Break-glass abuse by automation

Emergency privileges are invoked by an agent without the narrow incident and accountable operator that justify them.

01 / Attack path

How the boundary is crossed

A monitoring agent declares an emergency and uses a break-glass role to disable tenant-wide access controls.

Attack path and interception point
  1. 01Lower-trust input
  2. 02Attempted instruction
  3. 03Protected action
  4. 04Enforced decision

02 / Containment

Where bounded authority limits the effect

Require human initiation or a narrowly defined emergency trigger, short duration, exact target, independent logging and prompt post-use review.

03 / Failure and evidence

The attacker’s opportunity and the defender’s record

Exploit condition

The agent can self-declare the emergency and bypass the normal policy path indefinitely.

Evidence to retain

Record trigger evidence, initiator, role activation, duration, operations, observed effects and review.

04 / Canonical scope

Why this reference stands alone

Ordinary approval covers planned high-impact action; this page owns exceptional privilege activation and expiry.

Protocol or attack trace

Self-declared emergency

Sequence

Monitoring agent sets emergency flag and requests tenant-wide firewall disablement.

Negative test

Reject self-issued emergency claim; require accountable trigger, bounded override and separate expiry check.

Primary references

Read the underlying material

Architecture discussion

Choose one consequential action and make its boundary explicit.

Request a Conversation