The Curriculum / Reader / Red-Team Program
LEVEL 3 · ADVANCED · COMPANY TRACK

Red-Team Program

This page compiles 4 files from the repository, verbatim, in reading order. The living version: this folder on GitHub.

level-3-advanced/company/04-red-team-program/README.md

Red-Team Program

A red team turns assumptions into evidence. Its mandate is to find how a real attacker, careless user, or confusing document can cause unsafe behavior before customers do.

At company scale, AI is not a side project owned by the person who writes prompts. It is a production capability spanning product, domain operations, platform engineering, security, privacy, finance, and support. Belle Realty should make the operating decision visible: what is authorized, who is accountable, what evidence is required, and how the system is stopped when reality disagrees.

Operating model

Name one directly responsible individual for the outcome and one executive sponsor for the risk. Define the decision rights for data access, model changes, vendor changes, policy exceptions, and emergency shutdowns. Maintain a registry of deployed features with purpose, customer cohorts, model and retrieval versions, data sources, tool permissions, SLOs, evaluation evidence, and review date.

Control cadence

Review leading indicators weekly: reliability, safety interventions, access denials, cost, drift, user corrections, and unresolved incidents. Review material changes before launch and at a fixed expiry date after launch. The agenda should end in decisions, owners, and dates—not a dashboard tour.

Evidence standard

Require representative offline evaluation, staged release evidence, traceable telemetry, and a documented rollback path. Segment results by geography, property type, tenant context, language, and risk level. A global pass rate is insufficient for a system that operates differently for one high-risk cohort.

Practical scenario

Before allowing an assistant to send maintenance messages across a portfolio, prove authorization boundaries, approved language, escalation behavior, provider fallback, outage handling, audit retention, and per-property cost limits. Have operations rehearse the manual path and the stop path.

Decision test

The program is mature only when a new engineer can determine what is running, why it is permitted, how it is measured, and who can change or stop it without relying on tribal knowledge.

level-3-advanced/company/04-red-team-program/adversarial-eval-suite.md

Adversarial Evaluation Suite

Maintain versioned attacks for injection, data isolation, tool abuse, policy evasion, identity spoofing, retrieval poisoning, and harmful advice. Tie every discovered weakness to a regression test and an owner.

At company scale, AI is not a side project owned by the person who writes prompts. It is a production capability spanning product, domain operations, platform engineering, security, privacy, finance, and support. Belle Realty should make the operating decision visible: what is authorized, who is accountable, what evidence is required, and how the system is stopped when reality disagrees.

Operating model

Name one directly responsible individual for the outcome and one executive sponsor for the risk. Define the decision rights for data access, model changes, vendor changes, policy exceptions, and emergency shutdowns. Maintain a registry of deployed features with purpose, customer cohorts, model and retrieval versions, data sources, tool permissions, SLOs, evaluation evidence, and review date.

Control cadence

Review leading indicators weekly: reliability, safety interventions, access denials, cost, drift, user corrections, and unresolved incidents. Review material changes before launch and at a fixed expiry date after launch. The agenda should end in decisions, owners, and dates—not a dashboard tour.

Evidence standard

Require representative offline evaluation, staged release evidence, traceable telemetry, and a documented rollback path. Segment results by geography, property type, tenant context, language, and risk level. A global pass rate is insufficient for a system that operates differently for one high-risk cohort.

Practical scenario

Before allowing an assistant to send maintenance messages across a portfolio, prove authorization boundaries, approved language, escalation behavior, provider fallback, outage handling, audit retention, and per-property cost limits. Have operations rehearse the manual path and the stop path.

Decision test

The program is mature only when a new engineer can determine what is running, why it is permitted, how it is measured, and who can change or stop it without relying on tribal knowledge.

level-3-advanced/company/04-red-team-program/coordinated-disclosure.md

Coordinated Disclosure

Provide a safe channel for external researchers, acknowledge reports, triage severity, protect researchers acting in scope, communicate remediation status, and publish lessons when disclosure will improve ecosystem safety.

At company scale, AI is not a side project owned by the person who writes prompts. It is a production capability spanning product, domain operations, platform engineering, security, privacy, finance, and support. Belle Realty should make the operating decision visible: what is authorized, who is accountable, what evidence is required, and how the system is stopped when reality disagrees.

Operating model

Name one directly responsible individual for the outcome and one executive sponsor for the risk. Define the decision rights for data access, model changes, vendor changes, policy exceptions, and emergency shutdowns. Maintain a registry of deployed features with purpose, customer cohorts, model and retrieval versions, data sources, tool permissions, SLOs, evaluation evidence, and review date.

Control cadence

Review leading indicators weekly: reliability, safety interventions, access denials, cost, drift, user corrections, and unresolved incidents. Review material changes before launch and at a fixed expiry date after launch. The agenda should end in decisions, owners, and dates—not a dashboard tour.

Evidence standard

Require representative offline evaluation, staged release evidence, traceable telemetry, and a documented rollback path. Segment results by geography, property type, tenant context, language, and risk level. A global pass rate is insufficient for a system that operates differently for one high-risk cohort.

Practical scenario

Before allowing an assistant to send maintenance messages across a portfolio, prove authorization boundaries, approved language, escalation behavior, provider fallback, outage handling, audit retention, and per-property cost limits. Have operations rehearse the manual path and the stop path.

Decision test

The program is mature only when a new engineer can determine what is running, why it is permitted, how it is measured, and who can change or stop it without relying on tribal knowledge.

level-3-advanced/company/04-red-team-program/red-team-charter.md

Red-Team Charter

The charter specifies mission, scope, authorization, test data, systems in bounds, prohibited actions, evidence handling, disclosure, and remediation verification. Independence matters; do not let feature owners grade their own controls.

At company scale, AI is not a side project owned by the person who writes prompts. It is a production capability spanning product, domain operations, platform engineering, security, privacy, finance, and support. Belle Realty should make the operating decision visible: what is authorized, who is accountable, what evidence is required, and how the system is stopped when reality disagrees.

Operating model

Name one directly responsible individual for the outcome and one executive sponsor for the risk. Define the decision rights for data access, model changes, vendor changes, policy exceptions, and emergency shutdowns. Maintain a registry of deployed features with purpose, customer cohorts, model and retrieval versions, data sources, tool permissions, SLOs, evaluation evidence, and review date.

Control cadence

Review leading indicators weekly: reliability, safety interventions, access denials, cost, drift, user corrections, and unresolved incidents. Review material changes before launch and at a fixed expiry date after launch. The agenda should end in decisions, owners, and dates—not a dashboard tour.

Evidence standard

Require representative offline evaluation, staged release evidence, traceable telemetry, and a documented rollback path. Segment results by geography, property type, tenant context, language, and risk level. A global pass rate is insufficient for a system that operates differently for one high-risk cohort.

Practical scenario

Before allowing an assistant to send maintenance messages across a portfolio, prove authorization boundaries, approved language, escalation behavior, provider fallback, outage handling, audit retention, and per-property cost limits. Have operations rehearse the manual path and the stop path.

Decision test

The program is mature only when a new engineer can determine what is running, why it is permitted, how it is measured, and who can change or stop it without relying on tribal knowledge.

← Company Safety Program Multi-Region AI Deployment →