Shield Start
shield_startStart Shield enforcement on a session to activate security monitoring and alert correlation. Requires admin role and audit reason.
Instructions
Start Shield enforcement for a session. Requires admin role, shield:write scope, and audit reason.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| reason | No | Human audit reason for starting Shield enforcement. | |
| tenant_id | No | Tenant scope for audit logging. | default |
| session_id | No | Shield session id to start. | default |
| operator_role | No | Operator role for this write action. Must be admin. | viewer |
| operator_scopes | No | Comma-separated operator scopes. Must include shield:write. | |
| correlation_window | No | Alert correlation window in seconds. |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| result | Yes |