← Control library
O02 · Operations
Incident response for agent failures
Teams treat harmful output, data exposure or unauthorized action as an ordinary support ticket.
Requirement
Define agent-specific severity, containment, evidence preservation, notification assessment and learning responsibilities.
Expected evidence
- Incident playbook and contact tree.
- Exercise or real incident record with follow-up actions.
Proposed verification
- Tabletop a cross-tenant disclosure or unauthorized send.
- Confirm the team can identify affected versions, records and owners.
Limit
A tabletop demonstrates readiness, not performance under every real incident.