Solution · Cyber

Govern high-impact security AI actions with proof

When autonomous security agents attempt remediation or access changes with broad blast radius, Recon evaluates delegated authority at the boundary—before the action becomes an incident you cannot explain.

Anchored scenario

An autonomous security agent attempts to revoke credentials and isolate endpoints across a production segment.

  1. PolicyPolicy requires SOC lead approval before remediation executes.
  2. Trust Receipt Trust Receipt records the hold, policyId, and authority context.
  3. LedgerLedger preserves the same correlationId for audit and investigation.
  4. Mission Control When Policy escalates, operators open the receipt in Mission Control to investigate and coordinate review.

01 · Urgency

What can go wrong?

Security-adjacent AI can attempt high-impact actions—credential revocation, endpoint isolation, or access changes—without a durable record of who authorized what. When IR leadership or auditors ask why an action occurred, fragmented logs are not defensible proof.

  • Agent remediation crosses delegated authority without an explicit approval check
  • No inspectable record ties the action to policy and approver context
  • Incident response requires manual reconstruction across SIEM, SOAR, and chat logs

02 · Govern

What does Recon govern?

Recon governs the AI-action boundary: each governed interaction is one Trust Atom—observed, evaluated against your Policy, and resolved before execution proceeds. You configure rules; Recon enforces them consistently and returns a decision your systems can act on.

  • Observe the attempted security action with org scope and integration context
  • Evaluate trust and exposure against Policy—not opaque model confidence
  • Return permit, hold, or escalate outcomes your workflow can enforce

03 · Control

What happens when Policy intervenes?

Policy is business control—not an architecture diagram. Your team defines who may execute remediation, when SOC lead must approve, and what happens on violation. Recon applies those rules on every governed interaction.

  • Permit when authority and scope match your security Policy
  • Hold or require approval when high-impact remediation needs operator review
  • Escalate to human operators when blast radius exceeds automated thresholds

04 · Proof

What proof do I retain?

Every governed interaction produces a Trust Receipt—inspectable evidence of the action, Policy decision, and authority context. The Ledger appends durable evidence tied to the same correlationId so audit and investigation do not depend on internal graphs.

  • Trust Receipt — open the artifact and see why Recon decided permit, hold, or escalate
  • Ledger — confirm the entry persists for retention and export workflows
  • One correlationId threads from remediation → decision → receipt → ledger entry
require_approvalTrust ReceiptSample

Recon requires approval before this action proceeds.

correlationId
tacorr_8f3a2b1c4d5e6f708192a3b4c5d6e7f8
receiptId
a1b2c3d4e5f6789012345678901234567890abcdef1234567890abcdef123456
decision
require_approval
policyId
policy_cyber_delegated_authority_gate
actionType
cyber_remediation_access_action

Ledger

The Ledger is your durable evidence spine—every Trust Receipt links back to the same correlationId for retention and audit.

correlationId
tacorr_8f3a2b1c4d5e6f708192a3b4c5d6e7f8
ledger.entryId
b2c3d4e5f6789012345678901234567890abcdef1234567890abcdef1234567890
Confirm sample in Ledger →

05 · Outcome

What business risk does that reduce?

Teams reduce operational risk, audit friction, and blast-radius exposure from ungoverned security AI actions. You can show what was attempted, which Policy applied, and what proof exists—without asking buyers to learn internal runtime vocabulary.

  • Operational defensibility — explain high-impact AI remediation with attributable proof
  • Audit readiness — Ledger retention supports review and export without log stitching
  • Blast-radius containment — holds and escalations fire before irreversible access changes execute

Illustrative buyer language only—not automated remediation, not ticketing integration, and not a replacement for your SIEM or IR platform.

Home