Skip to content
PROJECT SHADOW 1.0.1 · CORRECTED R1 REFERENCE · PRELIVE · 2026-08-17

Project Shadow 1.0.1 contains no Myth package. Generic Myth v0.2.0 and Full-Canon Myth v0.3.5 are separate optional companions; both default off, neither is required by R1, and neither can authorize action or change an R1 result. PBHP remains in active testing; publication is not certification, independent validation, or deployment authorization.

IMPAdoption · roles · integration

Install a pause that can survive contact.

Adoption is not copying a prompt. It assigns authority, instruments the decision path, trains operators, binds receipts, creates challenge and repair loops, and proves that the protocol does not disappear when pressure rises.

12weeks in the supplied pilot
6minimum accountable roles
3integration patterns
LONG-FORM COMPANION

The field manual keeps the explanation visible.

Read the argument, numbered procedure, worked cases, failure contrasts, and evidence state behind this chamber.

Read the full chapter →
IMP / 01

Choose the operating form

The same discipline can live in human procedure, an AI interaction, or executable runtime—but the controls and evidence differ.

HUMAN

Decision review pattern

A facilitator runs the sequence in a meeting, case review, editorial desk, clinical workflow, civic process, or incident response.

The durable artifacts are the canonical action, stakeholder map, gate, dissent, Door, owner, and receipt. The facilitator is responsible for preventing status or time pressure from skipping least-powerful-first review.

ASSISTIVE AI

Conscience overlay

A model surfaces missing stakeholders, unknowns, alternatives, power asymmetry, and receipt fields without claiming final authority.

The host system's safety rules remain controlling. PBHP may add caution or route to a human; it may not relax platform safeguards, invent permissions, or present generated classifications as independent evidence.

RUNTIME

Deterministic gate

Structured inputs produce typed states, named floors, evidence bindings, and a write-ahead decision receipt.

Executable integration needs schema validation, provenance states, policy pins, refusal behavior, audit logging, challenge handling, version identity, and tests for action mutation and gate shopping.

  • Fail closed on missing load-bearing fields.
  • Separate declared values from attested evidence.
  • Require explicit human ownership for consequential execution.
IMP / 02

Assign real ownership

A protocol without authority and repair roles becomes theater.

DECISION OWNER

Own the act

Defines the exact action, supplies authority, accepts the gate, and remains accountable for consequences.

The owner may not delegate moral or legal responsibility to the facilitator, model, checklist, or approval interface.

PROTOCOL OPERATOR

Run the sequence

Maintains the action frame, routes missing expertise, records the receipt, and stops silent step-skipping.

The operator needs independence from the delivery pressure surrounding the action. If the operator can be overridden without a trace, the installation is cosmetic.

REVIEW + CHALLENGE

Attack and appeal

An independent reviewer red-teams higher gates; affected parties receive a meaningful challenge or appeal path.

Challenge must be accessible to people with less power, not only executives or engineers. Response times, stop authority, and anti-retaliation protections are part of the control.

STEWARD + CAPA

Maintain the system

A steward owns versions, calibration, training, thresholds, open questions, incidents, and corrective action.

The steward publishes changes, preserves old receipts against their original version, and verifies that fixes close the failure that triggered them.

IMP / 03

Adopt in four phases

Start narrow, make claims testable, and expand only after the organization demonstrates that the pause works under real pressure.

PHASE 01

Scope and map

Select one consequential decision class; map authority, stakeholders, irreversible paths, existing controls, and current failure evidence.

Do not begin with an enterprise-wide promise. Choose a workflow where receipts can be inspected and outcomes can be followed without exposing people to an unreviewed intervention.

PHASE 02

Dry-run and calibrate

Run historical and synthetic cases, include obvious passes and traps, and compare independent operators.

Measure agreement, missed harms, unnecessary pauses, Door quality, time cost, and whether least-powerful stakeholders were actually represented.

PHASE 03

Bounded pilot

Deploy with human ownership, explicit stop conditions, observation-only comparison, incident response, and scheduled review.

A pilot should specify what cannot be automated, what evidence is collected, who can halt it, and how affected people can challenge a decision.

PHASE 04

Govern and expand

Scale only after calibration, CAPA, version control, independent review, and evidence of benefit in the original scope.

Expansion is a new action and receives a new pause. A successful pilot does not authorize broader populations, higher stakes, new data, or new decision rights by analogy.

IMP / 04

Compare without borrowing authority

PBHP can map to established governance and quality practices, but a crosswalk is not certification or endorsement.

QUALITY SYSTEMS

CAPA, change control, traceability

PBHP imports disciplined habits from regulated quality systems: typed defects, root cause, corrective action, preventive control, verification, and records.

Those mechanisms improve maintainability and auditability. They do not make a non-medical system FDA-compliant or transfer the authority of any regulated domain.

AI GOVERNANCE

Risk, measurement, and accountability

The protocol can complement organizational risk frameworks by binding abstract principles to the exact action and least-powerful stakeholder.

Standards mappings are alignment views until the applicable official process is performed by qualified parties in the actual deployment context.

SECURITY + SAFETY

Threats, abuse, and stopping rules

Red teams, provenance, hostile-input handling, least privilege, rollback, and independent stop authority connect ethical review to operational controls.

A security success cannot cancel a rights or dignity failure; a humane intention cannot cancel an exploitable system. Independent floors remain independent.

IMP / 05

The supplied 90-day pilot

A real adoption test starts small enough to observe, compare, and stop. The dated playbook provides a twelve-week sequence rather than an enterprise promise.

WEEKS 01–02

Learn and baseline

Read the executive summary and CORE material, then rerun three to five recent consequential decisions retrospectively.

Record where PBHP would have changed the action, where it would not, and where the answer remains unclear. This establishes a local baseline without exposing anyone to a live uncalibrated intervention.

  • 3–5 retrospective receipts
  • One-page findings summary
  • Named workflow and accountable champion
WEEKS 03–06

Run MIN live

Teach the shortest viable pause and use it on the team's own high-stakes decisions for three weeks.

Track number of checks, time per check, gate distribution, challenged pauses, false positives, and weekly team feedback. The objective is habit and burden measurement—not a flattering adoption story.

WEEKS 07–10

Graduate YELLOW+ to CORE

Add the full harm map, constraint awareness, power analysis, alternatives, drift detection, and receipt discipline.

Compare MIN-only results with CORE outcomes. Measure override, Door quality, drift alarms, missing stakeholders, and whether the higher tier changes decisions that actually carry more consequence.

WEEKS 11–12

Adopt, adapt, or abandon

Review the evidence and choose a real disposition instead of automatic graduation.

Adopt when the workflow demonstrates value. Adapt with documented deviations and retesting. Abandon when burden outweighs benefit in the tested scope—and preserve why so the protocol can learn.

  • Pilot report
  • Metrics and adverse cases
  • Integration, revision, or retirement plan
IMP / 06

Govern the protocol itself

The supplied governance charter treats PBHP as a maintained, versioned system whose changes must remain reviewable.

CHANGE CONTROL

Version behavior—not just prose

Major changes alter architecture or authority; minor changes refine mechanisms; patches clarify without changing the decision contract.

A proposal names the affected sections and rationale, receives review, records the decision, updates the changelog, and preserves migration guidance. A silent semantic edit is a protocol defect.

LOCAL ADAPTATION

Tailor openly

An organization may calibrate thresholds, triggers, terminology, and workflow to its domain, but every deviation remains documented.

Local tailoring does not authorize removal of the core question, least-powerful-first ordering, challenge path, drift detection, or write-ahead record. A local edition must identify itself rather than impersonating the canonical release.

NON-NEGOTIABLES

Keep the immune system

Power-aware escalation · concrete Door · false-positive challenge · drift alarms · decision record.

These mechanisms keep the pause proportional, contestable, repairable, and resistant to wear-down. Removing one may create a useful checklist, but it should not be represented as the same protocol.

  • Review at least annually.
  • Open incident-triggered review when the protocol should have caught a serious failure.
  • Bind every receipt to the exact policy version used.
THE ADOPTION TEST
If the pause disappears when the deadline, hierarchy, or revenue pressure arrives, it was never installed.