PizarraContexto de trabajoDocumentos y registrosControles críticosRegistrosPreparaciónCondiciones bloqueantesAutorización
Aseguramiento / Técnico

Phase 6A — Operational Evidence Execution Board

BC-01 → BC-09 · Evidence Acquisition, Targeted Retest & Closure Control Room

Single integrated operational control room governing the conversion of DesignEvidence / SimulationEvidence into OperationalClosureEvidence sufficient for targeted retest and, ultimately, Phase 6A Integrated Revalidation.

Not a status report, not a progress instrument, not a Pilot authorization.

simulationBaseline: ACCEPTEDcorrectableSimulationDefectsOpen: 0expectedControlledOpenDependencies: 4blockers: BC-01 → BC-09 = OPENphase6A: HOLDphase6ARevalidationEligibility: NOT_ELIGIBLEphase6B: NOT_AUTHORIZEDphase7: NO_GObc09Protection: ACTIVEpilotExposure: PROHIBITED

DESIGN / SIMULATION ASSURANCE COMPLETE

NOT OPERATIONAL CLOSURE EVIDENCE

95 scenarios PASS · 14/14 frozen invariants PASS · 0 correctable defects open · 4 controlled open dependencies. Simulation may raise design confidence; it may never raise EvidenceQuality.

F · BC-09 Protection Panel — permanently visible

BC09 Protection
ACTIVE
Pilot Exposure
PROHIBITED
Prospective Collection
NOT_STARTED
Contamination Event
NONE RECORDED

Allowed pre-baseline activities:

  • Non-intrusive metric source and owner confirmation
  • Collection method definition and instrument preparation
  • Data access authorization requests
  • Observation that does not alter current field behaviour

Prohibited:

  • Any Pilot exposure to field crews or supervision
  • Training that changes current ways of working
  • Trial use of readiness outputs in live shift decisions
  • Retrospective reconstruction of a BEFORE baseline

Any proposed action that may alter current field behaviour is classified PILOT_INTERVENTION and blocked until BC-09 collection is formally underway.

A · Executive Phase 6A Evidence Dashboard

Phase 6A
HOLD
Total Blockers
9
Closed
0
Closed with Control
0
Rescoped
0
Open
9
Evidence NONE
9
Evidence PARTIAL
0
Eligible for Retest
0
Retests Completed
0
Active Escalations
4
Material Contradictions
0
BC09 Protection
ACTIVE
Pilot Exposure
PROHIBITED

NOT PROVIDED — no aggregate percentage may be used to authorize Pilot. Non-compensable conditions are counted, never averaged.

Board answers at any time:

  • What blocker remains open?
  • Why is it open?
  • What exact evidence is missing?
  • Who is competent to provide or approve that evidence?
  • Has evidence been requested?
  • Has it been received?
  • Is it current and valid?
  • Is it sufficient for targeted retest?
  • Has targeted retest been executed?
  • What residual dependency remains?
  • What prevents Phase 6A Integrated Revalidation?

New issue classification before any new blocker: SubCondition · Finding · Dependency · EvidenceGap · Contradiction

Rule: No new blocker may be created for administrative convenience. Every new issue is first classified; escalation to a tenth blocker requires competent authority and a recorded reason.

B · BC-01 → BC-09 Master Blocker Register

BC-01Enterprise Interfaces / System ParticipationMESA 1REMAINS_OPENEVIDENCE_REQUESTEDEVIDENCE NONENOT_ELIGIBLE

Why open: Zero owner confirmations received; participation is currently design intent only.

Design condition: Federated participation model defined per source and object class (Option C, ADR-13/CA-01); failure behaviour fail-closed.

Operational condition: No system owner has authorized real Pilot participation for any source; participation mode per source remains undeclared by the accountable owner.

Competent authority: Enterprise Architecture + each named System Owner

Evidence owner: Enterprise Architecture

Supporting owners: IT / IM · Q4 System Owner · Aconex / IM Owner · P6 / Project Controls · Smart Completions

Minimum acceptance evidence: Signed or attributable owner confirmation per source/object stating participation mode, authority boundaries and failure behaviour. Governed snapshot or controlled manual federation is acceptable where sufficient for CV-07 — live API is not demanded and never inferred.

Evidence received: NONE · Ref — none received · Date — · Effective — · SourceVersion —

Validity: N/A — no evidence in hand

External dependency: External system owners outside the design team; enterprise change windows. (EVIDENCE_DEPENDENCY)

Escalation: ESC-02

Retest: — not raised (queue empty) · Result NOT_EXECUTED

Residual risk: Pilot could be scoped against assumed participation that the owning organization does not authorize.

Closure disposition: REMAINS_OPEN

Next action: Issue and chase per-source owner confirmation requests (longest external lead time on the board).

Evidence required (4)
  • Per source/object owner confirmation of participation mode (LIVE_READ / CONTROLLED_TRANSACTION / CONTROLLED_SNAPSHOT / CONTROLLED_MANUAL_FEDERATION / SIMULATED_ONLY / NOT_REQUIRED)
  • Interface mechanism and authentication statement as it will actually operate in the Pilot
  • Read / write / snapshot authority declaration per object class
  • Version behaviour and source-unavailable failure behaviour confirmation
BC-02IAM / Identity / AuthorityMESA 1REMAINS_OPENEVIDENCE_REQUESTEDEVIDENCE NONENOT_ELIGIBLE

Why open: No enterprise identity artefact exists; all authority behaviour demonstrated so far is prototype-internal.

Design condition: Attribute-based authority model frozen: Role × Area × Activity × Shift × RiskLevel × RegisterType × DelegationScope; access ≠ authority; fail-closed on unresolved authority.

Operational condition: No enterprise identity provider integration confirmed, no Pilot identities provisioned, no enforceable role resolution outside the prototype.

Competent authority: IAM / Cyber

Evidence owner: IAM / Cyber

Supporting owners: IT / IM · HR / RRLL · Enterprise Architecture

Minimum acceptance evidence: IAM owner confirmation of provider, authentication, role resolution, delegation and revocation, plus a provisioned Pilot identity set. Prototype identity behaviour is explicitly not closure evidence.

Evidence received: NONE · Ref — none received · Date — · Effective — · SourceVersion —

Validity: N/A — no evidence in hand

External dependency: Enterprise IAM programme and cyber approval cycle. (EVIDENCE_DEPENDENCY)

Escalation: ESC-02

Retest: — not raised (queue empty) · Result NOT_EXECUTED

Residual risk: Authority enforcement would fall back to application access — the exact failure the design forbids.

Closure disposition: REMAINS_OPEN

Next action: Request IAM provider/role-resolution confirmation and Pilot identity provisioning plan.

Evidence required (4)
  • Identity provider and authentication method confirmation for Pilot users
  • Role resolution source and mapping to authority scopes (area/activity/shift/risk)
  • Delegation and revocation behaviour as enforced by the enterprise, not the prototype
  • IAM-01 → IAM-06 retest population definition with real identities
BC-03Lifecycle AuthorityMESA 1REMAINS_OPENEVIDENCE_REQUESTEDEVIDENCE NONENOT_ELIGIBLE

Why open: Lifecycle is defined by design, accepted by nobody operationally.

Design condition: Object lifecycles, allowed states and transitions defined; invalid transition and authority-unavailable behaviour fail-closed.

Operational condition: GovernanceLifecycleDefined = YES (design). TechnicallyEnforceable = NOT_DEMONSTRATED — no named lifecycle owner has accepted transition authority for the Pilot.

Competent authority: Business Product Owner + per-object Lifecycle Owners

Evidence owner: Business Product Owner

Supporting owners: Q4 System Owner · ES&H · Construction · Enterprise Architecture

Minimum acceptance evidence: Competent-authority decision artefact per object class accepting lifecycle ownership and transition authority. May close faster than BC-01/BC-02 because it is a decision, not an integration.

Evidence received: NONE · Ref — none received · Date — · Effective — · SourceVersion —

Validity: N/A — no evidence in hand

External dependency: BC-02 for technical enforcement of transition authority. (EXECUTION_DEPENDENCY)

Escalation: ESC-01

Retest: — not raised (queue empty) · Result NOT_EXECUTED

Residual risk: Lifecycle transitions executed without attributable authority.

Closure disposition: REMAINS_OPEN

Next action: Convene lifecycle owner acceptance session; produce per-object decision artefacts.

Evidence required (3)
  • Named lifecycle owner acceptance per object with allowed transitions and transition authority
  • Named delegate and authority-unavailable behaviour acceptance
  • Decision artefact format accepted by the accountable function
BC-04Stewardship / Governance / ChangeMESA 2REMAINS_OPENEVIDENCE_REQUESTEDEVIDENCE NONENOT_ELIGIBLE

Why open: Stewardship exists as a design role set with no operational appointments.

Design condition: GOVERNANCE_DESIGN_STRUCTURALLY_SOUND — roles, SoD and escalation paths defined (ADR-14 stewardship).

Operational condition: No real person assigned, authorized and available for the governing stewardship roles; capacity and SoD unverified.

Competent authority: Project Director / Accountable Executive

Evidence owner: Change / Adoption

Supporting owners: HR / RRLL · Compliance · Enterprise Architecture · Operational Support

Minimum acceptance evidence: Attributable appointment records with authorization, named delegate, allocated capacity and SoD confirmation. A name on an org chart is SUPPORTING_EVIDENCE only.

Evidence received: NONE · Ref — none received · Date — · Effective — · SourceVersion —

Validity: N/A — no evidence in hand

External dependency: Organizational resourcing decisions outside the programme. (EVIDENCE_DEPENDENCY)

Escalation: ESC-01

Retest: — not raised (queue empty) · Result NOT_EXECUTED

Residual risk: Vacant stewardship forces fail-closed HOLD in live operation (scenario G-01).

Closure disposition: REMAINS_OPEN

Next action: Escalate stewardship appointment decision with capacity commitment.

Evidence required (2)
  • Real named assignment for BusinessProductOwner, LocationSteward, FederationMappingSteward, RuleOwner, IntegrationOwner, OperationalSupportOwner, ChangeAdoptionOwner
  • For each: Assigned / Authorized / Available / Delegate / Escalation / Capacity / SoD evidence
BC-05Classification / Retention / Data MinimisationMESA 1REMAINS_OPENEVIDENCE_REQUESTEDEVIDENCE NONENOT_ELIGIBLE

Why open: Classification and retention are configured by design; no competent decision exists.

Design condition: CA-04 record classes modelled; RC-RET-01 v1.1 per-evidence-class retention; unclassified → RETAIN_AND_HOLD (fail-closed); minimum-attribute principle applied to person and health data.

Operational condition: No Records Management / Privacy / Compliance decision on classification, retention basis or access scope for the Pilot record classes.

Competent authority: Records Management + Privacy + Compliance

Evidence owner: Records Management

Supporting owners: Privacy · Compliance · Health · HR / RRLL

Minimum acceptance evidence: Competent decision artefact per material record class covering classification, retention basis, minimum attribute and custodian. No duplication of HR/Health source records is permitted.

Evidence received: NONE · Ref — none received · Date — · Effective — · SourceVersion —

Validity: N/A — no evidence in hand

External dependency: Privacy and legal review cycle. (EVIDENCE_DEPENDENCY)

Escalation: ESC-01

Retest: — not raised (queue empty) · Result NOT_EXECUTED

Residual risk: Evidence retained or minimised on design assumption rather than legal basis.

Closure disposition: REMAINS_OPEN

Next action: Table the CA-04 material item list for Records/Privacy decision — decision artefact, not integration.

Evidence required (3)
  • Per material CA-04 item: RecordClass, DataClassification, PersonalData flag, DecisionFactRequired, MinimumAttributeRequired
  • RetentionBasis and RetentionPeriodBasis decision (legal/contractual)
  • AccessScope and Custodian designation
BC-06Critical Control ParticipationMESA 1REMAINS_OPENEVIDENCE_REQUESTEDEVIDENCE NONENOT_ELIGIBLE

Why open: Path decision not taken; simulated critical control cannot substitute for either path.

Design condition: Critical Control model defined (Required/Available/Verified/Effective/Failed/Recovered), non-compensable; currently SIMULATED in the prototype.

Operational condition: No competent authority has elected PATH_A_REAL_PARTICIPATION or PATH_B_FORMAL_RESCOPE. Until formally elected, BC-06 = OPEN.

Competent authority: ES&H Accountable Executive + Critical Control / Forwood Owner

Evidence owner: Critical Control / Forwood Owner

Supporting owners: ES&H · Enterprise Architecture · Construction

Minimum acceptance evidence: One explicit, attributable path election. Path B must never be chosen merely to facilitate closure.

Evidence received: NONE · Ref — none received · Date — · Effective — · SourceVersion —

Validity: N/A — no evidence in hand

External dependency: Critical control system owner authorization (Path A) or executive rescope (Path B). (CLOSURE_DEPENDENCY)

Escalation: ESC-03

Retest: — not raised (queue empty) · Result NOT_EXECUTED

Residual risk: Path ambiguity propagates unresolved scope into BC-08 and Phase 7 claims.

Closure disposition: REMAINS_OPEN

Next action: Force the path election decision — it governs downstream field scope (BC-08).

Evidence required (2)
  • PATH A: governed source participation confirmation for critical control status and verification records
  • PATH B: formal rescope decision recording DecisionAuthority, Reason, PilotEvidenceLost, ResidualRisk, Phase7Impact
BC-07Operational Support / Design-Team IndependenceMESA 2REMAINS_OPENEVIDENCE_REQUESTEDEVIDENCE NONENOT_ELIGIBLE

Why open: No staffed L1/L2/L3 and zero operational drills executed.

Design condition: L1/L2/L3 support model, issue types, operating window, escalation and authority boundary defined.

Operational condition: No staffed support function; the design team remains the de-facto L2/L3 — a hidden dependency that invalidates sustainability.

Competent authority: Operational Support Owner

Evidence owner: Operational Support

Supporting owners: IT / IM · Change / Adoption · Enterprise Architecture

Minimum acceptance evidence: Staffed support model plus real drill records for S-01 (user/access), S-02 (mapping conflict), S-03 (rule question), S-04 (interface failure), S-05 (authority issue), S-06 (evidence reconstruction). Simulation drills are not operational drill evidence.

Evidence received: NONE · Ref — none received · Date — · Effective — · SourceVersion —

Validity: N/A — no evidence in hand

External dependency: Support resourcing and service-window commitment. (EVIDENCE_DEPENDENCY)

Escalation: ESC-01

Retest: — not raised (queue empty) · Result NOT_EXECUTED

Residual risk: Pilot operable only while the design team is present — non-sustainable.

Closure disposition: REMAINS_OPEN

Next action: Secure support staffing decision, then schedule S-01 → S-06 as real drills.

Evidence required (3)
  • Named L1 / L2 / L3 owners with operating window and escalation path
  • Authority boundary statement and explicit design-team dependency declaration
  • Operational drills S-01 → S-06 executed by the real support function
BC-08Field Execution PrerequisitesMESA 3REMAINS_OPENEVIDENCE_REQUESTEDEVIDENCE NONENOT_ELIGIBLE

Why open: No real workfront nominated; all ten dimensions carry DesignEvidence only.

Design condition: FIELD_AND_MEASUREMENT_DESIGN_STRUCTURALLY_SOUND — CV-07 field execution model complete.

Operational condition: 0/10 closure dimensions demonstrated with OperationalClosureEvidence. Missing evidence is OPEN, not FAILED.

Competent authority: Construction Manager + Field Supervision

Evidence owner: Construction

Supporting owners: BEO · Materials · Tools · Logistics · Environment · ES&H · Field Supervision

Minimum acceptance evidence: Attributable confirmation per dimension from the accountable field function for a real, nominated CV-07 workfront.

Evidence received: NONE · Ref — none received · Date — · Effective — · SourceVersion —

Validity: N/A — no evidence in hand

External dependency: BC-06 path election where Critical Controls apply; construction sequencing. (EXECUTION_DEPENDENCY)

Escalation: ESC-01

Retest: — not raised (queue empty) · Result NOT_EXECUTED

Residual risk: Pilot executed against a notional rather than real workfront.

Closure disposition: REMAINS_OPEN

Next action: Nominate a real CV-07 workfront and start dimension-by-dimension confirmation (0/10 today).

Evidence required (10)
  • RealWorkfront
  • RealLocation
  • RealWorkDemand
  • Crew
  • Equipment
  • Materials
  • FieldOwner
  • ExecutionWindow
  • SIMOPSContext
  • FieldPrerequisites
BC-09Prospective BEFORE MeasurementMESA 3REMAINS_OPENEVIDENCE_REQUESTEDEVIDENCE NONENOT_ELIGIBLE

Why open: Collection has not started; metrics remain at DEFINED with no confirmed source or owner.

Design condition: 12 frozen metrics defined with source, owner and collection method.

Operational condition: ProspectiveCollection = NOT_STARTED. All 12 metrics at DEFINED. Time-irreversible: BEFORE can never be reconstructed retrospectively.

Competent authority: Project Controls + Business Product Owner

Evidence owner: P6 / Project Controls

Supporting owners: Construction · Field Supervision · Operational Support

Minimum acceptance evidence: Attributable collection-start record plus a sufficient prospective data window per metric. Inference of collection is prohibited.

Evidence received: NONE · Ref — none received · Date — · Effective — · SourceVersion —

Validity: N/A — no evidence in hand

External dependency: Field data availability; strict precedence over any Pilot exposure. (CLOSURE_DEPENDENCY)

Escalation: ESC-04

Retest: — not raised (queue empty) · Result NOT_EXECUTED

Residual risk: Irreversible loss of the BEFORE baseline if any Pilot exposure changes current ways of working before collection starts.

Closure disposition: REMAINS_OPEN

Next action: Confirm metric sources and owners and start prospective collection — irreversibility makes this time-critical.

Evidence required (3)
  • Per metric: SOURCE_CONFIRMED, OWNER_CONFIRMED, COLLECTION_READY, then COLLECTING
  • Formal prospective collection start record
  • Anti-contamination confirmation that no Pilot exposure preceded collection start

B.1 · BC-01 Execution Card — Source / Object Participation

Do not infer APIs. Absence of a declared mechanism is recorded as NOT_DECLARED, never as an assumed integration. Do not demand live integration where governed snapshot or controlled manual federation is sufficient for CV-07. SIMULATED_ONLY is a valid declared mode but yields no OperationalClosureEvidence for participation.

SourceObject classOwnerParticipationMechanism / AuthRead / Write / SnapshotVersionFailure behaviourOwner confirmation
Q4 / Entity DeskPermit, JHA, Isolation, Sanction to Test, Work AuthorizationQ4 System OwnerNOT_DECLARED — candidate CONTROLLED_TRANSACTION or CONTROLLED_SNAPSHOTNOT_DECLARED — no API inferred / NOT_DECLAREDQ4 (source of record) / Q4 only — readiness layer never writes / NOT_DECLAREDPinned revision required at decision timeSource unavailable → UNVERIFIABLE → fail-closed HOLDNONE RECEIVED
AconexControlled documents, procedures, PETSAconex / IM OwnerNOT_DECLARED — candidate CONTROLLED_SNAPSHOTNOT_DECLARED / NOT_DECLAREDAconex / Aconex only / NOT_DECLARED — snapshot validity window governance open (ADR-05)Revision pinning + change detection + materiality assessmentSnapshot stale → STALE marker; unverifiable → HOLDNONE RECEIVED
Primavera P6WBS, activity, schedule, look-aheadP6 / Project ControlsNOT_DECLARED — candidate LIVE_READ or CONTROLLED_SNAPSHOTNOT_DECLARED / NOT_DECLAREDP6 / P6 only / NOT_DECLAREDLook-ahead window versioned per shiftDegradable — forecast degrades, field execution unaffectedNONE RECEIVED
Forwood (Critical Control)Critical controls, fatal-risk taxonomy, verification recordsCritical Control / Forwood OwnerSIMULATED_ONLY (current) — Path A/B election pending (BC-06)NOT_DECLARED / NOT_DECLAREDForwood or equivalent / Forwood only / NOT_DECLAREDVerification validity window governs currencyBlocking — unverifiable critical control → HOLD, never compensatedNONE RECEIVED
People & TrainingRoster, competency, qualification validityHR / RRLL + TrainingNOT_DECLARED — candidate CONTROLLED_SNAPSHOTNOT_DECLARED / NOT_DECLAREDPeople & Training / People & Training only / NOT_DECLAREDValidity-date driven; expiry is a blocking conditionBlocking for competency-gated activitiesNONE RECEIVED
Health StatusOperational fitness flag only (minimum attribute)HealthNOT_DECLARED — minimum-exposure read candidateNOT_DECLARED / NOT_DECLAREDHealth / Health only — no medical data duplicated / NOT_PERMITTED pending BC-05 decisionFlag currency windowNot confirmed → fail-closed for affected person/activityNONE RECEIVED
Smart CompletionsSubsystem / completion statusSmart CompletionsNOT_DECLAREDNOT_DECLARED / NOT_DECLAREDSmart Completions / Smart Completions only / NOT_DECLAREDCompletion state versioned per subsystemDegradable for forecast; blocking for release gatingNONE RECEIVED
Canonical Location RegisterLocation, SIMOPS contextLocation Steward (ADR-14 Option C — vacant)CONTROLLED_MANUAL_FEDERATION candidate — steward unassignedFederated canonical register / NOT_DECLAREDReadiness layer (federated canonical) / Location Steward under governance / Steward-governedLocation version pinned into every decisionVacant steward → fail-closed HOLD (G-01)NONE RECEIVED — depends on BC-04

B.2 · BC-02 Execution Card — Identity & Enforceable Authority

Prototype identity tests do not count as closure evidence under any circumstance.

Identity provider: NOT_CONFIRMED

Pilot identity: NOT_PROVISIONED

Authentication: NOT_CONFIRMED

Role resolution: NOT_CONFIRMED — prototype role context is not an identity source

Authority scope: Model frozen (attribute-based); enterprise enforcement NOT_CONFIRMED

Area / Activity / Shift / Risk scope: NOT_CONFIRMED · NOT_CONFIRMED · NOT_CONFIRMED · NOT_CONFIRMED

Delegation: Model defined; enterprise delegation source NOT_CONFIRMED

Revocation behaviour: Design: immediate fail-closed. Enterprise behaviour NOT_CONFIRMED

IAM-01

Authenticated identity resolves to a single authoritative role set.

NOT_EXECUTABLE — no real identity

IAM-02

Authority scope enforced by area.

NOT_EXECUTABLE

IAM-03

Authority scope enforced by activity and risk level.

NOT_EXECUTABLE

IAM-04

Shift-bounded authority expires at shift end.

NOT_EXECUTABLE

IAM-05

Delegation grants scoped authority and no more.

NOT_EXECUTABLE

IAM-06

Revocation takes effect immediately and fails closed.

NOT_EXECUTABLE

B.3 · BC-03 Execution Card — Lifecycle Authority

GovernanceLifecycleDefined = YES is a design property. TechnicallyEnforceable = NOT_DEMONSTRATED and remains an execution dependency on BC-02.

Preventive Work Package

Lifecycle owner: NOT_ASSIGNED (candidate: Construction Owner)

Allowed states: DRAFT → REVIEW → APPROVED → RE-AUTHORIZED → SUPERSEDED / EXPIRED / CLOSED / CANCELLED

Transitions / authority: Defined · NOT_ACCEPTED

Delegate: NOT_NAMED

Invalid transition: Rejected and logged (design)

Authority unavailable: Fail-closed HOLD (design)

Decision artefact: NOT_PRODUCED

Readiness Decision (IRDE)

Lifecycle owner: NOT_ASSIGNED (candidate: Business Product Owner)

Allowed states: READY / CONDITIONAL / HOLD / STOP

Transitions / authority: Deterministic, non-compensable · NOT_ACCEPTED

Delegate: NOT_NAMED

Invalid transition: Impossible by construction; attempt logged

Authority unavailable: HOLD

Decision artefact: NOT_PRODUCED

Restriction

Lifecycle owner: NOT_ASSIGNED (ADR-03 controlled open)

Allowed states: OPEN → IN_PROGRESS → RESOLVED → VERIFIED → CLOSED

Transitions / authority: Defined; verification separate from resolution · NOT_ACCEPTED

Delegate: NOT_NAMED

Invalid transition: Rejected

Authority unavailable: Remains OPEN

Decision artefact: NOT_PRODUCED

Critical Control state

Lifecycle owner: NOT_ASSIGNED (BC-06 path pending)

Allowed states: Required / Available / Verified / Effective / Failed / Recovered

Transitions / authority: Verification-driven only · NOT_ACCEPTED

Delegate: NOT_NAMED

Invalid transition: Rejected; no self-declared effectiveness

Authority unavailable: Treated as not verified → HOLD/STOP

Decision artefact: NOT_PRODUCED

Evidence record

Lifecycle owner: NOT_ASSIGNED (candidate: Records Management, BC-05)

Allowed states: PENDING_VERIFICATION → VERIFIED / BROKEN_CHAIN

Transitions / authority: Append-only · NOT_ACCEPTED

Delegate: NOT_NAMED

Invalid transition: Mutation prohibited

Authority unavailable: Retain and hold

Decision artefact: NOT_PRODUCED

B.4 · BC-04 Execution Card — Stewardship & Governance

RoleAssignedAuthorizedAvailableDelegateEscalationCapacitySoDEvidence
BusinessProductOwnerNONONONOT_NAMEDESC-01NOT_ALLOCATEDNOT_VERIFIED— none
LocationStewardNONONONOT_NAMEDESC-01NOT_ALLOCATEDNOT_VERIFIED— none
FederationMappingStewardNONONONOT_NAMEDESC-01NOT_ALLOCATEDNOT_VERIFIED— none
RuleOwnerNONONONOT_NAMEDESC-01NOT_ALLOCATEDNOT_VERIFIED— none
IntegrationOwnerNONONONOT_NAMEDESC-01NOT_ALLOCATEDNOT_VERIFIED— none
OperationalSupportOwnerNONONONOT_NAMEDESC-01NOT_ALLOCATEDNOT_VERIFIED— none
ChangeAdoptionOwnerNONONONOT_NAMEDESC-01NOT_ALLOCATEDNOT_VERIFIED— none

B.5 · BC-05 Execution Card — Classification, Retention & Minimisation

No duplication of HR or Health source records is permitted.

DecisionPin (readiness decision provenance)

Classification / personal data: NOT_DECIDED · Indirect (actor identity)

Decision fact required: Decision inputs, versions, authority, timestamp

Minimum attribute: Actor reference + role, not personal profile

Retention basis / period: NOT_DECIDED — design proposes RETAIN_UNTIL_RECONSTRUCTION_OBLIGATION_ENDS · NOT_DECIDED

Access scope / custodian: NOT_DECIDED · NOT_ASSIGNED

Competent decision: Records Management + Privacy

Evidence: — none

SourcePayloadProjection (federated snapshot)

Classification / personal data: NOT_DECIDED · Possible (roster projections)

Decision fact required: Pinned revision + hash

Minimum attribute: Only attributes consumed by a rule

Retention basis / period: NOT_DECIDED — design proposes 90d · NOT_DECIDED

Access scope / custodian: NOT_DECIDED · NOT_ASSIGNED

Competent decision: Records Management + source owner

Evidence: — none

CompetencyProjection

Classification / personal data: NOT_DECIDED · YES

Decision fact required: Qualification validity state at decision time

Minimum attribute: Person ref, qualification, validity date — no training history

Retention basis / period: NOT_DECIDED · NOT_DECIDED

Access scope / custodian: NOT_DECIDED · NOT_ASSIGNED

Competent decision: Privacy + HR / RRLL

Evidence: — none

Operational fitness flag

Classification / personal data: NOT_DECIDED · YES — health-adjacent

Decision fact required: FIT_FOR_TASK / NOT_CONFIRMED only

Minimum attribute: Binary flag; no medical data, no diagnosis, no duplication of Health records

Retention basis / period: NOT_DECIDED · NOT_DECIDED

Access scope / custodian: NOT_DECIDED — narrowest scope expected · NOT_ASSIGNED

Competent decision: Health + Privacy + Compliance

Evidence: — none

AuthorityRecord (delegation / approval)

Classification / personal data: NOT_DECIDED · YES (identity + role)

Decision fact required: Who authorized what, under which scope

Minimum attribute: Identity ref, role, scope, validity

Retention basis / period: NOT_DECIDED — design proposes RETAIN_FULL_LIFECYCLE · NOT_DECIDED

Access scope / custodian: NOT_DECIDED · NOT_ASSIGNED

Competent decision: Compliance + Records Management

Evidence: — none

B.6 · BC-06 Execution Card — Critical Control Path

Until a path is formally elected, BC-06 = OPEN.

PATH_A_REAL_PARTICIPATION

Requires: Real governed source participation for critical control status and verification records (links BC-01).

Current state: NOT_ELECTED — no source owner authorization received.

Consequence if elected: BC-06 closure depends on BC-01 participation evidence for the critical control source.

PATH_B_FORMAL_RESCOPE

Requires: DecisionAuthority · Reason · PilotEvidenceLost · ResidualRisk · Phase7Impact — all mandatory.

Current state: NOT_ELECTED — no rescope decision recorded.

Consequence if elected: Pilot loses critical-control participation evidence; Phase 7 claims must be narrowed accordingly. Never elected merely to facilitate closure.

B.7 · BC-07 Execution Card — Operational Support & Design-Team Independence

Simulation drills executed in the campaign are SIMULATION_EVIDENCE and are not recorded as operational drill evidence.

L1 / L2 / L3: NOT_ASSIGNED · NOT_ASSIGNED · NOT_ASSIGNED

Issue types: User/access · mapping conflict · rule question · interface failure · authority issue · evidence reconstruction

Operating window: NOT_DEFINED OPERATIONALLY

Escalation: ESC-01

Authority boundary: Support may never resolve an authority decision — it routes to competent authority.

Design-team dependency: PRESENT — currently the de-facto L2/L3. Must be eliminated before Pilot.

S-01 · User / Access

NOT_EXECUTED

S-02 · Mapping Conflict

NOT_EXECUTED

S-03 · Rule Question

NOT_EXECUTED

S-04 · Interface Failure

NOT_EXECUTED

S-05 · Authority Issue

NOT_EXECUTED

S-06 · Evidence Reconstruction

NOT_EXECUTED

B.8 · BC-08 Execution Card — Field Execution Prerequisites

0/10 demonstrated with OperationalClosureEvidence. Missing evidence is OPEN — not FAILED.

RealWorkfront

Owner: Construction

OPENDesignEvidence only

RealLocation

Owner: Location Steward (vacant)

OPENDesignEvidence only

RealWorkDemand

Owner: Construction / Planning

OPENDesignEvidence only

Crew

Owner: Field Supervision

OPENDesignEvidence only

Equipment

Owner: BEO

OPENDesignEvidence only

Materials

Owner: Materials

OPENDesignEvidence only

FieldOwner

Owner: Construction

OPENDesignEvidence only

ExecutionWindow

Owner: Field Supervision

OPENDesignEvidence only

SIMOPSContext

Owner: ES&H / Location Steward

OPENDesignEvidence only

FieldPrerequisites

Owner: Construction / Tools / Logistics

OPENDesignEvidence only

B.9 · BC-09 Execution Card — 12 Frozen Prospective BEFORE Metrics

Collection is never inferred; prospective BEFORE is never retrospectively reconstructed.

IDMetricStateOwner
M-01Time from work demand to preventive package preparedDEFINEDNOT_CONFIRMED
M-02Time from package prepared to authorization grantedDEFINEDNOT_CONFIRMED
M-03Time lost at workfront to missing prerequisiteDEFINEDNOT_CONFIRMED
M-04Number of work starts halted after mobilisationDEFINEDNOT_CONFIRMED
M-05Restriction detection lead time (before vs at workfront)DEFINEDNOT_CONFIRMED
M-06Rework of permits / authorizations per shiftDEFINEDNOT_CONFIRMED
M-07Document revision conflicts detected at executionDEFINEDNOT_CONFIRMED
M-08Competency expiry discovered at the workfrontDEFINEDNOT_CONFIRMED
M-09SIMOPS conflicts detected before vs during executionDEFINEDNOT_CONFIRMED
M-10Critical control verification currency at work startDEFINEDNOT_CONFIRMED
M-11Supervisor time spent assembling readiness informationDEFINEDNOT_CONFIRMED
M-12Evidence reconstruction time for an audited decisionDEFINEDNOT_CONFIRMED

C · Owner-Based Evidence Request Register

No commitment dates invented. 28 requests issued, all AWAITING_OWNER.

ER-01BC-01Enterprise ArchitectureISSUEDAWAITING_OWNERRETEST NO

Requested: Confirmed federated participation map per source and object class

Why required: BC-01 cannot be retested without a declared participation mode per source.

Minimum acceptable: Attributable participation declaration per source/object.

Preferred: Architecture-signed participation map with failure behaviour.

Alternative acceptable: Per-source owner emails consolidated and countersigned.

Not accepted: Design-team-authored assumption of participation.

Evidence ref: — none

ER-02BC-01Q4 System OwnerISSUEDAWAITING_OWNERRETEST NO

Requested: Participation mode, interface mechanism, authentication and failure behaviour for permit/JHA/isolation objects

Why required: Q4 objects gate work authorization; unverifiable source must fail closed.

Minimum acceptable: Owner statement of mode + authority boundaries.

Preferred: Owner-approved interface specification.

Alternative acceptable: Governed snapshot or controlled manual federation declaration.

Not accepted: Inferred API capability or vendor marketing material.

Evidence ref: — none

ER-03BC-01Aconex / IM OwnerISSUEDAWAITING_OWNERRETEST NO

Requested: Document snapshot authority and revision-change notification behaviour

Why required: Decision pinning depends on governed revision snapshots.

Minimum acceptable: Owner confirmation of snapshot authority and validity window.

Preferred: Signed snapshot governance note (ADR-05 input).

Alternative acceptable: Manual controlled export under governance.

Not accepted: Assumed export permissions.

Evidence ref: — none

ER-04BC-01P6 / Project ControlsISSUEDAWAITING_OWNERRETEST NO

Requested: Look-ahead read participation and refresh cadence

Why required: Forecast context requires a governed schedule source.

Minimum acceptable: Owner confirmation of read mode and cadence.

Preferred: Scheduled governed extract.

Alternative acceptable: Periodic controlled snapshot.

Not accepted: Ad-hoc unsanctioned file sharing.

Evidence ref: — none

ER-05BC-01Smart CompletionsISSUEDAWAITING_OWNERRETEST NO

Requested: Subsystem completion participation mode

Why required: Release gating consumes completion state.

Minimum acceptable: Owner confirmation of participation mode.

Preferred: Governed read interface statement.

Alternative acceptable: Controlled snapshot.

Not accepted: Assumed availability.

Evidence ref: — none

ER-06BC-01IT / IMISSUEDAWAITING_OWNERRETEST NO

Requested: Enterprise interface hosting, network and data-movement authorization

Why required: No participation is real without IT authorization.

Minimum acceptable: IT authorization statement for the declared mechanisms.

Preferred: Architecture review record.

Alternative acceptable: Conditional authorization with named constraints.

Not accepted: Verbal assurance without attribution.

Evidence ref: — none

ER-07BC-02IAM / CyberISSUEDAWAITING_OWNERRETEST NO

Requested: Identity provider, authentication method and Pilot identity provisioning plan

Why required: Authority enforcement must be enterprise-enforced, not prototype-simulated.

Minimum acceptable: IAM owner confirmation + provisioned identity set.

Preferred: Signed IAM design and provisioning record.

Alternative acceptable: Time-boxed Pilot identity scope with revocation controls.

Not accepted: Prototype role-context behaviour.

Evidence ref: — none

ER-08BC-02IAM / CyberISSUEDAWAITING_OWNERRETEST NO

Requested: Role resolution source and mapping to area / activity / shift / risk scopes

Why required: Attribute-based authority is unenforceable without a role source.

Minimum acceptable: Documented mapping from enterprise roles to authority scopes.

Preferred: IAM-owned mapping artefact.

Alternative acceptable: HR-sourced role feed with IAM endorsement.

Not accepted: Design-team role table.

Evidence ref: — none

ER-09BC-02IAM / CyberISSUEDAWAITING_OWNERRETEST NO

Requested: Delegation and revocation behaviour confirmation

Why required: Delegation must never widen scope; revocation must fail closed.

Minimum acceptable: Written enterprise behaviour statement.

Preferred: Demonstrated revocation in a controlled test with real identities.

Alternative acceptable: Documented procedure with named enforcement owner.

Not accepted: Simulated revocation results.

Evidence ref: — none

ER-10BC-02HR / RRLLISSUEDAWAITING_OWNERRETEST NO

Requested: Authoritative person-to-role source for Pilot population

Why required: Role resolution requires an authoritative person source.

Minimum acceptable: HR confirmation of authoritative source and update cadence.

Preferred: System-of-record extract governance note.

Alternative acceptable: Controlled snapshot with steward.

Not accepted: Spreadsheet of assumed personnel.

Evidence ref: — none

ER-11BC-03Business Product OwnerISSUEDAWAITING_OWNERRETEST NO

Requested: Acceptance of lifecycle ownership and transition authority per object

Why required: Lifecycle is defined by design and accepted by nobody.

Minimum acceptable: Decision artefact per object class.

Preferred: Signed lifecycle authority matrix.

Alternative acceptable: Minuted governance decision with attributable authority.

Not accepted: Design specification restated as acceptance.

Evidence ref: — none

ER-12BC-03Q4 System OwnerISSUEDAWAITING_OWNERRETEST NO

Requested: Confirmation of transaction lifecycle authority boundaries at the federation edge

Why required: Prevents accidental duplication of Q4 authority.

Minimum acceptable: Owner confirmation of who may transition what.

Preferred: Joint authority boundary statement.

Alternative acceptable: Documented exception list.

Not accepted: Assumed boundary.

Evidence ref: — none

ER-13BC-04Project Director / Accountable ExecutiveISSUEDAWAITING_OWNERRETEST NO

Requested: Named, authorized and available stewardship appointments (7 roles)

Why required: Vacant stewardship forces fail-closed HOLD in operation.

Minimum acceptable: Appointment records with authorization and capacity.

Preferred: Signed appointment letters with delegates.

Alternative acceptable: Interim appointments with explicit validity and escalation.

Not accepted: Org-chart names without authorization or capacity.

Evidence ref: — none

ER-14BC-04HR / RRLLISSUEDAWAITING_OWNERRETEST NO

Requested: Capacity allocation and SoD confirmation for stewardship roles

Why required: Assignment without capacity is not stewardship.

Minimum acceptable: Capacity statement per role.

Preferred: Formal resourcing record.

Alternative acceptable: Time-boxed allocation with review date.

Not accepted: Best-effort verbal commitment.

Evidence ref: — none

ER-15BC-04ComplianceISSUEDAWAITING_OWNERRETEST NO

Requested: Segregation-of-duties assessment for steward / owner combinations

Why required: SoD breach would compromise authority separation.

Minimum acceptable: Compliance SoD assessment.

Preferred: Signed assessment with conditions.

Alternative acceptable: Conditional acceptance with compensating control recorded.

Not accepted: Self-assessment by the design team.

Evidence ref: — none

ER-16BC-05Records ManagementISSUEDAWAITING_OWNERRETEST NO

Requested: Retention basis and period per material record class

Why required: Retention currently rests on a design proposal, not a legal basis.

Minimum acceptable: Competent retention decision per class.

Preferred: Signed retention schedule extract.

Alternative acceptable: Interim retention decision with review date.

Not accepted: Design proposal RC-RET-01 restated.

Evidence ref: — none

ER-17BC-05PrivacyISSUEDAWAITING_OWNERRETEST NO

Requested: Personal-data classification, minimum attribute and access scope decision

Why required: Person and health-adjacent data must be minimised by decision, not assumption.

Minimum acceptable: Privacy decision per class.

Preferred: DPIA-equivalent record.

Alternative acceptable: Conditional approval with narrowed attributes.

Not accepted: Design minimum-attribute proposal alone.

Evidence ref: — none

ER-18BC-05HealthISSUEDAWAITING_OWNERRETEST NO

Requested: Confirmation that only a binary fitness flag may be consumed

Why required: Prevents duplication of medical records.

Minimum acceptable: Health owner confirmation of exposed attribute.

Preferred: Signed data-exposure statement.

Alternative acceptable: Documented restriction with custodian.

Not accepted: Assumed minimum exposure.

Evidence ref: — none

ER-19BC-06ES&H Accountable ExecutiveISSUEDAWAITING_OWNERRETEST NO

Requested: Formal election of PATH_A or PATH_B for critical control participation

Why required: Path ambiguity propagates unresolved scope into BC-08 and Phase 7.

Minimum acceptable: Attributable path election.

Preferred: Path A with source owner authorization.

Alternative acceptable: Path B with DecisionAuthority, Reason, PilotEvidenceLost, ResidualRisk, Phase7Impact.

Not accepted: Continuation of SIMULATED_ONLY as an implicit decision.

Evidence ref: — none

ER-20BC-06Critical Control / Forwood OwnerISSUEDAWAITING_OWNERRETEST NO

Requested: Source participation authorization for critical control verification records (Path A)

Why required: Path A is unachievable without the owning system.

Minimum acceptable: Owner participation confirmation.

Preferred: Governed read of verification records.

Alternative acceptable: Controlled snapshot of verification status.

Not accepted: Inferred integration.

Evidence ref: — none

ER-21BC-07Operational Support OwnerISSUEDAWAITING_OWNERRETEST NO

Requested: Named L1 / L2 / L3 owners, operating window and escalation path

Why required: Design-team dependency invalidates support sustainability.

Minimum acceptable: Staffing record with operating window.

Preferred: Signed support model with named staff.

Alternative acceptable: Interim model with explicit expiry and escalation.

Not accepted: Design team named as L2/L3.

Evidence ref: — none

ER-22BC-07Operational Support OwnerISSUEDAWAITING_OWNERRETEST NO

Requested: Execution of operational drills S-01 → S-06 by the real support function

Why required: Support capability must be demonstrated, not described.

Minimum acceptable: Drill records with actor, outcome and time.

Preferred: Six executed drills with independent observation.

Alternative acceptable: Partial drill set with documented gap and plan.

Not accepted: Simulation campaign drill results.

Evidence ref: — none

ER-23BC-08Construction ManagerISSUEDAWAITING_OWNERRETEST NO

Requested: Nomination of a real CV-07 workfront with owner, window and work demand

Why required: BC-08 has no real workfront; all ten dimensions are design-only.

Minimum acceptable: Nomination record with named field owner and window.

Preferred: Approved workfront nomination with SIMOPS context.

Alternative acceptable: Provisional nomination with confirmation milestones.

Not accepted: Illustrative or synthetic workfront.

Evidence ref: — none

ER-24BC-08BEO / Materials / Tools / LogisticsISSUEDAWAITING_OWNERRETEST NO

Requested: Confirmation of crew, equipment, materials and field prerequisites for the nominated workfront

Why required: Dimension-level confirmation is required; no aggregate assertion accepted.

Minimum acceptable: Per-dimension attributable confirmation.

Preferred: Function-signed readiness confirmation.

Alternative acceptable: Conditional confirmation with named residual gap.

Not accepted: Blanket statement of readiness.

Evidence ref: — none

ER-25BC-08ES&HISSUEDAWAITING_OWNERRETEST NO

Requested: SIMOPS context and field prerequisite confirmation for the nominated workfront

Why required: SIMOPS cumulative rules require a real concurrent-work picture.

Minimum acceptable: ES&H confirmation of concurrent work context.

Preferred: Signed SIMOPS assessment for the window.

Alternative acceptable: Interim assessment with review trigger.

Not accepted: Prototype SIMOPS scenario.

Evidence ref: — none

ER-26BC-09P6 / Project ControlsISSUEDAWAITING_OWNERRETEST NO

Requested: Source and owner confirmation for the 12 frozen BEFORE metrics

Why required: Collection cannot start without a confirmed source and owner per metric.

Minimum acceptable: Per-metric source and owner confirmation.

Preferred: Signed measurement plan.

Alternative acceptable: Partial confirmation with metric-level status.

Not accepted: Assumed data availability.

Evidence ref: — none

ER-27BC-09Business Product OwnerISSUEDAWAITING_OWNERRETEST NO

Requested: Formal authorization to start prospective BEFORE collection

Why required: BEFORE is time-irreversible and must precede any Pilot exposure.

Minimum acceptable: Attributable collection-start authorization.

Preferred: Signed start record with date and scope.

Alternative acceptable: Staged start per metric with recorded dates.

Not accepted: Retrospective reconstruction of any kind.

Evidence ref: — none

ER-28BC-09Field SupervisionISSUEDAWAITING_OWNERRETEST NO

Requested: Non-intrusive observation access that does not alter current ways of working

Why required: Collection must not itself contaminate the baseline.

Minimum acceptable: Access confirmation with non-intrusive conditions.

Preferred: Documented observation protocol.

Alternative acceptable: Restricted observation windows.

Not accepted: Any activity classified PILOT_INTERVENTION.

Evidence ref: — none

D · Evidence Quality Register & Taxonomy

EvidenceQuality is assigned per blocker on whether received evidence demonstrates the acceptance criterion. It is never computed from a document count, never averaged, never compensated across criteria.

DESIGN_EVIDENCE

Meaning: Architecture, rule, model or specification artefact produced by the design team.

Closure power: NONE — cannot close a blocker.

SIMULATION_EVIDENCE

Meaning: Deterministic scenario result from the accepted Simulation Baseline.

Closure power: NONE — may support design confidence, never raises EvidenceQuality.

SUPPORTING_EVIDENCE

Meaning: Real organizational artefact that contextualises but does not itself demonstrate the acceptance criterion.

Closure power: May move EvidenceQuality NONE → PARTIAL only.

OPERATIONAL_CLOSURE_EVIDENCE

Meaning: Attributable artefact from the competent authority demonstrating the acceptance criterion in the real organization.

Closure power: The only class that may directly support blocker closure.

CONTRADICTORY_EVIDENCE

Meaning: Real evidence conflicting with an accepted baseline assumption.

Closure power: Blocks closure; routes to the Contradiction Register.

NOT_APPLICABLE_EVIDENCE

Meaning: Artefact outside the acceptance criterion scope.

Closure power: NONE — recorded, never silently discarded.

Workflow: OPEN → EVIDENCE_REQUESTED → EVIDENCE_RECEIVED → EVIDENCE_UNDER_ASSESSMENT → SUFFICIENT_FOR_RETEST → TARGETED_RETEST → CLOSED / CLOSED_WITH_CONTROL / RESCOPED_BY_COMPETENT_AUTHORITY / REMAINS_OPEN

Forbidden transition: EVIDENCE_RECEIVED → CLOSED is prohibited. Targeted retest is mandatory.

CLOSED_WITH_CONTROL: CLOSED_WITH_CONTROL requires Control, Owner, Validity, ResidualRisk, Escalation and EvidenceRef. It may never be used to bypass missing evidence.

BlockerQualityReceivedValidityWorkflow state
BC-01NONENONEN/A — no evidence in handEVIDENCE_REQUESTED
BC-02NONENONEN/A — no evidence in handEVIDENCE_REQUESTED
BC-03NONENONEN/A — no evidence in handEVIDENCE_REQUESTED
BC-04NONENONEN/A — no evidence in handEVIDENCE_REQUESTED
BC-05NONENONEN/A — no evidence in handEVIDENCE_REQUESTED
BC-06NONENONEN/A — no evidence in handEVIDENCE_REQUESTED
BC-07NONENONEN/A — no evidence in handEVIDENCE_REQUESTED
BC-08NONENONEN/A — no evidence in handEVIDENCE_REQUESTED
BC-09NONENONEN/A — no evidence in handEVIDENCE_REQUESTED

ACCEPTED

Demonstrates the acceptance criterion in full.

ACCEPTED_WITH_LIMITATION

Demonstrates the criterion within a recorded boundary; limitation carried as residual.

INSUFFICIENT

Relevant but does not demonstrate the criterion.

OUTDATED

Demonstrated once but no longer current against validity rules.

OUT_OF_SCOPE

Does not address the acceptance criterion.

CONTRADICTORY

Conflicts with an accepted baseline assumption; routed to the Contradiction Register.

Every evidence item receives an explicit disposition with a recorded reason. Evidence is never silently discarded.

E · Cross-Blocker Dependency Map

   BC-01 ────────────► BC-06 ◄──── ES&H path election (ESC-03)
     │  (participation)     │
     │                      ▼
   BC-02 ──► BC-03      BC-08 ──► BC-09 ──► Phase 6B (NOT_AUTHORIZED)
     │                      ▲                 ▲
     └──► BC-04 ──► BC-07 ──┘        BC-05 ───┘ (classification of measures)
BC-02BC-03EXECUTION_DEPENDENCY

Lifecycle transition authority is only technically enforceable once identity and authority resolution are real.

BC-01BC-06EVIDENCE_DEPENDENCY

Path A critical control participation requires governed source participation.

BC-06BC-01CLOSURE_DEPENDENCY

A Path B rescope removes the critical control source from the required participation set.

BC-02BC-04EXECUTION_DEPENDENCY

Stewardship authority must be enforceable where authority enforcement applies.

BC-04BC-07EVIDENCE_DEPENDENCY

Support model cannot be staffed or bounded without governance ownership.

BC-06BC-08EXECUTION_DEPENDENCY

Field readiness scope depends on whether critical controls participate in the Pilot.

BC-08BC-09CLOSURE_DEPENDENCY

The measured population must correspond to the real workfront — but collection must start before exposure.

BC-09Phase6BCLOSURE_DEPENDENCY

No Pilot execution may commence before the prospective BEFORE baseline is underway.

BC-05BC-09DESIGN_DEPENDENCY

Measurement records must sit inside an approved classification and retention basis.

G · Retest Eligibility Engine & Targeted Retest Queue

Queue empty — no blocker has reached SUFFICIENT_FOR_RETEST. Retests are targeted at the specific acceptance criterion; complete Mesa assessments are never rerun.

BC-01NOT_ELIGIBLE

Why: NOT_ELIGIBLE — EvidenceQuality = NONE. Eligibility requires ≥ SUFFICIENT_FOR_RETEST.

Evidence refs: — none received

Acceptance criteria to test: Signed or attributable owner confirmation per source/object stating participation mode, authority boundaries and failure behaviour. Governed snapshot or controlled manual federation is acceptable where sufficient for CV-07 — live API is not demanded and never inferred.

Residual dependencies: External system owners outside the design team; enterprise change windows.

BC-02NOT_ELIGIBLE

Why: NOT_ELIGIBLE — EvidenceQuality = NONE. Eligibility requires ≥ SUFFICIENT_FOR_RETEST.

Evidence refs: — none received

Acceptance criteria to test: IAM owner confirmation of provider, authentication, role resolution, delegation and revocation, plus a provisioned Pilot identity set. Prototype identity behaviour is explicitly not closure evidence.

Residual dependencies: Enterprise IAM programme and cyber approval cycle.

BC-03NOT_ELIGIBLE

Why: NOT_ELIGIBLE — EvidenceQuality = NONE. Eligibility requires ≥ SUFFICIENT_FOR_RETEST.

Evidence refs: — none received

Acceptance criteria to test: Competent-authority decision artefact per object class accepting lifecycle ownership and transition authority. May close faster than BC-01/BC-02 because it is a decision, not an integration.

Residual dependencies: BC-02 for technical enforcement of transition authority.

BC-04NOT_ELIGIBLE

Why: NOT_ELIGIBLE — EvidenceQuality = NONE. Eligibility requires ≥ SUFFICIENT_FOR_RETEST.

Evidence refs: — none received

Acceptance criteria to test: Attributable appointment records with authorization, named delegate, allocated capacity and SoD confirmation. A name on an org chart is SUPPORTING_EVIDENCE only.

Residual dependencies: Organizational resourcing decisions outside the programme.

BC-05NOT_ELIGIBLE

Why: NOT_ELIGIBLE — EvidenceQuality = NONE. Eligibility requires ≥ SUFFICIENT_FOR_RETEST.

Evidence refs: — none received

Acceptance criteria to test: Competent decision artefact per material record class covering classification, retention basis, minimum attribute and custodian. No duplication of HR/Health source records is permitted.

Residual dependencies: Privacy and legal review cycle.

BC-06NOT_ELIGIBLE

Why: NOT_ELIGIBLE — EvidenceQuality = NONE. Eligibility requires ≥ SUFFICIENT_FOR_RETEST.

Evidence refs: — none received

Acceptance criteria to test: One explicit, attributable path election. Path B must never be chosen merely to facilitate closure.

Residual dependencies: Critical control system owner authorization (Path A) or executive rescope (Path B).

BC-07NOT_ELIGIBLE

Why: NOT_ELIGIBLE — EvidenceQuality = NONE. Eligibility requires ≥ SUFFICIENT_FOR_RETEST.

Evidence refs: — none received

Acceptance criteria to test: Staffed support model plus real drill records for S-01 (user/access), S-02 (mapping conflict), S-03 (rule question), S-04 (interface failure), S-05 (authority issue), S-06 (evidence reconstruction). Simulation drills are not operational drill evidence.

Residual dependencies: Support resourcing and service-window commitment.

BC-08NOT_ELIGIBLE

Why: NOT_ELIGIBLE — EvidenceQuality = NONE. Eligibility requires ≥ SUFFICIENT_FOR_RETEST.

Evidence refs: — none received

Acceptance criteria to test: Attributable confirmation per dimension from the accountable field function for a real, nominated CV-07 workfront.

Residual dependencies: BC-06 path election where Critical Controls apply; construction sequencing.

BC-09NOT_ELIGIBLE

Why: NOT_ELIGIBLE — EvidenceQuality = NONE. Eligibility requires ≥ SUFFICIENT_FOR_RETEST.

Evidence refs: — none received

Acceptance criteria to test: Attributable collection-start record plus a sufficient prospective data window per metric. Inference of collection is prohibited.

Residual dependencies: Field data availability; strict precedence over any Pilot exposure.

Targeted retest queue: EMPTY — 0 retests raised, 0 executed.

H · Contradiction Register

No contradiction recorded — no real external evidence has been received. Architecture is never automatically reopened: every contradiction is first classified EvidenceDefect / LocalException / ConfigurationChange / ArchitectureImpact.

Entries: 0 — register empty.

I · Escalation Register

ESC-01BC-04 / BC-07 Stewardship & SupportACTIVE

Escalation owner: Project Director / Accountable Executive

Decision required: Appoint, authorize and resource stewardship and operational support roles.

Blocking impact: BC-03, BC-04, BC-07 and every location-governed decision (G-01 fail-closed).

Evidence: — none

ESC-02BC-01 / BC-02 Enterprise Sources & IAMACTIVE

Escalation owner: Enterprise Architecture + IAM / Cyber leadership

Decision required: Authorize source participation and enterprise identity provisioning for the Pilot.

Blocking impact: BC-01, BC-02 and downstream BC-03 enforcement. Longest external lead time.

Evidence: — none

ESC-03BC-06 Critical Control PathACTIVE

Escalation owner: ES&H Accountable Executive

Decision required: Elect PATH_A_REAL_PARTICIPATION or PATH_B_FORMAL_RESCOPE.

Blocking impact: BC-06 and BC-08 scope; Phase 7 evidence claims.

Evidence: — none

ESC-04BC-09 Prospective Baseline ProtectionACTIVE

Escalation owner: Business Product Owner + Project Controls

Decision required: Authorize and start prospective BEFORE collection before any Pilot exposure.

Blocking impact: BC-09 and Phase 6B entry. Time-irreversible.

Evidence: — none

J · Blocker Execution Heatmap

CLOSED → positive · OPEN / EVIDENCE_REQUIRED → amber · DEPENDENCY_HELD → controlled neutral / amber · CONTRADICTED / FAIL / PROHIBITED → red · Missing evidence is not failure.

BCMesaAuthorityEvidenceDependencyRetestClosureOwnerNext action
BC-01MESA 1Enterprise Architecture + each named System OwnerNONEExternal system owners outside the design team; enterprise change windows.NOT_ELIGIBLEREMAINS_OPENEnterprise ArchitectureIssue and chase per-source owner confirmation requests (longest external lead time on the board).
BC-02MESA 1IAM / CyberNONEEnterprise IAM programme and cyber approval cycle.NOT_ELIGIBLEREMAINS_OPENIAM / CyberRequest IAM provider/role-resolution confirmation and Pilot identity provisioning plan.
BC-03MESA 1Business Product Owner + per-object Lifecycle OwnersNONEBC-02 for technical enforcement of transition authority.NOT_ELIGIBLEREMAINS_OPENBusiness Product OwnerConvene lifecycle owner acceptance session; produce per-object decision artefacts.
BC-04MESA 2Project Director / Accountable ExecutiveNONEOrganizational resourcing decisions outside the programme.NOT_ELIGIBLEREMAINS_OPENChange / AdoptionEscalate stewardship appointment decision with capacity commitment.
BC-05MESA 1Records Management + Privacy + ComplianceNONEPrivacy and legal review cycle.NOT_ELIGIBLEREMAINS_OPENRecords ManagementTable the CA-04 material item list for Records/Privacy decision — decision artefact, not integration.
BC-06MESA 1ES&H Accountable Executive + Critical Control / Forwood OwnerNONECritical control system owner authorization (Path A) or executive rescope (Path B).NOT_ELIGIBLEREMAINS_OPENCritical Control / Forwood OwnerForce the path election decision — it governs downstream field scope (BC-08).
BC-07MESA 2Operational Support OwnerNONESupport resourcing and service-window commitment.NOT_ELIGIBLEREMAINS_OPENOperational SupportSecure support staffing decision, then schedule S-01 → S-06 as real drills.
BC-08MESA 3Construction Manager + Field SupervisionNONEBC-06 path election where Critical Controls apply; construction sequencing.NOT_ELIGIBLEREMAINS_OPENConstructionNominate a real CV-07 workfront and start dimension-by-dimension confirmation (0/10 today).
BC-09MESA 3Project Controls + Business Product OwnerNONEField data availability; strict precedence over any Pilot exposure.NOT_ELIGIBLEREMAINS_OPENP6 / Project ControlsConfirm metric sources and owners and start prospective collection — irreversibility makes this time-critical.

K · Top 5 Next Actions

Ranked by critical path, lead time, dependency, evidence and authority availability, and BC-09 irreversibility — never by blocker number.

#1Issue and escalate enterprise source participation confirmations (BC-01) via ESC-02.

Blockers: BC-01 (→ BC-06, BC-03)

Basis: Longest external lead time on the board; every federated decision depends on declared participation.

Competent authority: Enterprise Architecture + System Owners

#2Obtain IAM provider, role-resolution and Pilot identity provisioning commitment (BC-02).

Blockers: BC-02 (→ BC-03, BC-04)

Basis: External lead time plus downstream enforceability of all lifecycle and stewardship authority.

Competent authority: IAM / Cyber

#3Force the BC-06 critical control path election (Path A or Path B) via ESC-03.

Blockers: BC-06 (→ BC-08)

Basis: Path ambiguity propagates unresolved scope downstream; the decision itself has short lead time.

Competent authority: ES&H Accountable Executive

#4Start non-intrusive BC-09 metric source/owner confirmation and prepare collection start.

Blockers: BC-09 (→ Phase 6B)

Basis: Time-irreversible: the BEFORE baseline cannot be reconstructed once behaviour changes.

Competent authority: Project Controls + Business Product Owner

#5Table BC-03 lifecycle acceptance and BC-05 classification/retention decisions for competent decision artefacts.

Blockers: BC-03, BC-05

Basis: Decision artefacts, not integrations — they can close materially faster than BC-01/BC-02.

Competent authority: Business Product Owner · Records Management · Privacy

L · Phase 6A Integrated Revalidation Eligibility

This Board never outputs GO. GO belongs exclusively to Phase 6A Integrated Revalidation.

NOT_METAll mandatory blockers CLOSED / CLOSED_WITH_CONTROL / RESCOPED

0 closed, 0 CWC, 0 rescoped, 9 REMAINS_OPEN.

METNo material contradiction

Contradiction register empty — no external evidence received.

NOT_METCross-Mesa dependencies compatible

9 dependency edges unresolved; BC-02→BC-03, BC-06→BC-08 and BC-08→BC-09 all unsatisfied.

METBC-09 protection preserved

BC09Protection ACTIVE, PilotExposure PROHIBITED, no contamination event.

METPilot baseline materially intact

Phase 5 / Phase 6 baselines consumed unchanged; simulation baseline frozen.

NOT_METRequired operational evidence current

Zero OperationalClosureEvidence items received; 28 requests awaiting owner.

OUTPUT: NOT_ELIGIBLE

M · Evidence Change History (append-only)

Append-only. Prior evidence is never overwritten. Incremental updates touch only the affected blocker and its dependencies — Mesas are never rerun.

#12026-08-30

Previous state: IEW — 9 blockers REMAINS_OPEN, EvidenceQuality NONE

New state: OEB established — Operational Evidence Execution Board Rev.1 instantiated

Trigger: Phase 6A Operational Evidence Execution Board authorization

Evidence ref: OEB-BASELINE-001

Actor / authority: Programme governance

#22026-08-30

Previous state: Simulation campaign SIMULATION_BASELINE_ACCEPTED_WITH_FINDINGS

New state: SIMULATION_BASELINE_ACCEPTED consumed as design assurance only

Trigger: Simulation findings closure (F-SIM-04, F-SIM-05)

Evidence ref: SIMCLOSURE-001

Actor / authority: Design authority

#32026-08-30

Previous state: Evidence requests: 24 (IEW)

New state: Evidence requests: 28 issued, all AWAITING_OWNER, 0 received

Trigger: Owner-based request register expansion under the Board

Evidence ref: OEB-ER-REGISTER-001

Actor / authority: Evidence acquisition lead

N · Strict Program Boundaries

  • No fabricated evidence.
  • No simulated organizational approvals.
  • No invented system-owner confirmation.
  • No inferred APIs.
  • No invented IAM.
  • No invented field readiness.
  • No Pilot exposure.
  • BC-09 never closed without prospective measurement.
  • Phase 6B not initiated.
  • Phase 7 not initiated.
  • Architecture not changed.
  • Frozen simulation baseline not modified.
  • SimulationEvidence never converted into OperationalClosureEvidence.

The Board is not designed to show progress. It is designed to show whether each blocker has become technically, organizationally and evidentially defendable enough to be retested and closed. The next gate remains Phase 6A Integrated Revalidation and shall not be entered until this Board reports ELIGIBLE_FOR_INTEGRATED_REVALIDATION.