> ## Documentation Index
> Fetch the complete documentation index at: https://docs.get-hive.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Safety and control

> How Owners and Admins control what Hive may do on its own: the kill switch, autonomy ladder, spend caps, circuit breakers and role-based approvals.

Hive is built so that people stay in control of their business. The AI proposes; a deterministic policy engine — plain rules, not a model — decides whether a proposal runs, waits for a person, or is only simulated. This page covers the controls Owners and Admins use to set those rules.

All of these controls live on the **Policy & autonomy** page. Open **Settings → Products → Governance**.

<Info>
  The Policy & autonomy page describes itself as "Legible by design: this confidence × this blast radius × your learned threshold." Every decision Hive takes can be explained in those three terms.
</Info>

## The kill switch

The kill switch stops Hive acting, company-wide, immediately.

* **Engage it** from the Policy & autonomy page with **Kill switch**.
* **While it is on**, every action is forced into shadow mode (simulated, never sent), approvals are frozen, and active learned behaviours drop back to shadow. A banner across the product reads "Kill switch is on. Every autonomous action and approval is halted company-wide", and the sidebar shows "Kill switch active · everything halted".
* **Resume** with **Resume autonomy** on the banner, or **Actions halted — resume** on the Policy page.

The kill switch is per workspace, survives restarts, and is checked first on every execution path. If Hive cannot read the switch it assumes it is on — it fails closed.

<Warning>
  Only Owners and Admins can engage or release the kill switch. Tell your team where it is before you need it.
</Warning>

## The autonomy ladder

Every type of action sits on a rung of the **safety ladder** (shown as **Per-action autonomy · the safety ladder**). Actions start low and move up only when you allow it.

| Rung | What Hive does |
| - | - |
| **Shadow** | Simulates the action and records what it would have done. Nothing is sent. |
| **Suggest** | Proposes the action for a person to approve. |
| **Approve each** | Proposes, and every instance needs an explicit approval. |
| **Auto in limits** | Runs automatically, but only within every cap below. |
| **Autonomous** | Runs automatically within the workspace's hard ceilings. |

Even on the top rungs, a small set of overrides always sends an action to a person:

* anything at **B4** (money, legal or irreversible);
* anything Hive classifies as **irreversible**;
* **B3** actions below the high-confidence threshold.

Changing a rung requires an Admin or Owner. See [Autonomy and blast radius](/approvals/autonomy-and-blast-radius) for the full decision logic and how autonomy is earned.

## Blast radius

The **Blast radius** section explains the five tiers Hive assigns to every action, from **B0** (invisible or reversible) to **B4** (money, legal or irreversible). The tier decides both how much autonomy is allowed and who may approve. See [Roles and permissions](/admin/roles-and-permissions#approval-tiers).

## Money guardrails

**Money guardrails · hard ceilings** caps what Hive may spend without a person, whatever the rung.

| Cap | Default | What it limits |
| - | - | - |
| **Per-action cap** | £5,000 | The largest single automatic money action. Anything larger needs approval. |
| **Daily cap** | £25,000 | The total of automatic money actions in the window. |

The per-action cap can never exceed the daily cap. Both are set by Owners and Admins.

## Circuit breakers

Behind the ladder, Hive runs circuit breakers that trip on their own:

| Breaker | Default | Effect when tripped |
| - | - | - |
| Automatic actions per hour | 1,000 | Further automatic actions wait for approval. |
| Spend in the window | Daily cap | Further money actions wait for approval. |
| Error budget per action type | Per type | The action type drops one rung until errors clear. |
| Credit budget | Your plan | Further automatic actions wait for approval when the budget is exhausted. |

Automatic execution also requires confidence of at least 0.70, and the action's tier must be at or below the workspace's tier threshold (B3 by default).

## Approvals by role

When a proposal needs a person, it appears in [Signals](/signals/overview) (or inline in Ask, if you asked for it there). Who can approve depends on the tier:

| Role | Highest tier it can approve |
| - | - |
| Owner, Admin | B4 |
| Department lead | B3 |
| Operator | B2 |
| Analyst | Cannot approve |

Approvals are bound to the exact parameters that were reviewed and expire after 7 days. If anything about the action changes, it needs a fresh approval. See [Review and approve](/approvals/review-and-approve).

## The decision matrix

The **Decision matrix** on the Policy page shows the general priors Hive starts from — confidence band against blast radius, with outcomes **Auto-run**, **Ask first**, **Escalate**, **Suggest only** and **Block**. It is a guide to how Hive reasons; the live decision for each action also applies the rung, caps and breakers above.

## Everything leaves a receipt

Every action Hive takes — automatic or approved — is written to the [Audit log](/approvals/audit-log) with the signal, plan, decision and result. Reversible actions can be undone from there.

## A sensible starting setup

<Steps>
  <Step title="Leave new action types in Shadow or Suggest">
    Watch what Hive would do for a few weeks before allowing anything to run on its own.
  </Step>

  <Step title="Lower the money caps to match your business">
    The defaults are generous. Many teams start with a per-action cap in the hundreds of pounds.
  </Step>

  <Step title="Give approval rights deliberately">
    Keep B3 and B4 approvals with leads and Admins.
  </Step>

  <Step title="Know where the kill switch is">
    Make sure at least two people can reach it.
  </Step>
</Steps>

## Related

<CardGroup cols={2}>
  <Card title="Autonomy and blast radius" icon="stairs" href="/approvals/autonomy-and-blast-radius">
    How Hive earns autonomy.
  </Card>

  <Card title="Review and approve" icon="circle-check" href="/approvals/review-and-approve">
    The approval panel step by step.
  </Card>

  <Card title="Audit log" icon="receipt" href="/approvals/audit-log">
    Receipts and undo.
  </Card>

  <Card title="Security overview" icon="lock" href="/security/overview">
    The controls behind the controls.
  </Card>
</CardGroup>
