Incident response

One incident instead of twenty alerts, a signed record of the response, and the fix that stops it happening again.

When an agent misbehaves the signals arrive from everywhere: a runtime anomaly, a failed evaluation, a security finding. Praesidia groups them into one incident, walks the response step by step, signs the evidence at the end, and proposes the control that would have stopped it, which you test before it goes live.

Incident · Claims Triage AI system · runtime anomaly Illustrative
4signals grouped
6 / 9response steps done
2controls proposed
  1. Detect
  2. Correlate
  3. Contain
  4. Investigate
  5. Root cause
  6. Remediate
  7. Re-test
  8. Update control
  9. Generate evidence

Each step is started, completed or skipped with a reason, and every change lands on the incident's timeline. The last step signs the evidence bundle.

What you get

Three things incident response gives you

One incident, not a pile of alerts

Related signals on the same AI system are grouped into one incident with one timeline, so nobody triages the same problem four times.

A record a regulator can read

A signed evidence bundle closes the response, a post-mortem records what was learned, and a serious incident gets a regulator report with its notification deadline in view.

The fix, tested before it lands

Every incident proposes the control that would stop a repeat, and every fix can be simulated, tested, approved and rolled back.

How it works

From the first signal to the closing evidence

  1. 1

    Signals arrive from across the platform: runtime anomalies, failed evaluations, security findings, identity events, drift and discovery changes.

  2. 2

    Signals of the same kind on the same AI system, inside a time window you can tune, join one incident instead of opening new ones.

  3. 3

    Contain first. If it is bad enough, freeze agent traffic for the whole organization in one step, after previewing every AI system that will stop.

  4. 4

    Work through investigation, root cause, remediation and re-test, with each step recorded on the timeline.

  5. 5

    Accept or dismiss the controls the incident proposes: a new policy, a change to an existing control, a new evaluation or a monitoring rule.

  6. 6

    Generate the signed evidence bundle, write the post-mortem and, for a serious incident, the regulator report.

Remediation

Praesidia proposes the fix. You decide whether it ships.

Every day Praesidia looks across your organization for things worth fixing: permissions an agent holds but never uses, a policy that should change, an AI system with no owner, a release with no evaluation behind it. Each becomes a proposal that moves through the same steps before anything changes.

Proposal · reduce Claims Triage's CRM permissions to the ones it used Illustrative
Proposed Simulated Evaluated Approved Applied Monitored

If the change causes trouble after it is applied, rolling it back restores the state that was there before.

  • Five kinds of fix: reduce permissions to the ones actually used, change a policy, require an evaluation, update a control, assign an owner.
  • Proposals come from incidents, failed evaluations, risk-register entries, drift, least-privilege findings, gaps in evaluation coverage and your inventory, or you raise one by hand.
  • Approval needs someone with security authority in your organization; applying and rolling back are recorded like every other change.
Prevention

Try the new rule on last week's traffic before it touches this week's

The control an incident proposes should not cause the next one. Replay it against past traffic, roll it out in stages, and catch the dangerous sequence rather than the single call.

Replay against past traffic Advanced

Run a security policy, intent rule, sequence rule or guardrail over historical calls and see which ones it would have allowed, denied or sent for approval before you turn it on.

Roll out in four stages

Guardrails and agent policies move from simulate to observe to alert to enforce, and you can set one to roll itself back if denials spike after enforcement starts.

Catch the sequence Advanced

Sequence rules match one action followed by another within a time window: read the customer list, then send an external email within ten minutes.

Plan marks show the plan a capability starts on; see pricing. Blocking and approval apply when your organization runs in enforce mode; by default decisions are observed and recorded.

Technical details

What each part does, and where it stops

Incidents
Opened by hand or automatically from signals above a severity floor. Signals group only with signals of the same kind; the grouping window can be set for the whole organization and per kind of signal. Incidents, response steps and evidence bundles are in every plan.
Evidence bundle
Signed with your organization's audit key and holding the nine response steps as they stood when the response closed. It is verified the same way as your audit trail; see evidence.
Regulator report
Built from what is already stored on the incident and its timeline, after the impact assessment has been reviewed, so the same incident always produces the same report. It shows the time left until the recorded notification deadline. It is a draft for your team to file, not a filing.
Remediation
Proposals are never applied on their own; each needs an approval. Remediation is in every plan.
Containment
The emergency freeze lets you choose what to stop, such as agent-to-agent calls, MCP tool calls, model access or outbound traffic, across the whole organization, and by default it preserves the evidence. Through the API you can also cut credentials for chosen agents or one team; the organization-wide freeze applies either way. It is for organization owners, who see the preview of affected AI systems before confirming, and it stays in place until an owner lifts it.
Plans
Policy replay and sequence rules are part of agent governance on Advanced. Agent policies start on Individual; rule-based guardrails and their staged rollout are in every plan. Human approval of individual tool calls is Enterprise.
What it is not
Praesidia does not file reports with regulators for you or decide whether an incident is legally reportable, and a proposed control is a suggestion to test, not a guarantee that the incident cannot recur.

Then: runtime security · assurance · risk management · EU AI Act · the whole platform.

Be ready before the first incident

Connect one agent, watch its decisions, and see what an incident record looks like before you need one.