Skip to main content

Incidents & break-glass

The Incidents screen lets you contain issuance risk without interrupting existing identities. Its main control is the issuance kill switch: one authorized person can pause all new issuance immediately, but resuming always takes two different people.

ConsoleIncidents

What it's for​

  • Pause new issuance during an incident, such as a suspected key compromise.
  • Request and independently approve a resume once the incident is contained.
  • Review issuance guardrail findings: unusual requests that were flagged or blocked.

When the kill switch is active or a resume request is waiting, the Incidents item in the navigation shows a red dot and the top bar reads issuance paused.

What you see​

Incidents screen with the security controls card, issuance assessment summary, audit and quorum status, and the break-glass policy card
Incidents.

Security controls​

StateHeadingButton
NormalIssuance controls are normalActivate kill switch
Paused, no requestNew issuance is pausedRequest guarded resume
Paused, you made the pending requestNew issuance is pausedAwaiting another operator (disabled)
Paused, someone else made the requestNew issuance is pausedIndependently approve resume

Existing certificates continue operating. New issuance and renewals requiring approval fail closed.

While a resume request is pending, a panel shows RESUME REQUEST · GENERATION n, its status, the reason, who requested it and when it expires.

Request statusMeaning
1 of 2 approvalsWaiting for a second person.
expiredTen minutes passed without approval. The request can no longer be approved.

Status lines​

LineMeaning
No issuance-risk assessment has been recorded yetNo guardrail assessments exist yet.
n signed issuance assessments · no guardrail signalRequests were assessed and none raised a signal.
n signed guardrail signals · m requests blockedSome requests raised signals; m were blocked. Details are listed below.
Audit integrity labelSame labels as Audit evidence, for example Chain verified from genesis.
n healthy customer trust replicasHealthy Mesh Nodes available for the approval quorum.

Guardrail findings​

Up to six findings are listed, each with the signal type, an explanation, the requester's identity and the decision. A block decision means the request was denied before any CA was called. Configure guardrails in Policies under Issuance behavior guardrails.

Break-glass policy​

FieldValue
Resume authorityTwo distinct humans
Approval quorumRequired of eligible local nodes, for example 2 of 3 local
Quorum capacityAvailable or Fail closed
Approval window10 minutes · generation bound

Pause new issuance (kill switch)​

Activate issuance kill switch dialog with the reason box, the PAUSE ISSUANCE confirmation field and the Pause new issuance button
The kill-switch dialog.
  1. Open ConsoleIncidents and select Activate kill switch, or select Emergency controls on Trust health.
  2. In Activate issuance kill switch, enter the Reason for audited change (16 to 1,000 characters). It becomes immutable audit evidence.
  3. In Type exact confirmation, type PAUSE ISSUANCE.
  4. Select Pause new issuance.

The console confirms: New issuance paused; existing certificates remain active.

Resume issuance​

Resuming needs two different people, each with fresh MFA.

Step 1: request a resume​

  1. Select Request guarded resume (or Resume issuance on Trust health).
  2. In Request guarded issuance resume, enter the reviewed recovery reason (16 to 1,000 characters).
  3. Type REQUEST ISSUANCE RESUME.
  4. Select Request independent approval.

The console confirms: Guarded resume requested; a different operator must approve. The request expires after ten minutes.

Step 2: approve the resume (second person)​

  1. A different person signs in and opens ConsoleIncidents.
  2. They select Independently approve resume.
  3. In Independently approve issuance resume, they review REQUESTED BY and the reason.
  4. They type APPROVE ISSUANCE RESUME.
  5. They select Approve and resume issuance.

The console confirms: Independent approval recorded; issuance resumed.

What is rejected

You are the second human control. Self-approval, stale MFA, expired requests and requests from an earlier pause generation are rejected. A new pause cancels every pending resume request.

Confirmation phrases​

ActionType exactly
PausePAUSE ISSUANCE
Request resumeREQUEST ISSUANCE RESUME
Approve resumeAPPROVE ISSUANCE RESUME

Phrases are case-sensitive. The submit button stays disabled until the phrase matches and, for pause and request, the reason is at least 16 characters.

Demo workspace

In the demo, the requester can select Simulate second approval to see the full flow.

Permissions​

ActionRoles
View IncidentsEvery role
Pause, request resume, approve resumeBreak-glass Operator, Tenant Admin. Requires MFA within the last ten minutes, checked again on submit.
Approve resumeMust be a different person from the requester.

Pre-assign at least two separately controlled people or groups to the Break-glass Operator role so that you are never blocked by having only one. See Access & roles and Incident response.

Troubleshooting​

SymptomCause and fix
The submit button is greyed outThe confirmation phrase does not match exactly, or the reason is shorter than 16 characters.
Awaiting another operatorYou made the request. A different person must approve it.
The request shows expiredTen minutes passed. Select Refresh in the top bar; once the expired request clears, Request guarded resume is available again.
Approval is rejectedYour MFA is older than ten minutes, you are the requester, the request expired, or a newer pause replaced it.
Quorum capacity shows Fail closedNot enough healthy Mesh Nodes. Even after resume, new issuance fails until quorum returns. See Mesh nodes.