Phase 6A — Mesa 1 · Targeted Correction & Execution Reframe
- Correct one authority wording (Location).
- Restructure evidence acquisition into three parallel lanes.
- Update the Mesa 1 closure / dependency / retest registers accordingly.
- No architecture reopening — no structural contradiction was identified.
- No complete Mesa 1 re-assessment.
- No simulated evidence; no blocker closure without new OperationalClosureEvidence.
- No Mesa 2, no Mesa 3, no Phase 6A rerun, no Phase 6B commencement.
A · Corrected executive summary
ENTERPRISE_ENABLEMENT_HOLD
Status
NONE
EvidenceQuality
0 / 5
RetestEligibility
Unchanged closure state:
- BC-01 REMAINS_OPEN — enterprise interface validation not evidenced.
- BC-02 REMAINS_OPEN — enterprise IAM identity / role / authority enforcement not evidenced.
- BC-03 REMAINS_OPEN — ADR-15 / ADR-17 Pilot lifecycle authority artefact not issued.
- BC-05 REMAINS_OPEN — CA-04 classification / retention decisions not taken.
- BC-06 REMAINS_OPEN — no formal Path A / Path B election.
Corrected by this action:
- Location authority wording restated to ADR-14 Option C (Federated Canonical Location Register); Q4 is no longer implied to be canonical Location master.
- Execution reframed from ID-sequential to three parallel lanes (A Identity & Participation, B Governance Decision Artefacts, C Critical Control Path).
- Pilot integration maturity redefined as sufficiency for decision integrity and evidence, not maximal technical sophistication (MinimumViableParticipationForPilot).
- Dependency register now distinguishes CAN_DESIGN_OR_CLOSE_GOVERNANCE from CAN_EXECUTE_OPERATIONALLY, so dependency is not misread as failure.
MaterialChangeToClosure: NONE. No OperationalClosureEvidence has been received from any competent owner; the reframe changes the execution path only, never the closure state.
Mesa 1 remains ENTERPRISE_ENABLEMENT_HOLD. The binding constraint is unresolved external governance and accountability — authorized source participation, enforceable identity, named lifecycle authority, competent classification, and an elected Critical Control path — none of which the readiness layer may self-certify.
B · Corrected Location authority statement
SUPERSEDED: “Location authoritative in Q4” as a blanket / enterprise-level authority conclusion.
CORRECTED WORDINGQ4 holds the referenced operational Location object for the Pilot scenario where evidenced; canonical / enterprise Location identity and stewardship remain governed under ADR-14 Option C — Federated Canonical Location Register with explicit enterprise stewardship.
Rule: Q4 must not become universal or canonical Location master by implication. Where Q4 authority is evidenced, it is recorded at object-class / transaction level only.
Q4 Operational Location Reference
Meaning: The Location identifier as used by Q4 permit / isolation / work instruments for the Pilot scenario.
Authority: Q4 System Owner — operational reference only, scoped to the evidenced object class and transaction.
Status: NOT_AUTHORIZED_YET — read scope unconfirmed (BC-01).
Federated Mapping
Meaning: The governed correspondence between the Q4 operational reference and the canonical Location key.
Authority: Enterprise Architecture with the Location Steward; mapping is itself a governed artefact.
Status: UNRESOLVED — no mapping artefact issued; correlation may not be inferred.
Canonical Location Representation
Meaning: The enterprise canonical Location identity used for cumulative SIMOPS context (CUM-1…CUM-7) and decision pinning.
Authority: Federated Canonical Location Register under ADR-14 Option C. Not Q4.
Status: UNRESOLVED — canonical register instance not designated for Pilot.
Enterprise Location Stewardship
Meaning: Named accountable stewardship for canonical Location identity, hierarchy change and dispute resolution.
Authority: Enterprise Location Steward (role vacant — Mesa 2 dependency, not closable in Mesa 1).
Status: VACANT — fail-closed: no steward ⇒ no canonical Location change authority.
FailClosed: Absent an evidenced mapping to a canonical Location, cumulative SIMOPS evaluation cannot be performed and no READY verdict may be produced (HOLD).
C · Three-lane execution plan
Enterprise Identity & System Participation
BC-02 / GC-02BC-01 / GC-01Objective: Obtain evidence from enterprise IAM and system owners sufficient to validate real Pilot participation of each source.
LeadTime: LONGEST — external enterprise change control, cyber review and system-owner scheduling.
StartPosture: START IMMEDIATELY — critical path for every downstream real-authorization test.
Required focus
- RealPilotIdentity — actual enterprise principals, not scenario personas.
- RoleResolution — enterprise role mapped to readiness authority role.
- AuthorityEnforcement — enforcement demonstrated, not asserted.
- SystemOwnerConfirmation — named owner authorizing Pilot participation.
- ActualParticipationMode — the mechanism actually granted.
- InterfaceMechanism — API / snapshot / governed manual federation.
- Authentication — credential and token governance for the mechanism.
- VersionBehaviour — how document/object versions are pinned and revalidated.
- FailureBehaviour — observed behaviour when the source is unavailable or stale.
Constraints
- Do not infer API capability from product documentation or vendor claims.
- LIVE_READ is not required where a governed CONTROLLED_SNAPSHOT or CONTROLLED_MANUAL_FEDERATION is sufficient for the Pilot decision and evidence model.
- Pilot integration maturity must be sufficient for decision integrity and evidence — not maximized for technical sophistication.
Governance Decision Artefacts
BC-03 / GC-03BC-05 / GC-05Objective: Progress competent governance decisions independently of enterprise integration work, where the decision does not itself require live identity enforcement.
LeadTime: MEDIUM — bounded by decision-authority availability, not by technical delivery.
StartPosture: RUN IN PARALLEL WITH LANE A — must not wait on interface delivery.
Required focus
- BC-03: LifecycleOwner, StateOwner, AllowedTransition, TransitionAuthority, Delegation, EvidenceRequired, InvalidTransitionBehaviour, AuthorityUnavailableBehaviour.
- BC-05: competent classification for every material Pilot requirement, plus DataMinimisation for competency / fitness information used in decision pins.
Constraints
- BC-03 closure for REAL authorization remains dependent on BC-02 where identity enforcement is required; a governance artefact alone may close WITH_CONTROL only.
- CLASSIFICATION_UNRESOLVED must be preserved wherever competent authority has not decided — silence is never a decision.
- Personal information must not be persisted beyond what establishes the decision fact, reconstructs the evidence, and satisfies governed retention.
Critical Control Participation Decision
BC-06Objective: Force a competent, attributable election between Path A (real governed participation) and Path B (formal rescope), without unnecessary delay.
LeadTime: SHORT — the constraint is decision authority, not technical work.
StartPosture: FORCE DECISION EARLY — path selection changes BC-01 required interface scope, so late election wastes Lane A lead time.
Required focus
- Path A: real Critical Control source, authority, verification state and Pilot participation mechanism.
- Path B: DecisionAuthority, Reason, PilotEvidenceLost, ResidualRisk, Phase7Impact — all mandatory.
Constraints
- Path A is preferred wherever reasonably achievable.
- Path B may never be elected merely to reduce blocker count or accelerate Pilot GO.
- Until one path is formally elected, BC-06 = REMAINS_OPEN.
Priority rule: Do not execute blockers sequentially by ID. Run the three lanes in parallel.
Criteria: LeadTime · CrossBlockerDependency · DecisionAuthorityAvailability · EvidenceAvailability
- P1 — BC-01 / BC-02 (Lane A): start immediately; longest external lead time and widest downstream dependency.
- P1 — BC-06 (Lane C): force competent Path A/B election early because it sets BC-01 interface scope.
- P2 — BC-03 (Lane B): pursue lifecycle authority artefact in parallel; may reach SUFFICIENT_FOR_RETEST while BC-02 is open.
- P2 — BC-05 (Lane B): pursue classification / retention decisions in parallel; gated only by Records / Privacy authority availability.
D · Owner-based evidence acquisition pack
Enterprise Architecture
2 requestsOwns federation contracts, canonical identity and minimum viable participation classification.
CompetentOwner: Enterprise Architect (named)
RequiredDecisionOrEvidence: Signed per-source MinimumViableParticipationForPilot classification for all nine Pilot sources.
AcceptableEvidenceForm: Signed architecture decision record with per-source classification and rationale.
WhyRequired: Prevents over-engineering: defines the least mechanism that still satisfies CV-07 decision integrity and evidence reconstruction.
Dependency: Requires BC-06 path election to fix Critical Control scope.
TargetEvidenceQuality: SUFFICIENT_FOR_RETEST
RetestTrigger: Classification signed for all sources in Pilot scope.
BlockingImpact: Without it, interface scope is unbounded and BC-01 cannot be assessed against a target.
CompetentOwner: Enterprise Architect with Location Steward nominee
RequiredDecisionOrEvidence: Federated Location mapping artefact: Q4 operational Location reference → canonical Location key, per ADR-14 Option C.
AcceptableEvidenceForm: Issued mapping specification with governed key set and change control.
WhyRequired: Q4 is not canonical Location master; cumulative SIMOPS evaluation requires an evidenced canonical mapping.
Dependency: Enterprise Location stewardship nomination (Mesa 2) constrains full closure.
TargetEvidenceQuality: PARTIAL until stewardship named
RetestTrigger: Mapping artefact issued and Q4 read scope confirmed.
BlockingImpact: No canonical Location ⇒ no cumulative SIMOPS context ⇒ no READY verdict.
IT / IM
2 requestsOwns interface delivery, environments and snapshot transport controls.
CompetentOwner: IT/IM Integration Lead
RequiredDecisionOrEvidence: Confirmed InterfaceMechanism, Authentication, VersionBehaviour and FailureBehaviour per participating source.
AcceptableEvidenceForm: Interface confirmation record per source, or governed snapshot procedure where snapshot is sufficient.
WhyRequired: Participation must be demonstrated, never inferred from product capability.
Dependency: ER-EA-01 classification; system-owner authorization per source.
TargetEvidenceQuality: SUFFICIENT_FOR_RETEST
RetestTrigger: Mechanism confirmed for every source classified as required for Pilot.
BlockingImpact: BC-01 remains open; readiness computation has no authorized inputs.
CompetentOwner: IT/IM Integration Lead
RequiredDecisionOrEvidence: Observed staleness / unavailability behaviour for each CONTROLLED_SNAPSHOT source (fail-closed proof).
AcceptableEvidenceForm: Test record from the Pilot environment with timestamps and observed verdict.
WhyRequired: Snapshot sufficiency is only acceptable when staleness is governed and fails closed.
Dependency: ER-IT-01.
TargetEvidenceQuality: SUFFICIENT_FOR_CLOSURE
RetestTrigger: Fail-closed behaviour observed with real transport.
BlockingImpact: Unevidenced staleness handling invalidates snapshot-based participation.
IAM / Cyber
2 requestsOwns enterprise identity, role resolution and authority enforcement.
CompetentOwner: Enterprise IAM Owner
RequiredDecisionOrEvidence: RealPilotIdentity set: named enterprise principals provisioned for each Pilot readiness role.
AcceptableEvidenceForm: IAM provisioning record referencing enterprise directory entries.
WhyRequired: Authority cannot be enforced against personas; attribution requires real identity.
Dependency: None — may start immediately.
TargetEvidenceQuality: SUFFICIENT_FOR_RETEST
RetestTrigger: Principals provisioned and role mapping issued.
BlockingImpact: No enforceable authorization anywhere in the Pilot; BC-03 real execution blocked.
CompetentOwner: Enterprise IAM / Cyber Authority
RequiredDecisionOrEvidence: Executed AuthorityEnforcement scenarios with real identities, including denial and delegation-expiry cases.
AcceptableEvidenceForm: Executed test record with identity references and observed enforcement outcome.
WhyRequired: Fail-closed design evidence does not demonstrate enterprise enforcement.
Dependency: ER-IAM-01.
TargetEvidenceQuality: SUFFICIENT_FOR_CLOSURE
RetestTrigger: All six IAM scenarios executed with real principals.
BlockingImpact: BC-02 remains open; BC-03 may close WITH_CONTROL at most.
Q4 System Owner
1 requestsOwns permits, isolations, JHA and the operational Location reference used by the Pilot scenario.
CompetentOwner: Q4 (Engica / TSI) System Owner
RequiredDecisionOrEvidence: SystemOwnerConfirmation of Pilot participation, authorized read scope and object classes exposed — including the operational Location reference at object level only.
AcceptableEvidenceForm: Signed system-owner authorization naming object classes and read scope.
WhyRequired: Q4 authority is recorded per object class; it may not be generalized into canonical Location mastership.
Dependency: ER-EA-02 for canonical mapping.
TargetEvidenceQuality: SUFFICIENT_FOR_RETEST
RetestTrigger: Authorization signed and scope enumerated.
BlockingImpact: Permit/isolation/Location inputs unauthorized ⇒ readiness inputs unusable.
Aconex / IM Owner
1 requestsOwns controlled document identity, revision state and version pinning source.
CompetentOwner: Aconex / Document Control Owner
RequiredDecisionOrEvidence: Confirmed participation mode and VersionBehaviour for pinned document revisions used in decisions.
AcceptableEvidenceForm: Owner confirmation plus revision-pinning procedure reference.
WhyRequired: Decision pins must reference an authoritative revision that can be reconstructed later.
Dependency: ER-EA-01 classification.
TargetEvidenceQuality: SUFFICIENT_FOR_RETEST
RetestTrigger: Participation mode confirmed with revision semantics.
BlockingImpact: Superseded-document detection cannot be evidenced.
P6 / Project Controls Owner
1 requestsOwns schedule activity identity and lookahead horizon data.
CompetentOwner: Project Controls Manager
RequiredDecisionOrEvidence: Participation confirmation and snapshot cadence for lookahead activities in Pilot scope.
AcceptableEvidenceForm: Owner confirmation with governed snapshot cadence and staleness tolerance.
WhyRequired: Preventive lead time depends on a governed, dated schedule reference.
Dependency: ER-IT-02 staleness behaviour.
TargetEvidenceQuality: SUFFICIENT_FOR_RETEST
RetestTrigger: Cadence and tolerance agreed in writing.
BlockingImpact: Forecast horizon unevidenced; preventive value unverifiable.
Smart Completions Owner
1 requestsOwns system/subsystem completion and turnover state.
CompetentOwner: Completions Manager
RequiredDecisionOrEvidence: Participation confirmation and completion-state semantics for Pilot subsystems.
AcceptableEvidenceForm: Owner confirmation with state definition mapping.
WhyRequired: Unmapped completion states must fail closed, not be interpreted by the readiness layer.
Dependency: ER-EA-01.
TargetEvidenceQuality: SUFFICIENT_FOR_RETEST
RetestTrigger: State semantics confirmed by the owner.
BlockingImpact: Commissioning-phase readiness cannot be evaluated.
Critical Control / Forwood Owner
1 requestsOwns critical control verification state and its authority model.
CompetentOwner: Critical Control Authority (named)
RequiredDecisionOrEvidence: Formal election of PATH A (real governed participation) or PATH B (formal rescope), with the full mandatory record.
AcceptableEvidenceForm: Signed decision record. Path A: source, authority, verification state, participation mechanism. Path B: DecisionAuthority, Reason, PilotEvidenceLost, ResidualRisk, Phase7Impact.
WhyRequired: Critical Control is non-compensable; simulation is not acceptance evidence.
Dependency: Bidirectional with BC-01 — path selection sets required interface scope.
TargetEvidenceQuality: SUFFICIENT_FOR_CLOSURE
RetestTrigger: Path formally elected by competent authority.
BlockingImpact: BC-06 REMAINS_OPEN and BC-01 scope cannot be finalized.
HR / RRLL / Training / Health
1 requestsOwns competency, certification and fitness facts consumed by readiness decisions.
CompetentOwner: HR / Health Data Owner
RequiredDecisionOrEvidence: Minimum attribute set sufficient to establish each competency / fitness decision fact, with everything else explicitly not persisted.
AcceptableEvidenceForm: Signed data-minimisation determination per decision fact.
WhyRequired: Full HR/Health records must not be copied into Integrated Readiness merely because they exist upstream.
Dependency: Records / Privacy classification (ER-REC-01).
TargetEvidenceQuality: SUFFICIENT_FOR_RETEST
RetestTrigger: Minimum attribute set signed for all Pilot decision facts.
BlockingImpact: BC-05 remains open; personal-data exposure risk unbounded.
Operational Lifecycle Authority
1 requestsOwns Pilot-scope lifecycle states, transitions and delegation.
CompetentOwner: Operational Lifecycle Authority (named)
RequiredDecisionOrEvidence: ADR-15 / ADR-17 Pilot supplement defining LifecycleOwner, StateOwner, AllowedTransition, TransitionAuthority, Delegation, EvidenceRequired, InvalidTransitionBehaviour, AuthorityUnavailableBehaviour.
AcceptableEvidenceForm: Signed lifecycle authority decision artefact scoped to the Pilot.
WhyRequired: No named authority ⇒ no attributable state transition ⇒ no reconstructable decision.
Dependency: BC-02 required for enforceable REAL authorization; artefact itself may progress independently.
TargetEvidenceQuality: SUFFICIENT_FOR_RETEST
RetestTrigger: Artefact signed and issued.
BlockingImpact: Without the artefact BC-03 stays open; with it but without BC-02, BC-03 may close WITH_CONTROL only.
Records / Privacy / Compliance / Governance Authority
2 requestsOwns CA-04 classification, retention basis and access scope.
CompetentOwner: Records & Privacy Authority
RequiredDecisionOrEvidence: Competent classification and retention basis for all material Pilot requirements; unresolved items must remain CLASSIFICATION_UNRESOLVED.
AcceptableEvidenceForm: Signed classification determination register.
WhyRequired: Evidence reconstruction and retention obligations govern how long decision pins persist.
Dependency: ER-HR-01 for personal-data facts.
TargetEvidenceQuality: SUFFICIENT_FOR_RETEST
RetestTrigger: Determination issued for every material requirement.
BlockingImpact: BC-05 remains open; downstream retention and evidence behaviour undefined.
CompetentOwner: Compliance / Governance Authority
RequiredDecisionOrEvidence: AccessScope determination for decision pins containing personal decision facts.
AcceptableEvidenceForm: Signed access-scope determination with role list.
WhyRequired: Access must be scoped to the readiness decision, not to the HR source population.
Dependency: ER-REC-01.
TargetEvidenceQuality: SUFFICIENT_FOR_CLOSURE
RetestTrigger: Access scope signed.
BlockingImpact: Evidence reconstruction cannot be exposed safely.
E · Minimum viable participation matrix (Pilot / CV-07)
ObjectScope: Permit, Isolation, JHA, operational Location reference
Rationale: Permit and isolation state changes within the shift; a stale snapshot could authorize work against a revoked permit.
CurrentState: NOT_CONNECTED — read scope unauthorized (ER-Q4-01).
CV-07 Impact: Blocking. No permit truth ⇒ no READY verdict.
ObjectScope: Controlled document revision state
Rationale: Revision changes are infrequent and governed; a dated snapshot with staleness tolerance preserves pin integrity.
CurrentState: NOT_CONNECTED — participation unconfirmed (ER-ACN-01).
CV-07 Impact: Blocking for document-pin reconstruction; snapshot is acceptable.
ObjectScope: Lookahead activities and dates
Rationale: Lookahead is planning horizon data; daily governed snapshot supports preventive lead time.
CurrentState: NOT_CONNECTED — cadence unagreed (ER-P6-01).
CV-07 Impact: Blocking for forecast evidence only; not for point-in-time authorization.
ObjectScope: System / subsystem completion state
Rationale: Turnover state changes at low frequency; unmapped states must fail closed regardless of mechanism.
CurrentState: NOT_CONNECTED — state semantics unconfirmed (ER-SC-01).
CV-07 Impact: Blocking for commissioning-phase scope.
ObjectScope: Critical control verification state
Rationale: Non-compensable control; verification state must be current at the moment of authorization. Applies under Path A.
CurrentState: SIMULATED — not acceptance evidence; path not elected (ER-CC-01).
CV-07 Impact: Blocking. Under Path B this row becomes NOT_REQUIRED_FOR_CURRENT_SCOPE with recorded evidence loss.
ObjectScope: Competency and certification validity fact
Rationale: A governed, attributable manual attestation of the minimum decision fact avoids bulk personal-data transfer.
CurrentState: NOT_CONNECTED — minimum attribute set undetermined (ER-HR-01).
CV-07 Impact: Blocking for competency gating; minimisation-preferred mechanism.
ObjectScope: Fitness decision fact (binary, dated)
Rationale: Only the governed decision fact is required; clinical detail must never enter the readiness layer.
CurrentState: NOT_CONNECTED — classification unresolved (ER-REC-01).
CV-07 Impact: Blocking for person-level readiness; minimisation-mandatory.
ObjectScope: Expiry date for required qualifications
Rationale: Expiry horizons are computable from a dated snapshot; preventive alerting needs lead time, not liveness.
CurrentState: NOT_CONNECTED.
CV-07 Impact: Blocking for preventive expiry forecasting.
ObjectScope: Identity, role, authority assertion
Rationale: Authority and delegation must be evaluated at decision time; cached authority is unsafe.
CurrentState: NOT_CONNECTED — no real principals provisioned (ER-IAM-01).
CV-07 Impact: Blocking for every attributable action in the Pilot.
Do not over-engineer enterprise integration as a prerequisite where governed evidence can be achieved by a simpler controlled mechanism. SIMULATED_ONLY is never acceptance evidence.
F · BC-03 / BC-05 governance decision queue
DecisionRequired: Name LifecycleOwner and StateOwner for every Pilot-scope readiness state.
CompetentAuthority: Operational Lifecycle Authority
CurrentState: UNRESOLVED — no artefact issued.
ClosureCeiling: CLOSED_WITH_CONTROL (real enforcement depends on BC-02).
DecisionRequired: Define AllowedTransition set, TransitionAuthority and Delegation rules, with EvidenceRequired per transition.
CompetentAuthority: Operational Lifecycle Authority with Enterprise Architecture
CurrentState: UNRESOLVED.
ClosureCeiling: CLOSED_WITH_CONTROL.
DecisionRequired: Specify InvalidTransitionBehaviour and AuthorityUnavailableBehaviour (both must fail closed).
CompetentAuthority: Operational Lifecycle Authority
CurrentState: UNRESOLVED — design fail-closed behaviour exists but is DesignEvidence only.
ClosureCeiling: CLOSED_WITH_CONTROL.
DecisionRequired: Classification and retention basis for every material Pilot requirement (CA-04).
CompetentAuthority: Records & Privacy Authority
CurrentState: CLASSIFICATION_UNRESOLVED on 5 of 6 material requirements.
ClosureCeiling: CLOSED where determination is complete and access scope signed.
DecisionRequired: DataMinimisation determination for competency / fitness information used in decision pins.
CompetentAuthority: Records & Privacy Authority with HR / Health Data Owner
CurrentState: UNRESOLVED.
ClosureCeiling: CLOSED.
BC-05 data minimisation control
DecisionFactRequired: Person holds the required competency for the task at the time of authorization.
MinimumAttributeRequired: PersonRef + QualificationCode + ValidUntil (date) + IssuingAuthorityRef.
PersonalDataPersisted: Pseudonymous person reference, qualification code, validity date, issuer reference.
PersonalDataNotPersisted: Training history, scores, assessment records, disciplinary data, full HR profile, national identifiers.
RetentionBasis: CLASSIFICATION_UNRESOLVED — pending Records & Privacy determination (GQ-04).
AccessScope: CLASSIFICATION_UNRESOLVED — pending ER-REC-02.
EvidenceRef: Decision pin references the source attestation; the source record itself is never copied.
DecisionFactRequired: Person is fit for duty for the shift covering the authorization.
MinimumAttributeRequired: PersonRef + FitnessDecision (binary) + DecisionDate + DecidingAuthorityRef.
PersonalDataPersisted: Pseudonymous person reference, binary decision, date, authority reference.
PersonalDataNotPersisted: Any clinical, medical, diagnostic, test-result or health-condition data of any kind.
RetentionBasis: CLASSIFICATION_UNRESOLVED — health data requires explicit competent determination.
AccessScope: CLASSIFICATION_UNRESOLVED.
EvidenceRef: Decision pin stores the attestation reference only.
DecisionFactRequired: Person held delegated authority when the readiness action was taken.
MinimumAttributeRequired: PrincipalRef + RoleRef + DelegationRef + ValidFrom/ValidUntil.
PersonalDataPersisted: Enterprise principal reference, role, delegation instrument reference, validity window.
PersonalDataNotPersisted: Employment terms, org-chart detail beyond the role, contact data.
RetentionBasis: Governed by evidence reconstruction obligation — pending GQ-04 confirmation.
AccessScope: Assurance and audit roles; CLASSIFICATION_UNRESOLVED pending ER-REC-02.
EvidenceRef: Authority resolution trace within the decision pin.
Retain the minimum governed fact needed to support readiness and reconstruct the decision. Do not copy full HR/Health records into Integrated Readiness merely because they exist upstream.
G · BC-06 path decision register
ElectionAuthority: Critical Control Authority (named) — election must be attributable.
PATH A — REAL GOVERNED PARTICIPATION
Preference: PREFERRED where reasonably achievable.
- Named real Critical Control source system and its owner.
- Authority model for critical control verification state.
- Verification state semantics mapped to readiness consumption.
- Pilot participation mechanism (LIVE_READ_REQUIRED per Section E).
EffectOnBC-01: Expands BC-01 interface scope to include the Critical Control source with live read.
Status: NOT ELECTED — no evidence received.
PATH B — FORMAL RESCOPE
Preference: Permitted only through competent authority decision.
- DecisionAuthority — named individual and mandate.
- Reason — why real participation is not reasonably achievable for the Pilot.
- PilotEvidenceLost — the specific acceptance evidence forgone.
- ResidualRisk — the risk carried and its owner.
- Phase7Impact — consequence for production readiness evidence.
Prohibition: Must not be elected merely to reduce blocker count or accelerate Pilot GO.
EffectOnBC-01: Removes the Critical Control source from BC-01 required interface scope and records evidence loss.
Status: NOT ELECTED — no decision record received.
Until one path is formally elected, BC-06 = REMAINS_OPEN and BC-01 scope cannot be finalized.
H · Updated cross-blocker dependency register
CanProgressIndependently: YES for all non-Critical-Control sources; interface work on Q4, Aconex, P6, Smart Completions proceeds now.
ClosureDependency: BC-01 cannot reach full closure until the BC-06 path is elected, because required interface scope is undetermined.
ExecutionDependency: Critical Control interface work must not start before path election.
CanDesignOrCloseGovernance: YES — MinimumViableParticipation classification can be signed per source.
CanExecuteOperationally: PARTIAL — only for sources outside the Critical Control scope question.
CanProgressIndependently: YES — start immediately; longest external lead time.
ClosureDependency: Self-contained: requires provisioned real identities and executed enforcement scenarios.
ExecutionDependency: Gates real authorization execution across the whole Pilot.
CanDesignOrCloseGovernance: YES — role mapping specification is a governance artefact.
CanExecuteOperationally: NO — no real principals provisioned.
CanProgressIndependently: YES — the lifecycle authority artefact is a competent governance decision that does not require integration.
ClosureDependency: May reach CLOSED_WITH_CONTROL on the artefact alone; full CLOSED requires BC-02 enforcement evidence.
ExecutionDependency: Real transition execution cannot be demonstrated until BC-02 provides enforceable identity.
CanDesignOrCloseGovernance: YES.
CanExecuteOperationally: NO.
CanProgressIndependently: YES — classification and minimisation are competent decisions available now.
ClosureDependency: Self-contained; but its outcome determines retention, access scope and evidence-reconstruction behaviour for all pins.
ExecutionDependency: Decision pins containing personal decision facts may not be persisted in the Pilot until classification exists.
CanDesignOrCloseGovernance: YES.
CanExecuteOperationally: NO — persistence prohibited while CLASSIFICATION_UNRESOLVED.
CanProgressIndependently: YES — the path election is a decision, not a delivery.
ClosureDependency: Path A closure requires evidenced real participation (therefore BC-01); Path B closure requires only the complete decision record.
ExecutionDependency: Sets BC-01 required interface scope; late election wastes Lane A lead time.
CanDesignOrCloseGovernance: YES — election may be made now.
CanExecuteOperationally: NO — Path A participation not evidenced; simulation is not acceptance evidence.
Dependency is not failure. A blocker that can close its governance obligation while remaining execution-dependent is recorded as CLOSED_WITH_CONTROL, never as failed.
I · Updated retest eligibility queue
Rule: Targeted retest only. Do not rerun the complete Mesa 1 assessment after each update. A documentary artefact may make a blocker eligible for retest without closing adjacent blockers.
Chain: OriginalHOLD → ExternalAction → NewOperationalClosureEvidence → EvidenceQualityAssessment → TargetedRetest → ClosureDisposition.
NearestTrigger: Signed ADR-15 / ADR-17 Pilot lifecycle supplement (ER-OLA-01).
EligibleWithoutOtherBlockers: YES — may reach SUFFICIENT_FOR_RETEST while BC-02 remains open.
ExpectedDisposition: CLOSED_WITH_CONTROL (real execution remains dependent on BC-02).
NearestTrigger: Records & Privacy classification determination plus minimisation decision (ER-REC-01, ER-HR-01).
EligibleWithoutOtherBlockers: YES.
ExpectedDisposition: CLOSED once access scope is signed (ER-REC-02).
NearestTrigger: Formal Path A / Path B election (ER-CC-01).
EligibleWithoutOtherBlockers: YES — the election is self-contained.
ExpectedDisposition: CLOSED (Path A, if evidenced) or FORMALLY_RESCOPED (Path B, full record required).
NearestTrigger: Real principals provisioned and enforcement scenarios executed (ER-IAM-01, ER-IAM-02).
EligibleWithoutOtherBlockers: YES, but long lead time.
ExpectedDisposition: CLOSED only on executed enforcement evidence with real identities.
NearestTrigger: MinimumViableParticipation classification signed plus per-source owner confirmations (ER-EA-01, ER-IT-01, ER-Q4-01…).
EligibleWithoutOtherBlockers: PARTIAL — final scope depends on BC-06 election.
ExpectedDisposition: CLOSED_WITH_CONTROL at best until Critical Control scope is settled.
J · Updated escalation register
Trigger: No IAM provisioning or system-owner authorization commenced within the current planning cycle.
EscalateTo: Programme Director with Enterprise IAM Owner and IT/IM
Reason: Lane A carries the longest external lead time; delay here delays every downstream real-authorization test.
ConsequenceIfUnresolved: Pilot entry date becomes indeterminate; BC-03 permanently capped at CLOSED_WITH_CONTROL.
Trigger: No competent Path A / Path B election recorded.
EscalateTo: Critical Control Authority and Programme Director
Reason: Path selection sets BC-01 interface scope; indecision blocks Lane A scope finalization.
ConsequenceIfUnresolved: BC-01 and BC-06 both remain open; Critical Control stays SIMULATED, which is not acceptance evidence.
Trigger: Path B proposed without the complete mandatory record, or proposed to reduce blocker count.
EscalateTo: Governance Authority
Reason: Path B is a risk-acceptance decision, not an administrative convenience.
ConsequenceIfUnresolved: Rescope refused; BC-06 REMAINS_OPEN.
Trigger: Personal competency / fitness data proposed for persistence beyond the minimum decision fact.
EscalateTo: Records / Privacy / Compliance Authority
Reason: Data minimisation is a control, not a preference.
ConsequenceIfUnresolved: Persistence refused; CLASSIFICATION_UNRESOLVED preserved and Pilot pins remain non-persistent.
Trigger: Live integration demanded where a governed snapshot or manual federation is sufficient for CV-07.
EscalateTo: Enterprise Architecture
Reason: Over-engineering integration converts a governance problem into an unnecessary delivery programme.
ConsequenceIfUnresolved: Pilot entry delayed without any gain in decision integrity or evidence quality.
Trigger: Governance decisions deferred on the grounds that enterprise integration is incomplete.
EscalateTo: Programme Director
Reason: Lane B decisions are competent and independent; deferral is a false dependency.
ConsequenceIfUnresolved: Avoidable serialization of the closure path.
K · Mesa 1 current disposition
Counts: Closed 0 · Open 5 · EvidenceQuality NONE · Retest 0 / 5
Changed by this action
- Location authority wording corrected to ADR-14 Option C.
- Execution path restructured into three parallel lanes with explicit priority.
- Dependency, retest and escalation registers updated.
- MinimumViableParticipationForPilot and BC-05 data-minimisation controls added.
Unchanged
- All five blockers REMAIN_OPEN.
- EvidenceQuality remains NONE — no OperationalClosureEvidence received.
- RetestEligibility remains 0/5.
- Mesa 2 and Mesa 3 not commenced; Phase 6A not rerun; Phase 6B not commenced.
AuthorizedNext: Evidence acquisition across the three lanes and targeted blocker closure only. No pilot exposure; BC-09 time-irreversibility protection remains in force under Mesa 3.
MESA 1 DISPOSITION: ENTERPRISE_ENABLEMENT_HOLD — corrected and reframed, not closed.