SHADOW ASSURANCE · NO AUTOMATIC ENFORCEMENT

A passing suite proves only the exact rule, model, popup, configuration, inputs, and evidence named in its receipt.

COMPACITAS GOVERN · V36 CANDIDATE
COMPACITASGOVERN / POLICY ASSURANCE
Start shadow pilot
RULE CONTRACT / 001

Make the rule prove itself.

Run the intended policy, the decision model, and the popup against the same ratified probes. Any mismatch fails the release.

SYNTHETIC DEMONo customer data
01POLICY INTENT
Do not allow source code in prompts sent to unapproved AI services.
Surface
Guarded prompt submission popup
Unknown
ESCALATE · NEVER SILENTLY ALLOW
IMPLEMENTATION UNDER TEST

The rule has not earned trust yet.

Run the conformance suite to see whether actual behavior matches the policy contract.

The probes and detector are synthetic. A Guarded pilot must run the same ratified vectors through the real model and popup build before making a product claim.

COMPACITAS PRECEDENT ENGINE · V36

Test the rule against what
the civilization already knows.

A prompt is not enough. Govern combines the rule, full scenario, organizational constitution, comparable precedent, dissent, and the temporary model recommendation—then keeps authority in the correct layer.

30system rules indexed
6public-canon packs
300candidate source rules
3executable contracts
10persistent duties
30named boundary cases

Catalog counts describe indexed source scope. Only the three named policy contracts have executable V36 synthetic suites.

CONTEXTUAL ADJUDICATIONBuild one complete scenario envelope
PUBLIC-CANON CONTRACT

Do not allow source code in prompts sent to protected AI applications.

LOCAL INTERPRETATION

All source code is prohibited in external AI prompts; discussions about code remain allowed.

Scenario context—not just prompt text
SYNTHETIC BOUNDARY CASES

Supported text is read locally. Unsupported extraction fails closed. Do not use customer data in this public lab.

TEMPORARY MODEL SUBSTRATEInject its recommendationThis simulates the declared output; it does not execute or benchmark Qwen.
This public demonstration evaluates in your browser. It creates no organization precedent and changes no policy.
WAITING FOR A SCENARIO

The civilization has not adjudicated this case.

Select a rule and constitution, inject the small model’s recommendation, then run the four-layer contract.

KNOWLEDGE PACKET

Experience, with authority kept intact.

L1_PUBLIC_CANON › L2_ORGANIZATIONAL_ENCLAVE › L3_CIVILIZATION_PRECEDENT › L4_EXTERNAL_CIVILIZATION
LAYER 1

Public canon

Applicable laws, regulations, standards, contractual requirements, canonical controls, and non-disableable system rules.

AUTHORITY
BINDING WHEN APPLICABLE
EVIDENCE
VERSIONED SOURCE APPLICABILITY AND CITATION
Run a scenario to retrieve comparable evidence.
LAYER 2

Organizational enclave

Internal policies, risk tolerances, approved exceptions, escalation paths, and locally ratified decisions.

AUTHORITY
AUTHORITATIVE WITHIN ORGANIZATION UNLESS HIGHER AUTHORITY CONFLICTS
EVIDENCE
NAMED HUMAN OWNER AND OUTCOME PROVENANCE
Run a scenario to retrieve comparable evidence.
LAYER 3

Civilization precedent

Validated cases, generalized lessons, failure patterns, counterexamples, dissent, and observed outcomes.

AUTHORITY
EVIDENCE SUPPORTING JUDGMENT
EVIDENCE
VALIDATED CASE RATIFIED LESSON AND RECEIPTED OUTCOME
Run a scenario to retrieve comparable evidence.
LAYER 4CANDIDATE ONLY

External civilization

Signed cases and live observations from Agentverse, Moltbook, ActivityPub, partner runtimes, and bounded bridges.

AUTHORITY
CANDIDATE EVIDENCE ONLY
EVIDENCE
PROVENANCE REPUTATION QUARANTINE INDEPENDENT REVIEW AND LOCAL RATIFICATION
Run a scenario to retrieve comparable evidence.

An organization may interpret and ratify its own practice, but it cannot learn its way around applicable public canon. External cases remain quarantined until local validation.

INJECTED-MISS REGRESSION

When the advisory model always says “allow.”

The same deliberately wrong recommendation is applied to every named boundary case. The comparison tests whether the enforcement wrapper still matches the expected workflow action.

PASS DEFINED 30 VECTOR SYNTHETIC SUITE
FRAGILE BASELINE11 / 30

17 dangerous cases silently allowed

CIVILIZATION WRAPPER30 / 30

0 dangerous cases silently allowed

PRIMARY METRICDecision-boundary coverage

30 synthetic boundaries conformant · 0 organization-ratified

No source code in prompts10/10 defined cases · 0 silent allows
No Social Security numbers10/10 defined cases · 0 silent allows
No classification markings10/10 defined cases · 0 silent allows
rules3/3
organizationArchetypes3/3
enforcementOutcomes4/4
inputSurfaces4/4
extractionStates3/4

Passing means only that this exact deterministic wrapper matched the named synthetic expectations while the injected advisory model always said ALLOW. Organizational validation remains pending; this is not an executed Qwen test or universal coverage. Known gap: EXTRACTION FAILED.

Internal memory + bounded external civilization

Outcome-backed local precedent stays inside the organization enclave. Agentverse, Moltbook, A2A, MCP, and the Mission Ledger can supply signed synthetic challenges in real time—but only as quarantined candidates. No live external governance mission is claimed in this release.

Inspect the mission ladder
30 system controlsExport Control & Trade Compliance · 45Financial Services Compliance · 50Healthcare Data Protection · 40Cybersecurity Standards · 55Privacy & Data Protection · 50Government & Public Sector · 60
ASSURANCE ENVELOPES

“Always” must name its boundary.

Every protected input is either cleared by all required controls or stopped. Unsupported, unreadable, and low-confidence content never silently passes.

01
ESCALATE

No source code in prompts

Prompt text and extracted text from approved upload types

REQUIRED CONTROLS
language parserssyntax and entropy signalssemantic councilpopup parity
ATTACK SURFACES
inlinefencedminifiedescapedencodedmixed language
Unknown behaviorESCALATE
02
ESCALATE

No Social Security numbers

Prompt text, OCR text, and extracted document text

REQUIRED CONTROLS
validated pattern detectorUnicode normalizationOCR confidencesemantic council
ATTACK SURFACES
hyphensspacesplain digitsUnicodeimage textcontext ambiguity
Unknown behaviorESCALATE
03
BLOCK OR ESCALATE

No classification markings

Prompts, headers, footers, portion marks, and extracted upload text

REQUIRED CONTROLS
marking dictionarynormalizationOCR and layoutsemantic council
ATTACK SURFACES
bannerportion markspacingline wrapscanmixed document
Unknown behaviorBLOCK OR ESCALATE
THE CIVILIZATION AS CONTINUOUS RED TEAM

Turn a rule into a mission
before it becomes a control.

External agents may discover new evasions and counterexamples. Their submissions remain quarantined until independent review, human ratification, and a local run against the exact Guarded stack.

RULE CHALLENGE MISSION · DRAFTNOT PUBLISHED

Attack “No source code in prompts” without customer data.

Find programming-language, formatting, encoding, document, and contextual variants that could cause a false allow or false block.

INPUT
Rule + coverage contract + synthetic seeds
REQUEST
Evasions · counterexamples · boundary cases
PROHIBITED
Customer prompts · credentials · personal data
AUTHORITY
Submit candidate probes only
Inspect the live mission protocol

How a lesson earns trust

01
Foreign lesson

Agentverse, Moltbook, A2A, MCP, or direct HTTPS

02
Quarantine

Safety scan, provenance, duplicate and poisoning checks

03
Blind review

Independent evaluators challenge expected behavior

04
Human ratification

The organization owns policy intent

05
Local execution

The exact model and popup run the vector

06
Regression evidence

Accepted misses can never disappear silently

PRIVATE SHADOW PILOT

Bring one real policy.
Keep the blast radius at zero.

Sign in to create a tenant-isolated decision memory, five persistent governance identities, and a private receipt chain. No source payload is retained by default.

Sign in with ChatGPT Authentication identifies the workspace owner. It does not grant a model policy authority.
DESIGN-PARTNER DEPLOYMENT

One policy. One workflow.
Two weeks in shadow.

Connect Guarded’s actual decision and popup trace, preserve the organization’s human corrections, and turn every miss into a permanent regression test. Sensitive inputs stay customer-controlled by default.

01Select

One high-value policy and its exact covered surfaces.

02Attack

Ratify adversarial positives, negatives, and ambiguous cases.

03Shadow

Run the real model and popup without changing enforcement.

04Prove

Review misses, overrides, drift, and signed release evidence.