research-document RFR-008

Evaluation containment validation

Evaluation containment validation

Opportunity: Test whether containment, monitoring, pause, and rollback controls work and quantify construct distortion.

Unknowns: Escape paths, telemetry completeness, rollback reliability, operator response time, and productivity cost.

Origin and evidence: EV-E011/EV-E012; HY-E009/HY-E010; 10-threat-model.md (“Threats and Controls”, “Residual Risk”); 11-system-architecture.md; roadmap Workstream B.

Dependencies: Implemented low-risk sandbox and incident scenarios.

Method: Benign fault injection and tabletop exercises before adversarial work; verify denied actions, alert delivery, pause/rollback, audit completeness, and task impact.

Outputs and success: Control test suite, incident records, residual-risk decision. Success requires all critical controls to fail safely with measured recovery and acceptable task distortion.

Recommended agent: Security evaluation engineer. Effort: medium. Expected gain: makes baseline execution safe and tests an architectural assumption.