Containment should prioritize authority paths and active side effects, then preserve relationship evidence for recovery.
Why this question matters
Traditional response begins with affected assets and credentials. Multi-agent response must also identify descendants, peers that consumed artifacts, shared memory entries, scheduled callbacks, and market actions influenced by the agent.
Turning off one runtime may leave the plan alive elsewhere. Responders need a graph snapshot, a way to revoke delegated authority, and a record of which outcomes remain reversible. Recovery should re-establish trust from known identities and clean context rather than simply restarting services.
Signals worth observing
- Tasks continue after the suspected agent is isolated.
- Other agents rely on artifacts or memory it produced.
- Credential rotation does not affect derived or queued authority.
Practical control direction
- Map active delegation and influence paths during containment.
- Quarantine derived artifacts and shared-memory entries.
- Rebuild task context from verified checkpoints.
AgentCollusion lensIncident response is where temporal relationship evidence becomes immediately operational.

