Contain the Incident - Automatically or Behind an Approval Gate
Isolate the device, kill the process, expire the credential - with full audit trails, SOAR-lite playbooks, and separation of duties on everything sensitive.
The Actions That End an Incident
Every action carries an audit trail from the moment it is requested to the moment it completes.
| Action | Effect |
|---|---|
| Isolate device | Cut the endpoint off from the network while you investigate |
| Release isolation | Return the endpoint to normal operation |
| Kill process | Terminate a specific process |
| Expire credential | Kill a leaked credential server-side - no device required |
Bind a Trigger to an Ordered Set of Actions
A playbook binds a trigger pattern to an ordered list of response actions. Each playbook either auto-executes or files its actions for human approval, so containment speed and human judgment are a configuration choice rather than an architectural one.
Every firing is recorded as a run with the triggering context - alert ID, summary, device - and a status of executed, approval pending, or failed. Run counts and last-run timestamps are tracked per playbook.
Separation of Duties, Enforced
- Enforcement policies, response actions, and evidence attestation can each be gated behind human approval
- The requester cannot approve their own request - separation of duties is enforced by the platform, not by convention
- Approval decisions land in the append-only audit log with user, action, resource, and timestamp
Detected Threats, Safely Held
- Quarantined files are held encrypted (AES-256), unable to execute or spread
- Administrators review, restore, or permanently delete quarantined files from the dashboard
- Sample upload supports controlled retrieval for analysis


Controls This Pillar Satisfies
- NIST IR-6
- Incident reporting with recorded response actions and outcomes
- SOC 2 CC7.3
- Evaluation of security events and the response taken
- ISO A.8.15
- Logging - append-only audit trail of administrative actions
- NIST AC-6
- Least privilege - separation of duties on sensitive actions
See Kraitos AIDR in Action
Deploy in 60 seconds. Get answers in 24 hours. Stop guessing what your AI-augmented organization is doing.
[email protected]kraitos.io