Skip to content
PROJECT SHADOW 1.0.1 · CORRECTED R1 REFERENCE · PRELIVE · 2026-08-17

Project Shadow 1.0.1 contains no Myth package. Generic Myth v0.2.0 and Full-Canon Myth v0.3.5 are separate optional companions; both default off, neither is required by R1, and neither can authorize action or change an R1 result. PBHP remains in active testing; publication is not certification, independent validation, or deployment authorization.

RSKHarm model · thresholds · alternatives

Worst binding state wins.

PBHP refuses to let severe harm disappear inside an average. It rates impact, likelihood, reversibility, and power, then binds the action to the most restrictive credible floor.

5deterministic harm gates
4core risk fields
4time horizons
LONG-FORM COMPANION

The field manual keeps the explanation visible.

Read the argument, numbered procedure, worked cases, failure contrasts, and evidence state behind this chamber.

Read the full chapter →
RSK / 01

Build the harm picture

Classification begins with reality, not the proposed action's sales pitch.

BASELINE

Status quo harm is not zero

Inaction is an option with consequences, not a neutral comparison point.

The baseline review names current harms, historical analogs, existing distributions of power, and the people already paying. This prevents the protocol from preserving a violent status quo merely because intervention also carries risk.

  • Historical Analog Scan
  • Status Quo Harm Audit
  • Immediate: 0–72 hours
  • Near: 1–12 weeks
  • Medium: 3–24 months
  • Long: 2–10+ years
CASCADE

Autonomy can fail in sequence

A chain of individually modest actions can end in irreversible dependence or exclusion.

The accumulation gate evaluates the entire path: job loss can trigger eviction, credit collapse, healthcare loss, family separation, or coercive debt. If the chain terminates in irreversible or power-asymmetric harm, the sequence is ORANGE at minimum even when each step was labeled GREEN.

  • Map upstream trigger and downstream dependencies.
  • Identify the earliest point where a Door can break the chain.
  • Do not distribute one chain across departments to evade ownership.
DRIFT

Imagine the less ethical operator

A safe-looking use can become an abuse template, precedent, permanent system, or adjacent capability.

Drift review asks how the action changes when copied by a less careful actor, used outside the initial audience, stripped of mitigations, expanded after a crisis, or retained after its sunset.

  • Repurposing
  • Precedent
  • Permanence
  • Moral hazard
  • Taboo weakening
  • Trust erosion
RSK / 02

Rate without laundering

The four fields are recorded separately so a convenient aggregate cannot conceal the dimension that actually binds.

IMPACT

Magnitude

Trivial · Moderate · Severe · Catastrophic

Impact describes what happens if the harm occurs, including physical, autonomy, dignity, livelihood, institutional, and long-horizon consequences. Catastrophic outcomes receive scrutiny even when probability estimates are weak.

LIKELIHOOD

Plausibility

Unlikely · Possible · Likely · Imminent

Likelihood is not a license to round an uncomfortable low-probability catastrophe to zero. Evidence quality, uncertainty source, base rates, and inference distance remain visible beside the estimate.

IRREVERSIBILITY

Recovery and exit

Can the harmed party recover, appeal, opt out, or restore what was lost?

Rollback for the operator is not the same as repair for the stakeholder. Deleting a model output does not undo a denied benefit, public accusation, broken trust, or missed medical window.

POWER

Who controls the terms

Power gap increases the burden on the actor who can move.

Representation, consent, appeal, dependency, surveillance, coercion, and decision-maker insulation determine whether a nominal choice is meaningful. Large gaps escalate rigor and gate.

  • Who may refuse?
  • Who may leave?
  • Who owns the appeal?
  • Who remains insulated if wrong?
RSK / 03

Bind the action

A gate is a required action state, not a mood or recommendation color.

GREEN / YELLOW

Proceed or mitigate

GREEN stays inside tested scope. YELLOW proceeds only with named mitigations, monitoring, and ownership.

A GREEN decision still receives a receipt when consequential. YELLOW requires each mitigation to have an owner, verification method, failure response, and review date—not a vague promise to be careful.

ORANGE

Constrain

Reduce capability, users, tools, data, duration, or deployment context; require at least a D2-quality Door.

ORANGE is not a softer proceed. It changes the action until the irreversible path is broken, adds independent review, and records why safer alternatives were accepted or rejected.

RED / BLACK

Refuse, delay, or refuse absolutely

RED requires repair and recheck. BLACK cannot be pierced by urgency or break-glass rhetoric.

A RED action may return only after the failed premise changes and the evidence is independently reassessed. BLACK binds the assessed action absolutely. Rewording or decomposing an action to obtain a friendlier result is protocol drift.

  • No aggregate override
  • No gate shopping
  • No silent action mutation
  • No emergency waiver through an absolute floor
ALTERNATIVES

Least-powerful-first search

Prefer the safer action unless a documented reason shows it cannot meet the legitimate need.

The alternative search is lexicographic: first protect the people with the least power, then optimize within that protected set. This blocks arithmetic that treats ruining a smaller group as an acceptable cost of helping a larger one without exhausting safer Doors.

THE BINDING RULE
A clean average cannot erase a catastrophic, irreversible, or power-asymmetric floor.