Monitoring is a read-only decision. Remediation is not. This page answers the questions an operator should ask before letting anything touch production — plainly, and without claiming certifications we do not hold.
Each label says whether something is on by default today, off unless you enable it, or still on the roadmap. Nothing here is aspirational unless it says so.
No. Every account starts read-only. Remediation is a separate capability, it belongs to the Autopilot plan, and enabling it is an explicit act by an account administrator.
When you do enable it, it starts in shadow mode: it publishes the action it would have taken and performs nothing. Arming execution is a second, separate decision.
That is the design. You define which nodes are eligible targets, minimum free capacity, per-node cooldowns, how far load may be spread, and any jurisdiction rule that forbids a class of target outright.
A target excluded by your policy is dropped before scoring begins. It cannot be chosen because it looked healthy.
Yes, and it is enforced in one place rather than left to each feature. Every state-changing operation goes through a single audit call that writes the action log and sends the notification.
A change that is not logged cannot be applied, because the log entry is written first. You get a global history and a per-domain history.
DNS and provider credentials are held server-side, encrypted at rest, and are never sent to the browser or to an agent. The dashboard shows the last four characters and nothing more.
Scope them down at the provider: SystemsWarden only needs permission over the zones and records you intend it to manage.
Yes, from the dashboard, immediately. A revoked agent's ingest token stops being accepted on the next request; nothing needs to be uninstalled first.
Agents authenticate with a per-node ingest token, speak outbound-only over TLS, and never accept inbound connections. There is no port to expose.
Nothing moves. Remediation is fail-closed: with no confirmed multi-region verdict there is no action, and your DNS and proxy configuration keep serving exactly as they are.
Detection runs from edge locations independent of the control plane, so a control-plane outage cannot manufacture a false failure either.
These are not advisory. Each one is a gate that a proposed action must pass; failing any single gate stops the action and, where relevant, escalates instead.
What actually leaves your servers, over what channel, and how long it is kept.
Send it. Security questions get a direct answer from someone who works on the system, not a form letter.