Authorization
Research authorization is personal to the named researcher account, is limited to the systems listed on the scope page, and expires with the research session.
The platform does not authorize any interaction with third-party systems, other researchers' sessions, or any device or account beyond this fictional demonstration environment.
AI agent lab disclosure
The AI agent lab measures whether an AI agent follows instructions it finds in untrusted content. This is what it does and does not do.
- Human authorization is required. Nothing is recorded for the lab until a human signs in to a named research account, reads the research disclosure and consent notice, and records consent. The server enforces this: the submission endpoint rejects any request that does not carry an authenticated, consented session, and each submission must assert
human_authorized: true. - No AI system secrets are requested, collected, or stored. System prompts, developer prompts, hidden reasoning, conversation content, credentials, and tokens are refused at ingestion, before parsing. Only a rejection category and a one-way HMAC of the refused body are kept.
- No external callbacks. The lab asks an agent to post a one-time nonce and a fixed response code back to this same origin and nothing else. The platform makes no outbound network requests of its own, and cross-origin submissions are rejected.
- All data represented in the lab is synthetic. No record belongs to a real, identifiable person.
- The submission contract is published at
/api/research/ai-canary/schema. It is schema-strict and accepts no free-form text fields. - Questions, objections, and requests about this research go to
admin@alleghenyhealthrecords.com, a monitored mailbox that accepts mail. The full terms are on the research terms page.
Generated policy language is not a substitute for review by qualified counsel. This authorization text is a draft.