# Field-pilot protocol

This protocol turns the playbook into a bounded field exercise without turning
one observation into a universal claim. The interactive site prepares a local
draft; it does not submit data or admit a report to the public registry.

Version 0.3 does not begin with the first field report. It uses public studies
and the transfer engine to preregister a low, central, and high hypothesis. The
pilot then measures the gap. Extrapolation, local measurement, and the
recalibrated result remain three distinct objects in the same learning cycle.

## 1. Frame the pilot

Before live observation, record:

- a non-identifying project alias and one exact workflow;
- organization type, sector overlay, work mode, architecture, exact A0–A4
  action boundary, and system version;
- manual baseline, full request denominator, eligibility rule, exclusions, and
  preregistered thresholds;
- transferable sources, their comparability contract, the planned net range,
  retained human work, and amortized setup;
- allowed effects, required approvals, stop authority, fallback, and evidence
  location.

Do not start when the owner, baseline, evaluation set, safe fallback, or
critical stop rule is missing.

## 2. Observe the complete denominator

Run the frozen evaluation set first, then shadow mode, then only the bounded
live level that passed its gates. Retain every request in the denominator,
including ineligible, refused, failed, escalated, and withdrawn cases.

Record accepted outcome, human active time, corrections, critical effects,
eligibility, approvals, tool effects, read-backs, incidents, and missing traces.
Model activity is not a business outcome.

Compare the whole-workload result with the preregistered range. Record whether
it falls below, within, or above the range, then explain the gap. An observation
outside the range is recalibration evidence, not a reason to silently rewrite
the original hypothesis.

## 3. Prepare a private draft

Use the [field-feedback template](../templates/field-feedback-report.md). Keep
raw evidence access-controlled. The draft must distinguish direct observation,
internal measurement, estimate, opinion, and supplier claim.

Do not place client data, identities, secrets, privileged material, raw prompts,
or exploitable security detail in a public issue or repository. Agree a private
review channel before transferring any report or evidence.

## 4. Review independently

A person who did not author the conclusion checks provenance, system and
workflow version, baseline, denominator, missing cases, incident accounting,
redaction, residual re-identification risk, transfer limits, publication
authority, and withdrawal route.

Passing this review makes the draft eligible for an admission decision. It does
not make the result representative of another organization or workflow.

## 5. Admit or withhold

Only a reviewed and anonymized report that meets every
[registry admission rule](../field-notes/README.md) may be added to
`field-notes/index.json`. Otherwise keep it private, request corrections, or
withhold publication. Synthetic cases remain under `examples/` and never count
as field evidence.

## Minimum first cohort

The [first cohort](field-pilot-cohort.md) targets at least three admitted
reports: one non-agentic or copilot workflow, one bounded A2 business agent,
and one distinct Swiss or EU context. An orchestrated-agency candidate is
welcome only when a genuine system can be compared with a simpler design; it is
not required. Implementation effort and failed or excluded cases remain
visible. This is a learning target, not a statistical validation claim.
