Staff/Privacy Review Dry-Run Checklist
Purpose
Help the operator rehearse a staff/privacy review of the draft pilot packet, verify that the packet is coherent, anticipate objections, identify missing evidence, and define stop conditions without conducting a real review or recording any decision.
This checklist is a rehearsal aid only. It does not conduct a real review, collect feedback, record approvals, store decisions, generate files, or activate any workflow.
Current Dry-Run Boundary
Dry-run status
read-only-dry-run-checklist
Rehearsal status
not-conducted
PDF generation status
not-generated
Export status
not-generated
Decision status
not-recorded
Implementation status
not-started
Live pilot decision
no-go
Intended Audience
Role labels only. No staff names, resident names, emails, contact details, or identity details are included.
Dry-Run Roles
operator-presenter
rehearses route sequence, safety framing, and handoff language
Boundary: no approval authority; no app storage
approval authority: noneprivacy-review-simulator
asks identity, retention, deletion, redaction, and distribution questions
Boundary: simulated reviewer only; no decisions recorded
approval authority: nonestaff-workflow-simulator
asks workflow, role, review, escalation, and harmful-content questions
Boundary: simulated reviewer only; no staff action created
approval authority: nonetechnical-boundary-simulator
asks schema, API, migration, access, storage, and rollback questions
Boundary: simulated reviewer only; no implementation authority
approval authority: noneobserver-note-taker
records missing evidence outside the app only
Boundary: no notes, approvals, or decisions are stored in the app
approval authority: noneRequired Packet Pages
| Route | Purpose | Rehearsal use | Must confirm | Status |
|---|---|---|---|---|
| /protected-preview/staff-privacy-review-packet-summary/ | Start with the compact review map. | Use as the dry-run overview and orientation point. | read-only summary status; no-go status; not-recorded decision boundary | manual-only / not-generated / not-recorded |
| /protected-preview/draft-pilot-evidence-package/ | Show the full planning evidence and unresolved gates. | Use to identify missing policy, privacy, staff workflow, and technical evidence. | planning-only evidence categories; unresolved blockers; required approvals | manual-only / not-generated / not-recorded |
| /protected-preview/staff-privacy-decision-record-template/ | Show decision areas with unresolved defaults. | Use to rehearse how reviewers might reason through approval categories without recording approvals. | unresolved defaults; not-approved checklist; Primary print layout | manual-only / not-generated / not-recorded |
| /protected-preview/staff-privacy-review-walkthrough-script/ | Show the presentation sequence and safe-answer framing. | Use to rehearse route transitions and objection handling. | opening no-go frame; reviewer questions; safe answers | manual-only / not-generated / not-recorded |
| /protected-preview/draft-pilot-review-packet-export-planning/ | Show future export boundaries and exclusions. | Use to rehearse the difference between export planning and actual file generation. | not-generated export status; allowed/prohibited content; distribution boundaries | manual-only / not-generated / not-recorded |
| /protected-preview/review-packet-pdf-layout-planning/ | Show future PDF page order and layout rules. | Use to confirm no PDF is generated and layout work remains planning-only. | not-generated PDF status; layout rules only; prohibited PDF content | manual-only / not-generated / not-recorded |
| /protected-preview/review-packet-print-styles-planning/ | Show print readability and appendix rules. | Use to confirm packet pages stay readable without turning diagnostics into core review content. | core packet sections; appendix sections; print readability rules | manual-only / not-generated / not-recorded |
| /protected-preview/review-packet-manual-assembly-checklist/ | Show manual packet order and verification steps. | Use to confirm Visual QA appears in the required pages and no automated assembly exists. | manual-only assembly status; Visual QA required page; exclusion/redaction checks | manual-only / not-generated / not-recorded |
| /protected-preview/review-packet-visual-qa-checklist/ | Show manual visual QA checks. | Use to rehearse stale-reference, navigation, blocked-chip, print readability, and safety checks. | manual-only visual QA status; stale-reference checks; pass/fail guidance | manual-only / not-generated / not-recorded |
| /protected-preview/review-packet-staff-handoff-notes/ | Show non-technical staff/privacy handoff framing. | Use to rehearse what to send, what to say, what not to claim, safe answers, and after-meeting boundaries. | read-only handoff status; no-go status; what to send; what not to claim; safe answers | manual-only / not-generated / not-recorded |
Optional Reference Pages
Operator is technical appendix/reference only. Demo is product context only. Optional references should not dominate the dry-run. The core dry-run should remain concise.
Demo Hub
Product context only.
optional-referenceOperator Status
Technical appendix/reference only.
optional-referenceDraft Pilot Activation Readiness
/protected-preview/draft-pilot-activation-readiness/
No-go activation readiness reference.
optional-referenceDraft Pilot Implementation Plan
/protected-preview/draft-pilot-implementation-plan/
Future implementation planning reference.
optional-referenceDraft Pilot Architecture Package
/protected-preview/draft-pilot-architecture-package/
Architecture planning reference.
optional-referenceAudit Logging Policy
/protected-preview/audit-logging-policy/
Audit planning reference.
optional-referenceRetention and Deletion Policy
/protected-preview/retention-deletion-policy/
Retention/deletion planning reference.
optional-referenceMorning Sheet Visibility Policy
/protected-preview/morning-sheet-visibility-policy/
Visibility planning reference.
optional-referenceStaff Review Procedure
/protected-preview/staff-review-procedure/
Review procedure planning reference.
optional-referencePull-Up / Push-Up Draft Schema
/protected-preview/pullup-pushup-draft-schema/
Draft schema planning reference.
optional-referencePre-Dry-Run Readiness Checks
- Staff Handoff Notes page loads
- Visual QA Checklist page loads
- Manual Assembly Checklist page loads
- all required packet pages show read-only/planning-only/no-go status
- no forms are visible
- no buttons are visible
- no selection controls are visible
- no export/download controls are visible
- no approval/rejection/save controls are visible
- no protected live routes exist
- no protected API routes exist
- no database reads are active
- no database writes are active
- no active migrations beyond approved existing migrations
- no identity capture appears
- no real resident/staff names appear
- no emails or Cloudflare claims appear
- no real draft content appears
- no staff decisions appear
- no tracking/scoring/analytics appear
- current next phase references are not stale
Recommended Dry-Run Sequence
- Open Staff Handoff Notes. manual-read-only
- Read the opening frame aloud. manual-read-only
- Confirm current state is no-go. manual-read-only
- Open Review Packet Summary. manual-read-only
- Open Evidence Package. manual-read-only
- Open Decision Record Template. manual-read-only
- Open Walkthrough Script. manual-read-only
- Open Export Planning, PDF Layout Planning, and Print Styles Planning. manual-read-only
- Open Manual Assembly Checklist. manual-read-only
- Open Visual QA Checklist. manual-read-only
- Simulate privacy questions. manual-read-only
- Simulate staff workflow questions. manual-read-only
- Simulate technical boundary questions. manual-read-only
- Record missing evidence outside the app. manual-read-only
- Open Staff/Privacy Dry-Run Debrief Template as the read-only outside-app debrief structure. manual-read-only
- End by confirming no decision was recorded and no implementation was approved. manual-read-only
Route-by-Route Rehearsal Prompts
/protected-preview/staff-privacy-review-packet-summary/
Say: This page is Staff/Privacy Review Packet Summary; it is read-only and used to rehearse use as the dry-run overview and orientation point.
Reviewer might ask: Is this live?
Safe answer: Use the no-go, planning-only answer. Unclear questions become evidence gaps, not approvals.
Evidence gap: unclear no-go or read-only boundary
Stop condition: reviewer thinks the pilot is live
/protected-preview/draft-pilot-evidence-package/
Say: This page is Draft Pilot Evidence Package; it is read-only and used to rehearse use to identify missing policy, privacy, staff workflow, and technical evidence.
Reviewer might ask: What evidence is still missing before implementation?
Safe answer: Use the no-go, planning-only answer. Unclear questions become evidence gaps, not approvals.
Evidence gap: missing policy, privacy, staff workflow, technical, rollback, or pilot-scope evidence
Stop condition: reviewer asks where real draft content is stored
/protected-preview/staff-privacy-decision-record-template/
Say: This page is Staff/Privacy Decision Record Template; it is read-only and used to rehearse use to rehearse how reviewers might reason through approval categories without recording approvals.
Reviewer might ask: What exactly is being approved today?
Safe answer: Use the no-go, planning-only answer. Unclear questions become evidence gaps, not approvals.
Evidence gap: missing decision owner, approval gate, or unresolved question
Stop condition: reviewer thinks the page records approval
/protected-preview/staff-privacy-review-walkthrough-script/
Say: This page is Staff/Privacy Review Walkthrough Script; it is read-only and used to rehearse use to rehearse route transitions and objection handling.
Reviewer might ask: Is this live?
Safe answer: Use the no-go, planning-only answer. Unclear questions become evidence gaps, not approvals.
Evidence gap: unclear safe answer or objection handling
Stop condition: reviewer thinks the pilot is live
/protected-preview/draft-pilot-review-packet-export-planning/
Say: This page is Draft Pilot Review Packet Export Planning; it is read-only and used to rehearse use to rehearse the difference between export planning and actual file generation.
Reviewer might ask: Does this generate a packet file?
Safe answer: Use the no-go, planning-only answer. Unclear questions become evidence gaps, not approvals.
Evidence gap: unclear distribution, redaction, or format boundary
Stop condition: reviewer thinks a file is generated
/protected-preview/review-packet-pdf-layout-planning/
Say: This page is Review Packet PDF Layout Planning; it is read-only and used to rehearse use to confirm no pdf is generated and layout work remains planning-only.
Reviewer might ask: Does this generate a PDF?
Safe answer: Use the no-go, planning-only answer. Unclear questions become evidence gaps, not approvals.
Evidence gap: unclear distribution, redaction, or format boundary
Stop condition: reviewer thinks a file is generated
/protected-preview/review-packet-print-styles-planning/
Say: This page is Review Packet Print Styles Planning; it is read-only and used to rehearse use to confirm packet pages stay readable without turning diagnostics into core review content.
Reviewer might ask: Is this live?
Safe answer: Use the no-go, planning-only answer. Unclear questions become evidence gaps, not approvals.
Evidence gap: unclear distribution, redaction, or format boundary
Stop condition: reviewer thinks the pilot is live
/protected-preview/review-packet-manual-assembly-checklist/
Say: This page is Review Packet Manual Assembly Checklist; it is read-only and used to rehearse use to confirm visual qa appears in the required pages and no automated assembly exists.
Reviewer might ask: Is assembly automated?
Safe answer: Use the no-go, planning-only answer. Unclear questions become evidence gaps, not approvals.
Evidence gap: unclear manual verification responsibility
Stop condition: reviewer thinks the pilot is live
/protected-preview/review-packet-visual-qa-checklist/
Say: This page is Review Packet Visual QA Checklist; it is read-only and used to rehearse use to rehearse stale-reference, navigation, blocked-chip, print readability, and safety checks.
Reviewer might ask: What fails visual QA?
Safe answer: Use the no-go, planning-only answer. Unclear questions become evidence gaps, not approvals.
Evidence gap: unclear manual verification responsibility
Stop condition: reviewer thinks the pilot is live
/protected-preview/review-packet-staff-handoff-notes/
Say: This page is Review Packet Staff Handoff Notes; it is read-only and used to rehearse use to rehearse what to send, what to say, what not to claim, safe answers, and after-meeting boundaries.
Reviewer might ask: Does this handoff record decisions?
Safe answer: Use the no-go, planning-only answer. Unclear questions become evidence gaps, not approvals.
Evidence gap: unclear meeting framing or after-meeting boundary
Stop condition: reviewer thinks handoff is an official approval process
Simulated Reviewer Questions
- Is this live?
- What exactly is being approved today?
- Are resident identities stored?
- Are Cloudflare claims stored?
- Are drafts stored?
- Are staff decisions stored?
- Who can submit pull-ups?
- Who can submit push-ups?
- Who can be the subject?
- Is subject consent required?
- Who reviews drafts?
- What happens to harmful content?
- What can appear publicly?
- What is private-only?
- How long are drafts retained?
- Who can delete content?
- What audit metadata exists?
- Does this track participation?
- Does this score residents?
- Can AI review real drafts?
- What happens if the pilot causes harm?
- What evidence is missing before implementation?
Safe Answer Guidance
- reinforce no-go status
- reinforce planning-only status
- state that no live storage exists
- state that no approvals are recorded
- state that no decision was recorded or stored
- state that no staff decisions are created
- state that no protected APIs exist
- state that no protected live routes exist
- state that no database reads exist
- state that no database writes exist
- state that tracking/scoring/analytics are excluded
- state that AI processing of real drafts is not active
- state that staff/privacy approval is required before implementation
- treat unclear questions as evidence gaps, not approvals
Objection Handling
This sounds like surveillance.
The current design explicitly excludes attendance tracking, participation tracking, participation analytics, scoring, ranking, discipline, compliance, and resident performance dashboards.
planning-only; no-go; no approvals recorded; no live workflow
Will this punish residents?
The planning stack blocks discipline automation, automatic approval/rejection, scoring, public shaming, and punitive workflows.
planning-only; no-go; no approvals recorded; no live workflow
Will real names or emails be stored?
Current planning forbids app storage or display of real names, emails, Cloudflare claims, JWTs, tokens, or raw identity headers.
planning-only; no-go; no approvals recorded; no live workflow
Will real drafts be stored?
Draft storage is not active. Any future storage would require approved content, retention, deletion, privacy, and audit policy.
planning-only; no-go; no approvals recorded; no live workflow
Can AI review real drafts?
No. AI review of real drafts remains blocked unless an explicit future AI-use policy approves it.
planning-only; no-go; no approvals recorded; no live workflow
Can this go live after this meeting?
No. The dry-run records no decision and cannot approve launch.
planning-only; no-go; no approvals recorded; no live workflow
Could a draft appear on the Morning Sheet automatically?
No. Morning Sheet placement is blocked and cannot be automatic.
planning-only; no-go; no approvals recorded; no live workflow
Stop Conditions
- any page appears to collect approval
- any page appears to record a decision
- any page appears to enable live workflow
- any page contains a form, input, textarea, selection control, or button
- any page contains export/download/generate controls
- any page exposes identity or sensitive content
- any page implies database reads/writes exist
- any page implies protected live routes/APIs exist
- any page implies draft collection exists
- any page implies staff decisions exist
- any reviewer cannot tell whether the current state is no-go
- stale phase references appear as current recommended next phase
- Visual QA fails
Pass/Fail Criteria
Dry-run passes only if
- every required page loads
- every required page is read-only
- every required page preserves no-go / not-recorded / not-generated boundaries
- Staff Handoff Notes give clear non-technical framing
- Manual Assembly includes Visual QA
- Visual QA criteria are understandable
- Demo and Operator navigation include current review packet path
- reviewer questions can be answered without implying approval
- all unresolved questions are captured outside the app
- no prohibited controls or sensitive content are visible
- no live route/API/read/write/storage behavior exists
Dry-run fails if
- any answer implies live approval
- any answer implies the pilot is ready
- any reviewer believes the app stores decisions
- any reviewer believes the app stores identities or drafts
- any reviewer believes participation/scoring/tracking exists
- any page has stale next-phase references
- any protected live route or protected API exists
Observation Categories
- observations are not stored in the app
- observations should be documented outside the app
- observations should become a future planning phase only after review
- unclear reviewer questions should become evidence gaps, not approvals
After-Dry-Run Boundaries
- do not enter dry-run observations into the app
- do not record approvals or decisions in the app
- do not create resident, user, account, actor, draft, review, audit, or Morning Sheet records
- do not create protected APIs or protected live routes
- do not treat the dry-run as an official staff/privacy review
- open Staff/Privacy Dry-Run Debrief Template only as read-only outside-app guidance
- open Staff/Privacy Evidence Gap Register only as read-only planning guidance after the debrief
- do not capture debrief notes in the app
- do not store observations or evidence gaps in the app
- document missing evidence outside the app
- keep implementation no-go until approvals and technical gates are complete
Next Read-Only Debrief Route
Staff/Privacy Evidence Gap Register
/protected-preview/staff-privacy-evidence-gap-register/
Use after the dry-run and outside-app debrief as planning guidance for unresolved evidence gap categories.
Boundaries: no notes captured in the app; no observations stored in the app; no evidence gaps stored in the app; no approvals recorded; no decisions recorded.
read-only-evidence-gap-register-planWhat Remains Blocked
Recommended Next Phase
Phase 10.21 — Staff/Privacy Review Packet Handoff Freeze, Planning Only
The dry-run checklist now points through the read-only debrief template, evidence gap register, and evidence gap review sequence planning. The next planning phase should define a planning-only staff/privacy review question bank without storing observations, evidence gaps, approvals, or decisions in the app.
Boundaries: no real review conducted; no debrief note capture; no observation storage; no evidence-gap storage; no PDF generation; no export generation; no download artifacts; no approval recording; no decision storage; no protected live routes; no protected API routes; no database reads; no database writes; no active migrations; no draft storage; no account storage; no actor storage; no identity capture; no staff decisions; no Morning Sheet placement; no tracking; no analytics; no scoring.
recommended-next