This guide supports workshop, funder, and lab pilots of SCOPE 2.2 with institutional AS hardening (AS-01..AS-08). Start here for workshop flow; use runbooks/ for operator procedures and definition_of_done.md for claim boundaries.
In-repo: frozen review packets, independence evidence, review_mode gates,
institutional grant bindings, runtime evidence, append-only outcomes, quality
aggregates with denominators, and offline chain reconstruction.
External (not claimed): live IdP certification, WORM Object Lock retention, remote ledger authority, scientific correctness, or reviewer honesty/competence.
- Packet freeze / action chain —
content_revision, digests,action_chain_id— migration_action_chain.md - Reviewer independence evidence on production / execution-adjacent paths — migration_reviewer_independence.md
review_modeenforcement — shadow / read-only cannot issue grants — migration_review_mode.md, pilot_sequence.md- Institutional grant hardening — chain, digests, environment, revocation — migration_grant_hardening.md
- Runtime evidence + PF/PCS refs — migration_runtime_evidence.md
- Append-only outcomes / reflections — migration_outcome_feedback.md
- Quality metrics v3.0 (process/calibration proxies only) — quality_metrics.md
- AKTA one-shot / session path — akta_review_contract.md
- Identity / signing assurance — identity_assurance.md, signing_assurance.md
- Use SCOPE for structured review coordination and bounded grants
- Treat rendered packets and PCS exports as audit artifacts, not certifications
- Keep reviewer keys local; distribute public keys to auditors only
- Enable production mode (
SCOPE_PRODUCTION_MODE=true) for grant enforcement - Advance stages per pilot_sequence.md; do not replay shadow decisions into mode 5
- AKTA evaluation — Present a scientific action; AKTA emits record + review trigger
- SCOPE packet —
scope packet createorscope akta reviewfor one-shot packet/decision/grant - Review — Reviewers read rendered packet (permits/denies, checklist, warnings)
- Decision —
scope decision submitwith independence block when required - Sign —
scope decision signwith pilot reviewer key - Grant —
scope grant issuewith signed decision (mode 4/5 only) - Verify —
scope verify --public-keyfor auditor demonstration - Export / reconstruct — PCS bundle; offline gates for custody demo
Sample artifacts: examples/institutional_pilot/. Full-stack AS-08 reconstruction fixture: examples/institutional_pilot_as/. Operator runbooks: runbooks/. Offline gates:
python scripts/run_institutional_offline_gates.pyv0.8 pilot pack (historical scenarios): examples/pilot/.
Use persistent session storage so votes survive process restarts:
scope review session create --packet packet.json --out session.json \
--session-store json --session-dir ./pilot_sessionsCollect votes from required roles, then issue grant from session under an authorizing
review_mode.
Export quality report from ledger:
scope quality report --ledger pilot_events.jsonl --out quality_report.json \
--queue-dir .scope/queuesReport includes reviewer metrics, warnings, queue counts, and event counts. Metrics describe process quality and calibration proxies — not scientific validity. See quality_metrics.md.
- Policy YAML reviewed and version-pinned
- Reviewer roles mapped to lab personnel
- Ed25519 keypairs generated per reviewer role; public keys registered
- Authorization manifest signed for production mode
-
review_modechosen deliberately (default production: read-only) - PF-Core runtime configured to enforce grant obligations
- Ledger path configured (
SCOPE_LEDGER_PATHor Postgres DSN) - Ledger delivery mode set for institutional risk tolerance
- Session store directory secured (if using json/sqlite)
- Offline gates green:
python scripts/run_institutional_offline_gates.py - Pilot limitations documented to participants (no live IdP/WORM claims)
See limitations.md. Pilots should not rely on SCOPE for full enterprise IdP, live directory sync, biosecurity clearance, or clinical oversight.
- runbooks/ — deployment, identity, keys, review ops, incident/revoke
- adr/0010-institutional-pilot-release-boundaries.md — AS-08 claim boundary
- pilot_sequence.md — staged deployment
- reviewer_guide.md — role-specific guidance
- trusted_boundary.md — trust assumptions
- akta_scope_demo.md — full cross-repo demo
- key_management.md — key registry workflow