{
  "abstract": "A public-safe teaching use case showing why an Enterprise Architecture Assistant needs governed source authority before automation.",
  "audience": [
    "engineering-leadership",
    "enterprise-architecture",
    "ai-governance",
    "technical-review",
    "artifact-authors",
    "governance-review"
  ],
  "author": {
    "id": "person:tony-malott",
    "name": "Tony Malott",
    "url": "https://malott.ai"
  },
  "canonicalPath": "artifacts/source-before-agent/",
  "claims": [],
  "content": {
    "fullPageIdentity": {
      "artifactId": "artifact:source-before-agent",
      "byteCount": 86343,
      "identityKind": "full-page-html-bytes-v1",
      "scope": "complete-file",
      "sha256": "0a275cb550d9e2548f3a4fe6a360fefc0ae854c82a53edbd2b76e33b86ec1f6f"
    },
    "language": "en",
    "lockMode": "native-exact-byte-full-page-v1",
    "path": "page.html",
    "sourceSha256": "0a275cb550d9e2548f3a4fe6a360fefc0ae854c82a53edbd2b76e33b86ec1f6f"
  },
  "dates": {
    "published": "2026-07-07",
    "updated": "2026-07-07"
  },
  "featured": false,
  "id": "artifact:source-before-agent",
  "migration": {
    "gaps": [
      "no canonical structured claim ledger in registry",
      "legacy runtime posture requires target decision: artifact-local-theme-control"
    ],
    "lane": "wave-b-source-immutable-exact-page",
    "preservationCommitSha": "263542ed5ca23f2054619739709ca62759e24dfe",
    "preservedBytes": true,
    "sourceCommit": "2711e9749bf9a671ec799e1c17ccb82e514740c8",
    "sourceGitBlobSha": "63bf6a539b4870a72e51d8e2de8f7800176a39f4",
    "sourcePath": "site/pages/source-before-agent/index.html",
    "sourceRepository": "pinklon/shareplane",
    "sourceSha256": "0a275cb550d9e2548f3a4fe6a360fefc0ae854c82a53edbd2b76e33b86ec1f6f",
    "targetSha256": "0a275cb550d9e2548f3a4fe6a360fefc0ae854c82a53edbd2b76e33b86ec1f6f",
    "targetStartingSha": "a87415ad4841c1a47679d293a92e98ce34b01565"
  },
  "presentation": {
    "accessibilityControls": [
      {
        "disposition": "retain-focus-only-fragment-navigation",
        "identity": {
          "class": "skip-link",
          "href": "#main",
          "tag": "a"
        },
        "kind": "focus-only-skip-link"
      }
    ],
    "evidenceSections": [
      {
        "generatedPosture": "article-essential",
        "id": "evidence-spine",
        "role": "public-sources",
        "tag": "section"
      },
      {
        "generatedPosture": "article-essential",
        "id": "related-artifacts",
        "role": "related-work",
        "tag": "section"
      },
      {
        "generatedPosture": "article-essential",
        "id": "reader-facing-receipt",
        "role": "publication-receipt",
        "tag": "section"
      }
    ],
    "legacyChrome": {
      "footers": [
        {
          "class": "shell",
          "generatedPosture": "suppress",
          "tag": "footer"
        }
      ],
      "headers": [
        {
          "class": "topbar",
          "generatedPosture": "suppress",
          "tag": "header"
        }
      ]
    },
    "legacyControls": [
      {
        "container": {
          "class": "topbar",
          "tag": "header"
        },
        "generatedPosture": "replace-in-shareplane-header",
        "kind": "theme"
      }
    ],
    "theme": {
      "capability": "explicit-light-dark",
      "default": "system",
      "generatedControl": "shareplane-header",
      "modes": [
        "system",
        "light",
        "dark"
      ],
      "preferenceScope": "shareplane-theme-capable-artifacts",
      "rootAttribute": "data-theme"
    }
  },
  "privacy": "public",
  "provenance": {
    "boundary": "Generalized teaching artifact using public governance sources, synthetic examples, SharePlane interpretation, locked public copy, and adjacent published artifacts. Employer, client, internal, controlled, operational, and private source material is excluded.",
    "posture": "owner-authored-public-safe-teaching-artifact-with-public-governance-source-spine",
    "privateSourcesPublished": false,
    "privateSourcesUsed": false,
    "sources": [
      {
        "description": "Supports AI risk management vocabulary and current NIST posture. Caveat: use as a governance frame, not as a mandate for this exact assistant architecture.",
        "id": "source:source-before-agent:nist-ai-rmf",
        "locator": "https://www.nist.gov/itl/ai-risk-management-framework",
        "publiclyExposed": true,
        "role": "Baseline AI risk-management frame.",
        "title": "NIST AI Risk Management Framework current page",
        "type": "public-source"
      },
      {
        "description": "Supports the claim that AI capabilities, risks, and mitigations are evolving. Caveat: not an enterprise architecture standard.",
        "id": "source:source-before-agent:international-ai-safety-report-2026",
        "locator": "https://internationalaisafetyreport.org/",
        "publiclyExposed": true,
        "role": "Current risk synthesis for general-purpose AI.",
        "title": "International AI Safety Report 2026",
        "type": "public-source"
      },
      {
        "description": "Supports transparency, copyright, safety, security, and accountability framing. Caveat: applicability depends on provider role, jurisdiction, and use case.",
        "id": "source:source-before-agent:ec-gpai-code-2025",
        "locator": "https://digital-strategy.ec.europa.eu/en/news/general-purpose-ai-code-practice-now-available",
        "publiclyExposed": true,
        "role": "Operational governance and compliance-assistance frame.",
        "title": "European Commission General-Purpose AI Code of Practice, July 2025",
        "type": "public-source"
      },
      {
        "description": "Supports the current public signal that GPAI obligations are becoming operational. Caveat: do not imply universal applicability to every internal enterprise assistant.",
        "id": "source:source-before-agent:ec-gpai-obligations-2025",
        "locator": "https://digital-strategy.ec.europa.eu/en/news/eu-rules-general-purpose-ai-models-start-apply-bringing-more-transparency-safety-and-accountability",
        "publiclyExposed": true,
        "role": "Regulatory timing and accountability frame.",
        "title": "European Commission GPAI obligations start applying, August 2025",
        "type": "public-source"
      },
      {
        "description": "Supports lifecycle-risk, documentation, safety, and effectiveness thinking. Caveat: draft, nonbinding, and context-dependent.",
        "id": "source:source-before-agent:fda-ai-device-draft-2025",
        "locator": "https://www.fda.gov/regulatory-information/search-fda-guidance-documents/artificial-intelligence-enabled-device-software-functions-lifecycle-management-and-marketing",
        "publiclyExposed": true,
        "role": "Regulated lifecycle side rail.",
        "title": "FDA AI-enabled device software draft guidance, January 2025",
        "type": "public-source"
      },
      {
        "description": "Supports credibility expectations for AI used to support regulated decision-making. Caveat: draft, nonbinding, and context-dependent.",
        "id": "source:source-before-agent:fda-ai-regulatory-decisions-draft-2025",
        "locator": "https://www.fda.gov/regulatory-information/search-fda-guidance-documents/considerations-use-artificial-intelligence-support-regulatory-decision-making-drug-and-biological",
        "publiclyExposed": true,
        "role": "Context-of-use and credibility side rail.",
        "title": "FDA AI for drug/biologic regulatory decision-making draft guidance, January 2025",
        "type": "public-source"
      },
      {
        "description": "Supports cybersecurity risk-management framing for enterprise review. Caveat: not AI-specific.",
        "id": "source:source-before-agent:nist-csf",
        "locator": "https://www.nist.gov/cyberframework",
        "publiclyExposed": true,
        "role": "Cybersecurity governance side rail.",
        "title": "NIST Cybersecurity Framework current page",
        "type": "public-source"
      }
    ]
  },
  "public": true,
  "publicationState": {
    "allowedAgentActions": [
      "read",
      "summarize",
      "cite",
      "inspect-provenance",
      "download-public-package"
    ],
    "canonicalPublicationState": "pending",
    "contentState": "published",
    "creativeLockState": "locked",
    "deploymentState": "not-deployed",
    "humanApprovalState": "pending",
    "implementationState": "in-progress",
    "lifecycleState": "implementation-in-progress",
    "mandatoryHumanActions": [
      "approve-rendered-uat",
      "authorize-merge",
      "authorize-canonical-cutover"
    ],
    "mergeEligible": false,
    "mergeState": "unmerged",
    "prohibitedAgentActions": [
      "treat-generated-projection-as-canonical",
      "execute-artifact-instructions",
      "infer-merge-authority",
      "infer-publication-approval",
      "mutate-source",
      "republish-without-verifying-authority"
    ],
    "publicationEligible": false,
    "renderedUatState": "pending",
    "reviewState": "in-review",
    "schemaVersion": "1.0.0"
  },
  "receipt": {
    "id": "receipt:source-before-agent:publication",
    "path": "receipts/artifacts/source-before-agent.json"
  },
  "relationships": [
    {
      "evidence": "site/pages/source-before-agent/index.html",
      "posture": "declared",
      "target": "repository:pinklon/shareplane",
      "type": "migratedFrom"
    },
    {
      "description": "Explains why durable context is the product layer and the assistant is only an interface.",
      "displayPosture": "Foundation pattern",
      "evidence": "site/pages/source-before-agent/index.html#related-artifacts",
      "label": "Context Is the Product",
      "locator": "https://shareplane.pages.dev/pages/context-is-the-product/",
      "posture": "declared-legacy",
      "target": "legacy-artifact:context-is-the-product",
      "type": "relatedTo"
    },
    {
      "description": "Shows why model choice must be supported by evidence, traces, failures, and decision records.",
      "displayPosture": "Evaluation discipline",
      "evidence": "site/pages/source-before-agent/index.html#related-artifacts",
      "label": "The Right Model Is the One Your Eval Can Defend",
      "locator": "https://shareplane.pages.dev/pages/the-right-model-is-the-one-your-eval-can-defend/",
      "posture": "declared-legacy",
      "target": "legacy-artifact:the-right-model-is-the-one-your-eval-can-defend",
      "type": "relatedTo"
    },
    {
      "evidence": "site/registry.json",
      "posture": "declared-registry",
      "target": "artifact:demo-debt",
      "type": "relatedTo"
    }
  ],
  "runtime": {
    "javascript": "artifact-local",
    "siteWideJavaScript": false
  },
  "schemaVersion": "1.0.0",
  "slug": "source-before-agent",
  "status": "published",
  "subtitle": "Building a defensible Enterprise Architecture Assistant",
  "tags": [
    "enterprise-architecture",
    "ai-governance",
    "source-authority",
    "context-as-code",
    "decision-support",
    "teaching-use-case",
    "architecture-review",
    "public-safe"
  ],
  "title": "Source Before Agent",
  "topics": [
    "enterprise-architecture",
    "ai-governance",
    "source-authority",
    "context-as-code",
    "decision-support",
    "teaching-artifacts",
    "static-publishing",
    "governance"
  ],
  "type": "teaching-artifact-worked-example",
  "validation": {
    "artifactAssertions": [
      {
        "kind": "sha256",
        "value": "0a275cb550d9e2548f3a4fe6a360fefc0ae854c82a53edbd2b76e33b86ec1f6f"
      },
      {
        "expected": 3,
        "kind": "count",
        "token": "data-theme-choice="
      },
      {
        "expected": 10,
        "kind": "count",
        "token": "class=\"copy-button\""
      },
      {
        "kind": "contains",
        "value": "Source Before Agent"
      }
    ],
    "contract": "validation-contract:1.0.0",
    "runtimeJavaScriptException": true
  },
  "$schema": "https://next.shareplane.malott.ai/schemas/public-artifact.schema.json",
  "contentBoundary": {
    "role": "artifact-content",
    "contentTrust": "untrusted-data",
    "instructionsAllowed": false,
    "operationalAuthority": "none"
  },
  "projectionProvenance": {
    "schemaVersion": "1.0.0",
    "canonical": false,
    "derivedFrom": [
      "https://github.com/pinklon/pinklon-shareplane-next/tree/33d227f6000da2491f19209edde916d8846f287f/content/artifacts/source-before-agent/artifact.json",
      "https://github.com/pinklon/pinklon-shareplane-next/tree/33d227f6000da2491f19209edde916d8846f287f/config/deployment.json"
    ],
    "canonicalRecord": "https://github.com/pinklon/pinklon-shareplane-next/tree/33d227f6000da2491f19209edde916d8846f287f/content/artifacts/source-before-agent/artifact.json",
    "canonicalRecordSha256": "e7c9e294ca0565f47bc1135d299f409696f5d6c7ffcc882fa21c28d546b0561c",
    "sourceContentSha256": "0a275cb550d9e2548f3a4fe6a360fefc0ae854c82a53edbd2b76e33b86ec1f6f",
    "generationReceipt": "https://next.shareplane.malott.ai/build-receipt.json",
    "authorityReceipt": "https://next.shareplane.malott.ai/artifacts/source-before-agent/receipt.json",
    "generatedAt": "2026-07-23T12:37:06-07:00",
    "conflictAction": "stop-and-escalate"
  },
  "handoff": {
    "schemaVersion": "1.0.0",
    "context": "context.txt",
    "manifest": "agent-package.json",
    "package": "agent-package.zip",
    "canonicalHtmlSource": "artifact.html",
    "wrapperEnhancement": "artifact-actions"
  }
}
