Let agents read the whole network. Change nothing without an engineer.

In an incident an agent can read every alarm and find the cause in seconds. TraceMem lets it, holds any change to a live system for the engineer on call, makes the change itself so the agent never holds a credential, and keeps the record your incident report starts from.

Or call us on +1 650 550 1418

Northern ring

NorthgateMill RoadRiversideSouthfieldWestburyHarbourHeld for Nadia Kerr

Reroute proposed via Harbour and Westbury

Incident recordnoc-agent
  1. Span lost between Mill Road and RiversideT+00:00

    312 alarms from five exchanges in forty seconds.

  2. Agent reads alarms, topology and open ticketsT+00:12

    Every read goes through a published capability, for the engineer on call.

  3. 312 alarms, one causeT+00:31

    A fibre cut on the Mill Road to Riverside span. Nothing else is wrong.

  4. Reroute proposed via Harbour and WestburyT+00:48

    A change to the live network, so it waits for Nadia Kerr, on call, in Microsoft Teams.

    Held for Nadia Kerr

  5. Approved by Nadia Kerr. Traffic reroutedT+02:10

    TraceMem made the change through the orchestrator. The agent never held its credential.

  6. Early warning drafted from the recordT+02:14

    What happened, what changed and who allowed it, for the national authority.

Illustrative incident. The operator, exchanges, counts, names and times are made up.


Reads where you allow them.Changes wait. Some things never happen.

Each agent holds only the capabilities someone published for it, and no credential of its own. Pick an agent to see what it can read, what it has to ask an engineer for, and what it will never do.

  • Read alarms and topologyNetwork inventoryAllowed
  • Read tickets and planned changesService managementAllowed
  • Read feeder telemetryHistorian, through its APINot granted
  • Reroute trafficNetwork orchestratorHeld for a person
  • Draft a switching scheduleWork managementNot granted
  • Issue switching instructionsControl roomNot granted
  • Submit the incident reportThe authority's reporting portalNot granted
  • Update protection relay firmwareSubstation equipmentNever automated

Credentials held by noc-agent: none. TraceMem makes every call through the capability, so there is no key to leak.

Illustrative capabilities. Yours are the ones you publish.

Governed Data Access

The reporting clocks are already running.

Some of these already apply and some are still coming. Most of them ask for an incident report within hours, naming what changed and who allowed it, and only a record kept at the time can answer that fast.

  1. 20 May 2024 · US

    EPA water enforcement alert

    Over 70% of the water systems EPA inspected were not fully compliant, with default passwords and shared single logins among the weaknesses.

    Source (opens in a new tab)
  2. 17 Oct 2024 · EU

    NIS2 transposition deadline

    An early warning within 24 hours, a notification within 72, and management bodies answerable for cyber risk, supply chain included.

    Source (opens in a new tab)
  3. 6 Aug 2025 · UK

    NCSC Cyber Assessment Framework 4.0

    New sections on threat understanding and secure software development, stronger monitoring and threat hunting, and AI-related risk considered across it.

    Source (opens in a new tab)
  4. 3 Dec 2025 · Global

    Principles for AI in operational technology

    CISA, Australia's ACSC and partners: understand the AI, assess its use in OT, govern it, and keep humans in oversight.

    Source (opens in a new tab)
  5. 6 Dec 2025 · EU

    Germany's NIS2 law in force

    The NIS2 implementation act took effect the day after publication, with no transition period.

    Source (opens in a new tab)
  6. 1 Apr 2026 · US

    NERC CIP-003-9

    Low-impact grid assets must control vendor remote access: know it exists, be able to cut it, and detect malicious traffic.

    Source (opens in a new tab)
  7. 13 May 2026 · UK

    Ofgem guidance on AI in energy

    The second version of Ofgem's good-practice guidance adds explainability in grid management.

    Source (opens in a new tab)
  8. 8 Jul 2026 · EU

    NIS2 cases referred to the Court

    The Commission took four member states to the Court of Justice for failing to transpose NIS2, asking for penalties.

    Source (opens in a new tab)
  9. 14 Jul 2026 · UK

    Telecoms security code updated

    New measures for network automation, machine learning among it, and for privileged access workstations.

    Source (opens in a new tab)
  10. 17 Jul 2026 · EU

    Critical entities identified

    Member states name their critical entities under the CER Directive, whose resilience duties start ten months after they are told.

    Source (opens in a new tab)
  11. 11 Sep 2026 · EU

    Cyber Resilience Act reporting

    Manufacturers report actively exploited vulnerabilities and severe incidents: an early warning in 24 hours, a notification in 72.

    Source (opens in a new tab)
  12. 26 Oct 2026, scheduled · UK

    Cyber Security and Resilience Bill

    The bill reforming the UK's NIS regime reaches report stage in the Lords. It is not yet law.

    Source (opens in a new tab)
  13. 2 Dec 2027 · EU

    High-risk AI in critical infrastructure

    AI used as a safety component in running digital infrastructure, or the supply of water, gas, heating and electricity, takes on human oversight and logging duties.

    Source (opens in a new tab)

Dates checked against each regulator’s own publication, September 2026. Not legal advice.


Changes, credentials and automation are already on the record.

None of these involved an AI agent. Each is a regulator's or a national CERT's finding, and each came down to a change nobody reviewed, a credential that opened too much, or automation nobody had planned around.

AT&T

22 Feb 2024 · FCC report, 2024

92 million+ calls blocked

FCC report (opens in a new tab)

A misconfigured network element took the mobile network down, with full service restored only after at least 12 hours. More than 25,000 calls to 911 were blocked.

What it came down to

A change to the core network with no peer review, inadequate testing and too few controls on changes.

For an agent, with TraceMem

Every change an agent proposes to a live system waits for an engineer with change authority, and is on the record before it is reported done.

Policy and Exceptions

Polish energy sector

29 Dec 2025 · CERT Polska report, 2026

No MFA at any affected site

CERT Polska (opens in a new tab)

Attackers reached wind and solar sites through internet-facing VPNs, damaged controller firmware and ran a wiper. Generation was not interrupted.

What it came down to

Internet-facing VPNs that accepted logins without multi-factor authentication, and devices left on default credentials.

For an agent, with TraceMem

Agents hold no credentials of their own. TraceMem makes every call, for an engineer verified by your own directory.

Governed Data Access

Hornsea One, RWE and two UK Power Networks companies

9 Aug 2019 · Ofgem report, 2020

£10.5 million paid

Ofgem report (opens in a new tab)

After a lightning strike, offshore turbine controllers reacted incorrectly and an automated control system shut down a unit at a gas-fired station. 1.15 million customers lost power.

What it came down to

Automated control behaviour that had been flagged in modelling but never discussed with the system operator.

For an agent, with TraceMem

What every automated action did, under which rule and for whom, is on one record your engineers and your regulator can both read.

Decision Trace

Colonial Pipeline

2021 · PHMSA consent order, 2023

$948,400

PHMSA case (opens in a new tab)

After the ransomware attack, the regulator found the operator had not planned well enough for shutting down and restarting the pipeline by hand.

What it came down to

No adequate plan for running operations manually when the systems were down.

For an agent, with TraceMem

TraceMem fails closed: if it cannot be reached, agents stop and your people carry on, so the manual plan you already have is the plan.

Policy and Exceptions

Every month you wait, agents touch live systems nobody can account for.

Put in your own numbers. What your agents read and changed before a governed path is in place can never be recorded afterwards.

100
6 months

21 working days a month. Your numbers stay in your browser.

In 6 months of waiting

100,800

Agent actions with no record of which engineer they worked for, what they changed or who allowed it.

Next 18 monthsNo recordOn file

Put the first incident on the record this month.

Pick whichever is quickest for you. However you get in touch, a person replies. With our forward-deployed engineers, TraceMem can be running inside your network in days.

What would you like?
Where are your agents working?

Pick any that apply.

When do your agents act on production systems?

Optional. A sentence is enough.

45days, free

Free for 45 days on our Docker-based trial image, inside your own network. When you are ready, it upgrades to the full enterprise product.

Forward-deployed engineers, ours or our partners', can set it up in days and help you define policies and integrations. This may be charged separately.