A · Functional Contract Executive Summary
Eight descendant functional contracts for field pre-start orchestration, defined against the sealed parent baseline PH6A-IADA-REV1 and the accepted assessment PH6A-FPSO-AIA-REV0. Definition is not acceptance: nothing here is frozen, implemented or simulated.
§0 · Governing Condition
Definition and acceptance are deliberately separated
§0 · This workstream shall not
Prohibited actions
- · IMPLEMENT_UI
- · CREATE_ROUTES for pre-start execution
- · CREATE_COMPONENTS for the Pre-Start Board
- · BUILD_PROTOTYPE
- · RUN_OPERATIONAL_SIMULATION
- · DEFINE_DEMO_SCENARIOS
- · CREATE_SYNTHETIC_OPERATIONAL_DATA
- · CREATE_SIMULATED_PROCESS_TIMES
- · CREATE_OPERATIONAL_CLOSURE_EVIDENCE
- · FREEZE_ITS_OWN_CONTRACTS
- · SELF_ACCEPT
- · MODIFY_PH6A_IADA_REV1
Definition is not acceptance. Contracts are not frozen in this interaction and are not self-accepted.
B · Contract Scope Register
§1 — scope frozen from PH6A-FPSO-AIA-REV0
| ID | Contract | AIA origin | Scope state |
|---|---|---|---|
| FC-FPSO-01 | LocationAcquisitionService | AIA candidate 1 · location acquisition & confirmation | IN SCOPE |
| FC-FPSO-02 | ContextualDocumentRetrieval | AIA candidate 2 · contextual controlled-document retrieval | IN SCOPE |
| FC-FPSO-03 | PreStartPreventivePackage (+ Item) | AIA candidate 3 · pre-start package orchestration | IN SCOPE |
| FC-FPSO-04 | CrewConfirmationRecord | AIA candidate 4 · crew presence & decision facts | IN SCOPE |
| FC-FPSO-05 | IPERCContinuo | AIA candidate 5 · continuous field risk record | IN SCOPE |
| FC-FPSO-06 | FieldDeltaAssessment | AIA candidate 6 · expected vs observed context | IN SCOPE |
| FC-FPSO-07 | ToolReadiness | AIA candidate 7 · tool readiness distinct from equipment | IN SCOPE |
| FC-FPSO-08 | DigitalSignatureAssurance | AIA candidate 8 · signature binding assurance | IN SCOPE |
ContractScopeDeviation = 0. No ninth contract was created; no candidate capability required one.
§2 · REUSE_BEFORE_EXTENSION
Parent contracts consumed, never duplicated
- · LocationOperationalContext
- · WorkPackage
- · JobCard
- · Equipment
- · ActivityRisk
- · LocationRisk
- · SIMOPSInteractionRisk
- · DecisionRight
- · GovernedOperationalEvent
- · EvidenceCriterionAssessment
- · CanonicalSemanticDictionary
- · RequirementCatalogue
- · RecordCatalogue
- · RuleVersion
- · ProvenanceChain
DuplicatedParentContracts = 0.
§12 · Frozen fact classes reused
No new fact class introduced
| Fact class | Used by | New? |
|---|---|---|
| AUTHORITATIVE_FACT | canonical Location, permits, competency authority outputs | NO |
| FEDERATED_FACT | document metadata, decision facts, environmental feeds | NO |
| DERIVED_FACT | LocationCandidateSet, ApplicabilityStatus, completeness evaluation | NO |
| RULE_EVALUATION | materiality, completeness, tool readiness, crew rules | NO |
| AI_ADVISORY_OUTPUT | candidate ranking, hazard proposals, tool set proposals | NO |
| AUTHORIZED_DECISION | ConfirmedLocation, IPERC authorization, package authorization, signature acts | NO |
EvidenceEngine ≠ DecisionEngine ≠ AuthorityEngine preserved in every contract.
FC-FPSO-01 · LocationAcquisitionService
REV0 · parent PH6A-IADA-REV1
Assist a field user in resolving a physical position into a candidate canonical Location, and record the human confirmation that binds work to that Location.
- · creating, renaming or modifying canonical Locations
- · granting physical access authorization
- · granting work authorization
- · deriving SIMOPS verdicts (owned by parent SIMOPS contracts)
- · storing a position trail as personnel tracking
- · LocationOperationalContext
- · DecisionRight
- · GovernedOperationalEvent
- · ProvenanceChain
- · RuleVersion
- · CanonicalSemanticDictionary
- · PhysicalPositionReading { lat, lon, accuracyMetres, capturedAt, sourceDevice }
- · LocationRegisterSnapshot (AUTHORITATIVE_FACT, by reference)
- · ManualLocationSelection (optional, human input)
- · ProximityRuleVersion (configuration)
- · LocationCandidateSet (DERIVED_FACT)
- · LikelyLocation (DERIVED_FACT, advisory)
- · ConfirmedLocation_ID (AUTHORIZED_DECISION by the confirming human)
- · AcquisitionReasonCode
- · Location register snapshot available with a governed RuleVersion
- · Acting user identity resolved
- · ConfirmedLocation_ID exists only with a recorded human confirmation act
- · ProvenanceChain records acquisition mode (GPS / MANUAL / MIXED) and accuracy at confirmation time
- · Canonical Location register (Location steward)
- · Device positioning service (effectful shell, non-authoritative)
- · ProximityRadiusConfig
- · AccuracyThresholdConfig
- · CandidateSetMaxSizeConfig
- · RULE-LOC-CANDIDATE-SELECTION
- · RULE-LOC-ACCURACY-CLASSIFICATION
- · DecisionRight: CONFIRM_WORK_LOCATION
- · Authenticated session
- · Device binding for position source
- · Position retained only as the acquisition context of a confirmation act
- · No continuous location history; no personnel movement analytics
- · GPS_AVAILABLE
- · GPS_LOW_ACCURACY
- · GPS_UNAVAILABLE
- · MULTIPLE_LOCATION_CANDIDATES
- · NO_LOCATION_MATCH
- · MANUAL_LOCATION_SELECTION
- · LOCATION_CONFIRMED
- · LOCATION_CHANGED
- · GPS_AVAILABLE → MULTIPLE_LOCATION_CANDIDATES | LOCATION_CONFIRMED
- · GPS_LOW_ACCURACY → MANUAL_LOCATION_SELECTION
- · GPS_UNAVAILABLE → MANUAL_LOCATION_SELECTION
- · NO_LOCATION_MATCH → MANUAL_LOCATION_SELECTION
- · MANUAL_LOCATION_SELECTION → LOCATION_CONFIRMED
- · LOCATION_CONFIRMED → LOCATION_CHANGED (re-entry to acquisition)
- · GPS_AVAILABLE → LOCATION_CONFIRMED without a human confirmation act
- · LOCATION_CHANGED → retention of downstream authorizations
- · ConfirmedLocationWithoutLocationCandidateOrManualSelection
- · LOC-RC-01 ACCURACY_BELOW_THRESHOLD
- · LOC-RC-02 NO_CANDIDATE_IN_RADIUS
- · LOC-RC-03 AMBIGUOUS_CANDIDATE_SET
- · LOC-RC-04 POSITION_SOURCE_UNAVAILABLE
- · LOC-RC-05 MANUAL_OVERRIDE_APPLIED
- · LOC-RC-06 LOCATION_CHANGED_MID_SHIFT
- · LOCATION_REGISTER_UPDATED
- · LOCATION_STEWARDSHIP_CHANGED
- · LOCATION_CANDIDATES_DERIVED
- · LOCATION_CONFIRMED
- · LOCATION_CHANGE_DETECTED
- · rank candidates as AI_ADVISORY_OUTPUT with stated basis
- · confirming a location
- · suppressing candidates from the human view
- · creating canonical Locations
- · AP-01-1: ConfirmedLocation_ID ⇒ ∃ HumanLocationConfirmation with DecisionRight
- · AP-01-2: GPS output is never promoted above DERIVED_FACT
- · AP-01-3: all seven acquisition conditions have defined behaviour
- · EXTERNAL_VALIDATION_DEPENDENCY: Location steward confirmation of proximity radius policy
- · EXTERNAL_VALIDATION_DEPENDENCY: corporate policy on positional data retention
FC-FPSO-02 · ContextualDocumentRetrieval
REV0 · parent PH6A-IADA-REV1
Retrieve controlled documents relevant to the operational context and present them with full source, revision and applicability semantics intact.
- · becoming a local system of record for controlled documents
- · issuing, approving or superseding revisions
- · asserting authorization from retrieval
- · caching indefinitely without stated freshness
- · RequirementCatalogue
- · RecordCatalogue
- · LocationOperationalContext
- · JobCard
- · Equipment
- · ProvenanceChain
- · RuleVersion
- · GovernedOperationalEvent
- · RetrievalContext { location, workPackage, jobCard, activity, discipline, equipment, riskContext }
- · DocumentSourceParticipationMode (per source system)
- · ApplicabilityRuleVersion
- · ContextualDocumentCandidateSet [ Document_ID, DocumentClass, Revision, DocumentStatus, SourceSystem, SourceOwner, ParticipationMode, EffectiveDate, RetrievedAt, ApplicabilityStatus ]
- · RetrievalReasonCode
- · RetrievalContext resolved to at least Location + Activity
- · Source participation mode declared per source
- · Every candidate carries the ten mandatory attributes
- · ApplicabilityStatus is an explicit evaluation result, never an absence
- · Document source system of record (e.g. Aconex-class DMS)
- · Document metadata retrieval interface (mode-declared)
- · Work/schedule federation for activity context
- · DocumentClassMap
- · ContextToDocumentClassApplicabilityConfig
- · FreshnessWindowConfig
- · RULE-DOC-APPLICABILITY
- · RULE-DOC-REVISION-SELECTION
- · DecisionRight: DECLARE_DOCUMENT_APPLICABLE (where evaluation is not deterministic)
- · Source-side entitlement respected; no privilege elevation via retrieval
- · No personal data extracted from document bodies
- · RETRIEVED
- · APPLICABILITY_EVALUATED
- · APPLICABLE
- · NOT_APPLICABLE
- · APPLICABILITY_UNDETERMINED
- · SUPERSEDED_DOCUMENT
- · MULTIPLE_ACTIVE_REVISIONS
- · SOURCE_UNAVAILABLE
- · METADATA_INSUFFICIENT
- · DOCUMENT_NOT_FOUND
- · DOCUMENT_CONFLICT
- · RETRIEVED → APPLICABILITY_EVALUATED
- · APPLICABILITY_EVALUATED → APPLICABLE | NOT_APPLICABLE | APPLICABILITY_UNDETERMINED
- · APPLICABLE → SUPERSEDED_DOCUMENT (on revision change)
- · RETRIEVED → APPLICABLE without applicability evaluation
- · APPLICABLE → AUTHORIZED (not this contract's verb)
- · RetrievedDocumentTreatedAsApplicableWithoutApplicabilityEvaluation
- · DOC-RC-01 SOURCE_UNAVAILABLE
- · DOC-RC-02 METADATA_INSUFFICIENT
- · DOC-RC-03 MULTIPLE_ACTIVE_REVISIONS
- · DOC-RC-04 SUPERSEDED_AFTER_RETRIEVAL
- · DOC-RC-05 DOCUMENT_NOT_FOUND
- · DOC-RC-06 CONFLICTING_SOURCE_RECORDS
- · DOCUMENT_REVISION_PUBLISHED
- · DOCUMENT_SUPERSEDED
- · SOURCE_PARTICIPATION_CHANGED
- · DOCUMENT_CANDIDATE_SET_DERIVED
- · DOCUMENT_REVISION_CHANGE_DETECTED
- · DOCUMENT_CONFLICT_RAISED
- · suggest additional candidate documents as AI_ADVISORY_OUTPUT
- · marking a document APPLICABLE
- · selecting between multiple active revisions
- · hiding a superseded warning
- · AP-02-1: no candidate reaches APPLICABLE without an evaluation record
- · AP-02-2: RETRIEVED ≠ APPLICABLE ≠ AUTHORIZED preserved in the data model
- · AP-02-3: six abnormal conditions each have defined behaviour
- · EXTERNAL_VALIDATION_DEPENDENCY: document owner confirmation of retrievable metadata fields
- · EXTERNAL_VALIDATION_DEPENDENCY: participation mode per source system (no live API assumed)
FC-FPSO-03 · PreStartPreventivePackage + PreStartPreventivePackageItem
REV0 · parent PH6A-IADA-REV1
Orchestrate the pre-start preventive item set for a job card without collapsing the independent state of any item.
- · issuing permits, isolations or sanctions
- · computing a weighted or averaged readiness score
- · substituting one item's pass for another's absence
- · authorizing work
- · WorkPackage
- · JobCard
- · RequirementCatalogue
- · RecordCatalogue
- · SIMOPSInteractionRisk
- · LocationRisk
- · ActivityRisk
- · Equipment
- · DecisionRight
- · RuleVersion
- · GovernedOperationalEvent
- · ProvenanceChain
- · JobCard context
- · ApplicabilityConfiguration (which items are mandatory in this context)
- · Item state feeds: CrewConfirmation, WorkOrder, IPERCContinuo, ATS, PETAR, ApplicableChecklistSet, ToolReadiness, EquipmentReadiness, CriticalControlVerification, PermitReference, IsolationReference, PETS_CP_Reference, SIMOPSCondition, Restriction, EnvironmentalCondition
- · PreStartPreventivePackage { packageId, jobCardId, itemSet, mandatorySet, completenessState, authorizationState }
- · PreStartPreventivePackageItem { itemId, itemClass, mandatory, itemState, reasonCode, provenance }
- · ConfirmedLocation_ID present
- · Applicability configuration version resolved
- · PACKAGE_COMPLETE only when every mandatory item is individually satisfied
- · AUTHORIZED only via a distinct authorization act by a holder of the DecisionRight
- · Permit / isolation / critical-control systems of record
- · Work order source
- · Checklist source
- · Environmental condition source
- · MandatoryItemApplicabilityConfig
- · ItemClassCatalogue
- · RULE-PKG-APPLICABILITY
- · RULE-PKG-COMPLETENESS (conjunctive, non-compensatory)
- · DecisionRight: AUTHORIZE_PRESTART_PACKAGE
- · Item write scoped to the item's accountable role
- · Crew items reference decision facts only
- · PACKAGE_DRAFT
- · PACKAGE_IN_PROGRESS
- · PACKAGE_INCOMPLETE
- · PACKAGE_COMPLETE
- · PACKAGE_AUTHORIZED
- · PACKAGE_HOLD
- · PACKAGE_REASSESS_REQUIRED
- · PACKAGE_CLOSED
- · PACKAGE_CANCELLED
- · PACKAGE_DRAFT → PACKAGE_IN_PROGRESS
- · PACKAGE_IN_PROGRESS → PACKAGE_INCOMPLETE | PACKAGE_COMPLETE
- · PACKAGE_COMPLETE → PACKAGE_AUTHORIZED
- · any → PACKAGE_HOLD | PACKAGE_REASSESS_REQUIRED (on delta or control loss)
- · PACKAGE_AUTHORIZED → PACKAGE_REASSESS_REQUIRED → PACKAGE_AUTHORIZED (re-authorization only)
- · PACKAGE_INCOMPLETE → PACKAGE_AUTHORIZED
- · PACKAGE_REASSESS_REQUIRED → PACKAGE_AUTHORIZED without a new authorization act
- · PackageAuthorizedWithMandatoryItemIncomplete
- · AuthorizedWithoutDecisionRight
- · PKG-RC-01 MANDATORY_ITEM_INCOMPLETE
- · PKG-RC-02 MANDATORY_ITEM_UNVERIFIABLE
- · PKG-RC-03 MATERIAL_DELTA_OPEN
- · PKG-RC-04 CRITICAL_CONTROL_NOT_VERIFIED
- · PKG-RC-05 SIMOPS_CUMULATIVE_BLOCK
- · PKG-RC-06 AUTHORITY_UNRESOLVED
- · PKG-RC-07 RESTRICTION_ACTIVE
- · ITEM_STATE_CHANGED
- · MATERIAL_DELTA_RAISED
- · CRITICAL_CONTROL_STATE_CHANGED
- · SIMOPS_STATE_CHANGED
- · PACKAGE_COMPOSED
- · PACKAGE_COMPLETENESS_EVALUATED
- · PACKAGE_AUTHORIZED
- · PACKAGE_REASSESS_RAISED
- · propose applicable items as AI_ADVISORY_OUTPUT
- · marking items complete
- · declaring the package complete or authorized
- · removing a mandatory item
- · AP-03-1: PACKAGE_AUTHORIZED ⇒ ∀ mandatory items satisfied
- · AP-03-2: no arithmetic aggregation exists anywhere in completeness evaluation
- · AP-03-3: item states are independently retrievable and never overwritten by package state
- · CONTRACT_DEFINITION_GAP: mandatory-item designation per activity class awaits configuration governance (links F-DEAP-01)
- · EXTERNAL_VALIDATION_DEPENDENCY: permit/isolation owner confirmation of referenceable identifiers
FC-FPSO-04 · CrewConfirmationRecord
REV0 · parent PH6A-IADA-REV1
Record who is actually present for the task and bind each person to governed role, competency, training and fitness decision facts — without replicating HR, medical or training systems.
- · storing HRRecord, MedicalRecord or TrainingRecord content
- · computing competency itself
- · issuing medical fitness judgements
- · granting authorization from presence
- · JobCard
- · DecisionRight
- · RequirementCatalogue
- · GovernedOperationalEvent
- · ProvenanceChain
- · RuleVersion
- · ExpectedCrew (from work assignment)
- · IdentityConfirmation events
- · RoleDecisionFact / CompetencyDecisionFact / TrainingDecisionFact / FitnessDecisionFact (federated decision facts)
- · CrewConfirmationRecord { expected[], observedPresent[], perPersonFacts, exceptions[], crewState }
- · CrewException { personRef, exceptionClass, reasonCode, dispositionOwner }
- · JobCard resolved
- · Decision-fact source declared with participation mode
- · Every observed person carries an explicit competency/fitness decision-fact state or an exception
- · Competency authority
- · Occupational health authority (flag only)
- · Identity provider
- · Training/competency decision-fact service
- · RequiredRoleMatrixConfig
- · MandatoryCompetencyConfig
- · RULE-CREW-MANDATORY-ROLE
- · RULE-CREW-COMPETENCY-VALIDITY
- · DecisionRight: CONFIRM_CREW
- · DecisionRight: DISPOSITION_CREW_EXCEPTION
- · Identity assurance level per confirmation method
- · Data minimisation: boolean/decision facts and validity dates only
- · No medical detail, diagnosis or restriction cause
- · No biometric retention beyond the confirmation act
- · CREW_EXPECTED
- · CREW_OBSERVED
- · CREW_EXCEPTION_OPEN
- · CREW_CONFIRMED
- · CREW_BLOCKED
- · CREW_CHANGED
- · CREW_EXPECTED → CREW_OBSERVED
- · CREW_OBSERVED → CREW_CONFIRMED | CREW_EXCEPTION_OPEN
- · CREW_EXCEPTION_OPEN → CREW_CONFIRMED (disposition) | CREW_BLOCKED
- · CREW_CONFIRMED → CREW_CHANGED → CREW_OBSERVED
- · CREW_OBSERVED → CREW_CONFIRMED with an invalid mandatory competency
- · CREW_CHANGED retaining prior authorization
- · CrewValidWhileMandatoryCompetencyInvalid
- · CRW-RC-01 MANDATORY_ROLE_ABSENT
- · CRW-RC-02 COMPETENCY_EXPIRED
- · CRW-RC-03 COMPETENCY_UNVERIFIABLE
- · CRW-RC-04 FITNESS_NOT_CONFIRMED
- · CRW-RC-05 IDENTITY_NOT_CONFIRMED
- · CRW-RC-06 UNPLANNED_PERSON_PRESENT
- · COMPETENCY_DECISION_FACT_UPDATED
- · FITNESS_FLAG_UPDATED
- · CREW_ASSIGNMENT_CHANGED
- · CREW_CONFIRMED
- · CREW_EXCEPTION_RAISED
- · CREW_CHANGE_DETECTED
- · highlight expiring competencies as advisory
- · declaring a person competent
- · clearing a fitness flag
- · authorizing an exception
- · AP-04-1: PRESENT ≠ COMPETENT ≠ AUTHORIZED preserved structurally
- · AP-04-2: no HR/medical/training record content is persisted
- · AP-04-3: every exception has an owner and a reason code
- · EXTERNAL_VALIDATION_DEPENDENCY: data-privacy owner confirmation of the minimal decision-fact set
- · EXTERNAL_VALIDATION_DEPENDENCY: competency authority confirmation of fact issuance
FC-FPSO-05 · IPERCContinuo
REV0 · parent PH6A-IADA-REV1
Establish IPERC Continuo as a first-class governed record in which system prepopulation, field observation, human confirmation, supervisory review and authorization are distinct and separately attributable.
- · creating corporate risk standards
- · authorizing work
- · overwriting source-derived content silently
- · replacing the baseline risk assessment
- · ActivityRisk
- · LocationRisk
- · SIMOPSInteractionRisk
- · RequirementCatalogue
- · RecordCatalogue
- · DecisionRight
- · RuleVersion
- · ProvenanceChain
- · GovernedOperationalEvent
- · CanonicalSemanticDictionary
- · WorkContext, LocationContext, ApplicablePETS, ApplicableCP, CriticalRiskContext, Equipment, SIMOPS, Restrictions, Lessons (prepopulation sources)
- · Field observations and edits
- · IPERCContinuoRecord { rows[], lifecycleState, provenancePerField, version }
- · IPERCRow { taskStep, hazard, risk, control, residualRisk, responsible, origin, confirmationState }
- · ConfirmedLocation_ID
- · Applicable document set evaluated
- · Crew observed
- · Every row records origin (SYSTEM_PREPOPULATED or FIELD_OBSERVED) and its confirmation lineage
- · Field edits preserve the superseded source-derived value as prior provenance rather than deleting it
- · Corporate risk standards / critical-risk taxonomy
- · PETS/CP document source
- · Lessons-learned source
- · PrepopulationRuleConfig
- · MandatoryRowClassConfig
- · CrossReviewTriggerConfig
- · RULE-IPERC-PREPOPULATION
- · RULE-IPERC-RESIDUAL-RISK-ACCEPTANCE
- · RULE-IPERC-REASSESS-TRIGGER
- · DecisionRight: CONFIRM_IPERC
- · DecisionRight: REVIEW_IPERC
- · DecisionRight: AUTHORIZE_IPERC
- · Attributable field edit identity
- · Responsible party referenced by governed person reference only
- · SYSTEM_PREPOPULATED
- · FIELD_OBSERVED
- · HUMAN_CONFIRMED
- · SUPERVISOR_REVIEWED
- · AUTHORIZED
- · REASSESS_REQUIRED
- · CLOSED
- · SYSTEM_PREPOPULATED → FIELD_OBSERVED → HUMAN_CONFIRMED → SUPERVISOR_REVIEWED → AUTHORIZED → CLOSED
- · AUTHORIZED → REASSESS_REQUIRED (on any governed trigger)
- · REASSESS_REQUIRED → HUMAN_CONFIRMED (re-entry, re-authorization required)
- · SYSTEM_PREPOPULATED → AUTHORIZED
- · SYSTEM_PREPOPULATED → HUMAN_CONFIRMED without a field confirmation act
- · REASSESS_REQUIRED → AUTHORIZED without re-confirmation
- · IPERCAuthorizedWhileMaterialDeltaOpen
- · AuthorizedWithoutDecisionRight
- · IPC-RC-01 CREW_CHANGE
- · IPC-RC-02 LOCATION_CHANGE
- · IPC-RC-03 TASK_CHANGE
- · IPC-RC-04 DOCUMENT_REVISION_CHANGE
- · IPC-RC-05 NEW_HAZARD
- · IPC-RC-06 CONTROL_CHANGE
- · IPC-RC-07 SIMOPS_CHANGE
- · IPC-RC-08 HOLD_POINT_REACHED
- · IPC-RC-09 CROSS_REVIEW_REQUIRED
- · IPC-RC-10 RESIDUAL_RISK_NOT_ACCEPTED
- · MATERIAL_DELTA_RAISED
- · DOCUMENT_REVISION_CHANGE_DETECTED
- · CREW_CHANGE_DETECTED
- · SIMOPS_STATE_CHANGED
- · IPERC_PREPOPULATED
- · IPERC_CONFIRMED
- · IPERC_REVIEWED
- · IPERC_AUTHORIZED
- · IPERC_REASSESS_RAISED
- · IPERC_CLOSED
- · propose hazards/controls from lessons and PETS as AI_ADVISORY_OUTPUT
- · confirming a row
- · accepting residual risk
- · authorizing
- · removing a prepopulated hazard
- · AP-05-1: SYSTEM_PREPOPULATED ≠ HUMAN_CONFIRMED ≠ AUTHORIZED enforced by transitions
- · AP-05-2: no field edit destroys source-derived provenance
- · AP-05-3: all nine change triggers map to a governed reason code
- · EXTERNAL_VALIDATION_DEPENDENCY: ES&H owner confirmation of the IPERC Continuo lifecycle against site legal requirements
- · CONTRACT_DEFINITION_GAP: cross-review trigger thresholds await configuration governance
FC-FPSO-06 · FieldDeltaAssessment
REV0 · parent PH6A-IADA-REV1
Compare the expected operational context with the observed field context and determine whether reassessment is required.
- · inheriting prior authorization because contexts are similar
- · closing a delta without an owner disposition
- · weighting deltas into a single score
- · LocationOperationalContext
- · JobCard
- · Equipment
- · SIMOPSInteractionRisk
- · RuleVersion
- · GovernedOperationalEvent
- · ProvenanceChain
- · ExpectedOperationalContext snapshot (pinned)
- · ObservedFieldContext (field-entered / retrieved)
- · MaterialityRuleVersion
- · FieldDeltaAssessment { categoryResults[], verdict, reasonCodes[], dispositionOwner }
- · Expected context pinned with version
- · Observed context captured for every mandatory category
- · Verdict recorded with per-category evidence; MATERIAL_DELTA blocks authorization until dispositioned
- · Governing materiality configuration owner
- · Environmental, SIMOPS and document-revision feeds
- · MaterialityThresholdConfig per delta category
- · RULE-DELTA-MATERIALITY (categorical, non-compensatory)
- · DecisionRight: DISPOSITION_MATERIAL_DELTA
- · Attributable observation capture
- · Crew delta expressed as decision facts only
- · DELTA_NOT_ASSESSED
- · DELTA_ASSESSED
- · NO_MATERIAL_DELTA
- · MATERIAL_DELTA_REQUIRES_REASSESSMENT
- · DELTA_DISPOSITIONED
- · DELTA_NOT_ASSESSED → DELTA_ASSESSED
- · DELTA_ASSESSED → NO_MATERIAL_DELTA | MATERIAL_DELTA_REQUIRES_REASSESSMENT
- · MATERIAL_DELTA_REQUIRES_REASSESSMENT → DELTA_DISPOSITIONED (reassessment completed)
- · MATERIAL_DELTA_REQUIRES_REASSESSMENT → NO_MATERIAL_DELTA without reassessment
- · DELTA_NOT_ASSESSED → authorization downstream
- · IPERCAuthorizedWhileMaterialDeltaOpen
- · PackageAuthorizedWithMandatoryItemIncomplete
- · DLT-RC-01 LOCATION_DELTA
- · DLT-RC-02 CREW_DELTA
- · DLT-RC-03 EQUIPMENT_DELTA
- · DLT-RC-04 TOOL_DELTA
- · DLT-RC-05 ENVIRONMENT_DELTA
- · DLT-RC-06 SIMOPS_DELTA
- · DLT-RC-07 ACCESS_DELTA
- · DLT-RC-08 RESTRICTION_DELTA
- · DLT-RC-09 DOCUMENT_REVISION_DELTA
- · DLT-RC-10 CRITICAL_CONTROL_DELTA
- · DLT-RC-11 UNEXPECTED_HAZARD
- · LOCATION_CHANGE_DETECTED
- · CREW_CHANGE_DETECTED
- · DOCUMENT_REVISION_CHANGE_DETECTED
- · SIMOPS_STATE_CHANGED
- · CRITICAL_CONTROL_STATE_CHANGED
- · DELTA_ASSESSED
- · MATERIAL_DELTA_RAISED
- · MATERIAL_DELTA_DISPOSITIONED
- · flag candidate deltas as advisory
- · declaring NO_MATERIAL_DELTA
- · dispositioning a delta
- · AP-06-1: similarity never inherits prior authorization
- · AP-06-2: unassessable ⇒ material (fail-closed)
- · AP-06-3: all eleven delta categories carry a reason code
- · EXTERNAL_VALIDATION_DEPENDENCY: materiality thresholds per category require owner definition
FC-FPSO-07 · ToolReadiness
REV0 · parent PH6A-IADA-REV1
Establish tool readiness as a governed capability distinct from equipment readiness, based on physical verification rather than list presence.
- · issuing tool certifications
- · treating a preselected checkbox as physical verification
- · aggregating tool states into a score
- · Equipment
- · RequirementCatalogue
- · RecordCatalogue
- · RuleVersion
- · GovernedOperationalEvent
- · ProvenanceChain
- · DecisionRight
- · RequiredToolSet for activity
- · Tool register entries
- · Field verification acts
- · ToolReadinessRecord { tools[], verdict, reasonCodes[] }
- · ToolItem { Tool_ID, ToolClass, RequiredForActivity, InspectionRequirement, InspectionState, CertificationRequirement, CertificationState, Condition, Restriction, Validity }
- · Activity resolved so the required tool set is determinable
- · TOOL_READY only after a physical verification act per required tool
- · Tool inspection/certification authority
- · Tool register source (where federated)
- · RequiredToolByActivityConfig
- · InspectionColourCodeConfig
- · RULE-TOOL-REQUIRED-SET
- · RULE-TOOL-READINESS (conjunctive)
- · DecisionRight: VERIFY_TOOL_READINESS
- · Attributable verifier identity
- · None beyond verifier attribution
- · TOOL_LISTED
- · TOOL_VERIFICATION_PENDING
- · TOOL_READY
- · TOOL_NOT_READY
- · TOOL_UNVERIFIABLE
- · TOOL_QUARANTINED
- · TOOL_LISTED → TOOL_VERIFICATION_PENDING → TOOL_READY | TOOL_NOT_READY | TOOL_UNVERIFIABLE
- · TOOL_NOT_READY → TOOL_QUARANTINED
- · TOOL_LISTED → TOOL_READY without a physical verification act
- · ToolReadyWithRequiredInspectionInvalid
- · TLR-RC-01 INSPECTION_EXPIRED
- · TLR-RC-02 INSPECTION_NOT_PERFORMED
- · TLR-RC-03 CERTIFICATION_INVALID
- · TLR-RC-04 CONDITION_DEFECTIVE
- · TLR-RC-05 TOOL_ABSENT
- · TLR-RC-06 RESTRICTION_ON_TOOL
- · TOOL_REGISTER_UPDATED
- · TOOL_INSPECTION_RECORDED
- · TOOL_VERIFIED
- · TOOL_NOT_READY_RAISED
- · TOOL_QUARANTINED
- · propose the required tool set as advisory
- · marking a tool verified or ready
- · clearing an expired inspection
- · AP-07-1: TOOL_LISTED ≠ TOOL_READY structurally
- · AP-07-2: preselected checks are impossible — verification requires an attributable act
- · AP-07-3: ToolReadiness is separate from EquipmentReadiness in the item catalogue
- · EXTERNAL_VALIDATION_DEPENDENCY: tool inspection regime and colour-code policy owner confirmation
FC-FPSO-08 · DigitalSignatureAssurance
REV0 · parent PH6A-IADA-REV1
Define the functional assurance contract that binds identity, authority, content and version at the moment of signing — without selecting technology or asserting legal validity.
- · selecting a signature technology or provider
- · asserting legal sufficiency or equivalence
- · issuing credentials
- · manufacturing authority the signer does not hold
- · DecisionRight
- · GovernedOperationalEvent
- · ProvenanceChain
- · RecordCatalogue
- · RuleVersion
- · Object_ID + ObjectVersion
- · SignerIdentity + CredentialStatus
- · DecisionRight resolution
- · ContentIntegrityReference
- · SignatureMethod
- · SignatureAssuranceRecord { Object_ID, ObjectVersion, SignerIdentity, DecisionRight, SigningTimestamp, SignatureMethod, CredentialStatus, ContentIntegrityReference, PreviousState, NewState }
- · Signer authenticated
- · DecisionRight resolved for this object and decision
- · Content integrity reference computable
- · Signature valid only for the exact ObjectVersion signed
- · State transition recorded with previous and new state
- · Identity provider (authoritative for identity)
- · Authority engine (authoritative for decision rights)
- · Trust service / timestamp authority (if adopted)
- · SignatureMethodByObjectClassConfig
- · AssuranceLevelConfig
- · RULE-SIG-BINDING
- · RULE-SIG-VERSION-INVALIDATION
- · DecisionRight required per signed object class
- · Credential status verification at signing time
- · Tamper-evident content integrity reference
- · Signer attributes limited to identity reference and credential status
- · SIGNATURE_NOT_REQUIRED
- · SIGNATURE_REQUIRED
- · SIGNATURE_PENDING
- · SIGNED
- · SIGNATURE_SUPERSEDED_BY_VERSION_CHANGE
- · SIGNATURE_REJECTED
- · SIGNATURE_UNAVAILABLE
- · SIGNATURE_REQUIRED → SIGNATURE_PENDING → SIGNED | SIGNATURE_REJECTED | SIGNATURE_UNAVAILABLE
- · SIGNED → SIGNATURE_SUPERSEDED_BY_VERSION_CHANGE (on content change)
- · SIGNATURE_SUPERSEDED_BY_VERSION_CHANGE → SIGNED without a new signing act
- · SIGNATURE_PENDING → SIGNED without DecisionRight
- · SignedVersionDifferentFromCurrentVersion
- · AuthorizedWithoutDecisionRight
- · SIG-RC-01 DECISION_RIGHT_ABSENT
- · SIG-RC-02 CREDENTIAL_INVALID
- · SIG-RC-03 CONTENT_CHANGED_AFTER_SIGNATURE
- · SIG-RC-04 IDENTITY_SERVICE_UNAVAILABLE
- · SIG-RC-05 SIGNATURE_METHOD_NOT_PERMITTED_FOR_OBJECT
- · SIG-RC-06 SIGNER_DECLINED
- · OBJECT_VERSION_CHANGED
- · CREDENTIAL_STATUS_CHANGED
- · SIGNATURE_APPLIED
- · SIGNATURE_INVALIDATED_BY_VERSION_CHANGE
- · SIGNATURE_REJECTED
- · summarise what is being signed as advisory
- · signing
- · asserting legal validity
- · selecting signature method for a decision
- · AP-08-1: signature binds all ten mandatory elements
- · AP-08-2: content change invalidates the prior signature for the new version
- · AP-08-3: acknowledgement / electronic signature / digital signature are distinguished without legal equivalence claims
- · EXTERNAL_VALIDATION_DEPENDENCY: LEGAL_REQUIREMENTS
- · EXTERNAL_VALIDATION_DEPENDENCY: CORPORATE_REQUIREMENTS
- · EXTERNAL_VALIDATION_DEPENDENCY: CLIENT_REQUIREMENTS
- · EXTERNAL_VALIDATION_DEPENDENCY: IDENTITY_PROVIDER selection
- · EXTERNAL_VALIDATION_DEPENDENCY: TRUST_SERVICE selection
§11 · Signature tier distinction
No legal equivalence asserted
| Tier | Binds | Does not assert |
|---|---|---|
| ElectronicAcknowledgement | identity reference + timestamp + object version viewed | authority to decide, or legal signature effect |
| ElectronicSignature | identity + decision right + object version + content integrity reference | cryptographic non-repudiation or legal equivalence to a handwritten signature |
| DigitalSignature | cryptographic key material bound to identity, with integrity and timestamp evidence | jurisdictional legal sufficiency without a legal determination |
K · Cross-Contract Dependency Map
| From | To | Relation |
|---|---|---|
| FC-FPSO-01 | FC-FPSO-02 | ConfirmedLocation_ID scopes the retrieval context |
| FC-FPSO-01 | FC-FPSO-03 | ConfirmedLocation_ID is a package precondition |
| FC-FPSO-01 | FC-FPSO-06 | LOCATION_CHANGED feeds the delta assessment |
| FC-FPSO-02 | FC-FPSO-05 | Applicable PETS/CP feed IPERC prepopulation |
| FC-FPSO-02 | FC-FPSO-06 | Revision change is a delta category |
| FC-FPSO-03 | FC-FPSO-04 | CrewConfirmation is a package item |
| FC-FPSO-03 | FC-FPSO-05 | IPERC Continuo is a mandatory package item where applicable |
| FC-FPSO-03 | FC-FPSO-07 | ToolReadiness is a package item, distinct from EquipmentReadiness |
| FC-FPSO-04 | FC-FPSO-06 | Crew change is a delta category |
| FC-FPSO-06 | FC-FPSO-03 | MATERIAL_DELTA blocks package authorization |
| FC-FPSO-06 | FC-FPSO-05 | MATERIAL_DELTA forces IPERC REASSESS_REQUIRED |
| FC-FPSO-08 | FC-FPSO-03 | Package authorization requires a bound signature act |
| FC-FPSO-08 | FC-FPSO-05 | IPERC confirmation/review/authorization each require binding |
L · State / Transition Catalogue
| Contract | States | Transitions | Forbidden |
|---|---|---|---|
| FC-FPSO-01 | 8 | 6 | 2 |
| FC-FPSO-02 | 11 | 3 | 2 |
| FC-FPSO-03 | 9 | 5 | 2 |
| FC-FPSO-04 | 6 | 4 | 2 |
| FC-FPSO-05 | 7 | 3 | 3 |
| FC-FPSO-06 | 5 | 3 | 2 |
| FC-FPSO-07 | 6 | 2 | 1 |
| FC-FPSO-08 | 7 | 2 | 2 |
§13 · Pure Core / Effectful Shell
| Behaviour | Classification | Contract |
|---|---|---|
| Candidate selection from a location snapshot | PURE CORE | FC-FPSO-01 |
| GPS position read | EFFECTFUL SHELL | FC-FPSO-01 |
| Applicability evaluation over retrieved metadata | PURE CORE | FC-FPSO-02 |
| Corporate document system retrieval | EFFECTFUL SHELL | FC-FPSO-02 |
| Package completeness evaluation (conjunctive) | PURE CORE | FC-FPSO-03 |
| Persistence of package state | EFFECTFUL SHELL | FC-FPSO-03 |
| Crew rule evaluation over decision facts | PURE CORE | FC-FPSO-04 |
| Identity service call | EFFECTFUL SHELL | FC-FPSO-04 |
| IPERC prepopulation rule application | PURE CORE | FC-FPSO-05 |
| Delta materiality evaluation | PURE CORE | FC-FPSO-06 |
| Tool readiness conjunction | PURE CORE | FC-FPSO-07 |
| Signature binding validation | PURE CORE | FC-FPSO-08 |
| Signature/trust service invocation | EFFECTFUL SHELL | FC-FPSO-08 |
M · Invalid-State Catalogue
§17 — structurally illegal combinations
| ID | Invalid state | Prevented by | Contracts |
|---|---|---|---|
| IS-01 | AuthorizedWithoutDecisionRight | AuthorityEngine gate on every authorization transition | FC-FPSO-03, FC-FPSO-05, FC-FPSO-08 |
| IS-02 | SignedVersionDifferentFromCurrentVersion | RULE-SIG-VERSION-INVALIDATION | FC-FPSO-08 |
| IS-03 | ConfirmedLocationWithoutLocationCandidateOrManualSelection | Confirmation requires a candidate or manual selection antecedent | FC-FPSO-01 |
| IS-04 | IPERCAuthorizedWhileMaterialDeltaOpen | Open MATERIAL_DELTA forces REASSESS_REQUIRED | FC-FPSO-05, FC-FPSO-06 |
| IS-05 | PackageAuthorizedWithMandatoryItemIncomplete | Conjunctive completeness predicate | FC-FPSO-03 |
| IS-06 | ToolReadyWithRequiredInspectionInvalid | RULE-TOOL-READINESS conjunction | FC-FPSO-07 |
| IS-07 | CrewValidWhileMandatoryCompetencyInvalid | RULE-CREW-COMPETENCY-VALIDITY | FC-FPSO-04 |
| IS-08 | RetrievedDocumentTreatedAsApplicableWithoutApplicabilityEvaluation | ApplicabilityStatus is mandatory on every candidate | FC-FPSO-02 |
N · ReasonCode Catalogue
§16 — no reasoning encoded only in free text
| Code | Meaning | Contract |
|---|---|---|
| LOC-RC-01 | ACCURACY_BELOW_THRESHOLD | FC-FPSO-01 |
| LOC-RC-02 | NO_CANDIDATE_IN_RADIUS | FC-FPSO-01 |
| LOC-RC-03 | AMBIGUOUS_CANDIDATE_SET | FC-FPSO-01 |
| LOC-RC-04 | POSITION_SOURCE_UNAVAILABLE | FC-FPSO-01 |
| LOC-RC-05 | MANUAL_OVERRIDE_APPLIED | FC-FPSO-01 |
| LOC-RC-06 | LOCATION_CHANGED_MID_SHIFT | FC-FPSO-01 |
| DOC-RC-01 | SOURCE_UNAVAILABLE | FC-FPSO-02 |
| DOC-RC-02 | METADATA_INSUFFICIENT | FC-FPSO-02 |
| DOC-RC-03 | MULTIPLE_ACTIVE_REVISIONS | FC-FPSO-02 |
| DOC-RC-04 | SUPERSEDED_AFTER_RETRIEVAL | FC-FPSO-02 |
| DOC-RC-05 | DOCUMENT_NOT_FOUND | FC-FPSO-02 |
| DOC-RC-06 | CONFLICTING_SOURCE_RECORDS | FC-FPSO-02 |
| PKG-RC-01 | MANDATORY_ITEM_INCOMPLETE | FC-FPSO-03 |
| PKG-RC-02 | MANDATORY_ITEM_UNVERIFIABLE | FC-FPSO-03 |
| PKG-RC-03 | MATERIAL_DELTA_OPEN | FC-FPSO-03 |
| PKG-RC-04 | CRITICAL_CONTROL_NOT_VERIFIED | FC-FPSO-03 |
| PKG-RC-05 | SIMOPS_CUMULATIVE_BLOCK | FC-FPSO-03 |
| PKG-RC-06 | AUTHORITY_UNRESOLVED | FC-FPSO-03 |
| PKG-RC-07 | RESTRICTION_ACTIVE | FC-FPSO-03 |
| CRW-RC-01 | MANDATORY_ROLE_ABSENT | FC-FPSO-04 |
| CRW-RC-02 | COMPETENCY_EXPIRED | FC-FPSO-04 |
| CRW-RC-03 | COMPETENCY_UNVERIFIABLE | FC-FPSO-04 |
| CRW-RC-04 | FITNESS_NOT_CONFIRMED | FC-FPSO-04 |
| CRW-RC-05 | IDENTITY_NOT_CONFIRMED | FC-FPSO-04 |
| CRW-RC-06 | UNPLANNED_PERSON_PRESENT | FC-FPSO-04 |
| IPC-RC-01 | CREW_CHANGE | FC-FPSO-05 |
| IPC-RC-02 | LOCATION_CHANGE | FC-FPSO-05 |
| IPC-RC-03 | TASK_CHANGE | FC-FPSO-05 |
| IPC-RC-04 | DOCUMENT_REVISION_CHANGE | FC-FPSO-05 |
| IPC-RC-05 | NEW_HAZARD | FC-FPSO-05 |
| IPC-RC-06 | CONTROL_CHANGE | FC-FPSO-05 |
| IPC-RC-07 | SIMOPS_CHANGE | FC-FPSO-05 |
| IPC-RC-08 | HOLD_POINT_REACHED | FC-FPSO-05 |
| IPC-RC-09 | CROSS_REVIEW_REQUIRED | FC-FPSO-05 |
| IPC-RC-10 | RESIDUAL_RISK_NOT_ACCEPTED | FC-FPSO-05 |
| DLT-RC-01 | LOCATION_DELTA | FC-FPSO-06 |
| DLT-RC-02 | CREW_DELTA | FC-FPSO-06 |
| DLT-RC-03 | EQUIPMENT_DELTA | FC-FPSO-06 |
| DLT-RC-04 | TOOL_DELTA | FC-FPSO-06 |
| DLT-RC-05 | ENVIRONMENT_DELTA | FC-FPSO-06 |
| DLT-RC-06 | SIMOPS_DELTA | FC-FPSO-06 |
| DLT-RC-07 | ACCESS_DELTA | FC-FPSO-06 |
| DLT-RC-08 | RESTRICTION_DELTA | FC-FPSO-06 |
| DLT-RC-09 | DOCUMENT_REVISION_DELTA | FC-FPSO-06 |
| DLT-RC-10 | CRITICAL_CONTROL_DELTA | FC-FPSO-06 |
| DLT-RC-11 | UNEXPECTED_HAZARD | FC-FPSO-06 |
| TLR-RC-01 | INSPECTION_EXPIRED | FC-FPSO-07 |
| TLR-RC-02 | INSPECTION_NOT_PERFORMED | FC-FPSO-07 |
| TLR-RC-03 | CERTIFICATION_INVALID | FC-FPSO-07 |
| TLR-RC-04 | CONDITION_DEFECTIVE | FC-FPSO-07 |
| TLR-RC-05 | TOOL_ABSENT | FC-FPSO-07 |
| TLR-RC-06 | RESTRICTION_ON_TOOL | FC-FPSO-07 |
| SIG-RC-01 | DECISION_RIGHT_ABSENT | FC-FPSO-08 |
| SIG-RC-02 | CREDENTIAL_INVALID | FC-FPSO-08 |
| SIG-RC-03 | CONTENT_CHANGED_AFTER_SIGNATURE | FC-FPSO-08 |
| SIG-RC-04 | IDENTITY_SERVICE_UNAVAILABLE | FC-FPSO-08 |
| SIG-RC-05 | SIGNATURE_METHOD_NOT_PERMITTED_FOR_OBJECT | FC-FPSO-08 |
| SIG-RC-06 | SIGNER_DECLINED | FC-FPSO-08 |
O · Event Catalogue
GovernedOperationalEvent schema unchanged
| Event | Contract | Domain |
|---|---|---|
| LOCATION_CANDIDATES_DERIVED | FC-FPSO-01 | FIELD_PRESTART |
| LOCATION_CONFIRMED | FC-FPSO-01 | FIELD_PRESTART |
| LOCATION_CHANGE_DETECTED | FC-FPSO-01 | FIELD_PRESTART |
| DOCUMENT_CANDIDATE_SET_DERIVED | FC-FPSO-02 | FIELD_PRESTART |
| DOCUMENT_REVISION_CHANGE_DETECTED | FC-FPSO-02 | FIELD_PRESTART |
| DOCUMENT_CONFLICT_RAISED | FC-FPSO-02 | FIELD_PRESTART |
| PACKAGE_COMPOSED | FC-FPSO-03 | FIELD_PRESTART |
| PACKAGE_COMPLETENESS_EVALUATED | FC-FPSO-03 | FIELD_PRESTART |
| PACKAGE_AUTHORIZED | FC-FPSO-03 | FIELD_PRESTART |
| PACKAGE_REASSESS_RAISED | FC-FPSO-03 | FIELD_PRESTART |
| CREW_CONFIRMED | FC-FPSO-04 | FIELD_PRESTART |
| CREW_EXCEPTION_RAISED | FC-FPSO-04 | FIELD_PRESTART |
| CREW_CHANGE_DETECTED | FC-FPSO-04 | FIELD_PRESTART |
| IPERC_PREPOPULATED | FC-FPSO-05 | FIELD_PRESTART |
| IPERC_CONFIRMED | FC-FPSO-05 | FIELD_PRESTART |
| IPERC_REVIEWED | FC-FPSO-05 | FIELD_PRESTART |
| IPERC_AUTHORIZED | FC-FPSO-05 | FIELD_PRESTART |
| IPERC_REASSESS_RAISED | FC-FPSO-05 | FIELD_PRESTART |
| IPERC_CLOSED | FC-FPSO-05 | FIELD_PRESTART |
| DELTA_ASSESSED | FC-FPSO-06 | FIELD_PRESTART |
| MATERIAL_DELTA_RAISED | FC-FPSO-06 | FIELD_PRESTART |
| MATERIAL_DELTA_DISPOSITIONED | FC-FPSO-06 | FIELD_PRESTART |
| TOOL_VERIFIED | FC-FPSO-07 | FIELD_PRESTART |
| TOOL_NOT_READY_RAISED | FC-FPSO-07 | FIELD_PRESTART |
| TOOL_QUARANTINED | FC-FPSO-07 | FIELD_PRESTART |
| SIGNATURE_APPLIED | FC-FPSO-08 | FIELD_PRESTART |
| SIGNATURE_INVALIDATED_BY_VERSION_CHANGE | FC-FPSO-08 | FIELD_PRESTART |
| SIGNATURE_REJECTED | FC-FPSO-08 | FIELD_PRESTART |
§14–15 · Concurrency & Idempotency
Every contract defines an idempotency key so repeated external triggers cannot duplicate package items, signatures, approvals or operational events, nor silently change state.
P · Contract Requirement Traceability Matrix
§18 — no orphaned AIA capability
| AIA capability | Contract | Parent contract | Rule / configuration | Acceptance predicate |
|---|---|---|---|---|
| Resolve physical position to canonical location | FC-FPSO-01 | LocationOperationalContext | RULE-LOC-CANDIDATE-SELECTION / ProximityRadiusConfig | AP-01-1 |
| Human confirmation of working location | FC-FPSO-01 | DecisionRight | CONFIRM_WORK_LOCATION | AP-01-1 |
| Degraded positioning behaviour | FC-FPSO-01 | ProvenanceChain | AccuracyThresholdConfig | AP-01-3 |
| Contextual controlled-document surfacing | FC-FPSO-02 | RequirementCatalogue | ContextToDocumentClassApplicabilityConfig | AP-02-1 |
| Revision integrity and supersession handling | FC-FPSO-02 | RecordCatalogue | RULE-DOC-REVISION-SELECTION | AP-02-2 |
| Pre-start item orchestration | FC-FPSO-03 | JobCard / WorkPackage | MandatoryItemApplicabilityConfig | AP-03-1 |
| Non-compensatory package completeness | FC-FPSO-03 | RuleVersion | RULE-PKG-COMPLETENESS | AP-03-2 |
| Critical control verification reference | FC-FPSO-03 | ActivityRisk | ItemClassCatalogue | AP-03-1 |
| SIMOPS condition surfaced at pre-start | FC-FPSO-03 | SIMOPSInteractionRisk | cumulative SIMOPS (parent) | AP-03-1 |
| Crew presence and identity confirmation | FC-FPSO-04 | JobCard | RequiredRoleMatrixConfig | AP-04-1 |
| Competency / training / fitness decision facts | FC-FPSO-04 | RequirementCatalogue | RULE-CREW-COMPETENCY-VALIDITY | AP-04-2 |
| IPERC Continuo as a governed record | FC-FPSO-05 | RecordCatalogue | RULE-IPERC-PREPOPULATION | AP-05-1 |
| Prepopulation without authorship substitution | FC-FPSO-05 | ProvenanceChain | PrepopulationRuleConfig | AP-05-2 |
| Continuous reassessment triggers | FC-FPSO-05 | GovernedOperationalEvent | RULE-IPERC-REASSESS-TRIGGER | AP-05-3 |
| Expected vs observed field context | FC-FPSO-06 | LocationOperationalContext | RULE-DELTA-MATERIALITY | AP-06-1 |
| No inheritance of prior authorization | FC-FPSO-06 | DecisionRight | MaterialityThresholdConfig | AP-06-1 |
| Tool readiness distinct from equipment | FC-FPSO-07 | Equipment | RequiredToolByActivityConfig | AP-07-3 |
| Physical verification over list presence | FC-FPSO-07 | RecordCatalogue | RULE-TOOL-READINESS | AP-07-2 |
| Signature binds identity/authority/content/version | FC-FPSO-08 | DecisionRight | RULE-SIG-BINDING | AP-08-1 |
| Version change invalidates prior signature | FC-FPSO-08 | RuleVersion | RULE-SIG-VERSION-INVALIDATION | AP-08-2 |
| Signature tier distinction without legal claim | FC-FPSO-08 | CanonicalSemanticDictionary | SignatureMethodByObjectClassConfig | AP-08-3 |
OrphanedCapabilities = 0.
Q · Open Dependency Register
§19 — gaps are not converted into assumptions
| ID | Contract | Classification | Description | Owner |
|---|---|---|---|---|
| OD-01 | FC-FPSO-01 | EXTERNAL VALIDATION DEPENDENCY | Proximity radius and accuracy policy for location candidate derivation | Location steward (ADR-14 stewardship, unstaffed) |
| OD-02 | FC-FPSO-01 | EXTERNAL VALIDATION DEPENDENCY | Corporate policy on positional data retention and personnel-tracking prohibition | Data privacy owner |
| OD-03 | FC-FPSO-02 | EXTERNAL VALIDATION DEPENDENCY | Retrievable metadata fields and participation mode per document source | Document control owner |
| OD-04 | FC-FPSO-03 | CONTRACT DEFINITION GAP | Mandatory-item designation per activity class requires configuration governance (links F-DEAP-01) | Rule governance authority (ADR-16) |
| OD-05 | FC-FPSO-03 | EXTERNAL VALIDATION DEPENDENCY | Permit / isolation referenceable identifiers and states | Work control system owner |
| OD-06 | FC-FPSO-04 | EXTERNAL VALIDATION DEPENDENCY | Minimal decision-fact set acceptable under privacy and occupational health policy | Privacy + occupational health owners |
| OD-07 | FC-FPSO-05 | EXTERNAL VALIDATION DEPENDENCY | IPERC Continuo lifecycle validated against site legal and client requirements | ES&H authority |
| OD-08 | FC-FPSO-05 | CONTRACT DEFINITION GAP | Cross-review and hold-point trigger thresholds | Rule governance authority |
| OD-09 | FC-FPSO-06 | EXTERNAL VALIDATION DEPENDENCY | Materiality thresholds per delta category | ES&H + Construction authorities |
| OD-10 | FC-FPSO-07 | EXTERNAL VALIDATION DEPENDENCY | Tool inspection regime, certification classes and colour-code policy | Tools / equipment authority |
| OD-11 | FC-FPSO-08 | EXTERNAL VALIDATION DEPENDENCY | Legal, corporate and client signature requirements | Legal + corporate compliance |
| OD-12 | FC-FPSO-08 | EXTERNAL VALIDATION DEPENDENCY | Identity provider and trust service selection | Enterprise IAM authority (ADR-08) |
No open dependency has been converted into a design assumption. Where owner validation is absent, the contract records the gap and fails closed rather than adopting a default.
R · Contract Completeness Assessment
§3 — mandatory 38-element schema
| Contract | Elements | Result |
|---|---|---|
| FC-FPSO-01 | 40 / 38 | CONTRACT COMPLETE |
| FC-FPSO-02 | 40 / 38 | CONTRACT COMPLETE |
| FC-FPSO-03 | 40 / 38 | CONTRACT COMPLETE |
| FC-FPSO-04 | 40 / 38 | CONTRACT COMPLETE |
| FC-FPSO-05 | 40 / 38 | CONTRACT COMPLETE |
| FC-FPSO-06 | 40 / 38 | CONTRACT COMPLETE |
| FC-FPSO-07 | 40 / 38 | CONTRACT COMPLETE |
| FC-FPSO-08 | 40 / 38 | CONTRACT COMPLETE |
§21 · G-FPSO-02 — Contract Completeness
Evaluated, not frozen
| Contract | Def | State | Authority | Source | Failure | Concur | Idem | Prov | Predicates | Ambiguity |
|---|---|---|---|---|---|---|---|---|---|---|
| FC-FPSO-01 | YES | YES | YES | YES | YES | YES | YES | YES | YES | 1 |
| FC-FPSO-02 | YES | YES | YES | YES | YES | YES | YES | YES | YES | 1 |
| FC-FPSO-03 | YES | YES | YES | YES | YES | YES | YES | YES | YES | 2 |
| FC-FPSO-04 | YES | YES | YES | YES | YES | YES | YES | YES | YES | 1 |
| FC-FPSO-05 | YES | YES | YES | YES | YES | YES | YES | YES | YES | 2 |
| FC-FPSO-06 | YES | YES | YES | YES | YES | YES | YES | YES | YES | 1 |
| FC-FPSO-07 | YES | YES | YES | YES | YES | YES | YES | YES | YES | 0 |
| FC-FPSO-08 | YES | YES | YES | YES | YES | YES | YES | YES | YES | 2 |
All eight contracts satisfy the mandatory 38-element schema; state, authority, source, failure, concurrency, idempotency, provenance and acceptance-predicate elements are defined for every contract. Residual semantic ambiguity (10 items) is registered as open dependency, not as a definition gap masked by an assumption.
§22 · Required Final State
Definition output of record
Definition is not acceptance. This contract set was subsequently assured and frozen under PH6A-FPSO-FCA-REV0 (gate G-FPSO-03) — see the assurance sections below.
PH6A-FPSO-FCA-REV0 · A — Assurance Executive Decision
Independent functional architecture assurance · Design Assurance Evidence only
The eight descendant contracts are semantically closed after 9 controlled corrections. All internal semantic ambiguity is resolved; every remaining open item is a genuinely external owner decision that cannot be closed by design and does not make contract behaviour indeterminate. The set is fit to become Requirements of Record for implementation.
This is not an unconditional PASS: 12 external validation dependencies remain controlled-open and no operational evidence exists. Freeze governs specification, not readiness.
- · UI design
- · Route/component creation for the Pre-Start Board
- · Prototype behaviour
- · Demo scenarios and synthetic operational data
- · Operational simulation
- · Operational closure evidence
- · Any modification of PH6A-IADA-REV1
B · Input Integrity Assessment
Prompt 1 self-reporting recounted, not trusted
| Attribute | Claimed | Observed | Verdict | Note |
|---|---|---|---|---|
| ContractsDefined | 8 | 8 | CONFIRMED | — |
| ContractScopeDeviation | 0 | 0 | CONFIRMED | — |
| StatesReported | 60 | 59 | CONFIRMED WITH NOTE | Counted from permittedStates across the eight contracts. |
| TransitionsReported | 33 | 28 | CONFIRMED WITH NOTE | Recount from the definition module is authoritative over the reported figure. |
| ForbiddenTransitionsReported | 20 | 16 | CONFIRMED WITH NOTE | — |
| InvalidStatesReported | 8 | 8 | CONFIRMED | — |
| ReasonCodesReported | 55 | 58 | CONFIRMED WITH NOTE | — |
| EventsReported | 26 | 28 | CONFIRMED WITH NOTE | — |
| OrphanedCapabilities | 0 | 0 | CONFIRMED | — |
| OpenDependencies | 12 | 12 | CONFIRMED | — |
| ContractDefinitionGaps | 2 | 2 | CONFIRMED | — |
| ExternalValidationDependencies | 10 | 10 | CONFIRMED WITH NOTE | Register carries 10 EXTERNAL_VALIDATION_DEPENDENCY rows at OD level; contract-level clauses expand these to 12 distinct owner decisions at freeze (§AJ). |
| OpenSemanticAmbiguityCount | 10 | 10 | CONFIRMED | Self-reported completeness not accepted as assurance; each item reconciled individually in §C. |
INPUT_INTEGRITY = ACCEPTED_FOR_ASSURANCE. Prompt 1 self-reported completeness was recounted from the definition module rather than trusted; recounted values govern where they differ from the reported figures.
C · Open Semantic Ambiguity Reconciliation — all 10
OpenSemanticAmbiguityCount at freeze = 0
Corrected during assurance: 9 · resolved by existing contract: 1 · blocking: 0 · OpenSemanticAmbiguityCount_at_Freeze = 0.
D · Contract Definition Gap Reconciliation — both 2
ContractDefinitionGaps at freeze = 0
| ID | OD | Contract | Affected elements | Material | Correction | Residual external item | Outcome |
|---|---|---|---|---|---|---|---|
| GAP-01 | OD-04 | FC-FPSO-03 | Preconditions, Postconditions, StateTransition, RuleDependency, FailureBehaviour, AcceptancePredicate | YES | Contract now defines behaviour under absent mandatory-item configuration: completeness evaluates to COMPLETENESS_UNDETERMINABLE, the package cannot reach PACKAGE_COMPLETE, and reason code RC-PKG-CONFIG-ABSENT is emitted. The absence of configuration can never be read as 'not mandatory'. | Which items are mandatory per activity class — rule governance authority (ADR-16). | GAP CORRECTED |
| GAP-02 | OD-08 | FC-FPSO-05 | StateTransition, RuleDependency, FailureBehaviour, AcceptancePredicate, HumanValidationPoint | YES | Contract now defines behaviour under absent cross-review/hold-point thresholds: the trigger evaluates to UNDETERMINABLE for the affected risk class, AUTHORIZED is unreachable for that class, and reason code RC-IPERC-THRESHOLD-ABSENT is emitted. Threshold values are configuration, not contract semantics. | Threshold values per risk class — ES&H + rule governance authority. | GAP CORRECTED |
E · External Validation Dependency Assessment
§5 controlled-open test · CurrentAssumption = NONE for all
| ID | Contract | Owner | Decision needed | Determ. | No auth. assumption | No source assumption | Failure defined | Failure behaviour until validated | Closure evidence |
|---|---|---|---|---|---|---|---|---|---|
| XD-01 | FC-FPSO-01 | Location steward (ADR-14 stewardship, unstaffed) | Proximity radius and positional accuracy policy per location class | YES | YES | YES | YES | No candidate is derived; LOCATION_CANDIDATE_UNAVAILABLE and manual selection with governed justification | Signed steward configuration decision |
| XD-02 | FC-FPSO-01 | Corporate data privacy owner | Positional data retention period and personnel-tracking prohibition scope | YES | YES | YES | YES | Position retained only as decision provenance for the confirmation event | Privacy owner written determination |
| XD-03 | FC-FPSO-02 | Document control owner (Aconex participation) | Retrievable metadata fields and participation mode per source | YES | YES | YES | YES | SOURCE_UNAVAILABLE / METADATA_INSUFFICIENT; retrieved documents cannot be marked applicable | Owner confirmation of participation mode and metadata contract |
| XD-04 | FC-FPSO-03 | Rule governance authority (ADR-16) | Mandatory-item designation per activity class | YES | YES | YES | YES | COMPLETENESS_UNDETERMINABLE; package cannot reach PACKAGE_COMPLETE | Approved mandatory-item matrix |
| XD-05 | FC-FPSO-03 | Work control system owner (Q4 / Engica) | Referenceable permit and isolation identifiers and states | YES | YES | YES | YES | Permit/isolation items remain NOT_VERIFIABLE and block completeness where mandatory | Owner confirmation of identifier and state contract |
| XD-06 | FC-FPSO-04 | Privacy + occupational health owners | Minimal decision-fact set exposed for fitness and competency | YES | YES | YES | YES | Fitness fact absent → NOT_CONFIRMED, never assumed fit | Joint owner determination |
| XD-07 | FC-FPSO-04 | Competency authority (Training/HR) | Which body issues authoritative competency facts and their validity semantics | YES | YES | YES | YES | Competency UNVERIFIABLE → crew member not valid for the mandatory role | Authority designation record |
| XD-08 | FC-FPSO-05 | ES&H authority | IPERC Continuo lifecycle validated against site legal and client requirements | YES | YES | YES | YES | Lifecycle as specified; no legal sufficiency asserted | ES&H written validation |
| XD-09 | FC-FPSO-05 | ES&H + rule governance authority | Cross-review and hold-point threshold values per risk class | YES | YES | YES | YES | Trigger UNDETERMINABLE → AUTHORIZED unreachable for that class | Approved threshold table |
| XD-10 | FC-FPSO-06 | ES&H + Construction authorities | Materiality thresholds per delta category | YES | YES | YES | YES | Delta classified UNDETERMINABLE → treated as material (fail safe) | Approved materiality matrix |
| XD-11 | FC-FPSO-07 | Tools / equipment authority | Inspection regime, certification classes and colour-code policy | YES | YES | YES | YES | Inspection validity UNVERIFIABLE → tool NOT_READY | Approved tool control standard |
| XD-12 | FC-FPSO-08 | Legal + corporate compliance and enterprise IAM (ADR-08) | Signature legal/corporate/client requirements, identity provider and trust service selection | YES | YES | YES | YES | Signature binds identity, authority, content and version; legal sufficiency NOT asserted; service unavailable → NOT_SIGNED | Legal determination + IAM/trust-service decision record |
Every dependency satisfies §5: behaviour deterministic, no authority assumed, no source authority assumed, no state meaning contingent on an unknown decision, failure behaviour defined, acceptance boundary defined. CurrentAssumption = NONE for all twelve; no temporary assumption was invented to enable freeze.
F · Contract Completeness Verification — 8/8
38 elements independently verified per contract
| Contract | Name | Elements | Material defects found | Verdict |
|---|---|---|---|---|
| FC-FPSO-01 | LocationAcquisitionService | 38 | F-FCA-01 location supersession semantics | COMPLETE AFTER CORRECTION |
| FC-FPSO-02 | ContextualDocumentRetrieval | 38 | F-FCA-02 revision election prohibition | COMPLETE AFTER CORRECTION |
| FC-FPSO-03 | PreStartPreventivePackage + PreStartPreventivePackageItem | 38 | F-FCA-03 absent-configuration fail-closed; F-FCA-04 post-preparation item invalidation | COMPLETE AFTER CORRECTION |
| FC-FPSO-04 | CrewConfirmationRecord | 38 | F-FCA-05 crew replacement non-inheritance | COMPLETE AFTER CORRECTION |
| FC-FPSO-05 | IPERCContinuo | 38 | F-FCA-06 review ≠ authorization; F-FCA-07 absent threshold fail-closed | COMPLETE AFTER CORRECTION |
| FC-FPSO-06 | FieldDeltaAssessment | 38 | F-FCA-08 dependency-scoped invalidation map | COMPLETE AFTER CORRECTION |
| FC-FPSO-07 | ToolReadiness | 38 | None | COMPLETE |
| FC-FPSO-08 | DigitalSignatureAssurance | 38 | F-FCA-09 signature idempotency & version conflict | COMPLETE AFTER CORRECTION |
G · Cross-Contract Collision Matrix
Duplicate domain objects = 0
| Pair | Collision class | Finding | Verdict |
|---|---|---|---|
| LocationAcquisition ↔ LocationOperationalContext | DuplicateObject / DuplicateStateAuthority | FC-FPSO-01 produces a LocationConfirmation referencing the parent Location_ID; it never creates or mutates LocationOperationalContext. Corrected supersession semantics (F-FCA-01) removed the implicit in-place replacement path. | COLLISION CORRECTED |
| ContextualDocumentRetrieval ↔ Applicability | ResponsibilityLeakage | Retrieval produces candidates with mandatory ApplicabilityStatus = NOT_EVALUATED; applicability evaluation remains the parent RequirementCatalogue/rule responsibility. Revision election prohibition (F-FCA-02) closed the residual leak. | COLLISION CORRECTED |
| PreventivePackage ↔ IPERC | HiddenSharedState | IPERC is referenced as a package item by identifier and version; the package never mirrors IPERC state. Item state derives from the referenced IPERC version, one-directional. | NO COLLISION |
| PreventivePackage ↔ PETAR | SemanticOverlap | PETAR applicability is a requirement-catalogue outcome consumed as an item; the package does not decide PETAR applicability. | NO COLLISION |
| CrewConfirmation ↔ DecisionRight | DuplicateStateAuthority | Crew confirmation produces presence/competency/fitness facts only. Corrected replacement semantics (F-FCA-05) removed role-slot inheritance, which was the only path to implicit DecisionRight transfer. | COLLISION CORRECTED |
| CrewConfirmation ↔ competency sources | DuplicateSourceAuthority | Competency facts are federated per person from the designated authority; the contract never issues competency. | NO COLLISION |
| FieldDelta ↔ Continuity | ContradictoryTransition | Delta assessment raises reassessment requirements; continuity state remains owned by the parent readiness model. Dependency-scoped map (F-FCA-08) removed the contradictory blanket-invalidation path. | COLLISION CORRECTED |
| FieldDelta ↔ IPERC | CircularDependency | IPERC consumes delta outcomes; delta consumes expected context, not IPERC state. No cycle: the dependency graph is acyclic (verified over FCD_DEPENDENCY_MAP). | NO COLLISION |
| ToolReadiness ↔ FunctionalReadiness | SemanticOverlap | Tool readiness is an input fact to package completeness; it does not compute functional readiness or equipment readiness. | NO COLLISION |
| DigitalSignatureAssurance ↔ AuthorityEngine | DuplicateStateAuthority | Signature binds an already-granted DecisionRight exercise; it never grants, extends or repairs authority. Signature on an unauthorized decision is invalid by construction. | NO COLLISION |
H · State Normalization Assessment
States govern behaviour; they do not decorate workflow
| Item | Contract | Observation | Disposition | Rationale |
|---|---|---|---|---|
| LOCATION_CANDIDATE_DERIVED vs LOCATION_CANDIDATE_AMBIGUOUS | FC-FPSO-01 | Both precede confirmation but permit different transitions (confirm vs manual-selection-only). | RETAINED AS STATE | Behaviourally distinct: ambiguity forbids single-candidate confirmation. |
| RETRIEVED / APPLICABILITY_NOT_EVALUATED | FC-FPSO-02 | APPLICABILITY_NOT_EVALUATED did not alter permitted transitions beyond RETRIEVED. | RECLASSIFIED | Reclassified as a mandatory attribute (ApplicabilityStatus) of RETRIEVED — attribute, not state. RETRIEVED ≠ APPLICABLE preserved without a decorative state. |
| PACKAGE_PREPARED vs PACKAGE_COMPLETE | FC-FPSO-03 | Distinct transition sets (items mutable vs completeness evaluated). | RETAINED AS STATE | PACKAGE_EXISTS ≠ PACKAGE_COMPLETE ≠ AUTHORIZED is a governing invariant. |
| COMPLETENESS_UNDETERMINABLE | FC-FPSO-03 | Introduced by correction F-FCA-03. | RETAINED AS STATE | Alters permitted transitions: forbids progression to PACKAGE_COMPLETE. Not a reason code. |
| SUPERVISOR_REVIEWED vs AUTHORIZED | FC-FPSO-05 | Prompt 1 permitted an implicit collapse. | RETAINED AS STATE | Separation is an authority invariant (F-FCA-06). |
| PENDING_REVIEW / AWAITING_REVIEW duplication scan | ALL | No behaviourally identical duplicate state names found across the eight contracts. | RETAINED AS STATE | No consolidation warranted; counts were not reduced cosmetically. |
| SIGNATURE_VERSION_CONFLICT | FC-FPSO-08 | Introduced by correction F-FCA-09. | RETAINED AS STATE | Governs an explicit recovery transition rather than an error label. |
I · ReasonCode Normalization Assessment
| Item | Contract | Observation | Disposition | Rationale |
|---|---|---|---|---|
| RC-LOC-ACCURACY-LOW / RC-LOC-GPS-UNAVAILABLE | FC-FPSO-01 | Different cause, same fallback. | RETAINED AS REASON CODE | Different owner and different recovery condition (device vs environment). |
| RC-DOC-NOT-FOUND / RC-DOC-SOURCE-UNAVAILABLE | FC-FPSO-02 | Distinguish absence from unreachability. | RETAINED AS REASON CODE | Different owner (document control vs integration) and different recovery. |
| RC-DOC-REVISION-AMBIGUOUS | FC-FPSO-02 | Added by F-FCA-02. | RETAINED AS REASON CODE | Names a governed cause requiring document-owner resolution. |
| RC-PKG-ITEM-MISSING / RC-PKG-ITEM-INCOMPLETE | FC-FPSO-03 | Materially identical response, ownership and evidence. | CONSOLIDATED | Consolidated to RC-PKG-MANDATORY-ITEM-NOT-SATISFIED; item presence is an attribute of the item record. |
| RC-PKG-CONFIG-ABSENT | FC-FPSO-03 | Added by F-FCA-03. | RETAINED AS REASON CODE | Distinct cause with a distinct owner (rule governance). |
| RC-CREW-NOT-PRESENT / RC-CREW-NOT-AUTHENTICATED | FC-FPSO-04 | Distinct evidence and distinct remedy. | RETAINED AS REASON CODE | Presence ≠ identity assurance. |
| RC-IPERC-THRESHOLD-ABSENT | FC-FPSO-05 | Added by F-FCA-07. | RETAINED AS REASON CODE | Configuration absence is a governed cause, not a generic error. |
| RC-DELTA-UNCLASSIFIED / RC-DELTA-THRESHOLD-ABSENT | FC-FPSO-06 | Same response (treat as material), same owner, same evidence. | CONSOLIDATED | Consolidated to RC-DELTA-MATERIALITY-UNDETERMINABLE. |
| RC-SIG-VERSION-CONFLICT | FC-FPSO-08 | Added by F-FCA-09. | RETAINED AS REASON CODE | Distinct recovery: re-present current version for a new signature. |
| Free-text reason capture | ALL | No contract permits uncontrolled free-text as a governed cause. | RETAINED AS REASON CODE | Narrative may accompany a code; it may never substitute for one. |
States were neither added nor removed to influence counts; only semantic duplication and behavioural ambiguity were corrected.
J · State Machine Assurance
| Contract | Reachability | Transition completeness | Terminal states | Dead states | Illegal cycles | Recovery | Authority | Reason code | Event |
|---|---|---|---|---|---|---|---|---|---|
| FC-FPSO-01 | ALL REACHABLE | COMPLETE AFTER CORRECTION | CONFIRMED · SUPERSEDED | 0 | 0 | YES | YES | YES | YES |
| FC-FPSO-02 | ALL REACHABLE | COMPLETE AFTER CORRECTION | SUPERSEDED · WITHDRAWN | 0 | 0 | YES | YES | YES | YES |
| FC-FPSO-03 | ALL REACHABLE | COMPLETE AFTER CORRECTION | CLOSED · CANCELLED | 0 | 0 | YES | YES | YES | YES |
| FC-FPSO-04 | ALL REACHABLE | COMPLETE AFTER CORRECTION | SUPERSEDED · CLOSED | 0 | 0 | YES | YES | YES | YES |
| FC-FPSO-05 | ALL REACHABLE | COMPLETE AFTER CORRECTION | CLOSED · SUPERSEDED | 0 | 0 | YES | YES | YES | YES |
| FC-FPSO-06 | ALL REACHABLE | COMPLETE AFTER CORRECTION | DISPOSITIONED | 0 | 0 | YES | YES | YES | YES |
| FC-FPSO-07 | ALL REACHABLE | COMPLETE | WITHDRAWN_FROM_SERVICE | 0 | 0 | YES | YES | YES | YES |
| FC-FPSO-08 | ALL REACHABLE | COMPLETE AFTER CORRECTION | SIGNED · INVALIDATED_FOR_VERSION | 0 | 0 | YES | YES | YES | YES |
No state is reachable through an undefined transition, and no material transition is executable because a presentation layer permits it — every material transition names its DecisionRight, reason code and emitted event.
K · Invalid State Assurance
Reachable illegal material states = 0
| ID | Invalid state | Attempted construction | Prevented | Mechanism |
|---|---|---|---|---|
| IS-01 | AuthorizedWithoutDecisionRight | Authorize package via completed evidence set only | YES | AuthorityEngine gate is a precondition on every AUTHORIZED transition; evidence completeness is a separate predicate. |
| IS-02 | SignedVersionDifferentFromCurrentVersion | Mutate content after signature and retain effectiveness | YES | RULE-SIG-VERSION-INVALIDATION + SIGNATURE_VERSION_CONFLICT (F-FCA-09). |
| IS-03 | ConfirmedLocationWithoutCandidateOrManualSelection | Confirm location from a null GPS fix | YES | Confirmation precondition requires a candidate or an attributed manual selection. |
| IS-04 | IPERCAuthorizedWhileMaterialDeltaOpen | Authorize while an open material delta affects the IPERC dependency scope | YES | Open MATERIAL_DELTA in scope forces REASSESS_REQUIRED; authorization transition is blocked. |
| IS-05 | PackageAuthorizedWithMandatoryItemIncomplete | Compensate an incomplete mandatory item with surplus optional items | YES | Conjunctive, non-weighted completeness predicate. |
| IS-06 | ToolReadyWithRequiredInspectionInvalid | Mark tool ready from list presence | YES | RULE-TOOL-READINESS conjunction of inspection, certification and physical verification. |
| IS-07 | CrewValidWhileMandatoryCompetencyInvalid | Substitute a person into a role slot and inherit validity | YES | Per-person competency evaluation; role-slot inheritance removed (F-FCA-05). |
| IS-08 | RetrievedDocumentTreatedAsApplicableWithoutApplicabilityEvaluation | Consume a retrieved document as applicable | YES | ApplicabilityStatus is a mandatory attribute defaulting to NOT_EVALUATED; consumers must read it. |
| IS-09 | PackageCompleteWhileMandatoryItemConfigurationAbsent | Treat missing configuration as 'not mandatory' | YES | COMPLETENESS_UNDETERMINABLE (F-FCA-03). Added during assurance. |
| IS-10 | AuthorizationSurvivingLocationSupersession | Replace Location_ID in place after dependent records exist | YES | Location supersession creates a successor confirmation and dependency-scoped reassessment (F-FCA-01). |
L · Authority Assurance
Every path attempted and structurally blocked
| Path | Attempted construction | Impossible | Blocked by |
|---|---|---|---|
| GPS → Authorization | Treat a high-accuracy fix as location authority and proceed | YES | GPS yields CandidateFact only; confirmation is a DecisionRight exercise. |
| DocumentRetrieval → ApplicabilityAuthority | Treat retrieval success as applicability | YES | ApplicabilityStatus mandatory; retrieval adapter holds no rule authority. |
| Evidence → Authorization | Complete every record and infer authorization | YES | EvidenceEngine ≠ DecisionEngine ≠ AuthorityEngine (parent invariant). |
| IPERCCompletion → Authorization | Confirmed IPERC auto-authorizes work | YES | HUMAN_CONFIRMED ≠ AUTHORIZED (F-FCA-06). |
| CrewPresence → Competency | Attendance list creates competency | YES | Competency is a federated fact from the designated authority. |
| Competency → DecisionRight | Competent person self-authorizes | YES | DecisionRight is granted by the authority model, not derived from competency. |
| Signature → DecisionRight | Signing grants the right that was missing | YES | Signature binds an existing right; signature without DecisionRight is invalid. |
| UI Permission → DecisionRight | Visible action button implies authority | YES | Material transitions evaluate authority server-side; presentation state is not an input fact. |
Identity ≠ Role ≠ Permission ≠ Competency ≠ DecisionRight — preserved across all eight contracts. AuthorityContradictions = 0.
M · Source Authority Assurance
SourceAuthority = OBJECT_SPECIFIC · promotions = 0
| Source | Authoritative for | Not authoritative for |
|---|---|---|
| Aconex | Controlled document identity, revision and status | Applicability, authorization, competency, risk acceptance |
| Q4 / Engica | Permit, isolation and work-control transaction state | Location semantics, competency, document revision |
| Forwood | Critical control verification records | Package completeness, authorization |
| IAM | Identity and authentication assurance | DecisionRight, competency, fitness |
| HR / Training | Qualification and training validity facts | DecisionRight, fitness for a specific task condition |
| Health | Fitness decision fact (binary, non-clinical) | Competency, authority |
| Device GPS | Nothing — candidate physical context only | Location identity, authorization, presence proof |
- · CandidateSource ≠ AuthoritativeSource
- · FederatedSource ≠ LocalSystemOfRecord
N–U · Contract Challenge Registers
Location · Documents · Package · Crew · IPERC · Delta · Tools · Signature
| ID | Contract | Scenario | Required behaviour | Prohibited | Reason code | Verdict |
|---|---|---|---|---|---|---|
| CH-N1 | FC-FPSO-01 | GPS_LOW_ACCURACY | Candidate flagged low-confidence; manual selection with attributed justification required | Silent confirmation | RC-LOC-ACCURACY-LOW | ASSURED |
| CH-N2 | FC-FPSO-01 | OVERLAPPING_LOCATIONS | LOCATION_CANDIDATE_AMBIGUOUS; explicit human selection among candidates | Nearest-centroid auto-pick | RC-LOC-AMBIGUOUS | ASSURED |
| CH-N3 | FC-FPSO-01 | LOCATION_NOT_FOUND | No candidate; manual selection from the governed location register only | Free-text location creation | RC-LOC-NOT-FOUND | ASSURED |
| CH-N4 | FC-FPSO-01 | GPS_UNAVAILABLE | Manual selection path with provenance PositionSource = MANUAL | Blocking the whole pre-start on a device failure | RC-LOC-GPS-UNAVAILABLE | ASSURED |
| CH-N5 | FC-FPSO-01 | MANUAL_SELECTION | Same confirmation semantics, different provenance | Lower assurance treated as equal without provenance | RC-LOC-MANUAL | ASSURED |
| CH-N6 | FC-FPSO-01 | LOCATION_CHANGED_AFTER_CONFIRMATION | Successor confirmation + dependency-scoped downstream impact analysis; prior confirmation SUPERSEDED | Silent Location_ID replacement | RC-LOC-SUPERSEDED | ASSURED AFTER CORRECTION |
| CH-O1 | FC-FPSO-02 | SUPERSEDED_DOCUMENT | Marked SUPERSEDED and non-consumable for applicability | Presenting as current | RC-DOC-SUPERSEDED | ASSURED |
| CH-O2 | FC-FPSO-02 | MULTIPLE_ACTIVE_REVISIONS | Fail closed: DOCUMENT_REVISION_AMBIGUOUS pending document-control resolution | Automatic latest-revision election | RC-DOC-REVISION-AMBIGUOUS | ASSURED AFTER CORRECTION |
| CH-O3 | FC-FPSO-02 | DOCUMENT_STATUS_UNKNOWN | Status UNKNOWN blocks applicability evaluation | Defaulting to APPROVED | RC-DOC-STATUS-UNKNOWN | ASSURED |
| CH-O4 | FC-FPSO-02 | SOURCE_UNAVAILABLE | Last retrieved snapshot shown with RetrievedAt and STALE marking | Presenting stale content as current | RC-DOC-SOURCE-UNAVAILABLE | ASSURED |
| CH-O5 | FC-FPSO-02 | METADATA_INSUFFICIENT | Candidate not eligible for applicability evaluation | Inferring missing metadata | RC-DOC-METADATA-INSUFFICIENT | ASSURED |
| CH-O6 | FC-FPSO-02 | DOCUMENT_REVISION_CHANGED_DURING_REVIEW | Dependency-scoped reassessment of items referencing that document version | Silent in-place substitution | RC-DOC-REVISION-CHANGED | ASSURED AFTER CORRECTION |
| CH-P1 | FC-FPSO-03 | Mandatory item incomplete | Package not complete; no compensation by other items | Weighted scoring | RC-PKG-MANDATORY-ITEM-NOT-SATISFIED | ASSURED |
| CH-P2 | FC-FPSO-03 | Non-applicable item | Excluded with recorded applicability basis | Silent omission | RC-PKG-ITEM-NOT-APPLICABLE | ASSURED |
| CH-P3 | FC-FPSO-03 | Item invalid after preparation | REASSESS_REQUIRED on the dependent scope; authorization not effective for the new version | Retaining PACKAGE_COMPLETE | RC-PKG-ITEM-INVALIDATED | ASSURED AFTER CORRECTION |
| CH-P4 | FC-FPSO-03 | Mandatory-item configuration absent | COMPLETENESS_UNDETERMINABLE | Treating absence as non-mandatory | RC-PKG-CONFIG-ABSENT | ASSURED AFTER CORRECTION |
| CH-P5 | FC-FPSO-03 | PETAR applicability changes | Item set recomputed; new mandatory item blocks completeness until satisfied | Grandfathering the previous item set | RC-PKG-APPLICABILITY-CHANGED | ASSURED |
| CH-Q1 | FC-FPSO-04 | Replacement while package under review | Successor crew record version; competency of the new person evaluated independently | Role-slot inheritance | RC-CREW-CHANGED | ASSURED AFTER CORRECTION |
| CH-Q2 | FC-FPSO-04 | Replacement after authorization | Material crew delta → dependency-scoped reassessment and re-exercise of the affected authorization | Authorization inherited by the replacement | RC-CREW-CHANGED-POST-AUTH | ASSURED AFTER CORRECTION |
| CH-Q3 | FC-FPSO-04 | Expected ≠ Present | Six distinct facts maintained: Expected, Present, Authenticated, Competent, Fit, Authorized | Collapsing presence into competence or authority | RC-CREW-NOT-PRESENT | ASSURED |
| CH-R1 | FC-FPSO-05 | Prepopulation provenance | Each prepopulated line carries rule version, input fact and source record | Prepopulated content presented as human authorship | RC-IPERC-PREPOPULATED | ASSURED |
| CH-R2 | FC-FPSO-05 | New hazard observed in field | FIELD_OBSERVED entry appended with residual-risk recalculation | Overwriting the prepopulated line | RC-IPERC-FIELD-ADDITION | ASSURED |
| CH-R3 | FC-FPSO-05 | Supervisor review completes record | SUPERVISOR_REVIEWED only; authorization is a separate DecisionRight exercise | Review implying authorization | RC-IPERC-REVIEWED | ASSURED AFTER CORRECTION |
| CH-R4 | FC-FPSO-05 | Cross-review thresholds absent | Trigger UNDETERMINABLE; AUTHORIZED unreachable for the affected class | Assuming no cross-review needed | RC-IPERC-THRESHOLD-ABSENT | ASSURED AFTER CORRECTION |
| CH-S1 | FC-FPSO-06 | WeatherChange / SIMOPSChange / AccessChange | Classified against the delta-category dependency map; material deltas force reassessment of exactly the dependent scope | Blanket invalidation or blanket survival | RC-DELTA-MATERIAL | ASSURED AFTER CORRECTION |
| CH-S2 | FC-FPSO-06 | Materiality thresholds absent | RC-DELTA-MATERIALITY-UNDETERMINABLE → treated as material (fail safe) | Treating unknown as immaterial | RC-DELTA-MATERIALITY-UNDETERMINABLE | ASSURED AFTER CORRECTION |
| CH-S3 | FC-FPSO-06 | Similar prior task authorized yesterday | No inheritance by similarity; authorization is per object version | Precedent-based authorization | RC-DELTA-NO-INHERITANCE | ASSURED |
| CH-T1 | FC-FPSO-07 | Inspection expires during shift | Tool becomes NOT_READY; dependent package items only are reassessed | Readiness persisting to shift end | RC-TOOL-INSPECTION-EXPIRED | ASSURED |
| CH-T2 | FC-FPSO-07 | Tool substitution | New tool evaluated independently; prior verification not transferred | Inheriting readiness by tool class | RC-TOOL-SUBSTITUTED | ASSURED |
| CH-T3 | FC-FPSO-07 | Field condition contradicts source status | Field observation prevails for readiness and raises a source discrepancy for the tool owner | Source status overriding physical verification | RC-TOOL-FIELD-DISCREPANCY | ASSURED |
| CH-T4 | FC-FPSO-07 | Duplicated tool reference | Idempotent on tool identity; one readiness record per tool per job card version | Duplicate readiness records | RC-TOOL-DUPLICATE-IGNORED | ASSURED |
| CH-U1 | FC-FPSO-08 | Content changes after signature | Prior signature INVALIDATED_FOR_VERSION; it remains valid evidence for the version it signed | Carrying the signature forward | RC-SIG-VERSION-INVALIDATED | ASSURED |
| CH-U2 | FC-FPSO-08 | Signer loses DecisionRight before commit | Signature aborts; NOT_SIGNED with authority reason code | Completing on a stale right check | RC-SIG-AUTHORITY-LOST | ASSURED |
| CH-U3 | FC-FPSO-08 | Repeated signing request | Idempotent: returns the existing signature for the same key tuple | Duplicate signature records | RC-SIG-DUPLICATE-SUPPRESSED | ASSURED AFTER CORRECTION |
| CH-U4 | FC-FPSO-08 | Signature service unavailable / offline | NOT_SIGNED; queued intent is not a signature | Optimistic or provisional signature | RC-SIG-SERVICE-UNAVAILABLE | ASSURED |
| CH-U5 | FC-FPSO-08 | Legal sufficiency claim | LegalValidation = EXTERNAL_DEPENDENCY; no legal assertion made | Declaring legal validity | RC-SIG-LEGAL-EXTERNAL | ASSURED |
V · Document Revision Propagation
Impact is dependency-scoped; no global invalidation
| Dependent | Propagates | Behaviour |
|---|---|---|
| Applicability evaluation | YES | Re-evaluated for the affected document class only. |
| PreStartPreventivePackageItem | ONLY IF DEPENDENT | Items referencing the changed document version transition to REASSESS_REQUIRED. |
| IPERC Continuo | ONLY IF DEPENDENT | Reassessment only where prepopulation drew on the changed document. |
| PETAR | ONLY IF DEPENDENT | Only where the revision alters the applicability basis. |
| Checklist | ONLY IF DEPENDENT | Checklist instances bound to the prior revision are superseded, not silently rewritten. |
| Signature | ONLY IF DEPENDENT | Signature over a changed object version becomes INVALIDATED_FOR_VERSION. |
| Authorization | ONLY IF DEPENDENT | Authorization ceases to be effective for the new version of the dependent scope only. |
| Unrelated packages / job cards | NO | No global invalidation. Impact is dependency-scoped. |
W · Concurrency Assurance
NO_LAST_WRITE_WINS preserved; UncontrolledConcurrencyPaths = 0.
| ID | Scenario | Detection | Governed resolution | Verdict |
|---|---|---|---|---|
| CC-01 | TwoUsersModifyIPERC | BaseVersion mismatch at line granularity | CONCURRENCY_CONFLICT; both versions preserved for authorized reconciliation | ASSURED |
| CC-02 | TwoSupervisorsActOnPackage | BaseVersion mismatch on package version | Second action rejected with conflict; no silent overwrite of the first decision | ASSURED |
| CC-03 | DocumentRevisionChangesDuringReview | Referenced document version changed | Dependent items to REASSESS_REQUIRED before any completion transition | ASSURED |
| CC-04 | CrewChangesDuringApproval | Crew record version changed | Approval aborts with RC-CREW-CHANGED; re-exercise required | ASSURED |
| CC-05 | FieldDeltaOccursDuringSignature | Object version incremented mid-flight | SIGNATURE_VERSION_CONFLICT; signature not committed | ASSURED |
| CC-06 | OfflineUpdateConflictsWithOnlineUpdate | Queued event BaseVersion ≠ server version | Governed reconciliation by the resolution authority; queued event never auto-wins | ASSURED |
X · Idempotency Assurance
UncontrolledReplayPaths = 0.
| ID | Operation | Idempotency key | Replay outcome | Verdict |
|---|---|---|---|---|
| ID-01 | LocationConfirmation | (JobCard_ID, Location_ID, Actor, Idempotency_Key) | Returns the existing confirmation; no duplicate confirmation event | ASSURED |
| ID-02 | DocumentRetrieval | (Context hash, Source, RetrievalRequest_ID) | Returns the same candidate set; no duplicate candidates | ASSURED |
| ID-03 | PackageGeneration | (JobCard_ID, JobCardVersion, RuleVersion) | Returns the existing package; no duplicate items | ASSURED |
| ID-04 | CrewConfirmation | (Package_ID, CrewRecordVersion, Person_ID) | No duplicate crew rows; no state advancement | ASSURED |
| ID-05 | IPERCSubmission | (IPERC_ID, ObjectVersion, Actor, Idempotency_Key) | Returns the existing submission | ASSURED |
| ID-06 | SignatureRequest | (Object_ID, ObjectVersion, SignerIdentity, DecisionRight, Idempotency_Key) | Returns the existing signature; no duplicate approvals | ASSURED |
| ID-07 | EventSubmission | (Event_ID) | Deduplicated; events immutable | ASSURED |
Y · Failure / Degraded Mode Assurance
| ID | Failure | Affected capability | Allowed | Prohibited | Reason code | Recovery |
|---|---|---|---|---|---|---|
| FM-01 | GPS UNAVAILABLE | Location candidate derivation | Manual selection from the governed register with provenance | Blocking all pre-start work; inventing a position | RC-LOC-GPS-UNAVAILABLE | Fix acquired at required accuracy |
| FM-02 | ACONEX OR SOURCE UNAVAILABLE | Document retrieval | Present last snapshot marked STALE with RetrievedAt | Presenting stale as current; assuming approval | RC-DOC-SOURCE-UNAVAILABLE | Successful re-retrieval and revision confirmation |
| FM-03 | IAM UNAVAILABLE | Authentication and DecisionRight resolution | Read-only continuation of non-material activity | Any material authorization transition | RC-AUTH-IAM-UNAVAILABLE | IAM restored and right re-resolved |
| FM-04 | CRITICAL CONTROL SOURCE UNAVAILABLE | Critical control verification item | Item remains NOT_VERIFIABLE | Treating unverifiable as verified | RC-CC-UNVERIFIABLE | Source restored and verification fact retrieved |
| FM-05 | SIGNATURE SERVICE UNAVAILABLE | Signature binding | NOT_SIGNED with retained intent | Provisional or optimistic signature | RC-SIG-SERVICE-UNAVAILABLE | Service restored; signature re-requested against the current version |
| FM-06 | NETWORK OFFLINE | All federated reads/writes | Minimum safe cached set; queued events with BaseVersion | Offline authorization of material decisions | RC-NET-OFFLINE | Connectivity restored and queue reconciled |
| FM-07 | SYNC PENDING | State currency | Explicit SYNC_PENDING marking on affected objects | Presenting pending state as committed | RC-SYNC-PENDING | Commit confirmation received |
| FM-08 | SYNC CONFLICT | Reconciliation | Both versions preserved for governed resolution | Last-write-wins | RC-SYNC-CONFLICT | Authorized reconciliation decision recorded |
| FM-09 | DOCUMENT VERSION CONFLICT | Dependent items and signatures | Dependency-scoped reassessment | Global invalidation or silent substitution | RC-DOC-REVISION-CHANGED | Reassessment completed for the dependent scope |
| FM-10 | LOCATION AMBIGUOUS | Location confirmation | Human selection among candidates | Auto-selection | RC-LOC-AMBIGUOUS | Explicit confirmation recorded |
TechnologyFailure ≠ AutomaticControlFailure and TechnologyFailure ≠ PermissionToBypassControl. Degradation narrows what may be decided; it never widens it.
Z · Pure Core / Effectful Shell Assessment
| Concern | Classification | Note |
|---|---|---|
| Location candidate selection rule (given position + register) | PURE CORE | Deterministic function of inputs; device access is shell. |
| GPS acquisition | EFFECTFUL SHELL | May fail; failure is an input fact to the core. |
| Applicability evaluation | PURE CORE | Rule + facts → applicability; no I/O. |
| Aconex retrieval | EFFECTFUL SHELL | Availability is an input fact. |
| Package completeness predicate | PURE CORE | Conjunctive, non-weighted, testable in isolation. |
| Delta materiality classification | PURE CORE | Thresholds are configuration inputs, not embedded constants. |
| Crew competency validity evaluation | PURE CORE | Facts in, verdict out. |
| IAM / DecisionRight resolution | EFFECTFUL SHELL | Unavailability blocks material decisions; it does not alter rule semantics. |
| Signature binding predicate | PURE CORE | Version/authority/content binding is decidable without the trust service. |
| Trust service invocation and persistence | EFFECTFUL SHELL | Failure yields NOT_SIGNED. |
AA · AI Containment Assurance
AI_OFF_MATERIAL_STATE_EQUIVALENCE = PRESERVED
| Prohibited AI action | Structurally prevented | Mechanism |
|---|---|---|
| ConfirmLocation | YES | Confirmation requires a human DecisionRight exercise. |
| EstablishSourceAuthority | YES | Source authority is configuration under governance, not inference. |
| MarkWorkerCompetent | YES | Competency is a federated authoritative fact. |
| FinalizeMandatoryApplicability | YES | Mandatory applicability requires human validation (parent invariant). |
| ApproveIPERC | YES | Authorization transition requires DecisionRight. |
| ApprovePETAR | YES | Same authority gate. |
| Sign | YES | SignerIdentity must be an authenticated natural person. |
| GrantDecisionRight | YES | Authority model is not writable by advisory output. |
| AuthorizeWork | YES | AI output is AI_ADVISORY_OUTPUT and is never an input fact to material rule evaluation. |
Removing all advisory output changes no material decision outcome; advisory output is excluded from the deterministic fact set by the AI-to-Rule firewall (PH6A-AHP-REV1.1).
AB · Determinism Assurance
Residual determinism defects = 0
Same Authoritative/Federated Facts + Same RuleVersions + Same Configuration + Same DecisionRights ⇒ Same Material Decision.
- · Automatic latest-revision election (FC-FPSO-02) — removed by F-FCA-02
- · Implicit mandatory-item default under absent configuration (FC-FPSO-03) — removed by F-FCA-03
- · Undeclared invalidation scope for material deltas (FC-FPSO-06) — removed by F-FCA-08
Determinism = PRESERVED
AC · Provenance Assurance
Provenance = COMPLETE_FOR_FUNCTIONAL_SCOPE
| Value class | Reconstructable | Chain |
|---|---|---|
| PREPOPULATED_VALUE | YES | Value ← RuleVersion ← InputFact ← SourceRecord ← SourceSystem ← SourceOwner ← Timestamp ← (no human action; prepopulation is machine-attributed) |
| DERIVED_VALUE | YES | Value ← RuleVersion ← InputFacts ← SourceRecords ← Timestamp |
| RULE_EVALUATION | YES | Verdict ← RuleVersion ← ConfigurationVersion ← FactSet ← Timestamp |
| AUTHORIZED_DECISION | YES | Decision ← DecisionRight ← Actor identity ← ObjectVersion ← FactSet ← RuleVersion ← Timestamp |
| FIELD_CORRECTION | YES | Append-only successor entry; source-derived history preserved and never erased |
AD · Event Model Assurance
28 events reviewed
- · Event_ID
- · EventType
- · Object_ID
- · ObjectVersion
- · Actor
- · Timestamp
- · PreviousState
- · ResultingState
- · ReasonCode
- · RuleVersion
- · Correlation_ID
- · PackageItemUpdated vs PackageItemChanged (FC-FPSO-03) — consolidated to PackageItemVersionCreated
Events are immutable records of occurrence, not state. No consumer derives current state by replaying UI events alone.
AE · Traceability Assurance
Traceability = COMPLETE
AIA Capability → Contract → Parent Contract → Rule/Configuration → Acceptance Predicate
AF · FCA-P01…FCA-P20 Results
20/20 PASS · DESIGN_ASSURANCE_EVIDENCE only
| ID | Property | Method | Result | Correction |
|---|---|---|---|---|
| FCA-P01 | GPS never authorizes | Attempted construction of a GPS→authorization path over FC-FPSO-01 preconditions; no transition accepts a position fact as an authority input. | PASS | — |
| FCA-P02 | Retrieved document never auto-becomes applicable | ApplicabilityStatus attribute mandatory and defaults to NOT_EVALUATED on every candidate. | PASS | F-FCA-02 |
| FCA-P03 | Applicable document never grants authority | No authorization transition lists applicability as a sufficient precondition. | PASS | — |
| FCA-P04 | Prepopulated IPERC never equals confirmed | SYSTEM_PREPOPULATED and HUMAN_CONFIRMED are separate states with a human transition between them. | PASS | — |
| FCA-P05 | Confirmed IPERC never automatically equals authorized | Review→authorization separated as an invariant. | PASS | F-FCA-06 |
| FCA-P06 | Material delta prevents stale authorization | Open in-scope MATERIAL_DELTA forces REASSESS_REQUIRED before any effective authorization. | PASS | F-FCA-04 |
| FCA-P07 | Mandatory incomplete package item prevents package completeness | Conjunctive predicate; no weighting operator exists in the contract. | PASS | — |
| FCA-P08 | Attendance cannot create competency | Presence and competency are distinct facts with distinct sources. | PASS | — |
| FCA-P09 | Competency cannot create DecisionRight | DecisionRight resolution takes no competency input. | PASS | — |
| FCA-P10 | Tool invalidity propagates only to dependent readiness | Tool→item dependency map scoped; unrelated items unaffected. | PASS | — |
| FCA-P11 | Signed content mutation invalidates signature applicability to new version | Version binding + INVALIDATED_FOR_VERSION terminal state. | PASS | F-FCA-09 |
| FCA-P12 | Source unavailability cannot fabricate current data | All degraded paths mark STALE/UNVERIFIABLE; no default-to-approved path exists. | PASS | — |
| FCA-P13 | Concurrent update cannot silently overwrite | BaseVersion required on every material write; conflict is an explicit outcome. | PASS | — |
| FCA-P14 | Replay is idempotent | Idempotency keys defined for all seven replayable operations. | PASS | F-FCA-09 |
| FCA-P15 | AI output cannot transition material authority state | Advisory output excluded from the deterministic fact set. | PASS | — |
| FCA-P16 | Same governed input produces same deterministic decision | Three non-determinism sources removed; no remaining implementer-chosen default. | PASS | F-FCA-02 / F-FCA-03 / F-FCA-08 |
| FCA-P17 | Document revision impact remains dependency-scoped | Propagation table (§V) enumerates dependent scopes; no global invalidation path. | PASS | — |
| FCA-P18 | Location change cannot silently preserve dependent authorization | Supersession creates a successor confirmation and scoped reassessment. | PASS | F-FCA-01 |
| FCA-P19 | Crew replacement cannot inherit previous person's competency/authority | Per-person evaluation; role-slot inheritance removed. | PASS | F-FCA-05 |
| FCA-P20 | Signature cannot repair an otherwise unauthorized decision | Signature precondition requires an already-valid DecisionRight exercise; otherwise the signature is invalid. | PASS | — |
These results do not constitute OPERATIONAL_EVIDENCE, DEMO_EVIDENCE, OPERATIONAL_CLOSURE_EVIDENCE. Simulation, prototype behaviour and operational evidence remain explicitly out of scope.
AG · Findings Register
0 critical · 8 high · 0 high uncontrolled
| ID | Severity | Impact class | Contract | Finding | Status |
|---|---|---|---|---|---|
| F-FCA-01 | HIGH | SEMANTIC_AMBIGUITY / AUTHORITY_DEFECT | FC-FPSO-01 | Location change after confirmation permitted in-place Location_ID replacement, silently preserving dependent authorizations. | CLOSED BY CORRECTION |
| F-FCA-02 | HIGH | SOURCE_BOUNDARY_DEFECT / DETERMINISM_DEFECT | FC-FPSO-02 | Multiple active revisions permitted an implicit automatic revision election by the retrieval layer. | CLOSED BY CORRECTION |
| F-FCA-03 | HIGH | CONTRACT_DEFECT / DETERMINISM_DEFECT | FC-FPSO-03 | Behaviour under absent mandatory-item configuration undefined; could be read as 'not mandatory'. | CLOSED BY CORRECTION |
| F-FCA-04 | HIGH | STATE_MODEL_DEFECT | FC-FPSO-03 | Item invalidation after package preparation had no defined effect on PACKAGE_COMPLETE or on authorization effectiveness. | CLOSED BY CORRECTION |
| F-FCA-05 | HIGH | AUTHORITY_DEFECT | FC-FPSO-04 | Crew replacement into a role slot could inherit the predecessor's competency and authorization. | CLOSED BY CORRECTION |
| F-FCA-06 | HIGH | AUTHORITY_DEFECT | FC-FPSO-05 | SUPERVISOR_REVIEWED → AUTHORIZED could be read as a single act, merging evidence and authority. | CLOSED BY CORRECTION |
| F-FCA-07 | MEDIUM | CONTRACT_DEFECT | FC-FPSO-05 | Absent cross-review thresholds left trigger behaviour undefined. | CLOSED BY CORRECTION |
| F-FCA-08 | HIGH | DETERMINISM_DEFECT | FC-FPSO-06 | Material delta invalidation scope undeclared; implementers could choose blanket or minimal invalidation. | CLOSED BY CORRECTION |
| F-FCA-09 | HIGH | IDEMPOTENCY_DEFECT / CONCURRENCY_DEFECT | FC-FPSO-08 | Repeated signature requests and mid-flight version changes had no defined idempotency key or conflict outcome. | CLOSED BY CORRECTION |
| F-FCA-10 | LOW | OVERMODELLING_DEFECT | FC-FPSO-02 / 03 / 06 | One decorative state and two semantically duplicate reason-code pairs; one duplicate event semantic. | CLOSED BY CORRECTION |
| F-FCA-11 | MEDIUM | EXTERNAL_DEPENDENCY | ALL | Twelve owner decisions remain unavailable (thresholds, participation modes, legal, IAM, privacy). Not a contract defect. | CONTROLLED EXTERNAL |
AH · Controlled Corrections Register
NoSilentCorrection · NoScopeExpansion · NoNewContract
- · NoSilentCorrection — every change carries Finding_ID, original, defect, corrected definition and rationale.
- · NoScopeExpansion — no capability added.
- · NoNewContract — ContractCount remains 8.
- · NoNewFactClass — the six parent fact classes are unchanged.
- · NoAuthorityPromotion — no source, record or signature gained authority.
AI · Retest / Regression Register
CorrectedDefinitionExists ∧ AffectedInvariantRetested ∧ CrossContractRegressionPassed ∧ NoNewMaterialAmbiguityIntroduced
| Finding | Corrected definition | Invariant retested | Cross-contract regression | No new ambiguity | Closed |
|---|---|---|---|---|---|
| F-FCA-01 | YES | YES | YES | YES | YES |
| F-FCA-02 | YES | YES | YES | YES | YES |
| F-FCA-03 | YES | YES | YES | YES | YES |
| F-FCA-04 | YES | YES | YES | YES | YES |
| F-FCA-05 | YES | YES | YES | YES | YES |
| F-FCA-06 | YES | YES | YES | YES | YES |
| F-FCA-07 | YES | YES | YES | YES | YES |
| F-FCA-08 | YES | YES | YES | YES | YES |
| F-FCA-09 | YES | YES | YES | YES | YES |
| F-FCA-10 | YES | YES | YES | YES | YES |
10/10 findings closed · 37 regression executions.
AJ · External Dependency Register at Freeze
Carried forward with CurrentAssumption = NONE
| ID | Contract | Owner | Decision needed | Current assumption | Status | Implementation constraint |
|---|---|---|---|---|---|---|
| XD-01 | FC-FPSO-01 | Location steward (ADR-14 stewardship, unstaffed) | Proximity radius and positional accuracy policy per location class | NONE | NONE REQUIRED | Radius/accuracy are configuration inputs, never hard-coded literals |
| XD-02 | FC-FPSO-01 | Corporate data privacy owner | Positional data retention period and personnel-tracking prohibition scope | NONE | NONE REQUIRED | No continuous tracking capability may be implemented |
| XD-03 | FC-FPSO-02 | Document control owner (Aconex participation) | Retrievable metadata fields and participation mode per source | NONE | NONE REQUIRED | No live API is assumed; adapter mode is configuration |
| XD-04 | FC-FPSO-03 | Rule governance authority (ADR-16) | Mandatory-item designation per activity class | NONE | NONE REQUIRED | Mandatory designation is versioned configuration under RuleVersion |
| XD-05 | FC-FPSO-03 | Work control system owner (Q4 / Engica) | Referenceable permit and isolation identifiers and states | NONE | NONE REQUIRED | Reference only; no write-back to work control |
| XD-06 | FC-FPSO-04 | Privacy + occupational health owners | Minimal decision-fact set exposed for fitness and competency | NONE | NONE REQUIRED | Only decision facts, never clinical data |
| XD-07 | FC-FPSO-04 | Competency authority (Training/HR) | Which body issues authoritative competency facts and their validity semantics | NONE | NONE REQUIRED | Competency source is object-specific, not universal |
| XD-08 | FC-FPSO-05 | ES&H authority | IPERC Continuo lifecycle validated against site legal and client requirements | NONE | NONE REQUIRED | Lifecycle states may be constrained but not merged |
| XD-09 | FC-FPSO-05 | ES&H + rule governance authority | Cross-review and hold-point threshold values per risk class | NONE | NONE REQUIRED | Thresholds are configuration under RuleVersion |
| XD-10 | FC-FPSO-06 | ES&H + Construction authorities | Materiality thresholds per delta category | NONE | NONE REQUIRED | Thresholds configurable per category; dependency map fixed by contract |
| XD-11 | FC-FPSO-07 | Tools / equipment authority | Inspection regime, certification classes and colour-code policy | NONE | NONE REQUIRED | Regime is configuration; readiness conjunction fixed by contract |
| XD-12 | FC-FPSO-08 | Legal + corporate compliance and enterprise IAM (ADR-08) | Signature legal/corporate/client requirements, identity provider and trust service selection | NONE | NONE REQUIRED | No trust technology selected in the functional baseline |
AK · Freeze Readiness Predicate & Baseline Manifest
| Criterion | Required | Actual | Met |
|---|---|---|---|
| ContractsAccounted | 8/8 | 8/8 | YES |
| ContractScopeDeviation | 0 | 0 | YES |
| ContractDefinitionGaps | 0 | 0 | YES |
| OpenSemanticAmbiguityCount | 0 | 0 | YES |
| CriticalContractDefects | 0 | 0 | YES |
| HighUncontrolledDefects | 0 | 0 | YES |
| ArchitectureImpact | 0 | 0 | YES |
| DuplicateDomainObjects | 0 | 0 | YES |
| AuthorityContradictions | 0 | 0 | YES |
| SourceAuthorityPromotions | 0 | 0 | YES |
| IllegalMaterialStates | 0 | 0 | YES |
| UncontrolledConcurrencyPaths | 0 | 0 | YES |
| UncontrolledReplayPaths | 0 | 0 | YES |
| Determinism | PRESERVED | PRESERVED | YES |
| AIContainment | PRESERVED | PRESERVED | YES |
| Provenance | COMPLETE_FOR_FUNCTIONAL_SCOPE | COMPLETE_FOR_FUNCTIONAL_SCOPE | YES |
| Traceability | COMPLETE | COMPLETE | YES |
| ParentBaseline | UNCHANGED | UNCHANGED | YES |
Future UX and software implementation may consume these contracts; they may not silently redefine them. Registered as descendant provenance of PH6A-IADA-REV1; TechnicalAttribution and DesignProvenanceLineage preserved; no parent mutation.
| Change class | Definition | Requires |
|---|---|---|
| CONFIGURATION_CHANGE | Threshold, matrix or catalogue value change under RuleVersion | Governance approval and rule version increment |
| FUNCTIONAL_CONTRACT_CHANGE | Any change to a frozen contract element | AffectedContract, Reason, Impact, RegressionRequired — recorded before adoption |
| UX_PRESENTATION_CHANGE | Presentation of contract semantics | No contract change; must not alter material behaviour |
| IMPLEMENTATION_CHANGE | Technical realisation choices | No requirement change; implementation convenience never rewrites requirements of record |
| ARCHITECTURE_IMPACT | Change touching authority, source boundaries, fact classes or engine separation | Reopen architecture governance; not permitted as routine configuration |
AL · G-FPSO-03 Decision & Final State
G-FPSO-03 — FUNCTIONAL BASELINE FREEZE
All contract semantics are closed: OpenSemanticAmbiguityCount = 0, ContractDefinitionGaps = 0, no critical or uncontrolled high defect, no reachable illegal material state, determinism, AI containment, provenance and traceability preserved, parent baseline unchanged. The 12 remaining items are genuinely external owner decisions satisfying every §5 test, each with CurrentAssumption = NONE.
- · semantic ambiguity
- · undefined state behaviour
- · undefined authority
- · undefined failure behaviour
- · unresolved high contract defect
| Strict stop condition | Observed | Triggered |
|---|---|---|
| ArchitectureImpact > 0 | 0 | NOT TRIGGERED |
| NewFunctionalContractRequired | FALSE | NOT TRIGGERED |
| NewFactClassRequired | FALSE | NOT TRIGGERED |
| AuthorityModelChangeRequired | FALSE | NOT TRIGGERED |
| EvidenceDecisionAuthorityMergeRequired | FALSE | NOT TRIGGERED |
| OpenMaterialSemanticAmbiguity > 0 | 0 | NOT TRIGGERED |
| UnresolvedCriticalContractDefect > 0 | 0 | NOT TRIGGERED |
| UnresolvedHighContractDefect > 0 | 0 | NOT TRIGGERED |
| ReachableIllegalMaterialState > 0 | 0 | NOT TRIGGERED |