Degraded operation — Safe Mode

Preserve control. Do not go dark.

Security remains operational under pressure.

During a severe incident the instinct to shut everything down destroys exactly what an investigation needs. Safe Mode keeps Sentinel in control of a degraded environment instead: identity, read access, evidence capture and incident response stay available while high-risk operations are held.

Degraded operation

Under a severe incident Sentinel preserves control, not comfort.

Remains available

  • Critical read access
  • Identity and authentication
  • Evidence capture and Ledger writes
  • COLOSSEUM preservation
  • Incident response tooling

Paused or restricted

  • High-risk writes
  • Autonomous agent execution
  • Deployments and releases
  • Bulk export
  • New privileged sessions
  • Nonessential integrations

Restricted operations remain unavailable unless explicitly allowlisted for the incident.

Scoped, not global

Safe Mode applies at the narrowest boundary that contains the incident — a tenant, a workspace, a service. A single compromised credential does not stop an organisation working.

Allowlisted exceptions

Restricted operations can be individually permitted by an operator with sufficient authority. The exception is recorded with its justification in the same write as the change.

Evidence keeps running

Capture, Ledger writes and COLOSSEUM preservation are never among the things Safe Mode pauses. The record of an incident must outlast the incident.

Exit is verified

Safe Mode lifts when state integrity has been confirmed, not when the alert stops firing. Recovery is checked before normal operation resumes.