ControlDetection and responsex, held

Detection and response: contain a rogue agent while it runs.

Behavioural detection, automatic containment, a kill switch at four scopes and session replay, with who and why on record.

How it works

Specs

Detection and response, in detail

Delivery and data

Delivery
SaaS, from one login.
Isolation
Each customer runs in an isolated workspace with its own database.
Certifications
None held. Frameworks are mapped to and assessed against.

Frameworks

MITRE ATT&CK
Detections mapped to: Behavioural detections, mapped to techniques.
OWASP Top 10 for Agentic Applications
Assessed per agent against: Rogue agents, ASI10, assessed per agent.
See the frameworks

Last reviewed 6 Oct 2026

Runaway, containedIllustrative

Runaway, contained: 03:02 Calls at machine speed (research-agent); 03:02 Read, then sent out (in one window); 03:03 Quarantined automatically (on your limits); 03:03 Incident and alert (email, webhook, SIEM); 09:20 Released with a reason (who and why kept).

In shortAgent detection and responseAgent detection and response watches AI agents as they run, spots unsafe or out-of-character behaviour, and acts on it: holding a request for a person, containing an agent or stopping it altogether. It borrows the idea of endpoint detection and response, applied to software that decides and acts at machine speed. In the glossary

Agent detection and response in ColossalX spots an agent behaving unlike itself, against baselines mapped to MITRE ATT&CK and ATLAS, and contains a runaway or machine-speed agent on the limits you set. The ColossalX Kill Switch halts AI at 4 scopes with a written reason, sessions replay request by request, and response playbooks are rehearsed safely.

At three in the morning, an agent calls tools at machine speed, reading data and sending it out.

ColossalX contains it on the limits you set, raises an incident, and keeps who released it and why.

How it works

From a refused tool call to a contained agent.

One refusal at the gateway triggers a response workflow: an incident, the on-call team told, and a named person who decides whether to quarantine the agent, with each step recorded.

Workflow · a refused tool call, answeredIllustrative

01 Refusal triggers

The gateway refuses a tool call, and a response workflow starts.

02 Steps run

An incident is raised and the on-call team is told.

03 A person decides

A named person chooses to quarantine the agent, with a reason.

04 Contained, replayable

The agent is quarantined, and its session replays request by request.

What you see

Four switches, each with who and why on record.

The ColossalX Kill Switch halts AI for the whole workspace, a provider, a model or a person, and its event log keeps who switched it, when and why.

  1. Detect from behaviour
  2. Contain automatically
  3. Switch off by scope
  4. Replay and respond
Read the detail, step by step4
  1. Detect from behaviour. Each agent has a baseline; detections map to MITRE ATT&CK and ATLAS. Sequences of tool calls are watched as well as single requests. Code a model hands an agent to run is read before the agent receives it, and never run.
  2. Contain automatically. A runaway or machine-speed agent is contained on limits you set. The guard looks for sub-human cadence and data read then sent out in one window. A safe emulation through the gateway proves the guard catches it.
  3. Switch off by scope. Workspace, provider, model or person, each with a written reason. Each agent can also be suspended, quarantined, killed for a set time or released, and its history records who acted and why.
  4. Replay and respond. Replay a session request by request; run playbooks rehearsed in advance. Response workflows start on a schedule, an agent event or a gateway refusal, and can ask an agent, branch, wait for a person, contain, raise an incident or notify.
ContainmentIllustrative

An illustrative containment view: the ColossalX Kill Switch on standby at workspace, provider, model and person scope, one agent calling at machine speed and quarantined automatically on your limits, and a log of who acted and why, including the person who released it.

How it connectsx, held

Where a contained agent goes next.

Containment is the start of the work, not the end. The agent, the evidence and the fix each have somewhere to go.

  1. Its page keeps an append-only history: who contained it, when and why.

  2. After a fix, re-attack the agent to measure whether the gap closed.

  3. Incident playbooks are real workflows, rehearsed safely before they are needed.

  4. What your own controls caught appears in one detection feed.

Honest by design

What it does, and what it does not.

Model switch scopeIllustrative

Model switch scope: claims-bot to model B off; notes-bot to model B off; model B off refused before model B (refused); model B off to model B (served).

What it does not do

x, not measured

Provider and model switches catch requests that name that provider or model.

All 4 limits
  • Automatic containment by the machine-speed guard is switched on per workspace.
  • Runtime detections open incidents and tickets, not yet items in the one issue queue.
  • Code inspection reads code before an agent runs it; how much it catches is not measured.

How we know

  • A kill switch needs a written reason, kept with who switched it and when.
  • Code a model asks an agent to run is read before the agent gets it, and never run.
  • The containment guard is proven with a safe emulation through the gateway.
  • Each SIEM connection shows whether events are actually arriving, not only that it is connected.

Questions

Questions buyers ask

What is agent detection and response?

Agent detection and response watches what AI agents actually do, spots behaviour that departs from each agent's own baseline, and acts: contain the agent, alert the people responsible and keep a record that can be replayed. It treats agents as actors to be monitored and stopped, not only as prompts to be filtered.

How do you stop AI agents going rogue?

Layer it. Limit what each agent may do with trust zones and tool rules, watch its behaviour against its baseline, and contain it automatically when it acts at machine speed or breaks the limits you set. Then keep a switch a person can pull, with a reason, and replay what happened before releasing it.

What is an AI agent kill switch?

An AI agent kill switch stops AI activity at once, as narrowly or as broadly as an incident needs. The ColossalX Kill Switch works at 4 scopes, the whole workspace, a provider, a model or a person, and each agent can also be suspended, quarantined or killed for a set time. Each activation needs a written reason.

What should an AI incident response playbook contain?

Who is told, what is contained and who decides. In ColossalX a playbook is a real workflow: it can ask an agent, branch on the answer, wait for a named person, quarantine an agent, raise an incident and notify, with each agent step running through the gateway as that agent. Rehearse it safely before it is needed.

Can containment happen automatically?

Yes, on the limits you set. A guard that spots machine-speed cadence or data read then sent out can quarantine the agent without anyone clicking; that guard's containment is switched on per workspace. A safe emulation through the gateway proves the guard catches what it should.

Related

Next step

Know your x.

See how your own agents would be contained: the limits, the switches and the record left behind.

  1. 01Tell us what you run
  2. 02See the four verbs on it
  3. 03Decide where to start