Endpoint isolation
Bound target and duration. A different host or an indefinite window is a new action.
Solutions
Authorize autonomous security actions before remediation becomes production consequence.
Security agents are being asked to isolate endpoints, revoke sessions, disable accounts, quarantine hosts, and push network policy. Identity and tool scope say what the agent can invoke. They do not decide whether this exact action, against this exact target, under these exact conditions, may proceed.
OntoGuard does not detect threats and does not replace SIEM, EDR, XDR, or security orchestration. It determines whether the exact remediation action proposed by an agent has sufficient standing and authority to proceed, and returns ALLOW, BLOCK, or ESCALATE.
Bound target and duration. A different host or an indefinite window is a new action.
Authorize the exact identity and scope of revocation before it executes.
Disablement and role changes route to qualified security authority when blast radius exceeds the autonomous band.
Tenant-wide or production-path changes are not implied by a prior bounded ALLOW.
Prove whether a protected effect formed — or did not.
ESCALATE exists so high-consequence remediation is not autonomous by default.
A SOC agent proposes isolate WS-042 for 30 minutes. If evidence, target binding, capability, and duration are inside policy, OntoGuard can ALLOW that frozen action. If the target becomes DB-PROD-01 after authorization, the prior decision does not bind. If the proposal is to disable a privileged production service identity, OntoGuard can ESCALATE to human security authority.
Those three states are shown as controlled public-safe scenarios. They are not yet a current-pack Strict-Six cybersecurity acceptance set, and they were not exercised through the AgenTrust TRACE adapter.
See controlled scenarios Authorization vs IAM / OAuth Talk to us about a SOC corridor