Degraded primary uplink
A minimal failover with cited evidence, a bounded blast radius, verification steps, and a complete rollback.
ChangeSafe treats model output as untrusted, typed data. Pure policies validate every proposal, a human makes the decision, and every outcome becomes a verifiable receipt—without touching real infrastructure.
Six synthetic scenarios. No API key required. No infrastructure connection exists.
Fail over the primary uplink
Safety passed. Authority remains with the human reviewer.
Incident context is attacker-influenceable. An alert, operator note, or pull request can carry an injected instruction—and a model can repeat it with perfect confidence.
ChangeSafe makes resistance to persuasion irrelevant. The model's prose is reduced to typed data that must survive deterministic policy and an explicit human decision.
Confidence is displayed.DESIGN INVARIANT / 01
It is never used.
Every transition is explicit. Any BLOCK closes the airlock before approval or simulation can exist.
Structured output is locally re-validated. Unknown evidence and resources are rejected before the gate.
UNTRUSTED INPUTSeven pure policies return PASS, WARN, or BLOCK. Confidence, urgency, and eloquence have no vote.
FAIL CLOSEDA proposal with no BLOCK can be approved or rejected. Any BLOCK makes approval impossible at the domain layer.
NO AUTO-APPROVALAllowlisted operations apply transactionally to synthetic state, then safety properties and rollback are re-checked.
NOTHING REALCanonical JSON and SHA-256 hashes preserve an integrity trail for approved, rejected, and blocked outcomes.
VERIFY, DON'T TRUSTThe gate evaluates the proposed action, not the model's tone. Safe work stays a human choice. Unsafe work stops.
A minimal failover with cited evidence, a bounded blast radius, verification steps, and a complete rollback.
A confident proposal follows an instruction hidden in operator notes and would sever protected management reachability.
The portfolio story is backed by a public implementation, scenario contracts, and an extracted core that carries no network assumptions.
Inspect the repositoryEvery verdict path, from LOW approvable to CRITICAL blocked.
Ordered, fail-closed, and isolated from the AI layer.
The P2 exit gate across core, domain, application, and E2E.
Canonical hashes for input, proposal, and every outcome.
Probabilistic reasoning can propose. Only deterministic code can gate. Only a human can approve.
core → domain adapter → applicationAI modules never enter policy code.Read the architectureChangeSafe demonstrates a safety architecture. It does not pretend a synthetic network model is production infrastructure.
Current receipts prove integrity, not authorship or non-repudiation.
The synthetic sandbox never contacts real infrastructure and is not a production routing model.
The current showcase is single-user, without authentication or durable persistence.
The demo runs in replay mode with synthetic data, no API key, and no path to real infrastructure.