Pilot Design Kit · governed release 04

Make the pilot earn the right to continue—before it starts.

Define one bounded hypothesis, the current baseline, affected-party input, measures, authority, incident handling, and precommitted stop and rollback conditions. Then preserve an explicit end-of-pilot decision instead of allowing a test to drift into deployment.

Go directly to the builder ↓

Design one bounded pilot

Nothing entered here is transmitted to Aloha AI. Do not paste confidential, privileged, personal, security-sensitive, or regulated information.

Restoring your local design… Jump to download and reset controls ↓

Do not start.5 readiness gate(s) failed or unresolved.
01Bound the test
02Assign authority and voice
03Precommit evidence and safeguards
04Readiness gates

Every gate must be evidenced as passed before the kit can stop saying “Do not start.” This is still not authorization.

Bounded purpose and hypothesis

The task, intended benefit, people affected, exclusions, duration, and testable hypothesis are defined.

Baseline, measures, and evidence plan

The current baseline, success and harm measures, disaggregation, evidence sources, and monitoring cadence are credible enough to learn.

Authority, review, and affected-party input

An accountable owner, capable reviewers, and a practical route for affected-party input and contestability are named.

Data, incident, stop, and rollback safeguards

Data authority and limits are documented, and incident, stop, rollback, and fallback paths are usable before testing.

End-of-pilot decision firewall

A named authority will choose stop, revise and retest, or consider a separate deployment decision; learning value alone cannot excuse failed safeguards.

05Preserve uncertainty

A pilot is not a quiet path to production.

The end state must be stop, revise and retest, or consider a separate deployment decision. Completion, positive averages, or learning value do not erase failed safeguards.