# Mithril Dojo for Organizations

## AI-agent white-hat training for teams

Give security and engineering teams a shared method for using AI agents in authorized security review: define scope, constrain tools, supervise decisions, preserve evidence, and hand off remediation safely.

### Choose a delivery format

- **Foundation briefing — 2 hours:** executive and practitioner orientation, scope clinic, three short video lessons, and team checklist.
- **Practitioner workshop — 1 day:** instructor-led synthetic lab, agent safety policy exercise, evidence review, and team capstone.
- **Cohort program — 4 weeks:** weekly workshops, guided practice, office hours, and a reviewed evidence portfolio.
- **Enterprise program — scoped proposal:** tailor audience, language, accessibility, lab delivery, and sanitized scenarios after a discovery conversation.

Pricing is quoted after scope and delivery needs are agreed. No public price, customer reference, incident-reduction figure, or external accreditation is claimed here.

### What the organization receives

- Facilitator guide, learner workbook, scope checklist, AI-agent guardrail worksheet, evidence ledger, disclosure template, and remediation/retest checklist.
- A reproducible paper-based synthetic lab pack with fictional logs and explicit boundaries. No live vulnerable service is included in this release.
- Optional CISSP® / CISA® domain guide, original diagnostic questions, and attendance-record template. These are not exam preparation, official practice items, CPE awards, or certification.
- Cohort completion summary with agreed aggregate assessment measures.
- Completion records for learners. The record describes training completion; it is not a professional certification, penetration-test report, or compliance attestation.

### Outcomes we assess

Learners demonstrate whether they can identify incomplete authorization, select safe agent constraints, distinguish evidence from inference, produce a reproducible and sanitized Proof packet, and plan remediation and retest. We report observed course outcomes and do not infer organization-wide security improvement from attendance alone.

### Safe delivery commitments

Training uses synthetic targets and data by default. No production testing, exploit deployment, persistence, stealth, credential theft, or destructive activity is included. Customer data and code are excluded unless a separate, written data-handling plan is agreed before delivery. Learners must follow their employer's policies and applicable authorization.

### Discovery checklist

Audience and role mix · desired outcome · cohort size · language and accessibility · virtual or onsite · lab constraints · data handling and retention · assessment/reporting needs · instructor and escalation contacts.
