Canaries warn defenders before the attack lands, in nearly every case.
In the present condition (canaries deployed), 95.9% of the runs that reached admin privilege escalation had already tripped a canary before their first critical action. The median gap between first canary touch and that action was 8 minutes. Additionally, the share of runs reaching admin drops only modestly when canaries are present. While canaries do not prevent capable models from finding a path to admin, the advantage is timing: the defender knows before it matters.