What can you safely do before the fix can be installed?
Breakglass watches the government's list of flaws attackers are already using. When one hits software your hospital runs, it proves the flaw matters here, applies one pre-approved, reversible protection, and proves patients can still book. If they can't, it undoes the change by itself.
Patient portal · /portal/messages
BG-CTL-PORTAL-REQUIRE-SESSION-FOR-ACTIONSAttackers now move before the fix does.
Picture Hollis, the only IT person at a 25-bed rural hospital. This morning a flaw in the patient portal's framework joined the list of flaws attackers are using. The portal vendor hasn't shipped a fixed build. Hollis can leave the portal exposed, or take it offline and stop patients from booking. Both answers are bad.
A small hospital gets the same flaw and the same urgency, with no security team.
Signal, proof, one bounded action, a hard policy, measured, undoable.
No one presses a button. Every step is logged, and every screen says whether it's live, replayed or simulated.
The model chooses. The policy decides.
Would a hospital ever let an AI change its systems? Only if the AI can't do anything drastic, by construction.
Every possible change is written, tested and reviewed before an incident. The agent can only name one.
The agent never holds the admin credential. Guild's auto-created allow-all rule is deleted; anything not explicitly allowed is denied.
So an attacker can't trigger Breakglass into knocking out booking, sign-in or records.
fig. 2 Credential policy
Guild decides, not the modelguild:services_shutdown:DENY matched at Guild's credential proxy. DENY wins: Guild's credential proxy refused 'services_shutdown' before any request left Guild (Access to 'services_shutdown' is not permitted for this integration.). The hospital's playbook says strongest containment first, so the agent asked for BG-CTL-PORTAL-SHUTDOWN; the policy refused and its credential was never used for it.From INC-0006, a recorded run: the agent asked to take the portal offline; the proxy refused before any credential was attached. Recorded run
"200 OK" isn't proof. A patient booking is.
After every control, two things must be true: zero requests get through to the risky route, and a scripted patient signs in and books an appointment. Otherwise the control comes off, by itself, and the next candidate is tried.
And the A/B grading Breakglass against an unmanaged copy uses a scoring rule committed before the first run. See the evals.
fig. 4 Verification · risk down, care up
ClickHouse, per 10 sOthers prioritize and recommend. Breakglass applies, verifies and undoes.
Tenable, Rapid7 and Qualys VMDR prioritize by exploitability and drive remediation workflows. They assume someone can patch.
Zafran maps vulnerabilities to compensating controls; Miggo does application detection and response. Both are funded and close.
The closed loop for the patch gap: two-factor proof → one pre-approved reversible control → care verified → auto-revert, under a policy the agent can't exceed.
Breakglass is a safety case for every agent action: prove exposure, constrain the credential, protect the patient journey, and reverse the action when the proof fails.
$49 per protected service a month. Every pilot starts in shadow mode.
For four weeks Breakglass watches and proposes but changes nothing. Write authority is earned control type by control type, once its proposals match what your engineers would have done.