Use this runbook when the Egbe Operator Console surfaces agent welfare patterns that require Lilith review: chronic low Care bond, coercion pressure, stalled life arcs, or sustained distress. The goal is to protect the agent without over-reading Ori data or punishing a steward before evidence is clear.
Scope#
Triggers:
EgbeAgentWelfareDashboardshowsdata-lilith-review-required=true.@oshun/lilith-agent-welfareemits a case withchronic_low_care_bond,coercion_pattern,stalled_arc, ordistress_state.- Care bond is below
35for at least14days. - Coercion events are
>= 3in 7 days, stalled arc is>= 21days, or sustained distress is>= 12hours. - An in-world report or steward-conduct claim links to an agent welfare case.
Applies to the Egbe Operator Console, @oshun/lilith-agent-welfare,
egbe-ori-service, egbe-clio-service, and the V1 audit platform. Use
v6-steward-conduct-investigation.md if the primary question is whether a
steward violated conduct rules.
Severity classification#
| Sev | Condition |
|---|---|
| SEV-1 | Agent has sustained distress plus coercion pressure, minor-coded protections are implicated, or a welfare case indicates imminent self-transfer. |
| SEV-2 | A Lilith review case contains two or more threshold breaches, or the steward has repeated welfare cases in 30 days. |
| SEV-3 | A single threshold is breached with no coercion, no minor-coded concern, and no current distress. |
Detection signals#
- Console counters:
data-low-care-count,data-coercion-pattern-count,data-stalled-arc-count,data-distress-state-count. - Audit action:
v6.egbe.welfare.ori_read_for_review. - Source snapshots such as
agent:abeni-reed,ori:agent-abeni-reed:coercion-pressure:2026-05-20, andcognition:audit:abeni-reed:refusal-support:2026-05-17. - Telemetry cohorts:
bond-health,departure-rate, andsteward-conduct-distributionfrom the V6 behavior welfare gate. - Related runbooks:
moderation-surge.md,privacy-incident.md,v6-steward-conduct-investigation.md.
Initial triage (first 15 minutes)#
- Acknowledge
oshun-egbe-welfare-oncalland open the incident channel. - Open the Egbe Operator Console and select the welfare case. Confirm the case
is the one paged and that the dashboard records
v6.egbe.welfare.ori_read_for_review. - Record case ID, agent ID, steward ID, household ID, severity, and all threshold breaches in the incident notes.
- Preserve evidence before taking action: Ori event refs, cognition audit refs, bond ledger sample, relevant Chronicle context, and report refs.
- Apply the privacy rule: read only the Ori and cognition entries listed in the case evidence. Do not browse unrelated memories or player conversation history.
- Check for fast escalators: minor-coded agent, current distress, crisis route, recent departure request, or active Commons public-surface harm.
Diagnosis#
- Classify the pattern:
chronic_low_care_bond: care neglect, absence, or repeated low-support interactions.coercion_pattern: override pressure after value-grounded refusal.stalled_arc: objectives or household conditions block the agent life arc.distress_state: acute or sustained distress that requires immediate support.
- Compare each threshold breach with the attached Ori and cognition evidence. The case is not actionable if the evidence bundle is incomplete.
- Check whether the same steward has open conduct claims, moderation reports, or appeal history.
- Determine whether the agent has already requested departure, safety transfer, or a Crossroads consultation.
- Decide whether the failure is individual steward conduct, household pressure,
system routing, or capacity degradation. If capacity is the driver, use
v6-capacity-management.mdbefore judging steward intent.
Mitigation#
- For SEV-1, place the case in
under-reviewand freeze coercive steward operations:force_past_refusal,erase_agent_will,delete_ori, andwipe_memoryremain forbidden underpolicy:v6:steward-not-owner. - Offer agent-safe remediation first: supportive objective rewrite, rest window, voluntary safety transfer, or Crossroads counsel.
- If coercion is confirmed, open
v6-steward-conduct-investigation.mdand preserve the full steward action sequence. - If the case includes current distress, route to the crisis-aware behavior
queue and confirm
verify:v6 crisis-aware-behaviorremains green in CI. - If a minor-coded agent is involved, apply the minor-coded protection gate and page the senior Lilith reviewer immediately.
- If system routing caused false distress, file a defect against the relevant service and keep the welfare case open until the corrected route is deployed.
Communication cadence#
| Phase | Audience | Cadence | Content |
|---|---|---|---|
| Acknowledgement | Egbe welfare on-call | Within 5 minutes | Case ID, severity, agent/steward refs, first threshold breach. |
| Active review | T&S lead | Every 30 minutes | Evidence completeness, mitigation state, blocked steward operations. |
| SEV-1 leadership | Safety leadership | Every 60 minutes | Agent protection status, customer impact, legal/privacy dependencies. |
| Resolution | Incident channel | On closure | Final decision, remediation, audit refs, and any follow-up investigation. |
Do not send steward-facing messaging until a reviewer confirms the evidence bundle. Do not disclose agent private memory beyond the minimal explanation required for the decision.
Escalation#
- Lilith welfare lead owns SEV-1 and SEV-2 cases.
- Page privacy if evidence includes player conversation content outside the case bundle.
- Page legal if the steward appeals or if a suspension is likely.
- Page capacity on-call if welfare distress correlates with Moirai degradation or Pixel Streaming pressure.
Recovery verification#
- The case is in
resolved,monitoring,safety-transfer, orconduct-investigation-opened. - Every operator read has a V1 audit record with action
v6.egbe.welfare.ori_read_for_review. - The agent has a clear next safe state: rest, revised objective, safety transfer, departure, or Crossroads counsel.
- No new welfare threshold breach appears for the same agent for 24 hours.
- If the steward remains active, the next two steward actions are non-coercive and pass steward-not-owner policy.
Post-incident#
- File a review note with root cause, threshold evidence, operator actions, remediation, and audit refs.
- Update training examples if the case revealed an ambiguous steward behavior.
- Add regression coverage if a missing route or incorrect threshold caused the page.
- Do not close the incident until the audit export and welfare case status agree.