Protection states, from observation to enforcement
What Observe, Shadow and Enforcing mean, which gates sit between them and how you move safely in both directions.
You know exactly what changes for visitors in each protection state.
Observe
Traffic is measured; nothing changes for visitors. Inventory, threat relevance and traffic telemetry accumulate so every later decision has evidence.
Shadow
Candidate rules run against real traffic without blocking anything. You see exactly what would have been flagged, and false positives cost nothing.
Enforcing
Bounded controls may act - always scoped, always with a TTL, always with a rehearsed rollback. Enforcement requires explicit gates to pass first: certificate issued, origin stability window, health checks, rollback proof. Autonomous blanket blocking does not exist in AegiFlow.
Monitoring only
Some services are watched without ever routing traffic through AegiFlow: the external scan, certificate transparency, email posture, look-alike domains and the transaction checks all work from the outside. A service marked monitoring-only stays in that mode deliberately, and the onboarding steps that ask for traffic stop being asked of it.
Moving between states
Transitions are explicit operator decisions and work in both directions. Returning to Observe is always available and never gated.
Verification
- You can list the gates required before enforcement
- You know how to return to a previous state