Get started

DEFCON Alert Levels

Graduated risk control for AI automation.

DEFCON levels control what Quox can do automatically versus what requires human approval. Higher numbers = more automation allowed.

Level Definitions

DEFCON 5 - GREEN

Status: Full automation for safe operations

AttributeValue
AutomationAuto-run
ApprovalNone required
Use CaseRead-only operations, reporting, health checks
Risk LevelMinimal

Allowed Operations:

  • View logs and metrics
  • Check service status
  • List resources
  • Run health checks
  • Generate reports

DEFCON 4 - BLUE

Status: Automation with logging for low-risk changes

AttributeValue
AutomationAuto-run with logging
ApprovalNone, but logged
Use CaseSingle-host, non-destructive operations
Risk LevelLow

Allowed Operations:

  • Everything in DEFCON 5
  • Restart individual services
  • Update packages (single host)
  • Edit non-critical configs
  • Clear caches

DEFCON 3 - AMBER

Status: Operations require human approval

AttributeValue
AutomationAuto-plan, human approve
ApprovalSingle approver required
Use CaseMulti-host operations, service restarts
Risk LevelMedium

Requires Approval:

  • Multi-host operations
  • Service restarts (critical services)
  • Configuration changes
  • Resource scaling
  • Backup operations

DEFCON 2 - ORANGE

Status: Two-person approval for production changes

AttributeValue
AutomationPlan only
ApprovalTwo-person (separate approvers)
Use CaseProduction changes, data modifications
Risk LevelHigh

Requires Two-Person Approval:

  • Production deployments
  • Database schema changes
  • Network configuration
  • Security policy changes
  • User permission changes

DEFCON 1 - RED

Status: Manual-only, automation disabled

AttributeValue
AutomationDisabled
ApprovalManual execution only
Use CaseDestructive operations, credential management
Risk LevelCritical

Manual Only:

  • Data deletion
  • Credential rotation
  • Firewall rule changes
  • SSH key management
  • System wipes

Permissions Matrix

Complete matrix showing what's allowed at each DEFCON level.

Read Operations

ActionDEFCON 5DEFCON 4DEFCON 3DEFCON 2DEFCON 1
View logs✅ Auto✅ Auto✅ Auto✅ Auto✅ Manual
Check status✅ Auto✅ Auto✅ Auto✅ Auto✅ Manual
List resources✅ Auto✅ Auto✅ Auto✅ Auto✅ Manual
View metrics✅ Auto✅ Auto✅ Auto✅ Auto✅ Manual
Query memory✅ Auto✅ Auto✅ Auto✅ Auto✅ Manual

Single-Host Operations

ActionDEFCON 5DEFCON 4DEFCON 3DEFCON 2DEFCON 1
Restart service✅ Auto✅ Log⚠️ Approve❌ Plan❌ Disabled
Update package✅ Auto✅ Log⚠️ Approve❌ Plan❌ Disabled
Edit config✅ Log⚠️ Approve❌ Plan❌ Disabled
Clear cache✅ Auto✅ Log✅ Log⚠️ Approve❌ Disabled
Rotate log✅ Auto✅ Log✅ Log⚠️ Approve❌ Disabled

Multi-Host Operations

ActionDEFCON 5DEFCON 4DEFCON 3DEFCON 2DEFCON 1
Rolling restart⚠️ Approve⚠️ Approve👥 2-person❌ Disabled
Deploy update⚠️ Approve⚠️ Approve👥 2-person❌ Disabled
Config change⚠️ Approve⚠️ Approve👥 2-person❌ Disabled
Scale cluster⚠️ Approve⚠️ Approve👥 2-person❌ Disabled

Destructive Operations

ActionDEFCON 5DEFCON 4DEFCON 3DEFCON 2DEFCON 1
Delete container⚠️ Approve👥 2-person❌ Disabled
Drop database👥 2-person❌ Disabled
Remove volume👥 2-person❌ Disabled
Firewall change👥 2-person❌ Disabled
SSH key rotation❌ Disabled

Legend:

  • ✅ Auto = Executes immediately
  • ✅ Log = Executes and logs
  • ⚠️ Approve = Requires single approval
  • 👥 2-person = Requires two approvers
  • ❌ Plan = Can only generate plan
  • ❌ Disabled = Not allowed

Level Transitions

Raising DEFCON (More Restrictive)

DEFCON can be raised (made more restrictive) by:

  • Automatic triggers:

    • Security incident detected
    • Unusual activity patterns
    • Failed health checks
    • Compliance alert
  • Manual triggers:

    • Dashboard SafetyContext UI
    • Per-operation risk classification in policyGate

Lowering DEFCON (Less Restrictive)

Lowering DEFCON requires admin authorization via the dashboard SafetyContext panel. The change is logged in the AEE audit trail with the user who made the change and the timestamp.


Configuration

DEFCON levels are configured via the SafetyContext component in the QuoxCORE dashboard. The current level affects which operations require approval through the policy gate.

The default DEFCON level is set during the setup wizard and can be changed by administrators through the dashboard settings.


Monitoring DEFCON Status

Dashboard View

The DEFCON indicator is visible in the dashboard. The SafetyContext component shows the current level and allows administrators to change it.

DEFCON level changes are logged as AEE audit envelopes, creating a full trail of who changed the level and when.


See Also