Graduated Autonomy

Safe autonomy for cloud operations. On your terms.

Let CloudThinker agents investigate and execute pre-approved runbooks within your policies. Start with every action reviewed, then increase autonomy only when the evidence earns your trust.

MANUALAUTOAUTONOMOUSACTION PROPOSALACTION CLASSIFIERMode Check<5msPre-Approval<50msRisk Assessment<200msHard Guardrails<5msAUTO_APPROVEexecutes immediatelyESCALATEhuman approval queueDETECTANALYZERESOLVE ←VALIDATE
The Three Modes

Start safe. Grow autonomous.

Every CloudThinker deployment starts in Manual. You control the graduation — one approved Runbook at a time.

Manual

The agent proposes. You decide.

All write operations pause for human approval. Agents freely perform reads — querying metrics, searching logs, mapping dependencies — but every pod restart, scale event, or config change requires a thumbs-up.

read → autowrite → human approval

New customers, regulated environments, building initial trust

Auto

Pre-approved actions run. Everything else escalates.

If you've defined it in a Runbook or Agent Policy — the agent executes without interruption. Novel scenarios escalate to humans. Trust grows with every Runbook you author.

runbook match → autopolicy match → autono match → escalate

Established teams with Runbook coverage, recommended for production

Autonomous

Agents decide and act. Only hard limits escalate.

Full decision-making authority. Agents assess risk, choose actions, and execute — scaling, restarting, rolling back. The only exceptions are hard-coded safety guardrails that cannot be overridden.

all writes → autocritical ops → guardrail

Mature environments, non-production, speed-critical incident response

Trust journeyManualAutoAutonomous
How It Works

Every action classified. In under 200ms.

The Action Classifier sits between every agent decision and CloudSkill execution. It evaluates every proposal before anything touches your infrastructure.

1

Agent proposes

The agent submits an ActionProposal with full context — target resource, operation type, parameters, and justification for the action.

AgentActionProposalClassifier
2

Classifier evaluates

Four layers run in sequence: Mode Check, Pre-Approval (Runbook / Agent Policy), LLM Risk Assessment, and Hard Safety Guardrails.

Runbook: RB-pod-crashloop-restart → AUTO_APPROVE
3

Verdict issued

One of three outcomes in under 200ms. AUTO_APPROVE executes immediately. ESCALATE queues for human review. BLOCK_REDIRECT instructs the agent to reformulate.

AUTO_APPROVEESCALATEBLOCK_REDIRECT
4

Agent validates

After execution, the agent validates the outcome identically regardless of how the action was approved — confirming resolution or detecting unexpected side effects.

Agent: pod status OK — CONFIRMED
Action Classifierlayers
Mode Check<5ms

Deterministic read/write lookup against current mode.

Pre-Approval<50ms

Runbook match and Agent Policy lookup.

Risk Assessment<200ms

LLM evaluates reversibility, blast radius, environment, and history.

Hard Guardrails<5ms

Non-overridable limits enforced in every mode.

Possible verdicts

AUTO_APPROVEESCALATEBLOCK_REDIRECT
Risk Classification

Every action has a risk tier.

CloudThinker classifies every CloudSkill operation into one of four risk tiers. How each tier is handled depends on the current operating mode — giving you fine-grained control over what agents can do.

Risk TierManualAutoAutonomous
LOW

Reads, status checks, metric queries

✅ Auto-approve✅ Auto-approve✅ Auto-approve
MEDIUM

Scaling, pod restarts, non-prod writes

👤 Escalate✅ If pre-approved✅ Auto-approve
HIGH

Rollbacks, security changes, migrations

👤 Escalate✅ If pre-approved✅ Auto-approve
CRITICAL

Delete prod, IAM admin, VPC, cross-account

👤 Escalate👤 Always escalate🔒 Hard guardrail

Default action classification

infrastructure.read
LOW
monitoring.query_metrics
LOW
logs.search
LOW
infrastructure.scale_up
MEDIUM
infrastructure.scale_down
MEDIUM
pod.restart
MEDIUM
config.update_non_prod
MEDIUM
deployment.rollback
HIGH
security_group.modify
HIGH
database.migration
HIGH
infrastructure.delete_prod
CRITICAL
iam.modify_policy
CRITICAL
Safety & Security

Autonomous does not mean unchecked.

Every Auto Mode deployment runs within a layered defense model. Hard guardrails, circuit breakers, prompt injection detection, and complete audit trails — every action is governed, regardless of mode.

Hard Safety Guardrails

These limits are enforced in every mode and cannot be overridden by any customer configuration. They are the absolute floor of safety.

Never auto-approve deletion of production databases, clusters, or VPCs
Never auto-approve IAM policy changes that grant admin-level access
Never auto-approve actions affecting more than 50 resources simultaneously
Never auto-approve cross-account operations without an explicit Agent Policy
Always require approval for first-time actions on a resource type never touched before
Never auto-approve when prompt injection score exceeds safety threshold

Circuit Breaker

Auto Mode automatically falls back to Manual when issues are detected. The circuit opens fast, closes carefully, and notifies your team via Slack on every trigger.

3+ auto-approved actions fail Kai's validation within 1 hour → circuit opens for that agent
Agent proposes 5+ actions in 5 minutes on the same resource → rate limit, escalation required
Kai detects side effects from an auto-approved action → circuit opens for that action type
Customer reports an issue → circuit opens globally for 30 minutes

Recovery: circuit auto-closes after 1 hour with no further issues. Admins can close manually. All events notify via Slack.

Prompt Injection Defense

External data — logs, API responses, webhooks — is treated as untrusted. The classifier traces the causal chain and flags suspicious instruction patterns before any action executes.

External data stripped of instruction-like patterns before agent processing
Action provenance tracking — untrusted input in causal chain elevates risk score
Anomaly detection — statistically unusual actions flagged for review
Per-agent, per-resource rate limiting on auto-approved mutations

Complete Audit Trail

Every action — auto-approved or human-approved — generates an identical immutable audit entry. The trail includes the classifier reasoning, pre-approval source, and Kai's validation result.

modeMANUAL / AUTO / AUTONOMOUS at time of action
approval_typeAUTO_APPROVE
pre_approval_sourceRunbook or Agent Policy reference
classifier_reasoningLLM explanation (Autonomous mode)
validation_resultKai: CONFIRMED
risk_tierLOW
Capabilities

Everything you need to operate autonomously

Auto Mode is built on top of the full CloudThinker platform — every capability integrates with the Action Classifier, AgentGraph, and the three-layer autonomy framework.

Runbook Engine

Pre-approve step-by-step procedures. Any Runbook covered by an Agent Policy runs end-to-end in Auto mode without interruption.

Agent Policies

Define governance rules that feed the Action Classifier in real time. Update a policy and it takes effect immediately.

AgentGraph Context

Classifier uses live topology data — resource dependencies, environment tags, compliance scope — to enrich every risk decision.

Trust Progression

Every human approval in Auto mode is a Runbook candidate. Over time, coverage grows based on your actual operational patterns.

Real-time Action Feed

Watch every action as it happens — mode, verdict, classifier reasoning, and pre-approval source visible on a live dashboard.

MTTR Tracking

Measure mean time to resolution across modes. See the business impact of each Runbook you add and each trust level you unlock.

Runbook Coverage Map

Visualize which incident types have pre-approved Runbooks and which are gaps — guiding where to build trust next.

Key metrics

Auto-Approve Rate

% of actions auto-approved vs. escalated

>80%

Classifier Latency p99

Time to produce a verdict

<200ms

False Negative Rate

Auto-approved actions causing issues

<0.1%

Mean Time to Resolution

End-to-end incident resolution

<5 min

Circuit Breaker Triggers

Activations per week

<2

Runbook Coverage

% of incidents with pre-approved Runbooks

Growing

The CloudThinker difference

Traditional AutomationCloudThinker Auto Mode
Binary on/off per workflow3-mode trust journey: Manual → Auto → Autonomous
Static playbooks, manual executionRunbooks + Agent Policies — trust built over time
Alert context onlyFull topology via AgentGraph — blast radius, dependencies
Human is the safety layer3-layer classifier + circuit breakers + cross-keeper consultation
Action logs onlyFull reasoning trace with pre-approval source and classifier explanation
No learning — same approvals foreverApproval patterns → Runbook candidates → growing auto-approve coverage
Start Trial

Ready to graduate from manual approvals?

Start in Manual. Define your first Runbook. Watch your team sleep through the next 2AM incident.