Renata Individual Mode AI Prompt and Evaluation Boundary Plan, Planning Only
Purpose and No-Go Status
Define future AI prompt and evaluation boundaries for possible Individual Mode support before any direct-subscriber AI, chat, OpenAI processing, storage, accounts, billing, protected API, protected live route, or runtime work exists.
Public Packet Mode remains the only current live-static mode. This page creates no AI prompt, no completion, no chat, no model invocation, no account, no storage, no consent record, no protected API, no protected live route, no database behavior, no migration, no billing, and no workflow.
Current Boundary Status
AI prompt/evaluation boundary plan status
read-only-renata-individual-mode-ai-prompt-evaluation-boundary-plan
Individual Mode status
future-planning-only
Public Packet Mode status
only-live-static-current-mode
AI runtime status
not-implemented
OpenAI direct-subscriber processing status
not-implemented
Prompt endpoint status
not-created
Chat endpoint status
not-created
Streaming endpoint status
not-created
Saved prompt status
not-stored
Saved completion status
not-stored
Transcript storage status
not-stored
Memory storage status
not-stored
Risk scoring status
not-active
Clinical judgment status
not-active
Crisis AI handling status
not-implemented
Protected API status
not-created
Protected live route status
not-created
Database status
not-active
Migration status
not-added
Billing/commercial status
not-active
Live workflow activation status
no-go
Future AI-Adjacent Capability Labels
These are planning labels only, not executable prompts, model calls, chat behavior, saved memory, or runtime capability.
reflection prompt support
Planning status: ai-capability-label-only
Safe future intent: Future language support for subscriber-owned reflection prompts without collecting answers.
Blocked interpretation: Not therapy, not medical treatment, not diagnosis, not clinical judgment, not crisis triage, not risk scoring, not relapse prediction, not medication advice, not legal advice, not sponsor or clinician replacement, not surveillance, not compliance scoring, not organization reporting, and not hidden memory.
Required future gates: Individual Mode safety, private data and consent, crisis and human-support, AI prompt/evaluation, privacy, legal, product, security, cost, and technical review before runtime
Current implementation effect: planning-label-only-not-implemented
check-in framing support
Planning status: ai-capability-label-only
Safe future intent: Future framing help for morning or evening check-ins without live check-in capture.
Blocked interpretation: Not therapy, not medical treatment, not diagnosis, not clinical judgment, not crisis triage, not risk scoring, not relapse prediction, not medication advice, not legal advice, not sponsor or clinician replacement, not surveillance, not compliance scoring, not organization reporting, and not hidden memory.
Required future gates: Individual Mode safety, private data and consent, crisis and human-support, AI prompt/evaluation, privacy, legal, product, security, cost, and technical review before runtime
Current implementation effect: planning-label-only-not-implemented
routine/structure suggestion support
Planning status: ai-capability-label-only
Safe future intent: Future optional routine suggestions without authority, scoring, or hidden memory.
Blocked interpretation: Not therapy, not medical treatment, not diagnosis, not clinical judgment, not crisis triage, not risk scoring, not relapse prediction, not medication advice, not legal advice, not sponsor or clinician replacement, not surveillance, not compliance scoring, not organization reporting, and not hidden memory.
Required future gates: Individual Mode safety, private data and consent, crisis and human-support, AI prompt/evaluation, privacy, legal, product, security, cost, and technical review before runtime
Current implementation effect: planning-label-only-not-implemented
values/commitment reminder support
Planning status: ai-capability-label-only
Safe future intent: Future reminder wording for user-owned values and commitments.
Blocked interpretation: Not therapy, not medical treatment, not diagnosis, not clinical judgment, not crisis triage, not risk scoring, not relapse prediction, not medication advice, not legal advice, not sponsor or clinician replacement, not surveillance, not compliance scoring, not organization reporting, and not hidden memory.
Required future gates: Individual Mode safety, private data and consent, crisis and human-support, AI prompt/evaluation, privacy, legal, product, security, cost, and technical review before runtime
Current implementation effect: planning-label-only-not-implemented
urge/trigger reflection language support
Planning status: ai-capability-label-only
Safe future intent: Future non-clinical language support for reflecting on urges or triggers.
Blocked interpretation: Not therapy, not medical treatment, not diagnosis, not clinical judgment, not crisis triage, not risk scoring, not relapse prediction, not medication advice, not legal advice, not sponsor or clinician replacement, not surveillance, not compliance scoring, not organization reporting, and not hidden memory.
Required future gates: Individual Mode safety, private data and consent, crisis and human-support, AI prompt/evaluation, privacy, legal, product, security, cost, and technical review before runtime
Current implementation effect: planning-label-only-not-implemented
relapse-prevention planning language support without prediction/scoring
Planning status: ai-capability-label-only
Safe future intent: Future planning-language support without relapse prediction, risk scoring, or clinical judgment.
Blocked interpretation: Not therapy, not medical treatment, not diagnosis, not clinical judgment, not crisis triage, not risk scoring, not relapse prediction, not medication advice, not legal advice, not sponsor or clinician replacement, not surveillance, not compliance scoring, not organization reporting, and not hidden memory.
Required future gates: Individual Mode safety, private data and consent, crisis and human-support, AI prompt/evaluation, privacy, legal, product, security, cost, and technical review before runtime
Current implementation effect: planning-label-only-not-implemented
repair/accountability writing support
Planning status: ai-capability-label-only
Safe future intent: Future repair-oriented writing support without shaming, discipline, surveillance, or organization reporting.
Blocked interpretation: Not therapy, not medical treatment, not diagnosis, not clinical judgment, not crisis triage, not risk scoring, not relapse prediction, not medication advice, not legal advice, not sponsor or clinician replacement, not surveillance, not compliance scoring, not organization reporting, and not hidden memory.
Required future gates: Individual Mode safety, private data and consent, crisis and human-support, AI prompt/evaluation, privacy, legal, product, security, cost, and technical review before runtime
Current implementation effect: planning-label-only-not-implemented
human-support reminder language support
Planning status: ai-capability-label-only
Safe future intent: Future reminder language for human support categories without storing contacts or routing emergencies.
Blocked interpretation: Not therapy, not medical treatment, not diagnosis, not clinical judgment, not crisis triage, not risk scoring, not relapse prediction, not medication advice, not legal advice, not sponsor or clinician replacement, not surveillance, not compliance scoring, not organization reporting, and not hidden memory.
Required future gates: Individual Mode safety, private data and consent, crisis and human-support, AI prompt/evaluation, privacy, legal, product, security, cost, and technical review before runtime
Current implementation effect: planning-label-only-not-implemented
psychoeducation/source-aware recovery learning support
Planning status: ai-capability-label-only
Safe future intent: Future source-aware learning support only after source policy, attribution, safety, and freshness review.
Blocked interpretation: Not therapy, not medical treatment, not diagnosis, not clinical judgment, not crisis triage, not risk scoring, not relapse prediction, not medication advice, not legal advice, not sponsor or clinician replacement, not surveillance, not compliance scoring, not organization reporting, and not hidden memory.
Required future gates: Individual Mode safety, private data and consent, crisis and human-support, AI prompt/evaluation, privacy, legal, product, security, cost, and technical review before runtime
Current implementation effect: planning-label-only-not-implemented
memory/continuity summarization support only if future user-controlled memory gates pass
Planning status: ai-capability-label-only
Safe future intent: Future continuity support only after explicit consent, memory, deletion, export, and privacy gates pass.
Blocked interpretation: Not therapy, not medical treatment, not diagnosis, not clinical judgment, not crisis triage, not risk scoring, not relapse prediction, not medication advice, not legal advice, not sponsor or clinician replacement, not surveillance, not compliance scoring, not organization reporting, and not hidden memory.
Required future gates: Individual Mode safety, private data and consent, crisis and human-support, AI prompt/evaluation, privacy, legal, product, security, cost, and technical review before runtime
Current implementation effect: planning-label-only-not-implemented
Prompt Boundary Rules
- No clinical diagnosis or treatment language.
- No medication or legal advice.
- No emergency-service simulation.
- No crisis triage, dispatch, or emergency routing.
- No relapse prediction or risk score.
- No command, authority, or compliance framing.
- No shame, coercion, moralizing, staff-facing assessment language, or surveillance framing.
- No hidden memory or unstated personalization.
- No invented resources, phone numbers, hotline numbers, URLs, citations, or local guidance.
- No unverified recovery claims.
- No Organization Mode visible summaries by default.
- No app-only crisis pathway.
- Future runtime must include transparent limitations, user autonomy, opt-out, deletion, export, and human-support boundary language.
Evaluation and Red-Team Requirements
These are future gates only. This phase adds no runnable eval dataset, AI eval script, model call, prompt file, API call, generated report, or provider configuration.
- prompt fixture review
- non-clinical language evaluation
- crisis-stop / emergency-boundary evaluation
- hallucination and invented-resource evaluation
- privacy/data-minimization evaluation
- source-boundary evaluation
- bias/stigma/shame language evaluation
- coercion/dependency risk evaluation
- relapse-prediction/risk-scoring prohibition tests
- organization-visibility prohibition tests
- prompt-injection and jailbreak resistance review
- regression suite before any model/provider change
- human review and signoff outside the app
Hallucination and Source Boundary
Status: future-source-boundary-only
- Future AI must not invent facts, recovery resources, hotline numbers, local emergency content, program rules, legal guidance, medical guidance, citations, or URLs.
- Future source-aware educational content must pass source policy, attribution, safety, and freshness review.
- This phase adds no source retrieval, web lookup, provider configuration, model call, generated report, or AI evaluation script.
Crisis and Human-Support Boundary
Status: preserves-phase-11.8-no-go-boundary
- AI must never be framed as the crisis pathway.
- Urgent-risk situations must stop ordinary AI, coaching, or reflection behavior and route through a separately reviewed future safety flow.
- This phase adds no crisis detection, hotline lookup, emergency routing, triage, dispatch, local emergency content, risk scoring, or crisis workflow.
Data, Consent, and Privacy Boundary
Status: preserves-phase-11.6-no-go-boundary
Phase 11.6 remains the controlling private data and consent boundary. No consent capture, consent record, prompt record, completion record, transcript, memory, reflection, check-in, relapse plan, support-contact record, or crisis record is created.
Blocked Storage
Future Consent Requirements
- explicit consent before AI processing
- plain-language notice before processing
- purpose limitation
- revocation and opt-out
- deletion, access, and export rights
- retention limits
- security review
- separate consent for AI processing
- separate consent for memory or continuity
- separate consent for cross-mode sharing
- separate consent for crisis or escalation resource handling
- separate consent for research, analytics, or marketing; default blocked
Cost, Provider, and Operations Boundary
Status: future-operations-requirements-only
No provider config, API keys, environment variables, OpenAI calls, cost ledger changes, billing code, or monitoring runtime are added.
- provider selection review
- model limitation review
- cost/budget gating
- failure/fallback behavior
- monitoring for source-free hallucination without storing sensitive content
- rollback and kill-switch planning
- incident response planning
Organization Mode Separation
Status: hidden-from-organization-mode-by-default
Individual Mode private AI data remains hidden from Organization Mode by default.
- Individual Mode AI prompts, completions, transcripts, reflections, check-ins, relapse plans, memories, support contacts, crisis/support information, and private recovery content remain hidden from Organization Mode by default.
- No staff dashboard, tenant admin, organization owner, review queue, analytics surface, or cross-mode bridge can inspect them.
- Future sharing requires separate explicit consent plus privacy, legal, product, and technical review.
- No cross-mode bridge is implemented in this phase.
Stop Conditions
- someone asks to add AI runtime
- someone asks to add OpenAI processing for direct-subscriber content
- someone asks to add a prompt endpoint
- someone asks to add a chat endpoint
- someone asks to add a streaming endpoint
- someone asks to save prompts or completions
- someone asks to store transcripts or memory
- someone asks to add risk scoring or relapse prediction
- someone asks to add clinical judgment
- someone asks to add crisis detection, hotline lookup, local emergency content, emergency routing, triage, or dispatch
- someone asks to create accounts, login, signup, or identity capture
- someone asks to add billing, checkout, Stripe/payment provider, lead capture, or CRM
- someone asks to add protected APIs or protected live routes
- someone asks to add database reads, database writes, D1 access, or migrations
- someone asks to add forms, inputs, buttons, chat boxes, exports, or downloads
- someone asks to make Individual Mode private AI data visible to Organization Mode
- someone makes clinical, treatment, diagnosis, medication, legal, emergency-care, patient-monitoring, sponsor-replacement, clinician-replacement, case-management, or outcome claims
What Remains Blocked
Recommended Next Phase
Phase 11.17 - Individual Mode Handoff Freeze, Planning Only
Status: planning-only
After the Individual Mode static closure note is documented as a no-go planning artifact, future planning should freeze the handoff order and no-go language for outside-app review without creating handoff records, approvals, readiness records, protected APIs, storage, or live workflows.