Docs
How 3AM decides

Safety rails

Shadow mode, autonomy per service, policy, rehearsals, budgets and the halt switch.

RailWhat it does
Shadow modeThe default for every new install. 3AM diagnoses and records what it would do; it asks no one and changes nothing, not even a note on a page
Autonomy per serviceoff, shadow or L1 (one approval per action), set service by service. Raising needs two approvers; lowering is instant
Policy rulesFirst match wins. Refuse an action outright (with a reason), require a quorum, or allow it only during certain hours
RehearsalEvery change is dry-run before anyone is asked: SQL inside a transaction that is rolled back (statements that can't be rolled back are flagged), Kubernetes with server-side dry run, silences by listing what they would match
Bound and validatedFixes are filled in only from proven evidence, and every value must match its allowed pattern (a session id must be a number, a name a plain name)
BudgetsAt most N actions per service per hour, and in total
VerificationAfter a change, the cause must clear, or the incident is marked unresolved and handed to people
Halt switchRefuses every action everywhere, at once, until resumed
Audit logEvery decision, with its reasons, is recorded and verifiable

What 3AM will never do on its own

  • Act on a service in shadow mode, or on one set to off.
  • Act without the approvals the policy requires.
  • Run anything that isn't a pack's vetted remediation, filled in from proven evidence.
  • Retry a change the approver rejected.

On this page