AUTOPILOT · INCIDENT PASS

Let the AI look. Not keep the keys.

When production breaks, give Autopilot one cloud account, the regions that matter and a few minutes of read-only access. The pass expires on its own, and every read is counted.

Incident Pass on Business

The usual way

Production is down, and the AI wants a key.

Cloud key

ReadOnlyAccess · all regions · no expiry

Example data.

✕To let an assistant help, someone pastes a cloud key into it.
✕The key can read everything, everywhere.
✕Nobody removes it after the incident.
✕Nobody can say afterwards what it looked at.
What you are seeing
  1. 01Production breaks
  2. 02Open a narrow pass
  3. 03Autopilot reads, inside the pass
  4. 04Outside? Refused.
  5. 05It explains what happened
  6. 06The pass runs out
  7. 07Checked at every read

Example data.

How it works

Narrow, look, expire

01

Open a narrow pass

Choose one cloud account, required regions, an optional name prefix, minutes and why. The reason goes in the audit record.

One account

AWS · shop-prod

eu-west-2checkout*read-only30 min

Example data.

Example data.

02

Autopilot reads inside it

Zaysa checks each read against the pass and counts every read under it. Autopilot never receives a key.

Autopilot reads
load balancer target health · checkout-alballowed ✓
instance status · checkout-web-1..3allowed ✓
security group rules · sg-checkoutallowed ✓
recent changes · eu-west-2allowed ✓

Example data.

Example data.

03

It expires on its own

Expiry is checked at each read. An expired or revoked pass covers nothing.

Pass expired

expired · covers nothing

Example data.

Example data.

Scope

Narrower is safer

Choose one account, the regions, and optionally names to cover. Try the controls to see which example resources fit. A zone counts as inside its region.

Build a passAWS · shop-prod · read-only
Regions

A pass with no regions covers nothing.

Leave empty to cover the whole region.

Default 30 min · maximum 240 min.

checkout-alb · eu-west-2covered
checkout-web-1 · eu-west-2covered
orders-db · eu-west-1not covered
search-api · eu-west-2not covered
checkout-cache · eu-west-1not covered
checkout-vm · us-central1-bnot covered

Example data.

Expiry and revocation

Fails closed

A pass covers nothing when it has no regions, has expired or has been revoked. Expiry is checked at the moment of each read. Anything that is not a read is refused.

Example data.

Per request

Autopilot never gets the key

Zaysa holds the credential and decides on each request what Autopilot may see. Every read under the pass is counted. The reason stays in the audit record.

Autopilot

Sends a read request →

Never receives a key.

Zaysa

Holds the credential. Checks the pass per request.

Answer

Data or refusal. Every read under the pass is counted.

Example data.

Questions

Frequently asked questions

It can read within the pass to explain an incident. Anything that is not a read is refused. Fixes still go through Autopilot’s normal rules and approvals.

More in Autopilot

See what you run, and what it costs.

Free plan, no card needed.