Security automation that touches every build is production infrastructure. Production infrastructure needs an emergency brake. The teams that skip this lesson learn it during an incident: a scanner outage or a bad configuration starts failing every pipeline in the organization, and the only remediation is editing hundreds of definitions at panic speed.
Why blast radius is the price of enforcement
The same property that makes organization-wide injection powerful — one configuration, every build — makes misconfiguration expensive. You cannot have default coverage without accepting that the control itself becomes critical-path. The answer is not less enforcement; it is operational controls sized to the blast radius.
What a real kill switch looks like
- One switch, effective estate-wide, that disables the injected behavior without uninstalling anything.
- Authorized through the control plane — not by whoever can edit an extension setting fastest.
- Audited: who flipped it, when, and when it was restored.
- Granular fallbacks beneath it: per-pipeline disable for isolated issues, so the global switch is reserved for genuine emergencies.
In Kangl
Kangl exposes the Pipeline Security Runtime global kill switch as a first-class, backend-authorized control, alongside per-pipeline enable/disable and bulk operations. Flipping it is one audited action; restoring it is another; and drift detection confirms the estate actually followed. The emergency path is designed, not improvised.

