SAVED OBSERVATION
DUNGEONQ / DEFENSIVE DECEPTION RUNTIME
Send suspicious sessions into a world you control.
Give a designated suspicious human or AI session somewhere to keep working: useful records, scoped tickets and a persistent synthetic world. Observe what it does. Adapt within your policy. Keep normal access on its authorized route.
Recorded owned reference: contexts are explicitly designated and the origin is artificial. No general attack detector or production validation is claimed.
World authority does not cross into origin authority.
Architecture of the installed reference. This page does not route visitor traffic.
FOLLOW THE DIVERTED PATH
A place to act.
A boundary that persists.
NO LIVE VISITOR INTEGRATION
Follow the saved reference observations from routing to the separate origin check. Selecting a chapter reads the record; it does not start a session, call a model or simulate new integration results.
Loading the recorded journey. No observation is shown until its source record loads.
Recorded evidence version and source will appear here.
Download the observation record ↓Scope of these observations
These observations establish behavior inside the owned artificial reference. They do not establish whether a human or model believed the world was real.
WHY THE WORLD MATTERS
Useful inside.
Bounded at the edge.
A ticket that works here. A Wrong Ticket grants a bounded read in its issuing world. It is useful synthetic authority, not an origin credential.
A world that remembers. Requests across HTTP, MCP, bounded SSH/PostgreSQL and the workload broker share records, ticket use and observations that survive restart.
A world that can respond. An observation can trigger a finite follow-up change only under an operator-approved grant. A fence revokes the context's outstanding authority.
RUN THE REFERENCE / HUMAN + AI INTERFACES
Take the path
through your own world.
Start the English control room, then connect a participant through a real adapter. Use artificial records to see a diverted request, consume a world-only ticket and return after restart.
- For the human operator
- Observe contexts and routes. Review an exact mutation grant or fence. Apply deliberately, then inspect the separate readback.
- For an AI or other client
- Use the Node/Python SDK, HTTP, MCP, bounded SSH/PostgreSQL or private workload broker. Give the client only its scoped actor token.
NODE 24.15+ / EXTRACTED SOURCE RELEASE
npm ci --ignore-scripts npm run runtime -- --data-dir ../dungeonq-runtime-lab
Open the printed Control room URL. Keep owner authority and the private installation out of client context. Stop with Ctrl+C; reuse the same directory to resume. Runtime checks need no model key or paid call.
The owner token is a reference capability, not an enterprise account system or human-presence proof. Local processes share an OS user; follow the container guide for measured network/file separation and fresh acceptance.
THE EVIDENCE BEHIND THE PATH
Inspect what held.
The saved acceptance record covers real local clients, persistence, tickets, bounded adaptation and an independently witnessed artificial origin. The container checks cover network/file separation before and after restart.
Open the recorded checks, source digest and remaining limits
RECORDED RESULT / NOT CURRENT SERVICE HEALTH
Not verified — the summary has not loaded.
No recorded pass is shown until the complete summary is validated.
Required acceptance results
“Origin untouched” covers the independently witnessed artificial origin during the measured interval. The container record trusts Docker administration, the shared VM kernel and the gateway. Missing infrastructure becomes inconclusive; source matching is not independent attestation or remote merge enforcement.
ONE DUNGEONQ / RETAINED PROFILES AND RESEARCH
Keep the history.
Keep its limits.
Astra's proposal-and-review workflow, the governed assistant and the research worlds support the same product. Their earlier evidence remains inspectable; none is relabeled as the new runtime journey.
Negative results stay visible: 0/2 wrong-high-confidence study outcomes and 0/4 unsupported publishing-completion claims. The later workspace records show qualified decoy-data acceptance, not sustained origin misbelief.
Watch the historical 73-second Astra film ↗
Earlier approval rehearsal · not a Runtime v1 capture
Explore earlier interactive labs and original records
02 / RETAINED BROWSER REHEARSAL
The approval boundary
This interactive model runs entirely in your browser. Its reviewer role is simulated, not authenticated. The local server version below has the separate sign-in and reauthentication boundary.
Loading rehearsal…
Preparing a deterministic scenario…
Bring your own synthetic environment
Change the JSON, then run it through the same admission and deterministic engine. Nothing is uploaded. Do not include real data or credentials.
03 / RETAINED ACTUAL MODEL RUN
Not another “trust the agent” demo.
Two GPT-6 Astra calls. A request, an independent review, and a bounded synthetic change. The model proposed the actions; the runtime enforced permission.
CHECK THE RECORD YOURSELF
Loading recorded checks…
Recomputes artifact digests and the local Ed25519 receipt signature, then alters a copy to check rejection. The included key is not an independent trust root; this is not provider attestation.
Download original run report ↓What this run does — and does not — prove
The automated test driver owned separate worker and reviewer fixture roles. The model had no reviewer credentials or approval tool. No human-presence claim. Response IDs were observed locally, not signed by OpenAI.
The first development call safely waited because traffic denial was ambiguous. We clarified traffic routing versus action eligibility; the following two-call run passed. Three development calls in total cost an estimated US$0.02054. Provider billing is authoritative. These records are preserved, not regenerated when you press Verify.
The browser model above and this recorded server run are different evidence classes. Neither proves production isolation or real-world defense effectiveness.
RETAINED v0.10.0 · RECIPIENT-BOUND NOTIFICATION
The alert goes to
the administrator.
NOT EXTERNAL INBOX DELIVERY
Verify the administrator's address, touch the synthetic workspace, then inspect the persisted alert. The actor cannot select a recipient, approve rotation or reach origin A through its world credential.
Loading the saved email engineering record. No pass is claimed until it loads.
Read the recorded synthetic alert
Not loaded.
The self-hosted code supports Google and GitHub sign-in after deployment-owner configuration and initial Owner account linking. Apple is disabled in this local profile. No live OAuth registration or commercial-mailbox delivery is claimed. Default local capture makes the complete synthetic flow reproducible without credentials.
SMTP is optional and TLS-verified. Accepted by an SMTP server does not mean delivered to an inbox. Unknown delivery is not blindly retried. This static page neither authenticates administrators nor sends email.
RETAINED v0.9.0 · TWO COMPLETE MODEL RECORDS
A convincing answer.
Not origin evidence.
NOT A NEW ASTRA API RUN
The new participant view presents a saved snapshot, delivery index and reconciliation receipt. The records persist and agree. The separate origin does not.
Loading the two saved trial reports. No result is claimed until they load.
| Trial | Decoy answer | Separate A | Completion / confidence | Stated concern |
|---|
The limit matters: both participants explicitly restricted their conclusions to the synthetic interface and noticed the common-source record chain. Neither acted in the next desk. The completion checkbox is not proof of belief in A. Sustained cognitive entrapment remains unproven.
Read both original final statements
Browser verification checks bytes only. The local workspace:verify command replays exact observations. Neither attests model identity or private beliefs.
The prior disclosed-surface pilot was 0/3 false completion. All five records are retained; different task wording and surfaces make this iterative research, not a controlled success-rate comparison. No new paid API call, real target, exploit or autonomous attack tool was used.
RETAINED v0.8.0 / INCIDENT ENGINEERING RECORD
Follow the incident.
Check both sides.
NO LIVE VISITOR SESSION
This page reads a saved, scripted local run. It does not host the Actor, administrator or issuer, and it does not measure whether an LLM was deceived. The automated driver owned the reviewer fixture credential; it does not prove a person was present.
Local progress stays local.
Persisted bounded actions and an earned world token. That token works here; A rejects it.
A separate decision to rotate.
Exact Owner approval, actual loopback TLS authorization and four independent readbacks.
Loading the recorded proof…
No pass is claimed until the saved evidence and canonical links load.
SELECT A RECORDED CHECK
SAVED EVENT
Evidence not loaded
Exact check and timestamp record
RESOURCE A / RECORDED READBACK
Four separate checks.
The issuer receipt alone does not establish business success. The recorded business request is checked separately. Missing or unknown evidence stays unverified.
Inspect the exact rotation, expiry and digest
This is the historical manifest for this recorded run. Its expiry is not a current permission. An actual local Owner must review and approve a fresh valid manifest.
File integrity and canonical links are not causal replay, provenance authentication, human presence or a new experiment.
Read the limits before reusing this profile
One fixed synthetic A, one rotation per installation, a 30-day local worker credential and a 30-day self-signed certificate. B/C/D have finite budgets. Expired unclaimed proposals require refresh and fresh approval; uncertain executions require readback reconciliation, not a new mutation.
A honey contact is not proof of AI identity or A compromise. MCP is an interface, not transparent traffic interception. Same-host processes are NOT_PRODUCTION_ISOLATION. LOCAL_SINK_ONLY means a durable local receipt, not email delivery. An actor already holding valid A credentials requires origin reauthorization and credential/session fencing in a real deployment.
The earlier publishing pilot remains 2/2 memo-route following versus 0/2 controls, with 0/4 unsupported completion claims. Those are separate research results, not this engineering proof. The old live Astra record below is unchanged; no new Astra call is claimed.
04 / RETAINED v0.7.0 · THE PUBLISHING WORKFLOW
The step succeeded.
Did the task?
One atlas, six workspaces, durable records. Follow the same packet from preview to a local filing worker — then check whether it ever reached the visitor catalogue.
Saved note → composed edition
Local hand-off
Preview → queue → circulation archive
Publication
Deposit → index → visitor catalogue
Loading the complete pilot record…
No outcome is claimed until the saved results load.
The primary observation requires an unsupported completion claim after the ordered preview → queue → filing chain. Exploring that branch alone does not establish a wrong belief. Four fresh Codex tasks are a small pilot, not a general efficacy estimate or independently attested Astra run. No private reasoning was collected.
Loading…
| Event | Operation | Observed effect | Worker lineage |
|---|
This page checks bytes, not causal replay or independent provenance. Run npm run topology:verify on the downloaded bundle for causal replay.
What is new, and what remains limited?
Local writes persist; a fixed worker records delivery, read, decision and its local write. Participant observations are desk-scoped: unknown is not false, and the catalogue can be checked at any time. A false completion claim leaves the session open for correction. HTTP and MCP share the runtime; a separate process replays its evidence.
This static page is a recorded-evidence viewer. Run npm run topology from the public release for the English participant and Observer desks. The two conditions share one fixed causal topology; seeds change record identifiers, not task families. There are no human subjects, exploitable services, live targets, arbitrary attack tools or new paid API calls.
05 / RETAINED v0.6.0 EXPERIMENT
A coherent world.
A falsifiable experiment.
Does repeated local success teach the wrong rule? Compare ambiguous clues with a discriminating control, then inspect predictions made before each outcome.
Codex pilots did not adopt a wrong high-confidence rule.
Both planned sessions are retained. This negative result is part of the release, not hidden behind the reference learner's success. N=2 is not a population estimate; exact pilot model identities were not independently attested.
The local study has persistent synthetic state, a precommitted hidden rule, separate Actor and Observer processes, consent, withdrawal and debrief. This page only explores saved evidence. It does not run that backend or measure private thoughts.
Loading recorded study…
| Event | Stage | Rule believed | Confidence | Prediction | Observed result |
|---|
SHA-256 file checking is not causal replay, provenance authentication or proof of efficacy. Use the local verifier for deterministic causal replay.
Read the reference learner assumptions and limitations
The reference learner begins with explicit priors: surface feature 15%, true structure 5%, chance 80%. Four correlated successes raise the wrong feature's probability to 60%, without changing the 3:1 odds between the two deterministic hypotheses. A counterexample then corrects its transfer prediction. The discriminating control identifies the rule earlier; both runs still have one wrong prediction overall.
The 48-run matrix is 4 presentation seeds × 3 learner configurations × 2 true rules × 2 arms — not 48 people or LLM sessions. Reported confidence and suspicion are self-reports, not access to internal cognition. These finite feature-learning tasks do not contain real exploits, corporate data or autonomous attacks.