NORNR mark NORNR Shadow mode before enforcement.

NORNR / Shadow mode

No blocking yet

See what NORNR would have decided before you turn enforcement on.

Start from an existing runtime, browser or tool flow. NORNR should name where the action becomes real, what would have queued or blocked, and which defended record your team is still missing.

Shadow mode is the adoption bridge: insight, replay and packet first. Enforcement comes after the same lane is already legible.

Point NORNR at one live lane and get one report back.

Keep the current runtime. Pick one flow and one surface. NORNR should return one shadow report now, while keeping the same lane-id, packet spine and replay path that will later graduate into review-only and enforced.

Shadow report

One consequential provider step would queue above a reviewed threshold.

Shadow mode should show the first place the action becomes real without asking the team to enforce yet.

Decision surface
Boundary src/llm/provider.ts:203 (provider request)
Would decide Queue above one reviewed threshold
Pressure Recurring spend starts at the provider request, not after it.
Missing record
Missing now One defended record tying decision, owner, counterparty and export together.
Replay posture Replay only first. No blocking yet.
Next move Open one install path and keep the same lane in shadow first.
Install next
Framework OpenAI Agents
Lane Provider spend threshold
Packet Replay artifact / proof packet / finance packet
Weekly shadow memo
Headline One weekly memo should summarize what NORNR would have queued.
Owner next Ops receives the first weekly tightening note.
Memo output Boundary / decision / missing record / next install move
Lane identity
Lane ID lane.paid-model.openai
Packet spine Intent -> PolicyDecision -> Mandate -> CounterpartyStatus -> ApprovalState -> SettlementState -> ReceiptTrail -> AuditExport
Replay path Replay the same lane before you ask it to queue or clear.
Promotion path

Shadow should be the first stage of the same lane, not a disconnected preview.

  • Shadow -> one report from the live lane.
  • Review only -> one defended packet from the same lane.
  • Enforced -> one close handoff from the same lane.
Install this one lane Open control room Open full audit
Email capture after value Shadow artifact only after preview

Keep the shadow report without creating a workspace first.

Once the report is useful, send the shadow report or weekly memo to a work email. The right next move is still installer or audit, not a generic registration wall.

Shadow mode is ready. Email capture stays downstream of the report.