Protection states, from observation to enforcement

What Observe, Shadow and Enforcing mean, which gates sit between them and how you move safely in both directions.

Expected result

You know exactly what changes for visitors in each protection state.

Observe

Traffic is measured; nothing changes for visitors. Inventory, threat relevance and traffic telemetry accumulate so every later decision has evidence.

Shadow

Candidate rules run against real traffic without blocking anything. You see exactly what would have been flagged, and false positives cost nothing.

Enforcing

Bounded controls may act - always scoped, always with a TTL, always with a rehearsed rollback. Enforcement requires explicit gates to pass first: certificate issued, origin stability window, health checks, rollback proof. Autonomous blanket blocking does not exist in AegiFlow.

Monitoring only

Some services are watched without ever routing traffic through AegiFlow: the external scan, certificate transparency, email posture, look-alike domains and the transaction checks all work from the outside. A service marked monitoring-only stays in that mode deliberately, and the onboarding steps that ask for traffic stop being asked of it.

Moving between states

Transitions are explicit operator decisions and work in both directions. Returning to Observe is always available and never gated.

Verification

  • You can list the gates required before enforcement
  • You know how to return to a previous state