01An agent reaches an OT system
An agent pushes a change to an operational-technology system on the production floor, a physical process, not a document. Tier-gated authorization holds the change for a named operator and enforces hard limits before anything executes.
02Export-controlled data to the wrong account
An engineering agent attempts to share ITAR (export-controlled defense) technical data with an account not eligible to receive it. Authorization ties the action to the operator's eligibility, refuses it, and records the attempt.
03A safety-critical design changed silently
An agent edits a safety-critical engineering record in a way that would ship without review. Behavioral monitoring flags the out-of-pattern change and auto-quarantines the agent before it propagates.
04The defense auditor wants proof
An auditor asks who, or what, touched a controlled record and under whose authority. A tamper-evident, hash-linked trail answers it, mapped to the controls a defense contract requires.