Guides
Holds and drills
A hold says who may start a frozen agent again. A drill proves the kill switch works, end to end, and leaves a signed report.
#Holds
Every freeze carries a hold. Stopping is easy on purpose; starting again is a decision whose weight matches the reason for the stop.
| Hold | Lifted by | Typical cause |
|---|---|---|
owner | anyone who manages the agent | the person it acts for paused it |
security | the kill owner, a security lead or an admin, with a reason | a security concern, an SSF event, lapsed recertification, any machine’s freeze |
incident | as security, and a second person, not whoever froze it | over-capture at the card, a review verdict of incident, a SOAR incident |
Defaults follow who is stopping: the agent’s own principal places an owner hold; the kill owner and security leads default to security; a service token’s freeze is at least security; SSF events place security.
#Nobody lifts their own
Nobody lifts a security or incident hold on an agent that acts for them, whatever their role, by either route. A single unfreeze is refused; a bulk lift leaves those agents frozen, marked actsForYou, for someone else, and is refused outright if every agent in the batch is theirs.
#One rule for lifting
The same rule applies everywhere a freeze can be lifted (one agent, a batch, a pending freeze), and a service token can never lift anything. Tokens stop agents; they never start them.
#Drills
Auditors ask “when did you last test the kill switch, and how long did it take?” A drill answers with evidence.
curl -X POST "https://immiscible.fly.dev/api/w/$IMMISCIBLE_WORKSPACE/drills" \
-H "cookie: __Host-sid=$IMMISCIBLE_SESSION" -H "x-immiscible-csrf: 1" \
-H "content-type: application/json" \
-d '{ "selector": { "vendor": "anthropic" } }'A drill:
- freezes for real the agents the selector names (at most 200);
- probes every path: the gate, inference through the gateway, receipts and approvals, and checks each one refuses;
- restores only what it froze, leaving anything someone else froze in the meantime;
- returns a signed report (
immiscible-drill+jwt) with the timings for each step, and records it in the evidence ledger.
Drills run from the console by admins and security leads, or by a service token with agents:freeze via POST /v1/admin/drills. A token may start a drill at most once an hour per workspace (setting drillCooldownMinutes). Drill results post to Slack and Teams when connected; a drill’s own freezes do not, so the channel is not flooded.
#Start-up reconciliation
If the process stops in the middle of a drill, the agents it froze are not left frozen by accident: on start-up, and every five minutes after, drills a stopped process never restored are restored and recorded.