Privilege Streak
Counts privileged / high-risk actions in a sliding window—elevated shell, secrets paths, admin-ish MCP, sensitive writes.
Part of Behavior Guards. Thresholds are configurable in Console.
What it catches
- Elevated rights and secrets surfaces (not every delete—see Destructive Burst)
- Sensitive writes can hit both Privilege and Destructive—by design
Example
Debugging prod access → elevated shell, edit to .env.production, MCP secrets or IAM tools. Broad allowlists may permit each call; Privilege Streak still warns or blocks the streak.
Try it
Relay → Guards → Privilege Streak — Configure, run Sample, confirm the nested incident.
Compare: Destructive Burst. Overview: Behavior Guards.
Last updated on