[
  {
    "schema_version": "1.0.0",
    "spec_version": "1.0.0",
    "assessment_id": "HARBOR-H1",
    "revision": 1,
    "assessed_at": "2026-09-19T12:00:00Z",
    "illustrative": true,
    "system": {
      "name": "Harbor fictional coding agent",
      "version": "fictional-h1",
      "activity": "broad_deployment",
      "environment": "Fictional broad production scope without a verified preventive disclosure boundary",
      "allowed_actions": [
        "Requested broad deployment with production data access"
      ],
      "prohibited_actions": [
        "Unapproved changes to authority"
      ]
    },
    "stakes": {
      "severity": 4,
      "irreversibility": 4,
      "scale": 2,
      "autonomy": 3,
      "power_concentration": 2,
      "rights_affected": false,
      "rsi_relevant": false,
      "rationale": "Potential data consequences require independent review even within a limited exposure."
    },
    "critical_claims": [
      {
        "id": "CL-BOUNDARY",
        "claim": "The reactive containment mechanism takes effect within the stated test conditions.",
        "status": "supported",
        "evidence_ids": [
          "EV-BOUNDARY"
        ]
      }
    ],
    "hazards": [
      {
        "id": "HZ-DISCLOSURE",
        "description": "Disclosure cannot be undone by software rollback.",
        "unacceptable": true,
        "irreversible": true,
        "controls_sufficient": "no",
        "earliest_harm_seconds": 1,
        "trigger_event": "Attempted unauthorized outbound disclosure",
        "rationale": "Prevention must act before transmission; reactive response alone is insufficient.",
        "evidence_ids": [
          "EV-BOUNDARY"
        ]
      }
    ],
    "timing": {
      "scenario": "A detectable unsafe scope change requires containment.",
      "start_event": "The deviation becomes detectable under the specified monitor design.",
      "end_event": "Containment is confirmed across credentials, queued work and child agents.",
      "l_components": {
        "detection": {
          "estimate": {
            "lower": 1800,
            "central": 1800,
            "upper": 1800
          },
          "basis": "illustrative",
          "rationale": "Illustrative point estimate for a fictional scenario, not a field measurement.",
          "evidence_ids": [
            "EV-TIMING"
          ]
        },
        "decision": {
          "estimate": {
            "lower": 1800,
            "central": 1800,
            "upper": 1800
          },
          "basis": "illustrative",
          "rationale": "Illustrative point estimate for a fictional scenario, not a field measurement.",
          "evidence_ids": [
            "EV-TIMING"
          ]
        },
        "execution": {
          "estimate": {
            "lower": 3600,
            "central": 3600,
            "upper": 3600
          },
          "basis": "illustrative",
          "rationale": "Illustrative fallback containment duration; the designated required breaker failed its drill. This estimate never cures that known blocker.",
          "evidence_ids": [
            "EV-TIMING"
          ]
        }
      },
      "h": {
        "status": "known",
        "quantity": {
          "estimate": {
            "lower": 18000,
            "central": 18000,
            "upper": 18000
          },
          "basis": "illustrative",
          "rationale": "Illustrative point estimate for a fictional scenario, not a field measurement.",
          "evidence_ids": [
            "EV-TIMING"
          ]
        },
        "invalidation_events": [
          "Any change to tools, permissions, environment or critical evidence invalidates this estimate."
        ]
      }
    },
    "gears": {
      "governance": {
        "rating": "green",
        "rationale": "Fictional evidence establishes the required controls for this bounded activity.",
        "evidence_ids": [
          "EV-GEARS"
        ]
      },
      "equity": {
        "rating": "yellow",
        "rationale": "A known nonblocking concern remains bounded by the stated conditions.",
        "evidence_ids": [
          "EV-GEARS"
        ]
      },
      "aligned_incentives": {
        "rating": "yellow",
        "rationale": "A known nonblocking concern remains bounded by the stated conditions.",
        "evidence_ids": [
          "EV-GEARS"
        ]
      },
      "resilience": {
        "rating": "red",
        "rationale": "The requested scope lacks the preventive data boundary required for the irreversible hazard.",
        "evidence_ids": [
          "EV-GEARS"
        ]
      },
      "steering": {
        "rating": "green",
        "rationale": "Fictional evidence establishes the required controls for this bounded activity.",
        "evidence_ids": [
          "EV-GEARS"
        ]
      }
    },
    "breakers": [
      {
        "id": "BR-CONTAIN",
        "required": true,
        "owner": "Fictional incident commander",
        "trigger": "A scope or boundary violation is detected.",
        "action": "Revoke delegated authority, stop queued actions, and confirm containment.",
        "deadline_seconds": 7200,
        "test_status": "failed",
        "tested_system_version": "fictional-h1",
        "evidence_ids": [
          "EV-BOUNDARY"
        ]
      }
    ],
    "evidence": [
      {
        "id": "EV-TIMING",
        "title": "Fictional timing worksheet",
        "locator": null,
        "source_kind": "illustrative",
        "captured_at": "2026-09-19T11:00:00Z",
        "validity_status": "current",
        "scope": "Fictional evidence for HARBOR-H1; the hazard boundary is inadequate."
      },
      {
        "id": "EV-BOUNDARY",
        "title": "Fictional preventive boundary and containment drill",
        "locator": null,
        "source_kind": "illustrative",
        "captured_at": "2026-09-19T11:00:00Z",
        "validity_status": "current",
        "scope": "Fictional evidence for HARBOR-H1; the hazard boundary is inadequate."
      },
      {
        "id": "EV-GEARS",
        "title": "Fictional governance and stakeholder review",
        "locator": null,
        "source_kind": "illustrative",
        "captured_at": "2026-09-19T11:00:00Z",
        "validity_status": "current",
        "scope": "Fictional evidence for HARBOR-H1; the hazard boundary is inadequate."
      }
    ],
    "review": {
      "assessor": "Fictional platform engineer",
      "accountable_owner": "Fictional service owner",
      "independent_reviewer": "Fictional independent reviewer",
      "independent_status": "completed",
      "scope_matches": true,
      "valid_until": "2026-09-19T17:00:00Z",
      "dissent": [
        "The reviewer requests further evidence before any scope expansion."
      ],
      "limitations": [
        "This is a fictional worked example, not independently gathered evidence."
      ]
    },
    "actions": [
      {
        "id": "AC-RECOURSE",
        "description": "Verify the affected-user recourse process before broader rollout.",
        "addresses": [
          "gear:equity"
        ],
        "owner": "Fictional service owner",
        "due_at": "2026-09-19T16:00:00Z",
        "verification_test": "A representative user can request review and receive an accountable response.",
        "completed": false
      },
      {
        "id": "AC-INTERVENTION",
        "description": "Protect justified intervention from delivery penalties and staff alerts during the limited rollout.",
        "addresses": [
          "gear:aligned_incentives",
          "ratio:amber"
        ],
        "owner": "Fictional incident commander",
        "due_at": "2026-09-19T16:00:00Z",
        "verification_test": "Demonstrate staffed monitoring, timely escalation and an interruption without incentive penalties; reassess before any expansion.",
        "completed": false
      }
    ],
    "decision": {
      "advisory": "blocked",
      "reason_codes": [
        "RED_GEAR:resilience",
        "REQUIRED_CONTROL_FAILED:BR-CONTAIN",
        "UNCONTROLLED_HAZARD:HZ-DISCLOSURE"
      ],
      "human": {
        "status": "awaiting_decision",
        "recorded_by": null,
        "recorded_at": null,
        "expires_at": null,
        "rationale": "Illustrative example; no permission to operate is granted."
      },
      "ratio_snapshot": {
        "band": "amber",
        "lower": 0.4,
        "central": 0.4,
        "upper": 0.4,
        "l_seconds": {
          "lower": 7200,
          "central": 7200,
          "upper": 7200
        }
      }
    },
    "reassessment": {
      "due_at": "2026-09-19T17:00:00Z",
      "triggers": [
        "model_version",
        "tools_or_permissions",
        "environment",
        "critical_claim_change",
        "failed_control",
        "relevant_incident",
        "evidence_expiry"
      ]
    },
    "limitations": [
      "All figures and evidence are illustrative. A favorable timing band is not a safety certification."
    ]
  },
  {
    "schema_version": "1.0.0",
    "spec_version": "1.0.0",
    "assessment_id": "HARBOR-H2",
    "revision": 2,
    "assessed_at": "2026-09-19T12:00:00Z",
    "illustrative": true,
    "system": {
      "name": "Harbor fictional coding agent",
      "version": "fictional-h2",
      "activity": "broad_deployment",
      "environment": "Fictional broad production scope without a verified preventive disclosure boundary",
      "allowed_actions": [
        "Requested broad deployment with production data access"
      ],
      "prohibited_actions": [
        "Unapproved changes to authority"
      ]
    },
    "stakes": {
      "severity": 4,
      "irreversibility": 4,
      "scale": 2,
      "autonomy": 3,
      "power_concentration": 2,
      "rights_affected": false,
      "rsi_relevant": false,
      "rationale": "Potential data consequences require independent review even within a limited exposure."
    },
    "critical_claims": [
      {
        "id": "CL-BOUNDARY",
        "claim": "The reactive containment mechanism takes effect within the stated test conditions.",
        "status": "supported",
        "evidence_ids": [
          "EV-BOUNDARY"
        ]
      }
    ],
    "hazards": [
      {
        "id": "HZ-DISCLOSURE",
        "description": "Disclosure cannot be undone by software rollback.",
        "unacceptable": true,
        "irreversible": true,
        "controls_sufficient": "no",
        "earliest_harm_seconds": 1,
        "trigger_event": "Attempted unauthorized outbound disclosure",
        "rationale": "Prevention must act before transmission; reactive response alone is insufficient.",
        "evidence_ids": [
          "EV-BOUNDARY"
        ]
      }
    ],
    "timing": {
      "scenario": "A detectable unsafe scope change requires containment.",
      "start_event": "The deviation becomes detectable under the specified monitor design.",
      "end_event": "Containment is confirmed across credentials, queued work and child agents.",
      "l_components": {
        "detection": {
          "estimate": {
            "lower": 600,
            "central": 600,
            "upper": 600
          },
          "basis": "illustrative",
          "rationale": "Illustrative point estimate for a fictional scenario, not a field measurement.",
          "evidence_ids": [
            "EV-TIMING"
          ]
        },
        "decision": {
          "estimate": {
            "lower": 300,
            "central": 300,
            "upper": 300
          },
          "basis": "illustrative",
          "rationale": "Illustrative point estimate for a fictional scenario, not a field measurement.",
          "evidence_ids": [
            "EV-TIMING"
          ]
        },
        "execution": {
          "estimate": {
            "lower": 900,
            "central": 900,
            "upper": 900
          },
          "basis": "illustrative",
          "rationale": "Illustrative point estimate for a fictional scenario, not a field measurement.",
          "evidence_ids": [
            "EV-TIMING"
          ]
        }
      },
      "h": {
        "status": "known",
        "quantity": {
          "estimate": {
            "lower": 18000,
            "central": 18000,
            "upper": 18000
          },
          "basis": "illustrative",
          "rationale": "Illustrative point estimate for a fictional scenario, not a field measurement.",
          "evidence_ids": [
            "EV-TIMING"
          ]
        },
        "invalidation_events": [
          "Any change to tools, permissions, environment or critical evidence invalidates this estimate."
        ]
      }
    },
    "gears": {
      "governance": {
        "rating": "green",
        "rationale": "Fictional evidence establishes the required controls for this bounded activity.",
        "evidence_ids": [
          "EV-GEARS"
        ]
      },
      "equity": {
        "rating": "yellow",
        "rationale": "A known nonblocking concern remains bounded by the stated conditions.",
        "evidence_ids": [
          "EV-GEARS"
        ]
      },
      "aligned_incentives": {
        "rating": "yellow",
        "rationale": "A known nonblocking concern remains bounded by the stated conditions.",
        "evidence_ids": [
          "EV-GEARS"
        ]
      },
      "resilience": {
        "rating": "red",
        "rationale": "The requested scope lacks the preventive data boundary required for the irreversible hazard.",
        "evidence_ids": [
          "EV-GEARS"
        ]
      },
      "steering": {
        "rating": "green",
        "rationale": "Fictional evidence establishes the required controls for this bounded activity.",
        "evidence_ids": [
          "EV-GEARS"
        ]
      }
    },
    "breakers": [
      {
        "id": "BR-CONTAIN",
        "required": true,
        "owner": "Fictional incident commander",
        "trigger": "A scope or boundary violation is detected.",
        "action": "Revoke delegated authority, stop queued actions, and confirm containment.",
        "deadline_seconds": 1800,
        "test_status": "passed",
        "tested_system_version": "fictional-h2",
        "evidence_ids": [
          "EV-BOUNDARY"
        ]
      }
    ],
    "evidence": [
      {
        "id": "EV-TIMING",
        "title": "Fictional timing worksheet",
        "locator": null,
        "source_kind": "illustrative",
        "captured_at": "2026-09-19T11:00:00Z",
        "validity_status": "current",
        "scope": "Fictional evidence for HARBOR-H2; the hazard boundary is inadequate."
      },
      {
        "id": "EV-BOUNDARY",
        "title": "Fictional preventive boundary and containment drill",
        "locator": null,
        "source_kind": "illustrative",
        "captured_at": "2026-09-19T11:00:00Z",
        "validity_status": "current",
        "scope": "Fictional evidence for HARBOR-H2; the hazard boundary is inadequate."
      },
      {
        "id": "EV-GEARS",
        "title": "Fictional governance and stakeholder review",
        "locator": null,
        "source_kind": "illustrative",
        "captured_at": "2026-09-19T11:00:00Z",
        "validity_status": "current",
        "scope": "Fictional evidence for HARBOR-H2; the hazard boundary is inadequate."
      }
    ],
    "review": {
      "assessor": "Fictional platform engineer",
      "accountable_owner": "Fictional service owner",
      "independent_reviewer": "Fictional independent reviewer",
      "independent_status": "completed",
      "scope_matches": true,
      "valid_until": "2026-09-19T17:00:00Z",
      "dissent": [
        "The reviewer requests further evidence before any scope expansion."
      ],
      "limitations": [
        "This is a fictional worked example, not independently gathered evidence."
      ]
    },
    "actions": [
      {
        "id": "AC-RECOURSE",
        "description": "Verify the affected-user recourse process before broader rollout.",
        "addresses": [
          "gear:equity"
        ],
        "owner": "Fictional service owner",
        "due_at": "2026-09-19T16:00:00Z",
        "verification_test": "A representative user can request review and receive an accountable response.",
        "completed": false
      },
      {
        "id": "AC-INTERVENTION",
        "description": "Protect justified intervention from delivery penalties and staff alerts during the limited rollout.",
        "addresses": [
          "gear:aligned_incentives",
          "ratio:amber"
        ],
        "owner": "Fictional incident commander",
        "due_at": "2026-09-19T16:00:00Z",
        "verification_test": "Demonstrate staffed monitoring, timely escalation and an interruption without incentive penalties; reassess before any expansion.",
        "completed": false
      }
    ],
    "decision": {
      "advisory": "blocked",
      "reason_codes": [
        "RED_GEAR:resilience",
        "UNCONTROLLED_HAZARD:HZ-DISCLOSURE"
      ],
      "human": {
        "status": "awaiting_decision",
        "recorded_by": null,
        "recorded_at": null,
        "expires_at": null,
        "rationale": "Illustrative example; no permission to operate is granted."
      },
      "ratio_snapshot": {
        "band": "green",
        "lower": 0.1,
        "central": 0.1,
        "upper": 0.1,
        "l_seconds": {
          "lower": 1800,
          "central": 1800,
          "upper": 1800
        }
      }
    },
    "reassessment": {
      "due_at": "2026-09-19T17:00:00Z",
      "triggers": [
        "model_version",
        "tools_or_permissions",
        "environment",
        "critical_claim_change",
        "failed_control",
        "relevant_incident",
        "evidence_expiry"
      ]
    },
    "limitations": [
      "All figures and evidence are illustrative. A favorable timing band is not a safety certification."
    ]
  },
  {
    "schema_version": "1.0.0",
    "spec_version": "1.0.0",
    "assessment_id": "HARBOR-H3",
    "revision": 3,
    "assessed_at": "2026-09-19T12:00:00Z",
    "illustrative": true,
    "system": {
      "name": "Harbor fictional coding agent",
      "version": "fictional-h3",
      "activity": "limited_deployment",
      "environment": "Fictional isolated canary with a tested data boundary",
      "allowed_actions": [
        "Deploy allowlisted customer-portal fixes to the bounded canary"
      ],
      "prohibited_actions": [
        "External data disclosure",
        "Unapproved data modification",
        "Expansion of its own permissions"
      ]
    },
    "stakes": {
      "severity": 4,
      "irreversibility": 4,
      "scale": 2,
      "autonomy": 3,
      "power_concentration": 2,
      "rights_affected": false,
      "rsi_relevant": false,
      "rationale": "Potential data consequences require independent review even within a limited exposure."
    },
    "critical_claims": [
      {
        "id": "CL-BOUNDARY",
        "claim": "The canary cannot disclose protected data beyond the approved boundary.",
        "status": "supported",
        "evidence_ids": [
          "EV-BOUNDARY"
        ]
      }
    ],
    "hazards": [
      {
        "id": "HZ-DISCLOSURE",
        "description": "Disclosure cannot be undone by software rollback.",
        "unacceptable": true,
        "irreversible": true,
        "controls_sufficient": "yes",
        "earliest_harm_seconds": 1,
        "trigger_event": "Attempted unauthorized outbound disclosure",
        "rationale": "Prevention must act before transmission; reactive response alone is insufficient.",
        "evidence_ids": [
          "EV-BOUNDARY"
        ]
      }
    ],
    "timing": {
      "scenario": "A detectable unsafe scope change requires containment.",
      "start_event": "The deviation becomes detectable under the specified monitor design.",
      "end_event": "Containment is confirmed across credentials, queued work and child agents.",
      "l_components": {
        "detection": {
          "estimate": {
            "lower": 600,
            "central": 600,
            "upper": 600
          },
          "basis": "illustrative",
          "rationale": "Illustrative point estimate for a fictional scenario, not a field measurement.",
          "evidence_ids": [
            "EV-TIMING"
          ]
        },
        "decision": {
          "estimate": {
            "lower": 300,
            "central": 300,
            "upper": 300
          },
          "basis": "illustrative",
          "rationale": "Illustrative point estimate for a fictional scenario, not a field measurement.",
          "evidence_ids": [
            "EV-TIMING"
          ]
        },
        "execution": {
          "estimate": {
            "lower": 900,
            "central": 900,
            "upper": 900
          },
          "basis": "illustrative",
          "rationale": "Illustrative point estimate for a fictional scenario, not a field measurement.",
          "evidence_ids": [
            "EV-TIMING"
          ]
        }
      },
      "h": {
        "status": "known",
        "quantity": {
          "estimate": {
            "lower": 18000,
            "central": 18000,
            "upper": 18000
          },
          "basis": "illustrative",
          "rationale": "Illustrative point estimate for a fictional scenario, not a field measurement.",
          "evidence_ids": [
            "EV-TIMING"
          ]
        },
        "invalidation_events": [
          "Any change to tools, permissions, environment or critical evidence invalidates this estimate."
        ]
      }
    },
    "gears": {
      "governance": {
        "rating": "green",
        "rationale": "Fictional evidence establishes the required controls for this bounded activity.",
        "evidence_ids": [
          "EV-GEARS"
        ]
      },
      "equity": {
        "rating": "yellow",
        "rationale": "A known nonblocking concern remains bounded by the stated conditions.",
        "evidence_ids": [
          "EV-GEARS"
        ]
      },
      "aligned_incentives": {
        "rating": "yellow",
        "rationale": "A known nonblocking concern remains bounded by the stated conditions.",
        "evidence_ids": [
          "EV-GEARS"
        ]
      },
      "resilience": {
        "rating": "green",
        "rationale": "Fictional evidence establishes the required controls for this bounded activity.",
        "evidence_ids": [
          "EV-GEARS"
        ]
      },
      "steering": {
        "rating": "green",
        "rationale": "Fictional evidence establishes the required controls for this bounded activity.",
        "evidence_ids": [
          "EV-GEARS"
        ]
      }
    },
    "breakers": [
      {
        "id": "BR-CONTAIN",
        "required": true,
        "owner": "Fictional incident commander",
        "trigger": "A scope or boundary violation is detected.",
        "action": "Revoke delegated authority, stop queued actions, and confirm containment.",
        "deadline_seconds": 1800,
        "test_status": "passed",
        "tested_system_version": "fictional-h3",
        "evidence_ids": [
          "EV-BOUNDARY"
        ]
      }
    ],
    "evidence": [
      {
        "id": "EV-TIMING",
        "title": "Fictional timing worksheet",
        "locator": null,
        "source_kind": "illustrative",
        "captured_at": "2026-09-19T11:00:00Z",
        "validity_status": "current",
        "scope": "Fictional Harbor H3 boundary and operating conditions; no real test is claimed."
      },
      {
        "id": "EV-BOUNDARY",
        "title": "Fictional preventive boundary and containment drill",
        "locator": null,
        "source_kind": "illustrative",
        "captured_at": "2026-09-19T11:00:00Z",
        "validity_status": "current",
        "scope": "Fictional Harbor H3 boundary and operating conditions; no real test is claimed."
      },
      {
        "id": "EV-GEARS",
        "title": "Fictional governance and stakeholder review",
        "locator": null,
        "source_kind": "illustrative",
        "captured_at": "2026-09-19T11:00:00Z",
        "validity_status": "current",
        "scope": "Fictional Harbor H3 boundary and operating conditions; no real test is claimed."
      }
    ],
    "review": {
      "assessor": "Fictional platform engineer",
      "accountable_owner": "Fictional service owner",
      "independent_reviewer": "Fictional independent reviewer",
      "independent_status": "completed",
      "scope_matches": true,
      "valid_until": "2026-09-19T17:00:00Z",
      "dissent": [
        "The reviewer requests further evidence before any scope expansion."
      ],
      "limitations": [
        "This is a fictional worked example, not independently gathered evidence."
      ]
    },
    "actions": [
      {
        "id": "AC-RECOURSE",
        "description": "Verify the affected-user recourse process before broader rollout.",
        "addresses": [
          "gear:equity"
        ],
        "owner": "Fictional service owner",
        "due_at": "2026-09-19T16:00:00Z",
        "verification_test": "A representative user can request review and receive an accountable response.",
        "completed": false
      },
      {
        "id": "AC-INTERVENTION",
        "description": "Protect justified intervention from delivery penalties and staff alerts during the limited rollout.",
        "addresses": [
          "gear:aligned_incentives",
          "ratio:amber"
        ],
        "owner": "Fictional incident commander",
        "due_at": "2026-09-19T16:00:00Z",
        "verification_test": "Demonstrate staffed monitoring, timely escalation and an interruption without incentive penalties; reassess before any expansion.",
        "completed": false
      }
    ],
    "decision": {
      "advisory": "eligible_with_conditions",
      "reason_codes": [],
      "human": {
        "status": "awaiting_decision",
        "recorded_by": null,
        "recorded_at": null,
        "expires_at": null,
        "rationale": "Illustrative example; no permission to operate is granted."
      },
      "ratio_snapshot": {
        "band": "green",
        "lower": 0.1,
        "central": 0.1,
        "upper": 0.1,
        "l_seconds": {
          "lower": 1800,
          "central": 1800,
          "upper": 1800
        }
      }
    },
    "reassessment": {
      "due_at": "2026-09-19T17:00:00Z",
      "triggers": [
        "model_version",
        "tools_or_permissions",
        "environment",
        "critical_claim_change",
        "failed_control",
        "relevant_incident",
        "evidence_expiry"
      ]
    },
    "limitations": [
      "All figures and evidence are illustrative. A favorable timing band is not a safety certification."
    ]
  }
]
