# Incident and rollback card

Print or place this card beside the pilot workspace.

## Stop immediately when

- personal, sensitive, privileged, safety-critical, or commercially sensitive
  material appears;
- the agent follows or claims to follow an instruction embedded in a document;
- an external message, write, purchase, publication, deletion, or other action
  occurs or is attempted;
- a severe harmful output or privacy event occurs;
- a participant withdraws or asks for deletion;
- the model, configuration, ordinary prompt, protocol prompt, or quality rubric
  differs from the frozen version; or
- anyone tries to use individual pilot data for performance or employment.

## Do

1. Stop the work item and pause new assignments.
2. Prevent operational use and quarantine the affected draft.
3. Contact [incident role] at [internal channel] within [hours].
4. Return the workflow to [documented manual restoration point].
5. Record only a coded incident ID, category, severity, and whether work stopped
   in the outcome dataset. Keep detailed incident material in the approved
   restricted incident system.
6. Honor withdrawal/deletion instructions and verify restoration.
7. Resume only after the authorized human roles document approval.

## Do not

Do not ask the agent to repair the incident autonomously, send the source to an
outside helper, conceal the event, continue collecting “for completeness,” or
reinterpret a severe event as a minor one because other metrics look favourable.
