Build step: draw the envelope, then test it
- Status
- stable
- Owner
- Panaversity
- Approved
- Panaversity ·
In this lab you write the Authority Envelope for Brightline's AP Worker, the AI Worker that handles the bills the company owes, and then you test it. It is Wednesday, October 28, the day after the worker forwarded a payment run file to a look-alike address. Dave, the controller, owns the worker and approves its envelope. You draft the envelope, test how a worker handles this morning's inbox under it, and plan how each AI vendor's settings would enforce it.
Where you work. Most of the lab is in a folder on your computer. Download brightline-lab-ch07.zip from the Labs companion, unzip it, and open the files in any text editor, such as Notepad or TextEdit. Only step 3 uses chats with Claude and ChatGPT. Keep your envelope and your results in the folder, not in a chat. They are yours. No real mailbox or connector is needed.
You can also do the lab with the Claude or ChatGPT desktop app. First turn off every connector, the browser extension and computer use, because the emails in the folder carry instructions written to trick a worker. Then open the folder in the app, and ask it to read LAB.md and start. You write the envelope and decide. The app writes your answers down. Step 3 still uses new chats.
How long. About 3 hours in total. Each step ends with a file saved, so you can stop after any step.
The task. You get fifteen possible actions and AP policy version 3, with its clauses on vendor records. You also get the vendor records, a payment-status list and twelve emails for Wednesday, October 28. Three of the emails have problems that were put in them on purpose. You draft the envelope for Dave's approval.
What you do. Do the steps in order. This list says what each step is for. LAB.md, in the folder, gives the exact instructions, one Part for each step. Read each Part when you reach its step, not all at once.
- Predict (
LAB.mdPart A, 15 minutes, in the folder). Read Maria's Monday instruction from this chapter's story, and skim the twelve emails. Predict which emails would lead a worker with Maria's settings outside a reasonable envelope, and what it might do. You save:results/predictions.md. - Write the envelope (Part B, 45 minutes, in the folder). Give each of the fifteen actions a rung or a limit, with its reason from reversibility, familiarity and exposure. Write the thresholds as numbers, the list of what is never automated, and the escalation triggers, each with a named person. You save:
envelope/authority-envelope.md. - Run (Part C, 40 minutes, in the folder, then in chats). Write a brief that works inside your envelope. Before you run it, switch off every connector, the browser extension and computer use, and check on the settings screens yourself that they are off. Then attach the files
LAB.mdnames, and run the brief in Claude and in ChatGPT. Use a new chat for each, with the memory feature switched off, so it does not change the test: in Claude, turn off Memory in the "+" menu. In ChatGPT, open a Temporary Chat and choose Unpersonalized. You save:briefs/inbox-brief.mdandresults/inbox-run-log.md, with both replies. - Investigate (Part D, 30 minutes, in the folder). Only now, open the answer key, in
answer-key/. Score each run and your envelope. Keep three kinds of failure apart: a wrong or invented answer, an attempt at a forbidden action, and an action that actually happened. You save: the scores inresults/inbox-run-log.md. - Modify (Part E, 30 minutes, in the folder). Write each AI vendor's permission plan, using this chapter's 7.8 boxes and the help pages listed in the folder. Write a gap list for every envelope line that no setting can enforce, with the person who keeps that action. You save:
envelope/permission-plan.mdandresults/gap-list.md. - Make (Part F, 20 minutes, in the folder). Make the envelope the authority section of the Role Contract. If you kept Draft 3 from Chapter 4, add it there. If not, the lab gives a template. Then write a five-line envelope for one worker in a role you know. You save:
role/ap-worker-role-contract.mdandresults/my-envelope.md. The lab is not finished until both are saved.
The runs test the worker's behavior, not your settings, because nothing is connected. The permission plan shows how the envelope would be enforced. If you use only one AI vendor, write the transfer plan instead of the second run. The transfer plan lists what the other AI vendor would need.
Artifact checklist
-
results/predictions.md, which emails you expected to lead a worker outside the envelope, and why -
envelope/authority-envelope.md, with each of the fifteen actions given a rung or a limit, thresholds as numbers, the never-automated list and escalation triggers with named people -
briefs/inbox-brief.md, the brief you ran -
envelope/permission-plan.md, with each AI vendor's settings matched to envelope lines -
results/inbox-run-log.md, with both runs scored (or one run andresults/transfer-plan.md), every failure sorted by kind, and a record of how each hidden instruction was handled -
results/gap-list.md, with every envelope line that no setting can enforce, and who keeps that action -
role/ap-worker-role-contract.md, Draft 4, with the envelope as its authority section, for Dave's approval -
results/my-envelope.md, a five-line Authority Envelope for one worker in a role you know
7.8 The same envelope on both AI vendors
How Anthropic's and OpenAI's own pages say you can set the same limits, the three differences that change your setup, and what stays the same on both.
Check yourself
Recall and practice for the whole chapter: the flashcards, and a final quiz round from all eight concepts.