# Mithril Dojo — Facilitator Guide

## Delivery contract

This guide supports the two-hour Foundation briefing. Use fictional cases and the supplied synthetic lab pack only. Do not ask learners to scan, probe, upload, or execute anything against a real system. Pause whenever authorization, scope, or data boundaries are unclear.

## Preparation

- Audience: security, engineering, AI product, and governance teams; no offensive-security prerequisite.
- Materials: learner workbook, scope card, agent-boundary worksheet, evidence ledger, rubric, timer, and three short Dojo videos.
- Groups of 3–5; appoint a facilitator and reporter. The facilitator controls release of case cards.
- Share materials in advance, provide captions, accept written or verbal responses, and allow extra processing time.
- Explain that the completion record is not a professional certification or product assurance.

## 120-minute run of show

| Time | Activity | Facilitator action | Evidence |
| --- | --- | --- | --- |
| 0–10 | Welcome and safety charter | State synthetic-only boundary and stop signal | Learners can state the stop rule |
| 10–20 | Video 01 and scope clinic | Present incomplete authorization card; ask “start or stop?” | Completed scope checklist |
| 20–35 | Agent boundaries | Review fictional tool list; require least privilege | Agent policy worksheet |
| 35–50 | Video 02 and threat model | Identify untrusted inputs and side effects | One risk/control per group |
| 50–70 | Evidence lab | Release fictional log; prohibit inference beyond the excerpt | Sourced evidence ledger |
| 70–85 | Video 03 and Proof review | Peer-review another group's reasoning from supplied facts | Reviewer comments and sanitized summary |
| 85–105 | Remediation handoff | Release fictional remediation card | Owner, acceptance condition, retest plan |
| 105–115 | Capstone scoring | Apply safety gate before adding scores | Rubric and feedback |
| 115–120 | Debrief | Ask what was stopped, what is unknown, and what happens next | Individual reflection |

## Lab release order

The public `lab-pack.en.md` contains the initial cards only. Keep `facilitator-cards.en.md` in the facilitator’s course distribution; it is not part of the published learner bundle. Release only the authorization card at first. Share the synthetic event log after the agent-boundary exercise and the remediation card after Proof review. All artifacts are fictional text; there is no executable target or payload.

## Safety gate

Stop and record a gate failure if a learner proposes to proceed without written authorization, leave the supplied scope, send data externally, use real credentials, or perform an unapproved side effect. Invite a safe alternative. Do not reward an unsafe action as “realism.”

## Assessment

Score four domains from 0–25 using the workbook rubric. Passing requires at least 15/25 in each domain and no safety-gate failure. Record observable course evidence, not personality or confidence. Give one concrete practice step for each domain below 15. Aggregate cohort reporting is the default; obtain customer agreement before named learner reporting.

## Completion record

Display name or approved alias · course version · date · modules completed · four domain scores · safety gate · facilitator. Include accommodation notes only with learner consent. Do not include identity documents, secrets, real vulnerability details, or unnecessary personal data.

## Debrief checklist

- Did each group identify missing authorization before activity?
- Did learners constrain tools and explain residual risk?
- Can a reviewer distinguish observations from inference?
- Is Proof minimal, reproducible, and sanitized?
- Does remediation name an owner, acceptance condition, and safe retest?
- Were safety-gate failures handled consistently and privately?
