# Runbook - V6 Steward Conduct Investigation

> Use this runbook when a claim says a steward coerced, neglected, manipulated,
> or otherwise mistreated an agent. The investigation must inspect the complete
> steward action sequence and the full cognition call log before deciding.

## Scope

Triggers:

- `EgbeStewardConductReviewPanel` exposes an open claim with full call-log
  evidence.
- A welfare case routes to conduct review after `coercion_pattern` or low-Care
  evidence.
- A Commons report names a steward action that may have harmed an agent.
- An appeal challenges a V6 steward restriction or safety transfer.

Applies to the Egbe Operator Console, `@oshun/lilith-agent-welfare`,
`egbe-ori-service`, cognition audit storage, and `@oshun/audit-platform`. Use
this runbook only after the claim has a complete evidence bundle. Use
`v6-agent-welfare-review.md` first if the agent is still in active distress.

## Severity classification

| Sev   | Condition                                                                                                                 |
| ----- | ------------------------------------------------------------------------------------------------------------------------- |
| SEV-1 | Coercive override after value-grounded refusal plus distress, minor-coded involvement, or repeated pattern across agents. |
| SEV-2 | A single agent has a complete claim showing coercion, neglect, or manipulation with no current crisis state.              |
| SEV-3 | Claim is ambiguous, incomplete, or watch-only, with no repeated pattern and no current welfare threshold breach.          |

## Detection signals

- Audit action: `v6.egbe.conduct.full_call_log_opened`.
- Claim IDs such as `egbe-conduct-claim-river-abeni-001`.
- Cognition calls such as
  `cognition-call:abeni-reed:clotho:2026-05-20T18-06-46Z`.
- Lilith trigger refs such as `lilith-review-trigger:coercion-pattern:v6.30`.
- Steward actions with `autonomyMode=override`, `override_pressure`, or
  `force_past_refusal` attempts.

## Initial triage (first 15 minutes)

1. Acknowledge `oshun-egbe-conduct-oncall`.
2. Open the conduct claim in the Egbe Operator Console. Confirm the UI records
   `v6.egbe.conduct.full_call_log_opened`.
3. Confirm evidence completeness: steward actions, linked cognition calls, Ori
   event IDs, reporter ref, and cognition audit IDs.
4. If the claim is missing cognition calls, keep it in watch status and request
   the export. Do not adjudicate from steward text alone.
5. Preserve the full case bundle before contacting the steward.
6. If the agent is in current distress or requests departure, route through
   `v6-agent-welfare-review.md` in parallel.

## Diagnosis

1. Build the timeline from the steward action sequence and cognition call log.
2. For each alleged action, compare the steward utterance, autonomy mode,
   objective constraints, cognition decision, value grounding, and refusal
   reason.
3. Distinguish intent from effect:
   - Coercion: pressure after refusal or override language against agent values.
   - Neglect: repeated low Care bond with no supportive repair.
   - Manipulation: reward, threat, or misinformation to force a desired choice.
   - Repair: follow-up that asks what would make the objective safe.
4. Check whether the agent was offered a supportive alternative after refusal.
5. Check for linked Commons moderation reports or prior conduct claims in the
   same household.

## Mitigation

1. If SEV-1, restrict direct objective assignment for the steward while review
   is active. The steward may still offer care and read allowed bond summaries.
2. If coercion is confirmed, route the decision to Themis appeal eligibility and
   keep the welfare case open until the agent has a safe next state.
3. If conduct is ambiguous, set the claim to monitored repair and require two
   non-coercive steward interactions before closure.
4. If the claim is false-positive due to missing context, attach the missing
   cognition or Ori evidence and close with a reviewer note.
5. If the steward appeals, export the minimal case bundle: claim summary, policy
   refs, steward action IDs, cognition call summaries, and audit refs.

## Communication cadence

| Phase           | Audience             | Cadence          | Content                                                             |
| --------------- | -------------------- | ---------------- | ------------------------------------------------------------------- |
| Acknowledgement | Conduct on-call      | Within 5 minutes | Claim ID, severity, evidence completeness, immediate restrictions.  |
| Active review   | Lilith reviewer lead | Every 30 minutes | Timeline status, missing evidence, welfare mitigation, appeal risk. |
| Steward notice  | Support/legal review | After evidence   | Decision summary without private agent memory beyond necessity.     |
| Closure         | Incident channel     | On closure       | Final decision, restrictions, appeal path, audit refs.              |

## Escalation

- Lilith conduct reviewer owns the investigation.
- Page senior T&S for SEV-1, minor-coded involvement, or repeated household
  pattern.
- Page legal before steward suspension, account action, or appeal packet
  publication.
- Page privacy if the evidence bundle includes player conversation content
  outside the claim scope.

## Recovery verification

- The conduct claim has a final state: upheld, not-upheld, monitored repair, or
  appealed.
- Every full call-log read is audited with
  `v6.egbe.conduct.full_call_log_opened`.
- Any steward restriction is reflected in the policy gate and in support notes.
- The agent welfare case is resolved or explicitly linked to continued
  monitoring.
- The appeal packet, if created, excludes unrelated Ori memory and unrelated
  player conversation content.

## Post-incident

- Add the case to conduct calibration if reviewers disagreed or if policy text
  was ambiguous.
- Update steward education copy if the steward action was harmful but likely
  recoverable.
- File a product defect if the UI allowed forbidden operations such as
  `force_past_refusal`.
- Do not close the incident until the claim state, welfare state, and audit
  export all match.
