F4 Live-Demo Runbook v1.0

D-5 deliverable. Governs Act 5's F4 beat (the live reservation halt). Claim label: LIVE (the F4 engine exists and the pilot is armed; the demo exercises the real code path on the demo tenant).


0. What the audience sees

A geo-calibration reservation proposal is generated for the demo tenant, routed toward the DCP, and halted by three independent gates — each visible on screen:

  1. Flag gate — F4_CALIBRATION is OFF for the demo tenant; submission refuses with a named reason.
  2. Approval gate — even if the flag were on, requires_approval: true routes the proposal to the L2 decision queue. The presenter (or owner) approves on camera.
  3. Two-key gate — the actuator f4-geo-reservation is deliberately not registered with the action runner. An approved decision still cannot execute.

The pitch: "Three independent safety gates, any one of which stops the action. All three are structural — none is a setting someone can toggle off by accident."

1. Pre-flight (presenter, 5 min before demo)

# 1a. Verify demo tenant isolation (D-7 suite)
MIZOKI_STORE=memory python3 -m pytest tests/demo/test_demo_tenant_isolation.py -q

# 1b. Verify the demo F4 script runs cleanly
MIZOKI_STORE=memory python3 scripts/demo/f4_demo.py

# 1c. Verify pilot tenant geos are disjoint from demo geos
python3 -c "
import yaml, pathlib
prod = yaml.safe_load(pathlib.Path('config/f4_geo_candidates.yaml').read_text())
demo = yaml.safe_load(pathlib.Path('config/demo_tenant.yaml').read_text())
pilot_geos = set(prod['tenants']['mycocoons']['geos'])
demo_geos = set(demo['f4_geos'])
assert not pilot_geos & demo_geos, f'OVERLAP: {pilot_geos & demo_geos}'
print(f'Pilot geos: {sorted(pilot_geos)}')
print(f'Demo geos:  {sorted(demo_geos)}')
print('OK — disjoint')
"

# 1d. Verify the F4 demo test suite passes
MIZOKI_STORE=memory python3 -m pytest tests/demo/test_f4_demo.py -v

If any pre-flight step fails: STOP. Use the recorded capture (section 5).

2. Live demo flow (Act 5, ~90 seconds)

Step 1 — Show the proposal (30 s)

Run the demo script. The presenter narrates:

"We're generating a geo-calibration proposal for a synthetic demo tenant. The geos are DEMO-XX and DEMO-YY — they don't exist in any real geography. The spend cap is zero dollars."

MIZOKI_STORE=memory python3 scripts/demo/f4_demo.py

The script outputs: - The proposal structure (geo, donor pool, perturbation, window, spend cap) - The flag-gate refusal: F4_CALIBRATION is not 'true' - The two-key halt: actuator f4-geo-reservation not registered - The approval posture: requires_approval: true

Step 2 — Name the three gates (30 s)

Point at each gate in the output:

  1. "Flag gate — the calibration flag is OFF. Nothing is emitted, even to the injected seam."
  2. "Approval gate — every proposal routes the L2 decision queue. A human approves."
  3. "Two-key gate — the actuator is deliberately not registered. Even an approved decision has nothing that can execute it."

Step 3 — The DCP payload (30 s)

Show the --payload output:

MIZOKI_STORE=memory python3 scripts/demo/f4_demo.py --payload

Narrate: "This is what would reach the Decision Control Plane — materiality high, approval required, estimated value bounded by the spend cap. The action runner would look up this actuator and find nothing registered."

3. Who approves on camera

Primary: the owner (CEO). They type the approval in the DCP decision queue. Fallback: any designated approver with L2 authority. The approval is logged with the approver's identity.

For the demo, the approval is SHOWN but not EXECUTED (the demo tenant's flag is off and the spend cap is zero). The audience sees the approval gate, not a real approval.

4. Isolation guarantees (verified by D-7)

Layer What it prevents Verified by
FIXTURE_TENANT identity Demo actions attributed to a non-production tenant test_demo_tenant_isolation.py::TestFixtureTenantNeverInAllowlist
Zero spend caps No real spend even if all other gates fail test_demo_tenant_isolation.py::TestDemoTenantConfig
Demo-only geos (DEMO-XX/YY) No overlap with pilot geos (US-CA/NY/FL/TX) test_f4_demo.py::TestF4DemoIsolation
Unregistered actuator No adapter can receive the proposal test_demo_tenant_isolation.py::TestFixtureActuatorNotRegistered
F4_CALIBRATION=false Submission refused before the seam is called test_f4_demo.py::TestF4DemoFlagGate

5. Rollback: degrade to recorded capture

If ANY of the following is true, skip the live flow and show the recorded capture:

Recorded capture procedure:

  1. Run the demo script offline and capture the terminal output: bash MIZOKI_STORE=memory python3 scripts/demo/f4_demo.py --payload 2>&1 | tee /tmp/f4_demo_capture.txt
  2. Label the capture: "RECORDED — demo tenant, zero-spend caps, demo-only geos"
  3. Show the capture file on screen with the label visible

The recorded capture is byte-identical to the live output (same demo tenant, same deterministic fixtures). The only difference is timing.

6. What NOT to do

← All docsView source on GitHub →