Automatic mode
Adds exactly one thing: blocking attacking addresses without asking.
What it means
On a server set to Automatic, an address identified as attacking is blocked without asking. That is the only action Automatic mode adds. The list of actions that may run unattended is a single entry in the platform's code, and widening it is a release decision, not a setting.
Still waits for a person
- Hardening fixes to service configuration
- Package updates
- Service restarts
- Enabling or disabling an account
- Quarantining a suspected web shell
Choosing it
Onboarding recommends Automatic and preselects nothing; you choose per server and can change it at any time from the server page. A request that omits the mode gets Awaiting Approval.
Above the mode
A pause stops all automation while undo actions keep working. Safe mode, which the platform switches on by itself after three rollbacks across your servers within an hour, rejects everything except undo actions until a person turns it off. Controls resolve from server, to organisation, to category, to global.
Reviewed against the implementation on 2026-09-20. Something wrong? Tell us.