A step-by-step incident response workflow for the authorization layer, from mapping a compromised identity’s blast radius to proving containment held. Covers how centralized policy and decision logs compress each phase, what makes the workflow feasible in regulated and air-gapped environments, and how AI agents change the runbook.