This is the public record behind the artifact: what changed, what another person can reuse, what supports the system, and what the build is not entitled to claim.
MAKING
What changed
Reviewed the public overview, A route, B screening room, film/transcript and distribution language as one claim surface.
Separated cited context from RN analysis, design propositions, fictional fixture content and observable prototype behavior.
Published this record only for the qualified reviewed disposition.
METHOD
What travels
Keep synthetic records unmistakably synthetic.
Attach each named source to its exact locator and scope limit.
Do not convert contextual guidance into validation, compliance, safety or outcome evidence.
EVIDENCE
What supports it
Source classification: NIST Artificial Intelligence Risk Management Framework 1.0 (NIST AI 100-1, 26 January 2023).
Exact locator: §§3.4 and 5; Core GOVERN, MAP, MEASURE and MANAGE tables.
The source supports only the bounded context stated here; the prototype and its interface rules remain RN synthesis and implementation.
LIMITS
What it cannot claim
Explore how a system could be misused, manipulated, broken or exploited—and what blocks those paths.
Voluntary cross-sector risk-management context only. It does not prescribe this interface or prove thresholds, consequences, readiness, compliance, safety, effectiveness or outcomes.
Claim-reviewed does not validate effectiveness, safety, compliance, representativeness, cultural authority, professional suitability or outcomes.
External source locators
NIST — AI Risk Management Framework 1.0 → Exact locator: §§3.4 and 5; Core GOVERN, MAP, MEASURE and MANAGE tables. Scope limit: Voluntary cross-sector risk-management context only. It does not prescribe this interface or prove thresholds, consequences, readiness, compliance, safety, effectiveness or outcomes.
VISUAL ASSET REVIEW
Hook image, source candidate, and release gates
The creator-owned cover remains live unless every external-candidate gate is explicitly complete. Disabled controls report canonical status; they do not imply an approval action occurred here.
Use the complete 720×900 frame. Do not crop the headline, build number, safe margins or prototype boundary.
This creator-owned opening frame supports only the visible build proposition and build identity. It is not documentary evidence and does not establish institutional endorsement, lived experience, product performance, safety, compliance, effectiveness, causation, community authority or outcome.
Official visual candidate
Disposition: HOLD
HOLD — NIST AI RMF 1.0 is reusable and broadly relevant to AI security, but it does not specifically support an Attack Graph as the recognizable visual. Generic framework context is insufficient for selection.
Orientation/dimensions: portrait, US Letter; 612 × 792. PDF page box in points; verify page 1 before production crop.
Crop: Use only the publication title and directly relevant text/diagram area. Exclude seals, logos, personal imagery and third-party material. Preserve source/status credit; label any crop and do not imply endorsement.
Alt text: Official NIST AI Risk Management Framework 1.0 document or guidance page, selected as contextual evidence for Build 033, Attack Graph.
Credit: Tabassi, E. (2023), Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1. Republished courtesy of NIST.
Claim boundary: Supports recognition of NIST AI Risk Management Framework 1.0 and the limited source context adjacent to Build 033; it does not prove RN's prototype performance, compliance, safety, effectiveness or institutional endorsement.
EXTERNAL SOURCE REVIEW · HOLD · NOT SELECTED · NOT STAGED
Exact-source acquisition decision
Classification: CONTEXTUAL MISMATCH
HOLD — NIST AI RMF 1.0 is reusable and broadly relevant to AI security, but it does not specifically support an Attack Graph as the recognizable visual. Generic framework context is insufficient for selection.
Crop: Use only the publication title and directly relevant text/diagram area. Exclude seals, logos, personal imagery and third-party material. Preserve source/status credit; label any crop and do not imply endorsement.
Attribution: Tabassi, E. (2023), Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1. Republished courtesy of NIST.
Alt text: Official NIST AI Risk Management Framework 1.0 document or guidance page, selected as contextual evidence for Build 033, Attack Graph.
Caption: Official-source context reviewed for Build 033; external visual remains on HOLD.
Claim boundary: Supports recognition of NIST AI Risk Management Framework 1.0 and the limited source context adjacent to Build 033; it does not prove RN's prototype performance, compliance, safety, effectiveness or institutional endorsement.
Fallback decision: Retain the original RN cover. No external promotion is authorized.
Original HOLD fallback graphic
ORIGINAL RN FALLBACK • HOLD • NOT EVIDENCE
Original RN-created fallback diagram for Build 033, “Design the Attack Before It Happens.” It illustrates the build concept and is not evidence of external validation, performance, compliance or endorsement.
This generated RN-owned fallback is available for review while the third-party candidate remains on HOLD. It is not selected external evidence and does not change staging status.
1. Hook TEST THE SYSTEM WITHOUT TEACHING THE ATTACK — Defensive exploration should expose weak assumptions, controls, and recovery paths while withholding reusable harmful instructions.Visual, rights, and accessibility instructions
Use the complete RN-owned cover at /media/builds/033/build-033-linkedin-poster.png. Do not crop text, credits, safe margins, or claim boundary.
Claim boundary: This creator-owned opening frame supports only the visible build proposition and build identity. It is not documentary evidence and does not establish institutional endorsement, lived experience, product performance, safety, compliance, effectiveness, causation, community authority or outcome.
Accessibility: Slide 1 alt text must identify Build 033, the hook function, essential visible text, and the information conveyed by the visual. Keep reading order headline → visual → boundary/credit.
Rights: Creator-owned production asset; no third-party visual incorporated.
2. Problem The problem: Attack Graph fails when the underlying decision, audience, or evidence boundary is left implicit.Visual, rights, and accessibility instructions
RN-owned problem framing: isolate the tension behind “TEST THE SYSTEM WITHOUT TEACHING THE ATTACK — Defensive exploration should expose weak assumptions, controls, and recovery paths while withholding reusable harmful instructions.”. Use typography plus one simple contrast or decision fork; no stock people.
Accessibility: Slide 2 alt text must identify Build 033, the problem function, essential visible text, and the information conveyed by the visual. Keep reading order headline → visual → boundary/credit.
Rights: Use RN-owned typography, diagrams, and verified prototype captures only.
3. System The system: make the mechanism inspectable—show what enters, what changes, who retains authority, and what leaves the system.Visual, rights, and accessibility instructions
Show an RN-owned diagram or prototype view of the Attack Graph mechanism. Label inputs, decision/action, and output; do not depict outcomes not present in the build.
Accessibility: Slide 3 alt text must identify Build 033, the system function, essential visible text, and the information conveyed by the visual. Keep reading order headline → visual → boundary/credit.
Rights: Use RN-owned typography, diagrams, and verified prototype captures only.
4. Evidence Evidence boundary: NIST AI Risk Management Framework 1.0 frames the domain; the proposition and prototype remain RN synthesis.Visual, rights, and accessibility instructions
Use an RN-owned evidence-boundary card. The recognizable entity “NIST AI Risk Management Framework 1.0” may be named as context only; do not use its marks, screenshots, portraits, or trade dress.
Claim boundary: Supports recognition of NIST AI Risk Management Framework 1.0 and the limited source context adjacent to Build 033; it does not prove RN's prototype performance, compliance, safety, effectiveness or institutional endorsement.
Accessibility: Slide 4 alt text must identify Build 033, the evidence function, essential visible text, and the information conveyed by the visual. Keep reading order headline → visual → boundary/credit.
5. Demo Demo: walk through one bounded state change in the Build 033 prototype. Show the interaction or decision path, not an invented result.Visual, rights, and accessibility instructions
Use an authentic RN prototype/interface capture from Build 033, or a faithful RN-owned diagram if no stable interface view exists. Clearly label simulated, fictional, or illustrative states.
Claim boundary: Show only an observed prototype state; label simulation and fiction; do not imply deployment or outcome.
Accessibility: Slide 5 alt text must identify Build 033, the demo function, essential visible text, and the information conveyed by the visual. Keep reading order headline → visual → boundary/credit.
Rights: Use RN-owned typography, diagrams, and verified prototype captures only.
6. Implications Implication: Attack Graph can make the relevant structure visible and discussable. It does not by itself prove performance, compliance, safety, effectiveness, causation, or endorsement.Visual, rights, and accessibility instructions
Use a two-column RN synthesis: what this build makes possible / what it does not establish. No universal, causal, safety, compliance, or effectiveness claim.
Accessibility: Slide 6 alt text must identify Build 033, the implications function, essential visible text, and the information conveyed by the visual. Keep reading order headline → visual → boundary/credit.
Rights: Use RN-owned typography, diagrams, and verified prototype captures only.
7. CTA + sources Explore Build 033, Attack Graph: watch the cut, inspect the motion argument, test the interactive prototype, and review its evidence boundary.Visual, rights, and accessibility instructions
Use a quiet RN-owned closing card with Build 033, the canonical dossier URL, CTA, source/credit line, and “RN synthesis · no endorsement” where an institution is named.
Accessibility: Slide 7 alt text must identify Build 033, the cta + sources function, essential visible text, and the information conveyed by the visual. Keep reading order headline → visual → boundary/credit.
Rights: Use RN-owned typography, diagrams, and verified prototype captures only.
Platform repurposing
Instagram: Publish all seven 4:5 slides; keep credits and boundaries on-slide; write the supplied alt text manually.
LinkedIn: Export as an accessible seven-page PDF; preserve live links in the post copy and use the build dossier as the canonical source.
Reels/TikTok: Animate slides 1–6 as silent-first vertical beats; retain captions, visible source credit, and final CTA; do not imply motion footage is documentary.
Web/newsletter: Use slide 1 as the preview and embed/link the dossier; do not detach the source-context image from its caption, credit, and limitation.
All seven accessible 1200×1500 slides for this build are generated and included in the deterministic distribution packages. Metadata retains exact alt text, visual guidance, credit, source, rights, and claim boundaries.
This build’s current cover and complete metadata are included in the deterministic 100-cover handoff. The package preserves this dossier’s official/RN decision, source, rights, claim boundary, and rollback state.
A public build record has four sections and they are ordered on purpose. Making is the narrative of what changed, written so that someone who was not there can follow the decisions in sequence. Method is the part meant to travel: the rules and structures another person could apply to a different problem in a different field. Evidence is what supports the system, stated as specifically as the underlying material allows. Limits close the record because they determine how far everything above them can be carried.
The reason limits come last is that they are the part most often left out, and a record without them is a marketing page with citations. Every claim in the sections above is bounded by what the final section says, and a reader who skips it will overstate what the build establishes. If you only have time for two sections, read Method and Limits: together they tell you what you could reuse and how far you could trust it.
Where external sources appear, each is given with an exact locator rather than a bare link, so the specific passage relied on can be checked instead of the whole document. A scope limit accompanies each one. That limit describes what the source was used for in this build, which is frequently narrower than what the source as a whole covers, and quoting the source for a broader claim than the scope allows would be a misuse of it even though the link resolves.
Language here is chosen to hold up under scrutiny rather than to sound confident. Where a review is complete, the record says so and names what the review covered. Where a review remains open, the record says that instead, and continues to say it until the work is done. A statement that something is a demonstration, a synthetic fixture or an unverified claim is a factual description of that artifact, and it stays on the page because removing it would make the surrounding claims read as stronger than the evidence supports.
Finally, this record documents one build among a hundred that are designed to inherit from each other. What Method describes is often the thing a later build depends on, so a record is worth reading alongside the lineage view rather than purely on its own. That is where the capability described here can be traced forward into whatever was built on top of it.