StableMindActionGate Workspace
Customer-controlled · read only

SIO23 · Shadow Mode Quickstart

Observe the request.
Do not connect the consequence.

Turn your Refused Workflow Challenge into a digest-bound observation setup. Shadow mode can mirror minimized facts and later compute what ActionGate would have done. It cannot issue a permit or write to the system being observed.

WRITE SCOPES · 0PERMITS · PROHIBITEDEXECUTION · PROHIBITED
CHALLENGELOOKING FOR SESSION MANIFEST
SETUP STATECHALLENGE_REQUIRED
CUSTOMER CONNECTIONNOT ESTABLISHED

01 / Observation path

Start with the least connected option.

stablemind.shadow-mode-quickstart.v1

02 / Minimum observation envelope

Mirror facts, not secrets.

7 required fields
NEVER MIRROR

Passwords · private keys · access tokens · refresh tokens · raw execution credentials · full request bodies · unrelated customer data.

03 / Counterfactual output

What shadow mode is allowed to say.

WOULD_PERMIT

Observed facts appear within the supplied authority boundary.

WOULD_NARROW

The request exceeds a supplied scope or magnitude and would need contraction.

WOULD_REQUIRE_HUMAN_AUTHORITY

A target change, approval boundary, or unresolved duty would stop automation.

WOULD_DENY

The mirrored authority state would fail closed.

AUTHORITY_UNRESOLVED

The observation lacks enough attributable authority evidence to classify safely.

01

Read-only means no return path.

Connected transports are ingress-only or GET/list-only. The setup declares zero customer-system write scopes.

02

Counterfactual means no permit.

Shadow mode can say what ActionGate would have done under mirrored facts. It cannot issue a consumable Action Permit.

03

Opportunity is not realized value.

Time saved, risk reduced, or automation candidates remain hypotheses until customer-controlled evidence measures them externally.

Shadow ready ≠ production ready.write_scopes=0 · permit=PROHIBITED · credential=PROHIBITED · connection=NOT_ESTABLISHED · execution=PROHIBITED