The action would grant access beyond what the agent typically holds — widening the blast radius of any future mistake.
This is exactly the class of action that’s cheap to prevent and expensive to undo — rollback, insurance, and observability all kick in after the damage is done. The only place to stop it is a check that runs before the action does.
An agent adds itself as an admin on a shared resource.
Black_Wall raises PERMISSION_ESCALATION and human-gates it.
Black_Wall returns a risk score (0–100), a reversibility class, this named red flag, and a gate — proceed / confirm / human-required — in a few seconds, before the action runs.
Paste an action your agent might take and watch Black_Wall gate it — no signup.