Solution · Cyber
Govern high-impact security AI actions with proof
When autonomous security agents attempt remediation or access changes with broad blast radius, Recon evaluates delegated authority at the boundary—before the action becomes an incident you cannot explain.
Anchored scenario
An autonomous security agent attempts to revoke credentials and isolate endpoints across a production segment.
- Policy — Policy requires SOC lead approval before remediation executes.
- Trust Receipt — Trust Receipt records the hold, policyId, and authority context.
- Ledger — Ledger preserves the same correlationId for audit and investigation.
- Mission Control — When Policy escalates, operators open the receipt in Mission Control to investigate and coordinate review.
01 · Urgency
What can go wrong?
Security-adjacent AI can attempt high-impact actions—credential revocation, endpoint isolation, or access changes—without a durable record of who authorized what. When IR leadership or auditors ask why an action occurred, fragmented logs are not defensible proof.
- Agent remediation crosses delegated authority without an explicit approval check
- No inspectable record ties the action to policy and approver context
- Incident response requires manual reconstruction across SIEM, SOAR, and chat logs
02 · Govern
What does Recon govern?
Recon governs the AI-action boundary: each governed interaction is one Trust Atom—observed, evaluated against your Policy, and resolved before execution proceeds. You configure rules; Recon enforces them consistently and returns a decision your systems can act on.
- Observe the attempted security action with org scope and integration context
- Evaluate trust and exposure against Policy—not opaque model confidence
- Return permit, hold, or escalate outcomes your workflow can enforce
03 · Control
What happens when Policy intervenes?
Policy is business control—not an architecture diagram. Your team defines who may execute remediation, when SOC lead must approve, and what happens on violation. Recon applies those rules on every governed interaction.
- Permit when authority and scope match your security Policy
- Hold or require approval when high-impact remediation needs operator review
- Escalate to human operators when blast radius exceeds automated thresholds
04 · Proof
What proof do I retain?
Every governed interaction produces a Trust Receipt—inspectable evidence of the action, Policy decision, and authority context. The Ledger appends durable evidence tied to the same correlationId so audit and investigation do not depend on internal graphs.
- Trust Receipt — open the artifact and see why Recon decided permit, hold, or escalate
- Ledger — confirm the entry persists for retention and export workflows
- One correlationId threads from remediation → decision → receipt → ledger entry
Recon requires approval before this action proceeds.
- correlationId
- tacorr_8f3a2b1c4d5e6f708192a3b4c5d6e7f8
- receiptId
- a1b2c3d4e5f6789012345678901234567890abcdef1234567890abcdef123456
- decision
- require_approval
- policyId
- policy_cyber_delegated_authority_gate
- actionType
- cyber_remediation_access_action
Ledger
The Ledger is your durable evidence spine—every Trust Receipt links back to the same correlationId for retention and audit.
- correlationId
- tacorr_8f3a2b1c4d5e6f708192a3b4c5d6e7f8
- ledger.entryId
- b2c3d4e5f6789012345678901234567890abcdef1234567890abcdef1234567890
05 · Outcome
What business risk does that reduce?
Teams reduce operational risk, audit friction, and blast-radius exposure from ungoverned security AI actions. You can show what was attempted, which Policy applied, and what proof exists—without asking buyers to learn internal runtime vocabulary.
- Operational defensibility — explain high-impact AI remediation with attributable proof
- Audit readiness — Ledger retention supports review and export without log stitching
- Blast-radius containment — holds and escalations fire before irreversible access changes execute
Illustrative buyer language only—not automated remediation, not ticketing integration, and not a replacement for your SIEM or IR platform.