PizarraContexto de trabajoDocumentos y registrosControles críticosRegistrosPreparaciónCondiciones bloqueantesAutorización
Aseguramiento / Técnico
PH6A-FPSO-AIA-REV0 · ARCHITECTURE_IMPACT_ASSESSMENT_ONLY

A · Field Pre-Start AIA Executive View

Digital Pre-Start Board · Location Context · Applicability · Preventive Package. Assessed against parent baseline PH6A-IADA-REV1 (FROZEN_AND_SEALED) under seal PH6A-IADA-REV1-SEAL-01 and interaction baseline PH6A-BXIA-REV0.

AIA ACCEPTEDPHASE 6A HOLDBC09 PROTECTION ACTIVE
Capabilities assessed
26
Already covered
6
Configuration ext.
9
UX extensions
3
New contracts
8
Architecture impacts
0
§50 Required decision

PROCEED_WITH_CONTROLLED_FUNCTIONAL_EXTENSION

Eighteen of twenty-six capabilities are satisfied by existing contracts, configuration or presentation. The remaining eight require new behaviour that constrains — but never contradicts — the frozen invariants: none alters a fact class, closure predicate, authority boundary or deterministic contract. The sealed parent architecture therefore does not need to be reopened; the extension proceeds as controlled candidate descendants.

ARCHITECTURE REOPEN REQUIRED = FALSESTOP CONDITION NOT TRIGGERED
§0 Governing condition — preserved unchanged
BaselineOfRecord
PH6A-IADA-REV1
BaselineStatus
FROZEN_AND_SEALED
Seal_ID
PH6A-IADA-REV1-SEAL-01
InteractionArchitecture
PH6A-BXIA-REV0
ArchitectureChanges
0
FrozenContractChanges
0
TechnicalAttribution
PRESERVED
OperationalClosureEvidence
NOT_YET_ACQUIRED
Phase6A
HOLD
Phase6B
NOT_AUTHORIZED
Phase7
NO_GO
BC09Protection
ACTIVE
PilotExposure
PROHIBITED
This interaction shall not
  • · implement the Digital Pre-Start Board
  • · modify PH6A-IADA-REV1
  • · modify PH6A-BXIA-REV0
  • · create new operational authority
  • · create OperationalClosureEvidence
  • · generate real digital signatures
  • · execute corporate system integrations
  • · create live GPS authorizations
  • · change blocker status
  • · change Phase 6A status

B · Source Artefact Register

§1–2 — controlled references, not master data

IDArtefactCode / RevContent classNotes
SA-01
Pizarra de Pre-Inicio (Pre-Start Board)
3.Pizarra_Pre Inicio_Versión actualizada 1.pptx
Versión actualizada 1
STRUCTURE_VALID · FILLED_CONTENT_EXCLUDED (blue/red text)
NOT MODIFIED
Board structure, sections, information families, layout logic, visual hierarchy, operational sequence and inter-section relationships retained as reference. All populated names, phones, dates, tasks, risks and locations excluded.
SA-02
Orden de Trabajo (Work Order)
26443-325-GPP-GFQ-00001_native_000.docx
26443-325-GPP-GFQ-00001
Rev. 0 — 15.10.2024
FIELD_SEMANTICS_ONLY
NOT MODIFIED
Blank controlled form. Field inventory used for canonical-object mapping only; no master data derived.
SA-03
Análisis de Trabajo Seguro (ATS)
26443-325-GFX-GHX-00004_native_000.docx
26443-325-GFX-GHX-00004
Versión 000 — 30.05.2025
FIELD_SEMANTICS_ONLY
NOT MODIFIED
Preserves TASK STEP → HAZARD → RISK → CONTROL → RESPONSIBLE, plus live-energy annex and V°B° Gerencia block.
SA-04
IPERC Continuo
26443-325-GPP-GFQ-00002 Formato IPERC continuo_OP3 1 (1) (1).xlsx
26443-325-GPP-GFQ-00002
Rev: 002
FIELD_SEMANTICS_ONLY
NOT MODIFIED
Native project reference for future digital mapping: task/PETS header, fotocheck-signature roster, fatality-risk verification, and the step→hazard→risk→energies→initial risk→controls→energy controls→residual risk→lessons row model.

PRESTART_BOARD_STRUCTURAL_REFERENCE = VALID · PRESTART_BOARD_FILLED_CONTENT = EXCLUDED_FROM_BASELINE. BLUE and RED text in the Pre-Start Board are EXAMPLE_FILLED_CONTENT_ONLY. They are not requirements, defaults, master data, business rules, baseline data, personnel, permanent risks, permanent locations or permanent tasks.

C · Pre-Start Board Structural Map

§5 — 13 information families, populated values excluded

IDBand / SectionInformation familyFields (structure only)Canonical targetCoverage
PB-01
Identificación de turno
Header / Shift Context
ShiftContextDate · Shift (Día / Noche) · Project · Area · Sector · Phase (Construcción / PRECOM)ShiftContext + LocationOperationalContext (presentation)SUPPORTED
PB-02
Supervisión responsable
Header / Command
AccountabilityContextSupervisor · Contact · Emergency contactPerson → Role → DecisionRight (reference only)SUPPORTED
PB-03
Dotación del turno
Workforce
CrewContextHeadcount planned · Headcount present · Crew composition · RolesCrewConfirmationRecord (candidate new contract)NOT YET MODELLED
PB-04
Trabajo planificado / activo
Work
WorkContextPlanned work · Active work · Activity · Discipline · Progress objective · QuantitiesWorkPackage / JobCard (existing lifecycle)SUPPORTED
PB-05
Riesgos críticos y controles
Risk
CriticalRiskContextFatal risk theme · Critical controls · Verification responsible · Non-negotiablesCriticalControlDecisionFactSUPPORTED
PB-06
SIMOPS / trabajos concurrentes
Risk
ConcurrentWorkContextConcurrent activities · Pairwise status · Aggregate location statusPairwiseInteraction + LocationConcurrentWorkSet + AggregateLocationStateSUPPORTED
PB-07
Restricciones
Constraints
RestrictionContextRestriction · Origin · Owner · Required by · Impact windowRestriction registerSUPPORTED
PB-08
Condiciones ambientales
Environment
EnvironmentalContextWind · Visibility · Precipitation · Temperature · Electrical stormEnvironmentalCondition facts (FEDERATED_FACT)PARTIAL
PB-09
Continuidad de turno anterior
Continuity
ContinuityContextHandover state · Open work · Left-in-place isolations · Pending actionsLocationContinuityRecordSUPPORTED
PB-10
Acciones y responsables
Action
ActionContextAction · Owner · Due · StatusAction / Alert lifecycleSUPPORTED
PB-11
Observaciones y lecciones aprendidas
Learning
LearningContextObservation · Lesson · Reinforcement message · OwnerLesson reference (advisory input to applicability)PARTIAL
PB-12
Preparación / foco preventivo
Decision
ReadinessContextFunctional enabling readiness · Preventive / ES&H readiness · Preventive focus of the dayTwo independent readiness families (no compensation)SUPPORTED
PB-13
Equipos y herramientas del frente
Equipment
ResourceContextEquipment · Certification · Operator authorization · Tools · Inspection tagEquipment (existing) + ToolReadiness (candidate new contract)PARTIAL

DigitalPreStartBoard is assessed as UX_EXTENSION: it asserts nothing the frozen engines do not already assert. The families that are not yet supported resolve to candidate descendant contracts, not to board-owned data.

D · Source Artefact → Canonical Object Mapping

§14–16 — no duplicate master data

ArtefactSource fieldCanonical objectFact classDuplicates master?Note
SA-02 OTNombre del trabajadorPerson (HR federated)FEDERATED FACTNOReference by identity key; no HR record copy.
SA-02 OTFotocheckPerson.IdentityKeyFEDERATED FACTNOBadge is the federation key, not an identity authority.
SA-02 OTJefe inmediatoRole assignment → DecisionRight scopeFEDERATED FACTNOSupervisory line ≠ DecisionRight.
SA-02 OTFecha de vigencia (desde / hasta)Validity windowAUTHORITATIVE FACTNOFeeds temporal validity check D3.
SA-02 OTObjetivo / Descripción de la actividadJobCard.ActivityAUTHORITATIVE FACTNONo second Work object created.
SA-02 OTEstándares aplicados / normasSourceDocument → Clause → InterpretedRequirementFEDERATED FACTNOVersion-pinned reference.
SA-02 OTIdentificación de riesgos de fatalidadCriticalControlDecisionFactFEDERATED FACTNOForwood remains CANDIDATE_SOURCE.
SA-02 OTOtros riesgos asociados (físico, químico, ergonómico, psicosocial, seguridad)HazardClass taxonomyFEDERATED FACTNOTaxonomy is configuration, not code.
SA-02 OTEquipos y herramientas (cantidad, descripción, código)Equipment + ToolReadinessFEDERATED FACTNOTools kept separate from Equipment.
SA-02 OTRegistro de autorización para el trabajo (nombre, fotocheck, cargo, firma)AuthorityVerification + DigitalSignatureAssuranceAUTHORIZED DECISIONNOSignature must bind identity, DecisionRight, content and version.
SA-02 OTFirma del ejecutante / del responsableSignatureRecord (candidate)AUTHORIZED DECISIONNOTwo distinct signer roles, distinct DecisionRights.
SA-03 ATSProyecto / ÁreaProjectContext / CanonicalLocationRegisterAUTHORITATIVE FACTNOArea is a governed location node.
SA-03 ATSSupervisor del área / Superintendente responsableRole → DecisionRightFEDERATED FACTNOTwo review levels already modelled.
SA-03 ATSNombre de la tareaJobCard.ActivityAUTHORITATIVE FACTNO
SA-03 ATSPersonal ejecutor / firmasCrewConfirmationRecordAUTHORITATIVE FACTNOAttendance ≠ competency ≠ authorization.
SA-03 ATSEquipos y herramientas / EPPEquipment · ToolReadiness · PPERequirementFEDERATED FACTNOPPE modelled as a Control, not as stock.
SA-03 ATSPaso → Peligro → Riesgo potencial → Medida preventiva → ResponsableTaskStep → Hazard → Risk → Control → ResponsiblePersonAUTHORITATIVE FACTNORelationship preserved verbatim; each control carries an owner.
SA-03 ATSTrabajo con energía viva + V°B° GerenciaLiveEnergyException → escalated DecisionRightAUTHORIZED DECISIONNOHigher authority scope, not a checkbox.
SA-04 IPERCTarea a realizar / lugar / fecha / hora inicio-términoJobCard + ConfirmedLocation_ID + ExecutionWindowAUTHORITATIVE FACTNOWindow drives SIMOPS overlap.
SA-04 IPERCCódigo de PETSSourceDocument (Aconex) version-pinnedFEDERATED FACTNORevision pinning already contracted.
SA-04 IPERCRoster fotocheck + nombres + firma (10 rows)CrewConfirmationRecord entriesAUTHORITATIVE FACTNORow count is a form artefact, not a rule.
SA-04 IPERCCapataz / Jefe de grupo · SupervisorFieldValidator / SupervisorReviewer rolesAUTHORITATIVE FACTNO
SA-04 IPERCVerificación de riesgos de fatalidad + controles críticos por pasoCriticalControlDecisionFact per TaskStepFEDERATED FACTNOApplicability governed, never hard-coded.
SA-04 IPERCPaso · Peligro · Riesgo · Energías peligrosas · Riesgo inicial (A/M/B)IPERCRow (candidate contract)AUTHORITATIVE FACTNORisk banding is configuration.
SA-04 IPERCControles implementados · Controles de energías · Riesgo residualControl + ResidualRiskAssessmentAUTHORITATIVE FACTNOResidual banding requires human confirmation.
SA-04 IPERCLecciones aprendidasLesson referenceAI ADVISORY OUTPUTNOAI may propose relevant lessons; never mandatory by itself.
SA-01 BoardTurno / fecha / área / sector / faseShiftContextAUTHORITATIVE FACTNO
SA-01 BoardFoco preventivo del díaPreventiveFocus (configuration)DERIVED FACTNODerived from active critical risks, never free-typed authority.

E · End-to-End Pre-Start Journey

§4 — 17 governed steps

#StepProduced factFact classAuthority requiredCoverage
1Pre-Start BoardAssembled shift context viewDERIVED_FACTNone (presentation)UX EXTENSION
2Shift contextShiftContextAUTHORITATIVE_FACTNoneALREADY COVERED
3Location acquisitionCanonicalLocationCandidateDERIVED_FACTNone — candidate onlyNEW FUNCTIONAL CONTRACT
4Location confirmationConfirmedLocation_IDAUTHORIZED_DECISIONHuman confirmation with scopeUX EXTENSION
5Work / JobCard selectionSelected JobCardAUTHORITATIVE_FACTNoneALREADY COVERED
6Current operational contextLocationOperationalContextDERIVED_FACTNoneALREADY COVERED
7Corporate source federationFederatedFactSet + participation modesFEDERATED_FACTSource owner governsCONFIGURATION EXTENSION
8Applicability determinationApplicabilityVerdictRULE_EVALUATIONHuman confirm where mandatoryCONFIGURATION EXTENSION
9Pre-Start preventive package compositionPreStartPreventivePackageDERIVED_FACTNone at compositionNEW FUNCTIONAL CONTRACT
10Human field validationHUMAN_CONFIRMED item statesAUTHORIZED_DECISIONField validatorCONFIGURATION EXTENSION
11Supervisor reviewSupervisorReviewRecordAUTHORIZED_DECISIONSupervisor DecisionRightCONFIGURATION EXTENSION
12Authority verificationAuthorityVerificationResultRULE_EVALUATIONAuthorityEngineALREADY COVERED
13Digital signature assuranceSignatureAssuranceRecordAUTHORIZED_DECISIONSigner DecisionRightNEW FUNCTIONAL CONTRACT
14Authorized packageAUTHORIZED stateAUTHORIZED_DECISIONAuthoriserCONFIGURATION EXTENSION
15Work startIN_USE stateAUTHORIZED_DECISIONSupervisorCONFIGURATION EXTENSION
16Change monitoringMaterialChangeTriggerRULE_EVALUATIONNone to detectCONFIGURATION EXTENSION
17Reassess when requiredREASSESS_REQUIREDRULE_EVALUATIONRe-authorisation requiredALREADY COVERED

F · Location Acquisition Assessment

§6 — GPS gives physical context, never authority

Candidate flow
Device GPS → Coordinates → LikelyLocation → CanonicalLocationCandidate → Human Confirmation → ConfirmedLocation_ID
Accuracy
AccuracyRadius is a required attribute; below governed threshold → candidate only, never auto-confirm
Ambiguity
Multiple candidates → LOCATION_AMBIGUOUS → operator disambiguation, no ranking auto-selection
Overlapping zones
Nested/overlapping canonical nodes → present full path, confirm at governed granularity
LocationNotFound
No canonical match → ManualLocationSelection from CanonicalLocationRegister; free text prohibited
GPSUnavailable
Degraded mode → manual selection with explicit AcquisitionMode = MANUAL; not a HOLD by itself
LocationChangedDuringShift
New confirmation event required; prior authorization does not travel
Classification
NEW_FUNCTIONAL_CONTRACT — LocationAcquisitionService (candidate descendant)

Preserved invariants
· GPS ≠ Canonical Location Authority· GPS ≠ Access Authorization· GPS ≠ Work Authorization· Location identity remains governed by CanonicalLocationRegister

G · Work Selection Assessment

§8 — no second Work object

Objects consumed
WorkPackage · JobCard · Activity · Discipline · Crew · Equipment · PlannedExecutionWindow
Lifecycle
Existing JobCard lifecycle reused unchanged
Required change
Configuration of selection filters (by ConfirmedLocation_ID, shift, discipline)
Classification
ALREADY_COVERED

Preserved invariants
· A Pre-Start selection is a view over the existing Work object, never a new Work object

H · Corporate Source Federation Assessment

§9 — CandidateSource ≠ AuthoritativeSource

Aconex
CANDIDATE_SOURCE · documents · participation mode TO_BE_CONFIRMED
Q4 / Engica
CANDIDATE_SOURCE · permits, isolations, STT · read-only
Forwood
CANDIDATE_SOURCE · critical control taxonomy
IAM
CANDIDATE_SOURCE · identity assertion only, not DecisionRight
HR
CANDIDATE_SOURCE · role/assignment decision facts
Training
CANDIDATE_SOURCE · competency decision facts
Health
CANDIDATE_SOURCE · fitness decision fact only, minimum exposure
Project Controls
CANDIDATE_SOURCE · plan/lookahead
Classification
CONFIGURATION_EXTENSION — participation-mode registry per source

Preserved invariants
· No system becomes authoritative merely because the prototype consumes it· Source authority is established by competent owner evidence, which is NOT_YET_ACQUIRED

I · Aconex Contextual Retrieval Assessment

§10 — retrieval, not authority

Query context
Location ∧ Work ∧ Activity ∧ Discipline ∧ Equipment ∧ RiskContext
Candidate classes
PETS · CP · Plans · Specifications · Controlled Forms · Drawings · Work Instructions · Document Revisions · Related technical documents
Output
ContextualDocumentCandidateSet — candidates only, each version-pinned
Participation modes
LIVE_READ · CONTROLLED_SNAPSHOT · CONTROLLED_MANUAL_FEDERATION — mode is per-register configuration, undetermined until owner evidence
Not assumed
APIs · live connectivity · specific metadata schema · write authority
Classification
NEW_FUNCTIONAL_CONTRACT — ContextualDocumentRetrieval (candidate descendant)

Preserved invariants
· Aconex is not automatically the universal system of record· Retrieval never marks a document applicable

J · Applicability Architecture Assessment

§11 — chain already contracted, engine needs explicit descendant

Existing chain
SourceDocument → Clause → InterpretedRequirement → ApplicabilityRule → Control → RequiredRecord
Gap
The chain exists; a ContextualApplicabilityEngine binding it to live field context is not explicitly contracted
Required outputs
APPLICABLE · POTENTIALLY_APPLICABLE · NOT_APPLICABLE · REQUIRES_HUMAN_CONFIRMATION
AI boundary
AI may assist interpretation; may not determine final mandatory applicability where authority is required
Classification
CONFIGURATION_EXTENSION — engine is a configured composition of frozen contracts, not a new meaning

Preserved invariants
· Missing evidence yields REQUIRES_HUMAN_CONFIRMATION, never FAIL· Same facts + same rules + same configuration = same verdict

K · PreStartPreventivePackage Assessment

§12–13 — first-class object, independent item states

Contents
Crew confirmation · Work Order · IPERC Continuo · ATS · PETAR · Applicable checklists · Tools · Equipment · Critical controls · Permits/Isolations · PETS/CP refs · SIMOPS · Restrictions · Environmental conditions · Competencies · Authorizations
Item model
Item_ID · ObjectClass · Applicability · Source · SourceVersion · GenerationMode · ValidationState · AuthorityState · SignatureState · Validity · ReasonCode
Aggregation
No single compensatory readiness percentage. Package state is the conjunction of mandatory item states
Classification
NEW_FUNCTIONAL_CONTRACT — no existing contract represents a composed, independently-stated preventive package

Preserved invariants
· Independent states preserved· One failing mandatory item cannot be averaged away

L · Work Order Mapping

§14 — semantic reference only

Mapped fields
17 fields mapped to existing canonical objects (see Section D)
Duplicate master data created
0
New attributes needed
None — all fields resolve to Person, JobCard, SourceDocument, Equipment, ToolReadiness, CriticalControlDecisionFact or signature contracts
Classification
UX_EXTENSION — the Work Order becomes a rendered projection of governed facts

Preserved invariants
· Field existence does not make the field mandatory for every activity

M · IPERC Prepopulation Assessment

§16–17 — prepopulated ≠ completed

Generation states
SYSTEM_PREPOPULATED → PENDING_HUMAN_VALIDATION → HUMAN_CONFIRMED → AUTHORIZED
Deterministic prepopulation sources
Work context · Location context · Applicable PETS · Applicable CP · Critical risks · Equipment · SIMOPS · Known restrictions · Relevant previous lessons · Applicable critical controls
AI contribution
PotentialAdditionalHazard · PotentialMissingControl — stored strictly as AI_ADVISORY_OUTPUT
Prohibited
AI marking the IPERC complete; auto-transition to HUMAN_CONFIRMED; residual risk banding without a competent person
Classification
NEW_FUNCTIONAL_CONTRACT — IPERCContinuo object with per-row provenance

Preserved invariants
· SYSTEM_PREPOPULATED ≠ HUMAN_CONFIRMED ≠ AUTHORIZED

N · ATS Assessment

§15 — applicability-driven, not universally hard-coded

Preserved relation
TASK STEP → HAZARD → RISK → CONTROL → RESPONSIBLE
Header semantics
Project · Area · Area supervisor · Responsible superintendent · Task · Date · Personnel · Equipment · Tools · PPE
Annex
Live-energy exposure with implemented critical control and management V°B° — escalated DecisionRight scope
Applicability
GOVERNED_BY_CONFIGURATION — universality asserted only on competent-source evidence, which is NOT_YET_ACQUIRED
Classification
CONFIGURATION_EXTENSION

Preserved invariants
· Applicability is not hard-coded without competent-source evidence

O · Crew / Attendance Assessment

§19 — decision facts only, privacy minimised

Record
CrewConfirmationRecord — ExpectedCrew · PresentCrew · AuthenticatedIdentity · Role · CompetencyDecisionFact · TrainingDecisionFact · FitnessDecisionFact · AttendanceConfirmation · Exceptions
Data minimisation
No HR or Health record copies. Only governed boolean/enumerated decision facts with source and validity
Exceptions
Expired competency, absent person, unfit person → item-level blocker, not a package average
Classification
NEW_FUNCTIONAL_CONTRACT

Preserved invariants
· Authenticated ≠ competent· Competent ≠ authorized for the specific decision

P · Checklist Applicability Assessment

§20 — preselected ≠ completed

Determinants
Activity · Equipment · Tool · Location · Risk · CriticalControl · WorkMethod · WorkPhase
Output
ApplicableChecklistSet with per-checklist applicability verdict and reason code
Human step
Physical condition verification is mandatory and attributable
Classification
CONFIGURATION_EXTENSION — reuses ApplicabilityRule and RequiredRecord

Preserved invariants
· PRESELECTED ≠ COMPLETED

Q · Tools / Equipment Assessment

§21–22 — distinct object classes

ToolReadiness
Tool_ID · Type · RequiredForActivity · InspectionRequirement · InspectionStatus · Validity · Certification · Condition · Restriction
Equipment
Availability · Capacity · Certification · Inspection · Maintenance · PreUse · Compatibility · OperatorAuthorization · LocationPlacement
Boundary
Tools are not merged into Equipment for UI convenience; equipment authority source is not duplicated
Classification
ToolReadiness = NEW_FUNCTIONAL_CONTRACT · EquipmentReadiness = CONFIGURATION_EXTENSION

Preserved invariants
· Operator authorization is a DecisionRight check, not an equipment attribute

R · PETAR Assessment

§23 — never preapproved

Outputs
PETAR_NOT_REQUIRED · PETAR_REQUIRED · PETAR_APPLICABILITY_REQUIRES_CONFIRMATION
When required
PETAR_PREPOPULATED with PENDING_HUMAN_REVIEW
High-risk categories
NOT hard-coded — governed by the project high-risk register once owner-confirmed
Classification
CONFIGURATION_EXTENSION

Preserved invariants
· Do not preapprove PETAR· Prepopulation never satisfies review

S · Critical Control Assessment

§24 — consume the decision fact, not the source record

Consumption
CriticalControlDecisionFact (Required / Available / Verified / Effective / Failed / Recovered) with verifier and verification window
Reproduction
The full source record is NOT reproduced in the package
Source authority
Forwood = CANDIDATE_SOURCE until competent owner evidence confirms authority
Classification
ALREADY_COVERED

Preserved invariants
· Unverifiable mandatory critical control → fail closed, no compensation

T · SIMOPS Assessment

§25 — aggregate dominates

Reused
PairwiseInteraction · LocationConcurrentWorkSet · AggregateLocationState (CUM-1…CUM-7)
Board exposure
Pairwise status and aggregate location status shown as two separate, non-substitutable indicators
Dominance
Aggregate STOP dominates any set of pairwise PASS cells
Classification
ALREADY_COVERED

Preserved invariants
· PAIRWISE PASS ≠ LOCATION PASS

U · Human Validation & Authority Assessment

§26–27 — no automatic transitions

Sequence
SYSTEM_PREPOPULATED → FIELD_REVIEW → HUMAN_CONFIRMED → SUPERVISOR_REVIEW → AUTHORITY_VERIFICATION → AUTHORIZED
Reuse
Existing HUMAN_CONFIRMED evidence metadata and AuthorityEngine contracts carry this sequence without redefinition
Authority attributes
Identity · Role · Permission · DecisionRight · Scope · Location · Activity · Risk · EffectivePeriod
Classification
CONFIGURATION_EXTENSION (validation) · ALREADY_COVERED (authority verification)

Preserved invariants
· Identity ≠ Role ≠ Permission ≠ DecisionRight· No AI-driven state transition

V · Digital Signature Assurance Assessment

§28–29 — assurance, not legal conclusion

Binding set
Document_ID · Object_ID · DocumentVersion · Signer_ID · DecisionRight · SignatureTimestamp · SignatureMethod · CredentialStatus · ContentIntegrityReference · PreviousState · NewState
Naming
DIGITAL_SIGNATURE_ASSURANCE — the term 'Digital Notary' is rejected as a legal conclusion
Technology boundary
No certificate provider, PKI, timestamp authority, cryptographic service, biometric method or cloud platform preselected
Legal validation
LEGAL_SIGNATURE_REQUIREMENTS · CORPORATE_SIGNATURE_REQUIREMENTS · CLIENT_SIGNATURE_REQUIREMENTS = TO_BE_VALIDATED
Classification
NEW_FUNCTIONAL_CONTRACT — no frozen contract binds signature to content version and DecisionRight

Preserved invariants
· CONTENT_CHANGE_AFTER_SIGNATURE ⇒ PRIOR_SIGNATURE_NOT_VALID_FOR_NEW_VERSION· A signature does not manufacture legal sufficiency

W · Change / Continuity Assessment

§30–32 — reassessment over reuse

Candidate lifecycle
PLANNED · CONTEXT_ESTABLISHED · SOURCES_CHECKED · PACKAGE_GENERATED · FIELD_VALIDATION · SUPERVISOR_REVIEW · READY_FOR_AUTHORITY · AUTHORIZED · IN_USE · REASSESS_REQUIRED · HOLD · CLOSED
Semantic compatibility
Compatible with the existing document/transaction and operational state models; retained as CANDIDATE, not frozen by this assessment
Triggers
TIME · EVENT · CHANGE · DEMAND — location, document revision, crew, equipment, SIMOPS, environment, critical-control invalidation, authority change, restriction issued
Continuity
LocationContinuityRecord reused → CONTINUE · RENEW · REASSESS · CLOSE
Classification
CONFIGURATION_EXTENSION (monitoring) · ALREADY_COVERED (reassessment, continuity)

Preserved invariants
· INHERIT CONTEXT — NEVER INHERIT AUTHORIZATION· Prior authorization is never reused because context is merely similar

X · Failure & Degraded Mode Assessment

§41 — declared behaviour, no invented HOLD scope

ModeExisting coverageRequired configurationPotential new contractFailure behaviour
GPS_UNAVAILABLEPARTIALAcquisitionMode = MANUAL permittedLocationAcquisitionServiceManual canonical selection; no HOLD by itself
ACONEX_UNAVAILABLECOVEREDSnapshot freshness window per registerUse pinned snapshot if fresh; otherwise HOLD for mandatory documents only
Q4_ENGICA_UNAVAILABLECOVEREDPermit/isolation freshness windowPermit state unverifiable → HOLD for the affected item only
IAM_UNAVAILABLECOVEREDCached authority assertion validityNo valid authority resolution → HOLD; never a bypass
CRITICAL_CONTROL_SOURCE_UNAVAILABLECOVEREDContingency verification permission (organisationally open)Mandatory control unverifiable → fail closed
OFFLINE_MODECOVEREDMinimum Safe Information Set for the Pre-Start packageQueue events; no Last-Write-Wins; reconciliation by authority
SIGNATURE_SERVICE_UNAVAILABLENOT YET MODELLEDDeferred-signature policy TO_BE_VALIDATEDDigitalSignatureAssurancePackage remains READY_FOR_AUTHORITY; never auto-AUTHORIZED
LOCATION_AMBIGUOUSNOT YET MODELLEDDisambiguation threshold configurationLocationAcquisitionServiceCandidate set presented; confirmation required before context load
DOCUMENT_VERSION_CONFLICTCOVEREDMateriality assessment rulesMaterial revision → REASSESS_REQUIRED; non-material → CONTINUE + LOG

Missing evidence is never FAIL. An unverifiable mandatory condition yields HOLD — Unable to Verify Required Condition, scoped to the affected item, never widened automatically.

Y · Architecture Impact Matrix

§42–43 — one classification per capability

ALREADY COVERED 6CONFIGURATION EXTENSION 9UX EXTENSION 3NEW FUNCTIONAL CONTRACT 8ARCHITECTURE IMPACT 0
FPSO-01DigitalPreStartBoardUX EXTENSIONNO REOPEN

Field operational home assembling shift, location, work, risk, restriction, continuity and readiness context

Parent contract
PH6A-BXIA-REV0 register/detail pattern
Current coverage
All 13 board information families resolve to existing or candidate objects
Required change
Interaction descendant of PH6A-BXIA-REV0 with a Pre-Start landing surface
Authority impact
None — presentation only
Data impact
Read-only composition of existing facts
Integration impact
None additional
Security impact
Role-sensitive presentation only
UX impact
New landing surface for field users

A new screen is not a new architecture contract; the board asserts nothing the engines do not already assert.

FPSO-02LocationAcquisitionNEW FUNCTIONAL CONTRACTNEW CONTRACTNO REOPEN

Derive a canonical location candidate from device position

Parent contract
CanonicalLocationRegister
Current coverage
Canonical location governed; no acquisition/candidate contract exists
Required change
Candidate descendant LocationAcquisitionService producing DERIVED_FACT candidates only
Authority impact
None granted — explicitly authority-free
Data impact
Coordinates, accuracy radius, acquisition mode, candidate set
Integration impact
Device sensor only; no corporate integration
Security impact
Position data minimisation and retention class required
UX impact
Acquisition and disambiguation step

No frozen contract represents probable physical context distinct from canonical identity.

FPSO-03LocationConfirmationUX EXTENSIONNO REOPEN

Human confirmation converting a candidate into ConfirmedLocation_ID

Parent contract
AuthorityEngine + CanonicalLocationRegister
Current coverage
Human confirmation with attributable metadata already contracted
Required change
Confirmation surface bound to existing HUMAN_CONFIRMED metadata
Authority impact
Consumes existing confirmation scope
Data impact
Confirmation event
Integration impact
None
Security impact
Attributable actor required
UX impact
One explicit confirm step, never implicit

Confirmation semantics already exist; only presentation is new.

FPSO-04WorkSelectionALREADY COVEREDNO REOPEN

Select the JobCard to be prepared

Parent contract
WorkPackage / JobCard lifecycle
Current coverage
Fully covered
Required change
Filter configuration by confirmed location and shift
Authority impact
None
Data impact
None
Integration impact
None
Security impact
Scope-filtered visibility
UX impact
Selection list

Creating a second Work object is explicitly prohibited and unnecessary.

FPSO-05MultiSourceFederationCONFIGURATION EXTENSIONNO REOPEN

Orchestrate corporate sources for the pre-start context

Parent contract
Federation contracts + participation modes
Current coverage
Federation contracts frozen; per-source pre-start participation not configured
Required change
Participation-mode registry entry per source and per register
Authority impact
None — CandidateSource status unchanged
Data impact
Federated fact envelopes with source version and timestamp
Integration impact
Deferred until owner evidence acquired
Security impact
Minimum exposure for HR/Health
UX impact
Source availability indicators

The federation contract already carries mode, direction and authority attributes.

FPSO-06AconexContextualRetrievalNEW FUNCTIONAL CONTRACTNEW CONTRACTNO REOPEN

Locate applicable controlled documents from operational context

Parent contract
SourceDocument federation
Current coverage
Document reference and revision pinning covered; contextual multi-register retrieval not contracted
Required change
Candidate descendant ContextualDocumentRetrieval returning a candidate set with reason codes
Authority impact
None — retrieval never determines applicability
Data impact
Query context, candidate set, per-candidate reason code
Integration impact
Participation mode undetermined; manual federation must be viable
Security impact
Document entitlement filtering required
UX impact
Contextual document panel

Retrieving candidates across registers by context is behaviour no frozen contract represents.

FPSO-07ContextualApplicabilityCONFIGURATION EXTENSIONNO REOPEN

Determine what is required for this work in this context

Parent contract
ApplicabilityRule chain
Current coverage
Chain frozen and sufficient in meaning
Required change
Rule-set configuration and versioning for pre-start context predicates
Authority impact
REQUIRES_HUMAN_CONFIRMATION preserved where authority is required
Data impact
Rule evaluation facts with rule version
Integration impact
None
Security impact
None
UX impact
Four-value applicability presentation

The engine is a configured composition of frozen contracts, not a new meaning.

FPSO-08PreStartPreventivePackageNEW FUNCTIONAL CONTRACTNEW CONTRACTNO REOPEN

Compose the pre-start preventive package with independently-stated items

Parent contract
PH6A-IADA-REV1 (parent)
Current coverage
No frozen contract composes a multi-object package with independent item states
Required change
Candidate descendant PreStartPreventivePackage + PreventivePackageItem
Authority impact
Item-level AuthorityState and SignatureState required
Data impact
Package and item registers with reason codes
Integration impact
Consumes federated facts only
Security impact
Attribution required on every item transition
UX impact
Package view with no aggregate percentage

Composition with non-compensable item states is genuinely new behaviour.

FPSO-09CrewConfirmationNEW FUNCTIONAL CONTRACTNEW CONTRACTNO REOPEN

Confirm who is present and whether governed decision facts hold

Parent contract
Person → Role → Competency decision facts
Current coverage
Decision facts exist; no attendance confirmation record exists
Required change
Candidate descendant CrewConfirmationRecord
Authority impact
Attendance confirmation is not an authorization
Data impact
Minimised decision facts only; no HR/Health record copies
Integration impact
HR/Training/Health as candidate sources
Security impact
Highest — privacy minimisation mandatory
UX impact
Roster confirmation surface

Presence, identity, competency and fitness must be separately stated and none exists today as a record.

FPSO-10WorkOrderMappingUX EXTENSIONNO REOPEN

Render the Orden de Trabajo from governed facts

Parent contract
Existing canonical objects
Current coverage
All 17 fields map without new master data
Required change
Projection template with provenance per field
Authority impact
Signature blocks consume FPSO-23
Data impact
None new
Integration impact
None
Security impact
None
UX impact
Controlled-form rendering

The form is a view; the facts already exist.

FPSO-11IPERCPrepopulationNEW FUNCTIONAL CONTRACTNEW CONTRACTNO REOPEN

Deterministically prepopulate the IPERC Continuo pending human validation

Parent contract
PH6A-IADA-REV1 (parent)
Current coverage
No IPERC object exists
Required change
Candidate descendant IPERCContinuo with per-row GenerationMode and provenance
Authority impact
Human confirmation mandatory; AI cannot complete
Data impact
Row-level hazard/risk/control/residual data with provenance
Integration impact
Consumes PETS/CP/critical control facts
Security impact
Attributable row edits
UX impact
Prepopulated rows visually distinct from confirmed rows

The native project form has no canonical representation today.

FPSO-12FieldDeltaAssessmentNEW FUNCTIONAL CONTRACTNEW CONTRACTNO REOPEN

Compare expected context against observed field context

Parent contract
Change materiality contracts
Current coverage
Materiality assessment exists for documents; no general expected-vs-observed comparison exists
Required change
Candidate descendant FieldDeltaAssessment with declared delta categories
Authority impact
MATERIAL_DELTA_REQUIRES_REASSESSMENT blocks reuse of prior authorization
Data impact
Expected/observed pairs with delta category
Integration impact
None
Security impact
None
UX impact
Delta review step before submission

Generalising materiality beyond documents is new behaviour, not a reinterpretation.

FPSO-13ATSApplicabilityCONFIGURATION EXTENSIONNO REOPEN

Determine whether and how the ATS applies

Parent contract
ApplicabilityRule chain
Current coverage
Chain covers it; applicability basis not configured
Required change
Configured applicability basis pending competent-source evidence
Authority impact
Area supervisor and responsible superintendent scopes
Data impact
Step/hazard/risk/control/responsible rows
Integration impact
None
Security impact
None
UX impact
ATS rendering with responsible per control

Universality must not be hard-coded absent competent-source evidence.

FPSO-14ChecklistApplicabilityCONFIGURATION EXTENSIONNO REOPEN

Preselect applicable checklists

Parent contract
ApplicabilityRule + RequiredRecord
Current coverage
Covered in meaning
Required change
Checklist catalogue and determinant configuration
Authority impact
None — completion is a human act
Data impact
Checklist set with reason codes
Integration impact
None
Security impact
None
UX impact
Preselected vs completed clearly separated

Preselection is rule evaluation, already contracted.

FPSO-15ToolReadinessNEW FUNCTIONAL CONTRACTNEW CONTRACTNO REOPEN

State tool inspection, certification, condition and restriction independently

Parent contract
PH6A-IADA-REV1 (parent)
Current coverage
Equipment exists; Tool does not
Required change
Candidate descendant ToolReadiness as a distinct object class
Authority impact
None
Data impact
Tool register with inspection validity
Integration impact
Source undetermined
Security impact
None
UX impact
Separate tools panel

Merging tools into Equipment for UI convenience is explicitly prohibited.

FPSO-16EquipmentReadinessCONFIGURATION EXTENSIONNO REOPEN

Consume equipment availability, certification and operator authorization

Parent contract
Equipment
Current coverage
Object exists; pre-start attribute set not configured
Required change
Attribute selection and freshness rules
Authority impact
OperatorAuthorization resolved by AuthorityEngine
Data impact
None new
Integration impact
Equipment authority source not duplicated
Security impact
None
UX impact
Equipment readiness panel

Existing Equipment contract already carries the required meaning.

FPSO-17PETARApplicabilityCONFIGURATION EXTENSIONNO REOPEN

Determine PETAR requirement and prepare for human review

Parent contract
ApplicabilityRule chain
Current coverage
Covered in meaning; high-risk register not governed yet
Required change
High-risk category configuration pending owner governance
Authority impact
PETAR authorization is a distinct DecisionRight
Data impact
Applicability verdict + prepopulated draft state
Integration impact
None
Security impact
None
UX impact
Explicit three-value result

Hard-coding high-risk categories without governance would be unevidenced.

FPSO-18CriticalControlVerificationALREADY COVEREDNO REOPEN

Consume critical control decision facts in the package

Parent contract
CriticalControl architecture
Current coverage
Fully covered
Required change
None
Authority impact
Verifier identity preserved
Data impact
Decision fact only
Integration impact
Forwood remains CANDIDATE_SOURCE
Security impact
None
UX impact
Control status per task step

The decision fact abstraction already avoids source-record duplication.

FPSO-19SIMOPSContextALREADY COVEREDNO REOPEN

Expose pairwise and aggregate location state on the board

Parent contract
PairwiseInteraction + AggregateLocationState
Current coverage
Fully covered including CUM-1…CUM-7
Required change
None
Authority impact
None
Data impact
None
Integration impact
None
Security impact
None
UX impact
Two non-substitutable indicators

Aggregate dominance is already an invariant of the frozen model.

FPSO-20HumanValidationCONFIGURATION EXTENSIONNO REOPEN

Attributable field confirmation of prepared content

Parent contract
HUMAN_CONFIRMED evidence metadata
Current coverage
Contract exists; pre-start item scope not configured
Required change
Per-item validation configuration
Authority impact
Validator scope enforced
Data impact
Confirmation events
Integration impact
None
Security impact
Attribution mandatory
UX impact
Validation checklist

No new meaning; only new scope of application.

FPSO-21SupervisorReviewCONFIGURATION EXTENSIONNO REOPEN

Second-level review before authority verification

Parent contract
Review/approval state contracts
Current coverage
Review states exist
Required change
Review step configuration with supervisor scope
Authority impact
Review ≠ authorization
Data impact
Review event
Integration impact
None
Security impact
None
UX impact
Supervisor queue

The transition semantics already exist.

FPSO-22AuthorityVerificationALREADY COVEREDNO REOPEN

Verify DecisionRight for every material approval

Parent contract
AuthorityEngine
Current coverage
Fully covered
Required change
None
Authority impact
Core
Data impact
None
Integration impact
IAM as candidate identity source
Security impact
None new
UX impact
Authority panel already contracted in BXIA

Attribute-based DecisionRight resolution already handles every pre-start approval point.

FPSO-23DigitalSignatureAssuranceNEW FUNCTIONAL CONTRACTNEW CONTRACTLEGAL VALIDATIONNO REOPEN

Bind identity, authority, content and version at signature

Parent contract
PH6A-IADA-REV1 (parent)
Current coverage
Approval events exist; no contract binds signature to content integrity and version
Required change
Candidate descendant DigitalSignatureAssurance with the 11-attribute binding set
Authority impact
Signature invalid without matching DecisionRight
Data impact
Signature records with content integrity reference
Integration impact
Provider deliberately unselected
Security impact
Highest — credential status and integrity reference required
UX impact
Signature state visible per item

Content-version binding is new behaviour; it constrains but does not contradict any frozen invariant.

FPSO-24ChangeMonitoringCONFIGURATION EXTENSIONNO REOPEN

Detect material change after authorization

Parent contract
Change/materiality + alert lifecycle
Current coverage
Covered in meaning; trigger set not configured for pre-start
Required change
Trigger configuration for TIME/EVENT/CHANGE/DEMAND
Authority impact
Detection grants no authority
Data impact
Trigger events
Integration impact
Depends on source availability
Security impact
None
UX impact
Change banner on the board

The continuity architecture supports this once triggers are configured.

FPSO-25ReassessmentALREADY COVEREDNO REOPEN

Force re-evaluation and re-authorization on material change

Parent contract
Operational state machine (REASSESS)
Current coverage
Fully covered
Required change
None
Authority impact
Re-authorization mandatory
Data impact
None
Integration impact
None
Security impact
None
UX impact
Reassess state on the package

REASSESS already exists with the required meaning.

FPSO-26PreStartProvenanceALREADY COVEREDNO REOPEN

Answer 'why is this value here?' for every prepopulated field

Parent contract
Provenance chain + GovernedOperationalEvent
Current coverage
Fully covered
Required change
Bind pre-start fields to the existing provenance chain
Authority impact
None
Data impact
Field ← Rule ← SourceFact ← SourceRecord ← SourceSystem ← SourceOwner ← Version/Timestamp
Integration impact
None
Security impact
None
UX impact
Provenance popover per field

The BXIA provenance view already satisfies this requirement.

Z · New Functional Contract Candidates

§45 — defined, not integrated

CC-01LocationAcquisitionServiceCANDIDATE DESCENDANT NOT INTEGRATED
Parent baseline
PH6A-IADA-REV1
Why no existing contract suffices
Probable physical context has no representation distinct from canonical location identity
Duplicates existing contract
NO
Required invariants
GPS output is DERIVED_FACT only · Confirmation is a separate authorized act · Manual selection always available
CC-02ContextualDocumentRetrievalCANDIDATE DESCENDANT NOT INTEGRATED
Parent baseline
PH6A-IADA-REV1
Why no existing contract suffices
No contract expresses multi-register contextual candidate retrieval
Duplicates existing contract
NO
Required invariants
Candidates are never applicable by retrieval · Every candidate is version-pinned · Participation mode declared per register
CC-03PreStartPreventivePackage + PreventivePackageItemCANDIDATE DESCENDANT NOT INTEGRATED
Parent baseline
PH6A-IADA-REV1
Why no existing contract suffices
No contract composes heterogeneous objects with independent, non-compensable item states
Duplicates existing contract
NO
Required invariants
No aggregate readiness percentage · Item state independence · Mandatory item failure dominates
CC-04CrewConfirmationRecordCANDIDATE DESCENDANT NOT INTEGRATED
Parent baseline
PH6A-IADA-REV1
Why no existing contract suffices
Attendance and identity confirmation at the front is unmodelled
Duplicates existing contract
NO
Required invariants
Decision facts only · Authenticated ≠ competent · No HR/Health record copies
CC-05IPERCContinuoCANDIDATE DESCENDANT NOT INTEGRATED
Parent baseline
PH6A-IADA-REV1
Why no existing contract suffices
The native project IPERC row model has no canonical object
Duplicates existing contract
NO
Required invariants
SYSTEM_PREPOPULATED ≠ HUMAN_CONFIRMED ≠ AUTHORIZED · AI output stored as AI_ADVISORY_OUTPUT only
CC-06FieldDeltaAssessmentCANDIDATE DESCENDANT NOT INTEGRATED
Parent baseline
PH6A-IADA-REV1
Why no existing contract suffices
Materiality is contracted for documents only, not expected-vs-observed field context
Duplicates existing contract
NO
Required invariants
Material delta blocks reuse of prior authorization · Similarity is never sufficient
CC-07ToolReadinessCANDIDATE DESCENDANT NOT INTEGRATED
Parent baseline
PH6A-IADA-REV1
Why no existing contract suffices
Tools are not a subclass of Equipment in the governed model
Duplicates existing contract
NO
Required invariants
Tool state is independent of Equipment state
CC-08DigitalSignatureAssuranceCANDIDATE DESCENDANT NOT INTEGRATED
Parent baseline
PH6A-IADA-REV1
Why no existing contract suffices
No contract binds a signature to content integrity, version and DecisionRight
Duplicates existing contract
NO
Required invariants
CONTENT_CHANGE_AFTER_SIGNATURE ⇒ PRIOR_SIGNATURE_NOT_VALID_FOR_NEW_VERSION · No legal sufficiency claim · No provider preselection

AA · Architecture Findings Register

§48 — lack of owner evidence is not architecture failure

IDTypeFindingAffectsDisposition
F-FPSO-01FUNCTIONAL CONTRACT GAPEight capabilities require behaviour no frozen contract represents.CC-01…CC-08CANDIDATE_DESCENDANTS_DEFINED_NOT_INTEGRATED
F-FPSO-02SOURCE AUTHORITY GAPAconex, Q4/Engica, Forwood, IAM, HR, Training, Health and Project Controls all remain CANDIDATE_SOURCE; no owner evidence establishes authority.FPSO-05, FPSO-06, FPSO-18OPEN — dependent on Wave 1 owner evidence, not an architecture failure
F-FPSO-03LEGAL VALIDATION GAPLegal, corporate and client signature requirements are unvalidated; no provider may be preselected.FPSO-23OPEN — TO_BE_VALIDATED by competent legal and corporate owners
F-FPSO-04CONFIGURATION GAPATS and PETAR applicability bases are not governed; universality must not be hard-coded.FPSO-13, FPSO-17OPEN — configuration pending competent-source evidence
F-FPSO-05SECURITY GAPCrew confirmation and location acquisition introduce personal and position data requiring an explicit minimisation and retention class.FPSO-02, FPSO-09OPEN — data protection class to be declared before implementation
F-FPSO-06UX GAPThe Pre-Start Board requires an interaction descendant of PH6A-BXIA-REV0; no such surface exists.FPSO-01OPEN — presentation-only, no architecture impact
F-FPSO-07CONFIGURATION GAPEnvironmental conditions and lessons are only partially modelled as governed facts on the board.PB-08, PB-11OPEN — configuration extension
F-FPSO-08NO GAPSIMOPS, critical control, authority verification, reassessment and provenance are fully satisfied by frozen contracts.FPSO-18, 19, 22, 25, 26CLOSED — no action
F-FPSO-09AUTHORITY GAPSignature roles in the Work Order (ejecutante / responsable) and ATS (V°B° Gerencia) imply distinct DecisionRights not yet enumerated in the scope registry.FPSO-22, FPSO-23OPEN — scope enumeration is configuration, resolved by AuthorityEngine

§36 AI Boundary

Advisory only

AI may
  • · requirement interpretation
  • · hazard suggestions
  • · missing-control suggestions
  • · document comparison
  • · package explanation
AI may not
  • · establish Location
  • · establish authoritative source
  • · mark worker competent
  • · approve IPERC
  • · approve PETAR
  • · sign
  • · grant DecisionRight
  • · authorize work

All AI output is stored as AI_ADVISORY_OUTPUT.

§39 Prepopulation Conflict

Never overwrite silently

Object
FIELD_SOURCE_CONFLICT
PrepopulatedValueFieldObservedValueSourceActorTimestampResolutionAuthority

A field-observed value never silently overwrites a prepopulated value. Both are preserved and the resolution is attributable.

§40 No Compensation

Two independent families

Functional Enabling ReadinessPreventive / ES&H Readiness

A complete preventive package cannot compensate for unavailable engineering, missing equipment, invalid workforce, absent client release or a material SIMOPS conflict. Functional readiness cannot compensate for missing mandatory preventive controls.

§47 · Regression Impact Assessment

Any required violation would mean ARCHITECTURE_IMPACT

IDInvariantResultEvidence
RG-01AI Cannot AuthorizePRESERVEDAI limited to AI_ADVISORY_OUTPUT for hazards, missing controls, interpretation and explanation (FPSO-07, 11).
RG-02Evidence Cannot AuthorizePRESERVEDPackage item SignatureState and AuthorityState are distinct from ValidationState (FPSO-08).
RG-03Prediction Cannot AuthorizePRESERVEDPrepopulation and forecast lanes produce DERIVED_FACT only.
RG-04Location Cannot AuthorizePRESERVEDGPS and ConfirmedLocation_ID grant no access or work authorization (FPSO-02, 03).
RG-05Context Cannot Inherit AuthorizationPRESERVEDLocationContinuityRecord reuse retains INHERIT CONTEXT — NEVER INHERIT AUTHORIZATION (W).
RG-06No Last Write WinsPRESERVEDFIELD_SOURCE_CONFLICT preserves both values with actor, authority and resolution (§39).
RG-07DecisionRight Governs Material ActionPRESERVEDEvery approval point resolves through AuthorityEngine (FPSO-22).
RG-08Pairwise SIMOPS ≠ Aggregate PASSPRESERVEDBoard exposes both indicators; aggregate dominates (FPSO-19).
RG-09Missing Evidence ≠ FAILPRESERVEDApplicability returns REQUIRES_HUMAN_CONFIRMATION; degraded modes return NOT_DEMONSTRATED (J, X).
RG-10Same Facts + Same Rules + Same Configuration = Same DecisionPRESERVEDAll new logic is rule-versioned and AI-independent; AI-off equivalence retained.

10/10 invariants PRESERVED · 0 violations. No frozen invariant must be altered to deliver the Pre-Start orchestration, therefore the strict stop condition of §53 is not triggered.

AB · Recommended Extension Boundary

What may proceed and what may not

In scope
  • · Define candidate descendant contracts CC-01…CC-08 without integrating them
  • · Configure applicability, federation participation, checklist, ATS/PETAR and change-trigger rule sets
  • · Design the Pre-Start interaction descendant of PH6A-BXIA-REV0
  • · Map source artefact fields to canonical objects with provenance
Out of scope
  • · Any modification of PH6A-IADA-REV1 or its seal
  • · Live corporate integration or write-back
  • · Real digital signatures or provider selection
  • · GPS-based access or work authorization
  • · Blocker closure or Phase 6A status change
  • · Any pilot exposure (BC09Protection ACTIVE)

Contract candidates may be specified now; they may only be integrated after a formal architecture-descendant acceptance, and may only be exercised operationally after Phase 6A GO.

AC · Parent Baseline Protection Check

§45–46 — seal and attribution preserved

CheckResult
PH6A-IADA-REV1 content modifiedNO
Frozen contract meaning alteredNO
Fact classes addedNO — all Pre-Start data uses the six frozen classes
Closure predicates alteredNO
Seal PH6A-IADA-REV1-SEAL-01PRESERVED
Technical attributionPRESERVED — Ing. Victor Delgado Céspedes (CIP 84092), Technical Design Lead
Contribution registeredFUNCTIONAL_DESIGN / ARCHITECTURE_ASSESSMENT
Blocker status changedNO
OperationalClosureEvidence generatedNO

§51 · Acceptance Conditions

All conditions must be met

METAll 26 minimum capabilities assessed
METEvery capability carries exactly one architecture classification
METNo new contract duplicates an existing contract
METParent baseline unchanged
METDesign seal unchanged
METAuthority boundaries preserved
METAI boundaries preserved
METGPS not treated as authority
METAconex not automatically treated as universal SoR
METIPERC prepopulation remains human-confirmation dependent
METPETAR prepopulation remains human-review dependent
METDigital signature does not imply legal sufficiency
METNo fake integrations created
METNo OperationalClosureEvidence generated

§52 · Required Final State

Assessment output of record

FIELD_PRESTART_ORCHESTRATION_AIA
ACCEPTED
AssessmentID
PH6A-FPSO-AIA-REV0
ParentBaseline
PH6A-IADA-REV1
DesignSeal
PRESERVED
CapabilitiesAssessed
26
AlreadyCovered
6
ConfigurationExtensions
9
UXExtensions
3
NewFunctionalContracts
8
ArchitectureImpacts
0
ArchitectureReopenRequired
FALSE
RecommendedExtensionDisposition
PROCEED_WITH_CONTROLLED_FUNCTIONAL_EXTENSION
OperationalClosureEvidence
NOT_YET_ACQUIRED
Phase6A
HOLD
Phase6B
NOT_AUTHORIZED
Phase7
NO_GO
BC09Protection
ACTIVE
PilotExposure
PROHIBITED