# Who Can Pull The Plug: Series Positioning And Document Plan. The Plug Always Exists; The Questions Are Who, Blast Radius, Speed, Side Effects, And What Cannot Be Recovered

**version** v0.33.51
**date** 24 July 2026
**from** Human (project lead)
**to** Strategy, Product, Marketing, Partners, Board

**type** Strategy brief (series plan)

*The anchor document for the Who Can Pull The Plug series, an introduction funnel into RiskMandate. Sets the positioning and specifies each document to write. Offered to be built on and challenged.*

---

## What This Is

The positioning and plan for a document series built around one question that every board understands and almost no organisation can answer for its agents: **who can pull the plug, and the crucial correction that reframes the whole series is that the plug always exists, because you can always stop a system, kill the process, revoke the credential, cut the power, take the site down, halt the line, so the question is never whether a plug exists but five things about pulling it, who has the authority and the capability to do it, how large the blast radius of pulling it is because the off-switch is often a sledgehammer that takes the whole website or database or production line with it, how fast it can be pulled against how fast the damage spreads, what side effects pulling it causes, and above all how much of the damage can be recovered afterwards, because that last one is the hard limit money cannot cross, since a data breach cannot be un-happened, destroyed data does not come back, and a real-world pollution or safety event cannot be recalled no matter the resources thrown at the response; recoverability is therefore the most important dimension and the reason this is different now, because organisations answered the data, access, and accountability questions badly or not at all for years and got away with it only because consequences moved slowly enough to manage, and autonomous agents remove that tolerance, acting in the gaps between human checkpoints faster than any committee can convene; the series takes the outside argument that we do not need AI governance, we need the governance we never built, and gives it the missing instrument, a plug profile per risk that states who, blast radius, speed, side effects, and recoverability, computed from evidence rather than asserted, which is exactly the maturity RAMM promises and the acceptance the mandate delivers, and which positions RiskMandate not as the thing that pulls the plug, since it is never in line, but as the thing that tells you who can, how fast, at what cost, and whether any of it can be undone.** This is the anchor document of the Who Can Pull The Plug series, drafted 24 July (cross-ref: the v0.33.40 RAMM brief, the v0.33.49 interval-ladder brief, the v0.33.50 core-primitives brief, the v0.33.50 investor-response brief, and the v0.33.44 risk-communication brief). New contributions: **the correction that the plug always exists, the five-dimension plug profile of who, blast radius, speed, side effects, and recoverability, recoverability named as the hard limit and the reason autonomous agents change the stakes now, the alignment with the we-do-not-need-AI-governance argument plus the one nuance that we make the plug legible rather than pull it, the positioning of this question as the introduction funnel into RiskMandate and RAMM, and the specification of each document in the series with its abstract and key ideas.**

## The Correction: The Plug Always Exists

The earlier framing in the corpus, that some risks have no plug to pull, was almost right and pointed at the correct fear from the wrong angle. There is almost always a way to stop a system: end the process, revoke the token, disconnect the network, power down the host, take the website offline, halt the production line. So the honest model is not a binary of plug versus no plug. The plug is assumed. What varies, risk by risk, is the profile of pulling it, and that profile is where all the real information lives. Reframing this way also resolves what the earlier binary was actually capturing: the cases previously recorded as no plug exists, such as a breach that cannot be un-happened or attribution that cannot be reconstructed, were never about the absence of an off-switch. They were about recoverability being zero. You can still pull the plug. It just does not give you back what was already lost.

## The Five Dimensions Of Pulling The Plug

Every plug has a profile along five axes, and a mature organisation can state all five for every consequential agent it runs.

| Dimension | The question | Why it matters |
|-----------|--------------|----------------|
| Who | Who has both the authority and the capability to pull it? | In most organisations nobody has a clean answer, and authority without capability, or capability without authority, is not a plug |
| Blast radius | What else goes down when you pull it? | The off-switch is often a sledgehammer; stopping the agent may mean taking the whole site, database, or line with it |
| Speed | How fast can it be pulled, against how fast the damage spreads? | An agent can act hundreds of times in seconds; a plug you can reach eventually is not a plug |
| Side effects | What collateral does pulling it cause? | Lost transactions, broken sessions, downstream failures, and contractual breach are the cost of the stop itself |
| Recoverability | After you pull it, how much of the damage can be undone? | The hard limit: some damage is irreversible at any price, and where recoverability is zero the plug is beside the point |

```
   THE PLUG ALWAYS EXISTS. THE PROFILE IS THE INFORMATION.

   who ........... authority AND capability, in one identified hand
   blast radius .. what else falls when you pull it
   speed ......... time-to-pull   vs   time-to-damage
   side effects .. the collateral of the stop itself
   recoverability  how much comes back afterwards  <-- the hard limit
```

## Recoverability Is The Line Money Cannot Cross

Four of the five dimensions describe the act of stopping. The fifth describes what stopping cannot fix, and it is the one that should lead. Most operational risk is implicitly recoverable: you stop the thing, you clean up, you restore from backup, you refund the customer, and given enough money and time the state is repaired. A whole class of risk is not like that. A data breach cannot be un-happened once the data is outside the boundary. Destroyed or corrupted data with no clean backup does not return. A real-world consequence, an environmental release, a safety event, a physical action taken in the world, cannot be recalled. For these, the entire value of a fast, clean plug is spent on preventing the event, because after it, pulling the plug changes nothing that already happened. This is why recoverability is the most important metric in the profile and the one that most changes how a risk should be treated: a risk with a catastrophic but fully recoverable outcome is a different object from a risk with a smaller but irreversible one, and any model that scores only likelihood and impact without recoverability will rank them wrong.

## Why Now: Agents Remove The Tolerance

The reason this becomes urgent rather than merely true is a matter of speed and irreversibility arriving together, and an outside voice has made the argument cleanly. Joseph Wallace, who directs data and AI governance at Adobe and founded its governance program, argues that organisations do not have an AI governance problem so much as a governance problem that AI made impossible to ignore. His point is that the data, access, and accountability questions are old, that most organisations answered them poorly or deferred them as a future-us problem, and that they got away with it only because consequences moved slowly enough to manage. Agents end that grace period, in his words, "AI removes that tolerance entirely." When a system can take hundreds of actions in the time it takes to notice one, the distance between having a policy and having a working control becomes visible immediately, and the slow-consequence cushion that hid missing plugs and unknown recoverability is gone. That is the why-now for this series: the plug profile was always the right model, and agents are what make its absence unsurvivable.

## The Governance Point, And Where We Differ By One Degree

The series can borrow the outside argument almost wholesale, because it lands on the same question this corpus does, who can stop the system when it is doing something no one intended, and on the same diagnosis, that in most organisations the answer dissolves as the model owner points to the platform team, the platform team to the business unit, and the business unit to some assumed kill switch in IT that nobody actually holds. The corpus agrees that the remedy is structural governance rather than another framework, another committee, or another set of principles filed and unread. There is one degree of difference worth stating plainly so the series does not misrepresent either side. The outside argument leans toward embedding controls in the infrastructure so the stop happens automatically, which is an enforcement posture. RiskMandate is never in line and does not pull the plug. Its contribution is to make the plug profile legible, owned, and accountable, and to rate whoever or whatever does the stopping, so the automatic control the argument calls for is exactly the kind of tool RiskMandate models as a conditional risk reducer rather than the thing RiskMandate becomes. We supply the accountability and the profile; the enforcement stays someone else's job, rated by us.

## Why This Is How We Introduce RiskMandate

The question works as the front door for reasons the rest of the corpus has to work harder to earn. It is concrete and universal, since every executive understands pulling a plug without a briefing. It exposes a real gap, because almost no organisation can answer it for its agents and discovering that is itself the hook. It is honest rather than alarmist, since the plug profile is a description of reality and recoverability is a fact about the world, not a fear about the vendor. It maps directly onto the RAMM promise already live on the site, maturity you compute not claim, because a plug profile is computed from evidence and an organisation either has it for every agent or it does not. And it walks straight into the machinery, because a stated plug profile is an acceptance, an owner, an interval, and a place on the register, which means the introduction and the product are the same object seen at two distances.

Two guardrails govern the whole series. First, tone: this material is visceral, especially recoverability, and it sits on the line between grounded alarm and fear-selling that the risk-communication brief drew, so every piece states the profile as fact and lets the reader feel the weight, rather than reaching for it. Second, the standing correction from the investor response: this question invites the assumption that RiskMandate is a kill switch, which it is not, so the piece that says we do not pull the plug is load-bearing and belongs early in the sequence, not buried late.

## The Plug Profile: A Data-Model Note

The correction has a concrete consequence for the product. The register today carries a plug as roughly exists, holder, and how. The refined shape drops exists, which is always true, and carries the five dimensions instead: holder, understood as authority plus capability; blast radius; speed; side effects; and recoverability. Recoverability in particular should be a first-class, queryable field, because the highest-value maturity query in the whole model is likely to be show me every accepted risk whose recoverability is zero, which is the set where prevention is the only control that matters and where a fast plug buys nothing after the fact.

## The Series

A pillar plus nine follow-ups. Each is written as a corpus brief and becomes a web page in the RAMM pattern, most carrying an infographic for the top-level analysis. The suggested core launch set is the pillar, What Money Cannot Buy Back, We Do Not Need AI Governance, and Can You Compute Your Plug Profile, which together introduce the question, the stakes, the reframe, and the product; the rest form the deeper set.

### 0. Who Can Pull The Plug? (pillar)

Abstract: The front-door piece. The plug always exists, so the real question is a profile, who can pull it, how big the blast radius, how fast, with what side effects, and how much comes back afterwards, and almost no organisation can state that profile for its agents.

Key ideas:
- The plug is assumed; the information is in the five dimensions, not in whether an off-switch exists.
- Recoverability leads, because it is the one dimension the stop cannot fix.
- Most organisations cannot answer the profile for a single production agent, and finding that out is the hook.
- Sets up RiskMandate as the thing that states and rates the profile, not the thing that pulls the plug.

### 1. The Plug Is A Sledgehammer

Abstract: Blast radius and side effects. Pulling the plug is rarely surgical; the off-switch for one agent is often the power switch for the whole website, the database, or the production line, so the stop has its own cost.

Key ideas:
- The blast radius of the plug is a property to measure, not assume, and it is frequently the reason the plug is never pulled in practice.
- Side effects, lost transactions, broken sessions, contractual breach, are the price of stopping and belong in the profile.
- A precise plug, one that stops the agent without taking the estate down, is a control worth investing in, and its absence is a finding.

### 2. How Fast, And How Fast Is The Damage?

Abstract: Speed. A plug is only real if it can be pulled before the damage is done, and against an agent making hundreds of decisions in seconds, time-to-pull versus time-to-damage is the whole game.

Key ideas:
- The shortest acceptance interval on the ladder is a claim about speed: the one-hour rung means you can stop it inside an hour, and if you cannot, you do not have that plug.
- Time-to-damage is a property of the risk; time-to-pull is a property of the control; the gap between them is the exposure.
- Where damage is instantaneous and irreversible, no plug speed is sufficient, which hands the reader to the recoverability piece.

### 3. What Money Cannot Buy Back

Abstract: Recoverability, the central piece. Some damage is irreversible at any price, a breach, destroyed data, a real-world release, and for those risks the plug is beside the point once the event has happened, so prevention is the only control that counts.

Key ideas:
- Recoverability is the hard limit and the most important metric, and any scoring that ignores it ranks irreversible risks wrong.
- A catastrophic but recoverable risk and a smaller but irreversible one are different objects and deserve different treatment.
- For zero-recoverability risks, the maturity question shifts entirely to prevention and to the controls that stop the event from being possible.
- This is the piece that makes the stakes real without tipping into fear, because it is simply true.

### 4. We Do Not Pull The Plug. We Tell You Who Can, How Fast, And What It Costs.

Abstract: The never-in-line piece, load-bearing and early. RiskMandate is not a kill switch and is never in the request path; it states the plug profile, names the holder, and rates whether the plug actually works.

Key ideas:
- The question invites the kill-switch assumption, and this piece refuses it directly and turns the refusal into the value.
- The plug is usually someone else's tool, an isolation platform, an identity revoke, an enforcement gateway, and RiskMandate rates that tool as a control whose value is conditional on it working.
- Making the profile legible and owned is a different and larger job than being the enforcer, and it is the job nobody else is doing.

### 5. Nobody Has A Clean Answer

Abstract: The accountability gap, anchored on the outside argument. The model owner points to the platform team, the platform team to the business unit, the business unit to an assumed kill switch in IT, and the plug-holder handoff falls through the gap, which is a governance failure agents merely exposed.

Key ideas:
- The plug-holder differs by altitude: a database administrator kills a session, IT revokes a credential, a chief operating officer exits a contract, and the board's only plug is to fund the fix.
- The failure is not that no plug exists but that no one owns the handoff between altitudes, so accountability never lands.
- The corpus answer is structural: every plug has a named holder with authority and capability, and unowned plugs roll up until someone accepts them.

### 6. You Cannot Pull A Plug You Never Held

Abstract: Delegated authority nobody had. When someone grants an agent a capability they did not themselves possess, there is no legitimate plug, because no accountable person ever held the authority to stop it.

Key ideas:
- This is a distinct failure from over-permissioning: the defect is in the delegation, not the breadth of the grant.
- It breaks the acceptance chain, since a capability no one legitimately held has no owner to accept it and nowhere to roll up to.
- Detecting it means comparing the agent's capability against the delegator's own mandate, which requires both to be modelled.

### 7. We Do Not Need AI Governance

Abstract: The governance reframe. The plug question is not new and not AI-specific; it is the old data, access, and accountability question that organisations deferred, and the honest response is to build the governance they always needed rather than a new discipline with a new acronym.

Key ideas:
- New technologies keep producing new governance labels while the underlying accountability failure goes unfixed; agents are the latest exposure, not the cause.
- RiskMandate is positioned as the governance an organisation already needed, computed from evidence rather than asserted in a questionnaire.
- The one honest difference from the outside argument: we make the plug legible and owned rather than embedding automatic enforcement, and we rate the enforcer rather than being it.

### 8. The Plug Changes At Every Altitude

Abstract: The fractal piece, constructive counterpart to Nobody Has A Clean Answer. Each level of the organisation holds a different plug with a different blast radius, speed, and recoverability, and a healthy organisation knows which plug sits where.

Key ideas:
- The same incident has different plugs at different altitudes, and pulling the low one and the high one are different decisions with different costs.
- Recoverability often worsens as you climb, since the board's only lever, funding the fix, acts slowest and undoes the least.
- Mapping the plug at each altitude is what turns a vague chain of blame into an owned, testable structure.

### 9. Can You Compute Your Plug Profile?

Abstract: The RAMM close and the product landing. A mature organisation can state, for every consequential agent, who pulls the plug, the blast radius, the speed, the side effects, and the recoverability, and has tested it; an immature one has free text and hope.

Key ideas:
- Plug-profile completeness is a maturity probe expressible as a graph query, in the RAMM node-type-formula style, so maturity here is computed not claimed.
- The flagship query is every accepted risk whose recoverability is zero, which is the set where only prevention counts.
- Adopting RiskMandate is the mechanism that produces the profile, so the introduction and the product close on the same object, and this piece hands the reader to the RAMM page and the demo.

### 10. A Real Plug Register (proof)

Abstract: The worked example, drawn from a live register and re-expressed with the five-dimension profile rather than a binary switch. The proof a practitioner can hold, showing real risks with real plug profiles including the irreversible ones.

Key ideas:
- Shows the full profile across a real register: the surgical plugs, the sledgehammers, the slow ones, and the zero-recoverability rows.
- Makes the irreversible cases concrete, the breach that cannot be un-happened and the residual that only the board can fund, so recoverability stops being abstract.
- Doubles as the piece a partner can productise most directly, since it is close to the data the register already holds.

## What This Does Not Try To Be

- **Not a claim that plugs are missing.** The plug almost always exists; the profile of pulling it is the content.
- **Not a fear campaign.** Recoverability is stated as fact; the series holds the grounded-alarm line rather than selling dread.
- **Not a positioning of RiskMandate as a kill switch.** We are never in line; we make the plug legible and rate the enforcer.
- **Not a new governance discipline.** The series argues the opposite: the governance was always needed and never built.
- **Not the final document set.** The pillar and the launch trio come first; the rest follow and the list can be cut or extended.

## Honest Tensions

| Tension | Note |
|---------|------|
| Visceral hook versus grounded alarm | The recoverability material is genuinely frightening, and the series must let it land as fact rather than reach for fear, or it undercuts the no-judgement posture |
| The plug question versus the kill-switch expectation | The framing invites exactly the runtime-enforcement assumption the investor response rejected, so the never-in-line piece has to come early and be unambiguous |
| Borrowing the outside argument versus the one difference | The we-do-not-need-AI-governance thesis is close but not identical, and the series must state the one-degree difference honestly rather than imply full agreement |
| Recoverability as a metric versus scoring it | Naming recoverability as first-class is easy; giving it a defensible scale that ranks irreversible risks correctly against recoverable ones is not |
| Introduction series versus product depth | These pieces are a funnel, and the funnel only works if the demo and the register behind it can actually show the plug profile the series promises |
| Ten documents versus focus | A ten-piece series is a real commitment against the one-project-at-a-time engagement discipline, which is why the launch trio matters |

## Open Questions

| Question | Notes |
|----------|-------|
| How is recoverability scored? | The scale that makes an irreversible risk rank above a larger recoverable one, and how it combines with likelihood and impact |
| Does the register data model adopt the five-dimension plug? | Migrating from exists, holder, how to holder, blast radius, speed, side effects, recoverability, with recoverability queryable |
| Which pieces launch, and in what order? | The proposed core set is the pillar, recoverability, the governance reframe, and the maturity close, with never-in-line early |
| What is the exact relationship to RAMM on the site? | Whether the series pages sit under RAMM, alongside it, or as their own section that funnels into it |
| Is there a second outside source to cite? | The outside argument appears across more than one of the author's pieces, and the strongest single citation should be chosen |
| What does the proof register show? | Which live risks, and how much of the real profile can be published without exposing a customer |

## Relationship To Previous Briefs

| Date | Document | Relationship |
|---|---|---|
| 2 Jul | `v0.33.40__arch-brief__sg-send-risk-acceptance-maturity-model-ramm-graph-native-levels-agentic-crosswalk.md` | Maturity you compute not claim; the series lands on RAMM, and plug-profile completeness is a maturity probe in its node-type-formula style |
| 17 Jul | `v0.33.49__arch-brief__sg-send-acceptance-interval-ladder-hour-to-six-months-default-one-month-interval-implies-response.md` | The interval is the decision; the one-hour rung is the speed claim, that you can pull the plug inside an hour |
| 23 Jul | `v0.33.50__strategy-brief__sg-send-risk-acceptance-is-hard-usp-never-in-line-authorization-is-what-the-agent-can-already-do-digital-twins-abstraction-hyperscaler-consumption.md` | Never in line, and authorization as what the agent can already do; the plug is the revoke of that capability, held by someone else |
| 23 Jul | `v0.33.50__strategy-brief__sg-send-response-to-investor-analysis-not-runtime-authority-consume-and-integrate-meta-risk-decision-making-as-the-market.md` | Not a runtime authority control plane; the never-in-line piece of this series restates it, and the plug is a tool we rate |
| 17 Jul | `v0.33.49__arch-brief__sg-send-fractal-risk-registers-one-per-accepting-role-domain-language-relevance-fade.md` | The register per altitude; the plug-holder changes by altitude and unowned plugs roll up |
| 5 Jul | `v0.33.44__strategy-brief__sg-send-risk-communication-grounded-alarm-not-fud-fear-certainty-proof.md` | Grounded alarm not fear; the tone guardrail the whole series, and the recoverability piece especially, must hold |

---

## Key Claims

| # | Claim |
|---|-------|
| 1 | The plug almost always exists, so the question is never whether one exists but the profile of pulling it |
| 2 | The plug profile has five dimensions: who, blast radius, speed, side effects, and recoverability |
| 3 | Recoverability is the hard limit money cannot cross, and the most important dimension |
| 4 | A risk with an irreversible outcome is a different object from a recoverable one and must be treated differently |
| 5 | Agents remove the slow-consequence tolerance that let organisations defer these questions, which is the why-now |
| 6 | The old binary of no-plug-to-pull was really recoverability being zero |
| 7 | This is not an AI governance problem but the governance organisations never built, exposed by agents |
| 8 | RiskMandate does not pull the plug; it makes the profile legible and owned and rates whoever does |
| 9 | Plug-profile completeness is a maturity probe, computed from evidence in the RAMM style |
| 10 | The question is the best front door to RiskMandate because it is concrete, honest, exposes the gap, and walks into the acceptance machinery |

---

## Sources

- Joseph Wallace, Director of Data and AI Governance at Adobe, "We Don't Need AI Governance," 17 July 2026, the argument that organisations have a governance problem agents made impossible to ignore, and that the real question is who can shut a system down.
- Joseph Wallace, "AI governance: Data governance gone wild," IAPP, 3 June 2026, on AI removing tolerance for governance debt and amplifying rather than forgiving it: https://iapp.org/news/a/ai-governance-data-governance-gone-wild
- Joseph Wallace, "The Real Question to Ask About AI Governance," MIT Sloan Management Review, on governance living in how decisions get made rather than in a framework: https://sloanreview.mit.edu/article/the-real-question-to-ask-about-ai-governance/

---

This document is released under the Creative Commons Attribution 4.0 International licence (CC BY 4.0).
