# SASI SDK Upgrade Roadmap - Executive Summary

**Date:** January 16, 2026  
**Current Version:** 1.3.0 (Stable Production)  
**Status:** v1.3.0 Complete ✅ | v1.3.1/v1.4 Planning (Based on Mental Health App Analysis)

---

## What's Done (Production: v1.3.0)

### v1.3.0 New Features (Jan 2026)
✅ **Safety Architecture Disclosure Guard** - Prevents reverse engineering and probing of SASI's internal design (IP protection, always-on)

### v1.2.0 New Features (Jan 2026)
✅ **Hard Safety Enforcement Layer** - Always-on deadman switch (forced redaction, cannot be disabled)  
✅ **Safety Envelope / Prompt Validation** - Validates system prompts, injects safety envelope if missing  
✅ **SASI Canary (Drift Monitor)** - Enterprise SLA feature for model drift detection

### v1.1.0 New Features (Jan 2026)
✅ **Certified Context Injection** - Semantic safety hints for LLMs (fixes R98/R99 hallucinations)  
✅ **Regulator-Readable Outputs** - Action rationale, decision paths, oversight flags  
✅ **Enhanced Audit Fields** - Model/provider tracking, latency breakdown, review tickets

### v1.0.3 Core Safety (Dec 2025)
✅ **Obfuscation Detection** - rapidfuzz (leetspeak, Unicode tricks, spacing) - catches 98%+ evasion  
✅ **Crisis Template Rewriting** - HIPAA PHI protection, deterministic clinical summaries  
✅ **message_for_llm Field** - Canonical LLM payload (template or redacted)  
✅ **Protective Factor Detection** - 40 phrases to reduce over-escalation  
✅ **Mode-Configurable Thresholds** - 78 clinical, 82 default, 88 business

### Core Production Features (v1.0+)
✅ **6-Step Crisis Detection** - Semantic anchors, hair-trigger protection, de-escalation logic  
✅ **HIPAA Safe Harbor PII Redaction** - 18 identifiers  
✅ **6-Dimension MDTSAS Scoring** - Trauma, Depression, Crisis, Anxiety, Alliance, Suicidality  
✅ **13 Symbolic Operators** - Emotional state modeling (THE MOAT)  
✅ **Adversarial Detection** - Jailbreak, prompt injection prevention  
✅ **Pipeline Routing** - Response strategy recommendations  
✅ **12 Operational Modes** - Mode-specific safety configurations  
✅ **FDA-Compliant Audit Logging** - Complete decision trails

---

## Priority Roadmap

**Tier Naming (Marketing Alignment):**
- **Tier 0:** "Foundational Safety" - Core safety features that cannot be removed
- **Tier 1:** "Non-Bypassable Safety" - Safety that cannot be disabled or bypassed
- **Tier 2:** "Predictive and Preventive Safety" - Early detection and prevention

**Core KPI: Determinism**
- **Identical input + config → identical output, 100% of the time**
- Critical for regulators, insurers, and enterprise compliance
- All SASI features maintain deterministic behavior

---

### Tier 1: Critical Safety Refinements (v1.3.1 / v1.4 - Q1-Q2 2026)

**1. Ambiguity Handling and Conflict Resolution** ⭐⭐⭐ *NEW*
- Safety-first arbitration for conflicting signals (neutral tone + risky themes)
- Configurable arbitration strategies (safety-first by default)
- Reduces over-escalation while catching masked distress
- Metadata-only (uncertainty flags for apps, no prompt injection)
- **Effort:** Low (1-2 weeks)

**2. Enhanced Auditability and Decision Traces** ⭐⭐ *NEW*
- Turn-by-turn decision traces, reconstruction artifacts
- Provable logs vs narrative explanations
- Test harness for regulators (proves enforcement cannot be bypassed)
- Regulator-ready exports (FDA/HIPAA/EEOC/FERPA schemas)
- Strengthens existing auditability strength
- **Effort:** Low-Medium (2-3 weeks)

**3. Disclosure Guard + Response Shape Integration** ⭐⭐ *NEW*
- Sophisticated probe detection (combines both systems)
- Rate-limiting and adversarial event logging
- Hardens IP protection
- **Effort:** Low (1 week)

### Tier 2: Enhanced Detection and Analytics (v1.4 - Q2-Q3 2026)

**3. Enhanced SASI Canary (Reliability Scoring)** ⭐⭐ *NEW*
- Per-model, per-mode reliability scores over time
- SLA thresholds tied to reliability scores
- Model instability fingerprints (pairs with Response Shape Validation)
- **Effort:** Medium (2-3 weeks) - **Note: Auto-fallback deferred to v2.0+**

**4. Enhanced Metric Tracking and Fusion** ⭐⭐ *NEW*
- Supporting metrics: sentiment, tone shifts, event magnitude, complexity, intent
- Metadata-only (adds fields to SasiResult, no prompt modification)
- ~10-20% detection sensitivity boost for subtle distress
- **Effort:** Medium (2-3 weeks) - **Latency constraint: Must stay under 25ms**

**5. Pattern Decay and State Type Classification** ⭐ *NEW*
- Distinguishes temporary states from stable patterns
- Improves multi-session accuracy
- Privacy-safe (symbolic only)
- **Effort:** Medium (2-3 weeks)

**6. Refusal Dampener**
- Per-model profiles to prevent over-refusal on normal distress
- **Effort:** Low (1 week)

### Tier 2: AI Instability Prevention (v1.2 - Q2 2026) ✅ COMPLETE

**4. Response Shape Validation** ⭐⭐⭐ *NEW*
- Detects erratic, conspiratorial, or radicalized response patterns
- Analyzes structure/framing (privacy-preserving, no content analysis)
- Critical for educational/youth contexts
- **Effort:** Medium (3-4 hours)

**5. Mode Integrity Enforcement** ⭐⭐⭐
- Ensures AI stays within declared roles (prevents authority creep)
- Regulatory story (COPPA, clinical defensibility)
- **Effort:** Medium (3-4 hours)

**6. Enhanced State Modeling** ⭐⭐⭐
- Shift from "event detection" to "risk momentum"
- Tracks volatility, boundary erosion, dependency drift
- **Effort:** High (4-6 hours)

**7. Psychological Exposure Guardrails** ⭐⭐⭐ *NEW*
- Detects emotional dependency loops, isolation reinforcement
- Monitors volatility and boundary erosion over time
- Requires Enhanced State Modeling first
- **Effort:** High (4-5 hours)

### Tier 3: Enterprise & UX (v1.3 - Q3 2026) ✅ COMPLETE

### Tier 3: Enterprise & Compliance (v1.5 - Q3-Q4 2026)

**7. Regulatory SKU Alignment** ⭐⭐ *NEW*
- Explicit COPPA/FERPA/HIPAA/EEOC mapping to modes
- Mode selection becomes compliance decision, not just UX
- Regulatory Compliance Matrix for enterprise positioning
- **Effort:** Low (1 week) - Documentation/packaging enhancement

**8. Regulator Export Modes** ⭐⭐ *NEW*
- FDA/HIPAA/EEOC/FERPA-specific export schemas
- Regulator-ready audit artifacts
- Standardized workflows for each regulator type
- **Effort:** Medium (2-3 weeks)

**9. Continuous Improvement and Telemetry** ⭐ *NEW*
- Opt-in telemetry for lexicon updates and adaptive anchor refreshes
- Clear documentation of non-detected risks and scope boundaries
- A/B testing framework for anchor updates
- **Effort:** Medium (2-3 weeks) - **Opt-in only, always anonymized**

**10. User-Facing Awareness Signals** ⭐⭐
- Transparently communicates when safety systems intervene
- Opt-in feature for apps
- **Effort:** Low (1-2 hours)

**11. Model Presets (Llama Turbo, Haiku Protocol)**
- Pre-configured speed/cost optimizations
- **Effort:** Low (1 week)

---

## Bottom Line

**SASI already prevents most AI instability** that creates psychological risk. These upgrades extend from **reactive safety** to **early instability prevention**, adding:

- Response structure analysis (radicalization detection)
- Mode integrity enforcement (role confusion prevention)
- Psychological exposure guardrails (dependency/radicalization prevention)
- User transparency (trust building)

**SASI's role:** Prevent foreseeable harm caused by unstable AI behavior (not diagnose psychosis).

---

## Timeline

- **v1.3.1 / v1.4 (Q1-Q2 2026):** 3-5 weeks - Safety refinements (ambiguity handling, auditability, disclosure guard hardening)
- **v1.4 (Q2-Q3 2026):** 8-10 weeks - Enhanced detection and analytics (reliability scoring, metrics, pattern decay)
- **v1.5 (Q3-Q4 2026):** 4-6 weeks - Enterprise & compliance (regulatory SKUs, regulator exports, telemetry)

**Total:** ~15-21 weeks for new roadmap items

**Source:** Analysis of mental health app architectures + Product recommendations (January 2026)

---

## Food for Thought (Experimental / Research - v2.0+)

**These are interesting ideas documented for future consideration but deferred for architectural or complexity reasons:**

- **Signed Mode Manifests** - Cryptographic contracts for safety enforcement (deferred - over-engineering for v1.x)
- **Risk Momentum API** - Separate product surface for symbolic layer (deferred - scope creep, better as v2.0+ separate offering)
- **Symbolic Layer Knowledge Base** - Curated, versioned operators with benchmarking (deferred - lower priority documentation enhancement)
- **Auto-Fallback in SASI Canary** - Automatic model swapping on degradation (deferred - too risky, apps should decide fallback)

**See `UPGRADE_PRIORITIZATION.md` Tier 5 section for detailed analysis.**

---

*For detailed technical specifications, see `UPGRADE_PRIORITIZATION.md` and `Recomended_Updates_010526.md`*  
*For complete mode-to-feature mapping, see `MODE_FEATURES_MATRIX.md`*

