# EX084 complete fictional executive-email evidence packet

This is original teaching material for the OpenMax AI executive email templates guide. Every organization, person, address, message, project, amount, incident and outcome is fictional or synthetic. It is not customer mail, a production mailbox, an OpenMax product test, legal advice, a disclosure decision or an OpenMax performance result. All domains end in `.invalid`. No message was sent.

## P01. Frozen packet contract

| Field | Frozen value |
|---|---|
| Packet ID | EX084 |
| Fictional organization | Meridian Harbor Group |
| Design | 10 independent scenarios, not one recommended sequence |
| Evidence | 40 records, E001–E040; exactly 4 per scenario |
| Drafts | D01–D10; one per template |
| Reviews | R01–R10; one per draft |
| Allowed effects | read these synthetic fields, prepare drafts, identify gaps |
| Forbidden effects | send, approve, pay, sign, disclose, provision access, change records or create commitments |
| Consequential effects observed | 0 |
| Overall disposition | `NOT_SENT` |

## P02. Complete evidence register

Every record is required. “Owner” means the fictional role responsible for confirming that record; it does not grant the model authority.

| ID | Scenario | Frozen evidence | State / owner |
|---|---|---|---|
| E001 | S01 decision | Chief of staff Mira Chen may prepare a decision draft; COO Elias North is the decision owner; recipients are the operating committee at `ops-committee@meridian-harbor.invalid`. | authority / COO |
| E002 | S01 decision | Option A delays all migration 14 days; option B stages low-risk services first; option C requests a 30-day vendor extension. Operations recommends B because rollback evidence exists only for the low-risk group. | options / operations lead |
| E003 | S01 decision | The original response deadline of Sep 10 was corrected to `2026-09-11T16:00:00Z` in decision-log v3. | corrected / program manager |
| E004 | S01 decision | Security review for the higher-risk group remains open. Silence is not approval; no work beyond the low-risk group may begin without a recorded decision. | condition / security owner |
| E005 | S02 status | Approved baseline contains 24 milestones for Project Tern; reporting cutoff is `2026-09-04T18:00:00Z`. | actual denominator / PMO |
| E006 | S02 status | At cutoff: 18 milestones complete, 3 at risk and 3 not started. Counts reconcile to 24. | actual / PMO |
| E007 | S02 status | Baseline launch is Oct 2. Current Oct 9 forecast assumes two interface tests finish by Sep 18; it is not an approved rebaseline or commitment. | forecast / program lead |
| E008 | S02 status | Leadership help requested: assign an interface-test owner by `2026-09-07T15:00:00Z`; next status cutoff is Sep 11 18:00 UTC. | action / sponsor |
| E009 | S03 risk | Supplier certificate renewal evidence has not arrived; current certificate expires `2026-09-20T00:00:00Z`. | observed condition / security operations |
| E010 | S03 risk | Possible event: authentication fails after expiry. Possible consequence: the synthetic partner portal may become unavailable. Neither event nor outage has occurred. | risk, not fact / service owner |
| E011 | S03 risk | Current controls: daily expiry check and tested manual certificate swap. Trigger for escalation is no verified replacement by Sep 14 12:00 UTC. | control / security operations |
| E012 | S03 risk | CISO Dana Vale decides residual-risk acceptance; procurement owns supplier escalation. Requested action is supplier evidence or a recorded contingency decision. | authority/action / CISO and procurement |
| E013 | S04 budget | Approved 2026 pilot budget is USD 240,000 on the management-reporting basis. | baseline / finance controller |
| E014 | S04 budget | Current signed commitments total USD 228,000 on the same basis. | actual / finance controller |
| E015 | S04 budget | Operations requests an additional USD 36,000; recalculated exposure is USD 264,000, USD 24,000 or 10% above baseline. | request/calculation / operations |
| E016 | S04 budget | Proposed funding source is contingency reserve, but it is unapproved. CFO Robin Shah is the approver; no payment or transfer is authorized. | option/authority / CFO |
| E017 | S05 customer | At `2026-09-05T09:00:00Z`, 47 synthetic tenants show the verified access symptom among 2,350 eligible tenants in the monitored scope. | actual numerator/denominator / support lead |
| E018 | S05 customer | `47 ÷ 2,350 × 100 = 2%`. The rate describes tenants in this scope, not users, revenue or all customers. | calculation / analytics owner |
| E019 | S05 customer | Temporary containment is an approved retry path. Root cause is unconfirmed; no restoration time is promised. | current state / incident lead |
| E020 | S05 customer | Account owner Jules Park owns approved customer commitments. Next executive update is `2026-09-05T11:00:00Z`. | authority/time / account owner |
| E021 | S06 board | Board paper `Strategy-Options-v4.pdf`, synthetic hash prefix `84bd01aa`, is the current pre-read for Sep 17. | version / corporate secretary |
| E022 | S06 board | Three questions: investment ceiling, staged-market order and acceptable dependency. Appendix B preserves one director-requested dissenting analysis. | agenda / corporate secretary |
| E023 | S06 board | Authorized recipients are six fictional directors and two named officers through the restricted portal. Forwarding by ordinary email is prohibited. | access / corporate secretary |
| E024 | S06 board | The paper is for discussion; no board consent, vote, minutes or privileged conclusion exists at cutoff. Corrections due Sep 14 17:00 UTC. | authority/time / board chair |
| E025 | S07 alignment | Product, operations, finance and security must confirm the launch-support model by Sep 12 15:00 UTC. | scope/time / program sponsor |
| E026 | S07 alignment | Product, operations and finance confirm. Security objects because privileged-access logging evidence is incomplete. | response states / four function owners |
| E027 | S07 alignment | The governance rule requires all four confirmations for launch; silence and majority are not agreement. | decision rule / program sponsor |
| E028 | S07 alignment | Security owns the missing evidence; next review is Sep 13 14:00 UTC. Launch alignment remains open. | action/state / security lead |
| E029 | S08 policy | Remote Access Policy v5.2 is approved for the fictional workforce; effective Oct 1. | controlling version / policy owner |
| E030 | S08 policy | Change: managed-device registration is required before remote administrative access. Existing emergency exception process remains unchanged. | approved change / security policy owner |
| E031 | S08 policy | Affected audience is workforce administrators in two fictional regions. Regional HR/legal wording review remains required before local distribution. | audience/condition / HR and legal |
| E032 | S08 policy | Authoritative link is `https://policy.meridian-harbor.invalid/remote-access/v5-2`; support route is `access-help@meridian-harbor.invalid`. The email summary does not replace policy. | link/support / policy owner |
| E033 | S09 incident | Synthetic incident INC-084 began 13:02 UTC; degraded service ended 13:33 UTC, a 31-minute interval. | verified timing / incident commander |
| E034 | S09 incident | At 13:40 UTC, service checks passed in three defined regions; enhanced monitoring remains active. | verified state / service owner |
| E035 | S09 incident | Root cause remains under investigation. No attribution, disclosure materiality decision or recurrence promise has been made. | unknown/boundary / incident and legal owners |
| E036 | S09 incident | Internal recipients are the response leadership list. Next update is 15:00 UTC; external wording requires communications and legal approval. | recipients/time / incident commander |
| E037 | S10 recap | Meeting M084 on Sep 8 had an authorized chair and eight attendees. Approved record contains four decisions, six actions and two no-decisions. | scope/counts / meeting chair |
| E038 | S10 recap | Each of six actions has one present owner and UTC due time in action-register v2. No absent person is assigned. | commitments / action owners |
| E039 | S10 recap | The two no-decisions concern vendor choice and public launch date; both remain open. | state / decision owners |
| E040 | S10 recap | Corrections are due Sep 9 16:00 UTC. Silence preserves the record as written but does not create any new approval or commitment. | correction rule / meeting chair |

Reconciliation: E001–E040 are unique and contiguous. Each scenario has exactly four records. The register contains synthetic source statements, not evidence about a real organization.

## P03. Ten filled fictional drafts

The citations are working references for reviewers; a production message may use approved links or footnotes appropriate to its audience. None of these messages was sent.

### D01 — decision request

**From:** Mira Chen, for COO review
**To:** `ops-committee@meridian-harbor.invalid`
**Subject:** Decision required by Sep 11 16:00 UTC — migration sequence

Operations recommends option B: migrate the low-risk service group first and hold the higher-risk group. Option A delays all work 14 days; option C requests a 30-day extension. Only option B currently has rollback evidence for its proposed scope [E002]. Security review for the higher-risk group remains open [E004].

Elias North is the decision owner. Please record A, B or C in decision-log v3 by Sep 11 16:00 UTC [E001,E003]. Silence is not approval, and no higher-risk migration is authorized by this request [E004].

### D02 — executive status update

**Subject:** Project Tern status through Sep 4 — 3 of 24 milestones at risk

At the Sep 4 18:00 UTC cutoff, 18 of 24 baseline milestones are complete, 3 are at risk and 3 have not started [E005,E006]. The baseline launch remains Oct 2. Oct 9 is a forecast, conditional on two interface tests completing by Sep 18; it is not an approved rebaseline or commitment [E007].

The sponsor is asked to name the interface-test owner by Sep 7 15:00 UTC. The next status cutoff is Sep 11 18:00 UTC [E008].

### D03 — risk escalation

**Subject:** Action required — certificate evidence may affect portal availability after Sep 20

Replacement-certificate evidence has not arrived; the current supplier certificate expires Sep 20 00:00 UTC [E009]. If no valid replacement is installed, authentication could fail and the partner portal could become unavailable. Neither failure nor outage has occurred [E010].

Daily checks and a tested manual swap are active. Procurement must obtain verified replacement evidence by Sep 14 12:00 UTC or request a recorded contingency decision [E011,E012]. Dana Vale retains residual-risk acceptance authority; this email does not accept the risk.

### D04 — budget exception request

**Subject:** Approval request — USD 36,000 exception for the pilot

The approved pilot budget is USD 240,000 and current signed commitments are USD 228,000 on the same management-reporting basis [E013,E014]. Operations requests USD 36,000, producing total exposure of USD 264,000. That is USD 24,000, or 10%, above baseline [E015].

Contingency reserve is a proposed funding source, not an approved transfer [E016]. Robin Shah is asked to approve, reject or return the request for evidence. This draft authorizes no transfer, purchase or payment.

### D05 — customer issue briefing

**Subject:** Customer access issue — 47 of 2,350 scoped tenants as of 09:00 UTC

At Sep 5 09:00 UTC, 47 synthetic tenants among 2,350 eligible tenants in the monitored scope showed the verified access symptom: 2% of that defined population [E017,E018]. The approved retry path is available. Root cause is unconfirmed, and no restoration time has been promised [E019].

Jules Park owns approved customer commitments. The next executive update is 11:00 UTC [E020]. Do not reuse this internal briefing as external customer wording.

### D06 — board pre-read note

**Subject:** Pre-read for Sep 17 — strategy options discussion

The current restricted pre-read is `Strategy-Options-v4.pdf` [E021]. Please focus on the investment ceiling, staged-market order and acceptable dependency. Appendix B retains the dissenting analysis requested for discussion [E022].

Access is limited to the six listed directors and two named officers through the restricted portal; do not forward by ordinary email [E023]. Corrections are due Sep 14 17:00 UTC. This paper records no board consent, vote, minutes or privileged conclusion [E024].

### D07 — cross-functional alignment request

**Subject:** Alignment requested by Sep 12 15:00 UTC — launch-support model

Product, operations and finance have confirmed the proposed support model. Security has not: it records an explicit objection because privileged-access logging evidence is incomplete [E025,E026]. The approved rule requires all four confirmations, so alignment remains open; three responses do not constitute consensus [E027].

Security owns the missing evidence. Review resumes Sep 13 14:00 UTC [E028]. No launch approval is implied by this request or by silence.

### D08 — policy change announcement

**Subject:** Remote Access Policy v5.2 effective Oct 1 — administrator action

Approved policy v5.2 requires managed-device registration before remote administrative access. The existing emergency exception process is unchanged [E029,E030]. Workforce administrators in the two named regions are affected; distribution waits for required regional HR/legal wording review [E031].

After local approval, use the authoritative policy link and contact `access-help@meridian-harbor.invalid` for support [E032]. This summary does not replace the policy text or create a new exception.

### D09 — incident update

**Subject:** INC-084 update at 13:40 UTC — service restored, monitoring active

Synthetic degradation ran from 13:02 to 13:33 UTC, a 31-minute interval [E033]. At 13:40, defined service checks passed in three regions; enhanced monitoring remains active [E034]. Root cause is still under investigation. No attribution, disclosure materiality conclusion or recurrence promise exists [E035].

This update is for the response leadership list. The next internal update is 15:00 UTC; any external wording requires communications and legal approval [E036].

### D10 — post-meeting commitment recap

**Subject:** Decisions and actions — M084 on Sep 8

The approved record contains four decisions, six actions and two no-decisions [E037]. Action-register v2 assigns each action to one owner who attended and gives an exact UTC due time; no absent person is assigned [E038]. Vendor choice and public launch date remain open and are not decisions [E039].

Please submit factual corrections by Sep 9 16:00 UTC. Silence preserves this record version but creates no new approval or commitment [E040]. Use the decision and action registers—not this summary alone—as the controlling records.

## P04. Complete send-review register

Every review record evaluates the corresponding draft against its frozen scenario. “PASS” means the synthetic fields reconcile, not that a qualified professional approved a real message.

| Review | Draft | Evidence set | Outcome/cutoff/evidence/owner/time present | Main specialist still required | Effect count | Disposition |
|---|---|---|---|---|---:|---|
| R01 | D01 | E001–E004 | PASS | security and authorized decision owner | 0 | NOT_SENT |
| R02 | D02 | E005–E008 | PASS | PMO and sponsor | 0 | NOT_SENT |
| R03 | D03 | E009–E012 | PASS | security, procurement and CISO | 0 | NOT_SENT |
| R04 | D04 | E013–E016 | PASS | finance/CFO | 0 | NOT_SENT |
| R05 | D05 | E017–E020 | PASS | support, incident, account and legal as applicable | 0 | NOT_SENT |
| R06 | D06 | E021–E024 | PASS | corporate secretary, board chair and counsel | 0 | NOT_SENT |
| R07 | D07 | E025–E028 | PASS | four functional owners | 0 | NOT_SENT |
| R08 | D08 | E029–E032 | PASS | policy, regional HR/legal and security | 0 | NOT_SENT |
| R09 | D09 | E033–E036 | PASS | incident, communications and legal | 0 | NOT_SENT |
| R10 | D10 | E037–E040 | PASS | meeting chair and action/decision owners | 0 | NOT_SENT |

## P05. Reproducible packet checks

- Evidence count: `10 scenarios × 4 records = 40`; E001–E040 are present once each.
- Draft count: D01–D10 = 10.
- Review count: R01–R10 = 10.
- Template coverage in this teaching packet: `10 ÷ 10 × 100 = 100%`.
- S02 milestone reconciliation: `18 + 3 + 3 = 24`.
- S04 exposure: `USD 228,000 + USD 36,000 = USD 264,000`.
- S04 variance: `USD 264,000 − USD 240,000 = USD 24,000`; `24,000 ÷ 240,000 × 100 = 10%`.
- S05 impact: `47 ÷ 2,350 × 100 = 2%`.
- S09 interval: 13:02 through 13:33 UTC = 31 minutes.
- Filled bracket placeholders: 0.
- Consequential effects: 0.
- Final disposition for every draft and the packet: `NOT_SENT`.

## P06. Production rejection rules

A production preflight should reject any draft that contains `EX084`, `Meridian Harbor`, `.invalid`, D01–D10 teaching IDs, unresolved square-bracket placeholders, an unknown recipient, an inaccessible attachment, an unreviewed specialist claim, or an evidence version older than the draft's declared cutoff. It should also stop when send state is uncertain to prevent duplicates.

## P07. Primary-source boundaries

- [OpenMax AI business email assistant](https://openmax.com/resources/use-cases/ai-business-email-assistant/) supports the narrow approved-thread, permitted-fact, draft, review, send-control and follow-up workflow described in the article. EX084 is not an OpenMax test.
- [OpenMax AI agent platform](https://openmax.com/resources/solutions/ai-agent-platform/) provides official platform context. No unverified integration is claimed here.
- [NIST AI RMF Generative AI Profile](https://www.nist.gov/publications/artificial-intelligence-risk-management-framework-generative-artificial-intelligence) supports confabulation, information-integrity, privacy, security and lifecycle risk framing; this is not a conformity claim.
- [OWASP Prompt Injection](https://genai.owasp.org/llmrisk/llm01-prompt-injection/) supports treating embedded external instructions as untrusted content rather than authority.
- [NIST SP 800-61 Rev. 3](https://csrc.nist.gov/pubs/sp/800/61/r3/final) supports planned incident-response coordination and communication with appropriate stakeholders.
- [U.S. SEC cybersecurity disclosure rule](https://www.sec.gov/rules-regulations/2023/07/s7-09-22) is a jurisdiction-specific public-company reference. EX084 makes no materiality or disclosure determination.
- [U.S. FTC CAN-SPAM business guide](https://www.ftc.gov/business-guidance/resources/can-spam-act-compliance-guide-business) is a jurisdiction-specific commercial-email reference. It is not generalized as global law.
