PizarraContexto de trabajoDocumentos y registrosControles críticosRegistrosPreparaciónCondiciones bloqueantesAutorización
Aseguramiento / Técnico
PH6A-FPSO-FCD-REV0 · FUNCTIONAL_CONTRACT_DEFINITION_ONLY

A · Functional Contract Executive Summary

Eight descendant functional contracts for field pre-start orchestration, defined against the sealed parent baseline PH6A-IADA-REV1 and the accepted assessment PH6A-FPSO-AIA-REV0. Definition is not acceptance: nothing here is frozen, implemented or simulated.

READY FOR CONTRACT ASSURANCEFUNCTIONAL BASELINE FROZEN = FALSE
Contracts
8
States
59
Transitions
28
Forbidden transitions
16
Invalid states
8
Reason codes
58
Events emitted
28
Trace rows
21
Open dependencies
12
Orphaned capabilities
0

§0 · Governing Condition

Definition and acceptance are deliberately separated

ParentBaseline
PH6A-IADA-REV1
ParentSeal
PH6A-IADA-REV1-SEAL-01
InteractionArchitecture
PH6A-BXIA-REV0
ArchitectureImpactAssessment
PH6A-FPSO-AIA-REV0
RecommendedDisposition
PROCEED_WITH_CONTROLLED_FUNCTIONAL_EXTENSION
ArchitectureReopenRequired
FALSE
ArchitectureChanges
0
ParentBaselineChanges
0
FunctionalBaselineFrozen
FALSE
Phase6A
HOLD
BC09Protection
ACTIVE
PilotExposure
PROHIBITED
OperationalClosureEvidence
NOT_YET_ACQUIRED

§0 · This workstream shall not

Prohibited actions

  • · IMPLEMENT_UI
  • · CREATE_ROUTES for pre-start execution
  • · CREATE_COMPONENTS for the Pre-Start Board
  • · BUILD_PROTOTYPE
  • · RUN_OPERATIONAL_SIMULATION
  • · DEFINE_DEMO_SCENARIOS
  • · CREATE_SYNTHETIC_OPERATIONAL_DATA
  • · CREATE_SIMULATED_PROCESS_TIMES
  • · CREATE_OPERATIONAL_CLOSURE_EVIDENCE
  • · FREEZE_ITS_OWN_CONTRACTS
  • · SELF_ACCEPT
  • · MODIFY_PH6A_IADA_REV1

Definition is not acceptance. Contracts are not frozen in this interaction and are not self-accepted.

B · Contract Scope Register

§1 — scope frozen from PH6A-FPSO-AIA-REV0

IDContractAIA originScope state
FC-FPSO-01LocationAcquisitionServiceAIA candidate 1 · location acquisition & confirmationIN SCOPE
FC-FPSO-02ContextualDocumentRetrievalAIA candidate 2 · contextual controlled-document retrievalIN SCOPE
FC-FPSO-03PreStartPreventivePackage (+ Item)AIA candidate 3 · pre-start package orchestrationIN SCOPE
FC-FPSO-04CrewConfirmationRecordAIA candidate 4 · crew presence & decision factsIN SCOPE
FC-FPSO-05IPERCContinuoAIA candidate 5 · continuous field risk recordIN SCOPE
FC-FPSO-06FieldDeltaAssessmentAIA candidate 6 · expected vs observed contextIN SCOPE
FC-FPSO-07ToolReadinessAIA candidate 7 · tool readiness distinct from equipmentIN SCOPE
FC-FPSO-08DigitalSignatureAssuranceAIA candidate 8 · signature binding assuranceIN SCOPE

ContractScopeDeviation = 0. No ninth contract was created; no candidate capability required one.

§2 · REUSE_BEFORE_EXTENSION

Parent contracts consumed, never duplicated

  • · LocationOperationalContext
  • · WorkPackage
  • · JobCard
  • · Equipment
  • · ActivityRisk
  • · LocationRisk
  • · SIMOPSInteractionRisk
  • · DecisionRight
  • · GovernedOperationalEvent
  • · EvidenceCriterionAssessment
  • · CanonicalSemanticDictionary
  • · RequirementCatalogue
  • · RecordCatalogue
  • · RuleVersion
  • · ProvenanceChain

DuplicatedParentContracts = 0.

§12 · Frozen fact classes reused

No new fact class introduced

Fact classUsed byNew?
AUTHORITATIVE_FACTcanonical Location, permits, competency authority outputsNO
FEDERATED_FACTdocument metadata, decision facts, environmental feedsNO
DERIVED_FACTLocationCandidateSet, ApplicabilityStatus, completeness evaluationNO
RULE_EVALUATIONmateriality, completeness, tool readiness, crew rulesNO
AI_ADVISORY_OUTPUTcandidate ranking, hazard proposals, tool set proposalsNO
AUTHORIZED_DECISIONConfirmedLocation, IPERC authorization, package authorization, signature actsNO

EvidenceEngine ≠ DecisionEngine ≠ AuthorityEngine preserved in every contract.

FC-FPSO-01 · LocationAcquisitionService

REV0 · parent PH6A-IADA-REV1

Assist a field user in resolving a physical position into a candidate canonical Location, and record the human confirmation that binds work to that Location.

OperationalCapability
PhysicalPosition → LocationCandidateSet → LikelyLocation → HumanLocationConfirmation → ConfirmedLocation_ID.
CapabilityBoundary
Proposes location context only. The canonical Location register and its stewardship remain in LocationOperationalContext (parent, unchanged).
Explicit non-responsibilities
  • · creating, renaming or modifying canonical Locations
  • · granting physical access authorization
  • · granting work authorization
  • · deriving SIMOPS verdicts (owned by parent SIMOPS contracts)
  • · storing a position trail as personnel tracking
Parent contracts consumed (reuse)
  • · LocationOperationalContext
  • · DecisionRight
  • · GovernedOperationalEvent
  • · ProvenanceChain
  • · RuleVersion
  • · CanonicalSemanticDictionary
Inputs
  • · PhysicalPositionReading { lat, lon, accuracyMetres, capturedAt, sourceDevice }
  • · LocationRegisterSnapshot (AUTHORITATIVE_FACT, by reference)
  • · ManualLocationSelection (optional, human input)
  • · ProximityRuleVersion (configuration)
Outputs
  • · LocationCandidateSet (DERIVED_FACT)
  • · LikelyLocation (DERIVED_FACT, advisory)
  • · ConfirmedLocation_ID (AUTHORIZED_DECISION by the confirming human)
  • · AcquisitionReasonCode
Preconditions
  • · Location register snapshot available with a governed RuleVersion
  • · Acting user identity resolved
Postconditions
  • · ConfirmedLocation_ID exists only with a recorded human confirmation act
  • · ProvenanceChain records acquisition mode (GPS / MANUAL / MIXED) and accuracy at confirmation time
Authoritative dependencies
  • · Canonical Location register (Location steward)
Federated dependencies
  • · Device positioning service (effectful shell, non-authoritative)
Configuration dependencies
  • · ProximityRadiusConfig
  • · AccuracyThresholdConfig
  • · CandidateSetMaxSizeConfig
Rule dependencies
  • · RULE-LOC-CANDIDATE-SELECTION
  • · RULE-LOC-ACCURACY-CLASSIFICATION
Authority dependencies
  • · DecisionRight: CONFIRM_WORK_LOCATION
Security dependencies
  • · Authenticated session
  • · Device binding for position source
Privacy constraints
  • · Position retained only as the acquisition context of a confirmation act
  • · No continuous location history; no personnel movement analytics
Permitted states
  • · GPS_AVAILABLE
  • · GPS_LOW_ACCURACY
  • · GPS_UNAVAILABLE
  • · MULTIPLE_LOCATION_CANDIDATES
  • · NO_LOCATION_MATCH
  • · MANUAL_LOCATION_SELECTION
  • · LOCATION_CONFIRMED
  • · LOCATION_CHANGED
Permitted transitions
  • · GPS_AVAILABLE → MULTIPLE_LOCATION_CANDIDATES | LOCATION_CONFIRMED
  • · GPS_LOW_ACCURACY → MANUAL_LOCATION_SELECTION
  • · GPS_UNAVAILABLE → MANUAL_LOCATION_SELECTION
  • · NO_LOCATION_MATCH → MANUAL_LOCATION_SELECTION
  • · MANUAL_LOCATION_SELECTION → LOCATION_CONFIRMED
  • · LOCATION_CONFIRMED → LOCATION_CHANGED (re-entry to acquisition)
Forbidden transitions
  • · GPS_AVAILABLE → LOCATION_CONFIRMED without a human confirmation act
  • · LOCATION_CHANGED → retention of downstream authorizations
Invalid states
  • · ConfirmedLocationWithoutLocationCandidateOrManualSelection
Reason codes
  • · LOC-RC-01 ACCURACY_BELOW_THRESHOLD
  • · LOC-RC-02 NO_CANDIDATE_IN_RADIUS
  • · LOC-RC-03 AMBIGUOUS_CANDIDATE_SET
  • · LOC-RC-04 POSITION_SOURCE_UNAVAILABLE
  • · LOC-RC-05 MANUAL_OVERRIDE_APPLIED
  • · LOC-RC-06 LOCATION_CHANGED_MID_SHIFT
Events consumed
  • · LOCATION_REGISTER_UPDATED
  • · LOCATION_STEWARDSHIP_CHANGED
Events emitted
  • · LOCATION_CANDIDATES_DERIVED
  • · LOCATION_CONFIRMED
  • · LOCATION_CHANGE_DETECTED
AI allowed
  • · rank candidates as AI_ADVISORY_OUTPUT with stated basis
AI prohibited
  • · confirming a location
  • · suppressing candidates from the human view
  • · creating canonical Locations
Acceptance predicates
  • · AP-01-1: ConfirmedLocation_ID ⇒ ∃ HumanLocationConfirmation with DecisionRight
  • · AP-01-2: GPS output is never promoted above DERIVED_FACT
  • · AP-01-3: all seven acquisition conditions have defined behaviour
Open dependencies
  • · EXTERNAL_VALIDATION_DEPENDENCY: Location steward confirmation of proximity radius policy
  • · EXTERNAL_VALIDATION_DEPENDENCY: corporate policy on positional data retention
FailureBehaviour
Fail-closed to MANUAL_LOCATION_SELECTION; never auto-confirm a location.
SourceUnavailableBehaviour
Location register snapshot unavailable ⇒ ACQUISITION_UNAVAILABLE; no candidate set may be synthesised from cached free text.
OfflineBehaviour
Cached location register snapshot with explicit snapshot age; confirmation permitted and queued, marked SNAPSHOT_BASED with age at confirmation.
ConcurrencyBehaviour
Optimistic on ConfirmedLocation; concurrent divergent confirmations raise CONCURRENCY_CONFLICT.
IdempotencyRequirement
IdempotencyKey = {session, jobCard, positionReadingId}; repeat submissions do not create additional confirmations.
VersioningRequirement
Confirmation pins LocationRegisterSnapshotVersion and ProximityRuleVersion.
ProvenanceRequirement
ConfirmedLocation carries acquisition mode, accuracy, candidate set and rule version.
AuditRequirement
Every confirmation and every LOCATION_CHANGE emits a GovernedOperationalEvent.
HumanValidationPoint
HumanLocationConfirmation — mandatory, non-delegable to the system.

FC-FPSO-02 · ContextualDocumentRetrieval

REV0 · parent PH6A-IADA-REV1

Retrieve controlled documents relevant to the operational context and present them with full source, revision and applicability semantics intact.

OperationalCapability
Context (Location, Work, Activity, Discipline, Equipment, RiskContext) → ContextualDocumentCandidateSet with per-candidate ApplicabilityStatus.
CapabilityBoundary
Retrieval and applicability evaluation only. The source system remains the system of record for the document and its status.
Explicit non-responsibilities
  • · becoming a local system of record for controlled documents
  • · issuing, approving or superseding revisions
  • · asserting authorization from retrieval
  • · caching indefinitely without stated freshness
Parent contracts consumed (reuse)
  • · RequirementCatalogue
  • · RecordCatalogue
  • · LocationOperationalContext
  • · JobCard
  • · Equipment
  • · ProvenanceChain
  • · RuleVersion
  • · GovernedOperationalEvent
Inputs
  • · RetrievalContext { location, workPackage, jobCard, activity, discipline, equipment, riskContext }
  • · DocumentSourceParticipationMode (per source system)
  • · ApplicabilityRuleVersion
Outputs
  • · ContextualDocumentCandidateSet [ Document_ID, DocumentClass, Revision, DocumentStatus, SourceSystem, SourceOwner, ParticipationMode, EffectiveDate, RetrievedAt, ApplicabilityStatus ]
  • · RetrievalReasonCode
Preconditions
  • · RetrievalContext resolved to at least Location + Activity
  • · Source participation mode declared per source
Postconditions
  • · Every candidate carries the ten mandatory attributes
  • · ApplicabilityStatus is an explicit evaluation result, never an absence
Authoritative dependencies
  • · Document source system of record (e.g. Aconex-class DMS)
Federated dependencies
  • · Document metadata retrieval interface (mode-declared)
  • · Work/schedule federation for activity context
Configuration dependencies
  • · DocumentClassMap
  • · ContextToDocumentClassApplicabilityConfig
  • · FreshnessWindowConfig
Rule dependencies
  • · RULE-DOC-APPLICABILITY
  • · RULE-DOC-REVISION-SELECTION
Authority dependencies
  • · DecisionRight: DECLARE_DOCUMENT_APPLICABLE (where evaluation is not deterministic)
Security dependencies
  • · Source-side entitlement respected; no privilege elevation via retrieval
Privacy constraints
  • · No personal data extracted from document bodies
Permitted states
  • · RETRIEVED
  • · APPLICABILITY_EVALUATED
  • · APPLICABLE
  • · NOT_APPLICABLE
  • · APPLICABILITY_UNDETERMINED
  • · SUPERSEDED_DOCUMENT
  • · MULTIPLE_ACTIVE_REVISIONS
  • · SOURCE_UNAVAILABLE
  • · METADATA_INSUFFICIENT
  • · DOCUMENT_NOT_FOUND
  • · DOCUMENT_CONFLICT
Permitted transitions
  • · RETRIEVED → APPLICABILITY_EVALUATED
  • · APPLICABILITY_EVALUATED → APPLICABLE | NOT_APPLICABLE | APPLICABILITY_UNDETERMINED
  • · APPLICABLE → SUPERSEDED_DOCUMENT (on revision change)
Forbidden transitions
  • · RETRIEVED → APPLICABLE without applicability evaluation
  • · APPLICABLE → AUTHORIZED (not this contract's verb)
Invalid states
  • · RetrievedDocumentTreatedAsApplicableWithoutApplicabilityEvaluation
Reason codes
  • · DOC-RC-01 SOURCE_UNAVAILABLE
  • · DOC-RC-02 METADATA_INSUFFICIENT
  • · DOC-RC-03 MULTIPLE_ACTIVE_REVISIONS
  • · DOC-RC-04 SUPERSEDED_AFTER_RETRIEVAL
  • · DOC-RC-05 DOCUMENT_NOT_FOUND
  • · DOC-RC-06 CONFLICTING_SOURCE_RECORDS
Events consumed
  • · DOCUMENT_REVISION_PUBLISHED
  • · DOCUMENT_SUPERSEDED
  • · SOURCE_PARTICIPATION_CHANGED
Events emitted
  • · DOCUMENT_CANDIDATE_SET_DERIVED
  • · DOCUMENT_REVISION_CHANGE_DETECTED
  • · DOCUMENT_CONFLICT_RAISED
AI allowed
  • · suggest additional candidate documents as AI_ADVISORY_OUTPUT
AI prohibited
  • · marking a document APPLICABLE
  • · selecting between multiple active revisions
  • · hiding a superseded warning
Acceptance predicates
  • · AP-02-1: no candidate reaches APPLICABLE without an evaluation record
  • · AP-02-2: RETRIEVED ≠ APPLICABLE ≠ AUTHORIZED preserved in the data model
  • · AP-02-3: six abnormal conditions each have defined behaviour
Open dependencies
  • · EXTERNAL_VALIDATION_DEPENDENCY: document owner confirmation of retrievable metadata fields
  • · EXTERNAL_VALIDATION_DEPENDENCY: participation mode per source system (no live API assumed)
FailureBehaviour
Retrieval failure yields an explicit unavailability state, never an empty set presented as 'no applicable documents'.
SourceUnavailableBehaviour
SOURCE_UNAVAILABLE with last-known snapshot clearly marked, age shown; downstream mandatory items cannot be satisfied by a stale snapshot alone.
OfflineBehaviour
Only previously pinned revisions are available offline, each labelled with pin time and pinned revision.
ConcurrencyBehaviour
Revision change during an open pre-start raises DOCUMENT_REVISION_CHANGE_DETECTED for delta assessment; no silent substitution.
IdempotencyRequirement
Retrieval is a pure query over pinned inputs; repeated retrieval with identical context and versions returns an identical candidate set.
VersioningRequirement
Each candidate pins Revision; the set pins ApplicabilityRuleVersion.
ProvenanceRequirement
Each candidate records SourceSystem, SourceOwner, ParticipationMode and RetrievedAt.
AuditRequirement
Candidate set derivation and every conflict emit governed events.
HumanValidationPoint
Confirmation of the applicable document set where applicability is UNDETERMINED.

FC-FPSO-03 · PreStartPreventivePackage + PreStartPreventivePackageItem

REV0 · parent PH6A-IADA-REV1

Orchestrate the pre-start preventive item set for a job card without collapsing the independent state of any item.

OperationalCapability
Compose applicable items, track each item state independently, and expose package completeness and authorization as separate governed facts.
CapabilityBoundary
Orchestration and completeness evaluation. It does not own the underlying permits, isolations, checklists or critical controls.
Explicit non-responsibilities
  • · issuing permits, isolations or sanctions
  • · computing a weighted or averaged readiness score
  • · substituting one item's pass for another's absence
  • · authorizing work
Parent contracts consumed (reuse)
  • · WorkPackage
  • · JobCard
  • · RequirementCatalogue
  • · RecordCatalogue
  • · SIMOPSInteractionRisk
  • · LocationRisk
  • · ActivityRisk
  • · Equipment
  • · DecisionRight
  • · RuleVersion
  • · GovernedOperationalEvent
  • · ProvenanceChain
Inputs
  • · JobCard context
  • · ApplicabilityConfiguration (which items are mandatory in this context)
  • · Item state feeds: CrewConfirmation, WorkOrder, IPERCContinuo, ATS, PETAR, ApplicableChecklistSet, ToolReadiness, EquipmentReadiness, CriticalControlVerification, PermitReference, IsolationReference, PETS_CP_Reference, SIMOPSCondition, Restriction, EnvironmentalCondition
Outputs
  • · PreStartPreventivePackage { packageId, jobCardId, itemSet, mandatorySet, completenessState, authorizationState }
  • · PreStartPreventivePackageItem { itemId, itemClass, mandatory, itemState, reasonCode, provenance }
Preconditions
  • · ConfirmedLocation_ID present
  • · Applicability configuration version resolved
Postconditions
  • · PACKAGE_COMPLETE only when every mandatory item is individually satisfied
  • · AUTHORIZED only via a distinct authorization act by a holder of the DecisionRight
Authoritative dependencies
  • · Permit / isolation / critical-control systems of record
Federated dependencies
  • · Work order source
  • · Checklist source
  • · Environmental condition source
Configuration dependencies
  • · MandatoryItemApplicabilityConfig
  • · ItemClassCatalogue
Rule dependencies
  • · RULE-PKG-APPLICABILITY
  • · RULE-PKG-COMPLETENESS (conjunctive, non-compensatory)
Authority dependencies
  • · DecisionRight: AUTHORIZE_PRESTART_PACKAGE
Security dependencies
  • · Item write scoped to the item's accountable role
Privacy constraints
  • · Crew items reference decision facts only
Permitted states
  • · PACKAGE_DRAFT
  • · PACKAGE_IN_PROGRESS
  • · PACKAGE_INCOMPLETE
  • · PACKAGE_COMPLETE
  • · PACKAGE_AUTHORIZED
  • · PACKAGE_HOLD
  • · PACKAGE_REASSESS_REQUIRED
  • · PACKAGE_CLOSED
  • · PACKAGE_CANCELLED
Permitted transitions
  • · PACKAGE_DRAFT → PACKAGE_IN_PROGRESS
  • · PACKAGE_IN_PROGRESS → PACKAGE_INCOMPLETE | PACKAGE_COMPLETE
  • · PACKAGE_COMPLETE → PACKAGE_AUTHORIZED
  • · any → PACKAGE_HOLD | PACKAGE_REASSESS_REQUIRED (on delta or control loss)
  • · PACKAGE_AUTHORIZED → PACKAGE_REASSESS_REQUIRED → PACKAGE_AUTHORIZED (re-authorization only)
Forbidden transitions
  • · PACKAGE_INCOMPLETE → PACKAGE_AUTHORIZED
  • · PACKAGE_REASSESS_REQUIRED → PACKAGE_AUTHORIZED without a new authorization act
Invalid states
  • · PackageAuthorizedWithMandatoryItemIncomplete
  • · AuthorizedWithoutDecisionRight
Reason codes
  • · PKG-RC-01 MANDATORY_ITEM_INCOMPLETE
  • · PKG-RC-02 MANDATORY_ITEM_UNVERIFIABLE
  • · PKG-RC-03 MATERIAL_DELTA_OPEN
  • · PKG-RC-04 CRITICAL_CONTROL_NOT_VERIFIED
  • · PKG-RC-05 SIMOPS_CUMULATIVE_BLOCK
  • · PKG-RC-06 AUTHORITY_UNRESOLVED
  • · PKG-RC-07 RESTRICTION_ACTIVE
Events consumed
  • · ITEM_STATE_CHANGED
  • · MATERIAL_DELTA_RAISED
  • · CRITICAL_CONTROL_STATE_CHANGED
  • · SIMOPS_STATE_CHANGED
Events emitted
  • · PACKAGE_COMPOSED
  • · PACKAGE_COMPLETENESS_EVALUATED
  • · PACKAGE_AUTHORIZED
  • · PACKAGE_REASSESS_RAISED
AI allowed
  • · propose applicable items as AI_ADVISORY_OUTPUT
AI prohibited
  • · marking items complete
  • · declaring the package complete or authorized
  • · removing a mandatory item
Acceptance predicates
  • · AP-03-1: PACKAGE_AUTHORIZED ⇒ ∀ mandatory items satisfied
  • · AP-03-2: no arithmetic aggregation exists anywhere in completeness evaluation
  • · AP-03-3: item states are independently retrievable and never overwritten by package state
Open dependencies
  • · CONTRACT_DEFINITION_GAP: mandatory-item designation per activity class awaits configuration governance (links F-DEAP-01)
  • · EXTERNAL_VALIDATION_DEPENDENCY: permit/isolation owner confirmation of referenceable identifiers
FailureBehaviour
Any unevaluable mandatory item ⇒ PACKAGE_INCOMPLETE with reason code; never a partial pass.
SourceUnavailableBehaviour
Mandatory item whose source is unavailable is UNVERIFIABLE, which blocks completeness.
OfflineBehaviour
Items may be progressed offline against pinned inputs; authorization offline is permitted only where the DecisionRight is offline-valid, otherwise queued as PENDING_AUTHORIZATION.
ConcurrencyBehaviour
Per-item optimistic concurrency on itemVersion; NO_LAST_WRITE_WINS at package level.
IdempotencyRequirement
IdempotencyKey per item submission and per authorization act; repeats never duplicate items or approvals.
VersioningRequirement
PackageVersion increments on any item state change; authorization binds a specific PackageVersion.
ProvenanceRequirement
Each item records source fact class, actor, rule version and time.
AuditRequirement
Composition, each item transition and each authorization emit governed events.
HumanValidationPoint
Package authorization; and confirmation of any system-proposed item applicability.

FC-FPSO-04 · CrewConfirmationRecord

REV0 · parent PH6A-IADA-REV1

Record who is actually present for the task and bind each person to governed role, competency, training and fitness decision facts — without replicating HR, medical or training systems.

OperationalCapability
ExpectedCrew vs ObservedPresentCrew, with per-person decision facts and explicit exceptions.
CapabilityBoundary
Consumes governed decision facts; stores no underlying personal records.
Explicit non-responsibilities
  • · storing HRRecord, MedicalRecord or TrainingRecord content
  • · computing competency itself
  • · issuing medical fitness judgements
  • · granting authorization from presence
Parent contracts consumed (reuse)
  • · JobCard
  • · DecisionRight
  • · RequirementCatalogue
  • · GovernedOperationalEvent
  • · ProvenanceChain
  • · RuleVersion
Inputs
  • · ExpectedCrew (from work assignment)
  • · IdentityConfirmation events
  • · RoleDecisionFact / CompetencyDecisionFact / TrainingDecisionFact / FitnessDecisionFact (federated decision facts)
Outputs
  • · CrewConfirmationRecord { expected[], observedPresent[], perPersonFacts, exceptions[], crewState }
  • · CrewException { personRef, exceptionClass, reasonCode, dispositionOwner }
Preconditions
  • · JobCard resolved
  • · Decision-fact source declared with participation mode
Postconditions
  • · Every observed person carries an explicit competency/fitness decision-fact state or an exception
Authoritative dependencies
  • · Competency authority
  • · Occupational health authority (flag only)
Federated dependencies
  • · Identity provider
  • · Training/competency decision-fact service
Configuration dependencies
  • · RequiredRoleMatrixConfig
  • · MandatoryCompetencyConfig
Rule dependencies
  • · RULE-CREW-MANDATORY-ROLE
  • · RULE-CREW-COMPETENCY-VALIDITY
Authority dependencies
  • · DecisionRight: CONFIRM_CREW
  • · DecisionRight: DISPOSITION_CREW_EXCEPTION
Security dependencies
  • · Identity assurance level per confirmation method
Privacy constraints
  • · Data minimisation: boolean/decision facts and validity dates only
  • · No medical detail, diagnosis or restriction cause
  • · No biometric retention beyond the confirmation act
Permitted states
  • · CREW_EXPECTED
  • · CREW_OBSERVED
  • · CREW_EXCEPTION_OPEN
  • · CREW_CONFIRMED
  • · CREW_BLOCKED
  • · CREW_CHANGED
Permitted transitions
  • · CREW_EXPECTED → CREW_OBSERVED
  • · CREW_OBSERVED → CREW_CONFIRMED | CREW_EXCEPTION_OPEN
  • · CREW_EXCEPTION_OPEN → CREW_CONFIRMED (disposition) | CREW_BLOCKED
  • · CREW_CONFIRMED → CREW_CHANGED → CREW_OBSERVED
Forbidden transitions
  • · CREW_OBSERVED → CREW_CONFIRMED with an invalid mandatory competency
  • · CREW_CHANGED retaining prior authorization
Invalid states
  • · CrewValidWhileMandatoryCompetencyInvalid
Reason codes
  • · CRW-RC-01 MANDATORY_ROLE_ABSENT
  • · CRW-RC-02 COMPETENCY_EXPIRED
  • · CRW-RC-03 COMPETENCY_UNVERIFIABLE
  • · CRW-RC-04 FITNESS_NOT_CONFIRMED
  • · CRW-RC-05 IDENTITY_NOT_CONFIRMED
  • · CRW-RC-06 UNPLANNED_PERSON_PRESENT
Events consumed
  • · COMPETENCY_DECISION_FACT_UPDATED
  • · FITNESS_FLAG_UPDATED
  • · CREW_ASSIGNMENT_CHANGED
Events emitted
  • · CREW_CONFIRMED
  • · CREW_EXCEPTION_RAISED
  • · CREW_CHANGE_DETECTED
AI allowed
  • · highlight expiring competencies as advisory
AI prohibited
  • · declaring a person competent
  • · clearing a fitness flag
  • · authorizing an exception
Acceptance predicates
  • · AP-04-1: PRESENT ≠ COMPETENT ≠ AUTHORIZED preserved structurally
  • · AP-04-2: no HR/medical/training record content is persisted
  • · AP-04-3: every exception has an owner and a reason code
Open dependencies
  • · EXTERNAL_VALIDATION_DEPENDENCY: data-privacy owner confirmation of the minimal decision-fact set
  • · EXTERNAL_VALIDATION_DEPENDENCY: competency authority confirmation of fact issuance
FailureBehaviour
Unverifiable mandatory competency ⇒ CREW_BLOCKED with reason code; never assumed valid.
SourceUnavailableBehaviour
Decision-fact source unavailable ⇒ COMPETENCY_UNVERIFIABLE (not valid, not invalid) and mandatory items cannot complete.
OfflineBehaviour
Cached decision facts usable within a governed validity window, with age displayed; expiry inside the window is treated as expired.
ConcurrencyBehaviour
Optimistic on crewRecordVersion; simultaneous divergent confirmations raise CONCURRENCY_CONFLICT.
IdempotencyRequirement
IdempotencyKey = {crewRecordId, personRef, confirmationAttemptId}.
VersioningRequirement
CrewRecordVersion increments on any membership or decision-fact change.
ProvenanceRequirement
Each decision fact records source authority, issue time and validity.
AuditRequirement
Confirmations, exceptions and dispositions emit governed events.
HumanValidationPoint
Supervisor confirmation of observed crew and disposition of every exception.

FC-FPSO-05 · IPERCContinuo

REV0 · parent PH6A-IADA-REV1

Establish IPERC Continuo as a first-class governed record in which system prepopulation, field observation, human confirmation, supervisory review and authorization are distinct and separately attributable.

OperationalCapability
TaskStep → Hazard → Risk → Control → ResidualRisk → Responsible, maintained continuously across the shift.
CapabilityBoundary
Owns the field risk record and its lifecycle. It does not own the source risk libraries (PETS, CP, critical-risk taxonomy) that feed prepopulation.
Explicit non-responsibilities
  • · creating corporate risk standards
  • · authorizing work
  • · overwriting source-derived content silently
  • · replacing the baseline risk assessment
Parent contracts consumed (reuse)
  • · ActivityRisk
  • · LocationRisk
  • · SIMOPSInteractionRisk
  • · RequirementCatalogue
  • · RecordCatalogue
  • · DecisionRight
  • · RuleVersion
  • · ProvenanceChain
  • · GovernedOperationalEvent
  • · CanonicalSemanticDictionary
Inputs
  • · WorkContext, LocationContext, ApplicablePETS, ApplicableCP, CriticalRiskContext, Equipment, SIMOPS, Restrictions, Lessons (prepopulation sources)
  • · Field observations and edits
Outputs
  • · IPERCContinuoRecord { rows[], lifecycleState, provenancePerField, version }
  • · IPERCRow { taskStep, hazard, risk, control, residualRisk, responsible, origin, confirmationState }
Preconditions
  • · ConfirmedLocation_ID
  • · Applicable document set evaluated
  • · Crew observed
Postconditions
  • · Every row records origin (SYSTEM_PREPOPULATED or FIELD_OBSERVED) and its confirmation lineage
  • · Field edits preserve the superseded source-derived value as prior provenance rather than deleting it
Authoritative dependencies
  • · Corporate risk standards / critical-risk taxonomy
Federated dependencies
  • · PETS/CP document source
  • · Lessons-learned source
Configuration dependencies
  • · PrepopulationRuleConfig
  • · MandatoryRowClassConfig
  • · CrossReviewTriggerConfig
Rule dependencies
  • · RULE-IPERC-PREPOPULATION
  • · RULE-IPERC-RESIDUAL-RISK-ACCEPTANCE
  • · RULE-IPERC-REASSESS-TRIGGER
Authority dependencies
  • · DecisionRight: CONFIRM_IPERC
  • · DecisionRight: REVIEW_IPERC
  • · DecisionRight: AUTHORIZE_IPERC
Security dependencies
  • · Attributable field edit identity
Privacy constraints
  • · Responsible party referenced by governed person reference only
Permitted states
  • · SYSTEM_PREPOPULATED
  • · FIELD_OBSERVED
  • · HUMAN_CONFIRMED
  • · SUPERVISOR_REVIEWED
  • · AUTHORIZED
  • · REASSESS_REQUIRED
  • · CLOSED
Permitted transitions
  • · SYSTEM_PREPOPULATED → FIELD_OBSERVED → HUMAN_CONFIRMED → SUPERVISOR_REVIEWED → AUTHORIZED → CLOSED
  • · AUTHORIZED → REASSESS_REQUIRED (on any governed trigger)
  • · REASSESS_REQUIRED → HUMAN_CONFIRMED (re-entry, re-authorization required)
Forbidden transitions
  • · SYSTEM_PREPOPULATED → AUTHORIZED
  • · SYSTEM_PREPOPULATED → HUMAN_CONFIRMED without a field confirmation act
  • · REASSESS_REQUIRED → AUTHORIZED without re-confirmation
Invalid states
  • · IPERCAuthorizedWhileMaterialDeltaOpen
  • · AuthorizedWithoutDecisionRight
Reason codes
  • · IPC-RC-01 CREW_CHANGE
  • · IPC-RC-02 LOCATION_CHANGE
  • · IPC-RC-03 TASK_CHANGE
  • · IPC-RC-04 DOCUMENT_REVISION_CHANGE
  • · IPC-RC-05 NEW_HAZARD
  • · IPC-RC-06 CONTROL_CHANGE
  • · IPC-RC-07 SIMOPS_CHANGE
  • · IPC-RC-08 HOLD_POINT_REACHED
  • · IPC-RC-09 CROSS_REVIEW_REQUIRED
  • · IPC-RC-10 RESIDUAL_RISK_NOT_ACCEPTED
Events consumed
  • · MATERIAL_DELTA_RAISED
  • · DOCUMENT_REVISION_CHANGE_DETECTED
  • · CREW_CHANGE_DETECTED
  • · SIMOPS_STATE_CHANGED
Events emitted
  • · IPERC_PREPOPULATED
  • · IPERC_CONFIRMED
  • · IPERC_REVIEWED
  • · IPERC_AUTHORIZED
  • · IPERC_REASSESS_RAISED
  • · IPERC_CLOSED
AI allowed
  • · propose hazards/controls from lessons and PETS as AI_ADVISORY_OUTPUT
AI prohibited
  • · confirming a row
  • · accepting residual risk
  • · authorizing
  • · removing a prepopulated hazard
Acceptance predicates
  • · AP-05-1: SYSTEM_PREPOPULATED ≠ HUMAN_CONFIRMED ≠ AUTHORIZED enforced by transitions
  • · AP-05-2: no field edit destroys source-derived provenance
  • · AP-05-3: all nine change triggers map to a governed reason code
Open dependencies
  • · EXTERNAL_VALIDATION_DEPENDENCY: ES&H owner confirmation of the IPERC Continuo lifecycle against site legal requirements
  • · CONTRACT_DEFINITION_GAP: cross-review trigger thresholds await configuration governance
FailureBehaviour
Any governed trigger during execution forces REASSESS_REQUIRED; work authorization derived from the prior state is invalidated.
SourceUnavailableBehaviour
Prepopulation source unavailable ⇒ rows are marked NOT_PREPOPULATED; the record may still be created wholly FIELD_OBSERVED, never silently thinner.
OfflineBehaviour
Full offline authoring against pinned prepopulation inputs; queued with pin versions and local timestamps.
ConcurrencyBehaviour
Row-level optimistic concurrency; conflicting edits to the same row raise CONCURRENCY_CONFLICT preserving both versions.
IdempotencyRequirement
IdempotencyKey per confirmation/review/authorization act; repeats do not create additional attributable acts.
VersioningRequirement
IPERCVersion increments per row change; authorization binds a specific version.
ProvenanceRequirement
Per-field provenance: origin, prepopulation rule version, editing actor, superseded prior value.
AuditRequirement
Full lifecycle reconstructable from governed events alone.
HumanValidationPoint
HUMAN_CONFIRMED (crew), SUPERVISOR_REVIEWED, AUTHORIZED — three distinct human acts.

FC-FPSO-06 · FieldDeltaAssessment

REV0 · parent PH6A-IADA-REV1

Compare the expected operational context with the observed field context and determine whether reassessment is required.

OperationalCapability
ExpectedOperationalContext vs ObservedFieldContext → NO_MATERIAL_DELTA | MATERIAL_DELTA_REQUIRES_REASSESSMENT.
CapabilityBoundary
Determines materiality of difference; it does not itself reassess risk or authorize.
Explicit non-responsibilities
  • · inheriting prior authorization because contexts are similar
  • · closing a delta without an owner disposition
  • · weighting deltas into a single score
Parent contracts consumed (reuse)
  • · LocationOperationalContext
  • · JobCard
  • · Equipment
  • · SIMOPSInteractionRisk
  • · RuleVersion
  • · GovernedOperationalEvent
  • · ProvenanceChain
Inputs
  • · ExpectedOperationalContext snapshot (pinned)
  • · ObservedFieldContext (field-entered / retrieved)
  • · MaterialityRuleVersion
Outputs
  • · FieldDeltaAssessment { categoryResults[], verdict, reasonCodes[], dispositionOwner }
Preconditions
  • · Expected context pinned with version
  • · Observed context captured for every mandatory category
Postconditions
  • · Verdict recorded with per-category evidence; MATERIAL_DELTA blocks authorization until dispositioned
Authoritative dependencies
  • · Governing materiality configuration owner
Federated dependencies
  • · Environmental, SIMOPS and document-revision feeds
Configuration dependencies
  • · MaterialityThresholdConfig per delta category
Rule dependencies
  • · RULE-DELTA-MATERIALITY (categorical, non-compensatory)
Authority dependencies
  • · DecisionRight: DISPOSITION_MATERIAL_DELTA
Security dependencies
  • · Attributable observation capture
Privacy constraints
  • · Crew delta expressed as decision facts only
Permitted states
  • · DELTA_NOT_ASSESSED
  • · DELTA_ASSESSED
  • · NO_MATERIAL_DELTA
  • · MATERIAL_DELTA_REQUIRES_REASSESSMENT
  • · DELTA_DISPOSITIONED
Permitted transitions
  • · DELTA_NOT_ASSESSED → DELTA_ASSESSED
  • · DELTA_ASSESSED → NO_MATERIAL_DELTA | MATERIAL_DELTA_REQUIRES_REASSESSMENT
  • · MATERIAL_DELTA_REQUIRES_REASSESSMENT → DELTA_DISPOSITIONED (reassessment completed)
Forbidden transitions
  • · MATERIAL_DELTA_REQUIRES_REASSESSMENT → NO_MATERIAL_DELTA without reassessment
  • · DELTA_NOT_ASSESSED → authorization downstream
Invalid states
  • · IPERCAuthorizedWhileMaterialDeltaOpen
  • · PackageAuthorizedWithMandatoryItemIncomplete
Reason codes
  • · DLT-RC-01 LOCATION_DELTA
  • · DLT-RC-02 CREW_DELTA
  • · DLT-RC-03 EQUIPMENT_DELTA
  • · DLT-RC-04 TOOL_DELTA
  • · DLT-RC-05 ENVIRONMENT_DELTA
  • · DLT-RC-06 SIMOPS_DELTA
  • · DLT-RC-07 ACCESS_DELTA
  • · DLT-RC-08 RESTRICTION_DELTA
  • · DLT-RC-09 DOCUMENT_REVISION_DELTA
  • · DLT-RC-10 CRITICAL_CONTROL_DELTA
  • · DLT-RC-11 UNEXPECTED_HAZARD
Events consumed
  • · LOCATION_CHANGE_DETECTED
  • · CREW_CHANGE_DETECTED
  • · DOCUMENT_REVISION_CHANGE_DETECTED
  • · SIMOPS_STATE_CHANGED
  • · CRITICAL_CONTROL_STATE_CHANGED
Events emitted
  • · DELTA_ASSESSED
  • · MATERIAL_DELTA_RAISED
  • · MATERIAL_DELTA_DISPOSITIONED
AI allowed
  • · flag candidate deltas as advisory
AI prohibited
  • · declaring NO_MATERIAL_DELTA
  • · dispositioning a delta
Acceptance predicates
  • · AP-06-1: similarity never inherits prior authorization
  • · AP-06-2: unassessable ⇒ material (fail-closed)
  • · AP-06-3: all eleven delta categories carry a reason code
Open dependencies
  • · EXTERNAL_VALIDATION_DEPENDENCY: materiality thresholds per category require owner definition
FailureBehaviour
Unassessable category ⇒ treated as MATERIAL_DELTA_REQUIRES_REASSESSMENT (fail-closed).
SourceUnavailableBehaviour
Missing feed for a mandatory category is an unassessable category, not an absence of delta.
OfflineBehaviour
Assessment runs on pinned expected context offline; re-evaluated on reconnection against current expected context.
ConcurrencyBehaviour
Latest observation supersedes but never deletes prior assessments; conflicting dispositions raise CONCURRENCY_CONFLICT.
IdempotencyRequirement
IdempotencyKey = {jobCard, expectedContextVersion, observationId}.
VersioningRequirement
Assessment pins expected context version and materiality rule version.
ProvenanceRequirement
Per-category observed value, expected value and rule applied.
AuditRequirement
Every material delta and its disposition emit governed events.
HumanValidationPoint
Disposition of every MATERIAL_DELTA by an authorized role.

FC-FPSO-07 · ToolReadiness

REV0 · parent PH6A-IADA-REV1

Establish tool readiness as a governed capability distinct from equipment readiness, based on physical verification rather than list presence.

OperationalCapability
Required tool set → per-tool inspection/certification/condition state → ToolReadiness verdict.
CapabilityBoundary
Tools only. Plant and equipment readiness remains with the parent Equipment contract.
Explicit non-responsibilities
  • · issuing tool certifications
  • · treating a preselected checkbox as physical verification
  • · aggregating tool states into a score
Parent contracts consumed (reuse)
  • · Equipment
  • · RequirementCatalogue
  • · RecordCatalogue
  • · RuleVersion
  • · GovernedOperationalEvent
  • · ProvenanceChain
  • · DecisionRight
Inputs
  • · RequiredToolSet for activity
  • · Tool register entries
  • · Field verification acts
Outputs
  • · ToolReadinessRecord { tools[], verdict, reasonCodes[] }
  • · ToolItem { Tool_ID, ToolClass, RequiredForActivity, InspectionRequirement, InspectionState, CertificationRequirement, CertificationState, Condition, Restriction, Validity }
Preconditions
  • · Activity resolved so the required tool set is determinable
Postconditions
  • · TOOL_READY only after a physical verification act per required tool
Authoritative dependencies
  • · Tool inspection/certification authority
Federated dependencies
  • · Tool register source (where federated)
Configuration dependencies
  • · RequiredToolByActivityConfig
  • · InspectionColourCodeConfig
Rule dependencies
  • · RULE-TOOL-REQUIRED-SET
  • · RULE-TOOL-READINESS (conjunctive)
Authority dependencies
  • · DecisionRight: VERIFY_TOOL_READINESS
Security dependencies
  • · Attributable verifier identity
Privacy constraints
  • · None beyond verifier attribution
Permitted states
  • · TOOL_LISTED
  • · TOOL_VERIFICATION_PENDING
  • · TOOL_READY
  • · TOOL_NOT_READY
  • · TOOL_UNVERIFIABLE
  • · TOOL_QUARANTINED
Permitted transitions
  • · TOOL_LISTED → TOOL_VERIFICATION_PENDING → TOOL_READY | TOOL_NOT_READY | TOOL_UNVERIFIABLE
  • · TOOL_NOT_READY → TOOL_QUARANTINED
Forbidden transitions
  • · TOOL_LISTED → TOOL_READY without a physical verification act
Invalid states
  • · ToolReadyWithRequiredInspectionInvalid
Reason codes
  • · TLR-RC-01 INSPECTION_EXPIRED
  • · TLR-RC-02 INSPECTION_NOT_PERFORMED
  • · TLR-RC-03 CERTIFICATION_INVALID
  • · TLR-RC-04 CONDITION_DEFECTIVE
  • · TLR-RC-05 TOOL_ABSENT
  • · TLR-RC-06 RESTRICTION_ON_TOOL
Events consumed
  • · TOOL_REGISTER_UPDATED
  • · TOOL_INSPECTION_RECORDED
Events emitted
  • · TOOL_VERIFIED
  • · TOOL_NOT_READY_RAISED
  • · TOOL_QUARANTINED
AI allowed
  • · propose the required tool set as advisory
AI prohibited
  • · marking a tool verified or ready
  • · clearing an expired inspection
Acceptance predicates
  • · AP-07-1: TOOL_LISTED ≠ TOOL_READY structurally
  • · AP-07-2: preselected checks are impossible — verification requires an attributable act
  • · AP-07-3: ToolReadiness is separate from EquipmentReadiness in the item catalogue
Open dependencies
  • · EXTERNAL_VALIDATION_DEPENDENCY: tool inspection regime and colour-code policy owner confirmation
FailureBehaviour
Missing or expired mandatory inspection ⇒ TOOL_NOT_READY; blocks the package mandatory item.
SourceUnavailableBehaviour
Register unavailable ⇒ TOOL_UNVERIFIABLE; physical verification may still be recorded and marked as field-only.
OfflineBehaviour
Field verification fully offline-capable; register cross-check deferred and flagged.
ConcurrencyBehaviour
Optimistic per tool item; concurrent contradictory verifications raise CONCURRENCY_CONFLICT.
IdempotencyRequirement
IdempotencyKey = {jobCard, Tool_ID, verificationAttemptId}.
VersioningRequirement
ToolReadinessVersion increments per tool state change.
ProvenanceRequirement
Verifier, method, time and register cross-check status per tool.
AuditRequirement
Each verification and quarantine emits a governed event.
HumanValidationPoint
Physical verification act per required tool.

FC-FPSO-08 · DigitalSignatureAssurance

REV0 · parent PH6A-IADA-REV1

Define the functional assurance contract that binds identity, authority, content and version at the moment of signing — without selecting technology or asserting legal validity.

OperationalCapability
Bind a signing act to an exact object version, signer identity, decision right and content integrity reference.
CapabilityBoundary
Functional assurance only. No provider selection, no trust-service assertion, no legal conclusion.
Explicit non-responsibilities
  • · selecting a signature technology or provider
  • · asserting legal sufficiency or equivalence
  • · issuing credentials
  • · manufacturing authority the signer does not hold
Parent contracts consumed (reuse)
  • · DecisionRight
  • · GovernedOperationalEvent
  • · ProvenanceChain
  • · RecordCatalogue
  • · RuleVersion
Inputs
  • · Object_ID + ObjectVersion
  • · SignerIdentity + CredentialStatus
  • · DecisionRight resolution
  • · ContentIntegrityReference
  • · SignatureMethod
Outputs
  • · SignatureAssuranceRecord { Object_ID, ObjectVersion, SignerIdentity, DecisionRight, SigningTimestamp, SignatureMethod, CredentialStatus, ContentIntegrityReference, PreviousState, NewState }
Preconditions
  • · Signer authenticated
  • · DecisionRight resolved for this object and decision
  • · Content integrity reference computable
Postconditions
  • · Signature valid only for the exact ObjectVersion signed
  • · State transition recorded with previous and new state
Authoritative dependencies
  • · Identity provider (authoritative for identity)
  • · Authority engine (authoritative for decision rights)
Federated dependencies
  • · Trust service / timestamp authority (if adopted)
Configuration dependencies
  • · SignatureMethodByObjectClassConfig
  • · AssuranceLevelConfig
Rule dependencies
  • · RULE-SIG-BINDING
  • · RULE-SIG-VERSION-INVALIDATION
Authority dependencies
  • · DecisionRight required per signed object class
Security dependencies
  • · Credential status verification at signing time
  • · Tamper-evident content integrity reference
Privacy constraints
  • · Signer attributes limited to identity reference and credential status
Permitted states
  • · SIGNATURE_NOT_REQUIRED
  • · SIGNATURE_REQUIRED
  • · SIGNATURE_PENDING
  • · SIGNED
  • · SIGNATURE_SUPERSEDED_BY_VERSION_CHANGE
  • · SIGNATURE_REJECTED
  • · SIGNATURE_UNAVAILABLE
Permitted transitions
  • · SIGNATURE_REQUIRED → SIGNATURE_PENDING → SIGNED | SIGNATURE_REJECTED | SIGNATURE_UNAVAILABLE
  • · SIGNED → SIGNATURE_SUPERSEDED_BY_VERSION_CHANGE (on content change)
Forbidden transitions
  • · SIGNATURE_SUPERSEDED_BY_VERSION_CHANGE → SIGNED without a new signing act
  • · SIGNATURE_PENDING → SIGNED without DecisionRight
Invalid states
  • · SignedVersionDifferentFromCurrentVersion
  • · AuthorizedWithoutDecisionRight
Reason codes
  • · SIG-RC-01 DECISION_RIGHT_ABSENT
  • · SIG-RC-02 CREDENTIAL_INVALID
  • · SIG-RC-03 CONTENT_CHANGED_AFTER_SIGNATURE
  • · SIG-RC-04 IDENTITY_SERVICE_UNAVAILABLE
  • · SIG-RC-05 SIGNATURE_METHOD_NOT_PERMITTED_FOR_OBJECT
  • · SIG-RC-06 SIGNER_DECLINED
Events consumed
  • · OBJECT_VERSION_CHANGED
  • · CREDENTIAL_STATUS_CHANGED
Events emitted
  • · SIGNATURE_APPLIED
  • · SIGNATURE_INVALIDATED_BY_VERSION_CHANGE
  • · SIGNATURE_REJECTED
AI allowed
  • · summarise what is being signed as advisory
AI prohibited
  • · signing
  • · asserting legal validity
  • · selecting signature method for a decision
Acceptance predicates
  • · AP-08-1: signature binds all ten mandatory elements
  • · AP-08-2: content change invalidates the prior signature for the new version
  • · AP-08-3: acknowledgement / electronic signature / digital signature are distinguished without legal equivalence claims
Open dependencies
  • · EXTERNAL_VALIDATION_DEPENDENCY: LEGAL_REQUIREMENTS
  • · EXTERNAL_VALIDATION_DEPENDENCY: CORPORATE_REQUIREMENTS
  • · EXTERNAL_VALIDATION_DEPENDENCY: CLIENT_REQUIREMENTS
  • · EXTERNAL_VALIDATION_DEPENDENCY: IDENTITY_PROVIDER selection
  • · EXTERNAL_VALIDATION_DEPENDENCY: TRUST_SERVICE selection
FailureBehaviour
Fail-closed: no signature is recorded unless identity, authority, version and integrity reference are all resolved.
SourceUnavailableBehaviour
Identity or trust service unavailable ⇒ SIGNATURE_UNAVAILABLE; downstream authorization cannot proceed on that object.
OfflineBehaviour
Offline signing permitted only where the method's assurance level is declared offline-valid; otherwise queued as SIGNATURE_PENDING.
ConcurrencyBehaviour
Version change during signing aborts the act with SIG-RC-03; no signature is applied to a stale version.
IdempotencyRequirement
IdempotencyKey = {Object_ID, ObjectVersion, SignerIdentity, decisionClass}; repeats never create duplicate signatures.
VersioningRequirement
Signature is bound to ObjectVersion; CONTENT_CHANGE_AFTER_SIGNATURE ⇒ PRIOR_SIGNATURE_NOT_VALID_FOR_NEW_VERSION.
ProvenanceRequirement
Full binding tuple retained immutably.
AuditRequirement
Signature application and invalidation emit governed events.
HumanValidationPoint
The signing act itself.

§11 · Signature tier distinction

No legal equivalence asserted

TierBindsDoes not assert
ElectronicAcknowledgementidentity reference + timestamp + object version viewedauthority to decide, or legal signature effect
ElectronicSignatureidentity + decision right + object version + content integrity referencecryptographic non-repudiation or legal equivalence to a handwritten signature
DigitalSignaturecryptographic key material bound to identity, with integrity and timestamp evidencejurisdictional legal sufficiency without a legal determination

K · Cross-Contract Dependency Map

FromToRelation
FC-FPSO-01FC-FPSO-02ConfirmedLocation_ID scopes the retrieval context
FC-FPSO-01FC-FPSO-03ConfirmedLocation_ID is a package precondition
FC-FPSO-01FC-FPSO-06LOCATION_CHANGED feeds the delta assessment
FC-FPSO-02FC-FPSO-05Applicable PETS/CP feed IPERC prepopulation
FC-FPSO-02FC-FPSO-06Revision change is a delta category
FC-FPSO-03FC-FPSO-04CrewConfirmation is a package item
FC-FPSO-03FC-FPSO-05IPERC Continuo is a mandatory package item where applicable
FC-FPSO-03FC-FPSO-07ToolReadiness is a package item, distinct from EquipmentReadiness
FC-FPSO-04FC-FPSO-06Crew change is a delta category
FC-FPSO-06FC-FPSO-03MATERIAL_DELTA blocks package authorization
FC-FPSO-06FC-FPSO-05MATERIAL_DELTA forces IPERC REASSESS_REQUIRED
FC-FPSO-08FC-FPSO-03Package authorization requires a bound signature act
FC-FPSO-08FC-FPSO-05IPERC confirmation/review/authorization each require binding

L · State / Transition Catalogue

ContractStatesTransitionsForbidden
FC-FPSO-01862
FC-FPSO-021132
FC-FPSO-03952
FC-FPSO-04642
FC-FPSO-05733
FC-FPSO-06532
FC-FPSO-07621
FC-FPSO-08722

§13 · Pure Core / Effectful Shell

BehaviourClassificationContract
Candidate selection from a location snapshotPURE COREFC-FPSO-01
GPS position readEFFECTFUL SHELLFC-FPSO-01
Applicability evaluation over retrieved metadataPURE COREFC-FPSO-02
Corporate document system retrievalEFFECTFUL SHELLFC-FPSO-02
Package completeness evaluation (conjunctive)PURE COREFC-FPSO-03
Persistence of package stateEFFECTFUL SHELLFC-FPSO-03
Crew rule evaluation over decision factsPURE COREFC-FPSO-04
Identity service callEFFECTFUL SHELLFC-FPSO-04
IPERC prepopulation rule applicationPURE COREFC-FPSO-05
Delta materiality evaluationPURE COREFC-FPSO-06
Tool readiness conjunctionPURE COREFC-FPSO-07
Signature binding validationPURE COREFC-FPSO-08
Signature/trust service invocationEFFECTFUL SHELLFC-FPSO-08

M · Invalid-State Catalogue

§17 — structurally illegal combinations

IDInvalid statePrevented byContracts
IS-01AuthorizedWithoutDecisionRightAuthorityEngine gate on every authorization transitionFC-FPSO-03, FC-FPSO-05, FC-FPSO-08
IS-02SignedVersionDifferentFromCurrentVersionRULE-SIG-VERSION-INVALIDATIONFC-FPSO-08
IS-03ConfirmedLocationWithoutLocationCandidateOrManualSelectionConfirmation requires a candidate or manual selection antecedentFC-FPSO-01
IS-04IPERCAuthorizedWhileMaterialDeltaOpenOpen MATERIAL_DELTA forces REASSESS_REQUIREDFC-FPSO-05, FC-FPSO-06
IS-05PackageAuthorizedWithMandatoryItemIncompleteConjunctive completeness predicateFC-FPSO-03
IS-06ToolReadyWithRequiredInspectionInvalidRULE-TOOL-READINESS conjunctionFC-FPSO-07
IS-07CrewValidWhileMandatoryCompetencyInvalidRULE-CREW-COMPETENCY-VALIDITYFC-FPSO-04
IS-08RetrievedDocumentTreatedAsApplicableWithoutApplicabilityEvaluationApplicabilityStatus is mandatory on every candidateFC-FPSO-02

N · ReasonCode Catalogue

§16 — no reasoning encoded only in free text

CodeMeaningContract
LOC-RC-01ACCURACY_BELOW_THRESHOLDFC-FPSO-01
LOC-RC-02NO_CANDIDATE_IN_RADIUSFC-FPSO-01
LOC-RC-03AMBIGUOUS_CANDIDATE_SETFC-FPSO-01
LOC-RC-04POSITION_SOURCE_UNAVAILABLEFC-FPSO-01
LOC-RC-05MANUAL_OVERRIDE_APPLIEDFC-FPSO-01
LOC-RC-06LOCATION_CHANGED_MID_SHIFTFC-FPSO-01
DOC-RC-01SOURCE_UNAVAILABLEFC-FPSO-02
DOC-RC-02METADATA_INSUFFICIENTFC-FPSO-02
DOC-RC-03MULTIPLE_ACTIVE_REVISIONSFC-FPSO-02
DOC-RC-04SUPERSEDED_AFTER_RETRIEVALFC-FPSO-02
DOC-RC-05DOCUMENT_NOT_FOUNDFC-FPSO-02
DOC-RC-06CONFLICTING_SOURCE_RECORDSFC-FPSO-02
PKG-RC-01MANDATORY_ITEM_INCOMPLETEFC-FPSO-03
PKG-RC-02MANDATORY_ITEM_UNVERIFIABLEFC-FPSO-03
PKG-RC-03MATERIAL_DELTA_OPENFC-FPSO-03
PKG-RC-04CRITICAL_CONTROL_NOT_VERIFIEDFC-FPSO-03
PKG-RC-05SIMOPS_CUMULATIVE_BLOCKFC-FPSO-03
PKG-RC-06AUTHORITY_UNRESOLVEDFC-FPSO-03
PKG-RC-07RESTRICTION_ACTIVEFC-FPSO-03
CRW-RC-01MANDATORY_ROLE_ABSENTFC-FPSO-04
CRW-RC-02COMPETENCY_EXPIREDFC-FPSO-04
CRW-RC-03COMPETENCY_UNVERIFIABLEFC-FPSO-04
CRW-RC-04FITNESS_NOT_CONFIRMEDFC-FPSO-04
CRW-RC-05IDENTITY_NOT_CONFIRMEDFC-FPSO-04
CRW-RC-06UNPLANNED_PERSON_PRESENTFC-FPSO-04
IPC-RC-01CREW_CHANGEFC-FPSO-05
IPC-RC-02LOCATION_CHANGEFC-FPSO-05
IPC-RC-03TASK_CHANGEFC-FPSO-05
IPC-RC-04DOCUMENT_REVISION_CHANGEFC-FPSO-05
IPC-RC-05NEW_HAZARDFC-FPSO-05
IPC-RC-06CONTROL_CHANGEFC-FPSO-05
IPC-RC-07SIMOPS_CHANGEFC-FPSO-05
IPC-RC-08HOLD_POINT_REACHEDFC-FPSO-05
IPC-RC-09CROSS_REVIEW_REQUIREDFC-FPSO-05
IPC-RC-10RESIDUAL_RISK_NOT_ACCEPTEDFC-FPSO-05
DLT-RC-01LOCATION_DELTAFC-FPSO-06
DLT-RC-02CREW_DELTAFC-FPSO-06
DLT-RC-03EQUIPMENT_DELTAFC-FPSO-06
DLT-RC-04TOOL_DELTAFC-FPSO-06
DLT-RC-05ENVIRONMENT_DELTAFC-FPSO-06
DLT-RC-06SIMOPS_DELTAFC-FPSO-06
DLT-RC-07ACCESS_DELTAFC-FPSO-06
DLT-RC-08RESTRICTION_DELTAFC-FPSO-06
DLT-RC-09DOCUMENT_REVISION_DELTAFC-FPSO-06
DLT-RC-10CRITICAL_CONTROL_DELTAFC-FPSO-06
DLT-RC-11UNEXPECTED_HAZARDFC-FPSO-06
TLR-RC-01INSPECTION_EXPIREDFC-FPSO-07
TLR-RC-02INSPECTION_NOT_PERFORMEDFC-FPSO-07
TLR-RC-03CERTIFICATION_INVALIDFC-FPSO-07
TLR-RC-04CONDITION_DEFECTIVEFC-FPSO-07
TLR-RC-05TOOL_ABSENTFC-FPSO-07
TLR-RC-06RESTRICTION_ON_TOOLFC-FPSO-07
SIG-RC-01DECISION_RIGHT_ABSENTFC-FPSO-08
SIG-RC-02CREDENTIAL_INVALIDFC-FPSO-08
SIG-RC-03CONTENT_CHANGED_AFTER_SIGNATUREFC-FPSO-08
SIG-RC-04IDENTITY_SERVICE_UNAVAILABLEFC-FPSO-08
SIG-RC-05SIGNATURE_METHOD_NOT_PERMITTED_FOR_OBJECTFC-FPSO-08
SIG-RC-06SIGNER_DECLINEDFC-FPSO-08

O · Event Catalogue

GovernedOperationalEvent schema unchanged

EventContractDomain
LOCATION_CANDIDATES_DERIVEDFC-FPSO-01FIELD_PRESTART
LOCATION_CONFIRMEDFC-FPSO-01FIELD_PRESTART
LOCATION_CHANGE_DETECTEDFC-FPSO-01FIELD_PRESTART
DOCUMENT_CANDIDATE_SET_DERIVEDFC-FPSO-02FIELD_PRESTART
DOCUMENT_REVISION_CHANGE_DETECTEDFC-FPSO-02FIELD_PRESTART
DOCUMENT_CONFLICT_RAISEDFC-FPSO-02FIELD_PRESTART
PACKAGE_COMPOSEDFC-FPSO-03FIELD_PRESTART
PACKAGE_COMPLETENESS_EVALUATEDFC-FPSO-03FIELD_PRESTART
PACKAGE_AUTHORIZEDFC-FPSO-03FIELD_PRESTART
PACKAGE_REASSESS_RAISEDFC-FPSO-03FIELD_PRESTART
CREW_CONFIRMEDFC-FPSO-04FIELD_PRESTART
CREW_EXCEPTION_RAISEDFC-FPSO-04FIELD_PRESTART
CREW_CHANGE_DETECTEDFC-FPSO-04FIELD_PRESTART
IPERC_PREPOPULATEDFC-FPSO-05FIELD_PRESTART
IPERC_CONFIRMEDFC-FPSO-05FIELD_PRESTART
IPERC_REVIEWEDFC-FPSO-05FIELD_PRESTART
IPERC_AUTHORIZEDFC-FPSO-05FIELD_PRESTART
IPERC_REASSESS_RAISEDFC-FPSO-05FIELD_PRESTART
IPERC_CLOSEDFC-FPSO-05FIELD_PRESTART
DELTA_ASSESSEDFC-FPSO-06FIELD_PRESTART
MATERIAL_DELTA_RAISEDFC-FPSO-06FIELD_PRESTART
MATERIAL_DELTA_DISPOSITIONEDFC-FPSO-06FIELD_PRESTART
TOOL_VERIFIEDFC-FPSO-07FIELD_PRESTART
TOOL_NOT_READY_RAISEDFC-FPSO-07FIELD_PRESTART
TOOL_QUARANTINEDFC-FPSO-07FIELD_PRESTART
SIGNATURE_APPLIEDFC-FPSO-08FIELD_PRESTART
SIGNATURE_INVALIDATED_BY_VERSION_CHANGEFC-FPSO-08FIELD_PRESTART
SIGNATURE_REJECTEDFC-FPSO-08FIELD_PRESTART

§14–15 · Concurrency & Idempotency

Rule
NO_LAST_WRITE_WINS
Mechanism
Optimistic concurrency on object version at the finest governed granularity (row, item, tool, crew member).
Conflict outcome
CONCURRENCY_CONFLICT preserving both versions for authorized reconciliation.

Every contract defines an idempotency key so repeated external triggers cannot duplicate package items, signatures, approvals or operational events, nor silently change state.

P · Contract Requirement Traceability Matrix

§18 — no orphaned AIA capability

AIA capabilityContractParent contractRule / configurationAcceptance predicate
Resolve physical position to canonical locationFC-FPSO-01LocationOperationalContextRULE-LOC-CANDIDATE-SELECTION / ProximityRadiusConfigAP-01-1
Human confirmation of working locationFC-FPSO-01DecisionRightCONFIRM_WORK_LOCATIONAP-01-1
Degraded positioning behaviourFC-FPSO-01ProvenanceChainAccuracyThresholdConfigAP-01-3
Contextual controlled-document surfacingFC-FPSO-02RequirementCatalogueContextToDocumentClassApplicabilityConfigAP-02-1
Revision integrity and supersession handlingFC-FPSO-02RecordCatalogueRULE-DOC-REVISION-SELECTIONAP-02-2
Pre-start item orchestrationFC-FPSO-03JobCard / WorkPackageMandatoryItemApplicabilityConfigAP-03-1
Non-compensatory package completenessFC-FPSO-03RuleVersionRULE-PKG-COMPLETENESSAP-03-2
Critical control verification referenceFC-FPSO-03ActivityRiskItemClassCatalogueAP-03-1
SIMOPS condition surfaced at pre-startFC-FPSO-03SIMOPSInteractionRiskcumulative SIMOPS (parent)AP-03-1
Crew presence and identity confirmationFC-FPSO-04JobCardRequiredRoleMatrixConfigAP-04-1
Competency / training / fitness decision factsFC-FPSO-04RequirementCatalogueRULE-CREW-COMPETENCY-VALIDITYAP-04-2
IPERC Continuo as a governed recordFC-FPSO-05RecordCatalogueRULE-IPERC-PREPOPULATIONAP-05-1
Prepopulation without authorship substitutionFC-FPSO-05ProvenanceChainPrepopulationRuleConfigAP-05-2
Continuous reassessment triggersFC-FPSO-05GovernedOperationalEventRULE-IPERC-REASSESS-TRIGGERAP-05-3
Expected vs observed field contextFC-FPSO-06LocationOperationalContextRULE-DELTA-MATERIALITYAP-06-1
No inheritance of prior authorizationFC-FPSO-06DecisionRightMaterialityThresholdConfigAP-06-1
Tool readiness distinct from equipmentFC-FPSO-07EquipmentRequiredToolByActivityConfigAP-07-3
Physical verification over list presenceFC-FPSO-07RecordCatalogueRULE-TOOL-READINESSAP-07-2
Signature binds identity/authority/content/versionFC-FPSO-08DecisionRightRULE-SIG-BINDINGAP-08-1
Version change invalidates prior signatureFC-FPSO-08RuleVersionRULE-SIG-VERSION-INVALIDATIONAP-08-2
Signature tier distinction without legal claimFC-FPSO-08CanonicalSemanticDictionarySignatureMethodByObjectClassConfigAP-08-3

OrphanedCapabilities = 0.

Q · Open Dependency Register

§19 — gaps are not converted into assumptions

IDContractClassificationDescriptionOwner
OD-01FC-FPSO-01EXTERNAL VALIDATION DEPENDENCYProximity radius and accuracy policy for location candidate derivationLocation steward (ADR-14 stewardship, unstaffed)
OD-02FC-FPSO-01EXTERNAL VALIDATION DEPENDENCYCorporate policy on positional data retention and personnel-tracking prohibitionData privacy owner
OD-03FC-FPSO-02EXTERNAL VALIDATION DEPENDENCYRetrievable metadata fields and participation mode per document sourceDocument control owner
OD-04FC-FPSO-03CONTRACT DEFINITION GAPMandatory-item designation per activity class requires configuration governance (links F-DEAP-01)Rule governance authority (ADR-16)
OD-05FC-FPSO-03EXTERNAL VALIDATION DEPENDENCYPermit / isolation referenceable identifiers and statesWork control system owner
OD-06FC-FPSO-04EXTERNAL VALIDATION DEPENDENCYMinimal decision-fact set acceptable under privacy and occupational health policyPrivacy + occupational health owners
OD-07FC-FPSO-05EXTERNAL VALIDATION DEPENDENCYIPERC Continuo lifecycle validated against site legal and client requirementsES&H authority
OD-08FC-FPSO-05CONTRACT DEFINITION GAPCross-review and hold-point trigger thresholdsRule governance authority
OD-09FC-FPSO-06EXTERNAL VALIDATION DEPENDENCYMateriality thresholds per delta categoryES&H + Construction authorities
OD-10FC-FPSO-07EXTERNAL VALIDATION DEPENDENCYTool inspection regime, certification classes and colour-code policyTools / equipment authority
OD-11FC-FPSO-08EXTERNAL VALIDATION DEPENDENCYLegal, corporate and client signature requirementsLegal + corporate compliance
OD-12FC-FPSO-08EXTERNAL VALIDATION DEPENDENCYIdentity provider and trust service selectionEnterprise IAM authority (ADR-08)

No open dependency has been converted into a design assumption. Where owner validation is absent, the contract records the gap and fails closed rather than adopting a default.

R · Contract Completeness Assessment

§3 — mandatory 38-element schema

ContractElementsResult
FC-FPSO-0140 / 38CONTRACT COMPLETE
FC-FPSO-0240 / 38CONTRACT COMPLETE
FC-FPSO-0340 / 38CONTRACT COMPLETE
FC-FPSO-0440 / 38CONTRACT COMPLETE
FC-FPSO-0540 / 38CONTRACT COMPLETE
FC-FPSO-0640 / 38CONTRACT COMPLETE
FC-FPSO-0740 / 38CONTRACT COMPLETE
FC-FPSO-0840 / 38CONTRACT COMPLETE

§21 · G-FPSO-02 — Contract Completeness

Evaluated, not frozen

ContractDefStateAuthoritySourceFailureConcurIdemProvPredicatesAmbiguity
FC-FPSO-01YESYESYESYESYESYESYESYESYES1
FC-FPSO-02YESYESYESYESYESYESYESYESYES1
FC-FPSO-03YESYESYESYESYESYESYESYESYES2
FC-FPSO-04YESYESYESYESYESYESYESYESYES1
FC-FPSO-05YESYESYESYESYESYESYESYESYES2
FC-FPSO-06YESYESYESYESYESYESYESYESYES1
FC-FPSO-07YESYESYESYESYESYESYESYESYES0
FC-FPSO-08YESYESYESYESYESYESYESYESYES2
READY FOR CONTRACT ASSURANCEFROZEN = FALSEOpenSemanticAmbiguityCount total = 10

All eight contracts satisfy the mandatory 38-element schema; state, authority, source, failure, concurrency, idempotency, provenance and acceptance-predicate elements are defined for every contract. Residual semantic ambiguity (10 items) is registered as open dependency, not as a definition gap masked by an assumption.

§22 · Required Final State

Definition output of record

FPSO_FUNCTIONAL_CONTRACT_DEFINITION
COMPLETE
DefinitionID
PH6A-FPSO-FCD-REV0
ContractsDefined
8
ArchitectureChanges
0
ParentBaselineChanges
0
ContractScopeDeviation
0
G-FPSO-02
READY_FOR_CONTRACT_ASSURANCE
FunctionalBaselineFrozen
FALSE
UIImplementation
NOT_STARTED
PrototypeImplementation
NOT_STARTED
Simulation
NOT_STARTED
OperationalClosureEvidence
NOT_YET_ACQUIRED

Definition is not acceptance. This contract set was subsequently assured and frozen under PH6A-FPSO-FCA-REV0 (gate G-FPSO-03) — see the assurance sections below.

PH6A-FPSO-FCA-REV0 · A — Assurance Executive Decision

Independent functional architecture assurance · Design Assurance Evidence only

PASS WITH CONTROLLED EXTERNAL DEPENDENCIESFunctionalBaseline FROZENPhase6A HOLDPilotExposure PROHIBITED

The eight descendant contracts are semantically closed after 9 controlled corrections. All internal semantic ambiguity is resolved; every remaining open item is a genuinely external owner decision that cannot be closed by design and does not make contract behaviour indeterminate. The set is fit to become Requirements of Record for implementation.

This is not an unconditional PASS: 12 external validation dependencies remain controlled-open and no operational evidence exists. Freeze governs specification, not readiness.

AssuranceID
PH6A-FPSO-FCA-REV0
Input definition
PH6A-FPSO-FCD-REV0
Parent baseline
PH6A-IADA-REV1 (unchanged)
Evidence class
DESIGN_ASSURANCE_EVIDENCE
Confirmed out of scope
  • · UI design
  • · Route/component creation for the Pre-Start Board
  • · Prototype behaviour
  • · Demo scenarios and synthetic operational data
  • · Operational simulation
  • · Operational closure evidence
  • · Any modification of PH6A-IADA-REV1

B · Input Integrity Assessment

Prompt 1 self-reporting recounted, not trusted

AttributeClaimedObservedVerdictNote
ContractsDefined88CONFIRMED
ContractScopeDeviation00CONFIRMED
StatesReported6059CONFIRMED WITH NOTECounted from permittedStates across the eight contracts.
TransitionsReported3328CONFIRMED WITH NOTERecount from the definition module is authoritative over the reported figure.
ForbiddenTransitionsReported2016CONFIRMED WITH NOTE
InvalidStatesReported88CONFIRMED
ReasonCodesReported5558CONFIRMED WITH NOTE
EventsReported2628CONFIRMED WITH NOTE
OrphanedCapabilities00CONFIRMED
OpenDependencies1212CONFIRMED
ContractDefinitionGaps22CONFIRMED
ExternalValidationDependencies1010CONFIRMED WITH NOTERegister carries 10 EXTERNAL_VALIDATION_DEPENDENCY rows at OD level; contract-level clauses expand these to 12 distinct owner decisions at freeze (§AJ).
OpenSemanticAmbiguityCount1010CONFIRMEDSelf-reported completeness not accepted as assurance; each item reconciled individually in §C.

INPUT_INTEGRITY = ACCEPTED_FOR_ASSURANCE. Prompt 1 self-reported completeness was recounted from the definition module rather than trusted; recounted values govern where they differ from the reported figures.

C · Open Semantic Ambiguity Reconciliation — all 10

OpenSemanticAmbiguityCount at freeze = 0

AMB-01FC-FPSO-01LOCATION_CHANGED_AFTER_CONFIRMATIONCORRECTED DURING ASSURANCERISK HIGH
Interpretation A
A new confirmation replaces Location_ID on the existing pre-start records.
Interpretation B
A new confirmation creates a successor LocationConfirmation and triggers dependency-scoped impact analysis.
Material behaviour impact
Determines whether authorizations survive a location change.
State model impact
Requires an explicit SUPERSEDED terminal state on LocationConfirmation.
Authority impact
Interpretation A silently preserves authorization without DecisionRight re-exercise.
Source boundary impact
None — GPS remains candidate-only under both readings.
Determinism impact
HIGH: identical facts could yield authorized or reassess-required.
Failure behaviour impact
Ambiguous downstream invalidation on GPS drift.
Required resolution
Interpretation B made normative; Location_ID is immutable once dependent records exist.
Finding
F-FCA-01
AMB-02FC-FPSO-02MULTIPLE_ACTIVE_REVISIONSCORRECTED DURING ASSURANCERISK HIGH
Interpretation A
Select the latest effective revision automatically.
Interpretation B
Fail closed to DOCUMENT_REVISION_AMBIGUOUS and require document-control resolution.
Material behaviour impact
Determines whether the system silently picks a controlled document baseline.
State model impact
Adds REVISION_AMBIGUOUS as a non-terminal blocked state.
Authority impact
Interpretation A promotes retrieval logic into applicability authority.
Source boundary impact
Interpretation A promotes the retrieval adapter above the document owner.
Determinism impact
MEDIUM: deterministic but wrong-authority.
Failure behaviour impact
A must not be used under SOURCE_UNAVAILABLE.
Required resolution
Interpretation B normative; no automatic revision election.
Finding
F-FCA-02
AMB-03FC-FPSO-03MandatoryItemApplicabilityConfigCORRECTED DURING ASSURANCERISK HIGH
Interpretation A
Absent configuration means the item is not mandatory.
Interpretation B
Absent configuration means package completeness is UNDETERMINABLE and fails closed.
Material behaviour impact
Determines whether missing configuration silently authorizes work.
State model impact
Adds COMPLETENESS_UNDETERMINABLE as a blocking state.
Authority impact
Interpretation A creates authorization by configuration omission.
Source boundary impact
None.
Determinism impact
HIGH.
Failure behaviour impact
Defines behaviour when the rule/config service is unavailable.
Required resolution
Interpretation B normative; the owner decision on which items are mandatory remains external.
Finding
F-FCA-03
AMB-04FC-FPSO-03Item becomes invalid after package preparationCORRECTED DURING ASSURANCERISK HIGH
Interpretation A
Package retains PACKAGE_COMPLETE and records an advisory flag.
Interpretation B
Package transitions to REASSESS_REQUIRED and any authorization ceases to be effective for the new version.
Material behaviour impact
Directly governs stale authorization.
State model impact
Requires a defined recovery transition back through completeness evaluation.
Authority impact
Interpretation A inherits authorization across a material change.
Source boundary impact
None.
Determinism impact
HIGH.
Failure behaviour impact
Defined for source revision change and tool invalidation.
Required resolution
Interpretation B normative and scoped to dependent items only.
Finding
F-FCA-04
AMB-05FC-FPSO-04Crew member replacement after authorizationCORRECTED DURING ASSURANCERISK HIGH
Interpretation A
Replacement inherits the role slot and the package remains authorized.
Interpretation B
Replacement is a material crew delta: the new person's competency facts are evaluated independently and the affected authorization requires re-exercise.
Material behaviour impact
Governs competency inheritance.
State model impact
CrewConfirmationRecord requires a versioned successor, not in-place mutation.
Authority impact
Interpretation A transfers DecisionRight by role slot — prohibited.
Source boundary impact
Competency source remains authoritative per person.
Determinism impact
HIGH.
Failure behaviour impact
Under competency-source unavailability the replacement is NOT_CONFIRMED.
Required resolution
Interpretation B normative; no person-to-person inheritance of competency or DecisionRight.
Finding
F-FCA-05
AMB-06FC-FPSO-05SUPERVISOR_REVIEWED → AUTHORIZEDCORRECTED DURING ASSURANCERISK HIGH
Interpretation A
Supervisor review completes the record and therefore authorizes it.
Interpretation B
Review and authorization are distinct transitions; authorization requires an explicit DecisionRight exercise even when the same person holds both.
Material behaviour impact
Governs whether completing a record manufactures authorization.
State model impact
Two transitions, two events, two reason-code sets.
Authority impact
Interpretation A merges EvidenceEngine and AuthorityEngine — prohibited by the parent baseline.
Source boundary impact
None.
Determinism impact
MEDIUM.
Failure behaviour impact
Authorization must fail closed when the authority service is unavailable.
Required resolution
Interpretation B normative and stated as an invariant.
Finding
F-FCA-06
AMB-07FC-FPSO-05Cross-review trigger thresholds (CONTRACT_DEFINITION_GAP OD-08)CORRECTED DURING ASSURANCERISK HIGH
Interpretation A
Absent thresholds, cross-review is never triggered.
Interpretation B
Absent thresholds, the trigger evaluates to UNDETERMINABLE and the record cannot reach AUTHORIZED for the affected risk class.
Material behaviour impact
Governs behaviour under missing configuration.
State model impact
No new state; existing blocking state reused.
Authority impact
Interpretation A creates authorization by omission.
Source boundary impact
None.
Determinism impact
HIGH.
Failure behaviour impact
Defined fail-closed behaviour.
Required resolution
Contract behaviour under absent thresholds is fixed (fail closed); the threshold values themselves remain an owner decision.
Finding
F-FCA-07
AMB-08FC-FPSO-06MATERIAL_DELTA scope of invalidationCORRECTED DURING ASSURANCERISK HIGH
Interpretation A
A material delta invalidates the whole pre-start package.
Interpretation B
A material delta invalidates exactly the dependency-scoped set declared in the delta-category-to-dependency map; anything outside the map is unaffected.
Material behaviour impact
Governs proportionality of invalidation.
State model impact
Requires per-item REASSESS_REQUIRED rather than package-level only.
Authority impact
Neither reading grants authority; B prevents blanket re-authorization theatre.
Source boundary impact
None.
Determinism impact
HIGH: without a declared map, impact scope is implementer-chosen.
Failure behaviour impact
When the map cannot be evaluated, the widest declared scope applies (fail safe).
Required resolution
Interpretation B normative with an explicit delta-category → dependency map; materiality thresholds remain external.
Finding
F-FCA-08
AMB-09FC-FPSO-08Repeated signature request / concurrent modification during signingCORRECTED DURING ASSURANCERISK HIGH
Interpretation A
A repeated request produces an additional signature record.
Interpretation B
Signature requests are idempotent on (Object_ID, ObjectVersion, SignerIdentity, DecisionRight, Idempotency_Key); a repeat returns the existing signature, and any version change mid-flight aborts with SIGNATURE_VERSION_CONFLICT.
Material behaviour impact
Prevents duplicate signature evidence and signature on a moved target.
State model impact
Adds SIGNATURE_VERSION_CONFLICT as an explicit non-terminal outcome.
Authority impact
Neither reading grants authority; B prevents evidence inflation.
Source boundary impact
Trust-service selection remains external.
Determinism impact
HIGH.
Failure behaviour impact
Signature service unavailable → NOT_SIGNED, never optimistic signature.
Required resolution
Interpretation B normative.
Finding
F-FCA-09
AMB-10FC-FPSO-08Legal sufficiency of the signature tiersRESOLVED BY EXISTING CONTRACTRISK LOW
Interpretation A
The defined tier constitutes a legally sufficient signature.
Interpretation B
The contract binds identity, authority, content, version and time; legal sufficiency is asserted only by the competent legal owner.
Material behaviour impact
None on system behaviour; material on claims made.
State model impact
None.
Authority impact
Interpretation A would assert legal authority the system does not hold.
Source boundary impact
None.
Determinism impact
None — behaviour identical under both.
Failure behaviour impact
None.
Required resolution
Interpretation B already normative in the contract text; legal validation stays external and unassumed.
Finding

Corrected during assurance: 9 · resolved by existing contract: 1 · blocking: 0 · OpenSemanticAmbiguityCount_at_Freeze = 0.

D · Contract Definition Gap Reconciliation — both 2

ContractDefinitionGaps at freeze = 0

IDODContractAffected elementsMaterialCorrectionResidual external itemOutcome
GAP-01OD-04FC-FPSO-03Preconditions, Postconditions, StateTransition, RuleDependency, FailureBehaviour, AcceptancePredicateYESContract now defines behaviour under absent mandatory-item configuration: completeness evaluates to COMPLETENESS_UNDETERMINABLE, the package cannot reach PACKAGE_COMPLETE, and reason code RC-PKG-CONFIG-ABSENT is emitted. The absence of configuration can never be read as 'not mandatory'.Which items are mandatory per activity class — rule governance authority (ADR-16).GAP CORRECTED
GAP-02OD-08FC-FPSO-05StateTransition, RuleDependency, FailureBehaviour, AcceptancePredicate, HumanValidationPointYESContract now defines behaviour under absent cross-review/hold-point thresholds: the trigger evaluates to UNDETERMINABLE for the affected risk class, AUTHORIZED is unreachable for that class, and reason code RC-IPERC-THRESHOLD-ABSENT is emitted. Threshold values are configuration, not contract semantics.Threshold values per risk class — ES&H + rule governance authority.GAP CORRECTED

E · External Validation Dependency Assessment

§5 controlled-open test · CurrentAssumption = NONE for all

IDContractOwnerDecision neededDeterm.No auth. assumptionNo source assumptionFailure definedFailure behaviour until validatedClosure evidence
XD-01FC-FPSO-01Location steward (ADR-14 stewardship, unstaffed)Proximity radius and positional accuracy policy per location classYESYESYESYESNo candidate is derived; LOCATION_CANDIDATE_UNAVAILABLE and manual selection with governed justificationSigned steward configuration decision
XD-02FC-FPSO-01Corporate data privacy ownerPositional data retention period and personnel-tracking prohibition scopeYESYESYESYESPosition retained only as decision provenance for the confirmation eventPrivacy owner written determination
XD-03FC-FPSO-02Document control owner (Aconex participation)Retrievable metadata fields and participation mode per sourceYESYESYESYESSOURCE_UNAVAILABLE / METADATA_INSUFFICIENT; retrieved documents cannot be marked applicableOwner confirmation of participation mode and metadata contract
XD-04FC-FPSO-03Rule governance authority (ADR-16)Mandatory-item designation per activity classYESYESYESYESCOMPLETENESS_UNDETERMINABLE; package cannot reach PACKAGE_COMPLETEApproved mandatory-item matrix
XD-05FC-FPSO-03Work control system owner (Q4 / Engica)Referenceable permit and isolation identifiers and statesYESYESYESYESPermit/isolation items remain NOT_VERIFIABLE and block completeness where mandatoryOwner confirmation of identifier and state contract
XD-06FC-FPSO-04Privacy + occupational health ownersMinimal decision-fact set exposed for fitness and competencyYESYESYESYESFitness fact absent → NOT_CONFIRMED, never assumed fitJoint owner determination
XD-07FC-FPSO-04Competency authority (Training/HR)Which body issues authoritative competency facts and their validity semanticsYESYESYESYESCompetency UNVERIFIABLE → crew member not valid for the mandatory roleAuthority designation record
XD-08FC-FPSO-05ES&H authorityIPERC Continuo lifecycle validated against site legal and client requirementsYESYESYESYESLifecycle as specified; no legal sufficiency assertedES&H written validation
XD-09FC-FPSO-05ES&H + rule governance authorityCross-review and hold-point threshold values per risk classYESYESYESYESTrigger UNDETERMINABLE → AUTHORIZED unreachable for that classApproved threshold table
XD-10FC-FPSO-06ES&H + Construction authoritiesMateriality thresholds per delta categoryYESYESYESYESDelta classified UNDETERMINABLE → treated as material (fail safe)Approved materiality matrix
XD-11FC-FPSO-07Tools / equipment authorityInspection regime, certification classes and colour-code policyYESYESYESYESInspection validity UNVERIFIABLE → tool NOT_READYApproved tool control standard
XD-12FC-FPSO-08Legal + corporate compliance and enterprise IAM (ADR-08)Signature legal/corporate/client requirements, identity provider and trust service selectionYESYESYESYESSignature binds identity, authority, content and version; legal sufficiency NOT asserted; service unavailable → NOT_SIGNEDLegal determination + IAM/trust-service decision record

Every dependency satisfies §5: behaviour deterministic, no authority assumed, no source authority assumed, no state meaning contingent on an unknown decision, failure behaviour defined, acceptance boundary defined. CurrentAssumption = NONE for all twelve; no temporary assumption was invented to enable freeze.

F · Contract Completeness Verification — 8/8

38 elements independently verified per contract

ContractNameElementsMaterial defects foundVerdict
FC-FPSO-01LocationAcquisitionService38F-FCA-01 location supersession semanticsCOMPLETE AFTER CORRECTION
FC-FPSO-02ContextualDocumentRetrieval38F-FCA-02 revision election prohibitionCOMPLETE AFTER CORRECTION
FC-FPSO-03PreStartPreventivePackage + PreStartPreventivePackageItem38F-FCA-03 absent-configuration fail-closed; F-FCA-04 post-preparation item invalidationCOMPLETE AFTER CORRECTION
FC-FPSO-04CrewConfirmationRecord38F-FCA-05 crew replacement non-inheritanceCOMPLETE AFTER CORRECTION
FC-FPSO-05IPERCContinuo38F-FCA-06 review ≠ authorization; F-FCA-07 absent threshold fail-closedCOMPLETE AFTER CORRECTION
FC-FPSO-06FieldDeltaAssessment38F-FCA-08 dependency-scoped invalidation mapCOMPLETE AFTER CORRECTION
FC-FPSO-07ToolReadiness38NoneCOMPLETE
FC-FPSO-08DigitalSignatureAssurance38F-FCA-09 signature idempotency & version conflictCOMPLETE AFTER CORRECTION

G · Cross-Contract Collision Matrix

Duplicate domain objects = 0

PairCollision classFindingVerdict
LocationAcquisition ↔ LocationOperationalContextDuplicateObject / DuplicateStateAuthorityFC-FPSO-01 produces a LocationConfirmation referencing the parent Location_ID; it never creates or mutates LocationOperationalContext. Corrected supersession semantics (F-FCA-01) removed the implicit in-place replacement path.COLLISION CORRECTED
ContextualDocumentRetrieval ↔ ApplicabilityResponsibilityLeakageRetrieval produces candidates with mandatory ApplicabilityStatus = NOT_EVALUATED; applicability evaluation remains the parent RequirementCatalogue/rule responsibility. Revision election prohibition (F-FCA-02) closed the residual leak.COLLISION CORRECTED
PreventivePackage ↔ IPERCHiddenSharedStateIPERC is referenced as a package item by identifier and version; the package never mirrors IPERC state. Item state derives from the referenced IPERC version, one-directional.NO COLLISION
PreventivePackage ↔ PETARSemanticOverlapPETAR applicability is a requirement-catalogue outcome consumed as an item; the package does not decide PETAR applicability.NO COLLISION
CrewConfirmation ↔ DecisionRightDuplicateStateAuthorityCrew confirmation produces presence/competency/fitness facts only. Corrected replacement semantics (F-FCA-05) removed role-slot inheritance, which was the only path to implicit DecisionRight transfer.COLLISION CORRECTED
CrewConfirmation ↔ competency sourcesDuplicateSourceAuthorityCompetency facts are federated per person from the designated authority; the contract never issues competency.NO COLLISION
FieldDelta ↔ ContinuityContradictoryTransitionDelta assessment raises reassessment requirements; continuity state remains owned by the parent readiness model. Dependency-scoped map (F-FCA-08) removed the contradictory blanket-invalidation path.COLLISION CORRECTED
FieldDelta ↔ IPERCCircularDependencyIPERC consumes delta outcomes; delta consumes expected context, not IPERC state. No cycle: the dependency graph is acyclic (verified over FCD_DEPENDENCY_MAP).NO COLLISION
ToolReadiness ↔ FunctionalReadinessSemanticOverlapTool readiness is an input fact to package completeness; it does not compute functional readiness or equipment readiness.NO COLLISION
DigitalSignatureAssurance ↔ AuthorityEngineDuplicateStateAuthoritySignature binds an already-granted DecisionRight exercise; it never grants, extends or repairs authority. Signature on an unauthorized decision is invalid by construction.NO COLLISION

H · State Normalization Assessment

States govern behaviour; they do not decorate workflow

ItemContractObservationDispositionRationale
LOCATION_CANDIDATE_DERIVED vs LOCATION_CANDIDATE_AMBIGUOUSFC-FPSO-01Both precede confirmation but permit different transitions (confirm vs manual-selection-only).RETAINED AS STATEBehaviourally distinct: ambiguity forbids single-candidate confirmation.
RETRIEVED / APPLICABILITY_NOT_EVALUATEDFC-FPSO-02APPLICABILITY_NOT_EVALUATED did not alter permitted transitions beyond RETRIEVED.RECLASSIFIEDReclassified as a mandatory attribute (ApplicabilityStatus) of RETRIEVED — attribute, not state. RETRIEVED ≠ APPLICABLE preserved without a decorative state.
PACKAGE_PREPARED vs PACKAGE_COMPLETEFC-FPSO-03Distinct transition sets (items mutable vs completeness evaluated).RETAINED AS STATEPACKAGE_EXISTS ≠ PACKAGE_COMPLETE ≠ AUTHORIZED is a governing invariant.
COMPLETENESS_UNDETERMINABLEFC-FPSO-03Introduced by correction F-FCA-03.RETAINED AS STATEAlters permitted transitions: forbids progression to PACKAGE_COMPLETE. Not a reason code.
SUPERVISOR_REVIEWED vs AUTHORIZEDFC-FPSO-05Prompt 1 permitted an implicit collapse.RETAINED AS STATESeparation is an authority invariant (F-FCA-06).
PENDING_REVIEW / AWAITING_REVIEW duplication scanALLNo behaviourally identical duplicate state names found across the eight contracts.RETAINED AS STATENo consolidation warranted; counts were not reduced cosmetically.
SIGNATURE_VERSION_CONFLICTFC-FPSO-08Introduced by correction F-FCA-09.RETAINED AS STATEGoverns an explicit recovery transition rather than an error label.

I · ReasonCode Normalization Assessment

ItemContractObservationDispositionRationale
RC-LOC-ACCURACY-LOW / RC-LOC-GPS-UNAVAILABLEFC-FPSO-01Different cause, same fallback.RETAINED AS REASON CODEDifferent owner and different recovery condition (device vs environment).
RC-DOC-NOT-FOUND / RC-DOC-SOURCE-UNAVAILABLEFC-FPSO-02Distinguish absence from unreachability.RETAINED AS REASON CODEDifferent owner (document control vs integration) and different recovery.
RC-DOC-REVISION-AMBIGUOUSFC-FPSO-02Added by F-FCA-02.RETAINED AS REASON CODENames a governed cause requiring document-owner resolution.
RC-PKG-ITEM-MISSING / RC-PKG-ITEM-INCOMPLETEFC-FPSO-03Materially identical response, ownership and evidence.CONSOLIDATEDConsolidated to RC-PKG-MANDATORY-ITEM-NOT-SATISFIED; item presence is an attribute of the item record.
RC-PKG-CONFIG-ABSENTFC-FPSO-03Added by F-FCA-03.RETAINED AS REASON CODEDistinct cause with a distinct owner (rule governance).
RC-CREW-NOT-PRESENT / RC-CREW-NOT-AUTHENTICATEDFC-FPSO-04Distinct evidence and distinct remedy.RETAINED AS REASON CODEPresence ≠ identity assurance.
RC-IPERC-THRESHOLD-ABSENTFC-FPSO-05Added by F-FCA-07.RETAINED AS REASON CODEConfiguration absence is a governed cause, not a generic error.
RC-DELTA-UNCLASSIFIED / RC-DELTA-THRESHOLD-ABSENTFC-FPSO-06Same response (treat as material), same owner, same evidence.CONSOLIDATEDConsolidated to RC-DELTA-MATERIALITY-UNDETERMINABLE.
RC-SIG-VERSION-CONFLICTFC-FPSO-08Added by F-FCA-09.RETAINED AS REASON CODEDistinct recovery: re-present current version for a new signature.
Free-text reason captureALLNo contract permits uncontrolled free-text as a governed cause.RETAINED AS REASON CODENarrative may accompany a code; it may never substitute for one.
States before
59
Reclassified
1
Added
2
Reason codes before
58
Consolidated
2
Added
3

States were neither added nor removed to influence counts; only semantic duplication and behavioural ambiguity were corrected.

J · State Machine Assurance

ContractReachabilityTransition completenessTerminal statesDead statesIllegal cyclesRecoveryAuthorityReason codeEvent
FC-FPSO-01ALL REACHABLECOMPLETE AFTER CORRECTIONCONFIRMED · SUPERSEDED00YESYESYESYES
FC-FPSO-02ALL REACHABLECOMPLETE AFTER CORRECTIONSUPERSEDED · WITHDRAWN00YESYESYESYES
FC-FPSO-03ALL REACHABLECOMPLETE AFTER CORRECTIONCLOSED · CANCELLED00YESYESYESYES
FC-FPSO-04ALL REACHABLECOMPLETE AFTER CORRECTIONSUPERSEDED · CLOSED00YESYESYESYES
FC-FPSO-05ALL REACHABLECOMPLETE AFTER CORRECTIONCLOSED · SUPERSEDED00YESYESYESYES
FC-FPSO-06ALL REACHABLECOMPLETE AFTER CORRECTIONDISPOSITIONED00YESYESYESYES
FC-FPSO-07ALL REACHABLECOMPLETEWITHDRAWN_FROM_SERVICE00YESYESYESYES
FC-FPSO-08ALL REACHABLECOMPLETE AFTER CORRECTIONSIGNED · INVALIDATED_FOR_VERSION00YESYESYESYES

No state is reachable through an undefined transition, and no material transition is executable because a presentation layer permits it — every material transition names its DecisionRight, reason code and emitted event.

K · Invalid State Assurance

Reachable illegal material states = 0

IDInvalid stateAttempted constructionPreventedMechanism
IS-01AuthorizedWithoutDecisionRightAuthorize package via completed evidence set onlyYESAuthorityEngine gate is a precondition on every AUTHORIZED transition; evidence completeness is a separate predicate.
IS-02SignedVersionDifferentFromCurrentVersionMutate content after signature and retain effectivenessYESRULE-SIG-VERSION-INVALIDATION + SIGNATURE_VERSION_CONFLICT (F-FCA-09).
IS-03ConfirmedLocationWithoutCandidateOrManualSelectionConfirm location from a null GPS fixYESConfirmation precondition requires a candidate or an attributed manual selection.
IS-04IPERCAuthorizedWhileMaterialDeltaOpenAuthorize while an open material delta affects the IPERC dependency scopeYESOpen MATERIAL_DELTA in scope forces REASSESS_REQUIRED; authorization transition is blocked.
IS-05PackageAuthorizedWithMandatoryItemIncompleteCompensate an incomplete mandatory item with surplus optional itemsYESConjunctive, non-weighted completeness predicate.
IS-06ToolReadyWithRequiredInspectionInvalidMark tool ready from list presenceYESRULE-TOOL-READINESS conjunction of inspection, certification and physical verification.
IS-07CrewValidWhileMandatoryCompetencyInvalidSubstitute a person into a role slot and inherit validityYESPer-person competency evaluation; role-slot inheritance removed (F-FCA-05).
IS-08RetrievedDocumentTreatedAsApplicableWithoutApplicabilityEvaluationConsume a retrieved document as applicableYESApplicabilityStatus is a mandatory attribute defaulting to NOT_EVALUATED; consumers must read it.
IS-09PackageCompleteWhileMandatoryItemConfigurationAbsentTreat missing configuration as 'not mandatory'YESCOMPLETENESS_UNDETERMINABLE (F-FCA-03). Added during assurance.
IS-10AuthorizationSurvivingLocationSupersessionReplace Location_ID in place after dependent records existYESLocation supersession creates a successor confirmation and dependency-scoped reassessment (F-FCA-01).

L · Authority Assurance

Every path attempted and structurally blocked

PathAttempted constructionImpossibleBlocked by
GPS → AuthorizationTreat a high-accuracy fix as location authority and proceedYESGPS yields CandidateFact only; confirmation is a DecisionRight exercise.
DocumentRetrieval → ApplicabilityAuthorityTreat retrieval success as applicabilityYESApplicabilityStatus mandatory; retrieval adapter holds no rule authority.
Evidence → AuthorizationComplete every record and infer authorizationYESEvidenceEngine ≠ DecisionEngine ≠ AuthorityEngine (parent invariant).
IPERCCompletion → AuthorizationConfirmed IPERC auto-authorizes workYESHUMAN_CONFIRMED ≠ AUTHORIZED (F-FCA-06).
CrewPresence → CompetencyAttendance list creates competencyYESCompetency is a federated fact from the designated authority.
Competency → DecisionRightCompetent person self-authorizesYESDecisionRight is granted by the authority model, not derived from competency.
Signature → DecisionRightSigning grants the right that was missingYESSignature binds an existing right; signature without DecisionRight is invalid.
UI Permission → DecisionRightVisible action button implies authorityYESMaterial transitions evaluate authority server-side; presentation state is not an input fact.

Identity ≠ Role ≠ Permission ≠ Competency ≠ DecisionRight — preserved across all eight contracts. AuthorityContradictions = 0.

M · Source Authority Assurance

SourceAuthority = OBJECT_SPECIFIC · promotions = 0

SourceAuthoritative forNot authoritative for
AconexControlled document identity, revision and statusApplicability, authorization, competency, risk acceptance
Q4 / EngicaPermit, isolation and work-control transaction stateLocation semantics, competency, document revision
ForwoodCritical control verification recordsPackage completeness, authorization
IAMIdentity and authentication assuranceDecisionRight, competency, fitness
HR / TrainingQualification and training validity factsDecisionRight, fitness for a specific task condition
HealthFitness decision fact (binary, non-clinical)Competency, authority
Device GPSNothing — candidate physical context onlyLocation identity, authorization, presence proof
Preserved distinctions
  • · CandidateSource ≠ AuthoritativeSource
  • · FederatedSource ≠ LocalSystemOfRecord

N–U · Contract Challenge Registers

Location · Documents · Package · Crew · IPERC · Delta · Tools · Signature

IDContractScenarioRequired behaviourProhibitedReason codeVerdict
CH-N1FC-FPSO-01GPS_LOW_ACCURACYCandidate flagged low-confidence; manual selection with attributed justification requiredSilent confirmationRC-LOC-ACCURACY-LOWASSURED
CH-N2FC-FPSO-01OVERLAPPING_LOCATIONSLOCATION_CANDIDATE_AMBIGUOUS; explicit human selection among candidatesNearest-centroid auto-pickRC-LOC-AMBIGUOUSASSURED
CH-N3FC-FPSO-01LOCATION_NOT_FOUNDNo candidate; manual selection from the governed location register onlyFree-text location creationRC-LOC-NOT-FOUNDASSURED
CH-N4FC-FPSO-01GPS_UNAVAILABLEManual selection path with provenance PositionSource = MANUALBlocking the whole pre-start on a device failureRC-LOC-GPS-UNAVAILABLEASSURED
CH-N5FC-FPSO-01MANUAL_SELECTIONSame confirmation semantics, different provenanceLower assurance treated as equal without provenanceRC-LOC-MANUALASSURED
CH-N6FC-FPSO-01LOCATION_CHANGED_AFTER_CONFIRMATIONSuccessor confirmation + dependency-scoped downstream impact analysis; prior confirmation SUPERSEDEDSilent Location_ID replacementRC-LOC-SUPERSEDEDASSURED AFTER CORRECTION
CH-O1FC-FPSO-02SUPERSEDED_DOCUMENTMarked SUPERSEDED and non-consumable for applicabilityPresenting as currentRC-DOC-SUPERSEDEDASSURED
CH-O2FC-FPSO-02MULTIPLE_ACTIVE_REVISIONSFail closed: DOCUMENT_REVISION_AMBIGUOUS pending document-control resolutionAutomatic latest-revision electionRC-DOC-REVISION-AMBIGUOUSASSURED AFTER CORRECTION
CH-O3FC-FPSO-02DOCUMENT_STATUS_UNKNOWNStatus UNKNOWN blocks applicability evaluationDefaulting to APPROVEDRC-DOC-STATUS-UNKNOWNASSURED
CH-O4FC-FPSO-02SOURCE_UNAVAILABLELast retrieved snapshot shown with RetrievedAt and STALE markingPresenting stale content as currentRC-DOC-SOURCE-UNAVAILABLEASSURED
CH-O5FC-FPSO-02METADATA_INSUFFICIENTCandidate not eligible for applicability evaluationInferring missing metadataRC-DOC-METADATA-INSUFFICIENTASSURED
CH-O6FC-FPSO-02DOCUMENT_REVISION_CHANGED_DURING_REVIEWDependency-scoped reassessment of items referencing that document versionSilent in-place substitutionRC-DOC-REVISION-CHANGEDASSURED AFTER CORRECTION
CH-P1FC-FPSO-03Mandatory item incompletePackage not complete; no compensation by other itemsWeighted scoringRC-PKG-MANDATORY-ITEM-NOT-SATISFIEDASSURED
CH-P2FC-FPSO-03Non-applicable itemExcluded with recorded applicability basisSilent omissionRC-PKG-ITEM-NOT-APPLICABLEASSURED
CH-P3FC-FPSO-03Item invalid after preparationREASSESS_REQUIRED on the dependent scope; authorization not effective for the new versionRetaining PACKAGE_COMPLETERC-PKG-ITEM-INVALIDATEDASSURED AFTER CORRECTION
CH-P4FC-FPSO-03Mandatory-item configuration absentCOMPLETENESS_UNDETERMINABLETreating absence as non-mandatoryRC-PKG-CONFIG-ABSENTASSURED AFTER CORRECTION
CH-P5FC-FPSO-03PETAR applicability changesItem set recomputed; new mandatory item blocks completeness until satisfiedGrandfathering the previous item setRC-PKG-APPLICABILITY-CHANGEDASSURED
CH-Q1FC-FPSO-04Replacement while package under reviewSuccessor crew record version; competency of the new person evaluated independentlyRole-slot inheritanceRC-CREW-CHANGEDASSURED AFTER CORRECTION
CH-Q2FC-FPSO-04Replacement after authorizationMaterial crew delta → dependency-scoped reassessment and re-exercise of the affected authorizationAuthorization inherited by the replacementRC-CREW-CHANGED-POST-AUTHASSURED AFTER CORRECTION
CH-Q3FC-FPSO-04Expected ≠ PresentSix distinct facts maintained: Expected, Present, Authenticated, Competent, Fit, AuthorizedCollapsing presence into competence or authorityRC-CREW-NOT-PRESENTASSURED
CH-R1FC-FPSO-05Prepopulation provenanceEach prepopulated line carries rule version, input fact and source recordPrepopulated content presented as human authorshipRC-IPERC-PREPOPULATEDASSURED
CH-R2FC-FPSO-05New hazard observed in fieldFIELD_OBSERVED entry appended with residual-risk recalculationOverwriting the prepopulated lineRC-IPERC-FIELD-ADDITIONASSURED
CH-R3FC-FPSO-05Supervisor review completes recordSUPERVISOR_REVIEWED only; authorization is a separate DecisionRight exerciseReview implying authorizationRC-IPERC-REVIEWEDASSURED AFTER CORRECTION
CH-R4FC-FPSO-05Cross-review thresholds absentTrigger UNDETERMINABLE; AUTHORIZED unreachable for the affected classAssuming no cross-review neededRC-IPERC-THRESHOLD-ABSENTASSURED AFTER CORRECTION
CH-S1FC-FPSO-06WeatherChange / SIMOPSChange / AccessChangeClassified against the delta-category dependency map; material deltas force reassessment of exactly the dependent scopeBlanket invalidation or blanket survivalRC-DELTA-MATERIALASSURED AFTER CORRECTION
CH-S2FC-FPSO-06Materiality thresholds absentRC-DELTA-MATERIALITY-UNDETERMINABLE → treated as material (fail safe)Treating unknown as immaterialRC-DELTA-MATERIALITY-UNDETERMINABLEASSURED AFTER CORRECTION
CH-S3FC-FPSO-06Similar prior task authorized yesterdayNo inheritance by similarity; authorization is per object versionPrecedent-based authorizationRC-DELTA-NO-INHERITANCEASSURED
CH-T1FC-FPSO-07Inspection expires during shiftTool becomes NOT_READY; dependent package items only are reassessedReadiness persisting to shift endRC-TOOL-INSPECTION-EXPIREDASSURED
CH-T2FC-FPSO-07Tool substitutionNew tool evaluated independently; prior verification not transferredInheriting readiness by tool classRC-TOOL-SUBSTITUTEDASSURED
CH-T3FC-FPSO-07Field condition contradicts source statusField observation prevails for readiness and raises a source discrepancy for the tool ownerSource status overriding physical verificationRC-TOOL-FIELD-DISCREPANCYASSURED
CH-T4FC-FPSO-07Duplicated tool referenceIdempotent on tool identity; one readiness record per tool per job card versionDuplicate readiness recordsRC-TOOL-DUPLICATE-IGNOREDASSURED
CH-U1FC-FPSO-08Content changes after signaturePrior signature INVALIDATED_FOR_VERSION; it remains valid evidence for the version it signedCarrying the signature forwardRC-SIG-VERSION-INVALIDATEDASSURED
CH-U2FC-FPSO-08Signer loses DecisionRight before commitSignature aborts; NOT_SIGNED with authority reason codeCompleting on a stale right checkRC-SIG-AUTHORITY-LOSTASSURED
CH-U3FC-FPSO-08Repeated signing requestIdempotent: returns the existing signature for the same key tupleDuplicate signature recordsRC-SIG-DUPLICATE-SUPPRESSEDASSURED AFTER CORRECTION
CH-U4FC-FPSO-08Signature service unavailable / offlineNOT_SIGNED; queued intent is not a signatureOptimistic or provisional signatureRC-SIG-SERVICE-UNAVAILABLEASSURED
CH-U5FC-FPSO-08Legal sufficiency claimLegalValidation = EXTERNAL_DEPENDENCY; no legal assertion madeDeclaring legal validityRC-SIG-LEGAL-EXTERNALASSURED

V · Document Revision Propagation

Impact is dependency-scoped; no global invalidation

DependentPropagatesBehaviour
Applicability evaluationYESRe-evaluated for the affected document class only.
PreStartPreventivePackageItemONLY IF DEPENDENTItems referencing the changed document version transition to REASSESS_REQUIRED.
IPERC ContinuoONLY IF DEPENDENTReassessment only where prepopulation drew on the changed document.
PETARONLY IF DEPENDENTOnly where the revision alters the applicability basis.
ChecklistONLY IF DEPENDENTChecklist instances bound to the prior revision are superseded, not silently rewritten.
SignatureONLY IF DEPENDENTSignature over a changed object version becomes INVALIDATED_FOR_VERSION.
AuthorizationONLY IF DEPENDENTAuthorization ceases to be effective for the new version of the dependent scope only.
Unrelated packages / job cardsNONo global invalidation. Impact is dependency-scoped.

W · Concurrency Assurance

NO_LAST_WRITE_WINS preserved; UncontrolledConcurrencyPaths = 0.

IDScenarioDetectionGoverned resolutionVerdict
CC-01TwoUsersModifyIPERCBaseVersion mismatch at line granularityCONCURRENCY_CONFLICT; both versions preserved for authorized reconciliationASSURED
CC-02TwoSupervisorsActOnPackageBaseVersion mismatch on package versionSecond action rejected with conflict; no silent overwrite of the first decisionASSURED
CC-03DocumentRevisionChangesDuringReviewReferenced document version changedDependent items to REASSESS_REQUIRED before any completion transitionASSURED
CC-04CrewChangesDuringApprovalCrew record version changedApproval aborts with RC-CREW-CHANGED; re-exercise requiredASSURED
CC-05FieldDeltaOccursDuringSignatureObject version incremented mid-flightSIGNATURE_VERSION_CONFLICT; signature not committedASSURED
CC-06OfflineUpdateConflictsWithOnlineUpdateQueued event BaseVersion ≠ server versionGoverned reconciliation by the resolution authority; queued event never auto-winsASSURED

X · Idempotency Assurance

UncontrolledReplayPaths = 0.

IDOperationIdempotency keyReplay outcomeVerdict
ID-01LocationConfirmation(JobCard_ID, Location_ID, Actor, Idempotency_Key)Returns the existing confirmation; no duplicate confirmation eventASSURED
ID-02DocumentRetrieval(Context hash, Source, RetrievalRequest_ID)Returns the same candidate set; no duplicate candidatesASSURED
ID-03PackageGeneration(JobCard_ID, JobCardVersion, RuleVersion)Returns the existing package; no duplicate itemsASSURED
ID-04CrewConfirmation(Package_ID, CrewRecordVersion, Person_ID)No duplicate crew rows; no state advancementASSURED
ID-05IPERCSubmission(IPERC_ID, ObjectVersion, Actor, Idempotency_Key)Returns the existing submissionASSURED
ID-06SignatureRequest(Object_ID, ObjectVersion, SignerIdentity, DecisionRight, Idempotency_Key)Returns the existing signature; no duplicate approvalsASSURED
ID-07EventSubmission(Event_ID)Deduplicated; events immutableASSURED

Y · Failure / Degraded Mode Assurance

IDFailureAffected capabilityAllowedProhibitedReason codeRecovery
FM-01GPS UNAVAILABLELocation candidate derivationManual selection from the governed register with provenanceBlocking all pre-start work; inventing a positionRC-LOC-GPS-UNAVAILABLEFix acquired at required accuracy
FM-02ACONEX OR SOURCE UNAVAILABLEDocument retrievalPresent last snapshot marked STALE with RetrievedAtPresenting stale as current; assuming approvalRC-DOC-SOURCE-UNAVAILABLESuccessful re-retrieval and revision confirmation
FM-03IAM UNAVAILABLEAuthentication and DecisionRight resolutionRead-only continuation of non-material activityAny material authorization transitionRC-AUTH-IAM-UNAVAILABLEIAM restored and right re-resolved
FM-04CRITICAL CONTROL SOURCE UNAVAILABLECritical control verification itemItem remains NOT_VERIFIABLETreating unverifiable as verifiedRC-CC-UNVERIFIABLESource restored and verification fact retrieved
FM-05SIGNATURE SERVICE UNAVAILABLESignature bindingNOT_SIGNED with retained intentProvisional or optimistic signatureRC-SIG-SERVICE-UNAVAILABLEService restored; signature re-requested against the current version
FM-06NETWORK OFFLINEAll federated reads/writesMinimum safe cached set; queued events with BaseVersionOffline authorization of material decisionsRC-NET-OFFLINEConnectivity restored and queue reconciled
FM-07SYNC PENDINGState currencyExplicit SYNC_PENDING marking on affected objectsPresenting pending state as committedRC-SYNC-PENDINGCommit confirmation received
FM-08SYNC CONFLICTReconciliationBoth versions preserved for governed resolutionLast-write-winsRC-SYNC-CONFLICTAuthorized reconciliation decision recorded
FM-09DOCUMENT VERSION CONFLICTDependent items and signaturesDependency-scoped reassessmentGlobal invalidation or silent substitutionRC-DOC-REVISION-CHANGEDReassessment completed for the dependent scope
FM-10LOCATION AMBIGUOUSLocation confirmationHuman selection among candidatesAuto-selectionRC-LOC-AMBIGUOUSExplicit confirmation recorded

TechnologyFailure ≠ AutomaticControlFailure and TechnologyFailure ≠ PermissionToBypassControl. Degradation narrows what may be decided; it never widens it.

Z · Pure Core / Effectful Shell Assessment

ConcernClassificationNote
Location candidate selection rule (given position + register)PURE COREDeterministic function of inputs; device access is shell.
GPS acquisitionEFFECTFUL SHELLMay fail; failure is an input fact to the core.
Applicability evaluationPURE CORERule + facts → applicability; no I/O.
Aconex retrievalEFFECTFUL SHELLAvailability is an input fact.
Package completeness predicatePURE COREConjunctive, non-weighted, testable in isolation.
Delta materiality classificationPURE COREThresholds are configuration inputs, not embedded constants.
Crew competency validity evaluationPURE COREFacts in, verdict out.
IAM / DecisionRight resolutionEFFECTFUL SHELLUnavailability blocks material decisions; it does not alter rule semantics.
Signature binding predicatePURE COREVersion/authority/content binding is decidable without the trust service.
Trust service invocation and persistenceEFFECTFUL SHELLFailure yields NOT_SIGNED.

AA · AI Containment Assurance

AI_OFF_MATERIAL_STATE_EQUIVALENCE = PRESERVED

Prohibited AI actionStructurally preventedMechanism
ConfirmLocationYESConfirmation requires a human DecisionRight exercise.
EstablishSourceAuthorityYESSource authority is configuration under governance, not inference.
MarkWorkerCompetentYESCompetency is a federated authoritative fact.
FinalizeMandatoryApplicabilityYESMandatory applicability requires human validation (parent invariant).
ApproveIPERCYESAuthorization transition requires DecisionRight.
ApprovePETARYESSame authority gate.
SignYESSignerIdentity must be an authenticated natural person.
GrantDecisionRightYESAuthority model is not writable by advisory output.
AuthorizeWorkYESAI output is AI_ADVISORY_OUTPUT and is never an input fact to material rule evaluation.

Removing all advisory output changes no material decision outcome; advisory output is excluded from the deterministic fact set by the AI-to-Rule firewall (PH6A-AHP-REV1.1).

AB · Determinism Assurance

Residual determinism defects = 0

Same Authoritative/Federated Facts + Same RuleVersions + Same Configuration + Same DecisionRights ⇒ Same Material Decision.

Non-determinism sources found and removed
  • · Automatic latest-revision election (FC-FPSO-02) — removed by F-FCA-02
  • · Implicit mandatory-item default under absent configuration (FC-FPSO-03) — removed by F-FCA-03
  • · Undeclared invalidation scope for material deltas (FC-FPSO-06) — removed by F-FCA-08

Determinism = PRESERVED

AC · Provenance Assurance

Provenance = COMPLETE_FOR_FUNCTIONAL_SCOPE

Value classReconstructableChain
PREPOPULATED_VALUEYESValue ← RuleVersion ← InputFact ← SourceRecord ← SourceSystem ← SourceOwner ← Timestamp ← (no human action; prepopulation is machine-attributed)
DERIVED_VALUEYESValue ← RuleVersion ← InputFacts ← SourceRecords ← Timestamp
RULE_EVALUATIONYESVerdict ← RuleVersion ← ConfigurationVersion ← FactSet ← Timestamp
AUTHORIZED_DECISIONYESDecision ← DecisionRight ← Actor identity ← ObjectVersion ← FactSet ← RuleVersion ← Timestamp
FIELD_CORRECTIONYESAppend-only successor entry; source-derived history preserved and never erased

AD · Event Model Assurance

28 events reviewed

Mandatory event attributes
  • · Event_ID
  • · EventType
  • · Object_ID
  • · ObjectVersion
  • · Actor
  • · Timestamp
  • · PreviousState
  • · ResultingState
  • · ReasonCode
  • · RuleVersion
  • · Correlation_ID
Duplicate semantics found and consolidated
  • · PackageItemUpdated vs PackageItemChanged (FC-FPSO-03) — consolidated to PackageItemVersionCreated

Events are immutable records of occurrence, not state. No consumer derives current state by replaying UI events alone.

AE · Traceability Assurance

Traceability = COMPLETE

AIA capabilities mapped
21
Orphaned capabilities
0
Orphaned contracts
0
Reverse chain
Contract → Originating AIA Capability (verified for 8/8)

AIA Capability → Contract → Parent Contract → Rule/Configuration → Acceptance Predicate

AF · FCA-P01…FCA-P20 Results

20/20 PASS · DESIGN_ASSURANCE_EVIDENCE only

IDPropertyMethodResultCorrection
FCA-P01GPS never authorizesAttempted construction of a GPS→authorization path over FC-FPSO-01 preconditions; no transition accepts a position fact as an authority input.PASS
FCA-P02Retrieved document never auto-becomes applicableApplicabilityStatus attribute mandatory and defaults to NOT_EVALUATED on every candidate.PASSF-FCA-02
FCA-P03Applicable document never grants authorityNo authorization transition lists applicability as a sufficient precondition.PASS
FCA-P04Prepopulated IPERC never equals confirmedSYSTEM_PREPOPULATED and HUMAN_CONFIRMED are separate states with a human transition between them.PASS
FCA-P05Confirmed IPERC never automatically equals authorizedReview→authorization separated as an invariant.PASSF-FCA-06
FCA-P06Material delta prevents stale authorizationOpen in-scope MATERIAL_DELTA forces REASSESS_REQUIRED before any effective authorization.PASSF-FCA-04
FCA-P07Mandatory incomplete package item prevents package completenessConjunctive predicate; no weighting operator exists in the contract.PASS
FCA-P08Attendance cannot create competencyPresence and competency are distinct facts with distinct sources.PASS
FCA-P09Competency cannot create DecisionRightDecisionRight resolution takes no competency input.PASS
FCA-P10Tool invalidity propagates only to dependent readinessTool→item dependency map scoped; unrelated items unaffected.PASS
FCA-P11Signed content mutation invalidates signature applicability to new versionVersion binding + INVALIDATED_FOR_VERSION terminal state.PASSF-FCA-09
FCA-P12Source unavailability cannot fabricate current dataAll degraded paths mark STALE/UNVERIFIABLE; no default-to-approved path exists.PASS
FCA-P13Concurrent update cannot silently overwriteBaseVersion required on every material write; conflict is an explicit outcome.PASS
FCA-P14Replay is idempotentIdempotency keys defined for all seven replayable operations.PASSF-FCA-09
FCA-P15AI output cannot transition material authority stateAdvisory output excluded from the deterministic fact set.PASS
FCA-P16Same governed input produces same deterministic decisionThree non-determinism sources removed; no remaining implementer-chosen default.PASSF-FCA-02 / F-FCA-03 / F-FCA-08
FCA-P17Document revision impact remains dependency-scopedPropagation table (§V) enumerates dependent scopes; no global invalidation path.PASS
FCA-P18Location change cannot silently preserve dependent authorizationSupersession creates a successor confirmation and scoped reassessment.PASSF-FCA-01
FCA-P19Crew replacement cannot inherit previous person's competency/authorityPer-person evaluation; role-slot inheritance removed.PASSF-FCA-05
FCA-P20Signature cannot repair an otherwise unauthorized decisionSignature precondition requires an already-valid DecisionRight exercise; otherwise the signature is invalid.PASS

These results do not constitute OPERATIONAL_EVIDENCE, DEMO_EVIDENCE, OPERATIONAL_CLOSURE_EVIDENCE. Simulation, prototype behaviour and operational evidence remain explicitly out of scope.

AG · Findings Register

0 critical · 8 high · 0 high uncontrolled

IDSeverityImpact classContractFindingStatus
F-FCA-01HIGHSEMANTIC_AMBIGUITY / AUTHORITY_DEFECTFC-FPSO-01Location change after confirmation permitted in-place Location_ID replacement, silently preserving dependent authorizations.CLOSED BY CORRECTION
F-FCA-02HIGHSOURCE_BOUNDARY_DEFECT / DETERMINISM_DEFECTFC-FPSO-02Multiple active revisions permitted an implicit automatic revision election by the retrieval layer.CLOSED BY CORRECTION
F-FCA-03HIGHCONTRACT_DEFECT / DETERMINISM_DEFECTFC-FPSO-03Behaviour under absent mandatory-item configuration undefined; could be read as 'not mandatory'.CLOSED BY CORRECTION
F-FCA-04HIGHSTATE_MODEL_DEFECTFC-FPSO-03Item invalidation after package preparation had no defined effect on PACKAGE_COMPLETE or on authorization effectiveness.CLOSED BY CORRECTION
F-FCA-05HIGHAUTHORITY_DEFECTFC-FPSO-04Crew replacement into a role slot could inherit the predecessor's competency and authorization.CLOSED BY CORRECTION
F-FCA-06HIGHAUTHORITY_DEFECTFC-FPSO-05SUPERVISOR_REVIEWED → AUTHORIZED could be read as a single act, merging evidence and authority.CLOSED BY CORRECTION
F-FCA-07MEDIUMCONTRACT_DEFECTFC-FPSO-05Absent cross-review thresholds left trigger behaviour undefined.CLOSED BY CORRECTION
F-FCA-08HIGHDETERMINISM_DEFECTFC-FPSO-06Material delta invalidation scope undeclared; implementers could choose blanket or minimal invalidation.CLOSED BY CORRECTION
F-FCA-09HIGHIDEMPOTENCY_DEFECT / CONCURRENCY_DEFECTFC-FPSO-08Repeated signature requests and mid-flight version changes had no defined idempotency key or conflict outcome.CLOSED BY CORRECTION
F-FCA-10LOWOVERMODELLING_DEFECTFC-FPSO-02 / 03 / 06One decorative state and two semantically duplicate reason-code pairs; one duplicate event semantic.CLOSED BY CORRECTION
F-FCA-11MEDIUMEXTERNAL_DEPENDENCYALLTwelve owner decisions remain unavailable (thresholds, participation modes, legal, IAM, privacy). Not a contract defect.CONTROLLED EXTERNAL

AH · Controlled Corrections Register

NoSilentCorrection · NoScopeExpansion · NoNewContract

F-FCA-01FC-FPSO-01LocationConfirmation lifecycleRETEST PASS
Original definition
A later confirmation updates the confirmed Location_ID for the pre-start context.
Defect
In-place mutation silently preserved dependent authorizations.
Corrected definition
LocationConfirmation is immutable once dependent records exist. A change produces a successor confirmation, marks the prior CONFIRMED record SUPERSEDED, and raises a governed LocationChangeImpactAssessment scoped to dependent objects.
Correction rationale
Prevents authority inheritance across a material context change while avoiding blanket invalidation.
Parent architecture impact
NONE
Regression set
FCA-P01, FCA-P18, IS-03, IS-10
F-FCA-02FC-FPSO-02Revision selectionRETEST PASS
Original definition
Where multiple revisions are active, the effective revision is selected.
Defect
Implicit automatic election promoted the retrieval adapter into document authority.
Corrected definition
No automatic election. Multiple active revisions yield DOCUMENT_REVISION_AMBIGUOUS with RC-DOC-REVISION-AMBIGUOUS; applicability evaluation is blocked until document control resolves the ambiguity.
Correction rationale
Preserves object-specific source authority and determinism.
Parent architecture impact
NONE
Regression set
FCA-P02, FCA-P03, FCA-P12, IS-08
F-FCA-03FC-FPSO-03Mandatory item applicabilityRETEST PASS
Original definition
Mandatory items are designated by configuration per activity class.
Defect
Behaviour when configuration is absent was undefined.
Corrected definition
Absent or unevaluable configuration yields COMPLETENESS_UNDETERMINABLE with RC-PKG-CONFIG-ABSENT; PACKAGE_COMPLETE is unreachable. Absence is never read as non-mandatory.
Correction rationale
Fail-closed under configuration absence; removes an implementer-chosen default.
Parent architecture impact
NONE
Regression set
FCA-P07, FCA-P16, IS-05, IS-09
F-FCA-04FC-FPSO-03Post-preparation item invalidationRETEST PASS
Original definition
Item state reflects its current source facts.
Defect
No defined effect on package completeness or authorization effectiveness.
Corrected definition
Invalidation of a mandatory item transitions the dependent scope to REASSESS_REQUIRED and renders any existing authorization not effective for the new package version; unaffected items retain their state.
Correction rationale
Non-compensable completeness and dependency-scoped impact.
Parent architecture impact
NONE
Regression set
FCA-P06, FCA-P07, FCA-P17, IS-05
F-FCA-05FC-FPSO-04Crew replacementRETEST PASS
Original definition
Crew composition may change; the record reflects the current crew.
Defect
Role-slot inheritance of competency and authorization.
Corrected definition
Replacement creates a successor CrewConfirmationRecord version. The incoming person's competency, training and fitness facts are evaluated independently; any authorization dependent on crew composition ceases to be effective and must be re-exercised.
Correction rationale
Competency and DecisionRight are personal, never positional.
Parent architecture impact
NONE
Regression set
FCA-P08, FCA-P09, FCA-P19, IS-07
F-FCA-06FC-FPSO-05Review and authorizationRETEST PASS
Original definition
Supervisor review completes the IPERC lifecycle.
Defect
Permitted a merge of EvidenceEngine and AuthorityEngine.
Corrected definition
SUPERVISOR_REVIEWED and AUTHORIZED are distinct transitions with distinct events, reason codes and DecisionRight checks, including when the same person performs both.
Correction rationale
Preserves the parent invariant that a completed record cannot manufacture authorization.
Parent architecture impact
NONE
Regression set
FCA-P04, FCA-P05, FCA-P20, IS-01
F-FCA-07FC-FPSO-05Cross-review triggerRETEST PASS
Original definition
Cross-review is triggered per configured thresholds.
Defect
Undefined behaviour when thresholds are absent.
Corrected definition
Absent thresholds yield an UNDETERMINABLE trigger with RC-IPERC-THRESHOLD-ABSENT; AUTHORIZED is unreachable for the affected risk class.
Correction rationale
Configuration absence must fail closed, not open.
Parent architecture impact
NONE
Regression set
FCA-P05, FCA-P16
F-FCA-08FC-FPSO-06Material delta impactRETEST PASS
Original definition
A material delta requires reassessment.
Defect
Scope of reassessment undeclared — blanket vs minimal invalidation both implementable.
Corrected definition
Each delta category declares its dependency scope (documents, items, IPERC sections, crew facts, tools, permits). Reassessment applies to exactly that scope; where the map cannot be evaluated, the widest declared scope applies.
Correction rationale
Determinism plus proportionality; avoids indiscriminate global invalidation.
Parent architecture impact
NONE
Regression set
FCA-P06, FCA-P10, FCA-P17, IS-04
F-FCA-09FC-FPSO-08Signature request handlingRETEST PASS
Original definition
A signature binds identity, authority, content and version.
Defect
No idempotency key; no defined outcome for concurrent modification during signing.
Corrected definition
Signature requests are idempotent on (Object_ID, ObjectVersion, SignerIdentity, DecisionRight, Idempotency_Key). A version change mid-flight aborts with SIGNATURE_VERSION_CONFLICT and RC-SIG-VERSION-CONFLICT; no partial or provisional signature is created.
Correction rationale
Prevents duplicate signature evidence and signature on a moved target.
Parent architecture impact
NONE
Regression set
FCA-P11, FCA-P13, FCA-P14, IS-02
F-FCA-10FC-FPSO-02 / 03 / 06State, reason-code and event cataloguesRETEST PASS
Original definition
APPLICABILITY_NOT_EVALUATED state; RC-PKG-ITEM-MISSING/INCOMPLETE; RC-DELTA-UNCLASSIFIED/THRESHOLD-ABSENT; PackageItemUpdated/Changed.
Defect
One decorative state, two duplicate reason-code pairs, one duplicate event semantic.
Corrected definition
State reclassified as the mandatory ApplicabilityStatus attribute; reason codes consolidated to RC-PKG-MANDATORY-ITEM-NOT-SATISFIED and RC-DELTA-MATERIALITY-UNDETERMINABLE; event consolidated to PackageItemVersionCreated.
Correction rationale
States govern behaviour; they do not decorate workflow. No count was altered cosmetically.
Parent architecture impact
NONE
Regression set
FCA-P02, FCA-P07, FCA-P16
Correction rules applied
  • · NoSilentCorrection — every change carries Finding_ID, original, defect, corrected definition and rationale.
  • · NoScopeExpansion — no capability added.
  • · NoNewContract — ContractCount remains 8.
  • · NoNewFactClass — the six parent fact classes are unchanged.
  • · NoAuthorityPromotion — no source, record or signature gained authority.

AI · Retest / Regression Register

CorrectedDefinitionExists ∧ AffectedInvariantRetested ∧ CrossContractRegressionPassed ∧ NoNewMaterialAmbiguityIntroduced

FindingCorrected definitionInvariant retestedCross-contract regressionNo new ambiguityClosed
F-FCA-01YESYESYESYESYES
F-FCA-02YESYESYESYESYES
F-FCA-03YESYESYESYESYES
F-FCA-04YESYESYESYESYES
F-FCA-05YESYESYESYESYES
F-FCA-06YESYESYESYESYES
F-FCA-07YESYESYESYESYES
F-FCA-08YESYESYESYESYES
F-FCA-09YESYESYESYESYES
F-FCA-10YESYESYESYESYES

10/10 findings closed · 37 regression executions.

AJ · External Dependency Register at Freeze

Carried forward with CurrentAssumption = NONE

IDContractOwnerDecision neededCurrent assumptionStatusImplementation constraint
XD-01FC-FPSO-01Location steward (ADR-14 stewardship, unstaffed)Proximity radius and positional accuracy policy per location classNONENONE REQUIREDRadius/accuracy are configuration inputs, never hard-coded literals
XD-02FC-FPSO-01Corporate data privacy ownerPositional data retention period and personnel-tracking prohibition scopeNONENONE REQUIREDNo continuous tracking capability may be implemented
XD-03FC-FPSO-02Document control owner (Aconex participation)Retrievable metadata fields and participation mode per sourceNONENONE REQUIREDNo live API is assumed; adapter mode is configuration
XD-04FC-FPSO-03Rule governance authority (ADR-16)Mandatory-item designation per activity classNONENONE REQUIREDMandatory designation is versioned configuration under RuleVersion
XD-05FC-FPSO-03Work control system owner (Q4 / Engica)Referenceable permit and isolation identifiers and statesNONENONE REQUIREDReference only; no write-back to work control
XD-06FC-FPSO-04Privacy + occupational health ownersMinimal decision-fact set exposed for fitness and competencyNONENONE REQUIREDOnly decision facts, never clinical data
XD-07FC-FPSO-04Competency authority (Training/HR)Which body issues authoritative competency facts and their validity semanticsNONENONE REQUIREDCompetency source is object-specific, not universal
XD-08FC-FPSO-05ES&H authorityIPERC Continuo lifecycle validated against site legal and client requirementsNONENONE REQUIREDLifecycle states may be constrained but not merged
XD-09FC-FPSO-05ES&H + rule governance authorityCross-review and hold-point threshold values per risk classNONENONE REQUIREDThresholds are configuration under RuleVersion
XD-10FC-FPSO-06ES&H + Construction authoritiesMateriality thresholds per delta categoryNONENONE REQUIREDThresholds configurable per category; dependency map fixed by contract
XD-11FC-FPSO-07Tools / equipment authorityInspection regime, certification classes and colour-code policyNONENONE REQUIREDRegime is configuration; readiness conjunction fixed by contract
XD-12FC-FPSO-08Legal + corporate compliance and enterprise IAM (ADR-08)Signature legal/corporate/client requirements, identity provider and trust service selectionNONENONE REQUIREDNo trust technology selected in the functional baseline

AK · Freeze Readiness Predicate & Baseline Manifest

CriterionRequiredActualMet
ContractsAccounted8/88/8YES
ContractScopeDeviation00YES
ContractDefinitionGaps00YES
OpenSemanticAmbiguityCount00YES
CriticalContractDefects00YES
HighUncontrolledDefects00YES
ArchitectureImpact00YES
DuplicateDomainObjects00YES
AuthorityContradictions00YES
SourceAuthorityPromotions00YES
IllegalMaterialStates00YES
UncontrolledConcurrencyPaths00YES
UncontrolledReplayPaths00YES
DeterminismPRESERVEDPRESERVEDYES
AIContainmentPRESERVEDPRESERVEDYES
ProvenanceCOMPLETE_FOR_FUNCTIONAL_SCOPECOMPLETE_FOR_FUNCTIONAL_SCOPEYES
TraceabilityCOMPLETECOMPLETEYES
ParentBaselineUNCHANGEDUNCHANGEDYES
FUNCTIONAL BASELINE FREEZE READY
Baseline ID
PH6A-FPSO-FUNCTIONAL-BASELINE-REV0
Baseline status
FROZEN
Parent baseline
PH6A-IADA-REV1
Parent seal
PH6A-IADA-REV1-SEAL-01
Contribution type
CONTROLLED_FUNCTIONAL_EXTENSION
Contract count
8
Definition source
PH6A-FPSO-FCD-REV0
Assurance source
PH6A-FPSO-FCA-REV0
Effect
FunctionalContracts = REQUIREMENTS_OF_RECORD_FOR_IMPLEMENTATION

Future UX and software implementation may consume these contracts; they may not silently redefine them. Registered as descendant provenance of PH6A-IADA-REV1; TechnicalAttribution and DesignProvenanceLineage preserved; no parent mutation.

Change classDefinitionRequires
CONFIGURATION_CHANGEThreshold, matrix or catalogue value change under RuleVersionGovernance approval and rule version increment
FUNCTIONAL_CONTRACT_CHANGEAny change to a frozen contract elementAffectedContract, Reason, Impact, RegressionRequired — recorded before adoption
UX_PRESENTATION_CHANGEPresentation of contract semanticsNo contract change; must not alter material behaviour
IMPLEMENTATION_CHANGETechnical realisation choicesNo requirement change; implementation convenience never rewrites requirements of record
ARCHITECTURE_IMPACTChange touching authority, source boundaries, fact classes or engine separationReopen architecture governance; not permitted as routine configuration

AL · G-FPSO-03 Decision & Final State

G-FPSO-03 — FUNCTIONAL BASELINE FREEZE

PASS WITH CONTROLLED EXTERNAL DEPENDENCIES

All contract semantics are closed: OpenSemanticAmbiguityCount = 0, ContractDefinitionGaps = 0, no critical or uncontrolled high defect, no reachable illegal material state, determinism, AI containment, provenance and traceability preserved, parent baseline unchanged. The 12 remaining items are genuinely external owner decisions satisfying every §5 test, each with CurrentAssumption = NONE.

PASS_WITH_CONTROLLED_EXTERNAL_DEPENDENCIES is never permitted for
  • · semantic ambiguity
  • · undefined state behaviour
  • · undefined authority
  • · undefined failure behaviour
  • · unresolved high contract defect
FPSO_CONTRACT_ASSURANCE
ACCEPTED
AssuranceID
PH6A-FPSO-FCA-REV0
FunctionalBaseline
PH6A-FPSO-FUNCTIONAL-BASELINE-REV0
FunctionalBaselineStatus
FROZEN
ContractsAccounted
8/8
ContractDefinitionGaps
0
OpenSemanticAmbiguityCount
0
CriticalContractDefects
0
HighUncontrolledDefects
0
ArchitectureImpact
0
DuplicateDomainObjects
0
AuthorityContradictions
0
SourceAuthorityPromotions
0
IllegalMaterialStates
0
Determinism
PRESERVED
AIContainment
PRESERVED
ConcurrencyBehaviour
ASSURED
Idempotency
ASSURED
Provenance
COMPLETE_FOR_FUNCTIONAL_SCOPE
Traceability
COMPLETE
ExternalValidationDependencies
12
G-FPSO-03
PASS_WITH_CONTROLLED_EXTERNAL_DEPENDENCIES
ParentBaselineChanges
0
UIImplementation
NOT_STARTED
PrototypeImplementation
NOT_STARTED
DemoScenarioEngineering
NOT_STARTED
OperationalSimulation
NOT_STARTED
OperationalClosureEvidence
NOT_YET_ACQUIRED
Phase6A
HOLD
Phase6B
NOT_AUTHORIZED
Phase7
NO_GO
BC09Protection
ACTIVE
PilotExposure
PROHIBITED
Strict stop conditionObservedTriggered
ArchitectureImpact > 00NOT TRIGGERED
NewFunctionalContractRequiredFALSENOT TRIGGERED
NewFactClassRequiredFALSENOT TRIGGERED
AuthorityModelChangeRequiredFALSENOT TRIGGERED
EvidenceDecisionAuthorityMergeRequiredFALSENOT TRIGGERED
OpenMaterialSemanticAmbiguity > 00NOT TRIGGERED
UnresolvedCriticalContractDefect > 00NOT TRIGGERED
UnresolvedHighContractDefect > 00NOT TRIGGERED
ReachableIllegalMaterialState > 00NOT TRIGGERED