CyberCLI

Calibrated autonomy · 8 levels · per action template

You set the dial.
Every action carries a receipt.

Most "AI security" products give you one knob: on or off. CyberCLI gives you eight, set independently per action template per connector. L0 is total human control; L7 is full automation with audit-only reporting. v1 ships every customer at L3 for writes ("AI proposes, human approves") — the Advisor-not-Automator launch policy. Earn elevation by watching the Shadow log calibrate against your team's decisions.

Source: src/cybercli/bridge/trust_ladder.py · per Architecture v0.4 §4. Every level — including L7 — writes a hash-chained audit row. Trust without auditability isn't trust; it's hope.

Levels
8
L0 → L7 per action template
v1 write default
L3
AI Proposes · human approves
v1 read default
L7
AI Acts · logs only
Red = autonomous, not dangerous. Reads have zero blast radius; the red flags WHO acts (the engine), not what they can break.
Audit coverage
100%
Hash-chain at every level

Earned, not granted · uncontested in the category

How trust is earned.

Every other AI security product ships fixed autonomy. Their AI is at the same level on day 1 and day 365. CyberCLI is the only one where the ceiling moves as the role proves itself. Here is how one action template — notify_only.v1 — typically earns its way from L3 to L4 across the first 90 days of an install.

  1. Day 1 · Install
    Ceiling
    L3
    AI proposes

    notify_only.v1 fires on a signal. AI drafts the alert; nothing reaches an operator without explicit approval.

    Proposed: 14
    Approved: 14 (100%)
  2. Day 30 · Calibrating
    Ceiling
    L3
    Track record building

    Calibration log shows the AI's drafts vs. operator decisions on every disposition class. Zero false flips on the four "easy" disposition classes.

    Proposed: 89
    Approved: 87 (97.8%)
    Trust score · 4.2 / 5
  3. Day 60 · Promotion ready
    Ceiling
    L3 → L4
    Dashboard suggests lift

    Calibration window passes the threshold. The Trust Ladder card prompts: "notify_only.v1 has earned a veto window. Promote to L4?"

    Proposed: 268
    Approved: 261 (97.4%)
    Trust score · 4.6 / 5
  4. Day 90 · Promoted
    Ceiling
    L4
    AI acts · veto window

    AI now fires the notification after a 24-hour silent veto window. Operator can still intervene per row; no longer has to approve each one.

    Veto window: 24 h
    Audit row: every fire
    Drop-back to L3 · 1 click
Calibration is per-template

notify_only.v1 earning L4 doesn't lift wazuh.isolate_agent.v1. Every action template earns its own ceiling on its own track record. State changes start at L3 and stay at L3 until they prove they deserve more.

Operator always has the dial

Promotion is a suggestion, not a system action. You read the calibration log, you decide. Drop-back to a lower ceiling is one click and a hash row.

Audit at every level

L3 proposal, L4 veto-window fire, drop-back to L3 — all three carry hash-chained audit rows that say which model fired, at which level, against which evidence.

Numbers above are illustrative — they show the shape a calibration arc typically takes on a Free-tier install with light-volume notify_only traffic. Real-install numbers land in the dashboard's Trust Ladder card from day 1. The calibration mechanism, ceiling promotion, drop-back, and audit row at every step are all real v1 behavior.

Try it · the dial is yours

Set the dial. See what the AI would do.

Pick an action, choose how much autonomy you grant it, and pick a tier. CyberCLI takes the lowest of three ceilings — your dial, the action's own risk-lock, and your tier — so you can never over-trust an action by accident. Every outcome below writes a hash-chained receipt.

1 · Pick an action
2 · Set your dial
← human controlfull autonomy →
3 · Your tier
Tier sets the ceiling; inside it you dial freely.
What happens
L3 proposes

Always: a hash-chained audit row is written — proposed, approved, executed, or rolled back. Trust without auditability isn't trust; it's hope.

Reference · the eight levels, low to high autonomy

L0
Human Only

AI is off. Every action requires a human to perform it.

AI can do

Nothing. AI does not observe, propose, or act.

Requires approval for

Every single action — there is no AI in the loop.

Concrete examples at this level
  • Operator manually reviews alerts in dashboard
  • Operator manually clicks 'isolate host' in UniFi admin
  • All triage + containment is hands-on-keyboard
L1
AI Observes

AI watches and labels signals. Recommendations not stored or acted upon.

AI can do

Read events · classify · score · render the dashboard view.

Requires approval for

All actions. AI is purely read-only and ephemeral — no proposals are persisted.

Concrete examples at this level
  • Warden classifies events as benign / suspicious / urgent
  • Operator sees real-time AI labels in the queue
  • No decision packet is created; nothing is queued
L2
AI Shadow

AI proposes silently to itself. Decisions logged for calibration, never surfaced.

AI can do

Generate decision packets · evaluate · score · write to a shadow log.

Requires approval for

All actions. Shadow is a calibration mode — the operator never sees AI proposals.

Concrete examples at this level
  • Knight runs verification playbooks privately; results audit-logged
  • Marshal drafts containment plans into the shadow log only
  • Used to measure AI quality before flipping to L3
L3
AI Proposes v1 default · write

v1 default for write actions. AI drafts plans + waits for one human click.

AI can do

Triage · verify · sequence · render Decision Packets to the operator queue with full evidence + rollback metadata.

Requires approval for

Every execution. AI never executes a write action without operator approval through the AuthorityBridge gate.

Concrete examples at this level
  • Marshal sequences a 4-action containment plan
  • Plan lands in /queue with [Approve] / [Deny] / [Modify] controls
  • Operator clicks Approve → audit chain stamps → Paladin executes
L4
AI Veto Window

AI announces, executes after a countdown unless the operator vetoes within the window.

AI can do

Triage · verify · sequence · announce + execute after operator-configured veto window (e.g., 60 seconds).

Requires approval for

Implicit (no-veto). Operator can cancel before the timer expires; silence = consent.

Concrete examples at this level
  • Knight verifies → Marshal queues 60-sec veto banner in dashboard + Slack
  • If operator clicks Veto within 60 sec → halt + log
  • If silent → Paladin executes + audit-logs
L5
AI Acts + Alerts

AI executes immediately. Operator gets a real-time alert with the receipt.

AI can do

All of L3 + execute approved-template actions without waiting for approval.

Requires approval for

None at runtime. Operator reviews after the fact via Alert channel + audit chain.

Concrete examples at this level
  • High-confidence host isolation fires automatically
  • Slack + email alert lands within seconds of execution
  • Operator can roll back via /actions/:id if needed
L6
AI Acts + Reports

AI executes. Operator sees the action in the daily / weekly summary report, not in real time.

AI can do

All of L5 + suppress immediate alerts in favor of digest-mode reporting.

Requires approval for

None. Operator reviews via summary reports + audit chain.

Concrete examples at this level
  • Low-risk actions (quarantine known-bad attachments) auto-execute
  • Operator sees aggregated daily 'CyberCLI acted on N events' report
  • Useful for MSPs running unattended at scale
L7
AI Acts + Logs Only v1 default · read

v1 default for read actions. AI executes. Forensic record in the audit chain is the only artifact.

AI can do

Everything: read events, run verification probes, collect evidence, write case notes, send notifications — all without alerting.

Requires approval for

None. The audit chain IS the report. Operator reviews on demand via /cases or audit-log queries.

Concrete examples at this level
  • Warden classifies + dedupes + enriches every event silently
  • Herald sends operator notifications per channel preferences
  • Scribe writes case timelines as cases close — no extra signal

What's the max your tier can dial up to?

Each subscription tier sets a ceiling on Trust Level. Inside that ceiling you dial per-action-template freely. The ceiling exists because higher-autonomy actions need higher-trust roles (Marshal proposes, Paladin executes) — and those roles are tier-gated.

Tier Max ceiling Note
Free L3 (AI Proposes) Warden + Herald (rate-limited). Containment is all operator-side; no executor role at this tier.
Pro+ L5 (AI Acts (Approve)) Pro unlocks Knight + Marshal + Paladin — one-click single-action containment under operator approval. Paladin executes the one approved L5-eligible template (e.g., host isolation via the Wazuh agent).
Business+ L7 (AI Acts Autonomous) Business adds Marshal multi-action sequenced plans (one approval per plan) + Scribe. Full ladder available; L6+ requires explicit per-template operator op-in.
Enterprise L7 + Sovereign federation Enterprise adds the Crown Layer (Sovereign, doctrine v1.5) for cross-instance posture + custom autonomous-act enablement per template. Same Trust Ladder applies per-instance.

Five invariants that hold at every level.

The Trust Ladder gives the operator a dial. These guarantees apply no matter where the dial is set — including L7.

Invariant
Hash-chain audit

Every action — proposed, approved, executed, rolled back — writes a row to an append-only hash-linked log. Tampering changes the chain root. Operators can prove what happened to a forensic investigator without trusting CyberCLI.

Invariant
Rollback metadata

Any reversible action (most of them) carries the metadata needed to undo it: original firewall rule, original mailbox membership, pre-isolation host state. Rollback is one call, audit-logged itself.

Invariant
Trust Ceiling per tier

An action declared at risk_lock_ceiling=L5 will never execute above L5, regardless of what the operator dials. The engine caps below the declaration if the tier's max is lower. There's no way to over-trust an action by mistake.

Invariant
Operator override

Even with L7 dialed for an action template, an operator can intercept a specific Decision Packet from the queue, approve it manually, deny, or modify before it executes. Live ladder → not a guardrail you bypass.

Invariant
Connector-id in every row

Audit rows record which connector emitted the signal AND which connector executed the action — including community-submitted connectors. Per-connector forensic isolation is a property of the chain, not the dashboard view.

Invariant
Earned Elevation

v1 ships every write action at L3 (AI Proposes). To move to L5+ you watch the Shadow log calibrate — AI's proposals are scored against your team's decisions. Numbers cross a threshold → operator may elevate. The product won't elevate on your behalf.

Dial your trust. Audit every step. Sleep at night.

That's the architecture.

Trust isn't a binary; it's a calibration. CyberCLI lets you set it per action, per connector, per posture state — and proves what happened with cryptographic receipts at every level. You can revoke. You can audit. You own the keys.

v5.5 · 8-level Trust Ladder datasheet · sourced from engine src/cybercli/bridge/trust_ladder.py · Architecture v0.4 §4