DEFCON Alert Levels
Graduated risk control for AI automation.
DEFCON levels control what Quox can do automatically versus what requires human approval. Higher numbers = more automation allowed.
Level Definitions
DEFCON 5 - GREEN
Status: Full automation for safe operations
| Attribute | Value |
|---|---|
| Automation | Auto-run |
| Approval | None required |
| Use Case | Read-only operations, reporting, health checks |
| Risk Level | Minimal |
Allowed Operations:
- View logs and metrics
- Check service status
- List resources
- Run health checks
- Generate reports
DEFCON 4 - BLUE
Status: Automation with logging for low-risk changes
| Attribute | Value |
|---|---|
| Automation | Auto-run with logging |
| Approval | None, but logged |
| Use Case | Single-host, non-destructive operations |
| Risk Level | Low |
Allowed Operations:
- Everything in DEFCON 5
- Restart individual services
- Update packages (single host)
- Edit non-critical configs
- Clear caches
DEFCON 3 - AMBER
Status: Operations require human approval
| Attribute | Value |
|---|---|
| Automation | Auto-plan, human approve |
| Approval | Single approver required |
| Use Case | Multi-host operations, service restarts |
| Risk Level | Medium |
Requires Approval:
- Multi-host operations
- Service restarts (critical services)
- Configuration changes
- Resource scaling
- Backup operations
DEFCON 2 - ORANGE
Status: Two-person approval for production changes
| Attribute | Value |
|---|---|
| Automation | Plan only |
| Approval | Two-person (separate approvers) |
| Use Case | Production changes, data modifications |
| Risk Level | High |
Requires Two-Person Approval:
- Production deployments
- Database schema changes
- Network configuration
- Security policy changes
- User permission changes
DEFCON 1 - RED
Status: Manual-only, automation disabled
| Attribute | Value |
|---|---|
| Automation | Disabled |
| Approval | Manual execution only |
| Use Case | Destructive operations, credential management |
| Risk Level | Critical |
Manual Only:
- Data deletion
- Credential rotation
- Firewall rule changes
- SSH key management
- System wipes
Permissions Matrix
Complete matrix showing what's allowed at each DEFCON level.
Read Operations
| Action | DEFCON 5 | DEFCON 4 | DEFCON 3 | DEFCON 2 | DEFCON 1 |
|---|---|---|---|---|---|
| View logs | ✅ Auto | ✅ Auto | ✅ Auto | ✅ Auto | ✅ Manual |
| Check status | ✅ Auto | ✅ Auto | ✅ Auto | ✅ Auto | ✅ Manual |
| List resources | ✅ Auto | ✅ Auto | ✅ Auto | ✅ Auto | ✅ Manual |
| View metrics | ✅ Auto | ✅ Auto | ✅ Auto | ✅ Auto | ✅ Manual |
| Query memory | ✅ Auto | ✅ Auto | ✅ Auto | ✅ Auto | ✅ Manual |
Single-Host Operations
| Action | DEFCON 5 | DEFCON 4 | DEFCON 3 | DEFCON 2 | DEFCON 1 |
|---|---|---|---|---|---|
| Restart service | ✅ Auto | ✅ Log | ⚠️ Approve | ❌ Plan | ❌ Disabled |
| Update package | ✅ Auto | ✅ Log | ⚠️ Approve | ❌ Plan | ❌ Disabled |
| Edit config | ❌ | ✅ Log | ⚠️ Approve | ❌ Plan | ❌ Disabled |
| Clear cache | ✅ Auto | ✅ Log | ✅ Log | ⚠️ Approve | ❌ Disabled |
| Rotate log | ✅ Auto | ✅ Log | ✅ Log | ⚠️ Approve | ❌ Disabled |
Multi-Host Operations
| Action | DEFCON 5 | DEFCON 4 | DEFCON 3 | DEFCON 2 | DEFCON 1 |
|---|---|---|---|---|---|
| Rolling restart | ❌ | ⚠️ Approve | ⚠️ Approve | 👥 2-person | ❌ Disabled |
| Deploy update | ❌ | ⚠️ Approve | ⚠️ Approve | 👥 2-person | ❌ Disabled |
| Config change | ❌ | ⚠️ Approve | ⚠️ Approve | 👥 2-person | ❌ Disabled |
| Scale cluster | ❌ | ⚠️ Approve | ⚠️ Approve | 👥 2-person | ❌ Disabled |
Destructive Operations
| Action | DEFCON 5 | DEFCON 4 | DEFCON 3 | DEFCON 2 | DEFCON 1 |
|---|---|---|---|---|---|
| Delete container | ❌ | ❌ | ⚠️ Approve | 👥 2-person | ❌ Disabled |
| Drop database | ❌ | ❌ | ❌ | 👥 2-person | ❌ Disabled |
| Remove volume | ❌ | ❌ | ❌ | 👥 2-person | ❌ Disabled |
| Firewall change | ❌ | ❌ | ❌ | 👥 2-person | ❌ Disabled |
| SSH key rotation | ❌ | ❌ | ❌ | ❌ | ❌ Disabled |
Legend:
- ✅ Auto = Executes immediately
- ✅ Log = Executes and logs
- ⚠️ Approve = Requires single approval
- 👥 2-person = Requires two approvers
- ❌ Plan = Can only generate plan
- ❌ Disabled = Not allowed
Level Transitions
Raising DEFCON (More Restrictive)
DEFCON can be raised (made more restrictive) by:
-
Automatic triggers:
- Security incident detected
- Unusual activity patterns
- Failed health checks
- Compliance alert
-
Manual triggers:
- Dashboard SafetyContext UI
- Per-operation risk classification in policyGate
Lowering DEFCON (Less Restrictive)
Lowering DEFCON requires admin authorization via the dashboard SafetyContext panel. The change is logged in the AEE audit trail with the user who made the change and the timestamp.
Configuration
DEFCON levels are configured via the SafetyContext component in the QuoxCORE dashboard. The current level affects which operations require approval through the policy gate.
The default DEFCON level is set during the setup wizard and can be changed by administrators through the dashboard settings.
Monitoring DEFCON Status
Dashboard View
The DEFCON indicator is visible in the dashboard. The SafetyContext component shows the current level and allows administrators to change it.
DEFCON level changes are logged as AEE audit envelopes, creating a full trail of who changed the level and when.
See Also
- Safety Overview - Safety principles
- Policies - Custom policy configuration
- Destructive Operations - What's considered destructive
- Confirmation Flows - Approval process details