Pilot purpose
A DetCordon pilot demonstrates the contained observation and evidence workflow with synthetic payloads before any hostile workload is considered. It is a review-gated engagement, not an unauthenticated public sandbox.
Pilot sequence
- Agree the workload class, two-host topology, evidence-retention window,
- Review containment assumptions and unresolved trust gates.
- Run host preflight and generate deployment artifacts from the reviewed
- Execute the synthetic observation path through the DetectionOnly tap.
- Confirm expected events, encrypted samples, provenance, checksums, and
- Verify the signed evidence bundle offline using a separately obtained trust
- Record exceptions, remediation work, and the decision on whether hostile
analyst access, and success criteria.
release.
custody metadata without displaying sample bodies.
anchor.
workloads may be introduced.
Acceptance boundary
A successful demonstration proves that the reviewed synthetic run produced the expected evidence shape and that the handoff bundle detects tampering. It does not prove kernel isolation on every host, guarantee lossless telemetry, or authorize managed production. A pilot advances only when its written trust gates and operational checks pass.
Detailed operator commands, infrastructure values, and internal failure triage remain in the qualified diligence packet.