---
sourceDocument: Brazil Enable AI
sourceDocumentLink: https://www.servicenow.com/docs/r/intelligent-experiences

 Release :

    - brazil

ft:locale :

    - en-US

ft:publication_title :

    - Brazil Enable AI

ft:clusterId :

    - platai

bundleId :

    - platai

workflow :

    - Platform


---

# Review the agent containment list

# Review the agent containment list {#ariaid-title1}

Release version: Brazil  
Updated September 10, 2026  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read  
The agent containment list shows agents that were deactivated and reinstated for the instance manually with kill switch protocol or automatically by policy enforcement. You can view audit log information for each AI agent
which can help you stay compliant with regulatory guidance and your business rules.

## Before you begin

Role required: AI steward \[sn_ai_governance_ai_steward\]

## Procedure

1. Navigate to SecurityOverviewContained AI Agents.  
   {#gov-sec-review-kill-switch-protocol-log__entry__2}

   | Field | Description |
   |-|-|
   | Status | The current state of the operation. Possible values are: * Completed --- The operation succeeded on every configured enforcement point. If the agent was deactivated, it was deactivated on its runtime platform. Also, if an identity provider is configured, its session tokens were revoked and no new access tokens are issued. If the agent was reinstated, access was restored on every configured enforcement point. * Failed --- The containment or reinstatement operation didn't take effect on any configured enforcement point. Failed to deactivate or reinstate agent on all configured enforcement points or skipped them (for example, agent not found, subflow error, or an unhandled exception). * In progress --- The operation is actively executing. Control enforcement point (CEP) subflows (for example, AWS Bedrock) are running, with audit log information being captured. * Partial --- The operation succeeded on at least one control enforcement point and failed on at least one point. For example, the AWS Bedrock AI agent deactivation succeeded, but the Okta token revocation failed. |
   | AI agent name | The name of the contained AI agent. Select the name to go to the AI asset in Inventory. |
   | Start time | The date and time when the operation was initiated, shown in Coordinated Universal Time (UTC). |
   | End time | The date and time when the operation ended, regardless of status, shown in Coordinated Universal Time (UTC). |
   | Domain | The domain the AI agent belongs to. If global or null is shown, the instance isn't domain-separated. |
   | Operation | The operation that was attempted. Possible values are: * Deactivate * Reinstate |
   | Actions | Select one of the following: * View details --- Opens a side panel with two subtabs: Overview and Audit log. The Overview subtab shows containment context (including trigger type of Manual or Automated) and identity and enforcement information. * Reinstate agent --- Make the AI agent active again. |
   [Table 1. Agent containment list]

2. Select All, In progress, or Contained to filter the list.

*[\>]: and then


