# Participant packet

Kevin O'Connor. Version 1.0, September 9, 2026.

## Scenario and boundary

You are reviewing an invented support assistant. Maya belongs to tenant Amber and can read/edit an allowed document. Lee can review a proposed edit. Ben belongs to Birch. The assistant can read, draft and request an approved document write. It cannot delete, change sharing, execute commands, deploy code or send customer messages. A real pilot decision will need application-specific tests after this workshop.

Work in pairs with [the worksheets](worksheets.md). Record predictions before looking at the expected assertion. Record whether you ran a check or only inspected it. Python 3.10 or later and a text editor are sufficient; use [the setup index](README.md). No model, cloud account or client data is needed.

## Task 1: scope and authority

Complete one scope sheet and sketch the identity/data/action path. Identify the source of the user and tenant identity, the document ACL, the trusted reviewer and the enforcement point. Put the model's proposed action on the diagram as untrusted input. Mark what is implemented in the fixture and what would need authentication or durable coordination in a deployed system.

Produce a permission matrix for an allowed read, an approved write, cross-tenant access, a changed write after approval and a send request. The last request is excluded by workflow design; it should not become permitted because source text asks for it.

## Task 2: bind approval to the edit

Run `python3 document_permissions.py`. Open its `PolicyTests` class and find `test_approved_write`, `test_altered_body`, `test_replay`, `test_reviewer_revocation` and `test_stale_document`.

For each selected case, write the subject, resource, intended effect, relevant version/approval condition and expected state. Inspect whether denial occurs before document mutation. Pair each negative case with the allowed case that should remain usable. Explain what would need to be atomic when two production workers race to use an approval.

## Task 3: follow the document into the answer

Run `python3 rag_boundaries.py`. Predict which documents Amber and Birch can retrieve using the literal query `Calibration`. Follow a forged Birch candidate into Amber's context builder. Then inspect ACL revocation after search, citation filtering, stale versions and deletion.

The hostile Amber note is inert source text. Identify what the code does with its label and why a proposed send is denied. Write one additional real-system test for a cached answer after access is revoked; the reference code has no answer cache. Include citation title, URL, snippet and any generated export in your proposed observation points.

## Task 4: revoke and stop

Run `python3 credential_lifecycle.py`. Inspect a valid request, revoked handle, replacement handle, wrong audience and insufficient scope. Record the downstream-call count before and after denial.

For a real system, identify the owner who disables a connector and who can verify provider-side revocation. Record how the team would handle a cached token, in-flight effect and unfinished queue item. These are tabletop questions; do not claim the fixture tested them.

## Task 5: write the decision

Complete a conditional decision for the synthetic workflow. Separate allowed pilot activity, blocked effects and unresolved checks. Give every condition an owner, an acceptance criterion and a review date. Use the rubric with another pair and revise one unsupported claim.

Use the [board report builder](https://www.tkoresearch.com/tools/ai-risk-board-report) to prepare a leadership briefing. Use synthetic or appropriately redacted material, identify unknowns and describe only the checks you completed.

## Optional separate session: detection evaluation

Use [the detection handout](detection-module.md). Record the baseline before seeing the simulated suggestions. Maintain three prediction columns: unchanged rule, simulated suggestion and analyst-approved rule decision. Keep missing telemetry as a separate operational disposition even when the rule returns zero matches.
