Phase 6A — Mesa 2 · Organizational Governance & Support Readiness
Can the organization operate and sustain CV-07 as an accountable operational capability when the design team is no longer acting as its operational support structure?
HOLD — OperationalClosureEvidence not yet sufficient
ENTERPRISE_ENABLEMENT_HOLD — BC-01/02/03/05/06 REMAINS_OPEN, EvidenceQuality NONE, retest 0/5 (not reopened here).
- Non-compensatory: support strength never offsets absent authority, vacant stewardship, unacceptable SoD, unavailable escalation, insufficient capacity, unresolved delegation or design-team dependency.
- INHERIT CONTEXT — NEVER INHERIT AUTHORIZATION is preserved for all stewardship and delegation logic.
- A prototype role is not an organizational assignment; technical ability to click Approve is not decision authority.
- Mesa 2 conditions may close organizationally while the associated operational capability remains DEPENDENCY_HELD pending Mesa 1.
- External dependency is never converted into a Mesa 2 failure, and never hidden inside a generic HOLD.
- No Mesa 1 reopening, no Mesa 1 blocker closure, no IAM simulation, no invented system ownership.
- No Mesa 3, no prospective BEFORE measurement, no Phase 6B, no Phase 6A rerun.
- No change to the frozen Pilot baseline or accepted architecture.
- No organizational assignment inferred from prototype configuration.
A · Executive organizational readiness summary
ORGANIZATIONAL_GOVERNANCE_HOLD
HOLD — OperationalClosureEvidence not yet sufficient
Disposition
GOVERNANCE_DESIGN_STRUCTURALLY_SOUND
Governance Design Condition
REMAINS_OPEN — Evidence acquisition required
BC-04
REMAINS_OPEN — Evidence acquisition required
BC-07
NOT_YET_SUFFICIENT
Operational Closure Evidence
2/15 demonstrated (DesignEvidence) · 13/15 pending OperationalClosureEvidence · 0/15 confirmed failed — based on current evidence set
Exit Criteria
NONE IDENTIFIED
Structural Contradiction
NOT YET ELIGIBLE
Retest Eligibility
External execution / closure dependency — not counted as Mesa 2 failure.
Mesa 1 Dependency
Governance Design Condition: GOVERNANCE_DESIGN_STRUCTURALLY_SOUND
Mesa 2 governance design has no identified structural contradiction based on the current assessment.
This status applies to governance design integrity only and does not imply organizational readiness, operational closure, Pilot authorization or Phase 6A GO. Do not use this label as a substitute for READY, CLOSED or OPERATIONALLY_VALIDATED.
Operational Closure Evidence: NOT_YET_SUFFICIENT
Required organizational assignments, authority evidence, support evidence and operating demonstrations are still pending.
How to read this HOLD
Design contradiction: NONE IDENTIFIED
Operational evidence: INSUFFICIENT
BC-04: OPEN FOR EVIDENCE
BC-07: OPEN FOR EVIDENCE
Retest: NOT YET ELIGIBLE
Mesa 2 closure: NOT AUTHORIZED
NOT DEMONSTRATED ≠ FAILED. Absence of evidence is never recorded or coloured as a demonstrated adverse state.
Mesa 1 execution dependency: RECORDED SEPARATELY — 6 Mesa 2 conditions are EXECUTION_DEPENDENCY on BC-01 / BC-02 / BC-03. These are not counted as Mesa 2 failures.
- No Pilot governance function has a named person or position with a documented authority basis; all seven required functions are UNASSIGNED, so decision rights exist as design only.
- ADR-14 Option C stewardship (Location, federation mapping) has no operational steward and no delegate register; the vacancy test therefore resolves to DISABLED_SAFE by design, not by demonstrated organizational behaviour.
- Rule governance lifecycle roles are undifferentiated: with no assignments, segregation between requirement interpretation, rule approval, configuration and production release cannot be evidenced.
- P3-TRN-01 remains design intent; no adoption owner, no execution dates, no supervisor briefing or field communication evidence exists.
- L1/L2/L3 support structure has no named owners, operating windows or contact mechanisms; the design team is currently the de-facto L1, L2 and L3.
- Design-team-withdrawn model is not credible today: 6 residual dependencies, 4 classified REQUIRES_TRANSFER and 2 BLOCKING.
- Support drills S-01…S-06: 0 executed with organizational participation; 3 are NOT_EXECUTABLE pending Mesa 1, 3 hold DesignEvidence only.
- Negative organizational traces fail closed correctly at design level (DENIED / HOLD / DISABLED_SAFE, sideEffect NONE) — DesignEvidence, not OperationalClosureEvidence.
- Management acceptance evidence for the Pilot operating model has not been issued by any competent authority.
The Mesa 2 governance design is GOVERNANCE_DESIGN_STRUCTURALLY_SOUND and fails closed as intended. It is not organizationally live: no named accountable person holds any Pilot governance function, no support level has an owner, and the design team remains the implicit operator. Mesa 2 therefore returns ORGANIZATIONAL_GOVERNANCE_HOLD on its own evidence, independently of the separately recorded Mesa 1 execution dependency.
- GOVERNANCE_DESIGN_STRUCTURALLY_SOUND → controlled positive / green.
- REMAINS_OPEN → amber / neutral pending state.
- EVIDENCE_REQUIRED → amber.
- HOLD → controlled warning state.
- FAIL / CONTRADICTED / STOP → red, reserved for demonstrated adverse states only.
MESA_2_PRESENTATION_BASELINE = FROZEN
B · Pilot governance organization
Organization: Owner / Operations (position to be named)
Accountability: Owns Pilot business intent, scope discipline and acceptance of the CV-07 operating model.
DecisionBoundary: May accept or suspend the Pilot operating model; may NOT alter architecture, no-compensation rules or frozen baselines.
AuthorityBasis: Requires written delegation from Project/Operations management — not issued.
AssignedPerson: UNASSIGNED
Availability: UNKNOWN
Delegate: NONE
EscalationPath: Project Director (position unconfirmed)
EvidenceRef: —
Organization: Construction / Commissioning area organization
Accountability: Canonical location identity, child-location applicability, SIMOPS location context integrity.
DecisionBoundary: Decides location identity and applicability; may NOT grant work authorization (INHERIT CONTEXT — NEVER INHERIT AUTHORIZATION).
AuthorityBasis: ADR-14 Option C stewardship appointment — not issued.
AssignedPerson: UNASSIGNED
Availability: UNKNOWN
Delegate: NONE
EscalationPath: BusinessProductOwner → Project Director
EvidenceRef: —
Organization: Enterprise Architecture / Data governance
Accountability: Cross-system federation keys, mapping conflicts, canonical identity escalation.
DecisionBoundary: Resolves mapping conflicts; may NOT change source-system mastership or create records in source systems.
AuthorityBasis: ADR-13 / CA-01 stewardship appointment — not issued.
AssignedPerson: UNASSIGNED
Availability: UNKNOWN
Delegate: NONE
EscalationPath: Enterprise Architecture authority (unnamed)
EvidenceRef: —
Organization: Work Control / ES&H requirement custodianship (split expected)
Accountability: Owns readiness rule intent, classification of critical vs non-critical conditions, rule release approval.
DecisionBoundary: Approves rule content; may NOT configure or release the same rule technically (SoD).
AuthorityBasis: ADR-16 rule governance appointment — not issued.
AssignedPerson: UNASSIGNED
Availability: UNKNOWN
Delegate: NONE
EscalationPath: BusinessProductOwner
EvidenceRef: —
Organization: IT / Enterprise systems
Accountability: Interface health, contract versions, failure and degradation handling for federated sources.
DecisionBoundary: Owns interface operation; may NOT authorize source participation (Mesa 1 / BC-01).
AuthorityBasis: IT service ownership assignment — not issued.
AssignedPerson: UNASSIGNED
Availability: UNKNOWN
Delegate: NONE
EscalationPath: IT service management (unnamed)
EvidenceRef: —
Organization: Site operations support (position to be named)
Accountability: Owns L1/L2 support operation, drill readiness and support continuity across shifts.
DecisionBoundary: Owns support routing and containment; may NOT decide authority questions or approve readiness.
AuthorityBasis: Support model appointment (BC-07) — not issued.
AssignedPerson: UNASSIGNED
Availability: UNKNOWN
Delegate: NONE
EscalationPath: BusinessProductOwner
EvidenceRef: —
Organization: Project change management / area superintendency
Accountability: P3-TRN-01 execution: behaviour change, supervisor briefing, field communication, resistance management.
DecisionBoundary: Owns adoption plan execution; may NOT waive readiness rules to ease adoption.
AuthorityBasis: Change management appointment — not issued.
AssignedPerson: UNASSIGNED
Availability: UNKNOWN
Delegate: NONE
EscalationPath: BusinessProductOwner → Project Director
EvidenceRef: —
C · Decision rights matrix
Technical ability to click Approve does not constitute decision authority. Authority is resolved on Role × Area × Activity × Shift × Risk × RegisterType; where no competent authority and no valid delegate resolve, the control is DISABLED_SAFE and the decision remains HOLD. ES&H is never assigned as universal approval authority.
Activity: Issue / revoke READY or CONDITIONAL verdict
Accountable: BusinessProductOwner (UNASSIGNED)
Owner: Work Control Superintendent (position, unnamed)
Steward: —
Approver: Area Superintendent within own area only
Executor: Work Control coordinator
Custodian: Readiness layer (ReadinessDecision object)
EscalationOwner: Project Director (unnamed)
Delegate: NONE registered
Shift × Risk × Register: All shifts; high risk; register = ReadinessDecision
Behaviour without authority: DISABLED_SAFE — control not offered; HOLD retained.
Status: DESIGN_ONLY — no named authority
Activity: Attempt to proceed with a failed critical condition
Accountable: None — non-compensable by design
Owner: —
Steward: —
Approver: NO APPROVER EXISTS
Executor: —
Custodian: Readiness layer
EscalationOwner: Project Director
Delegate: NOT DELEGABLE
Shift × Risk × Register: All shifts; critical
Behaviour without authority: DENIED — no compensation path exists at any authority level.
Status: DESIGN VERIFIED (fail-closed)
Activity: Confirm child-location applicability of a preventive requirement
Accountable: LocationSteward (UNASSIGNED)
Owner: Area organization
Steward: LocationSteward
Approver: LocationSteward
Executor: Work Control
Custodian: Canonical Location Register (federated)
EscalationOwner: BusinessProductOwner
Delegate: NONE registered
Shift × Risk × Register: Day shift decision; night shift uncovered
Behaviour without authority: HOLD — context inherited, authorization never inherited.
Status: DESIGN_ONLY — vacancy unmitigated
Activity: Resolve conflicting cross-system identity mapping
Accountable: FederationMappingSteward (UNASSIGNED)
Owner: Enterprise Architecture
Steward: FederationMappingSteward
Approver: FederationMappingSteward
Executor: IntegrationOwner
Custodian: Federation key register
EscalationOwner: Enterprise Architecture authority
Delegate: NONE registered
Shift × Risk × Register: Business hours only; risk high
Behaviour without authority: DISABLED_SAFE — conflicting objects excluded from decision context.
Status: DESIGN_ONLY + Mesa 1 EXECUTION_DEPENDENCY
Activity: Release an approved readiness rule to Pilot production
Accountable: RuleOwner (UNASSIGNED)
Owner: RuleOwner
Steward: —
Approver: RuleOwner (content) + IntegrationOwner (technical release)
Executor: Configuration custodian (distinct person required)
Custodian: Rule register
EscalationOwner: BusinessProductOwner
Delegate: NONE registered
Shift × Risk × Register: Controlled window; register = RuleSet
Behaviour without authority: DISABLED_SAFE — release path locked; prior rule version remains pinned.
Status: DESIGN_ONLY — SoD unverifiable
Activity: Interpret an ES&H requirement affecting a critical condition
Accountable: ES&H requirement custodian (UNASSIGNED)
Owner: ES&H function
Steward: —
Approver: ES&H custodian for interpretation only
Executor: RuleOwner converts interpretation to rule intent
Custodian: Requirement register
EscalationOwner: ES&H management
Delegate: NONE registered
Shift × Risk × Register: Business hours; critical register
Behaviour without authority: HOLD — ambiguous requirement is not auto-resolved.
Status: DESIGN_ONLY — ES&H explicitly NOT a universal approval authority
Activity: Reconstruct the decision context of a past readiness verdict
Accountable: BusinessProductOwner
Owner: Records custodian (UNASSIGNED)
Steward: —
Approver: —
Executor: L3 support
Custodian: Decision pinning store
EscalationOwner: Project Director
Delegate: NONE registered
Shift × Risk × Register: On request; audit register
Behaviour without authority: Request queued; no partial reconstruction released.
Status: DESIGN_ONLY + CLOSURE_DEPENDENCY on BC-05
D · ADR-14 stewardship readiness register
Design: Canonical Location Register federated; steward confirms identity and hierarchy.
CompetentAuthority: LocationSteward
AssignedOwner: UNASSIGNED
OperationalEvidence: NONE
FailureBehaviour: DISABLED_SAFE — location-dependent decisions HOLD.
AcceptanceCriterion: Named steward with written appointment exercises at least one real location identity decision.
Design: Mapping steward owns cross-system keys and conflict adjudication.
CompetentAuthority: FederationMappingSteward
AssignedOwner: UNASSIGNED
OperationalEvidence: NONE
FailureBehaviour: DISABLED_SAFE — conflicting mappings excluded, no auto-merge.
AcceptanceCriterion: Named steward resolves one real mapping conflict with recorded rationale.
Design: Every conflict has a single accountable resolver; no shared ownership.
CompetentAuthority: FederationMappingSteward
AssignedOwner: UNASSIGNED
OperationalEvidence: NONE
FailureBehaviour: Conflict remains open; affected objects excluded from readiness context.
AcceptanceCriterion: Conflict register with named resolver and escalation timer.
Design: Unresolvable identity escalates to Enterprise Architecture authority.
CompetentAuthority: Enterprise Architecture authority
AssignedOwner: UNASSIGNED (ADR-13 / CA-01 controlled-open)
OperationalEvidence: NONE
FailureBehaviour: HOLD — identity ambiguity never resolved by inference.
AcceptanceCriterion: Escalation exercised once end-to-end with a named decision owner.
Design: Applicability decided per child location; context inherited, authorization not.
CompetentAuthority: LocationSteward
AssignedOwner: UNASSIGNED
OperationalEvidence: NONE
FailureBehaviour: Requirement remains applicable and unconfirmed → HOLD.
AcceptanceCriterion: One real applicability decision recorded with attributable confirmation.
Design: Vacancy detected explicitly; no silent reassignment to any other role.
CompetentAuthority: BusinessProductOwner
AssignedOwner: UNASSIGNED
OperationalEvidence: DesignEvidence only (prototype G-01 vacant stewardship scenario).
FailureBehaviour: DISABLED_SAFE + HOLD.
AcceptanceCriterion: Organizational vacancy procedure issued and exercised with real roster data.
Design: Delegation explicit, time-bounded, competence-checked, attributable.
CompetentAuthority: Appointing authority of the steward role
AssignedOwner: UNASSIGNED
OperationalEvidence: NONE
FailureBehaviour: Invalid or expired delegation → authority UNRESOLVED → HOLD.
AcceptanceCriterion: Delegation register exists with at least one valid, evidenced delegation.
Design: Two sources claiming the same canonical object resolve by mastership rule, never by recency.
CompetentAuthority: FederationMappingSteward
AssignedOwner: UNASSIGNED
OperationalEvidence: DesignEvidence only.
FailureBehaviour: Both claims quarantined; decision context excludes the object.
AcceptanceCriterion: Real conflict resolved with recorded mastership basis.
E · Rule governance operating model
CompetentAuthority: Any competent operational role or AI-assisted analysis
AssignedOwner: UNASSIGNED
Must not also perform: ApproveRule for the same rule
Evidence: NONE
CompetentAuthority: Requirement custodian (ES&H / Work Control / Engineering by requirement type)
AssignedOwner: UNASSIGNED
Must not also perform: ReleaseRule
Evidence: NONE
CompetentAuthority: RuleOwner
AssignedOwner: UNASSIGNED
Must not also perform: ConfigureRule or ReleaseRule for the same rule
Evidence: NONE
CompetentAuthority: Configuration custodian
AssignedOwner: UNASSIGNED (currently performed by the design team)
Must not also perform: ApproveRule
Evidence: NONE
CompetentAuthority: Independent tester (not the configurer)
AssignedOwner: UNASSIGNED
Must not also perform: ConfigureRule for the same rule
Evidence: NONE
CompetentAuthority: IntegrationOwner under RuleOwner approval
AssignedOwner: UNASSIGNED
Must not also perform: ApproveRule
Evidence: NONE
CompetentAuthority: RuleOwner or BusinessProductOwner
AssignedOwner: UNASSIGNED
Must not also perform: Suspend a critical classification to unblock work
Evidence: NONE
CompetentAuthority: IntegrationOwner with RuleOwner notification
AssignedOwner: UNASSIGNED
Must not also perform: Roll back silently without version pinning record
Evidence: NONE
Requirement: Requirement interpretation, rule approval, technical configuration and production release must not be silently controlled by one individual where this creates an unacceptable SoD condition.
CurrentState: All eight lifecycle steps are UNASSIGNED and, in practice, the design team performs proposal, interpretation support, configuration, test and release. This is an unacceptable SoD condition for Pilot operation.
AI boundary: AI may assist interpretation or comparison and may propose; AI must never hold rule authority, approve, release or resolve ambiguity.
FailureBehaviour: Where SoD cannot be evidenced, rule release is DISABLED_SAFE and the pinned prior rule version remains in force.
F · P3-TRN-01 change & adoption readiness
System training is not operational adoption. Adoption evidence requires demonstrated behaviour change by named roles in real shift conditions, owned by a named ChangeAdoptionOwner.
BehaviourChangeRequired: Stop treating an individually 'green' source system as authorization; accept an integrated HOLD that no single system shows.
TrainingRequirement: Decision-model briefing (non-compensation, integrated verdict, pinning) — not system click-training.
SupervisorBriefing: Required before first shift of exposure — NOT SCHEDULED
FieldCommunication: Shift-start message explaining HOLD semantics — NOT ISSUED
SupportChannel: L1 (owner unassigned)
ResistanceRisk: HIGH — perceived loss of local discretion.
AdoptionOwner: UNASSIGNED
ExecutionDate: NOT SET
CompletionEvidence: NONE
Escalation: BusinessProductOwner → Project Director
BehaviourChangeRequired: Confirm preventive package items with attributable evidence instead of verbal assurance.
TrainingRequirement: Attributable confirmation practice with real evidence metadata.
SupervisorBriefing: NOT SCHEDULED
FieldCommunication: NOT ISSUED
SupportChannel: L1 → L2
ResistanceRisk: MEDIUM — added effort at shift start.
AdoptionOwner: UNASSIGNED
ExecutionDate: NOT SET
CompletionEvidence: NONE
Escalation: ChangeAdoptionOwner
BehaviourChangeRequired: Act as requirement custodian, not as universal approver of readiness.
TrainingRequirement: Authority boundary briefing.
SupervisorBriefing: NOT SCHEDULED
FieldCommunication: NOT ISSUED
SupportChannel: L2
ResistanceRisk: MEDIUM — existing culture routes all approvals to ES&H.
AdoptionOwner: UNASSIGNED
ExecutionDate: NOT SET
CompletionEvidence: NONE
Escalation: ES&H management
BehaviourChangeRequired: Exercise stewardship decisions and record vacancy/delegation explicitly.
TrainingRequirement: Stewardship operating procedure walkthrough.
SupervisorBriefing: NOT SCHEDULED
FieldCommunication: N/A
SupportChannel: L2 → L3
ResistanceRisk: HIGH — role is new and unstaffed.
AdoptionOwner: UNASSIGNED
ExecutionDate: NOT SET
CompletionEvidence: NONE
Escalation: BusinessProductOwner
G · Workaround governance register
A workaround must never silently become the accepted operating process. Any workaround persisting beyond containment escalates to the BusinessProductOwner and must be either corrected or formally accepted with recorded residual risk.
Example: Field records confirmations on paper then batch-enters them later.
Detection: Bulk confirmations with identical timestamps.
Owner: OperationalSupportOwner
Containment: Flag batch entries; require evidence metadata per item.
RootCause: Field entry friction.
CorrectiveAction: Interaction fix or supported offline path.
Acceptance: ChangeAdoptionOwner
ClosureEvidence: NONE
Example: Work package split to avoid a blocking condition.
Detection: Package fragmentation pattern against baseline scope.
Owner: Work Control
Containment: Fragmentation review before release.
RootCause: Process pressure at shift start.
CorrectiveAction: Planning cadence change.
Acceptance: BusinessProductOwner
ClosureEvidence: NONE
Example: Approval performed by an available person rather than the competent one.
Detection: Authority attribution mismatch in decision record.
Owner: BusinessProductOwner
Containment: DISABLED_SAFE — control not offered to non-competent roles.
RootCause: Missing delegate coverage.
CorrectiveAction: Delegation register with shift coverage.
Acceptance: BusinessProductOwner
ClosureEvidence: NONE
Example: Users bypass the readiness view because refresh is slow.
Detection: Decision made without a pinned decision context.
Owner: IntegrationOwner
Containment: No verdict issued without pinned context.
RootCause: Interface latency.
CorrectiveAction: Interface tuning or caching contract.
Acceptance: IntegrationOwner
ClosureEvidence: NONE
Example: A rule is suspended informally to keep work moving.
Detection: Rule suspension without RuleOwner record.
Owner: RuleOwner
Containment: Suspension path locked without attributable authority.
RootCause: Unassigned rule authority.
CorrectiveAction: Rule governance appointment (ADR-16).
Acceptance: BusinessProductOwner
ClosureEvidence: NONE
Example: Crews continue to use the legacy shift sheet as the real plan.
Detection: Divergence between executed work and readiness records.
Owner: ChangeAdoptionOwner
Containment: Supervisor intervention and escalation.
RootCause: Adoption not executed (P3-TRN-01 open).
CorrectiveAction: Adoption plan execution.
Acceptance: BusinessProductOwner
ClosureEvidence: NONE
H · L1 / L2 / L3 support model
SupportedIssueTypes: Access / login · Device or offline sync · How-to and data entry · Evidence attachment
Owner: UNASSIGNED (OperationalSupportOwner to nominate)
OperatingWindow: NOT DEFINED — must cover all Pilot shifts
ContactMechanism: NOT DEFINED
EscalationTrigger: Issue affects a readiness verdict or authority resolution.
ResponseExpectation: NOT SET — no SLA invented; must be set by the support owner.
AuthorityBoundary: No authority over readiness decisions, rules, mappings or approvals.
Evidence: NONE
SupportedIssueTypes: Rule interpretation questions · Preventive package composition queries · Stewardship routing · Workaround triage
Owner: UNASSIGNED
OperatingWindow: NOT DEFINED
ContactMechanism: NOT DEFINED
EscalationTrigger: Requirement ambiguity, authority conflict or mapping conflict.
ResponseExpectation: NOT SET
AuthorityBoundary: May route and explain; may not approve rules or grant authority.
Evidence: NONE
SupportedIssueTypes: Interface failure · Federation identity defect · Evidence reconstruction · Architecture-impacting defects
Owner: UNASSIGNED — currently absorbed by the design team
OperatingWindow: NOT DEFINED
ContactMechanism: NOT DEFINED
EscalationTrigger: Source unavailable, contract mismatch, decision context not reconstructable.
ResponseExpectation: NOT SET
AuthorityBoundary: May restore service; may not alter decisions, rules or mastership.
Evidence: NONE
I · Design-team-withdrawn dependency register
DesignTeamPresent: Design team explains model behaviour, configures rules, resolves mapping questions and answers authority interpretation queries; the capability appears operable because the designers are inside the loop.
DesignTeamWithdrawn: No design-team participation in any operational path: no hidden system administrator, no unofficial steward, no authority interpreter, no support desk, no rule owner, no federation resolver. Every path resolves to a named organizational owner or fails closed.
CurrentVerdict: NOT CREDIBLE TODAY — 2 BLOCKING and 4 REQUIRES_TRANSFER residual dependencies; the design team is currently the de-facto L2/L3 and rule configurer.
CurrentPerformer: Design team
RequiredPerformer: Configuration custodian under RuleOwner
TransferCondition: ADR-16 rule governance appointments issued and SoD evidenced.
Status: OPEN
CurrentPerformer: Design team
RequiredPerformer: FederationMappingSteward
TransferCondition: Named steward appointed (ADR-13 / CA-01) and one real conflict resolved.
Status: OPEN
CurrentPerformer: Design team
RequiredPerformer: L2 support + BusinessProductOwner
TransferCondition: L2 owner named, authority boundary published, one drill executed.
Status: OPEN
CurrentPerformer: Design team
RequiredPerformer: L3 support + records custodian
TransferCondition: CA-04 classification/retention decisions taken (BC-05) and custodian named.
Status: OPEN — CLOSURE_DEPENDENCY on BC-05
CurrentPerformer: Design team
RequiredPerformer: ChangeAdoptionOwner and supervisors
TransferCondition: P3-TRN-01 executed; time-bounded to the early Pilot window with recorded end date.
Status: OPEN
CurrentPerformer: Design team
RequiredPerformer: L3 with design team as vendor-style escalation only
TransferCondition: L3 owner named and escalation contract recorded; design team never inside the decision path.
Status: OPEN
J · Support drill results / evidence status
No drill may be recorded as successful on prototype behaviour alone. Success requires organizational participation by the named owner acting under a documented authority basis.
Issue: User / access issue — field user cannot see their assigned job cards.
InitialOwner: L1 (UNASSIGNED)
Escalation: L2 → enterprise IAM
CompetentDecisionOwner: Enterprise IAM authority (UNRESOLVED — BC-02)
Resolution: NOT EXECUTED
ElapsedTime: —
SideEffect: NONE
DesignTeamDependency: YES — design team currently the only responder
EvidenceRef: —
Issue: Federation mapping conflict — two sources claim the same tag identity.
InitialOwner: L2 (UNASSIGNED)
Escalation: FederationMappingSteward → EA authority
CompetentDecisionOwner: UNASSIGNED
Resolution: Prototype quarantines both claims and excludes the object (DesignEvidence).
ElapsedTime: —
SideEffect: NONE
DesignTeamDependency: YES
EvidenceRef: DesignEvidence — prototype federation behaviour
Issue: Rule interpretation question — is a wind limit applicable to a sheltered child location?
InitialOwner: L2 (UNASSIGNED)
Escalation: Requirement custodian → RuleOwner
CompetentDecisionOwner: UNASSIGNED
Resolution: Prototype holds the condition pending human confirmation (DesignEvidence).
ElapsedTime: —
SideEffect: NONE
DesignTeamDependency: YES
EvidenceRef: DesignEvidence — HOLD on ambiguous requirement
Issue: Interface failure — a federated source is unavailable at shift start.
InitialOwner: L3 (UNASSIGNED)
Escalation: IntegrationOwner → source system owner
CompetentDecisionOwner: UNASSIGNED (source ownership unresolved — BC-01)
Resolution: NOT EXECUTED with real interfaces.
ElapsedTime: —
SideEffect: NONE
DesignTeamDependency: YES
EvidenceRef: —
Issue: Authority / approval issue — competent approver unavailable on night shift.
InitialOwner: L1 (UNASSIGNED)
Escalation: Delegate → EscalationOwner
CompetentDecisionOwner: UNASSIGNED — no delegation register
Resolution: Prototype disables the control and retains HOLD (DesignEvidence).
ElapsedTime: —
SideEffect: NONE
DesignTeamDependency: NO for the fail-closed behaviour; YES for resolution
EvidenceRef: DesignEvidence — DISABLED_SAFE
Issue: Evidence reconstruction request — reproduce the decision context of a past verdict.
InitialOwner: L3 (UNASSIGNED)
Escalation: Records custodian → BusinessProductOwner
CompetentDecisionOwner: UNASSIGNED
Resolution: NOT EXECUTED — retention/classification decisions outstanding.
ElapsedTime: —
SideEffect: NONE
DesignTeamDependency: YES
EvidenceRef: —
K · Stewardship vacancy test
Scenario: RequiredSteward = unavailable (LocationSteward absent at shift start; child-location applicability decision pending).
Result: NO DELEGATE REGISTERED — resolution fails explicitly.
Result: AuthorityResolutionState = UNRESOLVED; no substitute inferred from availability.
Result: Escalation target exists in design (BusinessProductOwner) but is UNASSIGNED organizationally.
Result: Applicability control not offered; job card remains HOLD.
Result: No other role acquires stewardship implicitly.
Result: Design team is not offered as a resolver in any path.
Principle: NoCompetentSteward + NoValidDelegate → HOLD / DISABLED_SAFE.
EvidenceClass: DesignEvidence — executed against the prototype governance model, not with real roster and appointment data.
Disposition: BEHAVIOUR CORRECT — ORGANIZATIONAL CLOSURE NOT ACHIEVED (escalation target unassigned).
L · Capacity & workload assessment
ExpectedWorkload: Applicability and identity decisions at every location change in Pilot scope.
DecisionFrequency: Daily, concentrated at shift start.
ShiftCoverage: Day shift only assumed; night shift uncovered.
AbsenceCover: None registered.
EscalationBurden: Receives all location ambiguity.
CompetingResponsibilities: Expected to be a full-time area role.
Basis: Unstaffed role with shift-start concentration and no delegate; no numeric staffing threshold assumed.
ExpectedWorkload: Conflict adjudication across all connected sources.
DecisionFrequency: Unknown until sources participate (BC-01).
ShiftCoverage: Business hours.
AbsenceCover: None registered.
EscalationBurden: Canonical identity escalations.
CompetingResponsibilities: Enterprise architecture duties.
Basis: Volume unknowable before source participation; role unstaffed.
ExpectedWorkload: Rule intent approval and classification decisions.
DecisionFrequency: Low volume, high consequence.
ShiftCoverage: Business hours.
AbsenceCover: None registered.
EscalationBurden: Rule ambiguity escalations.
CompetingResponsibilities: Existing work control or ES&H duties.
Basis: Feasible if a delegate is registered and release windows are controlled.
ExpectedWorkload: All field user contacts across Pilot shifts.
DecisionFrequency: Continuous during shift.
ShiftCoverage: Must cover all Pilot shifts — not defined.
AbsenceCover: None registered.
EscalationBurden: Primary intake for every issue class.
CompetingResponsibilities: Unknown — role unstaffed.
Basis: No owner, no operating window and no contact mechanism exist; the design team absorbs the load today.
ExpectedWorkload: Briefings, field communication, resistance handling.
DecisionFrequency: Front-loaded before and during early Pilot.
ShiftCoverage: Day shift with shift-start presence required.
AbsenceCover: None registered.
EscalationBurden: Behavioural escalations.
CompetingResponsibilities: Project change duties.
Basis: P3-TRN-01 unexecuted with no owner and no dates.
M · Segregation of duties assessment
PotentialConflict: Same person defines, approves, configures and releases a critical rule.
Risk: Critical classification silently weakened with no independent check.
Control: Mandatory separation of approval from configuration and release; release DISABLED_SAFE otherwise.
AuthorityDecision: NOT ACCEPTABLE
ResidualRisk: HIGH while unassigned — the design team currently spans the whole lifecycle.
PotentialConflict: Crew supervisor approves the readiness of their own work package.
Risk: Self-authorization of critical conditions.
Control: Approver must be outside the executing chain for critical registers.
AuthorityDecision: NOT ACCEPTABLE for critical conditions; acceptable for non-critical with record.
ResidualRisk: MEDIUM
PotentialConflict: Stewardship of location context held by the party benefiting from work release.
Risk: Applicability narrowed to remove blocking requirements.
Control: Applicability decisions recorded with rationale and subject to assurance sampling.
AuthorityDecision: ACCEPTABLE_WITH_CONTROL
ResidualRisk: MEDIUM
PotentialConflict: Technical resolver also adjudicates mastership.
Risk: Mapping resolved for technical convenience rather than authority.
Control: Mastership decision recorded by steward; integration executes only.
AuthorityDecision: ACCEPTABLE_WITH_CONTROL if roles are distinct persons.
ResidualRisk: MEDIUM
PotentialConflict: Assurance of one's own decision path.
Risk: Assurance becomes self-attestation.
Control: Assurance independent of the whole path.
AuthorityDecision: NOT ACCEPTABLE
ResidualRisk: HIGH while unassigned.
PotentialConflict: Designers operate the capability they designed.
Risk: Organizational accountability never establishes; withdrawal collapses operation.
Control: Design-team-withdrawn model with transfer register (Section I).
AuthorityDecision: NOT ACCEPTABLE for Pilot operation.
ResidualRisk: HIGH — currently the actual state.
N · Escalation & delegation architecture
Unresolved authority for a readiness decision
PrimaryOwner: Work Control coordinator
EscalationOwner: BusinessProductOwner (UNASSIGNED)
DecisionAuthority: BusinessProductOwner
ExpectedDisposition: HOLD retained until competent authority resolves.
Evidence: NONE
Steward vacancy
PrimaryOwner: Area organization
EscalationOwner: BusinessProductOwner (UNASSIGNED)
DecisionAuthority: Appointing authority
ExpectedDisposition: DISABLED_SAFE + temporary delegation or HOLD.
Evidence: DesignEvidence only
Federation mapping conflict
PrimaryOwner: FederationMappingSteward (UNASSIGNED)
EscalationOwner: Enterprise Architecture authority (UNASSIGNED)
DecisionAuthority: EA authority
ExpectedDisposition: Object quarantined until mastership decided.
Evidence: NONE
Rule ambiguity
PrimaryOwner: Requirement custodian
EscalationOwner: RuleOwner (UNASSIGNED)
DecisionAuthority: RuleOwner
ExpectedDisposition: Condition remains applicable → HOLD; no permissive default.
Evidence: DesignEvidence only
Repeated workaround
PrimaryOwner: OperationalSupportOwner
EscalationOwner: BusinessProductOwner
DecisionAuthority: BusinessProductOwner
ExpectedDisposition: Correct or formally accept with recorded residual risk — never silent adoption.
Evidence: NONE
Support failure (no responder)
PrimaryOwner: L1
EscalationOwner: OperationalSupportOwner
DecisionAuthority: BusinessProductOwner
ExpectedDisposition: Pilot exposure suspended for affected scope.
Evidence: NONE
Operational blocker at shift start
PrimaryOwner: Area Superintendent
EscalationOwner: Work Control
DecisionAuthority: Competent approver for the register
ExpectedDisposition: HOLD; no compensation of critical conditions.
Evidence: DesignEvidence only
Data / evidence integrity concern
PrimaryOwner: Records custodian (UNASSIGNED)
EscalationOwner: BusinessProductOwner
DecisionAuthority: Project Director
ExpectedDisposition: Affected decisions flagged; reconstruction requested.
Evidence: NONE — CLOSURE_DEPENDENCY BC-05
Shift handover: Authority and open decisions transfer explicitly at handover. — NOT EVIDENCED
Absence: Registered delegate with competence check and expiry. — NO DELEGATION REGISTER
Roster change: Authority re-validated against the new roster, never carried over implicitly. — NOT EVIDENCED
Temporary role replacement: Time-bounded appointment with attributable record. — NOT EVIDENCED
Organizational reassignment: Prior authority revoked explicitly. — NOT EVIDENCED
Delegation must be explicit and evidenceable. Authority is never inferred from availability, presence, seniority or system access.
O · Positive and negative organizational traces
Positive trace
Case: Field issue at shift start: crew cannot confirm a preventive item because the competency record appears expired.
- 1. FieldIssue raised — Crew supervisor · AVAILABLE (organizational role exists)
- 2. L1 intake — L1 support (UNASSIGNED) · NOT_EXECUTABLE
- 3. Routing to competent owner — Competency custodian (UNASSIGNED) · NOT_EXECUTABLE
- 4. GovernedDecision — Competent approver (UNRESOLVED — BC-02 IAM) · DEPENDENCY_HELD
- 5. OperationalResolution — Work Control · DEPENDENCY_HELD
- 6. EvidenceClosure — Records custodian (UNASSIGNED, BC-05) · DEPENDENCY_HELD
DesignTeamNeeded: YES — today the design team would be required at three of six steps.
Disposition: DEPENDENCY_HELD — not simulated as PASS. Two steps fail on Mesa 2 evidence (unassigned owners); three are held by Mesa 1 dependencies.
Scenario: Vacant stewardship — applicability decision requested with no steward.
SideEffect: NONE
EvidenceClass: DesignEvidence
Scenario: Invalid delegation — expired delegate attempts a stewardship decision.
SideEffect: NONE
EvidenceClass: DesignEvidence
Scenario: Authority conflict — two roles claim approval rights on the same critical register.
SideEffect: NONE
EvidenceClass: DesignEvidence
Scenario: Unsupported issue — issue class with no owning support level.
SideEffect: NONE
EvidenceClass: DesignEvidence
Scenario: Prohibited SoD — same identity attempts approve and release of one rule.
SideEffect: NONE
EvidenceClass: DesignEvidence
P · Mesa 1 ↔ Mesa 2 dependency register
Mesa1Blocker: —
CanProgressIndependently: YES
CanCloseOrganizationally: YES
CanExecuteOperationally: YES (appointments are organizational acts)
RequiredExternalEvidence: Signed appointment letters with authority basis and delegates.
Mesa1Blocker: BC-02 IAM
CanProgressIndependently: YES (matrix and boundaries)
CanCloseOrganizationally: YES
CanExecuteOperationally: NO — enforcement requires enterprise identity/role binding.
RequiredExternalEvidence: IAM role-to-authority binding evidence from the enterprise IAM owner.
Mesa1Blocker: BC-01 enterprise participation
CanProgressIndependently: YES (appointment, procedure)
CanCloseOrganizationally: YES
CanExecuteOperationally: NO — no authorized source participation to map.
RequiredExternalEvidence: Source participation authorization and interface validation.
Mesa1Blocker: BC-03 lifecycle authority
CanProgressIndependently: PARTIAL — SoD design only
CanCloseOrganizationally: NO — rule lifecycle authority artefact (ADR-15/17) must be issued.
CanExecuteOperationally: NO
RequiredExternalEvidence: Issued Pilot lifecycle authority artefact naming rule authority.
Mesa1Blocker: BC-05 CA-04 classification & retention
CanProgressIndependently: YES (support routing)
CanCloseOrganizationally: NO — retention and classification decisions are prerequisites.
CanExecuteOperationally: NO
RequiredExternalEvidence: CA-04 classification/retention decision record.
Mesa1Blocker: BC-02 IAM (access issues)
CanProgressIndependently: YES (owner, window, channel)
CanCloseOrganizationally: YES
CanExecuteOperationally: PARTIAL — access issues unresolvable without IAM ownership.
RequiredExternalEvidence: Named IAM support path.
Mesa1Blocker: BC-06 Path A / Path B election
CanProgressIndependently: YES
CanCloseOrganizationally: PARTIAL — support scope depends on the elected path.
CanExecuteOperationally: NO
RequiredExternalEvidence: Formal Path A / Path B decision record (Mesa 1).
Mesa1Blocker: —
CanProgressIndependently: YES
CanCloseOrganizationally: YES
CanExecuteOperationally: PARTIAL — training on live behaviour needs participating sources, briefings do not.
RequiredExternalEvidence: Adoption plan with owner, dates and completion evidence.
Q · BC-04 / BC-07 closure register
Percentages are never a substitute for closure criteria. Each blocker closes only on OperationalClosureEvidence meeting its acceptance criterion; DesignEvidence is recorded separately and closes nothing.
DesignEvidence: Governance functions defined; decision rights matrix specified; ADR-14 stewardship tests defined; vacancy behaviour verified fail-closed; SoD conflicts identified; escalation architecture specified; P3-TRN-01 converted to an executable plan structure.
OperationalClosureEvidence: NONE — no appointment, no delegation register, no adoption execution, no management acceptance.
AcceptanceCriterion: Named appointments with authority basis for all seven functions, a delegation register with shift coverage, acceptable SoD, and executed P3-TRN-01 with completion evidence.
FailureBehaviour: Authority UNRESOLVED → DISABLED_SAFE / HOLD; no inferred stewardship.
CrossMesaDependency: BC-03 CLOSURE_DEPENDENCY (rule lifecycle authority); BC-02 EXECUTION_DEPENDENCY (enforcement).
DesignEvidence: L1/L2/L3 structure, issue classes, authority boundaries and escalation triggers specified; six support drills defined; design-team-withdrawn model articulated with a residual dependency register.
OperationalClosureEvidence: NONE — no support owners, operating windows, contact mechanisms or response expectations set; 0 drills executed with organizational participation.
AcceptanceCriterion: Named owners per support level with operating windows and contact mechanisms, response expectations set by the support owner, all six drills executed or evidence-qualified, and no BLOCKING design-team dependency remaining.
FailureBehaviour: Unsupported issue class → HOLD; Pilot exposure not authorized for affected scope.
CrossMesaDependency: BC-01 / BC-02 EXECUTION_DEPENDENCY; BC-05 CLOSURE_DEPENDENCY (reconstruction); BC-06 DESIGN_DEPENDENCY.
R · Evidence acquisition / retest queue
Request: Issue written appointments for the seven Pilot governance functions with authority basis, decision boundary and delegate.
EvidenceQuality: NONE
Status: ISSUED — NOT RECEIVED
Request: Issue management acceptance of the Pilot operating model (governance, support, adoption).
EvidenceQuality: NONE
Status: ISSUED — NOT RECEIVED
Request: Provide roster-based shift coverage and delegation register for LocationSteward including night shift.
EvidenceQuality: NONE
Status: ISSUED — NOT RECEIVED
Request: Appoint FederationMappingSteward and publish the mapping conflict resolution procedure with escalation timer.
EvidenceQuality: NONE
Status: ISSUED — NOT RECEIVED
Request: Split and confirm requirement custodianship vs rule approval authority (ADR-16) with named holders.
EvidenceQuality: NONE
Status: ISSUED — DEPENDENCY BC-03
Request: Confirm SoD control for rule approval / configuration / release with distinct named persons.
EvidenceQuality: NONE
Status: ISSUED — NOT RECEIVED
Request: Issue executable P3-TRN-01 plan with adoption owner, dates, supervisor briefing and field communication artefacts.
EvidenceQuality: NONE
Status: ISSUED — NOT RECEIVED
Request: Provide completion evidence of supervisor briefings for the Pilot area.
EvidenceQuality: NONE
Status: ISSUED — NOT RECEIVED
Request: Name L1 owner, operating window covering all Pilot shifts, contact mechanism and response expectation.
EvidenceQuality: NONE
Status: ISSUED — NOT RECEIVED
Request: Name L2 owner and publish authority boundary and routing rules.
EvidenceQuality: NONE
Status: ISSUED — NOT RECEIVED
Request: Name L3 owner and escalation contract for interface and federation defects.
EvidenceQuality: NONE
Status: ISSUED — DEPENDENCY BC-01
Request: Execute drills S-02, S-03, S-05 with organizational participation and record owner, elapsed time and disposition.
EvidenceQuality: NONE
Status: ISSUED — NOT RECEIVED
Request: Provide the named support path for access issues (drill S-01 prerequisite).
EvidenceQuality: NONE
Status: HELD — DEPENDENCY BC-02
Request: Name the records custodian and confirm the evidence reconstruction request path.
EvidenceQuality: NONE
Status: HELD — DEPENDENCY BC-05
Request: Approve the design-team transfer plan closing DD-01 and DD-02 with transfer dates and receiving owners.
EvidenceQuality: NONE
Status: ISSUED — NOT RECEIVED
Request: Confirm capacity and absence cover for the appointed steward and support roles.
EvidenceQuality: NONE
Status: ISSUED — NOT RECEIVED
Retest rule: A condition enters targeted retest only at EvidenceQuality ≥ SUFFICIENT_FOR_RETEST. Full Phase 6A gate rerun occurs only after all mandatory blockers are CLOSED or FORMALLY_RESCOPED.
Queue state: QUEUE EMPTY — 0 of 2 Mesa 2 blockers reach SUFFICIENT_FOR_RETEST (EvidenceQuality NONE for both).
S · Mesa 2 final disposition
ORGANIZATIONAL_GOVERNANCE_HOLD
HOLD — OperationalClosureEvidence not yet sufficient
REMAINS_OPEN — Evidence acquisition required (EvidenceQuality NONE) · REMAINS_OPEN — Evidence acquisition required (EvidenceQuality NONE)
Exit criteria 2/15 demonstrated (DesignEvidence) · 13/15 pending OperationalClosureEvidence · 0/15 confirmed failed — based on current evidence set
NOT DEMONSTRATED ≠ FAILED. Absence of evidence is never recorded or coloured as a demonstrated adverse state.
Mesa 1 dependency: External execution / closure dependency — not counted as Mesa 2 failure.
Mesa 1 dependency (recorded separately): 6 conditions carry EXECUTION_DEPENDENCY or CLOSURE_DEPENDENCY on BC-01 / BC-02 / BC-03 / BC-05 / BC-06. These are recorded in Section P and are NOT the reason for the Mesa 2 HOLD.
Mesa 2 own-evidence reason: Mesa 2 holds on its own organizational evidence: no appointments, no delegation register, no support ownership, unacceptable SoD in the current de-facto arrangement, and unexecuted adoption.
Closable now without Mesa 1
- Governance appointments (ER-M2-01) — no Mesa 1 dependency.
- Delegation and shift coverage register (ER-M2-03) — no Mesa 1 dependency.
- L1 / L2 support ownership, windows and channels (ER-M2-09, ER-M2-10) — no Mesa 1 dependency.
- P3-TRN-01 executable plan and supervisor briefings (ER-M2-07, ER-M2-08) — no Mesa 1 dependency.
- Design-team transfer plan for DD-01 / DD-02 (ER-M2-15) — approval is organizational.
AuthorizedNext: Mesa 2 external evidence acquisition only. No Mesa 1 reopening, no Mesa 3, no prospective BEFORE measurement, no Phase 6B, no Phase 6A rerun.
The organization cannot yet operate and sustain CV-07 without the design team. The governance design is sound and fails closed, but it is unstaffed: authority, stewardship, support and adoption exist as design, not as accountable organizational fact. Mesa 2 returns ORGANIZATIONAL_GOVERNANCE_HOLD, with the Mesa 1 execution dependency recorded separately and visibly.