Safe Mode limits Autopilot to reversible, low-risk actions (retries, warm-cache, alert routing) while still letting it triage incidents automatically.
Safe Mode restricts Autopilot to reversible actions: retrying failed probes, warming the CDN cache, muting flapping alerts, and routing to the right on-call. Destructive actions (config changes, deploys) require explicit approval.
Settings → Autopilot → Safe Mode.
Yes for all new orgs. Full autonomy is opt-in per org.