NORNR
Shadow connect before enforcement.
NORNR / Shadow Connect
Shadow onlySwap one base URL. See what NORNR would have decided.
Shadow Connect is the light observer-proxy wedge: no blocking, no silent enforcement, no trust leap. Route one provider or tool flow through NORNR, see the consequential boundary, and get a weekly risk pulse worth forwarding.
Observer proxy
Keep the runtime. Connect one flow in shadow first.
This page is intentionally careful: one base URL swap, one shadow-only proxy, one weekly memo, and the same lane-id, packet spine and replay path the lane will keep as it graduates.
One base URL change should be enough to start shadow visibility.
Shadow Connect should return what NORNR sees, what it does not see, and one next lane if the flow is real enough to govern.
env
Sees
Intent metadata, destination, cost pressure and boundary shape.
Does not see
It does not need your full app or generic workspace rollout to start producing signal.
Would decide
Queue above one reviewed threshold once the flow graduates from shadow.
Headline
Your first weekly memo should say which seam actually mattered.
Output
Top boundary / drift note / next install lane / owner next
Next lane
Provider spend threshold first
Lane ID
lane.paid-model.openai
Packet spine
Intent -> PolicyDecision -> Mandate -> CounterpartyStatus -> ApprovalState -> SettlementState -> ReceiptTrail -> AuditExport
Replay path
Replay the same observed seam before promoting the lane.
Shadow Connect should start the lane, not fork it into a separate observer product.
- Shadow -> one weekly report from the same lane.
- Review only -> one defended packet from the same lane.
- Enforced -> one close handoff from the same lane.