Agentic Interventions Matrix
How do I stop the bleeding now?
Filter
Layers, by what they can actually enforce
- In-agent (empty) — none
An agent acting badly cannot be reliably told to stop. Empty for response. Listed for completeness.
- Client-side cutoffs — fast
Operator-machine actions. Milliseconds to seconds. Effective if the agent is contained to one host.
- Server-side cutoffs — authoritative
Target-system actions. Seconds to minutes. Catches agents and operator hosts that have been compromised.
Showing 5 of 15.
Identity at Client-side cutoffs
Kill agent process tree, delete local credential file, force re-authentication on next launch, logout SSO session on the operator host.
Authorization at Client-side cutoffs
Force-replace local hook config with deny-all, lock with chattr +i, kill running agent.
Blast radius at Client-side cutoffs
kill -KILL the agent process tree, tear down sandbox, optionally network-isolate operator host, docker stop or kubectl delete pod.
Approval gating at Client-side cutoffs
Replace approval hook with deny-all, disable Auto Mode classifier, disable judgment-query escalation channel, force out-of-band on every action.
Supply chain at Client-side cutoffs
Remove suspect MCP server from allowlist, quarantine downloaded packages to restricted location, lock lockfile, pin runtime to last-known-good, kill agent.