Documentation
Rollback
Every configuration change keeps a copy first; undo is one click.
The path every change takes
- A copy of each file is written to /var/lib/securityemployee/snapshots/<change id>/ with a manifest (path, hash before and after, owner, mode, size).
- The change is applied.
- The configuration is validated before any reload.
- The service is reloaded.
- The service and SecAI's own control channel are verified.
- A failure at any step restores the copy, reloads again if something was reloaded, and reports what happened.
Undo
Every applied change has an Undo in the dashboard by its own id. Undo refuses if the file has changed since SecAI wrote it. Copies stay on your server and are uploaded nowhere; they are pruned by age and count in step with the platform's record.
After a rollback
That kind of change on that server goes back to waiting for approval. Three rollbacks across your servers within an hour switch on safe mode for the organisation and email you what was attempted and what broke.
Agent updates
A failed update is rolled back to the previous binary kept at /usr/local/bin/security-agent.prev.
Reviewed against the implementation on 2026-09-20. Something wrong? Tell us.