Isolate WS-042 for 30 minutes
Endpoint bound. Alert current. Duration in policy. Capability in band.
Controlled scenarios
Identity tells an agent what capabilities it possesses. OntoGuard determines whether this exact security action, against this exact target, under these exact conditions, may become a production consequence.
Security agents are being asked not only to recommend, but to isolate endpoints, contain identities, disable accounts, and push rules. A token or role that can call those tools is not the same as permission for this exact action.
Not a customer SOC production case. No hardware-attestation, production non-bypassability, or L5 claim.
Endpoint bound. Alert current. Duration in policy. Capability in band.
Or duration changed to indefinite. The prior ALLOW no longer binds.
Or tenant-wide firewall rule. Qualified human security authority required.
Open these cases in Proof Explorer Authorization vs IAM / OAuth
Security agent proposes an action → OntoGuard Decision Authorization → ALLOW / BLOCK / ESCALATE → SOC execution path or human authority → evidence of effect or no-bind.
Detection, correlation, and playbook content stay with the security stack. OntoGuard authorizes the exact remediation movement. Customer-production enforcement requires the SOC route to consume the decision fail-closed.