Contain compromised authority before certainty arrives

Deterministic signals can raise a monotonic restriction ladder. Automation can only remove authority; recovery is a human act, and dangerous recovery requires two people.

One ladder, six explicit tradeoffs

C0

Record and score deterministic evidence.

C1

Page the operator and snapshot evidence.

C2

Throttle governed actions and egress.

C3

Freeze governed actions and broker egress.

C4

Mark credentials compromised and revoke the delegation subtree.

C5

Request termination through a separately configured customer isolation plane.

Designed for a hostile workload

Silence

Ordinary denial surface

A C3 refusal uses the same status, headers, body, reason code, error path, and timing grid as an ordinary default denial.

Latency

Measured, never hidden

Every transition records elapsed and target milliseconds. The human-only console reports recent p50, p95, and p99 samples.

Recovery

Compromise stays compromised

Moving down the ladder never reactivates a compromised credential. C4/C5 recovery needs a distinct second active member.

Evidence

Transactional transition record

Restriction state, transition evidence, and audit append commit together; operator writes are idempotent across retries.

C5 is not a claim that TrustRail owns your kill switch. It exists only when your deployment registers an isolation-plane hook, and the customer plane performs the termination. Live sole-route evidence is required before describing the egress broker as the only network path.