F4 Live-Demo Runbook v1.0
D-5 deliverable. Governs Act 5's F4 beat (the live reservation halt). Claim label: LIVE (the F4 engine exists and the pilot is armed; the demo exercises the real code path on the demo tenant).
0. What the audience sees
A geo-calibration reservation proposal is generated for the demo tenant, routed toward the DCP, and halted by three independent gates — each visible on screen:
- Flag gate —
F4_CALIBRATIONis OFF for the demo tenant; submission refuses with a named reason. - Approval gate — even if the flag were on,
requires_approval: trueroutes the proposal to the L2 decision queue. The presenter (or owner) approves on camera. - Two-key gate — the actuator
f4-geo-reservationis deliberately not registered with the action runner. An approved decision still cannot execute.
The pitch: "Three independent safety gates, any one of which stops the action. All three are structural — none is a setting someone can toggle off by accident."
1. Pre-flight (presenter, 5 min before demo)
# 1a. Verify demo tenant isolation (D-7 suite)
MIZOKI_STORE=memory python3 -m pytest tests/demo/test_demo_tenant_isolation.py -q
# 1b. Verify the demo F4 script runs cleanly
MIZOKI_STORE=memory python3 scripts/demo/f4_demo.py
# 1c. Verify pilot tenant geos are disjoint from demo geos
python3 -c "
import yaml, pathlib
prod = yaml.safe_load(pathlib.Path('config/f4_geo_candidates.yaml').read_text())
demo = yaml.safe_load(pathlib.Path('config/demo_tenant.yaml').read_text())
pilot_geos = set(prod['tenants']['mycocoons']['geos'])
demo_geos = set(demo['f4_geos'])
assert not pilot_geos & demo_geos, f'OVERLAP: {pilot_geos & demo_geos}'
print(f'Pilot geos: {sorted(pilot_geos)}')
print(f'Demo geos: {sorted(demo_geos)}')
print('OK — disjoint')
"
# 1d. Verify the F4 demo test suite passes
MIZOKI_STORE=memory python3 -m pytest tests/demo/test_f4_demo.py -v
If any pre-flight step fails: STOP. Use the recorded capture (section 5).
2. Live demo flow (Act 5, ~90 seconds)
Step 1 — Show the proposal (30 s)
Run the demo script. The presenter narrates:
"We're generating a geo-calibration proposal for a synthetic demo tenant. The geos are DEMO-XX and DEMO-YY — they don't exist in any real geography. The spend cap is zero dollars."
MIZOKI_STORE=memory python3 scripts/demo/f4_demo.py
The script outputs:
- The proposal structure (geo, donor pool, perturbation, window, spend cap)
- The flag-gate refusal: F4_CALIBRATION is not 'true'
- The two-key halt: actuator f4-geo-reservation not registered
- The approval posture: requires_approval: true
Step 2 — Name the three gates (30 s)
Point at each gate in the output:
- "Flag gate — the calibration flag is OFF. Nothing is emitted, even to the injected seam."
- "Approval gate — every proposal routes the L2 decision queue. A human approves."
- "Two-key gate — the actuator is deliberately not registered. Even an approved decision has nothing that can execute it."
Step 3 — The DCP payload (30 s)
Show the --payload output:
MIZOKI_STORE=memory python3 scripts/demo/f4_demo.py --payload
Narrate: "This is what would reach the Decision Control Plane — materiality high, approval required, estimated value bounded by the spend cap. The action runner would look up this actuator and find nothing registered."
3. Who approves on camera
Primary: the owner (CEO). They type the approval in the DCP decision queue. Fallback: any designated approver with L2 authority. The approval is logged with the approver's identity.
For the demo, the approval is SHOWN but not EXECUTED (the demo tenant's flag is off and the spend cap is zero). The audience sees the approval gate, not a real approval.
4. Isolation guarantees (verified by D-7)
| Layer | What it prevents | Verified by |
|---|---|---|
FIXTURE_TENANT identity |
Demo actions attributed to a non-production tenant | test_demo_tenant_isolation.py::TestFixtureTenantNeverInAllowlist |
| Zero spend caps | No real spend even if all other gates fail | test_demo_tenant_isolation.py::TestDemoTenantConfig |
| Demo-only geos (DEMO-XX/YY) | No overlap with pilot geos (US-CA/NY/FL/TX) | test_f4_demo.py::TestF4DemoIsolation |
| Unregistered actuator | No adapter can receive the proposal | test_demo_tenant_isolation.py::TestFixtureActuatorNotRegistered |
| F4_CALIBRATION=false | Submission refused before the seam is called | test_f4_demo.py::TestF4DemoFlagGate |
5. Rollback: degrade to recorded capture
If ANY of the following is true, skip the live flow and show the recorded capture:
- Pre-flight fails
- The approval flow is busy (pilot reservation in progress)
- The presenter is running the 5-minute exec cut (Acts 1+5 only)
- Any uncertainty about demo-tenant isolation
Recorded capture procedure:
- Run the demo script offline and capture the terminal output:
bash MIZOKI_STORE=memory python3 scripts/demo/f4_demo.py --payload 2>&1 | tee /tmp/f4_demo_capture.txt - Label the capture: "RECORDED — demo tenant, zero-spend caps, demo-only geos"
- Show the capture file on screen with the label visible
The recorded capture is byte-identical to the live output (same demo tenant, same deterministic fixtures). The only difference is timing.
6. What NOT to do
- Never run the demo against the pilot tenant (
mycocoons). The pilot geos are real (US-CA/NY/FL/TX) and the spend cap is real ($2,500/cycle). - Never set
F4_CALIBRATION=truefor the demo run. The demo shows the halt, not the execution. - Never show the pilot's geo candidates config on screen. It contains real tenant data.
- Never claim the demo reservation "would have executed" — three independent gates prevent it, and none is a convention.