- Incident operator
- Requests the containment action for one bounded target based on incident context.
- Containment approver
- Approves, rejects, or delays the action under incident authority and policy constraints.
- Execution surface
- Runs the actual containment command or workflow after the gate condition is met.
- Target system
- Reflects the blocked account, isolated host, revoked token, or other containment result.
- Evidence export path
- Carries approval, execution, and target-state evidence out for later inspection.