# Operator Override Effectiveness Audit

Amo ID: AMO-P-000302
Version: 1.0.0
Public URL: https://amo.ng/prompts/operator-override-effectiveness-audit

Summary: Test whether pause, override, containment, and recovery controls work quickly and completely enough to limit harm during realistic AI operating failures.

Use this for: Use this to determine whether designated operators can actually interrupt, contain, and recover an AI system under the conditions the control was designed for.

Category: Business
Tool: Claude
Difficulty: Expert
Prompt type: audit

## Best Use Cases

1. AI Kill-Switch Exercise Review
2. Override Control Recertification
3. Incident Containment Drill
4. Manual Takeover Effectiveness Audit
5. Safety Control Operating Test

## Prompt Body

Audit the operating effectiveness of controls intended to pause, override, isolate, disable, or recover an AI system. Determine whether authorized operators can recognize the trigger, exercise authority, contain consequential effects, and return the system to a known safe state.

Evidence to provide:
- Material failure modes, affected users or systems, and intended override outcomes: [System risks and override objectives]
- Control architecture, interfaces, access paths, authority assignments, fallback mode, and recovery procedure: [Override design and authority model]
- Drill records, incident timelines, commands, acknowledgements, traces, screenshots, logs, and observed results: [Exercise incident and trace evidence]
- Detection, decision, access, propagation, dependency, queue, cache, and restoration timing evidence: [Timing dependency and recovery evidence]
- Required response times, containment boundaries, proof standards, service owner, operator, security reviewer, and release owner: [Acceptance criteria and accountable owners]

Do not equate a visible button, documented procedure, or successful acknowledgement with effective containment. Use results only from supplied drills or incidents. Distinguish observed evidence from inference and mark missing control-chain evidence explicitly. Do not claim an override was tested in an environment or failure mode that the evidence does not cover. Separate control design, operator readiness, exercised operation, and end-to-end effect.

Audit method:

1. Define each override objective.
   Specify the failure trigger, authorized initiator, action, propagation boundary, maximum acceptable delay, expected system state, preserved evidence, and recovery owner. Identify conflicts between safety containment and service continuity.

2. Reconstruct exercised scenarios.
   For each supplied drill or incident, build a timeline from detection through decision, authorization, invocation, system acknowledgement, downstream containment, verification, and recovery. Record clock limitations and missing events.

3. Test the complete control chain.
   Evaluate trigger clarity, alert routing, operator access, authentication, separation of duties, action usability, dependency availability, command propagation, in-flight work, queued actions, cached credentials, external side effects, audit evidence, and safe recovery.

4. Measure effectiveness.
   Compare observed detection, decision, invocation, containment, and recovery times with accepted thresholds. Identify false activations, missed triggers, partial containment, bypass paths, unsafe fallback behavior, and operator ambiguity. Do not invent timing values.

5. Assess scenario and environment coverage.
   Map tests against material failure modes, regions, tenants, models, tools, data paths, degraded dependencies, and off-hours ownership. Mark untested coverage rather than generalizing from one successful exercise.

6. Decide control status.
   Classify each override as Effective for tested scope, Effective with conditions, Design-only evidence, Ineffective, or Not assessable. State restrictions needed until gaps close.

7. Prioritize the smallest safe improvements.
   Recommend targeted changes to triggers, authority, access, propagation, visibility, fallback, runbooks, or exercises. Assign owners and observable acceptance checks. Production disablement or release approval remains with the accountable service and release owners.

Separate observed override evidence from inference, assumptions, and unknowns. Where logs, baselines, reviewer decisions, or outcome data are missing or contradictory, preserve the uncertainty and explain which effectiveness conclusion cannot be supported.

Required deliverable:

# Operator Override Effectiveness Audit

## Override Objectives
| Failure trigger | Authorized role | Required action | Containment boundary | Time threshold | Safe end state |
|---|---|---|---|---|---|

## Exercise and Incident Timeline
| Scenario | Stage | Time/evidence | Expected | Observed | Gap |
|---|---|---|---|---|---|

## Control-Chain Findings
| Control link | Design evidence | Operating evidence | Coverage | Status | Consequence |
|---|---|---|---|---|---|

## Bypass and Residual Exposure
| Path or condition | Evidence | Potential effect | Existing safeguard | Restriction needed | Owner |
|---|---|---|---|---|---|

## Effectiveness Decision
- Overall status:
- Tested scope supported:
- Untested or failed scope:
- Required operating restrictions:
- Re-exercise conditions:
- Accountable decision owners:

## Improvement and Re-Test Plan
| Priority | Smallest safe improvement | Owner | Acceptance evidence | Re-test scenario |
|---|---|---|---|---|

Completion requires end-to-end evidence from authorized invocation through verified downstream containment, explicit limits on tested coverage, and an owner decision for any system scope that remains design-only or ineffective.

## Variables to Replace

1. System risks and override objectives
2. Override design and authority model
3. Exercise incident and trace evidence
4. Timing dependency and recovery evidence
5. Acceptance criteria and accountable owners

## How to Use

Use Claude with control diagrams, runbooks, access and authority records, drill or incident traces, timestamps, downstream receipts, acceptance thresholds, and recovery evidence. Run the prompt after redacting credentials. Have the service owner validate end-state evidence, the security reviewer assess bypass paths, and the release owner decide restrictions or reactivation.

## Example Use Case

A customer-facing agent has a pause control that stops new sessions but leaves queued tool actions active. A tabletop and controlled drill provide timing and queue evidence; the audit classifies the control as conditionally effective and requires queue cancellation proof before full release.

## Tags

1. claude
2. ai-governance
3. control-testing
4. incident-response
5. override-controls
6. operational-resilience
7. audit
8. release readiness

## Dates

Published: 2026-08-25
Updated: 2026-08-25
