Decision trees
Set release boundaries for the readiness decision tree
Page 7 defines what the readiness decision tree on hours × practice tests must refuse before release—security here is not a pasted happy path.
1Learn the idea
Read
Threats for this artifact only
Operational risks for the readiness decision tree on hours × practice tests center on training on labels that embed sensitive attributes without documenting them, plus the earlier failure mode (overfit tree with max_depth unrestricted on tiny data, or missing feature names in export). Safety lives in executable gates, allowlists, redaction, and a named owner—not in a warning paragraph under an unsafe function.
Read
Run the release gate
feature_notes={'hours':'study time','practice_tests':'count'}
assert 'ethnicity' not in feature_notes and 'name' not in feature_notes
print({'documented_features':list(feature_notes),'sensitive_undocumented':False})
Expected evidence: sensitive_undocumented False. A failed assertion means stop, investigate, and do not publish the readiness decision tree.
Read
Owner, retention, rollback
Name who can disable the feature, what data is retained, and how to roll back to the last known good artifact. Pin the reviewed configuration (versions, thresholds, allowlists) so “what shipped” is reconstructable for decision-trees.
Read
Lab notebook: release blocker
Write the release blocker as a predicate, not a feeling: “Do not ship the readiness decision tree if training on labels that embed sensitive attributes without documenting them.” Pair it with a passing control that shows the reviewed configuration still works for small hours/practice_tests readiness table with one holdout row. Name an owner and a rollback handle (git tag, docs_version, previous image).
Security pages must not paste the happy-path demo. If your gate code looks like the implementation page, replace it with a deny/allow check aimed at training on labels that embed sensitive attributes without documenting them.
Read
Worked judgment
State the data retention rule in one line (what is stored, for how long, who can read it). Then state the kill switch (env flag, config pin, or feature owner). The readiness decision tree is not shippable without both, even when held-out accuracy plus a tree text dump that mentions both features looks healthy.
Read
Why this stage matters for the readiness decision tree
At the safety and operations stage for decision-trees, the job is narrower than finishing a product demo. You are creating one progressive evidence piece about small hours/practice_tests readiness table with one holdout row that later pages inherit without redefining success. Keep that fixture small enough to inspect by hand, keep outputs copy-pasteable as text, and refuse to narrate this baseline as if it were a production SLA: majority-class accuracy on the holdout before fitting the tree.
For this page specifically, success looks like an executable deny gate for the lab-specific threat while still centering the user decision to predict readiness with a path a human can read aloud. If you cannot point to a file, command, or assertion that proves that for the readiness decision tree, stay on this page instead of advancing.
Go deeper
Before you start
Why this matters
Write an attack or unsafe misuse specific to this lab: training on labels that embed sensitive attributes without documenting them. Predict whether your current code blocks it. Then run the gate below and compare.
Related lessons
Check your understanding
Page assessment
Answer from memory. Completion is saved from this evidence, not from opening the next page.
All responses are required.