Rollback is a contract, not a feature flag.
Most CSPM platforms detect risk and hand it off. Autonomous Governance closes the loop: every Azure remediation handler ships matched captureState / restoreState pairs, the runtime refuses to execute any action whose rollback path is undefined, and the platform graduates from shadow → gated → autonomous as your team's confidence builds.

- CAP-01captureState / restoreStateEvery handler ships matched pairs. Type-checked at compile.
- CAP-023 safety gates per actionPre-validation · execution · post-validation · auto-rollback on fail.
- CAP-03Shadow → gated → autonomousThree trust modes. Operator votes feed the next decision.
- CAP-04Rollback contract = compileRefuses to execute actions without defined rollback.
- CAP-05Median MTTR ~30sDetect → propose → execute in seconds, not days.
- CAP-06Blast radius enforcedProduction-scope actions require explicit operator approval.
- 01ShadowPlatform proposes remediation; nothing executes. Operator votes train the model.
- 02GatedOperator approves each action. Most defense customers stay here for production.
- 03AutonomousPre-approved action classes run without per-action approval. Always reversible.
- DOE National LabActive consultant
- MITRECybersecurity engineering
- USAAFinancial-grade ops
- FrontierProduction cloud architecture
Founder runs every engagement personally. 4 U.S. patent applications filed.
What's a rollback contract?
A type-system guarantee that every action ships with its inverse. The platform refuses to compile handlers that lack a defined rollback path. Safety is enforced at build time, not by operator discipline.
What if rollback also fails?
Rollback failure is logged and escalated. State is captured pre-action, so manual intervention has the exact desired-state to restore to. We've never lost the source-of-truth across pilot engagements.
How long to graduate from gated → autonomous?
Most customers run gated mode for 2-4 weeks while building internal confidence. Then specific action classes graduate to autonomous (e.g., 'tighten unrestricted security groups') while higher-blast actions stay gated.
Can we lock specific resources out of autonomous?
Yes. Resource tags, account boundaries, or arbitrary policy expressions can keep specific resources in gated mode permanently. Production database tier stays gated even when other classes go autonomous.
Detect → propose → execute. With a rollback contract every step.
$15,000 flat for the 30-day pilot. Start in shadow, graduate to gated, get to autonomous on your timeline.
