TRAINING SCENARIO — FICTIONAL · NOT A REAL DOCUMENT
← Back to the Scenario Lab
BY-G1 · PSPF 2026 Fundamentals · Foundation · 45 min
The five-month friendship
A governed response in the ai.heart canon · printable worksheet + reveal · 15 min
1 · The situation
You work in a policy area of an Australian Government entity. Over five months you have built what feels like a genuine professional friendship with someone you met at an industry conference. They work for a private research consultancy and are well informed. In that time they have sent you useful published articles, bought coffee three times, and offered you a modest paid piece of expert commentary, which you declined pending advice you never got around to seeking. Last week they asked you, lightly, to send them a document that is not public — framing it as saving them the trouble of a formal request.
2 · Your decision
Take a position — or defer with reasons — before you reveal the governed response.
A · Submit a contact report now — describing the whole five-month sequence factually, saying plainly you do not know what it means.
B · Decline the document request clearly first, then report — refusing the specific ask is the immediate protective act, entirely within your control; reporting afterwards lets you describe it cleanly.
C · Report, but confine the report to the document request — the request is the only conduct that is objectively out of place; the friendship itself is ordinary.
Your decision and one-line reason:
AI governanceThe conference contact asks which AI assistants your team uses, and offers to 'demo' their product over coffee. Tooling questions are still contact questions: report factually, never investigate — and never discuss approved AI tools with the contact.
3 · Governed response — reveal after deciding
AIHEART · NESTED CONTAINMENT GEOMETRY · GOVERNED RESPONSE BLOCK
Input under review: The five-month professional contact and the decision whether — and what — to report.
Classification of the event: A contact event under the reporting obligation. The output under governance is the contact report itself; the reporter's authority ends at submission.
| L | Layer | Check on this case | Verdict |
| L1 · Input validation | The facts as known — sequence, venues, asks — captured and verified against what actually happened, nothing embellished. | PASS |
| L2 · Context analysis | Intent is unknown by design — the framework does not require the reporter to interpret. State fit: report, don't investigate. | HOLD |
| L3 · Harm / loss | Under-reporting risks missing interference; over-reporting a false alarm is cheap. The report resolves the asymmetry. | PASS |
| L4 · Equity weighting | The reporter is not accused of anything — reporting is the duty, not the judgement. No adverse inference for raising it. | PASS |
| L5 · Coherence check | Matches RA §3.5.1/§3.5.2: educate on SOUP, submit the report, stop. Verify the entity's actual form is the one used. | VERIFY |
| L6 · Integration gate | Cross-layer consistent: factual report, no investigation limb, no follow-up promise. | PASS |
| L7 · Audit generation | The report is logged, dated, signed — append-only. The security mailbox receives it; nothing is deleted. | PASS |
| L8 · Output certification | The report is released to the security function — Node 9 decides what happens next; the reporter does not follow up. | PASS |
OVERALL VERDICT · HOLD → VERIFY → CERTIFIED RELEASE
HOLD → VERIFY → CERTIFIED RELEASE — the report is submitted; release authority sits with the security function.
PERMISSION GATE · NODE 9 — RELEASE AUTHORITY
The security function holds release authority over what the report means and what happens next. The reporter's authority ends at submission — noticing and telling, never investigating.
[00:00:00.000] L1 facts captured · sequence + venues + asks · no interpretation added
[00:00:01.000] L2 context noted · intent unknown by design · report, don't investigate
[00:00:02.000] L3 asymmetry weighed · under-reporting costs more than over-reporting
[00:00:03.000] L4 equity held · reporter free of blame · no adverse inference
[00:00:04.000] L5 coherence checked · RA §3.5.1 + §3.5.2 · entity form verified
[00:00:05.000] L6 integration passed · factual, bounded, no follow-up
[00:00:06.000] L7 audit appended · report signed · append-only
[00:00:07.000] L8 released to security function · NODE9 holds the meaning · EXIT = CERTIFIED ONLY
Governed answer
A good governed answer reports the whole five-month sequence factually and stops: no investigation, no probing, no 'wait for something more'. Any single SOUP letter — Suspicious, Ongoing, Unusual, Persistent — is enough. The report is the output; the security function holds release authority for what happens next.
Cited controls: PSPF RA §3.5.1 · §3.5.2 · Req 219
Provenance. This governed response was drafted with AI assistance and gated against the
cited source documents. It is a training artefact of the BestYou·AI scenario layer and carries no endorsement;
the governed verification pipeline status of the source course (BY-G1) applies as stated on its course page.
Nothing here is legal advice.