Phase 6A — Mesa 1 · Enterprise Enablement Closure
Acquire, assess and qualify OperationalClosureEvidence for Mesa 1 only. DesignEvidence must never be converted into closure evidence.
- No architecture redesign.
- No Phase 6B Pilot execution.
- No full Phase 6A rerun.
Execution rule: OriginalHOLD → RequiredExternalAction → EvidenceRequest → EvidenceReceived → EvidenceQualityAssessment → TargetedRetestEligibility → ClosureDisposition.
Quality scale: NONE · PARTIAL · SUFFICIENT_FOR_RETEST · SUFFICIENT_FOR_CLOSURE — Targeted retest is permitted only when EvidenceQuality >= SUFFICIENT_FOR_RETEST.
A · Mesa 1 evidence acquisition dashboard
5
Blockers in scope
0
Individually dispositioned
0
CLOSED
0
CLOSED_WITH_CONTROL
0
FORMALLY_RESCOPED
5
REMAINS_OPEN
24
Evidence requests issued
0
Evidence items received
5
EvidenceQuality = NONE
0
Retest eligible
11
Competent owner groups
Mesa 1 is in evidence acquisition. Zero OperationalClosureEvidence artefacts have been received from any competent owner; no blocker is individually dispositioned, therefore ENTERPRISE_ENABLEMENT_READY may not be recommended.
B · Owner-based evidence request pack
Enterprise Architecture
2 requestsOwns Option C federation boundaries, object authority matrix and drift classification.
System/Object: Federation boundary — 22 object classes / source-of-truth matrix
CompetentOwner: Enterprise Architecture
WhyRequired: Interface validation cannot be assessed unless each source system's authoritative object set is confirmed by the architecture authority against the frozen Phase 5 matrix.
RequiredEvidence: Countersigned object authority confirmation per source system (Q4, Aconex, P6, Smart Completions, Critical Control, HR/Training/Health), stating mastership, read scope and write boundary.
AcceptableEvidenceForm: Signed architecture confirmation record with system owner countersignature and date.
Dependency: Requires each system owner (ER-Q4-01, ER-AC-01, ER-P6-01, ER-SC-01, ER-CC-01, ER-HR-01) to respond first.
BlockingImpact: Without it, BC-01 stays REMAINS_OPEN and no interface may be declared VALIDATED.
RetestTrigger: Receipt of countersigned matrix for all six participating source systems.
System/Object: ADR-15 / ADR-17 — JobCard and TemporaryModification lifecycle authority
CompetentOwner: Enterprise Architecture (with Operational Lifecycle Authority)
WhyRequired: Pilot lifecycle authority for JobCard and TempMod remains undetermined; the readiness layer must not assume authority it has not been granted.
RequiredEvidence: Architecture determination record naming the mastering system and the authorized transition set for the Pilot window.
AcceptableEvidenceForm: ADR supplement or architecture decision record, signed, referencing ADR-15 and ADR-17.
Dependency: Requires ER-OLA-01 operational concurrence.
BlockingImpact: BC-03 remains open; JobCard/TempMod transitions stay fail-closed DISABLED_SAFE.
RetestTrigger: Signed lifecycle authority determination received.
IT / IM
2 requestsOwns connectivity, environments, transport and integration runtime for the Pilot window.
System/Object: Pilot integration environment (non-production endpoints, network path, credentials custody)
CompetentOwner: IT / IM
WhyRequired: No interface may be validated without a reachable, owner-approved endpoint in a governed environment.
RequiredEvidence: Environment provisioning record per system: endpoint, protocol, auth mechanism, rate limits, availability window, support contact.
AcceptableEvidenceForm: Provisioning ticket closure record plus connectivity test log with timestamps.
Dependency: Depends on each system owner authorizing access.
BlockingImpact: Interface validation cannot commence; BC-01 blocked at the first step.
RetestTrigger: Connectivity test log demonstrating a successful authenticated round trip per system.
System/Object: Interface behaviour under degradation (timeout, partial payload, source unavailable)
CompetentOwner: IT / IM
WhyRequired: Fail-closed behaviour must be evidenced against real endpoints, not the prototype adapter, before any Pilot journey depends on it.
RequiredEvidence: Degradation test results per interface: latency profile, error codes, staleness signalling.
AcceptableEvidenceForm: Test execution report with raw request/response traces.
Dependency: ER-IT-01.
BlockingImpact: Readiness verdicts could be computed on stale source data without detection.
RetestTrigger: Degradation report available for all validated interfaces.
IAM / Cyber
3 requestsOwns enterprise identity, role mapping, authorization enforcement and audit attribution.
System/Object: Enterprise identity provider — actor mapping for the six Pilot actor classes
CompetentOwner: IAM / Cyber
WhyRequired: Every authorization and confirmation must be attributable to a real enterprise identity; prototype session identity is not attribution.
RequiredEvidence: Identity mapping record for all six actor classes (Supervisor, Permit Authority, Discipline Lead, Steward, Field Executor, Read-only) with entitlement source and revocation path.
AcceptableEvidenceForm: IdP configuration export plus signed entitlement mapping.
Dependency: Requires HR/RRLL competency source (ER-HR-01) for competency-linked entitlements.
BlockingImpact: BC-02 remains open; all authority-gated actions stay UNRESOLVED and fail-closed.
RetestTrigger: Signed mapping for all six actor classes received.
System/Object: Authorization enforcement tests (positive and negative) per actor class
CompetentOwner: IAM / Cyber
WhyRequired: Denial behaviour must be evidenced with real identities, including delegation and revocation.
RequiredEvidence: Executed test matrix: 6 actor classes × (grant, deny, delegate, revoke) with audit-log evidence.
AcceptableEvidenceForm: Test report with audit log extracts showing actor, action, decision and timestamp.
Dependency: ER-IAM-01.
BlockingImpact: Authority gating cannot be certified; Pilot confirmations would be non-attributable.
RetestTrigger: Full 6 × 4 enforcement matrix executed and reported.
System/Object: Offline authorization posture
CompetentOwner: IAM / Cyber
WhyRequired: The invariant OFFLINE DOES NOT AUTHORIZE must be enforced by enterprise identity policy, not only by application logic.
RequiredEvidence: Policy statement and technical control confirming no offline token grants authorization capability.
AcceptableEvidenceForm: Signed cyber control statement referencing the applicable policy identifier.
Dependency: None.
BlockingImpact: Residual risk of unattributable offline authorization remains uncontrolled.
RetestTrigger: Signed control statement received.
Q4 System Owner
2 requestsMaster of Safety Documents, Permits, Isolations, Locations and Work Packs.
System/Object: Q4 — Permit, Isolation, Safety Document, Location, Work Pack
CompetentOwner: Q4 System Owner
WhyRequired: Q4 is the authoritative source for the majority of critical enabling conditions; unmapped or unread states must fail closed against real data.
RequiredEvidence: Authorized read scope, complete state vocabulary per object, state-transition semantics, and confirmation of the unmapped-state handling contract.
AcceptableEvidenceForm: System owner data-sharing authorization plus exported state vocabulary/reference data.
Dependency: ER-IT-01 environment access.
BlockingImpact: Critical enabling conditions cannot be sourced; BC-01 blocked for the highest-weight source.
RetestTrigger: Authorized read scope and full state vocabulary received.
System/Object: Q4 — retention and record classification of permit/isolation evidence
CompetentOwner: Q4 System Owner (with Records Authority)
WhyRequired: Decision reconstruction requires that pinned source evidence remains retrievable for the governed retention period.
RequiredEvidence: Retention schedule and immutability statement for the objects referenced by pinned decisions.
AcceptableEvidenceForm: Records-schedule extract countersigned by the Records/Compliance Authority.
Dependency: ER-REC-01.
BlockingImpact: BC-05 remains open; evidence reconstruction cannot be guaranteed.
RetestTrigger: Retention schedule received and countersigned.
Aconex / IM Owner
1 requestsMaster of controlled documents, revisions and transmittals.
System/Object: Aconex — document revision, status, transmittal
CompetentOwner: Aconex / IM Owner
WhyRequired: Document version pinning requires an authoritative, resolvable revision identifier at the moment of decision.
RequiredEvidence: Revision identifier scheme, superseded-revision signalling, and API read authorization.
AcceptableEvidenceForm: IM owner authorization plus interface specification with sample payloads.
Dependency: ER-IT-01.
BlockingImpact: Pinned document evidence could silently reference a superseded revision.
RetestTrigger: Revision scheme documented and read access authorized.
P6 / Project Controls System Owner
1 requestsMaster of schedule activities, lookahead and sequence logic.
System/Object: P6 — activity, lookahead window, predecessor logic
CompetentOwner: P6 / Project Controls System Owner
WhyRequired: Forecast readiness and lookahead composition depend on authoritative schedule data with a known refresh cadence.
RequiredEvidence: Authorized read scope, refresh cadence, activity-to-JobCard correlation key, and data currency guarantee.
AcceptableEvidenceForm: System owner authorization plus extract specification and cadence statement.
Dependency: ER-IT-01; correlation key must reconcile with ER-EA-01.
BlockingImpact: Lookahead and forecast readiness cannot be sourced from authoritative schedule data.
RetestTrigger: Authorized read scope and correlation key confirmed.
Smart Completions Owner
1 requestsMaster of completion/commissioning system objects and turnover state.
System/Object: Smart Completions — system/subsystem, ITR, punch, turnover state
CompetentOwner: Smart Completions Owner
WhyRequired: Commissioning-phase readiness and discipline continuity depend on authoritative completion state.
RequiredEvidence: Authorized read scope, object state vocabulary and system/subsystem to Location correlation.
AcceptableEvidenceForm: System owner authorization plus reference data export.
Dependency: ER-IT-01; Location correlation depends on ER-Q4-01.
BlockingImpact: Commissioning readiness dimension remains unsourced.
RetestTrigger: Read scope authorized and correlation confirmed.
Critical Control / Forwood Owner
2 requestsMaster of life-critical control verification records.
System/Object: Critical Control participation decision — Path A or Path B
CompetentOwner: Critical Control / Forwood Owner (with Pilot Authority)
WhyRequired: Critical Control remains SIMULATED. A competent authority must elect Path A (real participation) or Path B (formal rescope); the choice may not be made to facilitate closure.
RequiredEvidence: Path A: participation authorization, read scope and verification-record contract. Path B: formal rescope record capturing DecisionAuthority, Reason, PilotEvidenceLost, ResidualRisk, Phase7Impact.
AcceptableEvidenceForm: Signed decision record from the accountable Critical Control authority.
Dependency: Path A additionally depends on ER-IT-01 and ER-IAM-01.
BlockingImpact: BC-06 remains open. Life-critical journeys cannot be executed with real verification, and Phase 6 acceptance would carry a non-evidenced life-critical dimension.
RetestTrigger: Signed Path A authorization, or a complete five-field Path B rescope record (which closes as FORMALLY_RESCOPED, not CLOSED).
System/Object: Critical Control — verification record interface (Path A only)
CompetentOwner: Critical Control / Forwood Owner
WhyRequired: If Path A is elected, the verification interface must be validated like any other participating source.
RequiredEvidence: Interface specification, currency guarantee and failure semantics for verification records.
AcceptableEvidenceForm: Interface specification plus connectivity and degradation test log.
Dependency: Conditional on ER-CC-01 electing Path A.
BlockingImpact: If Path A is elected without this, BC-01 cannot be completed.
RetestTrigger: Path A elected and interface validation log received.
HR / RRLL / Training / Health Owners
2 requestsMaster of person, competency, certification validity and fitness-for-duty state.
System/Object: Competency, certification expiry and fitness-for-duty records
CompetentOwner: HR / RRLL / Training / Health Owners
WhyRequired: Competency expiry is a critical non-compensable condition; it must be sourced authoritatively with a known validity horizon.
RequiredEvidence: Authorized read scope, person correlation key, competency taxonomy, expiry semantics, and personal-data handling authorization.
AcceptableEvidenceForm: Data-sharing authorization (including privacy approval) plus interface specification.
Dependency: Privacy approval depends on ER-REC-01; identity correlation depends on ER-IAM-01.
BlockingImpact: Competency-driven HOLD verdicts cannot be evidenced from authoritative data.
RetestTrigger: Data-sharing authorization and taxonomy received.
System/Object: Personal-data retention and minimisation for pinned competency evidence
CompetentOwner: HR / Health Owners (with Records Authority)
WhyRequired: Pinned decision evidence may embed personal data; retention must be governed and minimised to what reconstruction requires.
RequiredEvidence: Retention determination and minimisation rule for competency attributes held in decision pins.
AcceptableEvidenceForm: Signed privacy/records determination.
Dependency: ER-REC-01.
BlockingImpact: BC-05 remains open for the personal-data class.
RetestTrigger: Signed determination received.
Operational Lifecycle Authority
2 requestsAccountable for the operational validity of JobCard and TemporaryModification lifecycles in the Pilot.
System/Object: JobCard lifecycle — authorized transitions during the Pilot window
CompetentOwner: Operational Lifecycle Authority
WhyRequired: ADR-15 leaves JobCard authority undetermined; without an operational owner the readiness layer must remain fail-closed.
RequiredEvidence: Determination of mastering system, authorized transition set, and the accountable operational role.
AcceptableEvidenceForm: Signed operational determination referencing ADR-15.
Dependency: Concurrence with ER-EA-02.
BlockingImpact: JobCard lifecycle stays DISABLED_SAFE; Pilot journeys depending on transitions cannot run.
RetestTrigger: Signed determination received.
System/Object: TemporaryModification lifecycle — authority, expiry and reversion control
CompetentOwner: Operational Lifecycle Authority
WhyRequired: ADR-17 requires an accountable owner for temporary modification validity and forced reversion.
RequiredEvidence: Determination of authority, maximum validity period, expiry handling and reversion evidence requirement.
AcceptableEvidenceForm: Signed operational determination referencing ADR-17.
Dependency: ER-EA-02.
BlockingImpact: TempMod-dependent readiness cannot be authorized.
RetestTrigger: Signed determination received.
Records / Compliance / Governance Authority
2 requestsOwns CA-04 governed classification, retention and evidence reconstruction obligations.
System/Object: CA-04 — classification of readiness decision records
CompetentOwner: Records / Compliance / Governance Authority
WhyRequired: The record class of a readiness decision (and its pinned evidence) determines retention, immutability and disclosure obligations. It is currently undetermined.
RequiredEvidence: Formal classification determination for: readiness decision, pinned evidence set, human confirmation record, authority delegation record, and offline reconciliation record.
AcceptableEvidenceForm: Signed records classification determination with retention periods.
Dependency: None — this is the head dependency for ER-Q4-02 and ER-HR-02.
BlockingImpact: BC-05 remains open; decision reconstruction obligations are undefined.
RetestTrigger: Signed classification determination covering all five record types.
System/Object: Evidence reconstruction obligation and audit access
CompetentOwner: Records / Compliance / Governance Authority
WhyRequired: The Pilot must be able to reconstruct any decision exactly as taken, including source states at pin time.
RequiredEvidence: Reconstruction requirement statement, audit access model and permitted retention location.
AcceptableEvidenceForm: Signed governance statement.
Dependency: ER-REC-01.
BlockingImpact: Audit reconstruction cannot be certified for the Pilot.
RetestTrigger: Signed statement received.
C · BC-01…BC-06 evidence status register
OriginalHOLD: 0 of 9 source-system validation records exist; all participating systems are NOT_CONNECTED or SIMULATED.
RequiredExternalAction: System owners authorize read scope and IT/IM provisions governed endpoints; each interface is validated for content, currency and degradation behaviour.
EvidenceRequests: ER-EA-01 · ER-IT-01 · ER-IT-02 · ER-Q4-01 · ER-AC-01 · ER-P6-01 · ER-SC-01 · ER-CC-02 · ER-HR-01
EvidenceReceived: None. No system owner has returned an authorization, specification or test log.
DesignEvidence (non-closing): Adapter contracts, fail-closed handling of unmapped states, staleness signalling — demonstrated at prototype level only (FT-01, FT-02).
OperationalClosureEvidence: None.
TargetedRetestEligibility: NOT ELIGIBLE — EvidenceQuality = NONE (< SUFFICIENT_FOR_RETEST).
TargetClosureState: CLOSED when every participating interface holds a validation record; CLOSED_WITH_CONTROL if a non-critical source is formally deferred with a compensating manual control.
OriginalHOLD: 0 of 6 actor-class enforcement tests executed against enterprise identity; authority remains UNRESOLVED.
RequiredExternalAction: IAM/Cyber maps the six Pilot actor classes to enterprise identities and executes grant/deny/delegate/revoke enforcement tests with audit evidence.
EvidenceRequests: ER-IAM-01 · ER-IAM-02 · ER-IAM-03
EvidenceReceived: None.
DesignEvidence (non-closing): Prototype denial behaviour and UNRESOLVED fail-closed gating (FT-03).
OperationalClosureEvidence: None.
TargetedRetestEligibility: NOT ELIGIBLE — EvidenceQuality = NONE.
TargetClosureState: CLOSED when all six actor classes are mapped and the 6 × 4 enforcement matrix passes with audit attribution.
OriginalHOLD: 0 lifecycle determinations; JobCard and TemporaryModification authority undetermined, dependent capability DISABLED_SAFE.
RequiredExternalAction: Operational Lifecycle Authority and Enterprise Architecture jointly determine mastering system, authorized transitions, validity and reversion control.
EvidenceRequests: ER-EA-02 · ER-OLA-01 · ER-OLA-02
EvidenceReceived: None.
DesignEvidence (non-closing): Fail-closed DISABLED_SAFE behaviour when authority is undetermined.
OperationalClosureEvidence: None.
TargetedRetestEligibility: NOT ELIGIBLE — EvidenceQuality = NONE. Note: this blocker is closable by decision artefacts alone, with no integration dependency, and is therefore the lowest-friction Mesa 1 candidate.
TargetClosureState: CLOSED when both determinations are signed; CLOSED_WITH_CONTROL if TempMod is excluded from the Pilot with a recorded scope control.
OriginalHOLD: 0 classification determinations; record class, retention and reconstruction obligations undefined.
RequiredExternalAction: Records/Compliance/Governance Authority classifies the five decision-record types and states retention, immutability and audit access.
EvidenceRequests: ER-REC-01 · ER-REC-02 · ER-Q4-02 · ER-HR-02
EvidenceReceived: None.
DesignEvidence (non-closing): Decision pinning and evidence-set reconstruction implemented in the prototype engine.
OperationalClosureEvidence: None.
TargetedRetestEligibility: NOT ELIGIBLE — EvidenceQuality = NONE.
TargetClosureState: CLOSED when all five record types are classified with retention periods and an audit access model.
OriginalHOLD: Critical Control remains SIMULATED; no Path A / Path B election has been made by a competent authority.
RequiredExternalAction: Critical Control / Forwood Owner with Pilot Authority elects Path A (real participation) or Path B (formal rescope with the five mandatory fields).
EvidenceRequests: ER-CC-01 · ER-CC-02
EvidenceReceived: None.
DesignEvidence (non-closing): Life-critical conditions modelled as non-compensable; simulated source flagged as SIMULATED, never as verified.
OperationalClosureEvidence: None.
TargetedRetestEligibility: PARTIALLY RETESTABLE ON DECISION ALONE — a Path B election requires no integration evidence, but Path B must not be chosen to facilitate closure and results in FORMALLY_RESCOPED with recorded PilotEvidenceLost.
TargetClosureState: CLOSED via Path A (participation authorized and interface validated) or FORMALLY_RESCOPED via Path B with the five-field record.
D · Cross-blocker dependency register
DEP-01 — BC-01 (all interfaces) → depends on BC-02 (enterprise identity)
Nature: Authenticated, attributable access
Effect: Interface validation performed with unattributable service identity cannot support authorization evidence later.
DEP-02 — BC-01 (Critical Control interface, ER-CC-02) → depends on BC-06 (Path A election)
Nature: Conditional scope
Effect: If Path B is elected, ER-CC-02 is withdrawn and BC-01 scope reduces by one source — recorded as evidence lost, not as closure.
DEP-03 — BC-05 (Q4 and HR retention) → depends on BC-05 head determination (ER-REC-01)
Nature: Head-of-chain classification
Effect: Source-level retention statements are unassessable until the record class is determined.
DEP-04 — BC-01 (HR competency source) → depends on BC-05 (personal-data determination)
Nature: Privacy authorization
Effect: Competency data cannot be lawfully pinned into decision evidence before minimisation and retention are determined.
DEP-05 — BC-03 (lifecycle authority) → depends on BC-02 (actor classes)
Nature: Role attribution
Effect: An authorized transition set is meaningless unless the transitions can be bound to an accountable enterprise identity.
DEP-06 — BC-01 (P6 / Smart Completions correlation) → depends on ER-EA-01 object authority confirmation
Nature: Correlation key integrity
Effect: Without a confirmed correlation key, cross-source composition could bind the wrong Location or JobCard context.
DEP-07 — Mesa 1 as a whole → depends on Mesa 2 (BC-04 stewardship)
Nature: External to Mesa 1 scope
Effect: Several determinations require a named steward to receive and maintain them. Mesa 1 evidence may be acquired, but sustained ownership remains a Mesa 2 dependency and is not closed here.
E · Retest eligibility queue
- BC-03 — closable by two signed determinations with no integration dependency; becomes retest-eligible on receipt of ER-OLA-01 and ER-EA-02.
- BC-05 — closable by ER-REC-01 alone reaching PARTIAL, and by ER-REC-01 + ER-REC-02 reaching SUFFICIENT_FOR_RETEST.
- BC-06 — a Path B election alone would move the blocker to FORMALLY_RESCOPED without integration evidence; permitted only on competent authority, never for convenience.
Rule: OriginalHOLD → ExternalAction → EvidenceReceived → EvidenceAssessment → TargetedRetest → ClosureDisposition. Individual submissions never trigger a full Phase 6A rerun.
F · Escalation register
Trigger: No source system owner has authorized read scope or provisioned an endpoint.
EscalateTo: Project Director / Enterprise Architecture Board
Reason: Interface validation is the widest blocker (9 evidence requests, 6 owner organizations) and has the longest lead time; it governs the Mesa 1 critical path.
ConsequenceIfUnresolved: Mesa 1 cannot progress; Phase 6A remains HOLD indefinitely.
Trigger: IAM / Cyber has not accepted ownership of Pilot actor-class mapping.
EscalateTo: CISO / IAM Governance Board
Reason: Without enterprise identity, no Pilot confirmation is attributable and no authorization is defensible.
ConsequenceIfUnresolved: All authority-gated Pilot journeys stay fail-closed; Phase 6B cannot execute.
Trigger: No Path A / Path B election for Critical Control participation.
EscalateTo: Operations / HSE Accountable Executive
Reason: An unelected path leaves the life-critical dimension neither validated nor formally rescoped — the least defensible of the two allowed outcomes.
ConsequenceIfUnresolved: Phase 6 acceptance would carry an unresolved life-critical evidence gap.
Trigger: Records / Compliance Authority not engaged on CA-04 classification.
EscalateTo: Records & Compliance Governance Authority
Reason: ER-REC-01 is the head dependency for three further evidence items across two source domains.
ConsequenceIfUnresolved: Retention and reconstruction obligations remain undefined; audit defensibility unproven.
Trigger: No named operational owner for JobCard / TemporaryModification lifecycle.
EscalateTo: Operational Lifecycle Authority / Construction Manager
Reason: This is the lowest-cost Mesa 1 closure (decision artefacts only) yet remains open; continued delay indicates an accountability gap, not a technical one.
ConsequenceIfUnresolved: Lifecycle-dependent capability remains DISABLED_SAFE throughout the Pilot.
G · Mesa 1 current disposition
- 0 of 5 Mesa 1 blockers individually dispositioned.
- 0 OperationalClosureEvidence artefacts received across 24 issued evidence requests.
- EvidenceQuality = NONE for all five blockers; retest threshold (SUFFICIENT_FOR_RETEST) not reached by any.
- DesignEvidence exists for BC-01, BC-02, BC-03 and BC-06 but is explicitly not convertible into closure evidence.
Prohibition: ENTERPRISE_ENABLEMENT_READY may not be recommended until all five blockers are individually dispositioned as CLOSED, CLOSED_WITH_CONTROL or competently FORMALLY_RESCOPED.
AuthorizedNext: Issue the owner-based evidence pack to the eleven competent owner groups and acquire OperationalClosureEvidence. No Phase 6B execution, no architecture redesign, no full Phase 6A rerun.
PHASE 6A = HOLD · PHASE 6B = NOT AUTHORIZED · PHASE 7 = NO_GO.