# Workshop worksheets and evaluation rubric

Version 1.0, September 9, 2026. Copy these tables into your own local notes. Use invented names and data.

## Scope sheet

| Field | Participant entry |
| --- | --- |
| Workflow and decision needed | |
| Owner and intended users | |
| Tenant/matter/source boundary | |
| Allowed actions and outputs | |
| Explicitly excluded actions | |
| Identity and authorization assumptions | |
| Environment/version and materials inspected | |
| Checks executed versus source reviewed | |
| Stop condition and escalation owner | |

## Permission and boundary matrix

| Actor/role | Resource/tenant | Action | Current authorization source | Approval required and bound fields | Enforcement point | Expected result |
| --- | --- | --- | --- | --- | --- | --- |
| Maya / editor | Amber / permitted document | Read | | | | |
| Maya + Lee / reviewer | Amber / permitted document | Approved write | | | | |
| Ben / other tenant | Amber / document | Read | | | | |
| Maya / editor | Amber / document | Change body after approval | | | | |
| Source note | Any document | Request external send | | | | |

## Check record

| Check ID and named test | Allowed/denied case | Input and precondition | Expected behavior | Observed behavior or source-only review | Downstream state checked | Limit / next check |
| --- | --- | --- | --- | --- | --- | --- |
| | | | | | | |

Use separate records for output text, citation metadata and exported/shared output when adapting retrieval checks. A pass on one surface does not establish the others.

## Operational stop tabletop

| Condition | Responsible owner | Stop action | Confirmation needed | In-flight/queued work | Recovery gate |
| --- | --- | --- | --- | --- | --- |
| Connector disabled | | | | | |
| Token cached by worker | | | | | |
| Effect already submitted | | | | | |
| Logs incomplete | | | | | |

## Decision record

Decision options: proceed to implementation testing, permit a narrower synthetic pilot, or defer pending named checks. Workshop attendance alone does not authorize production use.

| Condition or unresolved risk | Affected action/data | Required control/check | Owner | Acceptance criterion | Review date | Consequence if unresolved |
| --- | --- | --- | --- | --- | --- | --- |
| | | | | | | |

Record the decision owner, permitted pilot boundaries, system version, and changes that reopen review. Examples include a new connector, broader role, external send capability, memory store or answer cache.

## Detection scoring worksheet

One row is one named case, not one log row or alert tuple. Label 1 means the observed records meet the specified correlation rule. It does not mean a confirmed attack. Fill baseline first; reveal the suggestion later.

| Case | Rule label | Baseline prediction | Simulated suggestion | Analyst-approved rule prediction | Operational disposition and reason |
| --- | --- | --- | --- | --- | --- |
| positive_sequence | 1 | | | | |
| ordinary_admin | 0 | | | | |
| two_failures | 0 | | | | |
| late_grant | 0 | | | | |
| boundary_grant | 1 | | | | |
| cross_tenant_join | 0 | | | | |
| duplicate_delivery | 0 | | | | |
| missing_success_telemetry | 0 | | | | |

| Stage | TP | FP | FN | TN | Total cases | Precision TP/(TP+FP) | Recall TP/(TP+FN) |
| --- | --- | --- | --- | --- | --- | --- | --- |
| Baseline | | | | | | | |
| Simulated suggestion | | | | | | | |
| Analyst-approved example | | | | | | | |

Write `undefined` when a denominator is zero. Keep unknown attack status outside this rule-conformance table; never quietly label it benign. Record who owns the telemetry, which records are missing, what must be collected next and when to escalate.

## Evaluation rubric

Score each dimension 0, 1 or 2. Maximum 10. This is a teaching rubric, not a security score or certification.

| Dimension | 0: absent/incorrect | 1: partial | 2: useful and specific |
| --- | --- | --- | --- |
| Boundary reasoning | Actor, resource or effect unclear | Some identities/actions mapped | Current authority, allowed effect and denial point identified |
| Reproduction | Assertion repeated without checking | Inputs or observed state recorded | Prediction, executed/source-only status, result and downstream state distinguishable |
| Negative and allowed cases | Only one side considered | Both named but enforcement unclear | Denial paired with a legitimate allowed case and reason |
| Uncertainty | Fixture/model/production claims conflated | Limits mentioned generally | Untested components and missing telemetry linked to a next check |
| Decision ownership | No action owner | Owner or acceptance check incomplete | Named owner, concrete acceptance check, review point and rollout consequence |

For the detection module, reproduction includes the unit of counting and correct TP/FP/FN/TN; negative/allowed reasoning includes boundary, threshold and duplicate cases. A zero in uncertainty or ownership requires revising the worksheet before calling the exercise complete, regardless of total. A score of 8–10 indicates a well-supported workshop output; 5–7 needs focused revision; 0–4 needs the scenario and boundary revisited. None of these bands approves a live system.
