Agentic Restorations Matrix
How do I get back to a known-good state and not repeat this?
Filter
Layers, by what they can actually enforce
- In-agent (empty) — none
The agent is the patient, not the surgeon. Empty for recovery.
- Client-side rebuild — low-blast-radius
Operator-machine actions. Minutes. Reversible.
- Server-side restore — high-blast-radius
Target-system actions. Minutes to hours. The only way to recover from cluster-level compromise.
Showing 5 of 15.
Identity at Client-side rebuild
Regenerate credential file with strict ACLs, rotate OIDC client secret, re-authenticate operator host to SSO, verify ACLs survived.
Authorization at Client-side rebuild
Restore local hook config from VCS, verify file ownership and ACLs, reinstall pre-commit hooks, verify Claude Code is on the patched version.
Blast radius at Client-side rebuild
Rebuild operator host from known-good image if untrusted, reinstall agent runtime with signature verification, re-derive sandbox profiles.
Approval gating at Client-side rebuild
Restore PreToolUse config from VCS, reapply tier definitions, re-enable Auto Mode, re-establish out-of-band channel.
Supply chain at Client-side rebuild
Reinstall agent runtime with signature verification, re-pin MCP hashes from clean source, regenerate lockfiles from declared deps.