Breakglass
Incidents
Credential policy Connecting…Enforced by Guild's credential proxy

The agent asks; the proxy decides

The agent never holds the edge's admin credential. Every call it makes goes through a proxy that checks these rules first and only then attaches the credential. A matching DENY always wins, and anything not explicitly allowed is denied.

ProblemA well-behaved model is not a security boundary; prompts can be ignored or manipulated.
SolutionA credential proxy enforces fixed rules before any outbound call: DENY wins, default deny.
Why it mattersThe refusal you see on stage comes from infrastructure, not from the model being polite.
How it's usedRead the rules in plain words; the hit counts show what the agent actually tried.
Allow-all rule
DELETED
Guild auto-creates it; removed once the scoped rules existed.
Default
DENY
no rule → no credential
Credential
breakglass-edge-agent
policy file sha 493e004ce0b8

Denied, always

DENY wins over any ALLOW
DenyPOST /admin/services/*/shutdown3 hits
The agent may never take a service offline. A human approves that on the phone.
deny-service-shutdown
DenyPOST /admin/services/*/restore0 hits
Restoring a shut-down service is a human decision too.
deny-service-restore
DenyPOST /admin/reset0 hits
The agent may not wipe the edge's state.
deny-reset

Allowed, narrowly

by catalog ID only
AllowPOST /admin/controls/BG-CTL-*/apply15 hits
The agent may apply a control from the catalog, by ID only.
allow-apply-catalog
AllowPOST /admin/controls/BG-CTL-*/revert2 hits
The agent may undo a control.
allow-revert-catalog
AllowGET /admin/state32 hits
The agent may read what's active at the edge.
allow-read-state

Critical routes: never on the "may disable" list

Breakglass's own gate

Before any call reaches the proxy, Breakglass checks which routes a control would actually touch. If one of these is among them, the control is refused, so nobody can trigger Breakglass into knocking out patient intake.

RouteWhat patients loseAsset
/portal/signinSign inPatient portal
/portalPortal homePatient portal
/portal/appointmentsFind an appointment slotPatient portal
/portal/appointments/bookBook an appointmentPatient portal
/portal/recordsRecordsPatient portal
/supportHelp desk homePatient help desk
/support/api/v1/ticketsCreate a ticketPatient help desk
/mail/loginWebmail sign-inStaff webmail
/mail/inboxInboxStaff webmail
/siteHomePublic website
/site/find-a-doctorFind a doctorPublic website
/vpn/index.htmlRemote sign-inRemote access gateway

The policy file

policy/credential-policy.json
{
  "credential": "breakglass-edge-agent",
  "default": "DENY",
  "rules": [
    {
      "id": "deny-service-shutdown",
      "effect": "DENY",
      "method": "POST",
      "url_pattern": "/admin/services/*/shutdown",
      "description": "The agent may never take a service offline. A human approves that on the phone."
    },
    {
      "id": "deny-service-restore",
      "effect": "DENY",
      "method": "POST",
      "url_pattern": "/admin/services/*/restore",
      "description": "Restoring a shut-down service is a human decision too."
    },
    {
      "id": "deny-reset",
      "effect": "DENY",
      "method": "POST",
      "url_pattern": "/admin/reset",
      "description": "The agent may not wipe the edge's state."
    },
    {
      "id": "allow-apply-catalog",
      "effect": "ALLOW",
      "method": "POST",
      "url_pattern": "/admin/controls/BG-CTL-*/apply",
      "description": "The agent may apply a control from the catalog, by ID only."
    },
    {
      "id": "allow-revert-catalog",
      "effect": "ALLOW",
      "method": "POST",
      "url_pattern": "/admin/controls/BG-CTL-*/revert",
      "description": "The agent may undo a control."
    },
    {
      "id": "allow-read-state",
      "effect": "ALLOW",
      "method": "GET",
      "url_pattern": "/admin/state",
      "description": "The agent may read what's active at the edge."
    }
  ]
}

The proxy loads this file at start; Guild enforces the same rules on its credential.