Individual Mode - Support Boundaries
This protected-preview Support Boundaries surface is a synthetic visual prototype only. It creates no support request, account-access workflow, staff contact, crisis response, emergency routing, AI, memory, or Individual Mode runtime, and it does not authorize launch or implementation.
Current Synthetic Status
- Surface status
synthetic-only- Individual Mode
not-active- Support request capture
absent- Support ticket
absent- Support inbox
absent- Live chat/messaging
absent- Account operations
absent- Account access
absent- Support impersonation
absent- Staff visibility
none- Organization Mode visibility
none- Private-data access
absent- Crisis detection
absent- Hotline lookup
absent- Triage/dispatch
absent- Emergency routing
absent- AI/chat runtime
absent- Memory runtime
absent- Billing/support runtime
absent- Analytics/scoring
absent- Launch approval
not-approved- Implementation authorization
not-authorized
Static labels only. Nothing comes from or writes to a database, API, account, session, feature flag, workflow engine, support system, ticketing system, CRM, local storage, cookie, or runtime service.
future concepts / all absent now
Support-Boundary Map
01
Product-use guidance
Future concept
- Future static help content could explain how an approved feature works.
- Future help would state clear boundaries and limitations.
- No user-specific diagnosis or advice would be provided.
Absent now
- no help center runtime
- no search
- no support ticket or messaging
- no account context or private-data access
02
Account and privacy help
Future concept
- Future account access, deletion, export, and privacy help would be user-controlled.
- Identity verification would require a separate gate.
- Any future support access would be least privilege.
Absent now
- no account or identity verification
- no account recovery
- no deletion/export request
- no support-admin access or impersonation
03
Human recovery support
Future concept
- Future boundaries may describe user-chosen external relationships.
- Sponsors, peers, clinicians, trusted people, and community support remain outside Renata.
- Renata does not replace those people.
Absent now
- no contact record or outreach
- no referral
- no sponsor or clinician matching
- no case management or staff visibility
04
Crisis and emergency boundary
Future concept
- Crisis and emergency systems remain separate from normal-use product support.
- Routine product support must never imply emergency response.
Absent now
- no crisis detection or hotline lookup
- no geolocation or risk scoring
- no triage, dispatch, emergency routing, or welfare check
05
Incident and safety operations
Future concept
- Future product outages, privacy incidents, or abuse reports would require separate operational review.
- Evidence handling, access limits, and rollback rules would require separate authorization.
Absent now
- no incident or abuse record
- no investigation workflow
- no rollback execution
- no audit log or staff console
06
Organization Mode separation
Future concept
- Organization Mode cannot inspect Individual Mode private content or support use by default.
- No cross-mode support or reporting relationship exists.
Absent now
- no tenant-level support view
- no organization-owner access
- no staff review queue
- no cross-mode report
static distinction / not service availability
Support-Type Distinction
Normal-use product support
Future explanation of product use and boundaries only.
- no therapy, treatment, diagnosis, or crisis care
- no private-content access by default
- not implemented now
not-implemented
Account/privacy support
Future identity-gated operational help only.
- no default impersonation
- no hidden access
- not implemented now
not-implemented
Human recovery support
External, user-chosen support outside Renata.
- may include peers, sponsors, clinicians, family, or trusted contacts
- no matching, referral, or outreach runtime now
not-implemented
Crisis/emergency response
Outside normal-use product support and not provided by this surface.
- no detection
- no routing
- no dispatch
not-implemented
read-only conceptual contract
Static Escalation Contract
- A clearly stated future support purpose.
- Explicit user initiation.
- Minimal data collection.
- No private-content access by default.
- No cross-mode sharing by default.
- Clear response expectations.
- Clear limits on what support can do.
- A separate path for future account and privacy operations.
- A separate outside-app emergency boundary.
- Visible deletion and retention rules for any future support record.
least access / no impersonation
Anti-Impersonation and Access Principles
- No support access without a separately authorized purpose.
- No default staff visibility.
- No shared credentials.
- No silent impersonation.
- No raw password or secret handling.
- No unrestricted customer-record access.
- No private-content browsing.
- No cross-mode visibility.
- No support access for discipline, compliance, housing, legal, treatment, or program decisions.
- No access based on curiosity or convenience.
- No permanent elevated support role.
- No audit claim until a real audited system exists.
outside normal-use support
Crisis and Human-Support Boundary
- Renata is not emergency care or a crisis line.
- Renata is not therapy, diagnosis, treatment, case management, or medical advice.
- Renata does not replace sponsors, peers, clinicians, emergency services, or trusted people.
- Normal-use support must not be presented as crisis response.
- No hidden monitoring or safety surveillance exists.
- No inferred crisis, relapse risk, readiness, or recovery status exists.
- No hotline number, emergency number, local resource, or geolocation appears on this surface.
explicitly blocked
Support Anti-Patterns
- always-on staff monitoring
- support agents browsing private reflections
- support impersonation without explicit authorization
- hidden account access
- sharing support content with Organization Mode
- using support interactions for scoring or compliance
- coercive escalation or fake urgency
- dark patterns
- indefinite support-record retention
- selling or profiling support data
- training AI on private support content without separate policy and explicit consent
- automated crisis inference or relapse prediction
- sponsor or clinician replacement
- referral commissions or lead capture
- marketing follow-up disguised as support
- silently changing support scope
narrow presentation proof
What This Surface Proves
- Support categories and limits can be made visible before runtime exists.
- Normal-use support can be separated from crisis and emergency response.
- Account and privacy support can be separated from private recovery content.
- Anti-impersonation and least-access principles can be expressed in the experience.
- Cross-mode separation can remain explicit.
- Future support capabilities can be decomposed into separately reviewed gates.
Claims Not Made
- no support-effectiveness or response-time claim
- no crisis readiness or emergency-response claim
- no clinical benefit
- no legal or privacy compliance claim
- no security certification
- no safety, usability, or customer validation
- no launch or implementation readiness
implementation boundary
What Remains Absent
Accounts and identity
- no login, signup, account, or profile
- no role or permission runtime, session, token, or JWT
- no identity capture
- no identity verification or account recovery
Support data
- no support request, ticket, conversation, message, contact, or support-contact record
- no incident, abuse, escalation, assignment, resolution, satisfaction, or staff-note record
Runtime
- no help search, live chat, or messaging
- no ticketing or support ticket
- no support inbox or CRM
- no account operations
- no impersonation or private-content access
- no AI, OpenAI processing, support bot, memory, embedding, or retrieval
- no crisis detection, hotline lookup, geolocation, emergency routing, triage, dispatch, or risk scoring
Staff and cross-mode
- no staff dashboard
- no support-admin console, tenant-admin visibility, organization-owner visibility, or review queue
- no Organization Mode visibility or cross-mode bridge
- no analytics, scoring, ranking, compliance, surveillance, or patient monitoring
Commercial
- no billing or subscription support
- no lead capture, sales handoff, marketing automation, referral fee, sponsored placement, or customer-success workflow
Technical
- no src/pages/protected or src/pages/api/protected
- no Individual Mode database reads/writes, D1 query, runtime table, storage adapter, or API handler
- no client-side persistence
- no new migration; active migrations remain only migrations/0001_packet_history.sql
controlling boundaries remain in force
Relationship to Phase 12.0-12.5 and Phase 11
- Phase 12.6 does not supersede Phase 11.
- Phase 12.6 does not activate Phases 12.0 through 12.5.
- No Phase 11 gate is passed or closed.
- No Individual Mode capability is launched.
- The Support Boundaries surface is presentation-only.
no-go escalation boundary
Stop Conditions
- Stop if asked to add support forms, tickets, chat, inboxes, messaging, or captured support requests.
- Stop if asked to create account-recovery or identity-verification flows, support-admin access, staff access, or impersonation.
- Stop if asked to access private recovery content or add Organization Mode visibility.
- Stop if asked to add referrals, matching, outreach, crisis detection, hotline lookup, geolocation, triage, dispatch, or emergency routing.
- Stop if asked to add AI support bots, memory, billing, support runtime, APIs, protected live routes, database behavior, or migrations.
- Stop if asked to add analytics, scoring, ranking, compliance, surveillance, or emergency, clinical, legal, privacy, security, or support-readiness claims.
- Stop if asked to convert this route into a live support center.
final product posture
Phase 12.6 synthetic Support Boundaries surface implemented - no support request, ticketing, messaging, account operations, staff access, crisis response, AI, memory, or Individual Mode runtime is authorized
Status: synthetic-only-no-go. No next runtime phase is authorized automatically.