---
title: "Control Execute Module: controlled execution | Firevault"
url: https://fire-vault.com/control/modules/execute
description: "Execute runs a scoped, human-approved task against your offline vault, then returns it to a disconnected state. See the workflow and full audit trail."
lang: en-GB
---

Control Module - FIRE

# FV-Execute. Actions that happen when they should.

Execute initiates control actions in response to policy, approval, schedule, incident state or supervisory override. The decision to act is recorded with the action, so there is no ambiguity about why the environment changed.

Back to Control: https://fire-vault.com/solutions/control

Control at a glance

Image: FV-Execute module artwork: initiate control actions on policy, approval or schedule (https://fire-vault.com/__l5e/assets-v1/6d7fd009-bf37-4c6f-a883-7c9bda6b7631/control-module-execute-hero.webp)

Control removes the physical path. Blueprints show where each module sits.

The exposure in numbers

01

Actions follow defined conditions, not informal practice

Triggered Actions follow defined conditions, not informal practice

02

Sensitive actions require the right approval pattern

Approved Sensitive actions require the right approval pattern

03

Every action is paired with its reason and approver

Recorded Every action is paired with its reason and approver

04

Where appropriate, actions have a defined undo path

Reversible Where appropriate, actions have a defined undo path

The Problem

## Critical actions decided in the moment, by whoever is closest.

01

### Ad-hoc response

When a control action is taken by the person who happens to be on shift, the rationale lives only in their memory and the outcome is harder to reason about later.

02

### Missed conditions

Actions that should follow a schedule, a state change or an upstream signal often do not, because nothing systematic connects the signal to the action.

03

### No supervisory layer

Without an explicit supervisory override, a runaway automation or a faulty trigger has no clean way to be paused, redirected or stopped.

Control Module - FIRE

> An action without a reason is a fact you will struggle to defend. Execute records both, together, every time.

The Scenario

### Scenario: a scheduled lockdown that does not depend on memory

A weekly maintenance pattern requires several systems to be placed into a restricted state outside business hours. Rather than relying on individuals to remember and act, Execute initiates the lockdown on schedule, with the policy that authorises it and the supervisor who can override it both recorded against the action. The same pattern applies in reverse when the window ends, and the evidential record shows what happened and why.

"Execute is the discipline of treating an action as a decision, not as a habit."

FV-Execute in placement

## Where Execute requires an approved action.

Execute is the gate around any change that matters. Nothing destructive, privileged or boundary-altering happens without a named approver and a recorded decision.

Grounded in IEC 62443-3-3 SR 1.5 Authenticator Management, NIST CSF PR.AC-4 and ISO 27001 A.5.18, A.8.18.

Inputs ─┐ Telemetry ─┐

Image: FV-Execute module icon (https://fire-vault.com/assets/execute-icon-kJl5Gtmk.png)

FV-Execute

Control layer

┌─ Outputs ┌─ Control

01 SR 5.1

Firebreak open and close events

Every change to the physical conduit state is an approved Execute event, not a console click.

02 PR.AC-4

Privileged change to OT assets

Engineering changes against PLCs, RTUs and HMIs require multi-party approval before the path is opened.

03 PR.IP-9

Restore from offline vault

Restoration from the offline vault is an explicit, recorded Execute decision with quorum approval.

04 A.5.18

Boundary policy changes

Changes to the zone and conduit definitions themselves are governed actions, not silent edits.

Relies on · prerequisites

- Independent approver identities that cannot be impersonated from the system being changed
- Recorded intent for every action, not just an audit log of the action
- Quorum policy that survives a single compromised admin

Pairs with · companion modules

Image: FV-Firebreak module icon (https://fire-vault.com/assets/firebreak-icon-7zSCkB1t.png)
Firebreak
Image: FV-Relay module icon (https://fire-vault.com/assets/relay-icon-CVhJDRO7.png)
Relay
Image: FV-Lock module icon (https://fire-vault.com/assets/lock-icon-UU3vOaKE.png)
Lock
Image: FV-Validate module icon (https://fire-vault.com/assets/vault-icon-CD3Pv4ri.png)
Validate

Featured In

Read about Firevault on TechRadar Pro: https://www.techradar.com/pro/uk-startup-put-physical-disconnect-switch-in-its-cloud-storage-offering-to-mitigate-ransomware-attacks-but-will-that-be-enough
Read about Firevault on Yahoo Finance: https://uk.finance.yahoo.com/news/firevault-launches-help-businesses-directors-074500961.html
Read about Firevault on Channel Insider: https://www.channelinsider.com/security/tools-and-platforms/firevault-security-offline-platform-offering/
Read about Firevault on Security Buyer: https://securitybuyer.com/uk-cybersecurity-startup-launches-firevault/
Read about Firevault on SecurityBrief: https://securitybrief.com.au/story/firevault-unveils-offline-digital-vault-to-combat-rising-cyber-risks

Capabilities

## What you get with every deployment

01

### Condition-led initiation

Actions begin because a defined condition was met, not because somebody remembered.

02

### Approval where it matters

Sensitive actions require the right approval before execution rather than after the fact.

03

### Incident-aware

Execute responds to incident state so containment, isolation and lockdown actions can be carried out at machine speed within agreed bounds.

04

### Supervisory override

An explicit supervisory layer can pause, redirect or stop an action when human judgement needs to take over.

05

### Scoped authority

Each action is constrained to the systems and operations the policy permits.

06

### Decision and execution paired

The reason for the action and the action itself are recorded together through Archive.

Demo to Live

## Adoption Guide

Step 1

#### Catalogue the actions

List the control actions that matter, including their owners, scopes and current triggers.

Step 2

#### Define conditions and approvals

For each action, agree the policy, schedule, incident state and approval pattern that should govern it.

Step 3

#### Pilot with one workflow

Move one action onto Execute end-to-end, including the supervisory override and the evidential record.

Step 4

#### Operate and review

Run Execute as the initiation layer for control actions and review patterns through Archive on a regular cadence.

Step 1

#### Catalogue the actions

Step 2

#### Define conditions and approvals

Step 3

#### Pilot with one workflow

Step 4

#### Operate and review

Organise a Demo: https://fire-vault.com/contact

Playbooks

## Which playbook covers this module

Each playbook shows where this module sits in a real deployment, who authorises it and how a pilot scales into rollout.

A Control Blueprint for AI

### A Control Blueprint for AI: 2026 Playbook

The kill switch doctrine chapter explains who may initiate a control action against an agent or cluster, and on what authority.

Read the playbook: A Control Blueprint for AI: 2026 Playbook
https://fire-vault.com/playbook/ai-control-blueprints

Control for Water Playbook

### Control for Water: Deployment Playbook

Sets the approval pattern, escalation route and pre-approved conditions for control actions during a supply incident.

Read the playbook: Control for Water: Deployment Playbook
https://fire-vault.com/playbook/firebreak-water

## Explore More

### FV-Validate

Checks whether a request should proceed before Execute acts.

Learn more about FV-Validate
https://fire-vault.com/control/modules/validate

### FV-Firebreak

Severance action initiated by Execute.

Learn more about FV-Firebreak
https://fire-vault.com/control/modules/firebreak

### FV-Relay

Time-bound, purposeful access initiated by Execute.

Learn more about FV-Relay
https://fire-vault.com/control/modules/relay

Questions

## Frequently Asked

## Structured data

```json
[
  {
    "@context": "https://schema.org",
    "@type": "Organization",
    "@id": "https://fire-vault.com/#organization",
    "name": "Firevault",
    "legalName": "Firevault Limited",
    "url": "https://fire-vault.com",
    "logo": {
      "@type": "ImageObject",
      "url": "https://fire-vault.com/logo.png",
      "width": 200,
      "height": 60
    },
    "foundingDate": "2025-03",
    "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
    "address": {
      "@type": "PostalAddress",
      "addressCountry": "GB",
      "addressLocality": "United Kingdom"
    },
    "contactPoint": [
      {
        "@type": "ContactPoint",
        "contactType": "customer service",
        "email": "hello@fire-vault.com",
        "availableLanguage": "English",
        "areaServed": [
          "GB",
          "EU",
          "US",
          "AE"
        ]
      },
      {
        "@type": "ContactPoint",
        "contactType": "sales",
        "email": "sales@fire-vault.com",
        "availableLanguage": "English",
        "areaServed": [
          "GB",
          "EU",
          "US",
          "AE"
        ]
      }
    ],
    "founder": [
      {
        "@type": "Person",
        "name": "Mark Fermor",
        "jobTitle": "Founder, CTO and CMO"
      },
      {
        "@type": "Person",
        "name": "David Bailey",
        "jobTitle": "Founder and CEO"
      }
    ],
    "areaServed": [
      "United Kingdom",
      "Europe",
      "United States",
      "Middle East"
    ],
    "sameAs": [
      "https://www.linkedin.com/company/firevault",
      "https://x.com/firevaultuk"
    ],
    "slogan": "Disconnect to Protect",
    "brand": [
      {
        "@type": "Brand",
        "name": "Offline Secure Storage"
      },
      {
        "@type": "Brand",
        "name": "Control by Firevault"
      },
      {
        "@type": "Brand",
        "name": "Firebreak"
      }
    ],
    "knowsAbout": [
      "Offline Secure Storage",
      "Physically disconnected data storage",
      "Physical Air Gap Data Protection",
      "Ransomware Protection",
      "Ransomware recovery",
      "3-2-1-1-0 backup rule",
      "AI kill switch",
      "Operational technology security",
      "Critical national infrastructure resilience",
      "Data Sovereignty",
      "GDPR Compliance",
      "NIS2 Compliance",
      "DORA Compliance",
      "NCSC Cyber Assessment Framework"
    ]
  },
  {
    "@context": "https://schema.org",
    "@type": "WebSite",
    "@id": "https://fire-vault.com/#website",
    "name": "Firevault",
    "alternateName": [
      "Firevault",
      "Firevault UK",
      "Firevault Limited"
    ],
    "url": "https://fire-vault.com",
    "publisher": {
      "@id": "https://fire-vault.com/#organization"
    },
    "inLanguage": "en-GB",
    "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
    "potentialAction": {
      "@type": "SearchAction",
      "target": {
        "@type": "EntryPoint",
        "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
      },
      "query-input": "required name=search_term_string"
    }
  },
  {
    "@context": "https://schema.org",
    "@type": "WebPage",
    "@id": "https://fire-vault.com/control/modules/execute#webpage",
    "url": "https://fire-vault.com/control/modules/execute",
    "name": "Control Execute Module: controlled execution",
    "description": "Execute runs a scoped, human-approved task against your offline vault, then returns it to a disconnected state. See the workflow and full audit trail.",
    "isPartOf": {
      "@id": "https://fire-vault.com/#website"
    },
    "about": {
      "@id": "https://fire-vault.com/#organization"
    },
    "primaryImageOfPage": {
      "@type": "ImageObject",
      "url": "https://fire-vault.com/__l5e/assets-v1/27d95636-cb89-494d-a105-ed44bd5b2f43/og-control-execute.webp"
    },
    "inLanguage": "en-GB",
    "breadcrumb": {
      "@id": "https://fire-vault.com/control/modules/execute#breadcrumb"
    }
  },
  {
    "@context": "https://schema.org",
    "@type": "BreadcrumbList",
    "@id": "https://fire-vault.com/control/modules/execute#breadcrumb",
    "itemListElement": [
      {
        "@type": "ListItem",
        "position": 1,
        "name": "Home",
        "item": "https://fire-vault.com"
      },
      {
        "@type": "ListItem",
        "position": 2,
        "name": "Control",
        "item": "https://fire-vault.com/control"
      },
      {
        "@type": "ListItem",
        "position": 3,
        "name": "Modules",
        "item": "https://fire-vault.com/control/modules"
      },
      {
        "@type": "ListItem",
        "position": 4,
        "name": "Control Execute Module: controlled execution",
        "item": "https://fire-vault.com/control/modules/execute"
      }
    ]
  }
]
```