# Holds and drills

> A hold says who may start a frozen agent again. A drill proves the kill switch works, end to end, and leaves a signed report.

Source: https://immiscible.fly.dev/docs/guides/holds-and-drills

## Holds

Every freeze carries a hold. Stopping is easy on purpose; starting again is a decision whose weight matches the reason for the stop.

| Hold | Lifted by | Typical cause |
|---|---|---|
| `owner` | anyone who manages the agent | the person it acts for paused it |
| `security` | the kill owner, a security lead or an admin, with a reason | a security concern, an SSF event, lapsed recertification, any machine's freeze |
| `incident` | as `security`, **and** a second person, not whoever froze it | over-capture at the card, a review verdict of `incident`, a SOAR incident |

Defaults follow who is stopping: the agent's own principal places an `owner` hold; the kill owner and security leads default to `security`; a service token's freeze is at least `security`; SSF events place `security`.

### Nobody lifts their own

Nobody lifts a security or incident hold on an agent that acts for them, whatever their role, by either route. A single unfreeze is refused; a bulk lift leaves those agents frozen, marked `actsForYou`, for someone else, and is refused outright if every agent in the batch is theirs.

### One rule for lifting

The same rule applies everywhere a freeze can be lifted (one agent, a batch, a pending freeze), and a service token can never lift anything. Tokens stop agents; they never start them.

## Drills

Auditors ask "when did you last test the kill switch, and how long did it take?" A drill answers with evidence.

```bash
curl -X POST "https://immiscible.fly.dev/api/w/$IMMISCIBLE_WORKSPACE/drills" \
  -H "cookie: __Host-sid=$IMMISCIBLE_SESSION" -H "x-immiscible-csrf: 1" \
  -H "content-type: application/json" \
  -d '{ "selector": { "vendor": "anthropic" } }'
```

A drill:

1. **freezes for real** the agents the selector names (at most 200);
2. **probes every path**: the gate, inference through the gateway, receipts and approvals, and checks each one refuses;
3. **restores only what it froze**, leaving anything someone else froze in the meantime;
4. returns a **signed report** (`immiscible-drill+jwt`) with the timings for each step, and records it in the evidence ledger.

Drills run from the console by admins and security leads, or by a service token with `agents:freeze` via [`POST /v1/admin/drills`](https://immiscible.fly.dev/docs/api/post-v1-admin-drills.md). A token may start a drill at most once an hour per workspace (setting `drillCooldownMinutes`). Drill results post to Slack and Teams when connected; a drill's own freezes do not, so the channel is not flooded.

> **Note**
> A drill that finds a path still answering is the most useful drill you will run. The report names which path, and the agents are still restored.

## Start-up reconciliation

If the process stops in the middle of a drill, the agents it froze are not left frozen by accident: on start-up, and every five minutes after, drills a stopped process never restored are restored and recorded.
