# RobotGov Two-Level External Pilot Intake

Use this intake to define a bounded evaluation inside a partner-owned simulator or controller sandbox.

## Select the pilot level

- Level 1: exact-command boundary.
- Level 2: exact-command boundary plus one partner-owned authority-freshness dependency.

## Required for both levels

- Organization and technical owner:
- Policy or operational owner:
- Command name and consequence:
- Command schema and material fields:
- Sandbox or simulator:
- Harmless observable effect:
- Receiver or adapter interface:
- Test-only credential method:
- Required audience and asset identity:
- Maximum validity period:
- Expected integration constraints:

## Level 2 freshness dependency

Complete this section only for Level 2.

- Dependency name and operational meaning:
- Authoritative state source:
- Method for reading the current state:
- Version or freshness semantics:
- Material state changes that revoke or alter authority:
- Event source and authenticity mechanism:
- Event ordering and delivery guarantees:
- Commands affected by the dependency:
- Commit-time read available when an event is lost:
- Unrelated events that must not revoke authority:
- Retention and data-handling constraints:

Examples include operator authorization, maintenance clearance, geofence or target state, occupancy, mission approval, asset availability, and protected mode.

## Frozen acceptance cases

Level 1 evaluates exact command, direct access, changed command, replay, and outage.

Level 2 additionally evaluates current basis, relevant revocation, a lost material event caught at commit, and an unrelated event that must not revoke valid authority.

## Boundaries

- No production credentials.
- No hardware command path.
- No external LLM calls or token-based processing.
- No robot safety, feasibility, certification, or deployment claim.
- The partner owns the command, state semantics, material-event definition, and sandbox.
- RobotGov returns deterministic application, effect, and zero-effect evidence.
