When Arcology boots, it should do so into safe mode, which rejects connections (politely), except from AI1 and AI2. Safe mode ends after a timer expires or if manually commanded. While in safe mode, an admin can exit safe mode or disable the timer (so that safe mode persists indefinitely).
We may also need a variant of safe-mode for secondary machines. We allow communications with Arcology Prime, but mark the machine (and all modules) as in safe mode and prevent normal messages (or something).
Note also that we need a separate safe mode for GridWhale.