!
{{ haltHeadline }}
No execution token will be minted or honoured while the halt holds. Campaign state stays durable — in-flight runs park at their current gate and resume from there.
{{ haltMeta }}
Lift halt
!
Ring 1 activation gate opens in 6 h 20 m. 12 hosts hold a failed T-0 pre-flight.
Backup currency unverified on 9 hosts · pending reboot on 3 · all 12 auto-deferred and parked with a stewardship task.
Review gate plan
Dismiss
In-scope CIs
4,431
3,998 prod · 433 non-prod
Baseline convergence
86.4%
▲ 3.1 pts vs last cycle
Data confidence
0.71
941 CIs below automation threshold
Human minutes per CI
7.4
▼ 41% since MVP
Unplanned downtime
0 min
attributable · 14 cycles
Critical exposure past SLA
7
1 with no campaign carrying it
Pre-patch and post-patch population
what the platform filled in, not what a human typed
Pre-patch · T-0 readiness
✓Backup currency verifiedRubrik · 1,195/1,204
✓Disk headroom ≥ 12%DataDog
✓Cluster / AG leg stateService Mapping
!Pending reboot on 3 hostsheld
✓Freeze / blackout collisionnone
Post-patch · verdict
✓Baseline diff cleanBigFix relevance 0
✓Health baseline restoredsoak 45 min
✓Synthetics for T1/T2 apps18/18 pass
!Residual vulnerabilities4 CIs · digest sent
✓CHG closed with evidencerun sealed
Autonomy posture
grant matrix
Analysis & recommendationGranted · all tiers
ITSM write-back (supervised)Granted
Gated execution · T4 ring 0Shadow · 96% agreement
Standing grant · T3 catalogGovernance-gated
Demotion is automatic. A regression on any granted cell revokes the grant and re-opens shadow mode on the next cycle.
Agent activity
Console →
Readiness agent returned 1,204 verdicts · 31 low-confidence held
tenable.scan_recency · rubrik.restore_point · 12 min ago
Enrichment agent proposed 74 owner resolutions from AD + DDI
never a silent write · 74 CMDB tasks drafted · 18 min ago
Estate Compliance agent opened 9 drift items into CMP-2026-08-SRV
catalyst.compliance · bigfix.relevance · 34 min ago
Guardrail blocked 1 tool call · write outside token scope
bigfix.issue_baseline → group not in grant · 51 min ago
Data confidence by cohort
Clinical T10.93
Research T20.78
Administrative T30.64
Network edge0.41
Open stewardship queue →
CMP-2026-08-SRV
CMP-2026-08-NET
CMP-2026-08-EMG
Export CAB packet
Advance to G4
Campaign · server track
Server monthly cycle · August 2026
1,204 CIs · T3 standard production · window Thu 02:00–06:00 PT · CHG0048812
Ready
1,142
Held
43
Deferred
19
G0✓
Scope & policy
machine · cohort resolved
G1✓
Readiness verdict
agent · conf 0.91
G2✓
Owner consent
human · 96% ack
G3now
Change approval
standard catalog · 2 exceptions in CAB
G4
Execution authority
human click → scoped token
G5
Health gate
machine · hard gate
G6
Closure
evidence bundle sealed
Ladder computed from risk tier T3, blast radius 22 applications, patch reputation clean, cohort confidence 0.64 — G4 stays human because confidence sits below the standing-grant threshold of 0.80.
Three-key execution
01
Approval — human click at G4
m.kaur@ucsf · pending
02
Scoped token — KMS-signed, single use
ttl 15 min · group SRV-RING1 · verb issue_baseline
03
Actuator verification at the edge
bigfix connector refuses any unsigned write
tok_9f31 · sig verified · replay guard on · idempotency key cmp-08-srv-r1-0042
Evidence bundle
Readiness verdicts + confidence1,204 rows
Model / prompt / policy versionp-4.2 · pol-1.7
Human dispositions41 accept · 6 edit · 2 override
Restore points tagged to CHG1,195 targets
Object Lock ledger writeimmutable
Open in evidence ledger
Notification & consent
t-5 business days noticeSent 1,204
24–48 h reminderQueued
Acknowledged1,156 · 96%
Deferred (cap 2)19 · 3 at cap
Risk-acceptance tasks3 open
Drift SentinelDeterministic
Nightly diffs across every witness. Emits typed drift events with evidence; computes freshness and confidence.
last run 02:14 · 1,904 diffs · no model call
Data StewardAgentic
Classifies conflict causes, drafts CMDB-update tasks with evidence, routes to the accountable steward.
haiku · 412 calls today · 0 direct writes
EnrichmentAgentic
Owner resolution from AD and DDI, MAC derivation, version enrichment, relationship edges — always with provenance.
sonnet · 74 proposals pending review
Estate ComplianceAgentic
Interprets baseline and golden-code drift, separates acceptable variance from action-needed, drafts the convergence narrative.
sonnet · 9 items opened into campaigns
Adding a skill
five artefacts, no platform change
{{ st.n }}
{{ st.cost }}
{{ st.title }}
{{ st.body }}
A new skill is a pull request and a CAB-visible policy change, not a deployment. Sequencing stays in Step Functions, so no skill can invent its own order of operations.
Extension surface
Skills in production6
In canary1 · residual-vuln digest
Proposed · backlog4
Median time to production3 weeks
Blocked on a new MCP tool2 of 4
Blocked on eval data0 · ledger self-labels
The binding constraint on new skills is connector coverage, not model capability. Every skill blocked today is waiting on a tool contract.
Guardrails in force
Tool allowlist per skillOn
Token scope check at actuatorOn
Injection canaries in eval setPermanent
Judgment fields → task onlyEnforced
Pinned model versionscanary first
Kill switch · per trackarmed
Agents propose and analyze inside Step Functions states. They never sequence a workflow and never reach a device directly.
Connector fleet
servicenow · witness + actuator
bigfix · actuator
catalyst · actuator
tenable · witness
rubrik · witness
datadog · witness
netmri · witness · exits 2027
ad + ddi · enrichment
Pattern 1 · MCP — agent-facing, default.
Pattern 2 · direct API — Step Functions to connector, no model in the path.
Pattern 3 · scripted fallback — governed, flagged as debt, never on the T1/T2 execution path.
Unmapped to application
941
▼ 214 this quarter
No maintenance group
482
campaign-driven repair
No maintenance window
81
81 CIs cannot be scheduled
Missing app administrator
669
server-to-application rows
CI enrichment · apex-sql-014
Declared
Owner j.reyes · window unset · tier T2 · app unmapped
confidence 0.38 · stale 214 d
Proposed
Owner a.okafor · window Sun 01:00–05:00 · tier T2 · app Apex Research LIMS
confidence 0.86 · 4 witnesses agree
ADa.okafor manages the security group that owns the service account
DDIDNS record updated by a.okafor 41 d ago
Service mapedge to Apex Research LIMS observed by Discovery
BigFixhistoric patch activity clusters Sun 01:00–05:00
Accept as task
Edit
Reject
disposition recorded as a labelled example
Degradation in force
Fail closed, per CI. One blank field parks one server — never a campaign. Every degradation emits a stewardship task, so this list drains itself.
No owner or escalation chaincontact ladder → hold-for-human
No criticality tiermost restrictive ladder
No dependency edgesrecommend-only · no standing grant
No monitor packno health gate → no execution
No current restore pointauto-defer + snapshot request
CI · CMDB record
srv-ucsfmc-epic-rpt-14
CI00418822 · 10.42.18.114
T3 standard prod
Ring 2 · IT-wide
Steward verified 12 Jul
Open in CMDB
Export evidence
Patch runs on this CI
select a run to load its pre-patch analysis, action log and post-patch verdict
{{ r.id }}
{{ r.outcome }}
{{ r.when }}
{{ run.glyph }}
{{ run.head }}
{{ run.sub }}
{{ run.cta1 }}
{{ run.cta2 }}
{{ m.k }}
{{ m.v }}
{{ m.n }}
Evidence artifacts
{{ a.k }}
{{ a.n }}
{{ a.act }}
Linked records
{{ l.k }}
{{ l.v }}
{{ l.state }}
Steward note
{{ run.note }}
Both tracks
Server
Network
Enumerate blackouts
Publish calendar v1.4
Window and freeze calendar
windows are edited once, in ServiceNow
calendar owner · j.villanueva · version 1.3
Aug 2026
3
4
5
6
7
8
9
10
11
12
13
14
15
16
Server windowsThu 02:00–06:00 PT
Network windowsnegotiated per change
Clinical freezeEpic go-live
Academic blackoutterm start
Fiscal closefinance systems
Every proposed window is checked against enumerated, versioned calendars. Until a calendar is enumerated, scheduling autonomy stays off for the cohort it covers.
Window-less CIs
81CIs cannot be scheduled at all
28 of 81 repaired this quarter · 53 stewardship tasks open
Assign windows manually
ServiceNow → BigFix sync
Integration builtScenario 1 item
Windows drifted outside SoR14 CIs
Last reconciliation02:14 · nightly
Until the sync exists, a window edited in BigFix silently disagrees with the system of record. Scheduling autonomy stays capped on the server track.
AO
a.okafor · 14 owned CIs
research · Apex Research LIMS · escalation chain set
1 notice open
!
Patch window Thu 06 Aug 02:00–06:00 PT affects 6 of your CIs.
Apex Research LIMS is expected offline for approximately 18 minutes per host, sequenced one cluster leg at a time. Acknowledge to confirm, or defer once — the policy cap is 2 deferrals per cycle.
CHG0048812 · notice sent t-5 business days · reminder 24–48 h
Acknowledge
Defer once
Request different window
deferrals used 0 / 2 · at cap a risk-acceptance task is raised
Quarterly attestation
Confirm or reassign ownership for every listed CI in one pass. Ownership that is never attested decays in confidence and loses automation eligibility.
9 of 14 confirmed · window closes 22 Aug · Q3 FY26
Confirm all mine
Reassign 2
Notice language
Research
Patient care
Administrative
Apex Research LIMS will be unavailable for approximately 18 minutes during the window of Thu 06 Aug, 02:00–06:00 PT. Long-running acquisitions should be completed before 01:30 PT.
template v2.1 · sign-off owner unassigned · autonomous send blocked until named
Advisories tracked
128
CVE · vendor KB · PSIRT
Auto-held items
7
reputation below threshold
Exposed CIs
1,412
ranked by severity × exposure
EoX devices
63
Cisco EoX · 2 past last-support
Auto-hold list · published before analysis
KB5041233held
SQL regression on AG secondaries · clears with the August rollup
KB5039119blocked
cluster service restart loop · no clearing release announced
IOS-XE 17.12.1held
superseded by 17.12.4 · stepped upgrade path required from 17.06
A held item never reaches a readiness verdict. The hold list is published to the campaign before analysis begins, so no agent spends a token reasoning about a patch already known bad.
Untrusted input · provenance
Vendor advisory text, CMDB free text and ticket comments are tagged untrusted and structurally extracted. Raw text never reaches a decision.
Extracted fieldsversion, CVSS, affected platforms, known issues
Discardednarrative prose, links, embedded instructions
Injection canariespermanent in eval set
Canary failures this quarter0 of 214
tier · allenv · productionconfidence < 0.80monitor pack · missingprotection · stale
Enroll new CIs
Deploy monitor pack
Golden-code compliance
C9300 · access17.12.4 · 88%
C9500 · distribution17.12.4 · 71%
ASR1001 · edge17.09.3 · 42%
WLC 980017.12.3 · 96%
source · Catalyst compliance-to-golden · mirrored CMDB field pending
Witness health
BigFix agent reporting4,388 / 4,431
DataDog monitor pack3,512 / 3,998 prod
Rubrik protection mappedtiers T1–T3
Tenable scan recencynightly · no on-demand tier
New CIs auto-enrolled31 this week
A CI without a monitor pack has no health gate, so it is recommend-only regardless of tier.
Open findings
18,204
ServiceNow VR · nightly from Tenable
Critical past SLA
7
all 7 in an open campaign or exception
Mean time to remediate
11.2 d
critical · SLO 14 d · down 4.1 d
Scan coverage
94.1%
network track incomplete
Emergency lane
speed changes, control does not
Trigger authoritysecurity lead · named
Change typeemergency CHG · compressed approvals
Wave orderexposure-ordered, not ring-ordered
Three-key executionunchanged
Invoked this year2 · Feb 14 · Jun 03
Open emergency lane
Review Feb 14 run
The lane compresses approval time. It does not remove a gate, mint a wider token, or bypass the clinical exclusion registry.
Scanner witness
Nightly sync to ServiceNow VR02:40 · green
Scan SLA · T1/T224 h · met
Scan SLA · T3/T47 d · met
On-demand rescan tiernot contracted
Network coveragepartial · 312 devices unscanned
Without a scoped rescan tier, high-tier post-patch verification waits for the nightly cycle. Closure stays BigFix-anchored regardless.
Risk acceptance & aging
Active exceptions41 · all time-boxed
Expiring in 30 d12 · resurfaced to owners
Past expiry3 · escalated
Clinical registry exclusions214 · not exceptions
servicenowwitness + actuator
read_ci · create_change · create_task · read_calendar · route_approval
pattern 1 + 2 · schema resolved at the edge
bigfixactuator
issue_baseline · read_relevance · read_status · read_inventory
pattern 1 · token check before issuance
catalystactuator
read_inventory · compliance · swim_distribute · swim_activate · archive
pattern 1 · distribute/activate split
tenablewitness
read_recency · rescan_scoped · vr_link
pattern 2 · nightly bulk plus delta
rubrikwitness
protection_status · restore_point.query · tag_chg · restore
pattern 1 · T-0 pre-flight
datadogwitness
provision_monitors · read_baseline · read_anomaly · synthetics
pattern 2 · monitors as code
netmrienrichment
config_history · mac_to_owner · dedup_keys
pattern 3 exception · exits 2027
ad + ddienrichment
resolve_owner · dns_record · group_membership
pattern 1 · proposal only, never a write
Contract tests
Pinned vendor API versions8 of 8
Contract tests green in CI8 of 8
Idempotency keys enforcedall writes
Pattern 3 exceptions1 · netmri export
Named exit criterioncontroller-native by Q2 FY27
Substitution restarts the evidence clock. Autonomy earned on one actuator re-earns on its replacement, because ledger evidence is per adapter.
!
Kill switch · {{ haltCardState }}
{{ haltCardMeta }}
{{ haltCardCta }}
Change freeze
Off
last used 14 Jul · Epic go-live
Game days rehearsed
4 of 4
kill switch · rollback · platform loss · token outage
Registry & promotion
Prompt registryp-4.2 · prod
Policy packpol-1.7 · prod
Model pinshaiku · sonnet · opus
Canary cohortT4 · 64 hosts
Eval golden set4,118 labelled dispositions
Regression rungreen · 02:40 today
A change to a prompt, policy or model is a ServiceNow change like any other, and reaches the canary cohort before fleet-wide effect.
⌕Search by CI, CHG, CVE, agent, gate or approver
track · servergate · G4disposition · override
Export CAB packet
Replay run
Replay · run_2026-08-04-a1
01
Cycle trigger · EventBridge to Step Functions
campaign opened 02:00:04 PT
02
Cohort resolved from CMDB
64 CIs · confidence 0.88 · policy pol-1.7
03
Gate plan computed
G2 defer-capped · G3 standard catalog · G4 standing grant
04
Readiness verdicts
agent p-4.2 · 64 ready · 0 held
05
Token minted and spent
tok_9e07 · scope SRV-RING0 · single use
06
Post-patch verdict
baseline diff clean · soak 45 min · synthetics pass
07
CHG closed · run sealed
evidence bundle written under Object Lock
Decision detail
RECOMMENDATION · READINESS · apex-sql-014
Defer. Restore point is 31 h old against a 24 h requirement, and the CI has no monitor pack, so no health gate can be evaluated.
Evidencerubrik · datadog · bigfix
Model / prompt / policyhaiku · p-4.2 · pol-1.7
Confidence0.62
Human dispositionaccepted · m.kaur
Used aslabelled example · eval set
The ledger is the compliance record, the evaluation dataset and the scorecard source at once. Nothing needs to be reconstructed later.
Gate-plan simulator
computed, not assumed
policy pol-1.7 · versioned in Git
Workflow · one template, ladder computed at runtime
{{ w.label }}
{{ g.label }}
{{ o.label }}
{{ gt.id }}
{{ gt.actor }}
{{ gt.name }}
{{ gt.note }}
{{ verdictGlyph }}
{{ verdictHead }}
{{ verdictBody }}
{{ verdictMeta }}
Clinical exclusion registry
CIs excluded from every envelope214
Owned with clinical engineeringdraft
IoMT overlapscope held open
Policy history
pol-1.7 · defer cap T4 → 301 Aug · CAB
pol-1.6 · confidence floor 0.8018 Jul · CAB
pol-1.5 · standard catalog T3/T402 Jul · CAB
Runbook logic lives in the policy plane, so process cannot drift from what is written.
Taxonomy
every label used in this console, defined once
T and N are criticality classes · never skill names
Server criticality · T
{{ t.id }}
{{ t.name }}
{{ t.desc }}
Network criticality · N
{{ t.id }}
{{ t.name }}
{{ t.desc }}
Gate vocabulary · G
{{ t.id }}
{{ t.name }}
{{ t.desc }}
The source design overloaded T1–T4 to mean both a criticality class and an agent skill. This console keeps T and N for criticality only; skills are named for what they do — readiness, consent, change, execution, validation, stewardship.
Convergence latency · T3
6.4 d
SLO 7 d · down 1.2 d
First-time-right
97.8%
no rework or rollback
Unplanned downtime
0 min
attributable · 14 cycles
Acceptance rate
91%
recommendations accepted
Hold precision
88%
correct refusals
Deferral aging
3
past policy cap
Demotion log
T3 scheduling autonomydemoted
22 Jul · two windows proposed inside an un-enumerated blackout · restored 29 Jul
Network hitless grantheld
11 Jul · rollback rehearsal not repeated after adapter change
T4 gated executionpromoted
04 Aug · 96% shadow agreement over 6 cycles · pen test evidence attached
Every promotion requires a governance amendment plus ledger evidence. CAB, the clinical registry, the kill switch, department scoping and the immutable audit never loosen at any level.