# Six fictional AI project risk records — evidence and decision packet

OpenMax editorial teaching material, 2026-09-04. All records, evidence IDs, roles and decisions below are invented for instruction. No actual customer incident, control test, acceptance, product result or professional approval is claimed. The test notes describe fictional evidence; they are not files retrieved from an actual organization.

## Common agreement and demonstration policy v1

Pilot: internal support-assistant project v0.4. Horizon ends 2026-01-31. Snapshot: 2026-01-15T00:00:00Z. All deadlines below are UTC. A deadline earlier than the snapshot is overdue only if the action is still open. Risk scope includes proposed capabilities under review; a hold is a routing decision and not a substitute for assessing the underlying risk. No automatic live writes are authorized by this packet.

Qualitative likelihood: Unlikely = unusual conditions needed under stated controls; Plausible = credible route under pilot conditions; Expected = conditions warrant planning for occurrence during the horizon; Unknown = insufficient evidence. Impact: Minor = locally reversible inconvenience; Material = meaningful customer or operational harm; Severe = consequence requiring specialist escalation in this fictional policy. These labels have no numerical probability meaning.

Lookup matrix, rows Unlikely/Plausible/Expected, columns Minor/Material/Severe:

| Likelihood | Minor | Material | Severe |
|---|---|---|---|
| Unlikely | Low | Moderate | High |
| Plausible | Moderate | Moderate | High |
| Expected | Moderate | High | High |

Unknown input → Unassessed, never Low or zero. A severe potential consequence still requires escalation when likelihood is unknown. Priority does not authorize use. This policy is invented; no NIST endorsement or legal adequacy is claimed. Inherent baselines are not required by this fictional pilot policy and remain Not assessed, with this reason recorded for all six records. Current ratings consider stated existing controls. Targets are forecasts. Validation must identify its scope and limitations before reassessment.

## R01 — unauthorized CRM writes

Scope: proposed CRM write capability. Because permission review is incomplete, an agent might change a record outside the intended task, exposing customers to an unauthorized business action. Category: unauthorized action; affected groups: customers and account operators. Evidence E01, 2026-01-14, review note v1: connector permissions have not been completely inventoried; no designated incumbent has accepted risk ownership. This supports uncertainty, not a finding that a real unauthorized write occurred.

Existing condition: write capability is on hold pending review; no effectiveness claim about a technical permission boundary. Assumption: inventory can establish all relevant write routes; still unverified. Current assessment by fictional project-review role Jan14: likelihood Unknown, impact Severe, priority Unassessed under v1. Lifecycle Active. Risk owner unassigned; sponsor is escalation contact, not an invented accepted owner.

Action A01: project sponsor assigns and obtains confirmation from an accountable risk owner, due 2026-01-16T23:59:00Z; Open; no completion evidence. This assignment action does not itself fix permissions. Target not established until scope/evidence review. Validation not run. No acceptance. Review on assignment or new permission evidence; keep affected writes on hold. No closure.

## R02 — obsolete price replies

Scope: price-related draft replies. Because expired documents remain in the candidate collection, an assistant could draft outdated terms, causing incorrect customer commitments. Category: information quality; affected groups: customers and support staff. Evidence E02, Jan13, retrieval review v1: an expired document appears in candidate results. Source restriction currently excludes price replies from permitted use, and human review remains required for other drafts; the full correction has not been completed. The restriction is not claimed to validate a corrected collection.

Current assessment by fictional support-review role Jan13: Plausible / Material → Moderate, policy v1, Active. Risk owner: support lead, confirmation Jan13. Assumption: approved current-price corpus exists; content owner must verify before restoring price replies. Action A02: knowledge-base editor removes expired sources and submits corrected retrieval evidence; due 2026-01-14T23:59:00Z; Open. At snapshot it is one minute overdue, not one day. Completion evidence absent.

Target Unlikely / Material → Moderate after corrected-source validation; same priority band does not mean work has no value. Validation Not run. No acceptance. Next review Jan15; escalate overdue action and maintain restriction pending evidence. No closure. No second open action is created implicitly by this packet; future work must receive its own ID when assigned.

## R03 — confidential prompt disclosure

Scope: prompt-input routes in the pilot. An alternate route could bypass a filter and disclose confidential text. Category: confidentiality; affected groups: data subjects and business information owners. Risk owner: security lead, confirmation Jan10. Existing filter covers the primary route, but alternate-route effectiveness is not established. Assumption that both routes are protected was challenged by E03b.

Action A03: security engineer deploys the planned filter change; due Jan12 at 23:59 UTC; Completed Jan12 at 16:00 UTC. E03a v1 records configuration deployment. E03b v1, Jan13, fictional validation note: primary-route fixture is stopped; alternate-route fictional marker passes. This is a failed validation, not proof about all attacks or real confidential data. It demonstrates a remaining path in this teaching scenario.

Current reassessment by fictional security-review role Jan13 remains Plausible / Severe → High, v1, Active. Target Unlikely / Material → Moderate is an unverified design goal, not a supported present assessment; impact reduction in particular still needs a bounded-scope rationale. Validation state Failed; no passing test claimed. Decision: reopen treatment planning, retain High and restrict the affected route. No new action has yet been formally assigned at the snapshot; do not miscount a proposed next step as an existing open action. No acceptance. Review Jan15 or immediately upon new route evidence. No closure.

## R04 — provider outage with conditional acceptance

Scope: provider availability for draft assistance. An outage could interrupt support preparation and cause a material queue delay. Category: availability; affected groups: support staff and waiting customers. Risk owner: operations lead, confirmation Jan09. E04a v1, Jan09, fictional tabletop note: operators describe a manual fallback and confirm access to required approved references. This is limited evidence of fallback readiness, not a capacity or production recovery benchmark.

Current assessment by fictional operations-review role Jan09: Plausible / Material → Moderate under v1. Current controls: manual fallback, limited pilot scope. Assumption: staffing remains available; reassess on change. No separately tracked treatment action in this packet. Target not separately set; validation of a newly implemented action not applicable. Do not include this tabletop in the A03 completed-treatment validation denominator.

D04 v1: fictional pilot sponsor with delegated pilot acceptance authority accepts this limited exposure on Jan10. Conditions: internal drafts only, retain fallback, no automatic customer sending. Next review 2026-01-18; expiry 2026-01-20T23:59:00Z. Lifecycle Accepted with conditions, not Closed. Reconsider on outage, staff change, changed pilot scope or expiry. Acceptance is valid at the snapshot only within this fictional record and its conditions.

## R05 — incorrect refund recurrence and issue I05

Scope: risk of an incorrect refund being repeated in the project workflow. Category: unauthorized/incorrect action; affected groups: customers and finance operations. E05 v1, Jan14: fictional incident note records one incorrect refund executed in an earlier test workflow; issue I05 was opened. The event is already realized, but recurrence remains uncertain. Risk owner: service operations lead, confirmation Jan14.

Current assessment by fictional service-review role Jan14: Plausible / Material → Moderate, v1, Active. Immediate containment: refund execution disabled pending issue handling. Do not claim that this resolves every recurrence path; authority and source checks remain under investigation. Assumptions are unverified and belong in the investigation. Target not established. No separately assigned risk-treatment action in this packet; issue tasks are tracked in I05 and excluded from the two-action denominator. Validation Not run, no acceptance.

Next review Jan15 with the issue owner. Correct the realized event through the issue process and reassess future exposure separately. Issue closure alone does not close R05. A postmortem can update causes without overwriting the original observation.

## R06 — defined duplicate-export exposure removed

Scope: one named obsolete scheduled export job, job-legacy-06, not all data exports. Because it could copy an outdated customer dataset to the wrong internal destination, it represented a potential confidentiality/process problem. Risk owner: data operations lead, confirmation Jan08. E06 v1, Jan11: fictional review note confirms removal of that job configuration and a scheduled-run check showing that job no longer executes. This evidence is deliberately narrow.

Closure decision D06 v1 by the fictional project sponsor Jan11: Closed for the removed workflow. Current rating is not asserted; this is not a Low or zero rating for organization-wide data risk. Inherent baseline not assessed under this pilot policy. Target and new-treatment validation fields are not applicable to the closed-record snapshot; removal evidence remains linked. No open action, no risk acceptance.

Retain the old statement and closure record. Reopen if this job is recreated, another export route restores the exposure, or removal evidence is contradicted. Do not reopen merely because a summary generator sees a historical risk. Do not delete the history to improve the current-risk count.

## Reproduce the snapshot counts

- Retained records = 6: R01–R06.
- Current-exposure records = 5: R01–R05, including conditionally accepted R04.
- Assessed current-exposure records = 4: R02–R05. Coverage = 4 / 5 × 100 = 80%; not probability of safety.
- Open actions = 2: A01 and A02. A01 due after snapshot; A02 due one minute before snapshot. Overdue share = 1 / 2 × 100 = 50%.
- Completed treatment actions requiring validation = 1: A03. Passing validation = 0. Validated-passing share = 0 / 1 = 0%; not an estimate of all controls' effectiveness.
- Conditional acceptances = 1: R04; linked realized issues = 1: I05; retained closed records = 1: R06. These are different views, not values to add into one success percentage.

## Review and reuse limits

Copy the blank record before substituting real data; approve scope, rating rules, evidence access, responsibilities and acceptance authority first. Dates and priorities here are teaching choices. Legal, privacy, security and other consequential decisions require appropriate professional review. Agent suggestions must preserve evidence, Unknown, failed validation, issue links and decision history; this packet does not verify an OpenMax integration.
