-impact approval covers planned actions; this page owns exceptional authority issuance and termination under emergency conditions.
Implementation review
Break-glass lifecycle
Incident I-9 validated → authorized operator activates override O-3 for tenant T, action disable_integration, 15-minute expiry → executor records each use → expiry or closure revokes O-3 → reviewer reconciles state.
Adversarial check
Have the agent set its own emergency flag or use O-3 against another tenant after expiry. Both should be denied without relying on a prompt instruction.
Primary references