Executes one approved containment action through the AuthorityBridge gate — host isolate (Wazuh), client block/deauth (UniFi), account disable + sessions revoke (Microsoft 365).
Charter
Execute the approved containment step under the AuthorityBridge gate. Paladin runs built-in, connector-backed remediation — isolate or restore a host (Wazuh), block or deauth a client (UniFi), disable an account or revoke its sessions (Microsoft 365) — each operator-approved at the v1 L3 default, audited, and reversible. Requires a Marshal-sequenced plan; never acts on a single uncorroborated signal, and never beyond a registered connector executor.
Skill enhancements
Paladin keeps its job — it just gets sharper when you equip an optional AI Skill (bring your own provider key; we never resell one). Equip one and it earns a title; equip more and it ascends.
A guarded containment layer with a safety preflight: block, isolate, or revoke through the connector that actually manages the target — refused or narrowed if the asset is critical or the blast radius is unconfirmed.
How it enhances: The jump from advises to acts. Paladin doesn't just recommend containment — it executes the approved action, with the preflight standing between a good call and a bad one.
Trust ceiling
L3 default (operator-approved). Some built-in templates are L5-eligible where their risk_lock_ceiling allows (e.g., host isolation); others are capped lower (M365 account-disable is L4 per its manifest). The Bridge enforces; the engine refuses any action_template_id not in the registered executor set.
AuthorityBridge → registered connector executor. Real today: wazuh.isolate_agent / restore_agent · unifi.block_client / deauth_station · m365.disable_user / revoke_sign_in_sessions.
Never acts on a single uncorroborated signal. Never beyond a registered executor (DryRun fallback otherwise). Never bypasses the Bridge.
Engine wiring
| Engine | Relationship | Note |
|---|---|---|
| AuthorityBridge | Execute | The Bridge authorizes + audits; the registered connector executor performs the action; rollback metadata is captured for every step. |
| Beacons | Read | Reads the case verdict that Marshal approved. |
Marshal · Human Commander
Marshal
- Engine status: Doctrine · v1.x
- Model lane: Local 8B (action-grounded, schema-strict — refuses anything off the registered template list).
- Training: QLoRA on 8B; action-template-scoped; planned.
- Status: Doctrine · v1.1. Six registered action_template_ids published; charter mission visible. The Pro tier unlocks Knight-bounded containment when v1.1 ships. Production prompt + execution playbook are NOT published (kept in-product).