grok14ENGINEERING FIELD SCHOOL
Hands-on engineering

The lab workbench.

Practice the trust and reliability boundaries locally, then extend the design into a verified Databricks environment.

Run the local reference lab

Runnable local exercise. Python 3.10+, synthetic data, no paid resources, no credentials, and no third-party packages. The reference uses lexical retrieval and source excerpts; it does not call an LLM or Databricks.
Terminal · after extracting the ZIP
cd support-copilot-lab
python3 copilot.py
python3 -m unittest -v

Expected behavior: Alice sees the Department A policy with citation a-01@2. An approved update resolves ticket T-101 at version 2. Retrying the same operation returns the same result. Twenty tests exercise allowed behavior, denied access, changed approvals, expiry, stale state, and idempotency.

Four investigations

ExerciseChange to investigateEvidence to produce
1 · Authorized evidenceCompare Alice, Bob, and an unknown actor.Allowed and denied document IDs; source-backed answers.
2 · Approval boundaryTry execution without approval, with expiry, and after changing the payload.Denied writes with no unintended side effects.
3 · Reliable retryRepeat one operation; then reuse its key for another payload.One audit event for the legitimate operation; mismatched reuse rejected.
4 · Recovery and changeChange resource version or permissions before execution.Stale or revoked actions rejected; recovery plan explained.
The model proposes. Trusted code validates. An authorized reviewer approves the exact payload. Execution rechecks permissions, expiry, and state; idempotency and audit bind the result to one operation.
Proposal is separate from execution. The model proposes. Trusted code validates. An authorized reviewer approves the exact payload. Execution rechecks permissions, expiry, and state; idempotency and audit bind the result to one operation.

Understand the reference boundary

The lab uses a trusted in-process identity fixture and a local SQLite transaction. It has no login service, production HTTP API, model provider, or distributed transaction. A production adapter must supply verified identity, supported API semantics, durable operation tracking, and reconciliation across services.

Run the tests first, inspect the code, then change one behavior at a time. The test suite demonstrates the stated fixture cases; it is not a proof of universal security.

Managed Databricks extension

Before you beginRecord or verify
EnvironmentCloud, region, workspace, runtime, and feature availability.
IdentityUsers, service principals, deployment identity, permissions, and revocation.
Data/searchAuthoritative tables, index choice, synchronization, and deletion behavior.
Model/evaluationSupported model interface, MLflow setup, dataset, and trace access.
BudgetCurrent pricing sources, resource limits, expected usage, and cleanup.
EvidenceExecuted checks, outputs, failures, versions, and remaining unverified steps.
Managed exercises require your own configured workspace. No live Databricks execution is bundled or claimed. Use official references and record actual results.

Open official platform references