How 3AM decides
Safety rails
Shadow mode, autonomy per service, policy, rehearsals, budgets and the halt switch.
| Rail | What it does |
|---|---|
| Shadow mode | The default for every new install. 3AM diagnoses and records what it would do; it asks no one and changes nothing, not even a note on a page |
| Autonomy per service | off, shadow or L1 (one approval per action), set service by service. Raising needs two approvers; lowering is instant |
| Policy rules | First match wins. Refuse an action outright (with a reason), require a quorum, or allow it only during certain hours |
| Rehearsal | Every change is dry-run before anyone is asked: SQL inside a transaction that is rolled back (statements that can't be rolled back are flagged), Kubernetes with server-side dry run, silences by listing what they would match |
| Bound and validated | Fixes are filled in only from proven evidence, and every value must match its allowed pattern (a session id must be a number, a name a plain name) |
| Budgets | At most N actions per service per hour, and in total |
| Verification | After a change, the cause must clear, or the incident is marked unresolved and handed to people |
| Halt switch | Refuses every action everywhere, at once, until resumed |
| Audit log | Every decision, with its reasons, is recorded and verifiable |
What 3AM will never do on its own
- Act on a service in shadow mode, or on one set to off.
- Act without the approvals the policy requires.
- Run anything that isn't a pack's vetted remediation, filled in from proven evidence.
- Retry a change the approver rejected.