The operating process for containing and learning from harmful agent behavior.
Agent incident response connects detection to immediate containment, evidence preservation, authority revocation, rollback or compensation, user communication, recovery validation, and a post-incident update to threat models and regression tests. A kill switch matters only if responders know what it stops and state can be recovered safely.