Kill switch runbook
Documents triggers, authorized operators, and post-halt messaging.
Pre-authorized halt paths with named stewards, thresholds, and restoration drills so harms stop in seconds.
Where it fits
Tagged for Governance, Friction with validator handshakes. Includes 3 steps, 3 reusable assets, and 4 snippet blocks.
Jump to
Key sections
Copy citation (APA/BibTeX)
APA
Ethotechnics Institute Research Team. (2026). MEC-05 Kill switch for runaway automation. Ethotechnics Institute. https://ethotechnics.org/mechanisms/patterns/kill-switch
MLA
Ethotechnics Institute Research Team. "MEC-05 Kill switch for runaway automation." Ethotechnics Institute, 2026, https://ethotechnics.org/mechanisms/patterns/kill-switch.
Chicago
Ethotechnics Institute Research Team. "MEC-05 Kill switch for runaway automation." Ethotechnics Institute. Jan 9, 2026. https://ethotechnics.org/mechanisms/patterns/kill-switch.
BibTeX
@misc{mechanism_kill-switch,
title={MEC-05 Kill switch for runaway automation},
author={Ethotechnics Institute Research Team},
year={2026},
howpublished={Ethotechnics Institute},
url={https://ethotechnics.org/mechanisms/patterns/kill-switch},
version={v1.1.0}
}
RIS
TY - WEB TI - MEC-05 Kill switch for runaway automation AU - Ethotechnics Institute Research Team PY - 2026 UR - https://ethotechnics.org/mechanisms/patterns/kill-switch ER -
Specification overview
Capture the scope, assets, and validator handshakes before diving into the steps.
Spec essentials
Filters & validators
Tagged in 2 filters with 2 linked validators.
Glossary anchors
Jump to the glossary terms that frame this mechanism.
Steps
Start with the field cues, then use the assets to keep the work legible.
3 steps with checklist-ready owners, plus linked assets for handoffs.
0 of 3 steps complete
Assets
Link or copy these assets into design docs, runbooks, and briefs so the mechanism travels with the work.
Documents triggers, authorized operators, and post-halt messaging.
Confirms data, access, and user impact are stable before resuming.
Captures what tripped the switch and how to tighten thresholds or observability.
Reuse-ready snippets
Use these snippets in requirements, audits, and postmortems with the mechanism permalink.
Policy requirement
Policy requirement (MEC-05 Kill switch for runaway automation) - Maintain a pre-authorized halt path with a named roster and protection from retaliation. - Publish tripwires tied to moral performance indicators and time-to-halt targets. Reference: https://ethotechnics.org/mechanisms/patterns/kill-switch
Product requirement
Product requirement (MEC-05) - The kill switch is reachable within one operational step from monitoring dashboards. - Halt events emit receipts with owner, trigger, and restoration checklist links.
Audit evidence checklist
Audit evidence checklist (MEC-05) [ ] Kill switch runbook names authorized operators and triggers. [ ] Drill logs demonstrate time-to-halt performance. [ ] Rollback checklists show safe restoration steps.
Postmortem trigger
Postmortem trigger (MEC-05) Trigger review when time-to-halt targets are exceeded or the kill switch is unavailable.
Example usage
A concrete scenario to help teams see how the pieces fit together.
How it plays out
Operations staff notice a spike in appeals and trip the kill switch, freezing recommendations, routing cases to humans, and restoring with updated thresholds before re-enabling automation.
Anti-patterns
Use these to avoid superficial compliance and clarify what success requires.
A halt path exists but no drills confirm that it works under pressure.
Counterfactual: Teams rehearse halts and document restore steps with time-to-halt targets.
False-positive warning: Simulation is acceptable when production drills are risky, but it must be documented.
Only one person can trigger the halt, creating dead zones off-hours.
Counterfactual: A pre-authorized roster can halt automation without retaliation risk.
False-positive warning: Small teams can assign a primary/secondary if coverage is explicit.
Validators
Use these tools to size risk and keep the stewardship path visible.
Validator
Tabletop simulation that plays through outages, maintenance windows, and handoffs to stress-test coverage.
Validator
Quantifies task load, cognitive friction, and risk exposure so you can reroute toil before it burns people out.