Phase 6A — Integrated Evidence Acquisition Workstream
Mesa 1 + Mesa 2 + Mesa 3 · BC-01 → BC-09
What real evidence is still required, who is competent to provide or approve it, what constitutes acceptable evidence, what blocker can be retested once it arrives, and what dependency still prevents operational closure?
Baseline consumed: Mesa 1 — ENTERPRISE_ENABLEMENT_HOLD (BC-01/02/03/05/06 REMAINS_OPEN, 5/5) · Mesa 2 — ORGANIZATIONAL_GOVERNANCE_HOLD (BC-04/BC-07 REMAINS_OPEN, GOVERNANCE_DESIGN_STRUCTURALLY_SOUND) · Mesa 3 — FIELD_EXECUTION_AND_MEASUREMENT_HOLD (BC-08/BC-09 REMAINS_OPEN, FIELD_AND_MEASUREMENT_DESIGN_STRUCTURALLY_SOUND)
Baseline changed: NONE — no architecture redesign, no Mesa reassessment, no disposition upgrade.
— · How to read this workstream
- Document exists ≠ Condition demonstrated.
- System capability ≠ Authorized participation.
- Named role ≠ Competent authority.
- Prototype behavior ≠ Operational evidence.
- Ready to measure ≠ Baseline established.
Closure = design clarity + competent authority + verifiable evidence + known failure condition + demonstrable acceptance criterion.
OPEN / EVIDENCE_REQUIRED → amber. STRUCTURALLY_SOUND → controlled positive. CLOSED → positive. HOLD → controlled warning. CONTRADICTED / FAIL / PROHIBITED / STOP → red.
Missing evidence is not failure. Absence of evidence is never reported as a confirmed failure.
- Do not simulate OperationalClosureEvidence or fabricate owner approvals.
- Do not infer system authority, invent APIs, IAM identities, JobCards or field evidence.
- Do not simulate Critical Control as closure evidence.
- Do not retrospectively reconstruct the BEFORE baseline or expose Pilot functionality before BC-09 permits it.
- Do not commence Phase 6B, initiate Phase 7, or reopen architecture without contradiction evidence.
A · Integrated evidence closure executive summary
Phase 6A
HOLD
Phase 6B
NOT_AUTHORIZED
Blockers open
9 / 9 REMAINS_OPEN
Evidence quality
NONE × 9
Evidence requests issued
24
Targeted retests completed
0
Material contradictions
NONE IDENTIFIED
BC-09 protection
ACTIVE · no contamination event
- Design across all three Mesas is structurally sound; what is missing is OperationalClosureEvidence from competent external owners — this is absence of evidence, not confirmed failure.
- No blocker may move from EvidenceQuality NONE directly to CLOSED. Evidence assessment and targeted retest are mandatory intermediate steps.
- The workstream converts nine HOLD conditions into nine externally addressable evidence demands with named competent owners and explicit acceptance criteria.
- The purpose of this workstream is not to make blockers appear closed. It is to create a controlled path by which each blocker can become technically and institutionally defendable through real evidence.
B · Master blocker register — BC-01 → BC-09
Permitted states: NONE · PARTIAL · SUFFICIENT_FOR_RETEST · SUFFICIENT_FOR_CLOSURE. A blocker may never move from NONE directly to CLOSED: evidence assessment and targeted retest are mandatory intermediate steps.
Design condition: Participation modes, federation keys and fail-closed interface behaviour defined at Phase 5 (ADR-13/ADR-15/ADR-17).
Competent authority: Enterprise Architecture (with each System Owner)
Evidence owner: Q4 Owner · Aconex/IM · P6/Project Controls · Smart Completions · IT/IM
Evidence required: Per source/object: SystemOwner, ParticipationMode, InterfaceMechanism, Authentication, Read/Write/Snapshot authority, VersionBehaviour, FailureBehaviour.
Acceptable evidence form: Signed system participation authorisation per source, plus interface/mechanism confirmation from the owning system's technical authority.
Evidence received: NONE_RECEIVED
Evidence ref / date / validity: NOT_SUPPLIED_BY_OWNER · NOT_SUPPLIED_BY_OWNER · NOT_SUPPLIED_BY_OWNER
External dependency: System owner authorisation outside the design team's authority (EVIDENCE_DEPENDENCY)
Retest eligibility: NOT_YET_ELIGIBLE · RT-01 (queued, not eligible)
Residual risk: Readiness verdicts could be computed from unauthorised or unversioned source reads; evidence reconstruction would be undefendable.
Closure disposition: REMAINS_OPEN
Design condition: ABAC authority resolution and fail-closed denial designed and prototype-demonstrated.
Competent authority: IAM / Cyber authority
Evidence owner: IAM / Cyber · IT/IM · Operational Lifecycle Authority
Evidence required: Real Pilot IAM test population IAM-01…IAM-06 evidencing RealIdentity, Authentication, RoleResolution, AuthorityScope, Delegation, Revocation/denial.
Acceptable evidence form: IAM-issued access record per test identity plus a witnessed authentication/denial log from the enterprise IAM system.
Evidence received: NONE_RECEIVED
Evidence ref / date / validity: NOT_SUPPLIED_BY_OWNER · NOT_SUPPLIED_BY_OWNER · NOT_SUPPLIED_BY_OWNER
External dependency: Enterprise IAM provisioning for Pilot identities (EVIDENCE_DEPENDENCY)
Retest eligibility: NOT_YET_ELIGIBLE · RT-02 (queued, not eligible)
Residual risk: Authority could be inferred rather than resolved; prototype UI denial is not IAM evidence and cannot be substituted.
Closure disposition: REMAINS_OPEN
Design condition: CV-07 state model, transitions and invalid-transition fail-closed behaviour defined.
Competent authority: Operational Lifecycle Authority
Evidence owner: Operations · Construction · Q4 Owner
Evidence required: Competent decision artefact naming LifecycleOwner, AllowedState, AllowedTransition, TransitionAuthority, Delegate, InvalidTransitionBehaviour, EvidenceRequired.
Acceptable evidence form: Approved CV-07 lifecycle authority decision record signed by the lifecycle owner.
Evidence received: NONE_RECEIVED
Evidence ref / date / validity: NOT_SUPPLIED_BY_OWNER · NOT_SUPPLIED_BY_OWNER · NOT_SUPPLIED_BY_OWNER
External dependency: BC-02 for technical enforceability of the named authorities (EXECUTION_DEPENDENCY)
Retest eligibility: NOT_YET_ELIGIBLE · RT-03 (queued, not eligible)
Residual risk: GovernanceLifecycleClosed may be reached while LifecycleTechnicallyEnforceable remains dependent on BC-02.
Closure disposition: REMAINS_OPEN
Design condition: GOVERNANCE_DESIGN_STRUCTURALLY_SOUND — 7 governance functions, decision rights, vacancy fail-closed behaviour defined.
Competent authority: Business Product Owner / Project Management
Evidence owner: Operations · Construction · ES&H · Project Management · Change/Adoption
Evidence required: Real named assignments for BusinessProductOwner, LocationSteward, FederationMappingSteward, RuleOwner, IntegrationOwner, OperationalSupportOwner, ChangeAdoptionOwner — each Assigned, Authorized, Available, DelegateDefined, EscalationDefined, with capacity and SoD tested.
Acceptable evidence form: Signed appointment letters or governance charter entries with named individuals, delegates and escalation paths.
Evidence received: NONE_RECEIVED
Evidence ref / date / validity: NOT_SUPPLIED_BY_OWNER · NOT_SUPPLIED_BY_OWNER · NOT_SUPPLIED_BY_OWNER
External dependency: Organisational appointment authority; BC-02 for operational authority enforcement (EVIDENCE_DEPENDENCY)
Retest eligibility: NOT_YET_ELIGIBLE · RT-04 (queued, not eligible)
Residual risk: Vacant stewardship keeps the system fail-closed; Pilot journeys would stall rather than mislead.
Closure disposition: REMAINS_OPEN
Design condition: CA-04 record classes and minimum-attribute model defined; data minimisation designed in.
Competent authority: Records Management with Privacy / Compliance
Evidence owner: Records Management · Privacy · Compliance
Evidence required: Per material CA-04 item: RecordClass, DataClassification, PersonalDataRequirement, MinimumAttribute, RetentionBasis, AccessScope, EvidenceRef.
Acceptable evidence form: Records/Privacy determination signed by the competent authority, referencing the enterprise retention schedule version.
Evidence received: NONE_RECEIVED
Evidence ref / date / validity: NOT_SUPPLIED_BY_OWNER · NOT_SUPPLIED_BY_OWNER · NOT_SUPPLIED_BY_OWNER
External dependency: Enterprise records and privacy determination process (EVIDENCE_DEPENDENCY)
Retest eligibility: NOT_YET_ELIGIBLE · RT-05 (queued, not eligible)
Residual risk: Without determination, readiness evidence could over-collect HR/Health attributes; minimisation must remain enforced by design.
Closure disposition: REMAINS_OPEN
Design condition: Critical Control non-compensable gating designed; currently SIMULATED in prototype — simulation is not closure evidence.
Competent authority: Critical Control Owner with ES&H competent authority
Evidence owner: Critical Control Owner · Forwood Owner · ES&H
Evidence required: A competent election of PATH_A_REAL_PARTICIPATION or PATH_B_FORMAL_RESCOPE. Path B must record DecisionAuthority, Reason, PilotEvidenceLost, ResidualRisk, Phase7Impact.
Acceptable evidence form: Path A: Forwood/Critical Control participation authorisation plus interface confirmation. Path B: signed rescope decision with all five fields populated.
Evidence received: NONE_RECEIVED
Evidence ref / date / validity: NOT_SUPPLIED_BY_OWNER · NOT_SUPPLIED_BY_OWNER · NOT_SUPPLIED_BY_OWNER
External dependency: BC-01 participation authorisation for the Critical Control source (EVIDENCE_DEPENDENCY)
Retest eligibility: NOT_YET_ELIGIBLE · RT-06 (queued, not eligible)
Residual risk: An unelected path leaves the highest-severity non-compensable gate unevidenced; Path B must never be chosen merely to facilitate closure.
Closure disposition: REMAINS_OPEN
Design condition: L1/L2/L3 support model and six drill scenarios S-01…S-06 defined.
Competent authority: Operational Support Owner
Evidence owner: IT Support · Functional Support · Business Product Owner
Evidence required: Named L1/L2/L3 ownership plus evidence-qualified execution of drills S-01…S-06 resolved without the design team acting as hidden support authority.
Acceptable evidence form: Support model appointment record plus dated drill reports with resolver identity, elapsed time and outcome.
Evidence received: NONE_RECEIVED
Evidence ref / date / validity: NOT_SUPPLIED_BY_OWNER · NOT_SUPPLIED_BY_OWNER · NOT_SUPPLIED_BY_OWNER
External dependency: BC-04 governance appointments define the escalation targets for L2/L3 (EXECUTION_DEPENDENCY)
Retest eligibility: NOT_YET_ELIGIBLE · RT-07 (queued, not eligible)
Residual risk: Hidden design-team dependence would invalidate any Pilot support conclusion.
Closure disposition: REMAINS_OPEN
Design condition: FIELD_AND_MEASUREMENT_DESIGN_STRUCTURALLY_SOUND — 17 non-compensable prerequisite domains and 10 acceptance conditions defined.
Competent authority: Construction (field execution authority)
Evidence owner: Construction · Field Supervision · Project Controls · BEO · Materials · Tools · Logistics · Environment · Client Interface · ES&H
Evidence required: Field evidence for the 10 BC-08 acceptance conditions: RealWorkfront, RealLocation, RealWorkDemand, Crew, Equipment, Materials, FieldOwner, ExecutionWindow, SIMOPSContext, FieldPrerequisites.
Acceptable evidence form: Field-issued records: approved workfront/work order references, crew rosters, materials status, permit/SIMOPS context, signed by field supervision.
Evidence received: NONE_RECEIVED
Evidence ref / date / validity: NOT_SUPPLIED_BY_OWNER · NOT_SUPPLIED_BY_OWNER · NOT_SUPPLIED_BY_OWNER
External dependency: BC-06 where Critical Controls apply to the CV-07 workfront (EXECUTION_DEPENDENCY)
Retest eligibility: NOT_YET_ELIGIBLE · RT-08 (queued, not eligible)
Residual risk: Without a real workfront the Pilot would evaluate synthetic demand; 0/10 demonstrated with OperationalClosureEvidence — this is absence of evidence, not confirmed failure.
Closure disposition: REMAINS_OPEN
Design condition: 12 BEFORE metrics FROZEN and DEFINED; measurement event model and attribution rules defined.
Competent authority: Measurement Owner with Project Controls
Evidence owner: Project Controls · Construction · Data/Analytics · Field Observation · Assurance
Evidence required: Per metric progression DEFINED → SOURCE_CONFIRMED → OWNER_CONFIRMED → COLLECTION_READY → COLLECTING → BASELINE_ESTABLISHED, with a real uncontaminated prospective collection period.
Acceptable evidence form: Named metric owner and source confirmation per metric, collection procedure, and dated prospective observation records.
Evidence received: NONE_RECEIVED
Evidence ref / date / validity: NOT_SUPPLIED_BY_OWNER · NOT_SUPPLIED_BY_OWNER · NOT_SUPPLIED_BY_OWNER
External dependency: BC-08 field representativeness; time itself (irreversible) (CLOSURE_DEPENDENCY)
Retest eligibility: NOT_YET_ELIGIBLE · RT-09 (queued, not eligible)
Residual risk: Time-irreversible: any Pilot exposure before collection starts permanently destroys the BEFORE baseline. BC09Protection remains ACTIVE.
Closure disposition: REMAINS_OPEN
C · Five-lane evidence acquisition plan
Objective: Prove that CV-07 can resolve RealIdentity → AuthorizedRole → AuthoritativeObject → GovernedLifecycle without inferred authority.
Owners: Enterprise Architecture · IT / IM · IAM / Cyber · Q4 Owner · Aconex / IM · P6 / Project Controls · Smart Completions · Operational Lifecycle Authority
First action: Issue per-source participation authorisation requests and the IAM-01…IAM-06 provisioning request; both are prerequisites to any lifecycle enforcement test.
Constraint: Controlled simpler mechanisms (snapshot, controlled manual federation) are acceptable; live integration is not required where a simpler authorised mechanism suffices.
Objective: Close classification, retention and Critical Control participation through competent decision artefacts and real system/process evidence.
Owners: Records Management · Privacy · Compliance · Governance · Critical Control Owner · Forwood Owner · ES&H competent authority
First action: Table the material CA-04 items for a Records/Privacy determination and force a competent BC-06 path election (A or B).
Constraint: Simulated Critical Control participation is DesignEvidence and can never close BC-06.
Objective: Demonstrate that CV-07 can be governed and supported without hidden dependence on the design team.
Owners: Business Product Owner · Operations · Construction · ES&H · IT Support · Functional Support · Change / Adoption · Project Management
First action: Obtain named appointments for the 7 governance functions; drills S-01…S-06 cannot be evidence-qualified until L2/L3 escalation targets exist.
Constraint: Named role ≠ competent authority: assignment must include authorisation, availability, delegate and escalation.
Objective: Prove that a real CV-07 workfront exists and that its prerequisites are evidenceable.
Owners: Construction · Project Controls · Field Supervision · BEO · Materials · Tools · Logistics · Environment · Client Interface · ES&H
First action: Field supervision to nominate the actual CV-07 workfront, its location and execution window from live field records.
Constraint: Field observation for identification is NON_INTRUSIVE_PREPARATION; nothing may change the current way of working.
Objective: Establish an uncontaminated prospective BEFORE baseline for the 12 frozen metrics.
Owners: Project Controls · Construction · Measurement Owner · Data / Analytics · Field Observation · Assurance
First action: Confirm metric owner and source per metric (SOURCE_CONFIRMED / OWNER_CONFIRMED) before any collection procedure is issued.
Constraint: PilotExposure remains PROHIBITED until the applicable BC-09 condition is satisfied.
D · Owner-based evidence request register
One request per unresolved acceptance criterion. No dates are invented: due dates are set by the competent owner on acceptance of the request.
Requested decision or evidence: Authorised participation mode for Q4 objects in the CV-07 Pilot (LIVE_READ / CONTROLLED_TRANSACTION / CONTROLLED_SNAPSHOT / CONTROLLED_MANUAL_FEDERATION / SIMULATED_ONLY / NOT_REQUIRED) with read/write/snapshot authority and failure behaviour.
Why required: Readiness verdicts consume Q4 work-control state; unauthorised reads make the decision trail undefendable.
Minimum acceptable: Written authorisation naming participation mode and read scope.
Preferred: Signed participation authorisation with interface mechanism, authentication method and version behaviour.
Acceptable alternative: Controlled snapshot authorisation with named snapshot custodian and cadence.
Not accepted: Verbal assurance, design-team assumption, prototype adapter configuration.
Due dependency: None
Retest triggered if received: RT-01
Requested decision or evidence: Participation authorisation and document version behaviour for pinned document references.
Why required: Decision pinning requires a stable, authoritative document version reference.
Minimum acceptable: Confirmation that pinned version references remain resolvable for the retention period.
Preferred: Signed participation authorisation including version and failure behaviour.
Acceptable alternative: Controlled snapshot of the applicable document register with custodian.
Not accepted: Screenshots of the document register; prototype mock adapter.
Due dependency: None
Retest triggered if received: RT-01
Requested decision or evidence: Participation authorisation for schedule/lookahead objects consumed by CV-07.
Why required: Lookahead and execution window determination depend on authoritative schedule data.
Minimum acceptable: Written confirmation of the authorised read mechanism and refresh cadence.
Preferred: Signed participation authorisation with failure behaviour on stale data.
Acceptable alternative: Controlled periodic extract with named custodian.
Not accepted: Ad-hoc spreadsheets without owner attribution.
Due dependency: None
Retest triggered if received: RT-01
Requested decision or evidence: Participation authorisation for completions/turnover objects, or a formal NOT_REQUIRED determination for the Pilot scope.
Why required: Scope must be authoritative: an unstated source is not the same as an out-of-scope source.
Minimum acceptable: Written participation mode or NOT_REQUIRED determination.
Preferred: Signed participation authorisation with object list.
Acceptable alternative: Formal NOT_REQUIRED determination with rationale.
Not accepted: Silence or absence from discussion.
Due dependency: None
Retest triggered if received: RT-01
Requested decision or evidence: Consolidated System Participation Matrix approval across all Pilot sources and objects.
Why required: BC-01 closes on the integrated matrix, not on individual confirmations alone.
Minimum acceptable: Approved matrix covering every Pilot object with no UNRESOLVED entries.
Preferred: Approved matrix plus fail-closed behaviour statement per interface.
Acceptable alternative: Approved matrix with explicitly recorded controlled exceptions.
Not accepted: Draft matrix maintained by the design team.
Due dependency: ER-01…ER-04
Retest triggered if received: RT-01
Requested decision or evidence: Provisioning of the real Pilot IAM test population IAM-01…IAM-06 with role resolution and delegation configured.
Why required: Authority must be resolved by the enterprise IAM, never inferred by the readiness layer.
Minimum acceptable: IAM-issued account records for all six identities with assigned roles.
Preferred: IAM records plus witnessed authentication and denial logs.
Acceptable alternative: IAM records with a scheduled witnessed test date confirmed by IAM.
Not accepted: Prototype UI denial screenshots; mock identities.
Due dependency: None
Retest triggered if received: RT-02
Requested decision or evidence: Revocation and denial evidence: an identity whose authority is withdrawn must be denied at the enterprise layer.
Why required: Fail-closed behaviour must be demonstrated at the real authority boundary.
Minimum acceptable: Dated revocation record for one test identity.
Preferred: Revocation record plus the corresponding denied access attempt log.
Acceptable alternative: Witnessed revocation demonstration recorded by Assurance.
Not accepted: Design-team assertion that the prototype denies access.
Due dependency: ER-06
Retest triggered if received: RT-02
Requested decision or evidence: CV-07 lifecycle authority decision record: owner, allowed states, allowed transitions, transition authority, delegate, invalid-transition behaviour, evidence required per transition.
Why required: Without a competent lifecycle decision, state changes have no institutional owner.
Minimum acceptable: Signed decision record naming the lifecycle owner and allowed transitions.
Preferred: Full record including delegate, invalid-transition behaviour and per-transition evidence.
Acceptable alternative: Interim decision record with named owner and a dated completion commitment.
Not accepted: Prototype state machine documentation.
Due dependency: None
Retest triggered if received: RT-03
Requested decision or evidence: Confirmation of whether GovernanceLifecycleClosed can be declared while technical enforceability remains dependent on BC-02.
Why required: The two conditions must be dispositioned separately, not merged.
Minimum acceptable: Written statement distinguishing governance closure from technical enforceability.
Preferred: Statement plus recorded residual risk and control.
Acceptable alternative: Recorded decision to hold both until BC-02 closes.
Not accepted: Implicit assumption that governance closure implies enforcement.
Due dependency: ER-08
Retest triggered if received: RT-03
Requested decision or evidence: Named appointments for the 7 governance functions, each with delegate, escalation path, authorisation and availability.
Why required: Vacant stewardship keeps the system fail-closed and blocks Pilot governance.
Minimum acceptable: Appointment record naming individuals for all 7 functions.
Preferred: Signed charter with authorisation, delegate, escalation and availability per function.
Acceptable alternative: Phased appointment with named interim holders and dated completion.
Not accepted: Role titles without named individuals.
Due dependency: None
Retest triggered if received: RT-04
Requested decision or evidence: Capacity and segregation-of-duties assessment for the appointed stewards.
Why required: One person holding conflicting stewardships defeats the governance design.
Minimum acceptable: Written SoD check across the 7 functions.
Preferred: SoD check plus capacity allocation (time commitment per function).
Acceptable alternative: SoD check with recorded controlled exceptions and compensating controls.
Not accepted: Assumption that appointees have capacity.
Due dependency: ER-10
Retest triggered if received: RT-04
Requested decision or evidence: Rule governance and change-control ownership confirmation (ADR-16 rule owner, change classification authority).
Why required: Rule changes alter readiness verdicts and must have a competent owner.
Minimum acceptable: Named rule owner with change authority.
Preferred: Rule governance procedure with classification and approval thresholds.
Acceptable alternative: Interim rule owner with a defined review cadence.
Not accepted: Design team retaining rule authority.
Due dependency: ER-10
Retest triggered if received: RT-04
Requested decision or evidence: Record class and retention basis determination for each material CA-04 readiness evidence item.
Why required: Evidence reconstruction depends on a lawful, owned retention basis.
Minimum acceptable: Determination naming record class and retention period per item.
Preferred: Full determination including access scope and disposal trigger.
Acceptable alternative: Provisional determination under an existing enterprise retention schedule reference.
Not accepted: Design-team proposed retention values.
Due dependency: None
Retest triggered if received: RT-05
Requested decision or evidence: Personal data determination and minimum attribute set for competency/medical-linked readiness conditions.
Why required: Readiness must consume the minimum attribute (e.g. valid/expired), not the underlying record.
Minimum acceptable: Written confirmation of the minimum attribute permitted per condition.
Preferred: Privacy determination with lawful basis and access scope.
Acceptable alternative: Determination restricting readiness to boolean validity flags only.
Not accepted: Any proposal to copy full HR or Health records into readiness evidence.
Due dependency: ER-13
Retest triggered if received: RT-05
Requested decision or evidence: Competent election of PATH_A_REAL_PARTICIPATION or PATH_B_FORMAL_RESCOPE for Critical Control in the Pilot.
Why required: Critical Control is non-compensable; an unelected path leaves the highest-severity gate unevidenced.
Minimum acceptable: Signed election naming the path and decision authority.
Preferred: Path A: participation authorisation and interface confirmation from the Forwood owner.
Acceptable alternative: Path B: signed rescope recording DecisionAuthority, Reason, PilotEvidenceLost, ResidualRisk, Phase7Impact.
Not accepted: Continued prototype simulation presented as participation.
Due dependency: ER-01 (BC-01 participation for the Critical Control source)
Retest triggered if received: RT-06
Requested decision or evidence: ES&H endorsement of the elected Critical Control path and its residual risk for the CV-07 workfront.
Why required: The ES&H authority owns the safety consequence of any rescope.
Minimum acceptable: Written endorsement or objection.
Preferred: Endorsement with named residual risk and monitoring control.
Acceptable alternative: Conditional endorsement with stated limits on Pilot scope.
Not accepted: Absence of ES&H position treated as consent.
Due dependency: ER-15
Retest triggered if received: RT-06
Requested decision or evidence: Named L1 / L2 / L3 support ownership for the Pilot, including hours of cover and escalation timings.
Why required: Support cannot silently default to the design team.
Minimum acceptable: Named owners for all three tiers.
Preferred: Support model document with cover hours, escalation timings and contact routes.
Acceptable alternative: Interim support model with named owners and a review date.
Not accepted: Design team listed as L2 or L3.
Due dependency: ER-10
Retest triggered if received: RT-07
Requested decision or evidence: Evidence-qualified execution of drills S-01 User/Access, S-02 Mapping Conflict, S-03 Rule Question, S-04 Interface Failure, S-05 Authority Issue, S-06 Evidence Reconstruction.
Why required: Support capability is demonstrated by resolution, not by an org chart.
Minimum acceptable: Dated drill reports for all six scenarios with resolver identity.
Preferred: Drill reports including elapsed time, outcome and design-team involvement statement.
Acceptable alternative: Partial drill set with a scheduled completion date for the remainder.
Not accepted: Drills resolved by the design team acting as hidden support authority.
Due dependency: ER-17
Retest triggered if received: RT-07
Requested decision or evidence: Nomination of the real CV-07 workfront: work demand reference, real location, field owner and execution window.
Why required: A Pilot evaluating synthetic demand proves nothing about field readiness.
Minimum acceptable: Field-issued workfront reference with named field owner.
Preferred: Workfront reference plus location, execution window and crew allocation from live field records.
Acceptable alternative: Nominated workfront with a dated commitment for the remaining attributes.
Not accepted: Prototype JobCards or design-team constructed scenarios.
Due dependency: None
Retest triggered if received: RT-08
Requested decision or evidence: Prerequisite status evidence for materials, tools, equipment and logistics for the nominated workfront.
Why required: Non-compensable prerequisites must be individually evidenceable, not averaged.
Minimum acceptable: Current status record per prerequisite domain.
Preferred: Status record with source system reference and date.
Acceptable alternative: Field-supervisor attested status with observation date.
Not accepted: Aggregated readiness percentages.
Due dependency: ER-19
Retest triggered if received: RT-08
Requested decision or evidence: SIMOPS context, permit and environmental constraint evidence for the nominated workfront and location.
Why required: Location context is inherited; authorisation is never inherited.
Minimum acceptable: Current SIMOPS/permit context for the location and window.
Preferred: Documented SIMOPS assessment referencing CUM rules applicable to the location.
Acceptable alternative: Field-issued permit records with attested currency.
Not accepted: Prototype SIMOPS scenario data.
Due dependency: ER-19
Retest triggered if received: RT-08
Requested decision or evidence: Per-metric owner confirmation for the 12 frozen BEFORE metrics (OWNER_CONFIRMED).
Why required: An unowned metric cannot be collected or defended.
Minimum acceptable: Named owner per metric.
Preferred: Named owner plus accountability statement per metric.
Acceptable alternative: Single accountable owner with named per-metric collectors.
Not accepted: Design team as metric owner.
Due dependency: None
Retest triggered if received: RT-09
Requested decision or evidence: Per-metric source confirmation and collection procedure (SOURCE_CONFIRMED → COLLECTION_READY).
Why required: Collection must be real and repeatable, not reconstructed.
Minimum acceptable: Source system or observation method per metric.
Preferred: Documented collection procedure with frequency, sampling and quality checks.
Acceptable alternative: Manual field observation protocol with named observers.
Not accepted: Retrospective reconstruction from historical records.
Due dependency: ER-22
Retest triggered if received: RT-09
Requested decision or evidence: Confirmation of the baseline period start and anti-contamination controls before any Pilot exposure.
Why required: BC-09 is time-irreversible; the BEFORE window cannot be recreated.
Minimum acceptable: Written baseline period start authorisation.
Preferred: Authorisation plus anti-contamination register acknowledgement by Construction and Project Controls.
Acceptable alternative: Provisional start with a named assurance observer and contamination watch.
Not accepted: Any start declared after Pilot exposure has begun.
Due dependency: ER-19, ER-22, ER-23
Retest triggered if received: RT-09
E–G · Mesa evidence status (Mesa 1 · Mesa 2 · Mesa 3)
Design condition: Design defined at Phase 5 baseline; no structural contradiction identified.
Evidence condition: OperationalClosureEvidence NOT_YET_SUFFICIENT — EvidenceQuality NONE across all five blockers.
Requests issued: 16
Retest eligible: 0/5
Note: Evidence acquisition open in Lanes 1 and 2. Mesa 1 is not reassessed here.
Design condition: GOVERNANCE_DESIGN_STRUCTURALLY_SOUND — no identified structural contradiction; does not imply READY or CLOSED.
Evidence condition: OperationalClosureEvidence NOT_YET_SUFFICIENT — 2/15 exit criteria demonstrated at DesignEvidence level, 13/15 pending.
Requests issued: 5
Retest eligible: 0/2
Note: MESA_2_PRESENTATION_BASELINE remains FROZEN. Lane 3 acquisition only.
Design condition: FIELD_AND_MEASUREMENT_DESIGN_STRUCTURALLY_SOUND — 12 metrics FROZEN and DEFINED.
Evidence condition: OperationalClosureEvidence NOT_YET_SUFFICIENT — BC-08 0/10 demonstrated with OperationalClosureEvidence (absence of evidence, not confirmed failure); BC-09 collection NOT_STARTED.
Requests issued: 6
Retest eligible: 0/2
Note: PilotExposure PROHIBITED · BC09Protection ACTIVE · no contamination event recorded.
H · Cross-blocker dependency graph
BC-02 ──▶ BC-03 (execution: authority enforceable) BC-01 ◀──▶ BC-06 (evidence / design: participation ↔ path election) BC-02 ──▶ BC-04 (execution: attributable steward decisions) BC-04 ──▶ BC-07 (execution: L2/L3 escalation targets) BC-06 ──▶ BC-08 (execution: Critical Control at the workfront) BC-05 ──▶ BC-09 (design: minimisation constrains collection) BC-08 ──▶ BC-09 (closure: field representativeness) BC-09 ──▶ PHASE 6B (closure: uncontaminated BEFORE baseline)
Meaning: Lifecycle transition authority is only technically enforceable once real IAM resolves the authorised role.
Meaning: Critical Control participation requires an authorised source interface; conversely a BC-06 Path B rescope changes the BC-01 participation set. Bidirectional.
Meaning: The elected Critical Control path determines whether the Critical Control source appears in the participation matrix at all.
Meaning: Appointed stewards need real identities and authority scopes for their decisions to be attributable.
Meaning: Support escalation targets (L2/L3) are defined by the governance appointments; drills cannot be evidence-qualified before then.
Meaning: Where Critical Controls apply to the CV-07 workfront, field prerequisites cannot be fully evidenced until the path is elected.
Meaning: The BEFORE baseline must be measured on a representative real workfront; without BC-08 the baseline has no defined subject.
Meaning: Phase 6B cannot commence until the prospective BEFORE baseline is established and uncontaminated.
Meaning: Metric collection must respect the classification, minimisation and retention determination.
I · Evidence quality register
DesignEvidence
Design artefacts, prototype screenshots, synthetic transactions, mock identities, simulated system participation.
Cannot close any blocker. Demonstrates design intent only.
SupportingEvidence
Real but partial artefacts: drafts, meeting records, indicative confirmations without competent sign-off.
May raise EvidenceQuality to PARTIAL. Cannot close.
OperationalClosureEvidence
Attributable artefact issued by the competent authority, dated, versioned, and verifiable outside the prototype.
The only class that may directly support blocker closure.
ContradictoryEvidence
Real evidence conflicting with an accepted design assumption.
Raises a CONTRADICTION_ID. Never silently reconciled.
NotApplicableEvidence
Formally scoped out by competent authority with recorded rationale.
Supports RESCOPED_BY_COMPETENT_AUTHORITY only, never CLOSED.
Every operational artefact must carry EvidenceDate, EffectiveDate, Validity, SourceVersion, Owner and CurrentAtRetest (YES/NO). An obsolete artefact cannot close a current operational condition; expiry re-opens the blocker.
OperationalClosureEvidence held: NONE
Required for retest / closure: SUFFICIENT_FOR_RETEST / SUFFICIENT_FOR_CLOSURE
Gap: Per source/object: SystemOwner, ParticipationMode, InterfaceMechanism, Authentication, Read/Write/Snapshot authority, VersionBehaviour, FailureBehaviour.
Current at retest: N/A — no operational artefact held
OperationalClosureEvidence held: NONE
Required for retest / closure: SUFFICIENT_FOR_RETEST / SUFFICIENT_FOR_CLOSURE
Gap: Real Pilot IAM test population IAM-01…IAM-06 evidencing RealIdentity, Authentication, RoleResolution, AuthorityScope, Delegation, Revocation/denial.
Current at retest: N/A — no operational artefact held
OperationalClosureEvidence held: NONE
Required for retest / closure: SUFFICIENT_FOR_RETEST / SUFFICIENT_FOR_CLOSURE
Gap: Competent decision artefact naming LifecycleOwner, AllowedState, AllowedTransition, TransitionAuthority, Delegate, InvalidTransitionBehaviour, EvidenceRequired.
Current at retest: N/A — no operational artefact held
OperationalClosureEvidence held: NONE
Required for retest / closure: SUFFICIENT_FOR_RETEST / SUFFICIENT_FOR_CLOSURE
Gap: Real named assignments for BusinessProductOwner, LocationSteward, FederationMappingSteward, RuleOwner, IntegrationOwner, OperationalSupportOwner, ChangeAdoptionOwner — each Assigned, Authorized, Available, DelegateDefined, EscalationDefined, with capacity and SoD tested.
Current at retest: N/A — no operational artefact held
OperationalClosureEvidence held: NONE
Required for retest / closure: SUFFICIENT_FOR_RETEST / SUFFICIENT_FOR_CLOSURE
Gap: Per material CA-04 item: RecordClass, DataClassification, PersonalDataRequirement, MinimumAttribute, RetentionBasis, AccessScope, EvidenceRef.
Current at retest: N/A — no operational artefact held
OperationalClosureEvidence held: NONE
Required for retest / closure: SUFFICIENT_FOR_RETEST / SUFFICIENT_FOR_CLOSURE
Gap: A competent election of PATH_A_REAL_PARTICIPATION or PATH_B_FORMAL_RESCOPE. Path B must record DecisionAuthority, Reason, PilotEvidenceLost, ResidualRisk, Phase7Impact.
Current at retest: N/A — no operational artefact held
OperationalClosureEvidence held: NONE
Required for retest / closure: SUFFICIENT_FOR_RETEST / SUFFICIENT_FOR_CLOSURE
Gap: Named L1/L2/L3 ownership plus evidence-qualified execution of drills S-01…S-06 resolved without the design team acting as hidden support authority.
Current at retest: N/A — no operational artefact held
OperationalClosureEvidence held: NONE
Required for retest / closure: SUFFICIENT_FOR_RETEST / SUFFICIENT_FOR_CLOSURE
Gap: Field evidence for the 10 BC-08 acceptance conditions: RealWorkfront, RealLocation, RealWorkDemand, Crew, Equipment, Materials, FieldOwner, ExecutionWindow, SIMOPSContext, FieldPrerequisites.
Current at retest: N/A — no operational artefact held
OperationalClosureEvidence held: NONE
Required for retest / closure: SUFFICIENT_FOR_RETEST / SUFFICIENT_FOR_CLOSURE
Gap: Per metric progression DEFINED → SOURCE_CONFIRMED → OWNER_CONFIRMED → COLLECTION_READY → COLLECTING → BASELINE_ESTABLISHED, with a real uncontaminated prospective collection period.
Current at retest: N/A — no operational artefact held
J · BC-09 anti-contamination status
BC09 protection
ACTIVE
Pilot exposure
PROHIBITED
Contamination event
NONE RECORDED
Prospective collection
NOT_STARTED
Every proposed action is assessed as NON_INTRUSIVE_PREPARATION or PILOT_INTERVENTION. If an action can materially change the current way of working, AllowedBeforeBaseline = NO.
BC-09 is time-irreversible. If contamination occurs a BC09_CONTAMINATION_EVENT must be raised and the baseline must NOT be retrospectively repaired.
K · Targeted retest queue
A blocker receiving new evidence triggers a targeted retest of that blocker only — never a Mesa-wide rerun. Retest requires EvidenceQuality ≥ SUFFICIENT_FOR_RETEST.
Original HOLD: Participation modes, federation keys and fail-closed interface behaviour defined at Phase 5 (ADR-13/ADR-15/ADR-17).
External action required: Per source/object: SystemOwner, ParticipationMode, InterfaceMechanism, Authentication, Read/Write/Snapshot authority, VersionBehaviour, FailureBehaviour.
Evidence received / assessment: NONE_RECEIVED · NOT_PERFORMED — no artefact submitted
Trigger: EvidenceQuality(BC-01) >= SUFFICIENT_FOR_RETEST
Scope: Targeted to BC-01 only — no Mesa-wide rerun.
Original HOLD: ABAC authority resolution and fail-closed denial designed and prototype-demonstrated.
External action required: Real Pilot IAM test population IAM-01…IAM-06 evidencing RealIdentity, Authentication, RoleResolution, AuthorityScope, Delegation, Revocation/denial.
Evidence received / assessment: NONE_RECEIVED · NOT_PERFORMED — no artefact submitted
Trigger: EvidenceQuality(BC-02) >= SUFFICIENT_FOR_RETEST
Scope: Targeted to BC-02 only — no Mesa-wide rerun.
Original HOLD: CV-07 state model, transitions and invalid-transition fail-closed behaviour defined.
External action required: Competent decision artefact naming LifecycleOwner, AllowedState, AllowedTransition, TransitionAuthority, Delegate, InvalidTransitionBehaviour, EvidenceRequired.
Evidence received / assessment: NONE_RECEIVED · NOT_PERFORMED — no artefact submitted
Trigger: EvidenceQuality(BC-03) >= SUFFICIENT_FOR_RETEST
Scope: Targeted to BC-03 only — no Mesa-wide rerun.
Original HOLD: GOVERNANCE_DESIGN_STRUCTURALLY_SOUND — 7 governance functions, decision rights, vacancy fail-closed behaviour defined.
External action required: Real named assignments for BusinessProductOwner, LocationSteward, FederationMappingSteward, RuleOwner, IntegrationOwner, OperationalSupportOwner, ChangeAdoptionOwner — each Assigned, Authorized, Available, DelegateDefined, EscalationDefined, with capacity and SoD tested.
Evidence received / assessment: NONE_RECEIVED · NOT_PERFORMED — no artefact submitted
Trigger: EvidenceQuality(BC-04) >= SUFFICIENT_FOR_RETEST
Scope: Targeted to BC-04 only — no Mesa-wide rerun.
Original HOLD: CA-04 record classes and minimum-attribute model defined; data minimisation designed in.
External action required: Per material CA-04 item: RecordClass, DataClassification, PersonalDataRequirement, MinimumAttribute, RetentionBasis, AccessScope, EvidenceRef.
Evidence received / assessment: NONE_RECEIVED · NOT_PERFORMED — no artefact submitted
Trigger: EvidenceQuality(BC-05) >= SUFFICIENT_FOR_RETEST
Scope: Targeted to BC-05 only — no Mesa-wide rerun.
Original HOLD: Critical Control non-compensable gating designed; currently SIMULATED in prototype — simulation is not closure evidence.
External action required: A competent election of PATH_A_REAL_PARTICIPATION or PATH_B_FORMAL_RESCOPE. Path B must record DecisionAuthority, Reason, PilotEvidenceLost, ResidualRisk, Phase7Impact.
Evidence received / assessment: NONE_RECEIVED · NOT_PERFORMED — no artefact submitted
Trigger: EvidenceQuality(BC-06) >= SUFFICIENT_FOR_RETEST
Scope: Targeted to BC-06 only — no Mesa-wide rerun.
Original HOLD: L1/L2/L3 support model and six drill scenarios S-01…S-06 defined.
External action required: Named L1/L2/L3 ownership plus evidence-qualified execution of drills S-01…S-06 resolved without the design team acting as hidden support authority.
Evidence received / assessment: NONE_RECEIVED · NOT_PERFORMED — no artefact submitted
Trigger: EvidenceQuality(BC-07) >= SUFFICIENT_FOR_RETEST
Scope: Targeted to BC-07 only — no Mesa-wide rerun.
Original HOLD: FIELD_AND_MEASUREMENT_DESIGN_STRUCTURALLY_SOUND — 17 non-compensable prerequisite domains and 10 acceptance conditions defined.
External action required: Field evidence for the 10 BC-08 acceptance conditions: RealWorkfront, RealLocation, RealWorkDemand, Crew, Equipment, Materials, FieldOwner, ExecutionWindow, SIMOPSContext, FieldPrerequisites.
Evidence received / assessment: NONE_RECEIVED · NOT_PERFORMED — no artefact submitted
Trigger: EvidenceQuality(BC-08) >= SUFFICIENT_FOR_RETEST
Scope: Targeted to BC-08 only — no Mesa-wide rerun.
Original HOLD: 12 BEFORE metrics FROZEN and DEFINED; measurement event model and attribution rules defined.
External action required: Per metric progression DEFINED → SOURCE_CONFIRMED → OWNER_CONFIRMED → COLLECTION_READY → COLLECTING → BASELINE_ESTABLISHED, with a real uncontaminated prospective collection period.
Evidence received / assessment: NONE_RECEIVED · NOT_PERFORMED — no artefact submitted
Trigger: EvidenceQuality(BC-09) >= SUFFICIENT_FOR_RETEST
Scope: Targeted to BC-09 only — no Mesa-wide rerun.
L · Targeted retest results
Targeted retests completed
0
Queue
EMPTY — no eligible blocker
Queue empty at workstream creation. No targeted retest has been performed because no blocker holds EvidenceQuality >= SUFFICIENT_FOR_RETEST. This is a correct starting condition, not a failure.
Record fields to be captured per retest: Retest_ID · Blocker · OriginalCondition · NewEvidence · AcceptanceCriterion · TestPerformed · ObservedResult · FailureBehaviourChecked · SideEffect · ResidualDependency · RetestDisposition
M · Contradiction register
New evidence contradicting the accepted design is never silently reconciled. A CONTRADICTION_ID is raised and dispositioned as Evidence defect, Local exception, Configuration correction or Architecture impact. Architecture may only reopen when the contradiction is material.
Fields captured per contradiction: CONTRADICTION_ID · DesignAssumption · ObservedEvidence · AffectedBlocker · ArchitectureImpact · OperationalImpact · CompetentAuthority · RequiredDisposition
N · Escalation register
Subject: Stewardship and support ownership not yet assigned
Competent authority: Business Product Owner / Project Management
Consequence if unresolved: Mesa 2 cannot progress beyond DesignEvidence; support drills cannot be evidence-qualified.
Subject: Enterprise source participation and IAM owners not yet engaged
Competent authority: Enterprise Architecture / IAM / Cyber
Consequence if unresolved: CV-07 cannot resolve RealIdentity → AuthorizedRole → AuthoritativeObject → GovernedLifecycle.
Subject: Critical Control path election outstanding
Competent authority: Critical Control Owner with ES&H
Consequence if unresolved: The highest-severity non-compensable gate remains SIMULATED; Path B must not be chosen for convenience.
Subject: Time-irreversible prospective BEFORE baseline not started
Competent authority: Measurement Owner / Assurance
Consequence if unresolved: Every day without prospective collection is permanently unrecoverable; PilotExposure must remain PROHIBITED.
O · Integrated Phase 6A evidence dashboard
Total blockers
9
Closed
0
Closed with control
0
Rescoped
0
Open
9
Evidence NONE
9
Evidence PARTIAL
0
Eligible for retest
0
Sufficient for closure
0
Retests completed
0
External dependencies
9
Active escalations
4
Evidence requests issued
24
BC09 protection
ACTIVE
Pilot exposure
PROHIBITED
No aggregate percentage readiness is published and none may be used to authorize Phase 6B. Closure is per-blocker and non-compensable.
P · Full Phase 6A revalidation eligibility
Phase 6A is not rerun automatically when individual blockers close. Full integrated revalidation becomes eligible only when all five conditions below are met simultaneously.
Criterion: Every mandatory blocker is CLOSED, CLOSED_WITH_CONTROL or formally RESCOPED_BY_COMPETENT_AUTHORITY.
Detail: 0/9 — all nine REMAINS_OPEN.
Criterion: No unresolved material contradiction exists.
Detail: Contradiction register empty — based on the current evidence set.
Criterion: BC-09 prospective baseline protection has been preserved.
Detail: BC09Protection ACTIVE, PilotExposure PROHIBITED, no contamination event.
Criterion: All cross-Mesa execution dependencies are compatible.
Detail: 9 dependency edges unresolved pending evidence in Lanes 1–5.
Criterion: Pilot baseline remains materially intact.
Detail: No Pilot exposure has occurred; the current way of working is unaltered.
Final disposition
Progress manufactured: NONE — no OperationalClosureEvidence has been supplied by any competent owner.
Authorized activity: Evidence acquisition and targeted blocker closure only. Phase 6B is not commenced. Phase 7 is not initiated. Architecture is not reopened.
Closure disposition rule: CLOSED_WITH_CONTROL must identify Control, Owner, Validity, ResidualRisk and Escalation. It is not a convenience mechanism to reduce the blocker count.