The kill switch is on by default. This playbook is about making it a control you trust rather than a button you've never pressed.
Decide who holds it
One named owner, plus one backup. In practice the best owner is whoever feels the consequences most — Head of Paid Media, Head of Retention, the founder. Ownership should sit with accountability, not with engineering.
Agree the triggers in advance
- A metric moves in a way no one can explain yet — stop first, diagnose second.
- An upstream platform is behaving abnormally and you don't want the agent reacting to bad data.
- A high-stakes launch or sale where you want a human hand on everything for a day.
Run the monthly drill
- 1On a normal day, press the kill switch on purpose.
- 2Confirm every executor stands down inside 90 seconds.
- 3Verify the decision_log chain signature is intact and in-flight actions kept their reverse ops.
- 4Flip it back on. Total time: about five minutes.
A switch you've never tested is a hope, not a control. Drill it before you need it.
