Workflows · Security containment

Workload isolation stops for the Security operations owner.

Show the workload, containment action, supporting evidence, decision owner, and execution result before isolation.

Request a demo

Agent request

Remove production access from workload checkout-worker-17

The containment action can stop a production workload from reaching required services.

Identity
response-agent · Security operations
Target
production/checkout-worker-17
Cost
Recorded agent cost
Evidence
Workload identity, current access, and containment reason

Policy decision

Production workload isolation requires the Security operations owner.

Approver

Security operations owner

The action waits until this owner approves or denies it.

Approved

Tool call resumes

The access tool applies the approved containment change and records the result.

Denied

Tool call stays blocked

The workload keeps its current access and the containment call does not run.

Execution order

The agent request stops before the connected tool runs.

  1. 01Response agent requests workload isolation
  2. 02Deixic checks the workload, access change, evidence, and policy
  3. 03Security operations owner decides
  4. 04Connected access tool returns the containment result

The request, decision, recorded cost, and execution result remain in activity history.

Put this action under policy.

Request a demo.