# THRIVE — Wellness Services Marketing & Management Complete AI OS

## Read this before installation

This is a standalone governed lane for wellness-services marketers, managers, program leaders, community-growth leaders, and small wellness-business operators. It is not a clinical system, CRM-of-record, advertising account, HR system, finance ledger, consent system, or institutional authority.

**Downloading, selecting, opening, or unzipping this package does not install or activate anything.** It does not verify identity, title, employment, marketing authority, delegated mandate, spending threshold, claims, evidence, consent, platform permission, legal compliance, clinical scope, or institutional approval.

## Start with inspection only

Give Hermes the entire one-file program, then issue only:

> `INSPECT THRIVE INSTALLER ONLY — CREATE NO STATE.`

This authorizes read-only S0 only: no state, profile change, installation, connector, memory, schedule, agent run, external action, organizational deployment, or live-system access.

Hermes must display the exact combined **THRIVE Activation Card** defined inside the controlling program. Confirm its computed complete-program SHA-256, target, authority, isolated lane and partitions, all component hashes, allowed/prohibited data and claims, tools/destinations/actions, human routes, unsupported controls, phase burden, rollback/uninstall scope, and exact choice.

## Exact post-card authority

Only after reviewing that exact card may the user issue:

> `INSTALL THRIVE AFTER S0 — USE EXACT VERIFIED COMPONENT HASHES AND KEEP ALL POWERS AND AGENTS INACTIVE.`

Silence, timeout, download, file opening, title, credentials, access, prior work, or a general request to publish/install is never approval. Any material target, program/hash, component, authority, policy, data, claim, route, partition, permission, action, or card change requires a new card.

## Permanent safety ceiling

Use only public, unmistakably synthetic, or separately approved aggregate/process information. Do not enter PHI; patient/client/lead/contact/employee/contractor rows or narratives; health histories; claims or adverse events; credentials; payment-card data; proprietary lists; confidential contracts/vendor/security/financial material; or merely name-stripped stories.

THRIVE may organize questions, scenarios, claims evidence, briefs, content drafts, campaign/service plans, and human review routes. It will not diagnose, recommend care, fabricate evidence or testimonials, target sensitive traits, manipulate vulnerability, contact people, publish, advertise, send, schedule, boost, bid, change price, spend, transact, sign, hire, evaluate, discipline, procure, change security, or write an official system. Human approval does not convert a categorically prohibited function into an allowed one.

The 160 criteria are **specified—not pre-passed**. Repository validation proves package structure, schemas, hashes, and declared contracts; it does not prove target-runtime execution, clinical or legal validity, compliance, platform permission, institutional authorization, safety, revenue, or outcomes.

Institution-managed use requires separate approval for the exact organization, platform/model, purpose, data, reads/writes, connectors/actions, logging, retention/deletion, security, incident response, human owners, and fallback. Private-workspace approval does not authorize organizational deployment.

*Agents propose. Humans judge. Nurses steward.*
