Vault SOC

Containment Policy

What the AI SOC may do without asking. Edits here create a v1.4 draft that requires CISO signature.

Policy v1.3 · signed by CISO, Halcyon Precision · Sep 30, 2026
ActionCriticalHighMediumLow
Isolate workstation
Isolate server
Isolate CUI-enclave asset
Quarantine file
Kill process
Block IP/URL/domain via SCM EDL
Push SCM security policy change
Disable user
Revoke sessions
Reset password
Delete email
Block sender

Guardrails

  • Servers and domain controllers always require approval.
  • CUI enclave assets: isolate auto only for Critical with ≥ 90% confidence and ≥ 95% when the user is an ITAR-authorized engineer.
  • SCM changes are limited to EDLs and the Vault-SOC rule folder.
  • Below 80% confidence every action requires approval.
  • Every action is reversible from Actions & Approvals where the platform allows.

Change history

  1. v1.3Sep 30, 2026 · CISO, Halcyon Precision

    CUI enclave isolation: auto only for Critical ≥ 95% confidence; quarterly review.

  2. v1.2Aug 14, 2026 · CISO, Halcyon Precision

    Enabled auto Revoke sessions for High after tabletop exercise.

  3. v1.1Jul 22, 2026 · IT Director

    Added SCM EDL blocking scoped to Vault-SOC folder.

  4. v1.0Jul 1, 2026 · CISO, Halcyon Precision

    Initial signed policy at service go-live.