Skip to main content

Emergency Lockdown

Available on Team and Enterprise.

Emergency lockdown is a break-glass capability that restricts access for a specific machine registered with Fleet. It is intended for urgent situations — a lost or stolen device, evidence of unauthorized access, or any scenario where you need to act before you have time to remove a member or wait for a session to expire. Only org owners and admins hold the lockdown permission.

:::note Availability The lockdown permission model and the member-facing alerts described below are live today. The self-serve admin control to initiate a lockdown from the dashboard is rolling out — if you need to lock down a device before it lands, contact Kameas support. :::

What it does

When a machine is locked down:

  • The machine's registration is marked locked in Fleet. Its Harness loses authorization to sync configuration or access org-scoped context.
  • Every affected member receives a lockdown alert notification (email and, if enabled, SMS) with the machine label, the time of the lockdown, who initiated it, and a reason.
  • The event appears in the org's audit log, stamped with the initiating admin's identity.

The lockdown is specific to the registered machine. Other machines owned by the same member are not affected unless locked down separately.

Who can use it

RoleHolds the lockdown permission
org_owner
org_admin
org_member

Lockdown is gated on the machines:emergency_lockdown permission, held by org owners and admins. Members can see their own registered machines but cannot lock down any device.

This is a Team and Enterprise capability. Pro orgs have a single seat — there are no other machines or admins to manage.

What members see

When a machine you own is locked down, Fleet sends you a Lockdown alert notification. The alert includes:

  • The label of the affected machine.
  • Who initiated the lockdown and when.
  • The reason provided by the initiating admin.
  • A link to your Fleet console.

Lockdown alerts are in the Operational notification class. They are on by default — Fleet treats them as a transparency mechanism, not a marketing message. You can adjust your delivery preference (email, SMS, or both) from Account → Notifications in the Fleet dashboard.

Notification preference

In your notification preferences, the lockdown_alert kind appears under the Operational group. You can disable the email or SMS delivery for this kind individually. Because lockdown is an operational event rather than a billing-critical one, the toggle is not forced, so you control whether you receive it. Fleet still records the event in the audit log regardless of your notification preference.

When to use it

Emergency lockdown is not a substitute for removing a member or revoking an invitation. It is the right tool when:

  • A device is lost, stolen, or believed compromised and you need immediate effect.
  • You want to act before investigating whether the situation warrants full member removal.
  • You need a logged, auditable event that the machine was restricted at a specific time and for a stated reason.

After a lockdown, you should still review the member's access from the Members page and decide whether removal or a role change is appropriate.


Next: FAQ — common questions from admins and members.