StableMindMachine Authority
Sign inStart with ActionGate

Guardian · Independent intervention

Power that can be granted
must be interruptible.

Guardian is StableMind's independent runtime intervention plane for consequential machine authority. It can narrow, revoke, contain, quarantine, or coordinate recovery when authority changes or runtime risk demands intervention, without depending on the agent that requested the action to voluntarily surrender power.

PRODUCT / GUARDIANPUBLIC AUTHORITY EFFECTS / 0BUILD / SIO08
GUARDIAN / SYNTHETICINDEPENDENT PATH
RUNTIME EVENTauthority_revoked

agent: deployment-operator
target: production-edge
permit: active when event observed

AUTHORITYREVOKED
PERMITINVALIDATE
CREDENTIALREVOKE
EXECUTIONCONTAIN
AGENTQUARANTINE
EVIDENCEAPPEND
INTERVENTION STATESTOP

Guardian may remove power. It may never create or broaden it.

Synthetic architecture illustration. No live agent, permit, credential, or downstream system is affected by this public page.

Product definition

What is Guardian?

Guardian is the independent control path that makes machine authority interruptible after delegation and authorization. Organizations often search for an AI agent kill switch, but a useful intervention system is more precise than a single red button. It needs current revocation state, bounded permit invalidation, credential and connector containment, agent quarantine, recovery state, and attributable evidence, all without accidentally granting new authority to the intervention mechanism itself.

Intervention is its own authority boundary

01 / INDEPENDENCE

The machine that requests power should not control the mechanism that removes it.

ACTIONGATE

Decides before consequence

ActionGate evaluates the exact request and may issue a bounded permit. Guardian is not a substitute for that deterministic decision boundary.

EXECUTION FABRIC

Realizes authorized capability

Execution Fabric binds temporary credentials and certified connectors to the permit. Guardian can make that downstream capability unusable when the control state changes.

GUARDIAN

Interrupts independently

Guardian owns containment and revocation paths that do not rely on the requesting agent's cooperation or on a prompt telling the model to stop.

EVIDENCE

Records the intervention

Revocation, quarantine, attempted execution, recovery, and resulting state become attributable evidence. Evidence still cannot create authority.

Intervention anatomy

02 / SIX BOUNDARIES

Stopping machine power is a chain, not a slogan.

  1. 01
    Observe a governed intervention signal

    Revocation, expiry, incident state, human authority, policy lifecycle change, runtime anomaly, downstream rejection, or another explicit control event becomes an attributable Guardian input.

  2. 02
    Resolve affected authority and permits

    Guardian identifies the delegation branches, permits, credentials, sessions, connectors, agents, and in-flight actions that depend on the changed control state.

  3. 03
    Choose the narrowest sufficient intervention

    The response can constrain one target, invalidate a permit, revoke a credential, quarantine an agent, halt a connector path, or escalate to a broader incident boundary. Intervention is not automatically maximal.

  4. 04
    Propagate revocation to execution

    Execution Fabric and downstream controls receive the intervention state quickly enough to remove future capability and, where supported, interrupt an in-flight operation before additional consequence.

  5. 05
    Preserve recovery without restoring ambient power

    Recovery can require re-authentication, new delegation, fresh ActionGate evaluation, changed policy, human review, or connector repair. Guardian does not simply re-enable yesterday's permit.

  6. 06
    Append attributable intervention evidence

    The trigger, affected lineage, actions taken, acknowledgments, residual exposure, and recovery state flow into Evidence so the organization can reconstruct what was stopped and what remained.

Intervention modes

03 / NARROW FIRST

Guardian can remove power at the smallest boundary that is sufficient.

CONSTRAIN

Narrow the envelope

Reduce targets, amount, concurrency, duration, or other execution scope when policy supports safe attenuation without granting anything new.

REVOKE

Invalidate authority or permit

Make a delegation branch or exact permit unusable for later decisions and execution, then propagate that state to dependent capabilities.

QUARANTINE

Isolate the actor or path

Remove an agent, connector, credential broker, executor, or environment from the trusted operating set while investigation or remediation occurs.

RECOVER

Return through a fresh boundary

Restore service only through explicit recovery criteria and, when consequential power is needed again, fresh authority and ActionGate decisioning.

When intervention matters

04 / RUNTIME CHANGE

The action can be legitimate at 10:01 and forbidden at 10:02.

AUTHORITY CHANGE

A principal revokes delegation

Guardian helps ensure descendant permits and temporary capabilities do not continue acting as if the historical grant were still current.

INCIDENT RESPONSE

A credential or connector is compromised

The affected path can be quarantined independently of the agent's reasoning state while other unrelated authority remains intact.

POLICY CHANGE

A new control boundary takes effect

Guardian can remove execution capability that no longer satisfies current policy rather than allowing stale permits or cached sessions to outlive the governing rule.

DOWNSTREAM RISK

The target environment changes

An action that was authorized under one operational state may become unsafe when the target, destination, balance, incident state, or other consequence facts change materially.

Revocation speed

05 / OUTRUN CONSEQUENCE

Revocation is only meaningful if it can reach the point of execution.

A database flag saying “revoked” is not enough when an agent still holds a reusable token, active cloud session, queued payment instruction, or connector retry. Guardian treats revocation as a propagation problem: authority state must reach permits, credentials, sessions, executors, agents, and downstream systems according to the interruption semantics each consequence actually supports.

01REVOCATION SOURCE

Human authority, lifecycle policy, incident response, or another governed event changes the current state.

02PERMIT INVALIDATION

Affected Action Permits become unusable for new execution attempts.

03CAPABILITY REVOCATION

Temporary credentials, delegated sessions, and connector paths are removed or constrained.

04IN-FLIGHT CONTAINMENT

Interruptible operations are halted or prevented from taking additional steps; non-interruptible consequences are surfaced as residual exposure.

05RECOVERY BOUNDARY

Any return to consequential power requires explicit recovery and, where needed, fresh authority plus a fresh ActionGate decision.

Constitutional boundaries

06 / REMOVE, NEVER GRANT

Guardian has strong control power and therefore an intentionally narrow constitution.

Guardian never broadens authority

Intervention may preserve, narrow, suspend, revoke, or quarantine. It cannot add an action, resource, destination, amount, duration, or delegation right that did not already exist.

A kill switch is not the authorization model

Emergency stopping matters, but it cannot compensate for giving agents ambient power in the first place. ActionGate and Authority Cloud remain upstream.

Prompt instructions are not revocation

Telling an agent to stop is behavioral guidance. Guardian uses control-plane mechanisms that can make permits, credentials, sessions, or execution paths unusable independently.

Intervention is attributable

The trigger, actor, reason, affected scope, acknowledgments, failures, residual risk, and recovery state should be reconstructable instead of disappearing into an opaque emergency action.

Recovery does not resurrect stale power

After an incident or revocation, reopening an execution path does not automatically restore prior delegations, permits, or credentials. Current authority must still be valid.

Commercial state creates zero intervention authority

A website account or subscription cannot secretly obtain the power to revoke a customer's machines. Customer control and deployment authority remain explicit and separate.

Evaluator questions

07 / BUYER CLARITY

Questions to ask about AI agent kill switches, revocation, and containment.

What is an AI agent kill switch?
At its simplest, it is a mechanism for stopping an agent or its ability to act. StableMind Guardian treats that need as a broader intervention plane that can invalidate permits, revoke credentials, constrain connectors, quarantine actors, coordinate recovery, and preserve evidence.
Can Guardian stop an action already in progress?
Only to the extent the downstream action is actually interruptible. Guardian propagates intervention to the relevant execution controls and records residual exposure rather than pretending every external consequence can always be rolled back mid-flight.
How is Guardian different from ActionGate?
ActionGate decides whether a specific action may begin. Guardian owns independent runtime intervention when authority, policy, incident state, or consequence conditions change before or during execution.
Does revoking a user or agent identity revoke machine authority?
Identity state can be a relevant intervention input, but machine authority and delegated lineage are separate facts. Guardian resolves the affected authority, permits, sessions, and execution paths rather than assuming one identity event automatically describes every dependent consequence.
Can Guardian grant emergency authority?
No. Guardian is constitutionally non-amplifying. Emergency authority, if an organization chooses to support it, must come from an explicit governed authority mechanism and still pass the required ActionGate decision boundary.
How do you recover after quarantining an AI agent?
Recovery should follow explicit criteria, restore only the necessary trusted components, and require fresh authority or decisioning when prior power was revoked or invalidated. Recovery is not a shortcut that silently resurrects old permits.

Public truth boundary

An intervention model is not a live incident response.

This page describes StableMind architecture and product behavior. Its runtime example is synthetic. It does not claim a named customer deployment, live agent containment, live revocation, external incident proof, recognized revenue, or realized customer value.

Read the Public Truth Contract

Control that survives runtime change

Authorize narrowly. Execute narrowly. Keep an independent path to stop.

StableMind's customer path still begins with ActionGate. Public account onboarding remains SIO19 and SIO21 remains the first governed-action experience. This public Guardian surface demonstrates architecture only and creates no revocation, credential, permit, execution, or customer authority.

website_session_creates_authority=false

Consequence boundary

Intervention can freeze exposure without rewriting its ownership.

Guardian may preserve, narrow, suspend, revoke, quarantine, or coordinate recovery while required Consequence Capital remains governed by its own reserve and release gates.