Skip to content

Answers

How do I stop all my AI agents at once?

Freeze them where every request they make is decided. A stopped agent in Immiscible is refused on every path it enforces, its actions, model calls, proxied tool calls and card authorisations, and only a person can start it again.

Freeze the agents at the point every request they make is decided, so one switch stops their actions and their model traffic together. In Immiscible a stopped agent is refused from that moment on every path Immiscible enforces, before anything goes upstream, and requests waiting for approval can no longer be approved.

#What exactly stops?

PathA stopped agent gets
Action requests, and the MCP server at /mcpa deny decision (agent_frozen)
Model calls through the gateway, OpenAI and Anthropic shapes, and Anthropic token counts403 agent_stopped; nothing reaches the provider
Tool calls and tool listing through the MCP proxy, to MCP servers and plain HTTP APIs403, JSON-RPC error -32003, agent_stopped; nothing reaches the tool
Card authorisationsdeclined
Its receipts and OAuth connectionsrevoked

The error names the hold and who may lift it, and every refusal is on the evidence ledger. A restart works on the next request, with nothing to restart. The kill switch guide has the detail.

#What about keys that are not an agent’s?

Stopping one agent leaves a person’s gateway key alone. Stop every agent (a fleet freeze of all) refuses model calls on every key in the workspace too, a person’s, a service’s and an admin’s, because the gateway cannot tell a coding agent on a person’s key from the person. It stands until the stop is lifted.

#How do I stop one agent?

In the console, Agents, Freeze, or the link in any approval, or from Slack with /immiscible freeze <agent> <reason>. Name a kill owner for every agent that matters: the person who may always stop it, whatever their role.

#How do I stop a whole fleet?

With a selector (all, agentIds, principalId, vendor, tier or upstreamId), looking first:

Shell
curl -X POST "https://immiscible.fly.dev/v1/admin/freeze" \
  -H "authorization: Bearer $IMMISCIBLE_SERVICE_TOKEN" -H "content-type: application/json" \
  -d '{ "selector": { "all": true }, "dryRun": true }'
# then the same with "reason", "hold" and "confirmCount" set to the count it returned

A SOAR playbook can do the same with a service token, and your identity provider can trigger a freeze through Shared Signals when the person an agent acts for is disabled. See the kill switch.

#Who can start it again?

Only a person, in the console, with a reason. Nothing an agent key can do unfreezes an agent. Every freeze and lift, with who and why, is in the agent’s history and the evidence ledger.

#What does it not do?

  • It stops what passes through Immiscible. An agent with a direct credential to a tool, a card or a provider keeps that route; take direct credentials away.
  • Machines have hourly freeze ceilings, so a looping playbook cannot stop the whole company; a freeze past the ceiling waits for a person.