PizarraContexto de trabajoDocumentos y registrosControles críticosRegistrosPreparaciónCondiciones bloqueantesAutorización
Aseguramiento / Técnico
ACCEPTEDG-FPSO-04 PASSPHASE 6A HOLDBC09 PROTECTION ACTIVE

Field Pre-Start Interaction & Application Design

Design ID
PH6A-FPSO-IAD-REV1
Functional baseline
PH6A-FPSO-FUNCTIONAL-BASELINE-REV0 · FROZEN
Parent architecture
PH6A-IADA-REV1 · FROZEN_AND_SEALED
Parent seal
PH6A-IADA-REV1-SEAL-01
Corporate interaction parent
PH6A-BXIA-REV0
Contract assurance
PH6A-FPSO-FCA-REV0
Gate target
G-FPSO-04 — DESIGN-TO-CONTRACT CONFORMANCE
Evidence class
INTERACTION_DESIGN_ASSURANCE_EVIDENCE

INTERACTION_DESIGN ≠ FUNCTIONAL_REDESIGN. This design specifies screens, actions, navigation, visibility and presentation semantics only. It creates no contract, state, fact class, authority path, source authority, integration, prototype, scenario or synthetic field data.

A · Interaction / Application Design Executive View

G-FPSO-03 = PASS_WITH_CONTROLLED_EXTERNAL_DEPENDENCIES

The eight frozen field pre-start contracts are expressible as a coherent field application without altering a single contract clause. Sixteen screens, one primary journey and a synthesis board carry every contractually required human transition; no material action exists without a governing contract, transition, decision right and event.

Field simplicity is produced by orchestration — the application decides what comes next from context — never by hiding or removing a control requirement.

Explicitly out of scope in this phase
  • · Prototype implementation of the Pre-Start Board
  • · Demo scenario engineering
  • · Synthetic field data and simulated process time
  • · End-to-end simulation
  • · Live integration to Q4 / Aconex / P6 / Forwood
  • · Operational closure evidence for BC-01…BC-09
  • · Formal Bechtelization certification (deferred to G-FPSO-04B)
This phase shall not
  • · MODIFY_FUNCTIONAL_CONTRACTS
  • · ADD_FUNCTIONAL_CONTRACTS
  • · ADD_FACT_CLASSES
  • · ADD_STATES
  • · ADD_STATE_TRANSITIONS
  • · ADD_DECISION_RIGHTS
  • · CHANGE_AUTHORITY_LOGIC
  • · CHANGE_SOURCE_AUTHORITY
  • · CHANGE_APPLICABILITY_LOGIC
  • · CHANGE_FAILURE_BEHAVIOUR
  • · CHANGE_DETERMINISTIC_RULES
  • · CREATE_LIVE_INTEGRATIONS
  • · BUILD_THE_FINAL_PROTOTYPE
  • · CREATE_DEMO_SCENARIOS
  • · CREATE_SYNTHETIC_FIELD_DATA
  • · CREATE_SIMULATED_PROCESS_TIME
  • · RUN_END_TO_END_SIMULATION
  • · CREATE_OPERATIONAL_CLOSURE_EVIDENCE

B · Input Baseline Integrity

All governing inputs consumed by reference; none modified.

InputIdentifierStatusConsumptionVerdictNote
Parent architecturePH6A-IADA-REV1FROZEN_AND_SEALED (SEAL-01)BY_REFERENCE_READ_ONLYCONFIRMED
Functional baselinePH6A-FPSO-FUNCTIONAL-BASELINE-REV0FROZENBY_REFERENCECONFIRMED8 descendant contracts consumed as requirements of record; 0 clauses restated as design.
Contract assurancePH6A-FPSO-FCA-REV0PASS_WITH_CONTROLLED_EXTERNAL_DEPENDENCIESBY_REFERENCECONFIRMED WITH NOTE12 external owner decisions remain controlled-open. UX renders them as governed unresolved states; it does not resolve them.
Corporate interaction architecturePH6A-BXIA-REV0ACCEPTEDBY_REFERENCECONFIRMEDInteraction grammar and 13-tab detail model inherited, not redefined.
Physical Pre-Start Board artefactPRESTART-BOARD-STRUCTURAL-REFSTRUCTURAL_REFERENCE = VALID · FILLED_CONTENT = EXCLUDED_FROM_BASELINEBY_REFERENCECONFIRMEDInformation families and layout familiarity preserved; no populated sample values carried as defaults or master data.
ContractNameVersionConsumptionModified
FC-FPSO-01LocationAcquisitionServiceREV0BY_REFERENCEYES
FC-FPSO-02ContextualDocumentRetrievalREV0BY_REFERENCEYES
FC-FPSO-03PreStartPreventivePackage + PreStartPreventivePackageItemREV0BY_REFERENCEYES
FC-FPSO-04CrewConfirmationRecordREV0BY_REFERENCEYES
FC-FPSO-05IPERCContinuoREV0BY_REFERENCEYES
FC-FPSO-06FieldDeltaAssessmentREV0BY_REFERENCEYES
FC-FPSO-07ToolReadinessREV0BY_REFERENCEYES
FC-FPSO-08DigitalSignatureAssuranceREV0BY_REFERENCEYES

Frozen contracts are REQUIREMENTS_OF_RECORD_FOR_IMPLEMENTATION. This design translates them into screens; it does not redefine them.

C · Corporate Interaction Inheritance

PH6A-BXIA-REV0

ProjectModuleRegisterSearchFilterSelectDetailWorkflowHistoryRelated Items
Preserved affordanceField expression
SavedViewsShift-scoped saved views: My Front, Blocking Only, Awaiting Signature, SIMOPS Affected.
ControlledStatusEvery register row carries the governed contract state, never a derived label.
OwnerVisibilityOwner and required-by are rendered adjacent to any blocking condition.
SourceVisibilitySourceSystem + SourceOwner + ParticipationMode shown on all federated records.
RevisionVisibilityRevision and effective date always visible; competing revisions raise REVISION_CONFLICT.
AuthorityVisibilityDecisionRight and scope shown at the point of action, not only in an admin screen.
HistoryGovernedOperationalEvent timeline on every material object.
Provenance'Why is this here?' chain available on every prepopulated or derived value.

This phase is not the formal Bechtelization conformance review. The design is constructed to be inherently compatible with G-FPSO-04B.

D · Field Journey Architecture

Specification only — the journey is not simulated.

#StepScreenContractHuman actProgression rule
1OPEN_PRESTARTS01Parent · sessionOpen field operational homeAlways available to an authenticated field identity.
2ESTABLISH_SHIFT_CONTEXTS01Parent · ShiftConfirm project / area / shift / supervisor contextShift context must be established before location acquisition is offered.
3ACQUIRE_LOCATIONS02FC-FPSO-01Trigger acquisition or manual selectionGPS candidate is a suggestion; it never advances the journey by itself.
4CONFIRM_LOCATIONS02FC-FPSO-01Human confirms locationHUMAN_CONFIRMED_LOCATION is the only input downstream screens consume.
5SELECT_WORKS03Parent · WorkPackage / JobCardSelect governed candidate workCandidates are governed objects only; no local work object is created.
6LOAD_OPERATIONAL_CONTEXTS04Parent · LocationOperationalContextRead contextCONTEXT ≠ AUTHORIZATION; loading context grants nothing.
7RETRIEVE_CONTEXTUAL_INFORMATIONS05FC-FPSO-02Review retrieved corporate documentsRetrieved ≠ applicable; competing revisions surface REVISION_CONFLICT.
8EVALUATE_APPLICABILITYS05 / S06FC-FPSO-02 / FC-FPSO-03Confirm applicability where the contract requires human confirmationAbsent configuration renders APPLICABILITY_UNRESOLVED, never NOT_REQUIRED.
9COMPOSE_PRESTART_PACKAGES06FC-FPSO-03Compose / review package itemsEvery item is evaluated independently; no compensatory score.
10CONFIRM_CREWS07FC-FPSO-04Confirm present crew and per-person decisionsPRESENT ≠ COMPETENT ≠ AUTHORIZED; replacement never inherits.
11VALIDATE_IPERCS08FC-FPSO-05Confirm / modify / add IPERC rowsPrepopulated rows remain prepopulated until explicitly human-confirmed.
12COMPLETE_APPLICABLE_CHECKSS10Parent · ChecklistComplete applicable checklistsPRESELECTED ≠ COMPLETED.
13REVIEW_PETAR_IF_REQUIREDS12Parent · Permit / PETARReview high-risk permit where requiredApplicability is resolved before any permit content is presented as actionable.
14RESOLVE_EXCEPTIONSS09 / allFC-FPSO-06 + originating contractsAddress reason-coded exceptionsEvery open exception exposes ReasonCode, AffectedObject, RequiredAction, Owner.
15SUBMIT_FOR_REVIEWS06FC-FPSO-03Submit package for reviewSubmission is a review act; it produces no authorization styling.
16VERIFY_DECISION_RIGHTS14Parent · DecisionRightSystem verifies right; human sees basisUI_PERMISSION ≠ DECISION_RIGHT; actions disabled without a governing right.
17SIGN_WHERE_REQUIREDS15FC-FPSO-08Execute signatureIdempotent request; signature records an act, it does not create authority.
18PRESENT_RESULTING_STATES16AllRead resulting operational stateREADY / CONDITIONAL / HOLD / STOP rendered from contract states only.

User journey specification only. The journey is not simulated, no step is executed, and no synthetic field data is produced.

E · Navigation Architecture

Context drives the next required step.

NodeModuleScreenContractContext gate
NAV-01Pre-Start HomeS01Parent · ShiftAlways
NAV-02LocationS02FC-FPSO-01Shift context established
NAV-03WorkS03Parent · JobCardHUMAN_CONFIRMED_LOCATION exists
NAV-04Operational ContextS04Parent · LocationOperationalContextLocation confirmed
NAV-05Preventive PackageS06FC-FPSO-03Work selected
NAV-06CrewS07FC-FPSO-04Work selected
NAV-07IPERCS08FC-FPSO-05Work selected
NAV-08ChecklistsS10Parent · ChecklistApplicability evaluated
NAV-09Tools & EquipmentS11FC-FPSO-07 + parent EquipmentWork selected
NAV-10PETAR / PermitsS12Parent · PermitApplicability resolved
NAV-11Risks & Critical ControlsS08bParent · CriticalControlWork selected
NAV-12SIMOPSS13Parent · SIMOPSLocation confirmed
NAV-13AuthorityS14Parent · DecisionRightAlways (read); action-scoped for material acts
NAV-14SignaturesS15FC-FPSO-08Signable object exists
NAV-15HistoryS17Parent · GovernedOperationalEventObject selected
NAV-16Assurance TraceS18Parent · provenanceOptional, opt-in depth
NAV-17Pre-Start BoardS16Synthesis of allOperational context exists
Navigation rules
  • · Context drives the next required step: the home screen always names one next action, derived from the first unmet contract precondition.
  • · Modules remain directly reachable for supervision and assurance roles; field users are never forced to walk all seventeen nodes manually.
  • · Navigation availability never implies authorization — an open module can still hold a disabled material action.
  • · A gated node is shown with its gating reason code, never hidden without explanation.

F–U · Screen Architecture

18 screen specifications with field/assurance separation.

S01

Digital Pre-Start Home

§FParent · Shift / SupervisorContext

FIELD_OPERATIONAL_HOME — operational synthesis and guided entry point; not a second system of record, not a free-form entry board, not a static dashboard, not a document folder.

Information families
  • · Project
  • · Area
  • · Shift
  • · Date
  • · SupervisorContext
  • · CurrentLocation
  • · PlannedWork
  • · CurrentConstraints
  • · PreStartPackageState
Primary action
IDENTIFY / CONFIRM WORK LOCATION
Enforced distinctions
  • · Planned work ≠ authorized work
  • · Package state is a contract state, never a score
Error / exception presentation
  • · No shift context → guided establish-context prompt with reason code, not an empty board
Field view
Plain operational language: where, what, what is blocking, what next. No architecture or assurance vocabulary on first load.
Assurance view
Optional expansion reveals fact class, rule version and provenance for every summarized value.
S02

Location Acquisition

§GFC-FPSO-01

Establish a human-confirmed working location; separate detection from confirmation at all times.

Information families
  • · GPS_DETECTED_POSITION
  • · LIKELY_LOCATION
  • · ALTERNATIVE_LOCATION_CANDIDATES
  • · MANUAL_LOCATION_SELECTION
  • · HUMAN_CONFIRMED_LOCATION
Primary action
CONFIRM LOCATION (human act)
Enforced distinctions
  • · SUGGESTED rendered as outlined/neutral candidate card
  • · CONFIRMED rendered as a solid governed state chip with actor and timestamp
  • · GPS_MATCH = AUTHORIZED is never rendered in any form
Error / exception presentation
  • · GPS unavailable → governed contract fallback state and manual selection path; no invented bypass
  • · Low-confidence candidate set → candidates listed without a default selection
Field view
One map/positional band, one candidate list, one confirm action.
Assurance view
Acquisition method, accuracy attribute, candidate derivation rule and rule version.
S02b

Location Change Behaviour

§GFC-FPSO-01

Make location change a governed, visible, dependency-scoped event.

Information families
  • · LOCATION_CHANGE_DETECTED
  • · AffectedObjects
  • · ReassessmentRequired
  • · ReasonCode
Primary action
ACKNOWLEDGE CHANGE AND REVIEW AFFECTED OBJECTS
Enforced distinctions
  • · Silent Location_ID replacement is structurally impossible: the prior confirmed location remains rendered until change is dispositioned
Error / exception presentation
  • · Dependent objects listed individually with their own reassessment reason code
Field view
Banner: location changed — N dependent records require reassessment.
Assurance view
Dependency graph of affected objects with propagation rule identity.
S03

Work Selection

§HParent · WorkPackage / JobCard / Activity

Select governed work under the confirmed location.

Information families
  • · WorkPackage
  • · JobCard
  • · Activity
  • · Discipline
  • · PlannedExecutionWindow
  • · Location
  • · Restrictions
  • · SIMOPS
  • · Readiness
Primary action
SELECT WORK
Enforced distinctions
  • · Selection ≠ authorization
  • · No local Work or JobCard object is created for UX convenience
Error / exception presentation
  • · No candidate work → reason code and owner for the planning gap, not an empty list
Field view
Card list ordered by planned window with blocking condition first.
Assurance view
Source system, source owner and participation mode per candidate.
S04

Operational Context

§IParent · LocationOperationalContext

Present the integrated location picture. CONTEXT ≠ AUTHORIZATION.

Information families
  • · Planned Work
  • · Active Work
  • · Crew
  • · Equipment
  • · Critical Risks
  • · SIMOPS
  • · Restrictions
  • · Environmental Conditions
  • · Permits / Isolations
  • · Continuity
  • · Recent Material Events
Primary action
REVIEW CONTEXT (read-only)
Enforced distinctions
  • · No action on this screen can advance an authorization state
Error / exception presentation
  • · Unavailable context section renders SOURCE_UNAVAILABLE with last verified timestamp where the contract permits
Field view
Sectioned accordion, critical risks and SIMOPS expanded by default.
Assurance view
Per-section source, owner, freshness and rule version.
S05

Contextual Corporate Information

§JFC-FPSO-02

Aconex-inspired document register scoped to the confirmed context.

Information families
  • · Document_ID
  • · Title
  • · DocumentClass
  • · Revision
  • · Status
  • · SourceSystem
  • · SourceOwner
  • · ParticipationMode
  • · EffectiveDate
  • · ApplicabilityState
Primary action
CONFIRM APPLICABILITY WHERE REQUIRED
Enforced distinctions
  • · Retrieved
  • · Applicable
  • · RequiresConfirmation
  • · NotApplicable — four visually distinct register states
  • · Missing configuration renders APPLICABILITY_UNRESOLVED, never NOT REQUIRED
Error / exception presentation
  • · Competing revisions → REVISION_CONFLICT row state; no automatic revision election, no default pre-selection
Field view
Only documents in Applicable or RequiresConfirmation are surfaced by default; the full register is one tap away.
Assurance view
Retrieval rule, applicability rule version, competing-revision set and elector identity (none, when unresolved).
S06

Pre-Start Preventive Package

§KFC-FPSO-03

Independent per-item readiness presentation with no compensatory score.

Information families
  • · Crew / Attendance
  • · Work Order
  • · IPERC Continuo
  • · ATS
  • · PETAR
  • · Checklists
  • · Tools
  • · Equipment
  • · Critical Controls
  • · Permits / Isolations
  • · PETS / CP References
  • · SIMOPS Conditions
  • · Restrictions
Primary action
SUBMIT FOR REVIEW (review act only)
Enforced distinctions
  • · Each item shows Applicability, CurrentState, RequiredAction, Owner, Source, Version, ReasonCode
  • · INVALIDATED_AFTER_PREPARATION is styled distinctly from CURRENTLY_COMPLETE
  • · No aggregate percentage, score or progress ring
Error / exception presentation
  • · Post-preparation invalidation propagates visibly to the package header and to dependent items only
Field view
Blocking items first, then required actions, then satisfied items collapsed.
Assurance view
Item-level predicate, rule version, invalidation cause chain.
S07

Crew Confirmation

§LFC-FPSO-04

Per-person governed confirmation with no inheritance on replacement.

Information families
  • · ExpectedCrew
  • · PresentCrew
  • · Identity
  • · Role
  • · CompetencyDecision
  • · TrainingDecision
  • · FitnessDecision
  • · AuthorityStatus
  • · Exception
Primary action
CONFIRM PRESENT CREW MEMBER
Enforced distinctions
  • · PRESENT ≠ COMPETENT
  • · COMPETENT ≠ AUTHORIZED
  • · Replacement opens an empty governed record: no role, competency, decision right or prior confirmation is carried over
Error / exception presentation
  • · Expired or missing competency renders as a reason-coded exception with owner and required action
Field view
Roster with three independent decision chips per person; exceptions pinned to top.
Assurance view
Competency source system, validity window, decision right derivation.
S08

IPERC Continuo

§MFC-FPSO-05

Field hazard assessment with strictly separated information origins.

Information families
  • · TaskStep
  • · Hazard
  • · Risk
  • · Control
  • · ResidualRisk
  • · Responsible
  • · DangerousEnergy
  • · CriticalControl
  • · HoldPoint
  • · CrossReview
Primary action
CONFIRM / MODIFY / ADD ROW
Enforced distinctions
  • · SYSTEM_PREPOPULATED
  • · FIELD_OBSERVED
  • · HUMAN_CONFIRMED
  • · AUTHORIZED — four never-merged visual origins
Error / exception presentation
  • · Cross-review threshold reached → governed cross-review requirement with owner; thresholds are configuration-governed, never UI-inferred
Field view
Sequential step→hazard→control flow; prepopulated rows collapsed with a source indicator and 'Why is this here?'.
Assurance view
Original proposed value, field-observed value, actor, timestamp and material reason preserved side by side.
S09

Field Delta Assessment

§NFC-FPSO-06

Expected versus observed comparison with dependency-scoped consequences.

Information families
  • · Location
  • · Crew
  • · Equipment
  • · Tool
  • · Environment
  • · SIMOPS
  • · Access
  • · Restriction
  • · DocumentRevision
  • · CriticalControl
  • · UnexpectedHazard
Primary action
RECORD OBSERVED CONTEXT
Enforced distinctions
  • · ExpectedContext and ObservedFieldContext are rendered as two columns, never merged
  • · MATERIAL_DELTA_REQUIRES_REASSESSMENT lists only impacted dependent objects
Error / exception presentation
  • · Global invalidation is prohibited where dependency is local; the impacted set is always enumerated
Field view
One dimension at a time, 'same / different' with reason on difference.
Assurance view
Materiality rule, dependency scope resolution, propagation targets.
S10

Checklists

§OParent · Checklist / Inspection

Present only the applicable checklist set with its justification.

Information families
  • · WhyApplicable
  • · SourceRequirement
  • · CurrentState
  • · RequiredVerifier
Primary action
COMPLETE CHECKLIST
Enforced distinctions
  • · PRESELECTED ≠ COMPLETED
  • · Applicability justification is always visible, never implicit
Error / exception presentation
  • · Absent applicability configuration → APPLICABILITY_UNRESOLVED, never omission from the list
Field view
Large-target checklist runner with required verifier named up front.
Assurance view
Source requirement clause and applicability rule version.
S11

Tools & Equipment

§PFC-FPSO-07 + parent Equipment

Tool readiness presentation; equipment reused from the parent object, never duplicated.

Information families
  • · Tool_ID
  • · ToolClass
  • · RequiredForActivity
  • · InspectionState
  • · CertificationState
  • · Condition
  • · Validity
  • · Restriction
  • · Equipment: Availability
  • · Inspection
  • · Certification
  • · Maintenance
  • · PreUse
  • · OperatorAuthorization
  • · Location
Primary action
RECORD TOOL VERIFICATION
Enforced distinctions
  • · LISTED ≠ READY
  • · No second Equipment entity is created inside Pre-Start
Error / exception presentation
  • · Tool failure propagates only to dependent work/readiness; unrelated work remains unaffected and this scoping is shown
Field view
Tool list with readiness chip and blocking dependency named.
Assurance view
Certification source, validity window, dependency scope of failure.
S12

PETAR / Permits

§QParent · Permit / WorkAuthorization

Applicability-first permit presentation.

Information families
  • · Applicability: NOT_REQUIRED / REQUIRED / REQUIRES_CONFIRMATION
  • · Permit content
  • · Approver
  • · Validity
  • · Conditions
Primary action
REVIEW PERMIT (review act only)
Enforced distinctions
  • · PREPOPULATED / PENDING_HUMAN_REVIEW styling is explicitly non-approval
  • · A prepopulated PETAR is never rendered with approved styling
Error / exception presentation
  • · Unresolved applicability renders REQUIRES_CONFIRMATION with owner, never NOT_REQUIRED
Field view
Applicability banner first, content second.
Assurance view
Approval authority path, source system of the permit record.
S13

SIMOPS

§RParent · SIMOPS compositional model

Pairwise and aggregate concurrent-work presentation.

Information families
  • · PairwiseInteraction
  • · LocationConcurrentWorkSet
  • · AggregateLocationState
Primary action
REVIEW SIMOPS CONDITION
Enforced distinctions
  • · PAIRWISE_PASS ≠ LOCATION_PASS
  • · Aggregate conflict stays visible even when every pairwise cell is acceptable
Error / exception presentation
  • · Aggregate conflict is rendered at location level with its cumulative rule identity (CUM-*)
Field view
Aggregate condition banner, then matrix on demand.
Assurance view
Full pairwise matrix and cumulative rule evaluation trace.
S14

Authority

§SParent · DecisionRight / Delegation

Make the authority basis of every material action explicit.

Information families
  • · AuthenticatedIdentity
  • · Role
  • · Permission
  • · Competency
  • · DecisionRight
  • · DecisionScope
  • · EffectivePeriod
  • · Delegate
  • · AuthoritySource
Primary action
VIEW AUTHORITY BASIS (read-only)
Enforced distinctions
  • · UI_PERMISSION ≠ DECISION_RIGHT
  • · Material action controls are enabled only where the governing decision right permits the act, with the basis shown on hover/expand
Error / exception presentation
  • · No valid delegate → governed HOLD with escalation route; never a bypass or a hidden control
Field view
Single 'what can I decide here' summary.
Assurance view
Full authority resolution chain including AuthorityResolutionState.
S15

Digital Signature Assurance

§TFC-FPSO-08

Record a governed signing act. Signature ≠ DecisionRight.

Information families
  • · Object_ID
  • · ObjectVersion
  • · Signer
  • · DecisionRightStatus
  • · SignatureMethod
  • · CredentialStatus
  • · Timestamp
  • · IntegrityReference
Primary action
SIGN (idempotent request)
Enforced distinctions
  • · Never labelled digital notary; no legal sufficiency claim is made anywhere in the UI
  • · SIGNATURE_VERSION_CONFLICT renders prior signatures as preserved history marked NOT_VALID_FOR_CURRENT_VERSION
Error / exception presentation
  • · Repeated activation enters a controlled pending state; duplicate material events cannot be produced by repeated clicks
Field view
One signer, one object version, one action, explicit pending state.
Assurance view
Integrity reference, credential status, version binding and event identity.
S16

Pre-Start Board Synthesis

§USynthesis of all consumed contracts

Reconstruct the familiar physical board as a dynamic synthesis view — never a second authoritative data-entry system.

Information families
  • · Shift / Project Context
  • · Work Planned
  • · Crew
  • · Critical Risks
  • · SIMOPS
  • · Restrictions
  • · Preventive Package
  • · Actions
  • · Previous Shift Continuity
  • · Current Operational State
Primary action
OPEN THE GOVERNING RECORD (navigate to source screen)
Enforced distinctions
  • · Every board cell is read-through to its governing object; no value is editable on the board
  • · Filled sample content from the physical reference artefact is excluded from the baseline
Error / exception presentation
  • · Unavailable family renders SOURCE_UNAVAILABLE, distinct from CONTROL_FAILED
Field view
Recognizable board layout retaining the physical section hierarchy.
Assurance view
Per-cell provenance to source object and rule version.
S17

History

§XParent · GovernedOperationalEvent

Reconstructable event timeline on every material object.

Information families
  • · Timestamp
  • · Actor
  • · Action
  • · PreviousState
  • · ResultingState
  • · ReasonCode
  • · ObjectVersion
Primary action
VIEW HISTORY (read-only)
Enforced distinctions
  • · History is append-only in presentation; no event may be visually suppressed
Error / exception presentation
  • · Gaps in event availability are labelled, never silently compressed
Field view
Last material change summarized inline on the object.
Assurance view
Full governed event list with object version at each transition.
S18

Assurance Trace

§WParent · provenance / fact classes

Optional deeper reconstructability view. Field simplicity must not eliminate reconstructability.

Information families
  • · Source
  • · SourceOwner
  • · FactClass
  • · RuleVersion
  • · Applicability
  • · DecisionRight
  • · ReasonCode
  • · GovernedEvent
  • · ProvenanceChain
Primary action
OPEN PROVENANCE CHAIN (read-only)
Enforced distinctions
  • · Provenance is strictly read-only; nothing in this view can alter a state
Error / exception presentation
  • · Broken chain renders BROKEN_CHAIN explicitly rather than an inferred value
Field view
Entry point is a single 'Why is this here?' affordance.
Assurance view
CurrentValue ← Rule ← Input ← SourceRecord ← SourceSystem ← Owner.

V · Field View & W · Assurance Trace Boundary

Field simplicity must not eliminate reconstructability.

Where am I?What work?What applies?What must I verify?What changed?What is blocking progression?Who needs to act?What is my next permitted action?
AspectField viewAssurance viewRule
VocabularyOperational languageArchitecture and governance vocabularySame underlying state; different naming layer only.
DepthBlocking conditions and next permitted actionFact class, rule version, provenance chainDepth is additive; nothing is removed from the record.
Control requirementsFully preservedFully preservedSimplification never removes a control requirement.
EditabilityGoverned field acts onlyRead-onlyAssurance depth never becomes an alternate entry path.

Y · Failure, Offline & Concurrency UX

Fail-closed presentation; never fabricate source state.

ConditionPresentationProhibited
SOURCE UNAVAILABLEExplicit unavailable state with the source system named; last verified information shown only where the governing contract permits, always with its timestamp and state.Fabricating current source status or rendering unavailability as CONTROL_FAILED.
CONTROL FAILEDMaterial failure styling (red) with reason code, affected object, required action and owner.Conflating a failed control with an unreachable source.
OFFLINEPersistent offline indicator scoped to what the contracts permit offline.Presenting unsynchronized field data as reconciled corporate truth.
SYNC PENDINGPer-object pending badge with queued event count.Implying corporate acceptance of a pending event.
CONFLICTBoth states preserved and displayed; resolution routed to the governing authority.Last-write-wins or silent overwrite.
CONCURRENCY CONFLICTYourVersion, CurrentVersion, ChangedBy, ChangedAt, RequiredResolution rendered together.Silent overwrite of another actor's version.
APPLICABILITY UNRESOLVEDControlled warning state with owner and required configuration decision.Rendering absent configuration as NOT REQUIRED.
StateUsage
READYAll governing contract preconditions satisfied for the presented scope.
CONDITIONALProgression permitted only under stated governed conditions.
HOLDProgression blocked; reason code, owner and required action always shown.
STOPActive work must cease — material failure or prohibition.
OPEN / PENDING / EVIDENCE REQUIRED / UNRESOLVEDControlled warning. Missing information does not automatically render as failure.

Red is reserved for material FAIL, STOP, PROHIBITED, CONTRADICTION or a governed equivalent. Positive/green styling is never applied to a reviewed-but-unauthorized record.

Reason-code-first experience
  • · Every material HOLD, REASSESS_REQUIRED, CONFLICT, REJECT and UNAVAILABLE exposes ReasonCode, ReasonDescription, AffectedObject, RequiredAction, Owner and EscalationRoute where defined.
  • · No unexplained HOLD may be rendered anywhere in the application.

Z · Responsive Field Design

Control requirements are never reduced on mobile.

BreakpointBehaviourPriority
Desktop (assurance / supervision)Full register + detail + assurance trace side by side; matrices rendered in full.Register density, cross-object comparison, provenance.
Tablet (field supervision)Two-pane: context list plus governed detail; matrices scroll horizontally with sticky headers.Package items, crew, IPERC, signature.
Field mobileSingle-column, large targets, one governed act per view, sticky blocking banner and next permitted action.Location · Work · CurrentState · RequiredAction · BlockingReason · FieldValidation · Signature.

Control requirements are never reduced on mobile. Reduced density is achieved by progressive disclosure, never by omitting a mandatory control, a reason code or an authority basis.

No consumer-app drift
  • · No decorative gamification
  • · No oversized marketing cards
  • · No arbitrary scores or readiness percentages
  • · No excessive animation
  • · No chat-first operational workflow
  • · No AI-avatar interaction
  • · No generic SaaS styling disconnected from project operations

AA · Design-to-Contract Traceability Matrix

25 material interactions · OrphanUIActions = 0

ScreenComponentUser actionContractClauseCurrent statePermitted transitionDecision rightEventReason codeResulting stateExpected UI behaviour
S02C-LOC-CONFIRMConfirm locationFC-FPSO-01LocationConfirmationLOCATION_CANDIDATE_PRESENTEDCANDIDATE → HUMAN_CONFIRMEDDR-FIELD-CONFIRM-LOCATIONLocationConfirmedRC-LOC-CONFIRMEDLOCATION_HUMAN_CONFIRMEDCandidate styling replaced by confirmed chip with actor and timestamp; downstream nodes unlock.
S02C-LOC-MANUALSelect location manuallyFC-FPSO-01ManualSelectionFallbackGPS_UNAVAILABLEGPS_UNAVAILABLE → MANUAL_SELECTION_PENDINGDR-FIELD-CONFIRM-LOCATIONManualLocationSelectedRC-LOC-GPS-UNAVAILABLELOCATION_CANDIDATE_PRESENTEDGoverned fallback path shown; no bypass affordance rendered.
S02bC-LOC-CHANGE-ACKAcknowledge location changeFC-FPSO-01LocationChangePropagationLOCATION_CHANGE_DETECTEDCHANGE_DETECTED → REASSESSMENT_REQUIREDDR-FIELD-CONFIRM-LOCATIONLocationChangeDispositionedRC-LOC-CHANGE-REASSESSDEPENDENTS_REASSESSMENT_REQUIREDAffected object list rendered; prior Location_ID remains visible until disposition.
S03C-WORK-SELECTSelect governed workParent · JobCardWorkSelectionWORK_CANDIDATE_LISTEDCANDIDATE → SELECTED_CONTEXTDR-FIELD-SELECT-WORKWorkContextSelectedRC-WORK-SELECTEDWORK_CONTEXT_ESTABLISHEDSelection establishes context only; no authorization styling applied.
S05C-DOC-APPLICABILITY-CONFIRMConfirm document applicabilityFC-FPSO-02ApplicabilityConfirmationREQUIRES_CONFIRMATIONREQUIRES_CONFIRMATION → APPLICABLEDR-APPLICABILITY-CONFIRMDocumentApplicabilityConfirmedRC-DOC-APPLICABLEAPPLICABLERegister row moves state; retrieved-only rows remain visually distinct.
S05C-DOC-REVISION-CONFLICTEscalate revision conflictFC-FPSO-02CompetingRevisionControlREVISION_CONFLICTREVISION_CONFLICT → ESCALATED_TO_DOCUMENT_AUTHORITYDR-DOC-AUTHORITYRevisionConflictRaisedRC-DOC-REVISION-CONFLICTAWAITING_DOCUMENT_AUTHORITYNo revision preselected; both revisions rendered with owner and escalation route.
S06C-PKG-ITEM-REVIEWReview package itemFC-FPSO-03ItemEvaluationITEM_PENDINGPENDING → ITEM_SATISFIED | ITEM_BLOCKEDDR-PACKAGE-REVIEWPackageItemEvaluatedRC-PKG-ITEM-STATEITEM_SATISFIED | ITEM_BLOCKEDItem evaluated independently; no aggregate score rendered.
S06C-PKG-SUBMIT-REVIEWSubmit package for reviewFC-FPSO-03PackageReviewSubmissionPACKAGE_COMPOSEDCOMPOSED → UNDER_REVIEWDR-PACKAGE-SUBMITPackageSubmittedForReviewRC-PKG-SUBMITTEDUNDER_REVIEWNeutral review styling; explicitly not authorization styling.
S06C-PKG-INVALIDATION-BANNEROpen invalidated itemFC-FPSO-03PostPreparationInvalidationINVALIDATED_AFTER_PREPARATIONINVALIDATED → ITEM_PENDINGDR-PACKAGE-REVIEWPackageItemInvalidationSurfacedRC-PKG-INVALIDATEDITEM_PENDINGDistinct styling from CURRENTLY_COMPLETE; propagation shown on package header.
S07C-CREW-CONFIRMConfirm crew memberFC-FPSO-04PersonConfirmationEXPECTEDEXPECTED → PRESENT_CONFIRMEDDR-CREW-CONFIRMCrewMemberConfirmedRC-CREW-PRESENTPRESENT_CONFIRMEDPresence chip only; competency and authority chips remain independent.
S07C-CREW-REPLACERecord crew replacementFC-FPSO-04ReplacementNonInheritancePRESENT_CONFIRMEDPRESENT_CONFIRMED → REPLACEMENT_PENDING_EVALUATIONDR-CREW-CONFIRMCrewReplacementRecordedRC-CREW-REPLACEMENTREPLACEMENT_PENDING_EVALUATIONNew person record opens empty: no role, competency, decision right or confirmation inherited.
S08C-IPERC-CONFIRM-ROWConfirm prepopulated rowFC-FPSO-05HumanConfirmationSYSTEM_PREPOPULATEDPREPOPULATED → HUMAN_CONFIRMEDDR-IPERC-CONFIRMIpercRowConfirmedRC-IPERC-CONFIRMEDHUMAN_CONFIRMEDOrigin styling changes; source provenance retained and still viewable.
S08C-IPERC-MODIFY-ROWModify prepopulated rowFC-FPSO-05FieldObservationSYSTEM_PREPOPULATEDPREPOPULATED → FIELD_OBSERVEDDR-IPERC-CONFIRMIpercRowModifiedRC-IPERC-FIELD-MODIFIEDFIELD_OBSERVEDOriginal proposed value preserved alongside observed value, actor, timestamp and reason.
S09C-DELTA-RECORDRecord observed contextFC-FPSO-06DeltaMaterialityEXPECTED_CONTEXT_LOADEDOBSERVED → MATERIAL_DELTA_REQUIRES_REASSESSMENT | NON_MATERIAL_LOGGEDDR-DELTA-RECORDFieldDeltaAssessedRC-DELTA-MATERIALMATERIAL_DELTA_REQUIRES_REASSESSMENT | NON_MATERIAL_LOGGEDOnly dependency-scoped impacted objects listed; no global invalidation.
S10C-CHECKLIST-COMPLETEComplete checklistParent · ChecklistChecklistCompletionAPPLICABLE_PRESELECTEDPRESELECTED → COMPLETEDDR-CHECKLIST-VERIFYChecklistCompletedRC-CHK-COMPLETEDCOMPLETEDPreselected state never styled as completed prior to verifier action.
S11C-TOOL-VERIFYRecord tool verificationFC-FPSO-07ToolVerificationLISTEDLISTED → READY | TOOL_BLOCKEDDR-TOOL-VERIFYToolReadinessRecordedRC-TOOL-STATEREADY | TOOL_BLOCKEDFailure propagates only to dependent activities; scope displayed.
S12C-PETAR-REVIEWReview PETARParent · PermitPermitReviewPREPOPULATED_PENDING_HUMAN_REVIEWPENDING_HUMAN_REVIEW → REVIEWEDDR-PERMIT-REVIEWPermitReviewedRC-PTR-REVIEWEDREVIEWEDReviewed styling is neutral; approval styling requires the approval contract state.
S13C-SIMOPS-AGGREGATEReview aggregate SIMOPS conditionParent · SIMOPSAggregateLocationStatePAIRWISE_EVALUATEDPAIRWISE_EVALUATED → AGGREGATE_EVALUATEDDR-SIMOPS-REVIEWAggregateSimopsPresentedRC-SIMOPS-AGGREGATEAGGREGATE_CONFLICT | AGGREGATE_ACCEPTABLEAggregate conflict remains visible even when all pairwise cells pass.
S14C-AUTHORITY-BASISInspect authority basisParent · DecisionRightDecisionRightResolutionANYNONE (read-only)DR-VIEW-AUTHORITYAuthorityBasisViewedRC-AUTH-BASISUNCHANGEDMaterial controls disabled where the right is absent, with the reason shown.
S15C-SIGN-EXECUTESign objectFC-FPSO-08SignatureExecutionSIGNATURE_REQUESTEDREQUESTED → SIGNED_FOR_VERSIONDR-SIGN-OBJECTSignatureRecordedRC-SIG-RECORDEDSIGNED_FOR_VERSIONIdempotent: repeat activation resolves to the same request, controlled pending state shown.
S15C-SIGN-VERSION-CONFLICTOpen signature version conflictFC-FPSO-08VersionBindingSIGNATURE_VERSION_CONFLICTCONFLICT → RESIGNATURE_REQUIREDDR-SIGN-OBJECTSignatureVersionConflictSurfacedRC-SIG-VERSION-CONFLICTRESIGNATURE_REQUIREDPrior signature preserved as history and marked NOT_VALID_FOR_CURRENT_VERSION.
S16C-BOARD-DRILLOpen governing record from board cellSynthesis (read-through)SynthesisReadThroughANYNONE (navigation only)DR-VIEW-CONTEXTBoardCellOpenedRC-BOARD-NAVIGATEUNCHANGEDBoard is never editable; navigation resolves to the governing screen.
S17C-HISTORY-VIEWView object historyParent · GovernedOperationalEventEventReconstructionANYNONE (read-only)DR-VIEW-HISTORYHistoryViewedRC-HIST-VIEWUNCHANGEDAll governed events shown with object version and reason code.
S18C-PROVENANCE-WHYOpen 'Why is this here?'Parent · provenanceProvenanceChainANYNONE (read-only)DR-VIEW-PROVENANCEProvenanceViewedRC-PROV-VIEWUNCHANGEDChain rendered CurrentValue ← Rule ← Input ← SourceRecord ← SourceSystem ← Owner; read-only.
ALLC-CONCURRENCY-RESOLVEResolve concurrency conflictParent · concurrency controlNoLastWriteWinsCONCURRENCY_CONFLICTCONFLICT → RECONCILIATION_REQUIREDDR-RECONCILEConcurrencyConflictRaisedRC-CONC-CONFLICTRECONCILIATION_REQUIREDBoth versions preserved and displayed; no silent overwrite path exists.

AB · Reverse Traceability Matrix

27 transitions · 20 human-required · 20 reachable · 7 NO_UI_REQUIRED · 0 unreachable

ContractTransitionHuman act requiredScreenComponentVerdict
FC-FPSO-01CANDIDATE → HUMAN_CONFIRMEDYESS02C-LOC-CONFIRMREACHABLE
FC-FPSO-01GPS_UNAVAILABLE → MANUAL_SELECTION_PENDINGYESS02C-LOC-MANUALREACHABLE
FC-FPSO-01CHANGE_DETECTED → REASSESSMENT_REQUIREDYESS02bC-LOC-CHANGE-ACKREACHABLE
FC-FPSO-01POSITION_SAMPLED → CANDIDATE_SET_DERIVEDNONO UI REQUIRED
FC-FPSO-02RETRIEVED → REQUIRES_CONFIRMATIONNONO UI REQUIRED
FC-FPSO-02REQUIRES_CONFIRMATION → APPLICABLEYESS05C-DOC-APPLICABILITY-CONFIRMREACHABLE
FC-FPSO-02REVISION_CONFLICT → ESCALATED_TO_DOCUMENT_AUTHORITYYESS05C-DOC-REVISION-CONFLICTREACHABLE
FC-FPSO-02CONFIGURATION_ABSENT → APPLICABILITY_UNRESOLVEDNOS05C-DOC-UNRESOLVED (display)NO UI REQUIRED
FC-FPSO-03PENDING → ITEM_SATISFIED | ITEM_BLOCKEDYESS06C-PKG-ITEM-REVIEWREACHABLE
FC-FPSO-03COMPOSED → UNDER_REVIEWYESS06C-PKG-SUBMIT-REVIEWREACHABLE
FC-FPSO-03SATISFIED → INVALIDATED_AFTER_PREPARATIONNOS06C-PKG-INVALIDATION-BANNER (display)NO UI REQUIRED
FC-FPSO-03INVALIDATED → ITEM_PENDINGYESS06C-PKG-INVALIDATION-BANNERREACHABLE
FC-FPSO-04EXPECTED → PRESENT_CONFIRMEDYESS07C-CREW-CONFIRMREACHABLE
FC-FPSO-04PRESENT_CONFIRMED → REPLACEMENT_PENDING_EVALUATIONYESS07C-CREW-REPLACEREACHABLE
FC-FPSO-04COMPETENCY_EVALUATED → EXCEPTION_RAISEDNOS07C-CREW-EXCEPTION (display)NO UI REQUIRED
FC-FPSO-05PREPOPULATED → HUMAN_CONFIRMEDYESS08C-IPERC-CONFIRM-ROWREACHABLE
FC-FPSO-05PREPOPULATED → FIELD_OBSERVEDYESS08C-IPERC-MODIFY-ROWREACHABLE
FC-FPSO-05ROW_ADDED (field origin)YESS08C-IPERC-ADD-ROWREACHABLE
FC-FPSO-05CROSS_REVIEW_THRESHOLD_REACHED → CROSS_REVIEW_REQUIREDNOS08C-IPERC-CROSS-REVIEW (display)NO UI REQUIRED
FC-FPSO-06OBSERVED → MATERIAL_DELTA_REQUIRES_REASSESSMENTYESS09C-DELTA-RECORDREACHABLE
FC-FPSO-06OBSERVED → NON_MATERIAL_LOGGEDYESS09C-DELTA-RECORDREACHABLE
FC-FPSO-07LISTED → READYYESS11C-TOOL-VERIFYREACHABLE
FC-FPSO-07LISTED → TOOL_BLOCKEDYESS11C-TOOL-VERIFYREACHABLE
FC-FPSO-08REQUESTED → SIGNED_FOR_VERSIONYESS15C-SIGN-EXECUTEREACHABLE
FC-FPSO-08SIGNED_FOR_VERSION → SIGNATURE_VERSION_CONFLICTNOS15C-SIGN-VERSION-CONFLICT (display)NO UI REQUIRED
FC-FPSO-08CONFLICT → RESIGNATURE_REQUIREDYESS15C-SIGN-VERSION-CONFLICTREACHABLE
Parent · concurrencyCONFLICT → RECONCILIATION_REQUIREDYESALLC-CONCURRENCY-RESOLVEREACHABLE

49 · Application Design Invariants

12/12 held by construction.

IDInvariantUI enforcementHeld
INV-01GPSCandidate ≠ ConfirmedLocationCandidate cards are outlined and unactionable downstream; only C-LOC-CONFIRM yields the confirmed chip.YES
INV-02ConfirmedLocation ≠ AuthorizedWorkConfirmation unlocks navigation only; authorization state is rendered separately on S14/S15.YES
INV-03RetrievedDocument ≠ ApplicableDocumentFour distinct register states with distinct chips; retrieved rows carry no applicability styling.YES
INV-04ApplicableDocument ≠ WorkAuthorizationDocument register offers no authorization affordance.YES
INV-05Prepopulated ≠ HumanConfirmedFour never-merged IPERC origins with source indicators.YES
INV-06Reviewed ≠ AuthorizedReview states use neutral styling; green reserved for reached authorization contract states.YES
INV-07Presence ≠ CompetencyIndependent presence / competency / training / fitness chips per person.YES
INV-08Competency ≠ DecisionRightAuthority status is a separate attribute resolved on S14, not derived from competency chips.YES
INV-09Signature ≠ DecisionRightSign control is disabled without a governing right; signature panel shows DecisionRightStatus explicitly.YES
INV-10PairwisePASS ≠ AggregateLocationPASSAggregate banner is computed and rendered independently of the matrix.YES
INV-11MissingConfiguration ≠ NotRequiredAPPLICABILITY_UNRESOLVED warning state; NOT REQUIRED cannot be rendered without positive configuration.YES
INV-12PriorSignature ≠ CurrentVersionSignaturePrior signature preserved and marked NOT_VALID_FOR_CURRENT_VERSION on conflict.YES
Carried-forward assurance controlUX treatmentReintroduced
SilentLocationReplacement = PROHIBITEDS02b renders change, affected objects and reason code before any replacement is effective.NOT REINTRODUCED
AutomaticRevisionElection = PROHIBITEDS05 presents competing revisions with no default selection.NOT REINTRODUCED
MissingConfiguration ≠ NOT_MANDATORYAPPLICABILITY_UNRESOLVED used across S05, S06, S10, S12.NOT REINTRODUCED
PostPreparationItemInvalidationMustPropagate = TRUES06 invalidation banner plus dependent item propagation.NOT REINTRODUCED
CrewReplacement ≠ RoleSlotInheritanceS07 replacement opens an empty governed record.NOT REINTRODUCED
Review ≠ AuthorizationNeutral review styling rule enforced globally (§23 / §35).NOT REINTRODUCED
CrossReviewThresholdsMustBeGovernedS08 renders governed threshold source; UI never infers a threshold.NOT REINTRODUCED
MaterialDeltaInvalidationMustBeDependencyScopedS09 lists impacted dependents only; global invalidation is not renderable.NOT REINTRODUCED
SignatureRequestMustBeIdempotentS15 controlled pending state; repeat activation resolves to the same request.NOT REINTRODUCED
SignatureVersionConflictMustBeVisibleS15 conflict panel with preserved history.NOT REINTRODUCED
DecorativeStateCreation = PROHIBITEDEvery rendered state maps to a frozen contract state (AA matrix).NOT REINTRODUCED
DuplicateStateSemantics = PROHIBITEDNo screen introduces a second label for an existing contract state.NOT REINTRODUCED

AC · IAD-R01…R20 Interaction Design Assurance

20/20 PASS · interaction design assurance evidence only

IDAssertionMethodObservedResult
IAD-R01GPS suggestion visibly distinct from confirmed locationS02 component-state inspectionCandidate = outlined neutral card; Confirmed = governed chip with actor/timestamp; GPS_MATCH = AUTHORIZED not renderable.PASS
IAD-R02Location change cannot silently replace existing Location_IDS02b transition inspectionReplacement requires LOCATION_CHANGE_DETECTED disposition listing affected objects and reason code.PASS
IAD-R03Retrieved document visibly distinct from applicableS05 register state inspectionFour distinct states: Retrieved / Applicable / RequiresConfirmation / NotApplicable.PASS
IAD-R04Multiple revisions never result in silent revision selectionS05 conflict path inspectionREVISION_CONFLICT with no preselected revision; escalation to document authority.PASS
IAD-R05Missing configuration never renders as Not RequiredCross-screen state audit (S05/S06/S10/S12)APPLICABILITY_UNRESOLVED used in all four; NOT REQUIRED requires positive configuration.PASS
IAD-R06Prepopulated IPERC visibly distinct from human-confirmedS08 origin inspectionSYSTEM_PREPOPULATED / FIELD_OBSERVED / HUMAN_CONFIRMED / AUTHORIZED never merged.PASS
IAD-R07Review never visually implies authorizationGlobal styling rule auditGreen reserved for reached authorization states; review states neutral.PASS
IAD-R08Crew replacement never inherits prior worker authorityS07 replacement path inspectionREPLACEMENT_PENDING_EVALUATION opens empty record; no inheritance affordance exists.PASS
IAD-R09Mandatory invalidated package item propagates visiblyS06 invalidation inspectionINVALIDATED_AFTER_PREPARATION distinct from CURRENTLY_COMPLETE; header propagation present.PASS
IAD-R10Material delta impact remains dependency-scopedS09 propagation inspectionImpacted dependents enumerated; no global invalidation presentation.PASS
IAD-R11Pairwise SIMOPS PASS cannot mask aggregate conflictS13 composition inspectionAggregate banner independent of matrix; conflict persists with all-pass matrix.PASS
IAD-R12DecisionRight governs material actionsAA matrix decision-right column auditAll 25 material rows carry a DecisionRight; disabled-with-reason pattern defined.PASS
IAD-R13Signature version conflict visibleS15 conflict inspectionSIGNATURE_VERSION_CONFLICT rendered; prior signature preserved as NOT_VALID_FOR_CURRENT_VERSION.PASS
IAD-R14Duplicate signature request does not create duplicate actionS15 idempotency inspectionControlled pending state; repeat activation resolves to the same request identity.PASS
IAD-R15Source unavailable does not display fabricated current stateFailure UX auditSOURCE_UNAVAILABLE distinct from CONTROL_FAILED; last verified data timestamped and contract-permitted only.PASS
IAD-R16Concurrency conflict cannot silently overwriteConcurrency UX auditYourVersion / CurrentVersion / ChangedBy / ChangedAt / RequiredResolution; no last-write-wins path.PASS
IAD-R17Every material UI action maps to contractOrphan check over AA matrixOrphanUIActions = 0.PASS
IAD-R18Every required human transition is reachableAB reverse traceabilityHuman-required transitions 20, reachable 20, unreachable 0.PASS
IAD-R19No UI element introduces new functional stateState-provenance audit of AA matrixEvery current/resulting state resolves to a frozen contract or parent state; 0 decorative states.PASS
IAD-R20Parent and functional baselines remain unchangedBaseline manifest diffPH6A-IADA-REV1 changes = 0; PH6A-FPSO-FUNCTIONAL-BASELINE-REV0 changes = 0.PASS

These results are INTERACTION_DESIGN_ASSURANCE_EVIDENCE. They are not implementation evidence, simulation evidence or operational closure evidence, and they close no Phase 6A blocking condition.

AE · Bechtelization Readiness Assessment

Formal certification deferred to G-FPSO-04B.

DimensionVerdictBasis
CorporateVocabularyReadyREADY WITH GAPCorporate grammar inherited from BXIA-REV0; saved-view and column vocabulary pending project approval (F-IAD-03).
AconexInteractionPatternReadyREADYRegister → search → filter → select → detail → workflow → history → related items preserved on S05 and every register surface.
DocumentIdentityReadyREADYDocument_ID, class, revision, status, source system, source owner, participation mode and effective date rendered on every document row.
GovernanceVisibilityReadyREADYOwner, decision right, reason code and escalation route are mandatory on all material blocking presentations.
FieldExperienceReadyREADYEight field questions drive S01 and the mobile priority order; control requirements preserved at all breakpoints.
ProvenanceVisibilityReadyREADY'Why is this here?' chain available on all prepopulated/derived values; assurance trace view is read-only.
READY FOR G-FPSO-04B1 BECHTELIZATION PRECONDITION GAP (F-IAD-03, non-blocking)

AF · G-FPSO-04 Decision & Final State

DESIGN-TO-CONTRACT CONFORMANCE

CriterionRequiredActualMet
FunctionalContractChanges00YES
ArchitectureChanges00YES
NewFunctionalStates00YES
NewAuthorityPaths00YES
NewSourceAuthority00YES
OrphanUIActions00YES
UnreachableHumanTransitions00YES
AssuranceRegressions00YES
ContractTraceabilityCOMPLETECOMPLETEYES
ReverseTraceabilityCOMPLETECOMPLETEYES
FieldVsAssuranceBoundaryPRESERVEDPRESERVEDYES
IAD-R01…R2020/20 PASS20/20 PASSYES
Strict stop conditionObservedTriggered
FunctionalContractChangeRequiredFALSENOT TRIGGERED
ArchitectureChangeRequiredFALSENOT TRIGGERED
NewFactClassRequiredFALSENOT TRIGGERED
NewDecisionRightRequiredFALSENOT TRIGGERED
NewAuthorityPathRequiredFALSENOT TRIGGERED
NewMaterialStateRequiredFALSENOT TRIGGERED
ExistingContractMeaningMustChangeFALSENOT TRIGGERED
FPSO_INTERACTION_APPLICATION_DESIGN
ACCEPTED
DesignID
PH6A-FPSO-IAD-REV1
FunctionalBaseline
PH6A-FPSO-FUNCTIONAL-BASELINE-REV0
CorporateInteractionParent
PH6A-BXIA-REV0
FunctionalContractChanges
0
ArchitectureChanges
0
NewFunctionalStates
0
NewAuthorityPaths
0
SourceAuthorityChanges
0
OrphanUIActions
0
UnreachableHumanTransitions
0
AssuranceRegressions
0
DesignToContractTraceability
COMPLETE
ReverseTraceability
COMPLETE
IADRegression
20/20
G-FPSO-04
PASS
BechtelizationReadiness
READY_FOR_G-FPSO-04B
PrototypeImplementation
NOT_STARTED
DemoScenarioEngineering
NOT_STARTED
Simulation
NOT_STARTED
OperationalClosureEvidence
NOT_YET_ACQUIRED
Phase6A
HOLD
Phase6B
NOT_AUTHORIZED
Phase7
NO_GO
BC09Protection
ACTIVE
PilotExposure
PROHIBITED