{
  "slug": "rogue-agent-runbook",
  "title": "The first hour after an agent goes wrong",
  "summary": "Killing the process is not containment. A working runbook for the first hour of an AI agent incident, and why receipts turn a hunt into a query.",
  "lede": "At two in the morning, the question is not whether the agent is running. It is what the agent is still allowed to do, and what it has already done. Most stacks cannot answer either question, which is why the first hour of an agent incident is spent on archaeology instead of containment.",
  "date": "2026-09-29",
  "reading_time": "14 min read",
  "category": "Agents",
  "tags": [
    "AI agent incident response",
    "rogue agent",
    "blast radius",
    "revocation",
    "runbook",
    "delegation",
    "incident response"
  ],
  "image": "https://cdn.twc.sh/images/igcache/Rogue%20Agent%20Runbook/1200_630/blog.jpg",
  "url": "/blog/rogue-agent-runbook.html",
  "wordcount": 4758,
  "related": [
    "agent-deleted-production",
    "revocation-that-propagates",
    "authority-graph"
  ],
  "schema": "Article"
}