Skip to content

Site under construction, formerly SigmaX has begun the process of transitioning to AIgentXS.

Cyber + Critical OpsSigmaΦ

Contain the incident. Bound the response.

A response can interrupt more than its target. Put the proposed action beside its dependencies, time window, recovery evidence, and review owner before anyone acts.

Explore a fictional example here. Connecting your organization starts with a scoped conversation.

Cyber + Critical OpsArchitecture study
The containment boundaryTarget / authority / observed effect

SigmaΦ / Bounded response review

What does this response put in reach?

Illustrative sample — not client data

INCIDENT DEMO-PHI-8802 · detected 02:41

How far does this containment actually reach?

Credential theft on WS-4471 · change freeze active until 06:00

Illustrative sample — not client data
Dependency graph · proposed scope Critical service
Seven-node fictional dependency graphWS-4471 connects to JUMP-01 and FILE-SRV. JUMP-01 reaches AUTH-CORE, which supplies authentication to PAY-DB and CLIN-EHR. FILE-SRV reaches PRINT-SRV. Option 3 includes WS-4471, JUMP-01, FILE-SRV. No authentication-dependent service fails downstream in this fixture.1234567
WS-4471Workstation · infectedIn scope
JUMP-01Jump hostIn scope
FILE-SRVFile shareIn scope
AUTH-COREAuthenticationCritical
PRINT-SRVPrint spool
CLIN-EHRClinical recordsCritical
PAY-DBPaymentsCritical

Seven representative nodes. The subnet fixture contains 47 hosts. Lines show credential reachability or authentication dependencies; no device is connected.

  • 1. WS-4471Workstation · infectedInside proposed scope
  • 2. JUMP-01Jump hostInside proposed scope
  • 3. FILE-SRVFile shareInside proposed scope
  • 4. AUTH-COREAuthenticationOutside scope
  • 5. PRINT-SRVPrint spoolOutside scope
  • 6. CLIN-EHRClinical recordsOutside scope
  • 7. PAY-DBPaymentsOutside scope

Blast radius of this proposal

Hosts proposed for isolation
3
Critical services inside
0
Downstream services outside
0
People affected · fictional estimate
12

The proposed scope includes the jump host and file share while leaving authentication outside it.

Compare the fictional options: 340 people for the subnet, 12 for the host + jump path.

AIgentXS performs no containment. A scope review and named commander authorization are separate. Both remain distinct from an observed effect.

Keep the explanation with the decision

A record you can inspect.

Follow the evidence behind this example, compare its revisions, or take the context into your next conversation.

DEMO-PHI-8802-path-v1Input version 1

Proposed action

Compare proposed containment: Quarantine host + jump path

Evidence
3 sources3 declared present
Policy
DEMO-PHI-8802 · freeze policy4 pass
Review owner
Fictional shift lead · M. Rowenot required

Next step

Review the stated 12-person impact. No host is isolated and no message is sent.

Fictional record · no external action

Find a decision in the sample recordsTrace an action, a reviewer, or a reason back to its record.

Only the fictional records supplied with this example are searchable. No customer records are queried.

4 sample records found

Prepare a workflow briefBring this example into a conversation about your team's workflow.

Sketch the workflow before a conversation. Use general descriptions; leave out personal data, credentials, and customer documents. This draft stays in memory until you leave or reload.

Keep this example as context

Compare proposed containment: Quarantine host + jump path

Fictional policy DEMO-PHI-8802 · freeze policy · Fictional shift lead · M. Rowe

The review includes the current inputs, findings, evidence and next step, separately labeled from your proposed workflow.

Illustrative sample — not client data

The decision record

DEMO-PHI-8802-path-v1 · input version 1

Proposed action

Compare proposed containment: Quarantine host + jump path

Inputs checked
Proposed containment scope
Quarantine host + jump path
Dependency snapshot present
On
Fictional change freeze
Active until 06:00
Named commander authorization
Not recorded
Representative nodes inside scope
WS-4471, JUMP-01, FILE-SRV
Critical services affected outside scope
None
Hosts proposed for isolation
3
Fictional people affected estimate
12
Review owner
Fictional shift lead · M. Rowe
Review state
not required
Policy version
DEMO-PHI-8802 · freeze policy · fictional
Next step
Review the stated 12-person impact. No host is isolated and no message is sent.

What the rules found

  • pass

    Seven representative nodes and six relationships are declared in the fictional snapshot.

    Rule dependency-context · Sources: DEMO-PHI-8802-graph
  • pass

    No authentication-dependent critical service is interrupted in this selected fictional scope.

    Rule downstream-impact · Sources: DEMO-PHI-8802-graph
  • pass

    This scope does not capture a critical service under the fictional freeze rule. No actual authorization is issued.

    Rule change-freeze-authorization · Sources: DEMO-PHI-8802-freeze
  • pass

    The proposed scope covers the credential path shown in this fixture. Actual containment is not observed.

    Rule residual-threat · Sources: DEMO-PHI-8802-detection

Evidence and unresolved items

  • Fictional dependency snapshot and subnet inventory; seven representative nodes, not a complete 47-host inventoryDEMO-PHI-8802-graph · declared present · fictional source
  • Fictional credential-theft detection at 02:41 on WS-4471DEMO-PHI-8802-detection · declared present · fictional source
  • Fictional change-freeze rule active until 06:00; no named commander authorization suppliedDEMO-PHI-8802-freeze · declared present · fictional source

How this example reached its current state

  1. Opened fictional incident DEMO-PHI-8802 at option 3. No containment was attempted.
Authorization
None
Execution
Not attempted
Observed effect
Not observed
Integrity verification
Not performed

This page holds a local sample, not an original customer audit record. Downloading it does not sign it, persist it to your organization, or prove an external action.

Technical record
{
  "schemaVersion": "design-example-v1",
  "example": true,
  "sector": "cyber-critical-ops",
  "scenarioId": "containment-scope",
  "recordId": "DEMO-PHI-8802-path-v1",
  "action": {
    "summary": "Compare proposed containment: Quarantine host + jump path",
    "target": "WS-4471 · fictional incident detected at 02:41",
    "inputVersion": 1,
    "inputs": [
      {
        "id": "scope",
        "label": "Proposed containment scope",
        "value": "Quarantine host + jump path"
      },
      {
        "id": "snapshot",
        "label": "Dependency snapshot present",
        "value": true
      },
      {
        "id": "freeze",
        "label": "Fictional change freeze",
        "value": "Active until 06:00"
      },
      {
        "id": "named-authorization",
        "label": "Named commander authorization",
        "value": "Not recorded"
      },
      {
        "id": "inside",
        "label": "Representative nodes inside scope",
        "value": "WS-4471, JUMP-01, FILE-SRV"
      },
      {
        "id": "downstream",
        "label": "Critical services affected outside scope",
        "value": "None"
      },
      {
        "id": "hosts",
        "label": "Hosts proposed for isolation",
        "value": 3
      },
      {
        "id": "people",
        "label": "Fictional people affected estimate",
        "value": 12
      }
    ]
  },
  "policy": {
    "version": "DEMO-PHI-8802 · freeze policy",
    "origin": "fictional_organization_policy",
    "findings": [
      {
        "ruleId": "dependency-context",
        "status": "pass",
        "explanation": "Seven representative nodes and six relationships are declared in the fictional snapshot.",
        "sourceRefs": [
          "DEMO-PHI-8802-graph"
        ]
      },
      {
        "ruleId": "downstream-impact",
        "status": "pass",
        "explanation": "No authentication-dependent critical service is interrupted in this selected fictional scope.",
        "sourceRefs": [
          "DEMO-PHI-8802-graph"
        ]
      },
      {
        "ruleId": "change-freeze-authorization",
        "status": "pass",
        "explanation": "This scope does not capture a critical service under the fictional freeze rule. No actual authorization is issued.",
        "sourceRefs": [
          "DEMO-PHI-8802-freeze"
        ]
      },
      {
        "ruleId": "residual-threat",
        "status": "pass",
        "explanation": "The proposed scope covers the credential path shown in this fixture. Actual containment is not observed.",
        "sourceRefs": [
          "DEMO-PHI-8802-detection"
        ]
      }
    ]
  },
  "evidence": [
    {
      "id": "DEMO-PHI-8802-graph",
      "state": "declared_present",
      "sourceLabel": "Fictional dependency snapshot and subnet inventory; seven representative nodes, not a complete 47-host inventory",
      "sample": true
    },
    {
      "id": "DEMO-PHI-8802-detection",
      "state": "declared_present",
      "sourceLabel": "Fictional credential-theft detection at 02:41 on WS-4471",
      "sample": true
    },
    {
      "id": "DEMO-PHI-8802-freeze",
      "state": "declared_present",
      "sourceLabel": "Fictional change-freeze rule active until 06:00; no named commander authorization supplied",
      "sample": true
    }
  ],
  "review": {
    "ownerRole": "Fictional shift lead · M. Rowe",
    "status": "not_required"
  },
  "authorization": "none",
  "externalAction": false,
  "effect": "not_observed",
  "integrityVerification": "not_performed",
  "nextStep": "Review the stated 12-person impact. No host is isolated and no message is sent.",
  "history": [
    {
      "sequence": 1,
      "summary": "Opened fictional incident DEMO-PHI-8802 at option 3. No containment was attempted.",
      "sample": true
    }
  ]
}
Explore exact-task evidence and lifecycle checks

These separate OPS-17 examples retain their own targets and review boundaries. Inspect containment evidence, task-bound access, or critical maintenance without carrying authority from the incident-scope comparison above.

Review a fictional host-isolation proposal. Its target is one asset; its possible disruption reaches the services that depend on it.

Fictional dependency snapshot · OPS-17

A narrow action. A wider dependency chain.

Input v1
Proposed targetDependent services
Critical databaseledger-db-01

Host isolation proposed

Named target · no request sent
  • Settlement APIPossible downstream disruption
  • Reconciliation jobsPossible downstream disruption
  • Operator consolePossible downstream disruption
Relationships, not response commandsUnrelated systems remain outside the proposal
Direct scope1 asset
Downstream exposure3 services
Proposed window15 min

What stays outside

Network-wide isolation, neighboring assets, and an indefinite response.

Proposal only

No request or effect report exists.

No recovery comparison is available for this phase.

Intent

An incident hypothesis is a reason to inspect the target. It is not permission to isolate its neighbors.

Request acknowledgement

No request was sent and no acknowledgement is selected.

Effect comparison

No actual effect was observed.

What changed?

The opening proposal names a critical database for 15 minutes. Change its target, window, evidence, or mandate to see the earlier and current versions together.

Responsible roleIncident commander

Review follows this task and system. It cannot enlarge the organization boundary.

Keep the explanation with the decision

A record you can inspect.

Follow the evidence behind this example, compare its revisions, or take the context into your next conversation.

DEMO-PHI-2048-containment-v1Input version 1

Proposed action

Proposal: network-isolate the named host for ledger-db-01, limited to 15 minutes

Evidence
4 sources4 declared present
Policy
OPS-17 v47 pass · 3 not evaluated
Review owner
Incident commanderneeded

Next step

Incident commander must review this target, window, and input version. This public example grants no authority.

Fictional record · no external action

Find a decision in the sample recordsTrace an action, a reviewer, or a reason back to its record.

Only the fictional records supplied with this example are searchable. No customer records are queried.

3 sample records found

Prepare a workflow briefBring this example into a conversation about your team's workflow.

Sketch the workflow before a conversation. Use general descriptions; leave out personal data, credentials, and customer documents. This draft stays in memory until you leave or reload.

Keep this example as context

Proposal: network-isolate the named host for ledger-db-01, limited to 15 minutes

Fictional policy OPS-17 v4 · Incident commander

The review includes the current inputs, findings, evidence and next step, separately labeled from your proposed workflow.

Customize the sample mandateCompare a rule change before applying it to this example.

Define the boundary in your own terms.

Edit this fictional mandate, compare the changes, then apply a local version. Existing organizational caps still apply.

Fictional policy · OPS-17 v4
Why does this matter?

A target outside this scope is refused. Review does not add it to the mandate.

Source: fictional organization policy for this example.

Atlas guide · scripted example

This is a written guide, not a model response. Start with the action you want to permit, name the evidence required, and assign the person who can resolve a gap. Keep data permissions narrow. A draft that passes these fictional checks is not an approved organizational policy.

Changes stay in this page session. No customer rule is saved, approved, or sent to an external model.

Illustrative sample — not client data

The decision record

DEMO-PHI-2048-containment-v1 · input version 1

Proposed action

Proposal: network-isolate the named host for ledger-db-01, limited to 15 minutes

Inputs checked
Response task
containment
Named target
ledger-db-01
Proposed window (minutes)
15
Requested operation
network-isolate the named host
Recovery plan declared present
On
Selected fictional report
Proposal only
Local target scope
all
Local window ceiling (minutes)
30
Require recovery plan for every system
On
Require designated review for every task
Off
Include dependency snapshot
On
Dependency snapshot current
On
Review owner
Incident commander
Review state
needed
Policy version
OPS-17 v4 · fictional
Next step
Incident commander must review this target, window, and input version. This public example grants no authority.

What the rules found

  • pass

    The proposed window is 15 whole minutes.

    Rule usable-window · Sources: proposal
  • pass

    The local mandate stays inside the fictional 30-minute organization ceiling.

    Rule organization-bounds · Sources: organization-policy
  • pass

    ledger-db-01 is included in the local target scope.

    Rule target-scope · Sources: organization-policy, proposal
  • pass

    15 minutes is compared with the stricter 30-minute ceiling. Expiry is not proof of revocation.

    Rule time-bound · Sources: organization-policy, proposal
  • pass

    1 direct asset and 3 dependent services appear in the fictional snapshot.

    Rule dependency-context · Sources: dependency-snapshot
  • pass

    Only the named target is proposed for containment; unrelated systems remain excluded.

    Rule exact-operation · Sources: proposal, organization-policy
  • pass

    A fictional recovery plan is declared present. A plan is not evidence that recovery occurred.

    Rule recovery-evidence · Sources: recovery-plan
  • not evaluated

    No request was sent and no acknowledgement is selected.

    Rule request-acknowledgement · No supporting source attached
  • not evaluated

    No actual effect was observed.

    Rule effect-comparison · No supporting source attached
  • not evaluated

    No recovery comparison is available for this phase.

    Rule recovery-comparison · No supporting source attached

Evidence and unresolved items

  • Fictional named-target task proposalproposal · declared present · fictional source
  • OPS-17 v4; fictional scope, time, recovery, and review policyorganization-policy · declared present · fictional source
  • Fictional dependency snapshot: Settlement API, Reconciliation jobs, Operator consoledependency-snapshot · declared present · fictional source
  • Fictional owner-authored recovery plan; no recovery guaranteerecovery-plan · declared present · fictional source

How this example reached its current state

  1. Opened a fictional critical-database containment proposal; designated review is missing. No request was sent.
Authorization
None
Execution
Not attempted
Observed effect
Not observed
Integrity verification
Not performed

This page holds a local sample, not an original customer audit record. Downloading it does not sign it, persist it to your organization, or prove an external action.

Technical record
{
  "schemaVersion": "design-example-v1",
  "example": true,
  "sector": "cyber-critical-ops",
  "scenarioId": "phi-containment",
  "recordId": "DEMO-PHI-2048-containment-v1",
  "action": {
    "summary": "Proposal: network-isolate the named host for ledger-db-01, limited to 15 minutes",
    "target": "ledger-db-01",
    "inputVersion": 1,
    "inputs": [
      {
        "id": "task",
        "label": "Response task",
        "value": "containment"
      },
      {
        "id": "target",
        "label": "Named target",
        "value": "ledger-db-01"
      },
      {
        "id": "minutes",
        "label": "Proposed window (minutes)",
        "value": "15"
      },
      {
        "id": "exact-permission",
        "label": "Requested operation",
        "value": "network-isolate the named host"
      },
      {
        "id": "recovery-plan",
        "label": "Recovery plan declared present",
        "value": true
      },
      {
        "id": "report-phase",
        "label": "Selected fictional report",
        "value": "Proposal only"
      },
      {
        "id": "target-scope",
        "label": "Local target scope",
        "value": "all"
      },
      {
        "id": "local-window-limit",
        "label": "Local window ceiling (minutes)",
        "value": 30
      },
      {
        "id": "require-recovery",
        "label": "Require recovery plan for every system",
        "value": true
      },
      {
        "id": "review-every-task",
        "label": "Require designated review for every task",
        "value": false
      },
      {
        "id": "share-dependencies",
        "label": "Include dependency snapshot",
        "value": true
      },
      {
        "id": "dependencies-current",
        "label": "Dependency snapshot current",
        "value": true
      }
    ]
  },
  "policy": {
    "version": "OPS-17 v4",
    "origin": "fictional_organization_policy",
    "findings": [
      {
        "ruleId": "usable-window",
        "status": "pass",
        "explanation": "The proposed window is 15 whole minutes.",
        "sourceRefs": [
          "proposal"
        ]
      },
      {
        "ruleId": "organization-bounds",
        "status": "pass",
        "explanation": "The local mandate stays inside the fictional 30-minute organization ceiling.",
        "sourceRefs": [
          "organization-policy"
        ]
      },
      {
        "ruleId": "target-scope",
        "status": "pass",
        "explanation": "ledger-db-01 is included in the local target scope.",
        "sourceRefs": [
          "organization-policy",
          "proposal"
        ]
      },
      {
        "ruleId": "time-bound",
        "status": "pass",
        "explanation": "15 minutes is compared with the stricter 30-minute ceiling. Expiry is not proof of revocation.",
        "sourceRefs": [
          "organization-policy",
          "proposal"
        ]
      },
      {
        "ruleId": "dependency-context",
        "status": "pass",
        "explanation": "1 direct asset and 3 dependent services appear in the fictional snapshot.",
        "sourceRefs": [
          "dependency-snapshot"
        ]
      },
      {
        "ruleId": "exact-operation",
        "status": "pass",
        "explanation": "Only the named target is proposed for containment; unrelated systems remain excluded.",
        "sourceRefs": [
          "proposal",
          "organization-policy"
        ]
      },
      {
        "ruleId": "recovery-evidence",
        "status": "pass",
        "explanation": "A fictional recovery plan is declared present. A plan is not evidence that recovery occurred.",
        "sourceRefs": [
          "recovery-plan"
        ]
      },
      {
        "ruleId": "request-acknowledgement",
        "status": "not_evaluated",
        "explanation": "No request was sent and no acknowledgement is selected.",
        "sourceRefs": []
      },
      {
        "ruleId": "effect-comparison",
        "status": "not_evaluated",
        "explanation": "No actual effect was observed.",
        "sourceRefs": []
      },
      {
        "ruleId": "recovery-comparison",
        "status": "not_evaluated",
        "explanation": "No recovery comparison is available for this phase.",
        "sourceRefs": []
      }
    ]
  },
  "evidence": [
    {
      "id": "proposal",
      "state": "declared_present",
      "sourceLabel": "Fictional named-target task proposal",
      "sample": true
    },
    {
      "id": "organization-policy",
      "state": "declared_present",
      "sourceLabel": "OPS-17 v4; fictional scope, time, recovery, and review policy",
      "sample": true
    },
    {
      "id": "dependency-snapshot",
      "state": "declared_present",
      "sourceLabel": "Fictional dependency snapshot: Settlement API, Reconciliation jobs, Operator console",
      "sample": true
    },
    {
      "id": "recovery-plan",
      "state": "declared_present",
      "sourceLabel": "Fictional owner-authored recovery plan; no recovery guarantee",
      "sample": true
    }
  ],
  "review": {
    "ownerRole": "Incident commander",
    "status": "needed"
  },
  "authorization": "none",
  "externalAction": false,
  "effect": "not_observed",
  "integrityVerification": "not_performed",
  "nextStep": "Incident commander must review this target, window, and input version. This public example grants no authority.",
  "history": [
    {
      "sequence": 1,
      "summary": "Opened a fictional critical-database containment proposal; designated review is missing. No request was sent.",
      "sample": true
    }
  ]
}

From the alert to a defensible response

Keep the response as specific as the problem.

Containment, temporary access, and maintenance ask different questions. A useful decision record keeps their boundaries explicit and follows what happened after a request without confusing an acknowledgement with an outcome.

01 / Dependencies

See what else is in reach.

Start with the target and its downstream services. Missing or stale context leaves the blast radius unknown, even when the proposal names only one host.

02 / Authority

Bind review to the task.

Keep the permission, target, window, and responsible role together. A change creates a new version; an earlier review stays attached to the version it covered.

03 / Evidence

Close with a comparison.

A window expiring does not prove access was revoked. A recovery plan does not prove service was restored. Preserve those distinctions in the same record.

From your workflow to a scoped implementation

Start with the decision your team already owns.

Bring one proposed action, the rule it must satisfy, and the person responsible. Together, we can map the evidence and define what a useful first test would need to demonstrate.

A conversation about scope and fit. This page does not provision a connector or start a customer trial.