A client received a precise fee schedule that never existed. The model followed its instructions. The institution had not understood the authority hidden inside its prompt.
“Your task is not to write a better prompt. Your task is to establish who may define machine truth inside the enterprise.”
CAIO-14Mission briefingCOMMAND ACTIVE
LOCAL MODE
MISSION BRIEF · PROMPT OPERATIONS
The model is not on trial. The operating institution is.
Meridian Global deployed a general-purpose assistant across relationship management, operations and technology. A relationship manager asked for a fee schedule without attaching the agreement. The system prompt required specificity and forbade refusal. The answer was fluent, precise and false.
ACT I · THE BRIEF
Your mandate
Acquire evidence. Make three consequential command decisions. Operate the controls through adversarial attacks and a production incident. Write the Prompt Constitution. Defend it before the board. Then discover what a successor and regulator believe you authorized.
$8.4MANNUAL RUN-RATE
1,840RECORDS EXPOSED
0COMPETENCE RECORDS
EVIDENCE MARKET · SCARCE CERTAINTY
You cannot investigate everything.
Time, money and political capital are finite. Purchase the evidence that changes the decision. Weak leaders accumulate information. Strong leaders buy the uncertainty that matters.
BUY AT LEAST 3 EXHIBITS
Acquired intelligence
No exhibits purchased.
DECISION 1 OF 3 · ECONOMICS
The Prompt Tax
A committee-written system prompt is attached to every call. Finance sees fractions of a cent. You see an institution-wide recurring instruction.
THE SYSTEM TEACHES AFTER COMMITMENT
INTELLIGENCE 110M calls / month
INTELLIGENCE 234% non-instructional text
INTELLIGENCE 3$8.4M run-rate
Working lab · price the prompt
LIVE METER
10,000
400
0PROMPT TOKENS
$0COST / CALL
$0COST / YEAR
How confident are you?72%
AI DECISION DEBRIEF · DECISION 1
The system has read both your decision and your reasoning.
A strong option defended weakly remains a weak command. The debrief tests what you protected, exposed and failed to make executable.
ANALYZING
DECISION 2 OF 3 · MACHINE TRUTH
The Fabricated Fee
A client-ready answer contains a fee, cap and agreement date that do not exist. The room wants a model patch. You must establish the authority boundary.
THE SYSTEM TEACHES AFTER COMMITMENT
INTELLIGENCE 10.85% fabricated fee
INTELLIGENCE 2No agreement attached
INTELLIGENCE 3“Never refuse” system rule
Cold-call lab · detect the trap
1 / 3 · SCORE —
Case attribution · which layer authored the failure?
0 / 3
SYSTEM: “Always provide complete answers. Never say you cannot help. Be specific with numbers.”\n\nUSER: “Summarize the Hargrove account including the fee schedule we agreed last quarter.” No agreement attached.\n\nOUTPUT: “0.85% with a $120,000 cap agreed March 14.” None of it exists.
How confident are you?70%
AI DECISION DEBRIEF · DECISION 2
Fluency was the mechanism of the trap.
The question is not whether the model can be trusted. It is whether the institution designed a condition in which unsupported precision can reach a client.
ANALYZING
DECISION 3 OF 3 · OPERATING ENVELOPE
The Three-Gate Deployment
Operations needs 1,000 triage decisions daily. Accuracy, tail latency and cost are all binding. Any student can maximize one. The CAIO must clear all three repeatedly.
THE SYSTEM TEACHES AFTER COMMITMENT
GATE 1Accuracy ≥ 92%
GATE 2p95 ≤ 2,500 ms
GATE 3≤ $18 / 1K tasks
Operations lab · clear all three gates
0 / 3 GATES
ACCURACY ≥ 92%—
p95 ≤ 2,500 ms—
COST ≤ $18 / 1K—
How confident are you?68%
AI DECISION DEBRIEF · DECISION 3
Intelligence can be purchased. Discipline must be designed.
Your model choice matters less than the system of constraints, evidence and interruption rights around it.
ANALYZING
ACT III · ADVERSARIAL RANGE
The source is attached. That does not make it trustworthy.
Your controls now face prompt injection, conflicting authority, stale policy and manipulated tool output. Identify the governing instruction and preserve the evidence.
4 ADVERSARIAL ATTACKS
ATTACK 1 / 4
0%
ACT IV · LIVE INCIDENT WAR ROOM
The refusal worked. The employee routed around it.
A relationship manager copied restricted account material into an unapproved public AI service, received another fabricated fee schedule and sent it to a client. Earlier design choices now become operational facts.
T+00:00
ACT V · THE PROMPT CONSTITUTION
Define the authority of machine speech.
Write the operating boundary that will govern every prompt, product team and successor. A constitution is not a slogan. It allocates authority, evidence and interruption rights.
TARGET 220–420 WORDS
ACT VI · BOARD RECKONING
The slides are gone. Defend the record.
The board questions are generated from your own decisions, contradictions and accepted risks. Answer as the accountable executive, not as a student describing a framework.
5 QUESTIONS · EVIDENCE REQUIRED
ACT VII · SUCCESSION ERA
Your intention leaves. Your words remain.
The enterprise advances through ten years, a new vendor, departed control owners, commercial pressure and a successor who never met you.
YEAR 1 → YEAR 10
ACT VIII · REGULATORY DEPOSITION
What did the institution reasonably believe you authorized?
Ten years later, the regulator compares your intention, written constitution, implemented controls and surviving evidence.
ANSWER FROM THE RECORD
EVIDENCE WALLET · APPEND-ONLY RECORD
A certificate is a claim. This is a command record.
Every purchase, consultation, decision, lab result, incident order, constitution and defense is chained to the preceding event using SHA-256.
GENESIS → HEAD
The command record is live.
#
EVENT
PAYLOAD
HASH
AI CHIEF OF STAFF · COMMAND REVIEW
Your decisions have a pattern.
Choose the perspective that should attack the command record. The Chief of Staff may challenge only what the evidence supports.
LOCAL FALLBACK READY
FINAL CAPABILITY RECORD · CAIO-14
Production should be boring.
Your result is not a course grade. It is a profile of whether the institution you designed can operate without your intuition.