Canonical Classification
Recoverability checkpoint before automated actions execute
SMERC sits after detection, identity, and policy but before execution. It decides whether an AI-agent, security, cloud, DevOps, MCP tool-call, or automation action should be allowed, throttled, frozen, denied, or escalated based on recoverability and evidence.
MCPTool-call governance before execution.
Microsoft-styleSecurity response replay before automated action.
GitHubShadow-mode CI/CD and PR review path.
CISOBlast-radius and replay-evidence review.