01 / Attack path
How the boundary is crossed
A remediation agent proposes restarting a production database because a telemetry note says it is unhealthy.
- 01Lower-trust input
- 02Attempted instruction
- 03Protected action
- 04Enforced decision
02 / Containment
Where bounded authority limits the effect
Require a current incident, exact resource and operation grant, change window and independent approval for high-impact targets before the cloud API call.
03 / Failure and evidence
The attacker’s opportunity and the defender’s record
A broad operations role converts a model recommendation into a production restart.
Record incident, target, command, approver, enforcement result and independently observed service state.
04 / Canonical scope
Why this reference stands alone
Policy bypass concerns routing around the check; this threat owns the unauthorized change itself.
Protocol or attack trace
Production-change gate
Telemetry text suggests restarting database D while incident grant only covers host H.
Cloud API denies restart of D; high-impact change requires current maintenance context and approval.
Primary references