Loading...

AI Risk Engine

Tool execution guardrails, approval history, and analytics

Guardrail Tier Matrix

Tier 1

Auto-Execute (Read-Only)

59 tools

Read-only operations that execute automatically without any approval or logging overhead.

Tier 2

Auto-Execute + Audit

27 tools

Low-risk mutations that execute automatically but are logged to the audit trail.

Manage Alerts (Acknowledge)Acknowledge alerts

Manage Alerts (Resolve)Resolve alerts

Manage Alerts (Suppress)Suppress alerts temporarily

Manage Notification Channels (Test)Test notification channel

Manage Services (List)List services on device

Acknowledge Network DeviceAcknowledge network device

Configure Network BaselineConfigure network baseline

Manage Dns PolicyDNS policy management

Take ScreenshotCapture device screenshot

Analyze ScreenAnalyze captured screenshot

Set Device ContextSet brain device context

Resolve Device ContextResolve brain device context

Detect Log CorrelationsLog correlation detection

Set Agent Log LevelSet agent log level

Apply Configuration PolicyAssign config policy

Remove Configuration Policy AssignmentRemove config assignment

Manage Configuration Policy (Activate/Deactivate)Toggle policy status

Test WebhookTest webhook delivery

Manage Tags (Add/Remove)Add or remove device tags

Manage Saved Filters (Create/Delete)Create or delete saved filters

Manage Deployments (Pause/Resume)Pause or resume deployments

Manage Patches (Approve/Decline/Defer)Patch approval decisions

Manage Groups (Add/Remove Devices)Manage group membership

Manage Maintenance Windows (Create/Update)Create or update maintenance windows

Manage Automations (Enable/Disable)Toggle automation status

Manage Alert Rules (Create/Update)Create or update alert rules

Generate Report (Create/Update/Delete/Generate)Report management

Tier 3

Requires Approval

27 tools

Destructive or mutating operations that require explicit user approval before execution.

Manage Services (Start/Stop/Restart)Mutate device services

Manage Processes (Kill)Terminate a running process

Manage Startup Items (Enable/Disable)Manage startup items

Manage Scheduled Tasks (Run/Disable/Enable/Delete)Mutate scheduled tasks

Execute CommandExecute system commands on device

Run ScriptRun scripts on up to 10 devices

Computer ControlSend input actions to device

Create Remote SessionCreate remote terminal or file session

Security Scan (Quarantine/Remove/Restore)Threat management actions

Manage Software PolicySoftware policy management

Remediate Software ViolationRemediate software violations

File Operations (Write/Delete/Mkdir/Rename)Mutate files on device

Disk Cleanup (Execute)Execute disk cleanup

Registry Operations (Set/Create/Delete)Modify Windows registry

Network DiscoveryNetwork discovery scan

Execute PlaybookExecute self-healing playbook

Trigger BackupInitiate on-demand backup

Restore SnapshotRestore a backup snapshot

Manage Monitors (Create/Update/Delete)Create, update, or delete monitors

Trigger Agent UpgradeQueue agent upgrade

Manage Configuration Policy (Create/Update/Delete)Create, update, or delete config policies

Manage Deployments (Create/Start/Cancel)Create, start, or cancel deployments

Manage Patches (Scan/Install/Rollback)Scan, install, or rollback patches

Manage Groups (Create/Update/Delete)Create, update, or delete device groups

Manage Maintenance Windows (Delete)Delete maintenance windows

Manage Automations (Create/Update/Delete/Run)Manage automation lifecycle

Manage Alert Rules (Delete)Delete alert rules

Tier 4

Blocked

2 tools

Operations that are never allowed, such as cross-organization data access or unknown tools.

Cross-Org AccessAny operation targeting resources outside the current organization

Unknown ToolsAny unregistered tool invocation is blocked

Breeze AI

Breeze AI Assistant

Ask about your devices, alerts, metrics, or troubleshoot issues.

Cmd+Enter to send