Phase 6A — Operational Evidence Execution Board
BC-01 → BC-09 · Evidence Acquisition, Targeted Retest & Closure Control Room
Single integrated operational control room governing the conversion of DesignEvidence / SimulationEvidence into OperationalClosureEvidence sufficient for targeted retest and, ultimately, Phase 6A Integrated Revalidation.
Not a status report, not a progress instrument, not a Pilot authorization.
DESIGN / SIMULATION ASSURANCE COMPLETE
NOT OPERATIONAL CLOSURE EVIDENCE
95 scenarios PASS · 14/14 frozen invariants PASS · 0 correctable defects open · 4 controlled open dependencies. Simulation may raise design confidence; it may never raise EvidenceQuality.
F · BC-09 Protection Panel — permanently visible
Allowed pre-baseline activities:
- Non-intrusive metric source and owner confirmation
- Collection method definition and instrument preparation
- Data access authorization requests
- Observation that does not alter current field behaviour
Prohibited:
- Any Pilot exposure to field crews or supervision
- Training that changes current ways of working
- Trial use of readiness outputs in live shift decisions
- Retrospective reconstruction of a BEFORE baseline
Any proposed action that may alter current field behaviour is classified PILOT_INTERVENTION and blocked until BC-09 collection is formally underway.
A · Executive Phase 6A Evidence Dashboard
NOT PROVIDED — no aggregate percentage may be used to authorize Pilot. Non-compensable conditions are counted, never averaged.
Board answers at any time:
- What blocker remains open?
- Why is it open?
- What exact evidence is missing?
- Who is competent to provide or approve that evidence?
- Has evidence been requested?
- Has it been received?
- Is it current and valid?
- Is it sufficient for targeted retest?
- Has targeted retest been executed?
- What residual dependency remains?
- What prevents Phase 6A Integrated Revalidation?
New issue classification before any new blocker: SubCondition · Finding · Dependency · EvidenceGap · Contradiction
Rule: No new blocker may be created for administrative convenience. Every new issue is first classified; escalation to a tenth blocker requires competent authority and a recorded reason.
B · BC-01 → BC-09 Master Blocker Register
Why open: Zero owner confirmations received; participation is currently design intent only.
Design condition: Federated participation model defined per source and object class (Option C, ADR-13/CA-01); failure behaviour fail-closed.
Operational condition: No system owner has authorized real Pilot participation for any source; participation mode per source remains undeclared by the accountable owner.
Competent authority: Enterprise Architecture + each named System Owner
Evidence owner: Enterprise Architecture
Supporting owners: IT / IM · Q4 System Owner · Aconex / IM Owner · P6 / Project Controls · Smart Completions
Minimum acceptance evidence: Signed or attributable owner confirmation per source/object stating participation mode, authority boundaries and failure behaviour. Governed snapshot or controlled manual federation is acceptable where sufficient for CV-07 — live API is not demanded and never inferred.
Evidence received: NONE · Ref — none received · Date — · Effective — · SourceVersion —
Validity: N/A — no evidence in hand
External dependency: External system owners outside the design team; enterprise change windows. (EVIDENCE_DEPENDENCY)
Escalation: ESC-02
Retest: — not raised (queue empty) · Result NOT_EXECUTED
Residual risk: Pilot could be scoped against assumed participation that the owning organization does not authorize.
Closure disposition: REMAINS_OPEN
Next action: Issue and chase per-source owner confirmation requests (longest external lead time on the board).
Evidence required (4)
- Per source/object owner confirmation of participation mode (LIVE_READ / CONTROLLED_TRANSACTION / CONTROLLED_SNAPSHOT / CONTROLLED_MANUAL_FEDERATION / SIMULATED_ONLY / NOT_REQUIRED)
- Interface mechanism and authentication statement as it will actually operate in the Pilot
- Read / write / snapshot authority declaration per object class
- Version behaviour and source-unavailable failure behaviour confirmation
Why open: No enterprise identity artefact exists; all authority behaviour demonstrated so far is prototype-internal.
Design condition: Attribute-based authority model frozen: Role × Area × Activity × Shift × RiskLevel × RegisterType × DelegationScope; access ≠ authority; fail-closed on unresolved authority.
Operational condition: No enterprise identity provider integration confirmed, no Pilot identities provisioned, no enforceable role resolution outside the prototype.
Competent authority: IAM / Cyber
Evidence owner: IAM / Cyber
Supporting owners: IT / IM · HR / RRLL · Enterprise Architecture
Minimum acceptance evidence: IAM owner confirmation of provider, authentication, role resolution, delegation and revocation, plus a provisioned Pilot identity set. Prototype identity behaviour is explicitly not closure evidence.
Evidence received: NONE · Ref — none received · Date — · Effective — · SourceVersion —
Validity: N/A — no evidence in hand
External dependency: Enterprise IAM programme and cyber approval cycle. (EVIDENCE_DEPENDENCY)
Escalation: ESC-02
Retest: — not raised (queue empty) · Result NOT_EXECUTED
Residual risk: Authority enforcement would fall back to application access — the exact failure the design forbids.
Closure disposition: REMAINS_OPEN
Next action: Request IAM provider/role-resolution confirmation and Pilot identity provisioning plan.
Evidence required (4)
- Identity provider and authentication method confirmation for Pilot users
- Role resolution source and mapping to authority scopes (area/activity/shift/risk)
- Delegation and revocation behaviour as enforced by the enterprise, not the prototype
- IAM-01 → IAM-06 retest population definition with real identities
Why open: Lifecycle is defined by design, accepted by nobody operationally.
Design condition: Object lifecycles, allowed states and transitions defined; invalid transition and authority-unavailable behaviour fail-closed.
Operational condition: GovernanceLifecycleDefined = YES (design). TechnicallyEnforceable = NOT_DEMONSTRATED — no named lifecycle owner has accepted transition authority for the Pilot.
Competent authority: Business Product Owner + per-object Lifecycle Owners
Evidence owner: Business Product Owner
Supporting owners: Q4 System Owner · ES&H · Construction · Enterprise Architecture
Minimum acceptance evidence: Competent-authority decision artefact per object class accepting lifecycle ownership and transition authority. May close faster than BC-01/BC-02 because it is a decision, not an integration.
Evidence received: NONE · Ref — none received · Date — · Effective — · SourceVersion —
Validity: N/A — no evidence in hand
External dependency: BC-02 for technical enforcement of transition authority. (EXECUTION_DEPENDENCY)
Escalation: ESC-01
Retest: — not raised (queue empty) · Result NOT_EXECUTED
Residual risk: Lifecycle transitions executed without attributable authority.
Closure disposition: REMAINS_OPEN
Next action: Convene lifecycle owner acceptance session; produce per-object decision artefacts.
Evidence required (3)
- Named lifecycle owner acceptance per object with allowed transitions and transition authority
- Named delegate and authority-unavailable behaviour acceptance
- Decision artefact format accepted by the accountable function
Why open: Stewardship exists as a design role set with no operational appointments.
Design condition: GOVERNANCE_DESIGN_STRUCTURALLY_SOUND — roles, SoD and escalation paths defined (ADR-14 stewardship).
Operational condition: No real person assigned, authorized and available for the governing stewardship roles; capacity and SoD unverified.
Competent authority: Project Director / Accountable Executive
Evidence owner: Change / Adoption
Supporting owners: HR / RRLL · Compliance · Enterprise Architecture · Operational Support
Minimum acceptance evidence: Attributable appointment records with authorization, named delegate, allocated capacity and SoD confirmation. A name on an org chart is SUPPORTING_EVIDENCE only.
Evidence received: NONE · Ref — none received · Date — · Effective — · SourceVersion —
Validity: N/A — no evidence in hand
External dependency: Organizational resourcing decisions outside the programme. (EVIDENCE_DEPENDENCY)
Escalation: ESC-01
Retest: — not raised (queue empty) · Result NOT_EXECUTED
Residual risk: Vacant stewardship forces fail-closed HOLD in live operation (scenario G-01).
Closure disposition: REMAINS_OPEN
Next action: Escalate stewardship appointment decision with capacity commitment.
Evidence required (2)
- Real named assignment for BusinessProductOwner, LocationSteward, FederationMappingSteward, RuleOwner, IntegrationOwner, OperationalSupportOwner, ChangeAdoptionOwner
- For each: Assigned / Authorized / Available / Delegate / Escalation / Capacity / SoD evidence
Why open: Classification and retention are configured by design; no competent decision exists.
Design condition: CA-04 record classes modelled; RC-RET-01 v1.1 per-evidence-class retention; unclassified → RETAIN_AND_HOLD (fail-closed); minimum-attribute principle applied to person and health data.
Operational condition: No Records Management / Privacy / Compliance decision on classification, retention basis or access scope for the Pilot record classes.
Competent authority: Records Management + Privacy + Compliance
Evidence owner: Records Management
Supporting owners: Privacy · Compliance · Health · HR / RRLL
Minimum acceptance evidence: Competent decision artefact per material record class covering classification, retention basis, minimum attribute and custodian. No duplication of HR/Health source records is permitted.
Evidence received: NONE · Ref — none received · Date — · Effective — · SourceVersion —
Validity: N/A — no evidence in hand
External dependency: Privacy and legal review cycle. (EVIDENCE_DEPENDENCY)
Escalation: ESC-01
Retest: — not raised (queue empty) · Result NOT_EXECUTED
Residual risk: Evidence retained or minimised on design assumption rather than legal basis.
Closure disposition: REMAINS_OPEN
Next action: Table the CA-04 material item list for Records/Privacy decision — decision artefact, not integration.
Evidence required (3)
- Per material CA-04 item: RecordClass, DataClassification, PersonalData flag, DecisionFactRequired, MinimumAttributeRequired
- RetentionBasis and RetentionPeriodBasis decision (legal/contractual)
- AccessScope and Custodian designation
Why open: Path decision not taken; simulated critical control cannot substitute for either path.
Design condition: Critical Control model defined (Required/Available/Verified/Effective/Failed/Recovered), non-compensable; currently SIMULATED in the prototype.
Operational condition: No competent authority has elected PATH_A_REAL_PARTICIPATION or PATH_B_FORMAL_RESCOPE. Until formally elected, BC-06 = OPEN.
Competent authority: ES&H Accountable Executive + Critical Control / Forwood Owner
Evidence owner: Critical Control / Forwood Owner
Supporting owners: ES&H · Enterprise Architecture · Construction
Minimum acceptance evidence: One explicit, attributable path election. Path B must never be chosen merely to facilitate closure.
Evidence received: NONE · Ref — none received · Date — · Effective — · SourceVersion —
Validity: N/A — no evidence in hand
External dependency: Critical control system owner authorization (Path A) or executive rescope (Path B). (CLOSURE_DEPENDENCY)
Escalation: ESC-03
Retest: — not raised (queue empty) · Result NOT_EXECUTED
Residual risk: Path ambiguity propagates unresolved scope into BC-08 and Phase 7 claims.
Closure disposition: REMAINS_OPEN
Next action: Force the path election decision — it governs downstream field scope (BC-08).
Evidence required (2)
- PATH A: governed source participation confirmation for critical control status and verification records
- PATH B: formal rescope decision recording DecisionAuthority, Reason, PilotEvidenceLost, ResidualRisk, Phase7Impact
Why open: No staffed L1/L2/L3 and zero operational drills executed.
Design condition: L1/L2/L3 support model, issue types, operating window, escalation and authority boundary defined.
Operational condition: No staffed support function; the design team remains the de-facto L2/L3 — a hidden dependency that invalidates sustainability.
Competent authority: Operational Support Owner
Evidence owner: Operational Support
Supporting owners: IT / IM · Change / Adoption · Enterprise Architecture
Minimum acceptance evidence: Staffed support model plus real drill records for S-01 (user/access), S-02 (mapping conflict), S-03 (rule question), S-04 (interface failure), S-05 (authority issue), S-06 (evidence reconstruction). Simulation drills are not operational drill evidence.
Evidence received: NONE · Ref — none received · Date — · Effective — · SourceVersion —
Validity: N/A — no evidence in hand
External dependency: Support resourcing and service-window commitment. (EVIDENCE_DEPENDENCY)
Escalation: ESC-01
Retest: — not raised (queue empty) · Result NOT_EXECUTED
Residual risk: Pilot operable only while the design team is present — non-sustainable.
Closure disposition: REMAINS_OPEN
Next action: Secure support staffing decision, then schedule S-01 → S-06 as real drills.
Evidence required (3)
- Named L1 / L2 / L3 owners with operating window and escalation path
- Authority boundary statement and explicit design-team dependency declaration
- Operational drills S-01 → S-06 executed by the real support function
Why open: No real workfront nominated; all ten dimensions carry DesignEvidence only.
Design condition: FIELD_AND_MEASUREMENT_DESIGN_STRUCTURALLY_SOUND — CV-07 field execution model complete.
Operational condition: 0/10 closure dimensions demonstrated with OperationalClosureEvidence. Missing evidence is OPEN, not FAILED.
Competent authority: Construction Manager + Field Supervision
Evidence owner: Construction
Supporting owners: BEO · Materials · Tools · Logistics · Environment · ES&H · Field Supervision
Minimum acceptance evidence: Attributable confirmation per dimension from the accountable field function for a real, nominated CV-07 workfront.
Evidence received: NONE · Ref — none received · Date — · Effective — · SourceVersion —
Validity: N/A — no evidence in hand
External dependency: BC-06 path election where Critical Controls apply; construction sequencing. (EXECUTION_DEPENDENCY)
Escalation: ESC-01
Retest: — not raised (queue empty) · Result NOT_EXECUTED
Residual risk: Pilot executed against a notional rather than real workfront.
Closure disposition: REMAINS_OPEN
Next action: Nominate a real CV-07 workfront and start dimension-by-dimension confirmation (0/10 today).
Evidence required (10)
- RealWorkfront
- RealLocation
- RealWorkDemand
- Crew
- Equipment
- Materials
- FieldOwner
- ExecutionWindow
- SIMOPSContext
- FieldPrerequisites
Why open: Collection has not started; metrics remain at DEFINED with no confirmed source or owner.
Design condition: 12 frozen metrics defined with source, owner and collection method.
Operational condition: ProspectiveCollection = NOT_STARTED. All 12 metrics at DEFINED. Time-irreversible: BEFORE can never be reconstructed retrospectively.
Competent authority: Project Controls + Business Product Owner
Evidence owner: P6 / Project Controls
Supporting owners: Construction · Field Supervision · Operational Support
Minimum acceptance evidence: Attributable collection-start record plus a sufficient prospective data window per metric. Inference of collection is prohibited.
Evidence received: NONE · Ref — none received · Date — · Effective — · SourceVersion —
Validity: N/A — no evidence in hand
External dependency: Field data availability; strict precedence over any Pilot exposure. (CLOSURE_DEPENDENCY)
Escalation: ESC-04
Retest: — not raised (queue empty) · Result NOT_EXECUTED
Residual risk: Irreversible loss of the BEFORE baseline if any Pilot exposure changes current ways of working before collection starts.
Closure disposition: REMAINS_OPEN
Next action: Confirm metric sources and owners and start prospective collection — irreversibility makes this time-critical.
Evidence required (3)
- Per metric: SOURCE_CONFIRMED, OWNER_CONFIRMED, COLLECTION_READY, then COLLECTING
- Formal prospective collection start record
- Anti-contamination confirmation that no Pilot exposure preceded collection start
B.1 · BC-01 Execution Card — Source / Object Participation
Do not infer APIs. Absence of a declared mechanism is recorded as NOT_DECLARED, never as an assumed integration. Do not demand live integration where governed snapshot or controlled manual federation is sufficient for CV-07. SIMULATED_ONLY is a valid declared mode but yields no OperationalClosureEvidence for participation.
| Source | Object class | Owner | Participation | Mechanism / Auth | Read / Write / Snapshot | Version | Failure behaviour | Owner confirmation |
|---|---|---|---|---|---|---|---|---|
| Q4 / Entity Desk | Permit, JHA, Isolation, Sanction to Test, Work Authorization | Q4 System Owner | NOT_DECLARED — candidate CONTROLLED_TRANSACTION or CONTROLLED_SNAPSHOT | NOT_DECLARED — no API inferred / NOT_DECLARED | Q4 (source of record) / Q4 only — readiness layer never writes / NOT_DECLARED | Pinned revision required at decision time | Source unavailable → UNVERIFIABLE → fail-closed HOLD | NONE RECEIVED |
| Aconex | Controlled documents, procedures, PETS | Aconex / IM Owner | NOT_DECLARED — candidate CONTROLLED_SNAPSHOT | NOT_DECLARED / NOT_DECLARED | Aconex / Aconex only / NOT_DECLARED — snapshot validity window governance open (ADR-05) | Revision pinning + change detection + materiality assessment | Snapshot stale → STALE marker; unverifiable → HOLD | NONE RECEIVED |
| Primavera P6 | WBS, activity, schedule, look-ahead | P6 / Project Controls | NOT_DECLARED — candidate LIVE_READ or CONTROLLED_SNAPSHOT | NOT_DECLARED / NOT_DECLARED | P6 / P6 only / NOT_DECLARED | Look-ahead window versioned per shift | Degradable — forecast degrades, field execution unaffected | NONE RECEIVED |
| Forwood (Critical Control) | Critical controls, fatal-risk taxonomy, verification records | Critical Control / Forwood Owner | SIMULATED_ONLY (current) — Path A/B election pending (BC-06) | NOT_DECLARED / NOT_DECLARED | Forwood or equivalent / Forwood only / NOT_DECLARED | Verification validity window governs currency | Blocking — unverifiable critical control → HOLD, never compensated | NONE RECEIVED |
| People & Training | Roster, competency, qualification validity | HR / RRLL + Training | NOT_DECLARED — candidate CONTROLLED_SNAPSHOT | NOT_DECLARED / NOT_DECLARED | People & Training / People & Training only / NOT_DECLARED | Validity-date driven; expiry is a blocking condition | Blocking for competency-gated activities | NONE RECEIVED |
| Health Status | Operational fitness flag only (minimum attribute) | Health | NOT_DECLARED — minimum-exposure read candidate | NOT_DECLARED / NOT_DECLARED | Health / Health only — no medical data duplicated / NOT_PERMITTED pending BC-05 decision | Flag currency window | Not confirmed → fail-closed for affected person/activity | NONE RECEIVED |
| Smart Completions | Subsystem / completion status | Smart Completions | NOT_DECLARED | NOT_DECLARED / NOT_DECLARED | Smart Completions / Smart Completions only / NOT_DECLARED | Completion state versioned per subsystem | Degradable for forecast; blocking for release gating | NONE RECEIVED |
| Canonical Location Register | Location, SIMOPS context | Location Steward (ADR-14 Option C — vacant) | CONTROLLED_MANUAL_FEDERATION candidate — steward unassigned | Federated canonical register / NOT_DECLARED | Readiness layer (federated canonical) / Location Steward under governance / Steward-governed | Location version pinned into every decision | Vacant steward → fail-closed HOLD (G-01) | NONE RECEIVED — depends on BC-04 |
B.2 · BC-02 Execution Card — Identity & Enforceable Authority
Prototype identity tests do not count as closure evidence under any circumstance.
Identity provider: NOT_CONFIRMED
Pilot identity: NOT_PROVISIONED
Authentication: NOT_CONFIRMED
Role resolution: NOT_CONFIRMED — prototype role context is not an identity source
Authority scope: Model frozen (attribute-based); enterprise enforcement NOT_CONFIRMED
Area / Activity / Shift / Risk scope: NOT_CONFIRMED · NOT_CONFIRMED · NOT_CONFIRMED · NOT_CONFIRMED
Delegation: Model defined; enterprise delegation source NOT_CONFIRMED
Revocation behaviour: Design: immediate fail-closed. Enterprise behaviour NOT_CONFIRMED
IAM-01
Authenticated identity resolves to a single authoritative role set.
NOT_EXECUTABLE — no real identityIAM-02
Authority scope enforced by area.
NOT_EXECUTABLEIAM-03
Authority scope enforced by activity and risk level.
NOT_EXECUTABLEIAM-04
Shift-bounded authority expires at shift end.
NOT_EXECUTABLEIAM-05
Delegation grants scoped authority and no more.
NOT_EXECUTABLEIAM-06
Revocation takes effect immediately and fails closed.
NOT_EXECUTABLEB.3 · BC-03 Execution Card — Lifecycle Authority
GovernanceLifecycleDefined = YES is a design property. TechnicallyEnforceable = NOT_DEMONSTRATED and remains an execution dependency on BC-02.
Preventive Work Package
Lifecycle owner: NOT_ASSIGNED (candidate: Construction Owner)
Allowed states: DRAFT → REVIEW → APPROVED → RE-AUTHORIZED → SUPERSEDED / EXPIRED / CLOSED / CANCELLED
Transitions / authority: Defined · NOT_ACCEPTED
Delegate: NOT_NAMED
Invalid transition: Rejected and logged (design)
Authority unavailable: Fail-closed HOLD (design)
Decision artefact: NOT_PRODUCED
Readiness Decision (IRDE)
Lifecycle owner: NOT_ASSIGNED (candidate: Business Product Owner)
Allowed states: READY / CONDITIONAL / HOLD / STOP
Transitions / authority: Deterministic, non-compensable · NOT_ACCEPTED
Delegate: NOT_NAMED
Invalid transition: Impossible by construction; attempt logged
Authority unavailable: HOLD
Decision artefact: NOT_PRODUCED
Restriction
Lifecycle owner: NOT_ASSIGNED (ADR-03 controlled open)
Allowed states: OPEN → IN_PROGRESS → RESOLVED → VERIFIED → CLOSED
Transitions / authority: Defined; verification separate from resolution · NOT_ACCEPTED
Delegate: NOT_NAMED
Invalid transition: Rejected
Authority unavailable: Remains OPEN
Decision artefact: NOT_PRODUCED
Critical Control state
Lifecycle owner: NOT_ASSIGNED (BC-06 path pending)
Allowed states: Required / Available / Verified / Effective / Failed / Recovered
Transitions / authority: Verification-driven only · NOT_ACCEPTED
Delegate: NOT_NAMED
Invalid transition: Rejected; no self-declared effectiveness
Authority unavailable: Treated as not verified → HOLD/STOP
Decision artefact: NOT_PRODUCED
Evidence record
Lifecycle owner: NOT_ASSIGNED (candidate: Records Management, BC-05)
Allowed states: PENDING_VERIFICATION → VERIFIED / BROKEN_CHAIN
Transitions / authority: Append-only · NOT_ACCEPTED
Delegate: NOT_NAMED
Invalid transition: Mutation prohibited
Authority unavailable: Retain and hold
Decision artefact: NOT_PRODUCED
B.4 · BC-04 Execution Card — Stewardship & Governance
| Role | Assigned | Authorized | Available | Delegate | Escalation | Capacity | SoD | Evidence |
|---|---|---|---|---|---|---|---|---|
| BusinessProductOwner | NO | NO | NO | NOT_NAMED | ESC-01 | NOT_ALLOCATED | NOT_VERIFIED | — none |
| LocationSteward | NO | NO | NO | NOT_NAMED | ESC-01 | NOT_ALLOCATED | NOT_VERIFIED | — none |
| FederationMappingSteward | NO | NO | NO | NOT_NAMED | ESC-01 | NOT_ALLOCATED | NOT_VERIFIED | — none |
| RuleOwner | NO | NO | NO | NOT_NAMED | ESC-01 | NOT_ALLOCATED | NOT_VERIFIED | — none |
| IntegrationOwner | NO | NO | NO | NOT_NAMED | ESC-01 | NOT_ALLOCATED | NOT_VERIFIED | — none |
| OperationalSupportOwner | NO | NO | NO | NOT_NAMED | ESC-01 | NOT_ALLOCATED | NOT_VERIFIED | — none |
| ChangeAdoptionOwner | NO | NO | NO | NOT_NAMED | ESC-01 | NOT_ALLOCATED | NOT_VERIFIED | — none |
B.5 · BC-05 Execution Card — Classification, Retention & Minimisation
No duplication of HR or Health source records is permitted.
DecisionPin (readiness decision provenance)
Classification / personal data: NOT_DECIDED · Indirect (actor identity)
Decision fact required: Decision inputs, versions, authority, timestamp
Minimum attribute: Actor reference + role, not personal profile
Retention basis / period: NOT_DECIDED — design proposes RETAIN_UNTIL_RECONSTRUCTION_OBLIGATION_ENDS · NOT_DECIDED
Access scope / custodian: NOT_DECIDED · NOT_ASSIGNED
Competent decision: Records Management + Privacy
Evidence: — none
SourcePayloadProjection (federated snapshot)
Classification / personal data: NOT_DECIDED · Possible (roster projections)
Decision fact required: Pinned revision + hash
Minimum attribute: Only attributes consumed by a rule
Retention basis / period: NOT_DECIDED — design proposes 90d · NOT_DECIDED
Access scope / custodian: NOT_DECIDED · NOT_ASSIGNED
Competent decision: Records Management + source owner
Evidence: — none
CompetencyProjection
Classification / personal data: NOT_DECIDED · YES
Decision fact required: Qualification validity state at decision time
Minimum attribute: Person ref, qualification, validity date — no training history
Retention basis / period: NOT_DECIDED · NOT_DECIDED
Access scope / custodian: NOT_DECIDED · NOT_ASSIGNED
Competent decision: Privacy + HR / RRLL
Evidence: — none
Operational fitness flag
Classification / personal data: NOT_DECIDED · YES — health-adjacent
Decision fact required: FIT_FOR_TASK / NOT_CONFIRMED only
Minimum attribute: Binary flag; no medical data, no diagnosis, no duplication of Health records
Retention basis / period: NOT_DECIDED · NOT_DECIDED
Access scope / custodian: NOT_DECIDED — narrowest scope expected · NOT_ASSIGNED
Competent decision: Health + Privacy + Compliance
Evidence: — none
AuthorityRecord (delegation / approval)
Classification / personal data: NOT_DECIDED · YES (identity + role)
Decision fact required: Who authorized what, under which scope
Minimum attribute: Identity ref, role, scope, validity
Retention basis / period: NOT_DECIDED — design proposes RETAIN_FULL_LIFECYCLE · NOT_DECIDED
Access scope / custodian: NOT_DECIDED · NOT_ASSIGNED
Competent decision: Compliance + Records Management
Evidence: — none
B.6 · BC-06 Execution Card — Critical Control Path
Until a path is formally elected, BC-06 = OPEN.
PATH_A_REAL_PARTICIPATION
Requires: Real governed source participation for critical control status and verification records (links BC-01).
Current state: NOT_ELECTED — no source owner authorization received.
Consequence if elected: BC-06 closure depends on BC-01 participation evidence for the critical control source.
PATH_B_FORMAL_RESCOPE
Requires: DecisionAuthority · Reason · PilotEvidenceLost · ResidualRisk · Phase7Impact — all mandatory.
Current state: NOT_ELECTED — no rescope decision recorded.
Consequence if elected: Pilot loses critical-control participation evidence; Phase 7 claims must be narrowed accordingly. Never elected merely to facilitate closure.
B.7 · BC-07 Execution Card — Operational Support & Design-Team Independence
Simulation drills executed in the campaign are SIMULATION_EVIDENCE and are not recorded as operational drill evidence.
L1 / L2 / L3: NOT_ASSIGNED · NOT_ASSIGNED · NOT_ASSIGNED
Issue types: User/access · mapping conflict · rule question · interface failure · authority issue · evidence reconstruction
Operating window: NOT_DEFINED OPERATIONALLY
Escalation: ESC-01
Authority boundary: Support may never resolve an authority decision — it routes to competent authority.
Design-team dependency: PRESENT — currently the de-facto L2/L3. Must be eliminated before Pilot.
S-01 · User / Access
NOT_EXECUTEDS-02 · Mapping Conflict
NOT_EXECUTEDS-03 · Rule Question
NOT_EXECUTEDS-04 · Interface Failure
NOT_EXECUTEDS-05 · Authority Issue
NOT_EXECUTEDS-06 · Evidence Reconstruction
NOT_EXECUTEDB.8 · BC-08 Execution Card — Field Execution Prerequisites
0/10 demonstrated with OperationalClosureEvidence. Missing evidence is OPEN — not FAILED.
RealWorkfront
Owner: Construction
RealLocation
Owner: Location Steward (vacant)
RealWorkDemand
Owner: Construction / Planning
Crew
Owner: Field Supervision
Equipment
Owner: BEO
Materials
Owner: Materials
FieldOwner
Owner: Construction
ExecutionWindow
Owner: Field Supervision
SIMOPSContext
Owner: ES&H / Location Steward
FieldPrerequisites
Owner: Construction / Tools / Logistics
B.9 · BC-09 Execution Card — 12 Frozen Prospective BEFORE Metrics
Collection is never inferred; prospective BEFORE is never retrospectively reconstructed.
| ID | Metric | State | Owner |
|---|---|---|---|
| M-01 | Time from work demand to preventive package prepared | DEFINED | NOT_CONFIRMED |
| M-02 | Time from package prepared to authorization granted | DEFINED | NOT_CONFIRMED |
| M-03 | Time lost at workfront to missing prerequisite | DEFINED | NOT_CONFIRMED |
| M-04 | Number of work starts halted after mobilisation | DEFINED | NOT_CONFIRMED |
| M-05 | Restriction detection lead time (before vs at workfront) | DEFINED | NOT_CONFIRMED |
| M-06 | Rework of permits / authorizations per shift | DEFINED | NOT_CONFIRMED |
| M-07 | Document revision conflicts detected at execution | DEFINED | NOT_CONFIRMED |
| M-08 | Competency expiry discovered at the workfront | DEFINED | NOT_CONFIRMED |
| M-09 | SIMOPS conflicts detected before vs during execution | DEFINED | NOT_CONFIRMED |
| M-10 | Critical control verification currency at work start | DEFINED | NOT_CONFIRMED |
| M-11 | Supervisor time spent assembling readiness information | DEFINED | NOT_CONFIRMED |
| M-12 | Evidence reconstruction time for an audited decision | DEFINED | NOT_CONFIRMED |
C · Owner-Based Evidence Request Register
No commitment dates invented. 28 requests issued, all AWAITING_OWNER.
Requested: Confirmed federated participation map per source and object class
Why required: BC-01 cannot be retested without a declared participation mode per source.
Minimum acceptable: Attributable participation declaration per source/object.
Preferred: Architecture-signed participation map with failure behaviour.
Alternative acceptable: Per-source owner emails consolidated and countersigned.
Not accepted: Design-team-authored assumption of participation.
Evidence ref: — none
Requested: Participation mode, interface mechanism, authentication and failure behaviour for permit/JHA/isolation objects
Why required: Q4 objects gate work authorization; unverifiable source must fail closed.
Minimum acceptable: Owner statement of mode + authority boundaries.
Preferred: Owner-approved interface specification.
Alternative acceptable: Governed snapshot or controlled manual federation declaration.
Not accepted: Inferred API capability or vendor marketing material.
Evidence ref: — none
Requested: Document snapshot authority and revision-change notification behaviour
Why required: Decision pinning depends on governed revision snapshots.
Minimum acceptable: Owner confirmation of snapshot authority and validity window.
Preferred: Signed snapshot governance note (ADR-05 input).
Alternative acceptable: Manual controlled export under governance.
Not accepted: Assumed export permissions.
Evidence ref: — none
Requested: Look-ahead read participation and refresh cadence
Why required: Forecast context requires a governed schedule source.
Minimum acceptable: Owner confirmation of read mode and cadence.
Preferred: Scheduled governed extract.
Alternative acceptable: Periodic controlled snapshot.
Not accepted: Ad-hoc unsanctioned file sharing.
Evidence ref: — none
Requested: Subsystem completion participation mode
Why required: Release gating consumes completion state.
Minimum acceptable: Owner confirmation of participation mode.
Preferred: Governed read interface statement.
Alternative acceptable: Controlled snapshot.
Not accepted: Assumed availability.
Evidence ref: — none
Requested: Enterprise interface hosting, network and data-movement authorization
Why required: No participation is real without IT authorization.
Minimum acceptable: IT authorization statement for the declared mechanisms.
Preferred: Architecture review record.
Alternative acceptable: Conditional authorization with named constraints.
Not accepted: Verbal assurance without attribution.
Evidence ref: — none
Requested: Identity provider, authentication method and Pilot identity provisioning plan
Why required: Authority enforcement must be enterprise-enforced, not prototype-simulated.
Minimum acceptable: IAM owner confirmation + provisioned identity set.
Preferred: Signed IAM design and provisioning record.
Alternative acceptable: Time-boxed Pilot identity scope with revocation controls.
Not accepted: Prototype role-context behaviour.
Evidence ref: — none
Requested: Role resolution source and mapping to area / activity / shift / risk scopes
Why required: Attribute-based authority is unenforceable without a role source.
Minimum acceptable: Documented mapping from enterprise roles to authority scopes.
Preferred: IAM-owned mapping artefact.
Alternative acceptable: HR-sourced role feed with IAM endorsement.
Not accepted: Design-team role table.
Evidence ref: — none
Requested: Delegation and revocation behaviour confirmation
Why required: Delegation must never widen scope; revocation must fail closed.
Minimum acceptable: Written enterprise behaviour statement.
Preferred: Demonstrated revocation in a controlled test with real identities.
Alternative acceptable: Documented procedure with named enforcement owner.
Not accepted: Simulated revocation results.
Evidence ref: — none
Requested: Authoritative person-to-role source for Pilot population
Why required: Role resolution requires an authoritative person source.
Minimum acceptable: HR confirmation of authoritative source and update cadence.
Preferred: System-of-record extract governance note.
Alternative acceptable: Controlled snapshot with steward.
Not accepted: Spreadsheet of assumed personnel.
Evidence ref: — none
Requested: Acceptance of lifecycle ownership and transition authority per object
Why required: Lifecycle is defined by design and accepted by nobody.
Minimum acceptable: Decision artefact per object class.
Preferred: Signed lifecycle authority matrix.
Alternative acceptable: Minuted governance decision with attributable authority.
Not accepted: Design specification restated as acceptance.
Evidence ref: — none
Requested: Confirmation of transaction lifecycle authority boundaries at the federation edge
Why required: Prevents accidental duplication of Q4 authority.
Minimum acceptable: Owner confirmation of who may transition what.
Preferred: Joint authority boundary statement.
Alternative acceptable: Documented exception list.
Not accepted: Assumed boundary.
Evidence ref: — none
Requested: Named, authorized and available stewardship appointments (7 roles)
Why required: Vacant stewardship forces fail-closed HOLD in operation.
Minimum acceptable: Appointment records with authorization and capacity.
Preferred: Signed appointment letters with delegates.
Alternative acceptable: Interim appointments with explicit validity and escalation.
Not accepted: Org-chart names without authorization or capacity.
Evidence ref: — none
Requested: Capacity allocation and SoD confirmation for stewardship roles
Why required: Assignment without capacity is not stewardship.
Minimum acceptable: Capacity statement per role.
Preferred: Formal resourcing record.
Alternative acceptable: Time-boxed allocation with review date.
Not accepted: Best-effort verbal commitment.
Evidence ref: — none
Requested: Segregation-of-duties assessment for steward / owner combinations
Why required: SoD breach would compromise authority separation.
Minimum acceptable: Compliance SoD assessment.
Preferred: Signed assessment with conditions.
Alternative acceptable: Conditional acceptance with compensating control recorded.
Not accepted: Self-assessment by the design team.
Evidence ref: — none
Requested: Retention basis and period per material record class
Why required: Retention currently rests on a design proposal, not a legal basis.
Minimum acceptable: Competent retention decision per class.
Preferred: Signed retention schedule extract.
Alternative acceptable: Interim retention decision with review date.
Not accepted: Design proposal RC-RET-01 restated.
Evidence ref: — none
Requested: Personal-data classification, minimum attribute and access scope decision
Why required: Person and health-adjacent data must be minimised by decision, not assumption.
Minimum acceptable: Privacy decision per class.
Preferred: DPIA-equivalent record.
Alternative acceptable: Conditional approval with narrowed attributes.
Not accepted: Design minimum-attribute proposal alone.
Evidence ref: — none
Requested: Confirmation that only a binary fitness flag may be consumed
Why required: Prevents duplication of medical records.
Minimum acceptable: Health owner confirmation of exposed attribute.
Preferred: Signed data-exposure statement.
Alternative acceptable: Documented restriction with custodian.
Not accepted: Assumed minimum exposure.
Evidence ref: — none
Requested: Formal election of PATH_A or PATH_B for critical control participation
Why required: Path ambiguity propagates unresolved scope into BC-08 and Phase 7.
Minimum acceptable: Attributable path election.
Preferred: Path A with source owner authorization.
Alternative acceptable: Path B with DecisionAuthority, Reason, PilotEvidenceLost, ResidualRisk, Phase7Impact.
Not accepted: Continuation of SIMULATED_ONLY as an implicit decision.
Evidence ref: — none
Requested: Source participation authorization for critical control verification records (Path A)
Why required: Path A is unachievable without the owning system.
Minimum acceptable: Owner participation confirmation.
Preferred: Governed read of verification records.
Alternative acceptable: Controlled snapshot of verification status.
Not accepted: Inferred integration.
Evidence ref: — none
Requested: Named L1 / L2 / L3 owners, operating window and escalation path
Why required: Design-team dependency invalidates support sustainability.
Minimum acceptable: Staffing record with operating window.
Preferred: Signed support model with named staff.
Alternative acceptable: Interim model with explicit expiry and escalation.
Not accepted: Design team named as L2/L3.
Evidence ref: — none
Requested: Execution of operational drills S-01 → S-06 by the real support function
Why required: Support capability must be demonstrated, not described.
Minimum acceptable: Drill records with actor, outcome and time.
Preferred: Six executed drills with independent observation.
Alternative acceptable: Partial drill set with documented gap and plan.
Not accepted: Simulation campaign drill results.
Evidence ref: — none
Requested: Nomination of a real CV-07 workfront with owner, window and work demand
Why required: BC-08 has no real workfront; all ten dimensions are design-only.
Minimum acceptable: Nomination record with named field owner and window.
Preferred: Approved workfront nomination with SIMOPS context.
Alternative acceptable: Provisional nomination with confirmation milestones.
Not accepted: Illustrative or synthetic workfront.
Evidence ref: — none
Requested: Confirmation of crew, equipment, materials and field prerequisites for the nominated workfront
Why required: Dimension-level confirmation is required; no aggregate assertion accepted.
Minimum acceptable: Per-dimension attributable confirmation.
Preferred: Function-signed readiness confirmation.
Alternative acceptable: Conditional confirmation with named residual gap.
Not accepted: Blanket statement of readiness.
Evidence ref: — none
Requested: SIMOPS context and field prerequisite confirmation for the nominated workfront
Why required: SIMOPS cumulative rules require a real concurrent-work picture.
Minimum acceptable: ES&H confirmation of concurrent work context.
Preferred: Signed SIMOPS assessment for the window.
Alternative acceptable: Interim assessment with review trigger.
Not accepted: Prototype SIMOPS scenario.
Evidence ref: — none
Requested: Source and owner confirmation for the 12 frozen BEFORE metrics
Why required: Collection cannot start without a confirmed source and owner per metric.
Minimum acceptable: Per-metric source and owner confirmation.
Preferred: Signed measurement plan.
Alternative acceptable: Partial confirmation with metric-level status.
Not accepted: Assumed data availability.
Evidence ref: — none
Requested: Formal authorization to start prospective BEFORE collection
Why required: BEFORE is time-irreversible and must precede any Pilot exposure.
Minimum acceptable: Attributable collection-start authorization.
Preferred: Signed start record with date and scope.
Alternative acceptable: Staged start per metric with recorded dates.
Not accepted: Retrospective reconstruction of any kind.
Evidence ref: — none
Requested: Non-intrusive observation access that does not alter current ways of working
Why required: Collection must not itself contaminate the baseline.
Minimum acceptable: Access confirmation with non-intrusive conditions.
Preferred: Documented observation protocol.
Alternative acceptable: Restricted observation windows.
Not accepted: Any activity classified PILOT_INTERVENTION.
Evidence ref: — none
D · Evidence Quality Register & Taxonomy
EvidenceQuality is assigned per blocker on whether received evidence demonstrates the acceptance criterion. It is never computed from a document count, never averaged, never compensated across criteria.
DESIGN_EVIDENCE
Meaning: Architecture, rule, model or specification artefact produced by the design team.
Closure power: NONE — cannot close a blocker.
SIMULATION_EVIDENCE
Meaning: Deterministic scenario result from the accepted Simulation Baseline.
Closure power: NONE — may support design confidence, never raises EvidenceQuality.
SUPPORTING_EVIDENCE
Meaning: Real organizational artefact that contextualises but does not itself demonstrate the acceptance criterion.
Closure power: May move EvidenceQuality NONE → PARTIAL only.
OPERATIONAL_CLOSURE_EVIDENCE
Meaning: Attributable artefact from the competent authority demonstrating the acceptance criterion in the real organization.
Closure power: The only class that may directly support blocker closure.
CONTRADICTORY_EVIDENCE
Meaning: Real evidence conflicting with an accepted baseline assumption.
Closure power: Blocks closure; routes to the Contradiction Register.
NOT_APPLICABLE_EVIDENCE
Meaning: Artefact outside the acceptance criterion scope.
Closure power: NONE — recorded, never silently discarded.
Workflow: OPEN → EVIDENCE_REQUESTED → EVIDENCE_RECEIVED → EVIDENCE_UNDER_ASSESSMENT → SUFFICIENT_FOR_RETEST → TARGETED_RETEST → CLOSED / CLOSED_WITH_CONTROL / RESCOPED_BY_COMPETENT_AUTHORITY / REMAINS_OPEN
Forbidden transition: EVIDENCE_RECEIVED → CLOSED is prohibited. Targeted retest is mandatory.
CLOSED_WITH_CONTROL: CLOSED_WITH_CONTROL requires Control, Owner, Validity, ResidualRisk, Escalation and EvidenceRef. It may never be used to bypass missing evidence.
| Blocker | Quality | Received | Validity | Workflow state |
|---|---|---|---|---|
| BC-01 | NONE | NONE | N/A — no evidence in hand | EVIDENCE_REQUESTED |
| BC-02 | NONE | NONE | N/A — no evidence in hand | EVIDENCE_REQUESTED |
| BC-03 | NONE | NONE | N/A — no evidence in hand | EVIDENCE_REQUESTED |
| BC-04 | NONE | NONE | N/A — no evidence in hand | EVIDENCE_REQUESTED |
| BC-05 | NONE | NONE | N/A — no evidence in hand | EVIDENCE_REQUESTED |
| BC-06 | NONE | NONE | N/A — no evidence in hand | EVIDENCE_REQUESTED |
| BC-07 | NONE | NONE | N/A — no evidence in hand | EVIDENCE_REQUESTED |
| BC-08 | NONE | NONE | N/A — no evidence in hand | EVIDENCE_REQUESTED |
| BC-09 | NONE | NONE | N/A — no evidence in hand | EVIDENCE_REQUESTED |
ACCEPTED
Demonstrates the acceptance criterion in full.
ACCEPTED_WITH_LIMITATION
Demonstrates the criterion within a recorded boundary; limitation carried as residual.
INSUFFICIENT
Relevant but does not demonstrate the criterion.
OUTDATED
Demonstrated once but no longer current against validity rules.
OUT_OF_SCOPE
Does not address the acceptance criterion.
CONTRADICTORY
Conflicts with an accepted baseline assumption; routed to the Contradiction Register.
Every evidence item receives an explicit disposition with a recorded reason. Evidence is never silently discarded.
E · Cross-Blocker Dependency Map
BC-01 ────────────► BC-06 ◄──── ES&H path election (ESC-03)
│ (participation) │
│ ▼
BC-02 ──► BC-03 BC-08 ──► BC-09 ──► Phase 6B (NOT_AUTHORIZED)
│ ▲ ▲
└──► BC-04 ──► BC-07 ──┘ BC-05 ───┘ (classification of measures)Lifecycle transition authority is only technically enforceable once identity and authority resolution are real.
Path A critical control participation requires governed source participation.
A Path B rescope removes the critical control source from the required participation set.
Stewardship authority must be enforceable where authority enforcement applies.
Support model cannot be staffed or bounded without governance ownership.
Field readiness scope depends on whether critical controls participate in the Pilot.
The measured population must correspond to the real workfront — but collection must start before exposure.
No Pilot execution may commence before the prospective BEFORE baseline is underway.
Measurement records must sit inside an approved classification and retention basis.
G · Retest Eligibility Engine & Targeted Retest Queue
Queue empty — no blocker has reached SUFFICIENT_FOR_RETEST. Retests are targeted at the specific acceptance criterion; complete Mesa assessments are never rerun.
Why: NOT_ELIGIBLE — EvidenceQuality = NONE. Eligibility requires ≥ SUFFICIENT_FOR_RETEST.
Evidence refs: — none received
Acceptance criteria to test: Signed or attributable owner confirmation per source/object stating participation mode, authority boundaries and failure behaviour. Governed snapshot or controlled manual federation is acceptable where sufficient for CV-07 — live API is not demanded and never inferred.
Residual dependencies: External system owners outside the design team; enterprise change windows.
Why: NOT_ELIGIBLE — EvidenceQuality = NONE. Eligibility requires ≥ SUFFICIENT_FOR_RETEST.
Evidence refs: — none received
Acceptance criteria to test: IAM owner confirmation of provider, authentication, role resolution, delegation and revocation, plus a provisioned Pilot identity set. Prototype identity behaviour is explicitly not closure evidence.
Residual dependencies: Enterprise IAM programme and cyber approval cycle.
Why: NOT_ELIGIBLE — EvidenceQuality = NONE. Eligibility requires ≥ SUFFICIENT_FOR_RETEST.
Evidence refs: — none received
Acceptance criteria to test: Competent-authority decision artefact per object class accepting lifecycle ownership and transition authority. May close faster than BC-01/BC-02 because it is a decision, not an integration.
Residual dependencies: BC-02 for technical enforcement of transition authority.
Why: NOT_ELIGIBLE — EvidenceQuality = NONE. Eligibility requires ≥ SUFFICIENT_FOR_RETEST.
Evidence refs: — none received
Acceptance criteria to test: Attributable appointment records with authorization, named delegate, allocated capacity and SoD confirmation. A name on an org chart is SUPPORTING_EVIDENCE only.
Residual dependencies: Organizational resourcing decisions outside the programme.
Why: NOT_ELIGIBLE — EvidenceQuality = NONE. Eligibility requires ≥ SUFFICIENT_FOR_RETEST.
Evidence refs: — none received
Acceptance criteria to test: Competent decision artefact per material record class covering classification, retention basis, minimum attribute and custodian. No duplication of HR/Health source records is permitted.
Residual dependencies: Privacy and legal review cycle.
Why: NOT_ELIGIBLE — EvidenceQuality = NONE. Eligibility requires ≥ SUFFICIENT_FOR_RETEST.
Evidence refs: — none received
Acceptance criteria to test: One explicit, attributable path election. Path B must never be chosen merely to facilitate closure.
Residual dependencies: Critical control system owner authorization (Path A) or executive rescope (Path B).
Why: NOT_ELIGIBLE — EvidenceQuality = NONE. Eligibility requires ≥ SUFFICIENT_FOR_RETEST.
Evidence refs: — none received
Acceptance criteria to test: Staffed support model plus real drill records for S-01 (user/access), S-02 (mapping conflict), S-03 (rule question), S-04 (interface failure), S-05 (authority issue), S-06 (evidence reconstruction). Simulation drills are not operational drill evidence.
Residual dependencies: Support resourcing and service-window commitment.
Why: NOT_ELIGIBLE — EvidenceQuality = NONE. Eligibility requires ≥ SUFFICIENT_FOR_RETEST.
Evidence refs: — none received
Acceptance criteria to test: Attributable confirmation per dimension from the accountable field function for a real, nominated CV-07 workfront.
Residual dependencies: BC-06 path election where Critical Controls apply; construction sequencing.
Why: NOT_ELIGIBLE — EvidenceQuality = NONE. Eligibility requires ≥ SUFFICIENT_FOR_RETEST.
Evidence refs: — none received
Acceptance criteria to test: Attributable collection-start record plus a sufficient prospective data window per metric. Inference of collection is prohibited.
Residual dependencies: Field data availability; strict precedence over any Pilot exposure.
Targeted retest queue: EMPTY — 0 retests raised, 0 executed.
H · Contradiction Register
No contradiction recorded — no real external evidence has been received. Architecture is never automatically reopened: every contradiction is first classified EvidenceDefect / LocalException / ConfigurationChange / ArchitectureImpact.
Entries: 0 — register empty.
I · Escalation Register
Escalation owner: Project Director / Accountable Executive
Decision required: Appoint, authorize and resource stewardship and operational support roles.
Blocking impact: BC-03, BC-04, BC-07 and every location-governed decision (G-01 fail-closed).
Evidence: — none
Escalation owner: Enterprise Architecture + IAM / Cyber leadership
Decision required: Authorize source participation and enterprise identity provisioning for the Pilot.
Blocking impact: BC-01, BC-02 and downstream BC-03 enforcement. Longest external lead time.
Evidence: — none
Escalation owner: ES&H Accountable Executive
Decision required: Elect PATH_A_REAL_PARTICIPATION or PATH_B_FORMAL_RESCOPE.
Blocking impact: BC-06 and BC-08 scope; Phase 7 evidence claims.
Evidence: — none
Escalation owner: Business Product Owner + Project Controls
Decision required: Authorize and start prospective BEFORE collection before any Pilot exposure.
Blocking impact: BC-09 and Phase 6B entry. Time-irreversible.
Evidence: — none
J · Blocker Execution Heatmap
CLOSED → positive · OPEN / EVIDENCE_REQUIRED → amber · DEPENDENCY_HELD → controlled neutral / amber · CONTRADICTED / FAIL / PROHIBITED → red · Missing evidence is not failure.
| BC | Mesa | Authority | Evidence | Dependency | Retest | Closure | Owner | Next action |
|---|---|---|---|---|---|---|---|---|
| BC-01 | MESA 1 | Enterprise Architecture + each named System Owner | NONE | External system owners outside the design team; enterprise change windows. | NOT_ELIGIBLE | REMAINS_OPEN | Enterprise Architecture | Issue and chase per-source owner confirmation requests (longest external lead time on the board). |
| BC-02 | MESA 1 | IAM / Cyber | NONE | Enterprise IAM programme and cyber approval cycle. | NOT_ELIGIBLE | REMAINS_OPEN | IAM / Cyber | Request IAM provider/role-resolution confirmation and Pilot identity provisioning plan. |
| BC-03 | MESA 1 | Business Product Owner + per-object Lifecycle Owners | NONE | BC-02 for technical enforcement of transition authority. | NOT_ELIGIBLE | REMAINS_OPEN | Business Product Owner | Convene lifecycle owner acceptance session; produce per-object decision artefacts. |
| BC-04 | MESA 2 | Project Director / Accountable Executive | NONE | Organizational resourcing decisions outside the programme. | NOT_ELIGIBLE | REMAINS_OPEN | Change / Adoption | Escalate stewardship appointment decision with capacity commitment. |
| BC-05 | MESA 1 | Records Management + Privacy + Compliance | NONE | Privacy and legal review cycle. | NOT_ELIGIBLE | REMAINS_OPEN | Records Management | Table the CA-04 material item list for Records/Privacy decision — decision artefact, not integration. |
| BC-06 | MESA 1 | ES&H Accountable Executive + Critical Control / Forwood Owner | NONE | Critical control system owner authorization (Path A) or executive rescope (Path B). | NOT_ELIGIBLE | REMAINS_OPEN | Critical Control / Forwood Owner | Force the path election decision — it governs downstream field scope (BC-08). |
| BC-07 | MESA 2 | Operational Support Owner | NONE | Support resourcing and service-window commitment. | NOT_ELIGIBLE | REMAINS_OPEN | Operational Support | Secure support staffing decision, then schedule S-01 → S-06 as real drills. |
| BC-08 | MESA 3 | Construction Manager + Field Supervision | NONE | BC-06 path election where Critical Controls apply; construction sequencing. | NOT_ELIGIBLE | REMAINS_OPEN | Construction | Nominate a real CV-07 workfront and start dimension-by-dimension confirmation (0/10 today). |
| BC-09 | MESA 3 | Project Controls + Business Product Owner | NONE | Field data availability; strict precedence over any Pilot exposure. | NOT_ELIGIBLE | REMAINS_OPEN | P6 / Project Controls | Confirm metric sources and owners and start prospective collection — irreversibility makes this time-critical. |
K · Top 5 Next Actions
Ranked by critical path, lead time, dependency, evidence and authority availability, and BC-09 irreversibility — never by blocker number.
Blockers: BC-01 (→ BC-06, BC-03)
Basis: Longest external lead time on the board; every federated decision depends on declared participation.
Competent authority: Enterprise Architecture + System Owners
Blockers: BC-02 (→ BC-03, BC-04)
Basis: External lead time plus downstream enforceability of all lifecycle and stewardship authority.
Competent authority: IAM / Cyber
Blockers: BC-06 (→ BC-08)
Basis: Path ambiguity propagates unresolved scope downstream; the decision itself has short lead time.
Competent authority: ES&H Accountable Executive
Blockers: BC-09 (→ Phase 6B)
Basis: Time-irreversible: the BEFORE baseline cannot be reconstructed once behaviour changes.
Competent authority: Project Controls + Business Product Owner
Blockers: BC-03, BC-05
Basis: Decision artefacts, not integrations — they can close materially faster than BC-01/BC-02.
Competent authority: Business Product Owner · Records Management · Privacy
L · Phase 6A Integrated Revalidation Eligibility
This Board never outputs GO. GO belongs exclusively to Phase 6A Integrated Revalidation.
0 closed, 0 CWC, 0 rescoped, 9 REMAINS_OPEN.
Contradiction register empty — no external evidence received.
9 dependency edges unresolved; BC-02→BC-03, BC-06→BC-08 and BC-08→BC-09 all unsatisfied.
BC09Protection ACTIVE, PilotExposure PROHIBITED, no contamination event.
Phase 5 / Phase 6 baselines consumed unchanged; simulation baseline frozen.
Zero OperationalClosureEvidence items received; 28 requests awaiting owner.
OUTPUT: NOT_ELIGIBLE
M · Evidence Change History (append-only)
Append-only. Prior evidence is never overwritten. Incremental updates touch only the affected blocker and its dependencies — Mesas are never rerun.
Previous state: IEW — 9 blockers REMAINS_OPEN, EvidenceQuality NONE
New state: OEB established — Operational Evidence Execution Board Rev.1 instantiated
Trigger: Phase 6A Operational Evidence Execution Board authorization
Evidence ref: OEB-BASELINE-001
Actor / authority: Programme governance
Previous state: Simulation campaign SIMULATION_BASELINE_ACCEPTED_WITH_FINDINGS
New state: SIMULATION_BASELINE_ACCEPTED consumed as design assurance only
Trigger: Simulation findings closure (F-SIM-04, F-SIM-05)
Evidence ref: SIMCLOSURE-001
Actor / authority: Design authority
Previous state: Evidence requests: 24 (IEW)
New state: Evidence requests: 28 issued, all AWAITING_OWNER, 0 received
Trigger: Owner-based request register expansion under the Board
Evidence ref: OEB-ER-REGISTER-001
Actor / authority: Evidence acquisition lead
N · Strict Program Boundaries
- No fabricated evidence.
- No simulated organizational approvals.
- No invented system-owner confirmation.
- No inferred APIs.
- No invented IAM.
- No invented field readiness.
- No Pilot exposure.
- BC-09 never closed without prospective measurement.
- Phase 6B not initiated.
- Phase 7 not initiated.
- Architecture not changed.
- Frozen simulation baseline not modified.
- SimulationEvidence never converted into OperationalClosureEvidence.
The Board is not designed to show progress. It is designed to show whether each blocker has become technically, organizationally and evidentially defendable enough to be retested and closed. The next gate remains Phase 6A Integrated Revalidation and shall not be entered until this Board reports ELIGIBLE_FOR_INTEGRATED_REVALIDATION.