# AI Employees: isolated draft-review runtime

Recorded 24 September 2026. This is review infrastructure evidence, not a deployment guide or proof of autonomous employee execution.

**Historical checkpoint:** this document describes the initial draft-only configuration. Later, narrowly scoped exceptions for one dedicated employee enabled the [manual lifecycle](ai-employees-manual-lifecycle.md) and [genuine isolated model/provider/file rehearsals](ai-employees-actual-model.md). Those later reports supersede the blanket execution refusals below for that fixture only. Main API3312 was subsequently restarted for the separate [storage metadata disclosure fix](storage-driver-disclosure.md); it was untouched at this initial checkpoint.

## Result

Current AI Employee source is available to the browser reviewer through local API port **3313**. The existing API on **3312**, its installed application fixes, existing AI workers and shared AI configuration were left untouched. Nine compiled AI Employee modules were refreshed in a temporary runtime clone at `/tmp/ai-employee-draft-review/runtime`.

The original installed API had older Instructions handling and no Team route. The isolated runtime now returns the current response shapes:

| Request | Observed result before draft hiring |
|---|---|
| Authenticated `GET /ai-employees` | 200; zero employees |
| `GET /ai-employees/templates` | 200; six templates |
| `GET /ai-employees/config` | 200; config/from/isPlatform |
| `GET /ai-employees/instructions` | 200; data/platform/isPlatform; no organization instructions |
| `GET /ai-employees/team` | 200; workspace field |
| `GET /ai-employees/work` | 200; zero work items |
| Anonymous employee list | 401 |

Readback: [isolated-runtime-readback.json](assets/ai-employees/isolated-runtime-readback.json).

## Isolation and checks

These controls exist only in the temporary review preload; canonical application source was not changed to impose them.

- Nest scheduled jobs and synchronization are disabled in this review process.
- Every registered Bull queue receives prefix `learner-review-ai-draft-20260924` and no configured processors.
- Bull consumer discovery is disabled entirely. No consumer is registered to take jobs from an existing queue.
- AI bootstrap reconciliation, shared organization registration, periodic heartbeats and AI event handlers are disabled.
- Activation/status changes, leases, work enqueueing and stub execution explicitly refuse execution.
- Provision, deprovision and sign-in handover explicitly refuse execution, preventing worker creation and credential rotation through those paths.
- The real draft-creation method remains available only for the controlled review organization.

All **four guard regression tests passed**: scoped real draft creation, disabled bootstrap/events/pings, refused execution, and refused runtime handover. Additional checks exercised the actual compiled service class and Bull queue-options factory; the latter confirmed the private prefix, empty processors and disabled consumer discovery.

Artifacts: [guards](assets/ai-employees/review-isolation/guards.cjs), [preload](assets/ai-employees/review-isolation/preload.cjs), [tests](assets/ai-employees/review-isolation/guards.test.cjs), [passing output](assets/ai-employees/review-isolation/guard-tests.txt).

A switch-on attempt against a nonexistent review handle returned 500 from the intentional review refusal. This is not a canonical application defect or evidence that a worker started.

## Actions available to the browser reviewer

Inspect templates, configuration, instructions and the empty team/work views; create a uniquely named draft in the review organization; inspect its real persisted profile, locked AI identity, access settings, private team membership and empty work list. Restrict writes to that new review record. Do not send team messages, activate an employee or change existing configuration.

Draft hiring can create real private workspace/team records and enqueue workspace notifications. Notification delivery is **not** exercised because this review process has no queue consumers. The draft review therefore cannot substantiate successful notifications, periodic pings, autonomous work, model execution, provider provisioning or completed employee tasks. Those require a separate explicitly isolated execution rehearsal.

The live UI reviewer records the actual draft actions and screenshots in [AI Employees local review](ai-employees-local-review.md). Endpoint readiness above was captured before those actions and must not be presented as proof that hiring itself was completed.
