PLANNED FIRST PILOT

Evaluate one consequential action boundary.

A planned, controlled pilot for one action family, one initiating workflow, one external boundary, explicit authority conditions, and defined receipt and replay criteria.

PILOT OBJECTIVE

Evaluate the assurance model without granting production effect.

The planned pilot receives a proposed change, establishes custody and declared intent, binds test, security, policy, and review evidence, preserves the separate authority requirement, characterizes the potential change surface, and produces a replayable decision package.

The initial pilot posture is observational. It does not merge, deploy, promote, hold credentials, issue authority, or perform a production mutation.

PILOT EXECUTION BOUNDARY

Shadow-mode contract

NBX-PILOT-GCC-001
MODE
READ-ONLY / SHADOW
MERGE
NOT PERFORMED
DEPLOYMENT
NOT PERFORMED
CREDENTIALS
NOT HELD
AUTHORITY
EXTERNAL / REQUIRED
OUTPUT
REPLAYABLE DECISION PACKAGE

BEST-FIT PILOT

A strong first pilot has a defined consequential boundary.

Pilot conversations are evaluated against a narrow assurance problem. Enrollment, deployment, and production access are not automatic.

One defined consequential action family

One initiating system or workflow

Known evidence and approval sources

One controlled merge, promotion, deployment, or operational boundary

Explicit authority conditions and a bounded change surface

Defined decision-receipt and replay acceptance criteria

PILOT FLOW

A complete object-to-decision path.

The pilot should be narrow enough to evaluate rigorously and complete enough to test the NBX operating model.

01

Proposed change object

Diff, configuration, policy, or infrastructure request.

02

Origin and custody

Repository, actor, tool, and object identity are bound.

03

Declared purpose and plan

The intended outcome and proposed execution path are explicit.

04

Evidence package

Tests, reviews, policies, and security findings are bound to the object.

05

Authority validation

External approval or bounded permission remains separate from evidence.

06

Change-surface classification

Potential mutation and blast radius are characterized.

07

Decision record

The result and unresolved conditions are preserved.

08

Replay package

The decision can be reconstructed without relying on memory or trust.

ACCEPTANCE STANDARD

The pilot is successful only if the decision can be explained and replayed.

A polished interface is not proof. The acceptance criteria are behavioral and evidentiary.

Determinism

Identical canonical inputs produce the same governed result.

Provenance

Every admitted change object has attributable origin and custody.

Authority separation

Tests, model output, reviews, and scanner evidence cannot satisfy authority requirements.

Fail-closed behavior

Missing or malformed mandatory inputs do not become implied permission.

Canonical form

Semantically similar but noncanonical objects are not admitted as equivalent.

Replay

An independent reviewer can reconstruct the decision from preserved artifacts.

PILOT INTAKE

Discuss the action boundary you need to govern.

Useful pilot candidates have a consequential proposed action, known evidence sources, an external approval or authority boundary, and a required audit or replay outcome.