Safety controlRuntime control
Emergency disable
Disable unsafe enforcement quickly while preserving scope, reason, and recovery evidence.
Emergency disable — contract and behavior
- Emergency disable is a deliberate high-severity action with an explicit target and operator reason.
- The control does not delete the hook, justification, telemetry, or release history.
- Recovery requires a validated policy/release decision rather than an automatic timeout that silently re-enables enforcement.
- The UI confirms observed disabled state after issuing the request.