An admission review captures one moment. Continued use requires an owner, review triggers and a tested shutdown path. This operating worksheet is general educational guidance and should be adapted by the team responsible for the system.
Changes that require another review
Reassess a new publisher, revision, dependency source, data category, authentication scope, writable path, network destination or business purpose. A change that looks small in a manifest can create a materially different capability. Keep the old approval linked to the old conditions until the changed deployment is evaluated.
When suspicious behavior appears
Pause the affected capability through the platform’s authorized controls. Preserve the relevant decision logs, exact artifact and configuration. Identify credentials and downstream systems within its reach. Revoke or rotate exposed credentials through the responsible owners. Avoid continuing execution merely to see what happens in a sensitive environment.
Investigation questions
Which version actually ran? What data could it read? Which operations did it attempt and complete? Were destinations constrained? Did the behavior originate in the package, a dependency, tool output or another untrusted input? Was there a human approval, and did the final action match it? Separate observed events from what a permission theoretically allowed.
Return to service
The responsible team should define the conditions for restoration, including a reviewed replacement, corrected scopes, evidence of containment and a successful revocation exercise. Record remaining uncertainty. A clean scanner result alone does not prove that an incident is resolved.
Retirement
Remove the capability from the active inventory, revoke credentials, terminate queued work and remove unnecessary retained data under the organization’s retention process. Preserve the minimum audit evidence required by the operator. Verify that the capability can no longer access its former resources. Review references from other skills so retirement does not leave an unexpected dependency path.