Phase 6A — Owner Evidence Intake Integration
Wave 1 · Real Evidence Acquisition & Controlled Assessment
Lovable orchestrates evidence; competent owners establish authority; authoritative systems establish fact; targeted retests establish operational confidence; only Phase 6A Integrated Revalidation can establish GO.
A · Owner Evidence Intake Executive View
A controlled owner evidence intake mechanism is now active against the six existing Wave 1 Evidence Requests (ER-01, ER-06, ER-07, ER-11, ER-16, ER-17). It can receive real acknowledgements and artefacts, preserve provenance, assess them against the frozen acceptance criteria and prepare targeted retests. No acknowledgement, artefact or assessment has been supplied; every request remains AWAITING_OWNER.
- · Lovable operates as: Evidence Orchestration · Assessment · Traceability · Retest Preparation · Assurance Control Room.
- · Lovable does not operate as: Authoritative Corporate Repository · Competent Authority · System of Record · Legal Authority · IAM Authority · Critical Control Authority.
B · 6-Request Reconciliation
Reconciliation is a precondition of activation. A failed reconciliation stops activation; it is never resolved by adding or removing a request.
| ER | Blocker | Competent owner | Questions | Minimum acceptance evidence | Potential retest trigger | Escalation | Status |
|---|---|---|---|---|---|---|---|
| ER-01 | BC-01 | Enterprise Architecture | Q-W1-01 · Q-W1-02 · Q-W1-03 · Q-W1-04 · Q-W1-05 | Attributable participation declaration per source/object. | RT-01 — BC-01 object participation retest · NOT_PREPARED | ESC-02 | AWAITING_OWNER |
| ER-06 | BC-01 | IT / IM | Q-W1-06 · Q-W1-07 · Q-W1-08 · Q-W1-09 | IT authorization statement for the declared mechanisms. | RT-02 — BC-01 federation mechanism retest · NOT_PREPARED | ESC-02 | AWAITING_OWNER |
| ER-07 | BC-02 | IAM / Cyber | Q-W1-10 · Q-W1-11 · Q-W1-12 · Q-W1-13 · Q-W1-14 · Q-W1-15 · Q-W1-16 | IAM owner confirmation + provisioned identity set. | RT-03 — BC-02 IAM-01 → IAM-06 identity chain retest · NOT_PREPARED | ESC-02 | AWAITING_OWNER |
| ER-11 | BC-03 | Business Product Owner | Q-W1-17 · Q-W1-18 · Q-W1-19 · Q-W1-20 · Q-W1-21 | Decision artefact per object class. | RT-04 — BC-03 lifecycle authority / SoD retest · NOT_PREPARED | ESC-02 | AWAITING_OWNER |
| ER-16 | BC-05 | Records Management | Q-W1-22 · Q-W1-23 · Q-W1-24 · Q-W1-25 | Competent retention decision per class. | RT-05 — BC-05 classification & retention retest · NOT_PREPARED | ESC-02 | AWAITING_OWNER |
| ER-17 | BC-05 | Privacy | Q-W1-26 · Q-W1-27 · Q-W1-28 | Privacy decision per class. | RT-05 — BC-05 classification & retention retest (privacy limb) · NOT_PREPARED | ESC-02 | AWAITING_OWNER |
C · Frozen Questionnaire — Read-Only View
QUESTIONNAIRE_BASELINE_ID = PH6A-W1-OEAVQ-REV1, FROZEN_FOR_OWNER_VALIDATION. No question may be rewritten, merged, deleted, reassigned or reinterpreted without explicit architecture governance instruction. DesignResponse and OwnerValidatedResponse are held separately and are never reconciled into a single field.
| Question | ER | BC | Owner | Dimension | Design response (design only) | Evidence class | Owner-validated response | Owner evidence ref | Assessment | Residual gap |
|---|---|---|---|---|---|---|---|---|---|---|
| Q-W1-01 | ER-01 | BC-01 | Enterprise Architecture | ObjectClass | 22 governed object classes are declared in the Phase 5 authority matrix. | FROZEN_ARCHITECTURAL_INVARIANT | NOT_SUPPLIED | NONE | NOT_ASSESSED | No owner has confirmed object-class coverage. |
| Q-W1-02 | ER-01 | BC-01 | Enterprise Architecture | AuthoritativeSource | Q4, Aconex, P6, Forwood and HR/Competency are candidate sources per object class. | CANDIDATE_SOURCE | NOT_SUPPLIED | NONE | NOT_ASSESSED | Sources remain candidates, not confirmed. |
| Q-W1-03 | ER-01 | BC-01 | Enterprise Architecture | SourceOwner | System Owner role assumed per source; individuals unnamed. | DESIGN_ASSERTION | NOT_SUPPLIED | NONE | NOT_ASSESSED | No named accountable owner exists. |
| Q-W1-04 | ER-01 | BC-01 | Enterprise Architecture | ParticipationMode | API / SNAPSHOT / MANUAL_FEDERATED are all acceptable participation modes. | PROPOSED_RULE | NOT_SUPPLIED | NONE | NOT_ASSESSED | Participation mode unelected. |
| Q-W1-05 | ER-01 | BC-01 | Enterprise Architecture | VersionPrecedence | Source version pins the decision; readiness layer never re-versions a source record. | FROZEN_ARCHITECTURAL_INVARIANT | NOT_SUPPLIED | NONE | NOT_ASSESSED | Precedence unconfirmed by source owners. |
| Q-W1-06 | ER-06 | BC-01 | IT / IM | ReadAuthority | Readiness layer reads source records under source-owner authority only. | DESIGN_ASSERTION | NOT_SUPPLIED | NONE | NOT_ASSESSED | No authorization decision exists. |
| Q-W1-07 | ER-06 | BC-01 | IT / IM | WriteAuthority | No write-back to any source system in the Pilot. | FROZEN_ARCHITECTURAL_INVARIANT | NOT_SUPPLIED | NONE | NOT_ASSESSED | Boundary unconfirmed operationally. |
| Q-W1-08 | ER-06 | BC-01 | IT / IM | SnapshotAuthority | Snapshot federation is permitted where API is unavailable. | PROPOSED_RULE | NOT_SUPPLIED | NONE | NOT_ASSESSED | Snapshot route unapproved. |
| Q-W1-09 | ER-06 | BC-01 | IT / IM | FailureBehaviour | Source unavailable ⇒ fail-closed; readiness degrades to HOLD, never inferred pass. | FROZEN_ARCHITECTURAL_INVARIANT | NOT_SUPPLIED | NONE | NOT_ASSESSED | Detection capability unevidenced. |
| Q-W1-10 | ER-07 | BC-02 | IAM / Cyber | EnterpriseIdentityProvider | A single enterprise IdP is assumed for Pilot identities. | CANDIDATE_AUTHORITY | NOT_SUPPLIED | NONE | NOT_ASSESSED | IdP unnamed. |
| Q-W1-11 | ER-07 | BC-02 | IAM / Cyber | AuthenticationMechanism | Federated SSO assumed; protocol not selected by the design team. | TO_BE_VALIDATED | NOT_SUPPLIED | NONE | NOT_ASSESSED | Protocol unstated — no assumption permitted. |
| Q-W1-12 | ER-07 | BC-02 | IAM / Cyber | RoleSource | Role is resolved from an enterprise role source, distinct from identity. | FROZEN_ARCHITECTURAL_INVARIANT | NOT_SUPPLIED | NONE | NOT_ASSESSED | Role source unnamed. |
| Q-W1-13 | ER-07 | BC-02 | IAM / Cyber | CompetencySource | Competency validity is sourced externally and expires deterministically. | CANDIDATE_SOURCE | NOT_SUPPLIED | NONE | NOT_ASSESSED | Competency source unconfirmed. |
| Q-W1-14 | ER-07 | BC-02 | IAM / Cyber | AuthoritySource | DecisionAuthority is separate from permission and is resolved per object. | FROZEN_ARCHITECTURAL_INVARIANT | NOT_SUPPLIED | NONE | NOT_ASSESSED | Separation unvalidated by IAM. |
| Q-W1-15 | ER-07 | BC-02 | IAM / Cyber | Delegation / Revocation | Delegation is time-bounded and revocable; revocation is immediate and attributable. | PROPOSED_RULE | NOT_SUPPLIED | NONE | NOT_ASSESSED | Mechanisms unevidenced. |
| Q-W1-16 | ER-07 | BC-02 | IAM / Cyber | AuthorityUnavailableBehaviour | AuthorityResolutionState = UNRESOLVED ⇒ fail-closed, no default grant. | FROZEN_ARCHITECTURAL_INVARIANT | NOT_SUPPLIED | NONE | NOT_ASSESSED | Confirmation absent. |
| Q-W1-17 | ER-11 | BC-03 | Business Product Owner | LifecycleOwner | Each governed object has one accountable lifecycle owner. | DESIGN_ASSERTION | NOT_SUPPLIED | NONE | NOT_ASSESSED | Owners unnamed. |
| Q-W1-18 | ER-11 | BC-03 | Business Product Owner | AllowedStates / Transitions | State sets and transitions are declared per object in the Phase 5 baseline. | FROZEN_ARCHITECTURAL_INVARIANT | NOT_SUPPLIED | NONE | NOT_ASSESSED | Acceptance not recorded. |
| Q-W1-19 | ER-11 | BC-03 | Business Product Owner | TransitionAuthority / SoD | Transition authority is role-bound with segregation of duties on authorization. | PROPOSED_RULE | NOT_SUPPLIED | NONE | NOT_ASSESSED | Matrix unissued. |
| Q-W1-20 | ER-11 | BC-03 | Business Product Owner | AI Boundary | AI assists; AI holds no authority and satisfies no material criterion. | FROZEN_ARCHITECTURAL_INVARIANT | NOT_SUPPLIED | NONE | NOT_ASSESSED | Confirmation absent. |
| Q-W1-21 | ER-11 | BC-03 | Business Product Owner | DecisionReconstruction | Every transition is reconstructable from pinned inputs and authority state. | DESIGN_EVIDENCE | NOT_SUPPLIED | NONE | NOT_ASSESSED | Not validated by the accountable business owner. |
| Q-W1-22 | ER-16 | BC-05 | Records Management | DataClassification | CA-04 record classes are proposed for readiness decisions and evidence. | PROPOSED_RULE | NOT_SUPPLIED | NONE | NOT_ASSESSED | No classification decision issued. |
| Q-W1-23 | ER-16 | BC-05 | Records Management | RetentionBasis | Retention aligned to decision reconstruction needs. | DESIGN_ASSERTION | NOT_SUPPLIED | NONE | NOT_ASSESSED | Retention basis unstated. |
| Q-W1-24 | ER-16 | BC-05 | Records Management | Custodian | Custodianship assumed to remain with the source function. | CANDIDATE_AUTHORITY | NOT_SUPPLIED | NONE | NOT_ASSESSED | Custodians unnamed. |
| Q-W1-25 | ER-16 | BC-05 | Records Management | ReconstructionRequirements | Decision pin retains references, not full source records. | FROZEN_ARCHITECTURAL_INVARIANT | NOT_SUPPLIED | NONE | NOT_ASSESSED | Confirmation absent. |
| Q-W1-26 | ER-17 | BC-05 | Privacy / Data Protection | DataMinimisation | Only validity flags and references are held for HR/Health-derived facts. | FROZEN_ARCHITECTURAL_INVARIANT | NOT_SUPPLIED | NONE | NOT_ASSESSED | No privacy decision exists. |
| Q-W1-27 | ER-17 | BC-05 | Privacy / Data Protection | AccessScope | Access is scoped by role and location context. | PROPOSED_RULE | NOT_SUPPLIED | NONE | NOT_ASSESSED | Scope undecided. |
| Q-W1-28 | ER-17 | BC-05 | Privacy / Data Protection | SemanticAuthority | Semantic proposals are never consumed without human validation. | FROZEN_ARCHITECTURAL_INVARIANT | NOT_SUPPLIED | NONE | NOT_ASSESSED | Unconfirmed. |
| Q-W1-29 | ER-19 | BC-06 | NOT_CONFIRMED — ES&H Executive proposed | PathAorPathBDecision | Critical Control participation remains SIMULATED pending a competent election. | TO_BE_VALIDATED | NOT_SUPPLIED | NONE | NOT_ASSESSED | No competent authority has accepted the election; ESC-03 active. Not an intake request in this Wave. |
D · Owner Acknowledgement Register
No state may be skipped. A response of "Yes, confirmed" is an acknowledgement, not evidence, and never a closure.
- · AWAITING_OWNER → OWNER_ACKNOWLEDGED
- · OWNER_ACKNOWLEDGED → EVIDENCE_SUBMITTED
- · EVIDENCE_SUBMITTED → UNDER_EVIDENCE_REVIEW
- · UNDER_EVIDENCE_REVIEW → ACCEPTED | ACCEPTED_WITH_LIMITATION | INSUFFICIENT | OUTDATED | OUT_OF_SCOPE | CONTRADICTORY
- · Competent authority demonstrated
- · Scope stated and applicable
- · Traceable basis (reference, version, date)
- · Applicable artefact or governed confirmation attached
- · Acceptance criterion coverage shown explicitly
E · Evidence Intake Register
Owner confirmation must explicitly demonstrate the applicable criterion. Document presence alone creates neither classification nor sufficiency.
- · OPERATIONAL_CLOSURE_EVIDENCE — Competent, current, in-scope artefact or governed decision that demonstrates an acceptance criterion.
- · SUPPORTING_EVIDENCE — Relevant and attributable, but does not by itself demonstrate a criterion.
- · CONTRADICTORY_EVIDENCE — Materially conflicts with the frozen baseline or another accepted artefact.
- · NOT_APPLICABLE_EVIDENCE — Attributable but outside the ApplicableScope of the request.
- · DESIGN_EVIDENCE / SIMULATION_EVIDENCE — Existing internal material. Never upgraded because an owner has seen it.
F · Seven-Check Assessment Queue
Missing evidence is NOT_DEMONSTRATED, never FAIL. FAIL is reserved for evidence that is present and fails the check.
- · AUTHENTIC — Issued by the named owner through an attributable channel.
- · CURRENT — Within its stated validity window and not superseded.
- · IN_SCOPE — Addresses the ApplicableScope of the request, not an adjacent topic.
- · OWNER_COMPETENT — The issuing function actually holds the authority claimed.
- · TRACEABLE — Carries a reference, version and date that can be reconstructed later.
- · SUFFICIENT_FOR_CRITERION — Satisfies the MinimumAcceptableEvidence of this request.
- · NO_MATERIAL_CONTRADICTION — Does not conflict with the frozen architecture or another accepted artefact.
G · Evidence Quality View
EvidenceQuality is updated only after a completed seven-check assessment, never on receipt.
- · NONE — No competent operational evidence received.
- · PARTIAL — Some criteria satisfied; the blocker cannot yet be retested.
- · SUFFICIENT_FOR_RETEST — Enough to attempt a targeted retest — not closure.
- · SUFFICIENT_FOR_CLOSURE — Retest passed and every acceptance criterion is evidenced.
| Blocker | Evidence quality | OperationalClosureEvidence | SupportingEvidence | Blocker state | Retest eligibility |
|---|---|---|---|---|---|
| BC-01 | NONE | 0 | 0 | OPEN | NOT_ELIGIBLE |
| BC-02 | NONE | 0 | 0 | OPEN | NOT_ELIGIBLE |
| BC-03 | NONE | 0 | 0 | OPEN | NOT_ELIGIBLE |
| BC-05 | NONE | 0 | 0 | OPEN | NOT_ELIGIBLE |
| BC-06 | NONE | 0 | 0 | OPEN | NOT_ELIGIBLE |
H · BC-01 Evidence View — Source participation & object authority
Object-level authority is preserved. No single system may be converted into a universal System of Record.
| Dimension | Owner evidence | Assessment |
|---|---|---|
| ObjectClass | NOT_SUPPLIED | NOT_DEMONSTRATED |
| AuthoritativeSource | NOT_SUPPLIED | NOT_DEMONSTRATED |
| SourceOwner | NOT_SUPPLIED | NOT_DEMONSTRATED |
| ParticipationMode | NOT_SUPPLIED | NOT_DEMONSTRATED |
| ReadAuthority | NOT_SUPPLIED | NOT_DEMONSTRATED |
| WriteAuthority | NOT_SUPPLIED | NOT_DEMONSTRATED |
| SnapshotAuthority | NOT_SUPPLIED | NOT_DEMONSTRATED |
| VersionPrecedence | NOT_SUPPLIED | NOT_DEMONSTRATED |
| FailureBehaviour | NOT_SUPPLIED | NOT_DEMONSTRATED |
I · BC-02 Evidence View — Identity, role, authority resolution
Identity ≠ Role ≠ Permission ≠ DecisionAuthority. No protocol is assumed until the IAM owner confirms it.
| Dimension | Owner evidence | Assessment |
|---|---|---|
| EnterpriseIdentityProvider | NOT_SUPPLIED | NOT_DEMONSTRATED |
| AuthenticationMechanism | NOT_SUPPLIED | NOT_DEMONSTRATED |
| RoleSource | NOT_SUPPLIED | NOT_DEMONSTRATED |
| CompetencySource | NOT_SUPPLIED | NOT_DEMONSTRATED |
| AuthoritySource | NOT_SUPPLIED | NOT_DEMONSTRATED |
| Delegation | NOT_SUPPLIED | NOT_DEMONSTRATED |
| Revocation | NOT_SUPPLIED | NOT_DEMONSTRATED |
| AuthorityUnavailableBehaviour | NOT_SUPPLIED | NOT_DEMONSTRATED |
J · BC-03 Evidence View — Object lifecycle governance
AI assistance only — no AI authority. AI may not satisfy any material authority criterion.
| Dimension | Owner evidence | Assessment |
|---|---|---|
| LifecycleOwner | NOT_SUPPLIED | NOT_DEMONSTRATED |
| AllowedStates | NOT_SUPPLIED | NOT_DEMONSTRATED |
| AllowedTransitions | NOT_SUPPLIED | NOT_DEMONSTRATED |
| TransitionAuthority | NOT_SUPPLIED | NOT_DEMONSTRATED |
| Delegation | NOT_SUPPLIED | NOT_DEMONSTRATED |
| SegregationOfDuties | NOT_SUPPLIED | NOT_DEMONSTRATED |
| AuthorityUnavailableBehaviour | NOT_SUPPLIED | NOT_DEMONSTRATED |
| DecisionReconstruction | NOT_SUPPLIED | NOT_DEMONSTRATED |
K · BC-05 Evidence View — Data classification, minimisation & retention
Full HR/Health source records are not copied into the intake layer unless explicitly required by a competent governance decision.
| Dimension | Owner evidence | Assessment |
|---|---|---|
| DataClassification | NOT_SUPPLIED | NOT_DEMONSTRATED |
| DataMinimisation | NOT_SUPPLIED | NOT_DEMONSTRATED |
| DecisionPin | NOT_SUPPLIED | NOT_DEMONSTRATED |
| SemanticAuthority | NOT_SUPPLIED | NOT_DEMONSTRATED |
| AccessScope | NOT_SUPPLIED | NOT_DEMONSTRATED |
| RetentionBasis | NOT_SUPPLIED | NOT_DEMONSTRATED |
| Custodian | NOT_SUPPLIED | NOT_DEMONSTRATED |
| ReconstructionRequirements | NOT_SUPPLIED | NOT_DEMONSTRATED |
L · BC-06 Evidence View — Critical Control participation
BC-06 remains OPEN until real owner evidence determines PATH_A_REAL_PARTICIPATION or PATH_B_FORMAL_RESCOPE. Path A is never inferred from prototype behaviour; ESC-03 remains active.
| Dimension | Owner evidence | Assessment |
|---|---|---|
| CriticalControlSource | NOT_SUPPLIED | NOT_DEMONSTRATED |
| CriticalControlObject | NOT_SUPPLIED | NOT_DEMONSTRATED |
| ParticipationMode | NOT_SUPPLIED | NOT_DEMONSTRATED |
| ValidityCriterion | NOT_SUPPLIED | NOT_DEMONSTRATED |
| FailureBehaviour | NOT_SUPPLIED | NOT_DEMONSTRATED |
| PathAorPathBDecision | NOT_SUPPLIED | NOT_DEMONSTRATED |
| CompetentAuthority | NOT_SUPPLIED | NOT_DEMONSTRATED |
M · Contradiction Register & Authority Disputes
A contradiction is recorded, classified and routed for decision. Architecture is never reopened automatically; ARCHITECTURE_IMPACT requires an explicit architecture governance decision.
An authority dispute is governance evidence, preserved verbatim and routed to ESC-01…ESC-04. It is never recorded as blocker failure and never resolved by appointing a substitute owner.
| ER | Competent owner | If owner states | Classified as | Routed to |
|---|---|---|---|---|
| ER-01 | Enterprise Architecture | NOT_MY_AUTHORITY / PARTIAL_AUTHORITY | OWNER_AUTHORITY_DISPUTED | ESC-02 |
| ER-06 | IT / IM | NOT_MY_AUTHORITY / PARTIAL_AUTHORITY | OWNER_AUTHORITY_DISPUTED | ESC-02 |
| ER-07 | IAM / Cyber | NOT_MY_AUTHORITY / PARTIAL_AUTHORITY | OWNER_AUTHORITY_DISPUTED | ESC-02 |
| ER-11 | Business Product Owner | NOT_MY_AUTHORITY / PARTIAL_AUTHORITY | OWNER_AUTHORITY_DISPUTED | ESC-02 |
| ER-16 | Records Management | NOT_MY_AUTHORITY / PARTIAL_AUTHORITY | OWNER_AUTHORITY_DISPUTED | ESC-02 |
| ER-17 | Privacy | NOT_MY_AUTHORITY / PARTIAL_AUTHORITY | OWNER_AUTHORITY_DISPUTED | ESC-02 |
N · Targeted Retest Eligibility Queue
A blocker becomes ELIGIBLE_FOR_TARGETED_RETEST only when EvidenceQuality = SUFFICIENT_FOR_RETEST. Preparation is never execution; no retest executes automatically and no synthetic evidence may trigger one.
O · Evidence Timeline (Append-Only)
Append-only. Entries are never edited or deleted; corrections are appended as EVIDENCE_CORRECTION events so that decision reconstruction remains possible.
| Timestamp | ER | Event | Actor | Evidence ref | Previous | New | Reason |
|---|---|---|---|---|---|---|---|
| 2026-08-31T00:00:00Z | ALL (ER-01 / ER-06 / ER-07 / ER-11 / ER-16 / ER-17) | OWNER_EVIDENCE_INTAKE_ACTIVATED | Assurance Control Room (orchestration only) | PH6A-W1-OEAVQ-REV1 | AWAITING_OWNER | AWAITING_OWNER | Intake mechanism linked to the six existing Wave 1 requests. Activation is not progress; no acknowledgement or artefact received. |
When evidence is received, only the affected ER, its related questions, the affected BC, the dependent retest trigger, the relevant escalation and the evidence history are updated. /board, /erx, /wave1 and /s1 are never re-run in full and all prior history is preserved.
P · Owner Evidence Dashboard
No readiness percentage is displayed. Counts describe evidence position only and can never be aggregated into progress against Phase 6A.
- · No owner acknowledgement invented.
- · No evidence invented; no synthetic OperationalClosureEvidence.
- · Questionnaire Baseline unaltered; Simulation Baseline remains frozen.
- · No blocker closed; no targeted retest executed.
- · Phase 6A Integrated Revalidation not started; Phase 6B not started; Phase 7 not started.
- · BC09Protection unchanged (ACTIVE); PilotExposure remains PROHIBITED.
RequestsLinked 6 · AwaitingOwner 6 · OwnerAcknowledged 0 · EvidenceSubmitted 0 · EvidenceUnderReview 0 · SufficientForRetest 0 · RetestsPrepared 0 · BC-01 / BC-02 / BC-03 / BC-05 / BC-06 = OPEN
Lovable orchestrates evidence; competent owners establish authority; authoritative systems establish fact; targeted retests establish operational confidence; only Phase 6A Integrated Revalidation can establish GO.
Deep Evidence Assessment Protocol — Rev.1
Seven-Check Admission + Seven-Test Deep Assurance · native to PH6A-AHP-REV1.1
DEAP is an assurance capability of the Evidence Engine. It admits, qualifies and traces evidence against criteria. It never authorizes work, never sets operational state and never creates authority.
DEAP AExecutive Integration View
The Deep Evidence Assessment Protocol is integrated as a native assurance capability inside Owner Evidence Intake. It layers evidence admission (A1–A7) ahead of deep assurance (D1–D7), binds every result to a specific acceptance criterion rather than to a document, derives EvidenceQuality by rule rather than by arithmetic, and hands only qualified evidence states to the Decision Engine. No blocker closes, no request state advances and no owner artefact exists.
- · Criterion-scoped assessment: an artefact may be SUFFICIENT for one criterion, PARTIAL for another and NOT_APPLICABLE for a third.
- · A hard sequencing rule: Layer 2 deep assurance runs only after Layer 1 returns ADMISSIBLE or ADMISSIBLE_WITH_LIMITATION.
- · Missing evidence is NOT_DEMONSTRATED — never FAIL — so absence is never scored as a defect of the owner.
- · Rule-versioned assessment history: a rule change never rewrites a historical assessment; it creates a new assessment event.
- · Six Wave 1 evidence requests remain exactly six; no request is added, split or retired.
- · The frozen questionnaire baseline PH6A-W1-OEAVQ-REV1 is read-only to DEAP.
- · Every blocker closure predicate remains UNSATISFIED and every request remains AWAITING_OWNER.
DEAP BArchitecture Reuse Map
DEAP is not a parallel framework. Any DEAP-local re-definition of a hardened core object would be an ARCHITECTURE_IMPACT change, not a configuration change.
| Hardened object | Origin | DEAP use | Duplicated |
|---|---|---|---|
| FactTypeSystem (6 classes) | /ahp §C | Classifies every assessment input and output; promotion between classes is prohibited. | NO |
| EvidenceEngine / DecisionEngine / AuthorityEngine | /ahp §D | DEAP executes inside the Evidence Engine only; it queries the Authority Engine and emits inputs to the Decision Engine. | NO |
| EvidenceCriterionAssessment | /ahp §K | The single assessment record type; DEAP adds Layer1Disposition and Layer2Results as populated fields, not a new type. | NO |
| BlockerClosurePredicate | /ahp §L | Sole closure mechanism; DEAP supplies predicate operands and never a closure verdict. | NO |
| GovernedOperationalEvent | /ahp §F | Carries all evidence-state changes as assurance events, distinguished by EventDomain = ASSURANCE. | NO |
| RuleVersion register | /ahp §G | DEAP rules DEAP-R-01…DEAP-R-06 are registered entries with owner and approval reference. | NO |
| ProvenanceChain | /ahp §Q | Every assessment result must reconstruct through the existing chain nodes. | NO |
| ReasonCode | /ahp §P | DEAP dispositions reference existing reason codes; negative owner responses map to codes, not to new taxonomies. | NO |
| DecisionRight | /ahp §V | Queried read-only for the D1 AUTHORITY test; never created or modified. | NO |
| CanonicalSemanticDictionary | /ahp §H | Drives the D5 SEMANTIC_CONSISTENCY test and SourceTerm → CanonicalTerm mapping. | NO |
| AI_TO_RULE_FIREWALL | /ahp §I | Bounds AI participation to advisory provenance only. | NO |
| Determinism contract | /ahp §R | Extended in scope to assessment outcomes; the contract itself is unchanged. | NO |
- · No Deep Evidence assessment may silently promote one fact class into another.
- · EvidenceAccepted ≠ AuthorizedDecision — admission is a statement about a criterion, not about work.
- · AI_ADVISORY_OUTPUT ≠ EvidenceFact unless stored solely as advisory provenance attached to a deterministic assessment.
- · DERIVED_FACT carries the RuleVersion that derived it; without it the derivation is not reconstructable and the assessment is NOT_DEMONSTRATED.
EvidenceEngine ≠ DecisionEngine ≠ AuthorityEngine (frozen)
DEAP CLayer 1 — Evidence Admission
Missing evidence is NOT_DEMONSTRATED, not FAIL. FAIL is reserved for evidence that is present and materially contradicts, misattributes or invalidates the criterion.
| ID | Check | Assessment question | Mandatory | NOT_DEMONSTRATED means |
|---|---|---|---|---|
| A1 | AUTHENTIC | Does the artefact originate from the stated source and owner, by an owner-confirmed mechanism? | YES | Origin not yet stated — evidence gap, not a defect. |
| A2 | CURRENT | Is the artefact effective for the assessed period, with an EffectiveTimestamp or revision? | YES | No effectivity supplied; currency cannot be judged. |
| A3 | IN_SCOPE | Does the artefact address the object class, process or population of the criterion? | YES | Scope relationship not yet established. |
| A4 | OWNER_COMPETENT | Is the responding owner competent for the assertion made (queried from the Authority Engine)? | YES | Competence not asserted; DEAP may not infer it and AI may never mark it. |
| A5 | TRACEABLE | Can the artefact be reconstructed to a source record by any owner-confirmed reference mechanism? | YES | No reference mechanism supplied yet. |
| A6 | SUFFICIENT_FOR_CRITERION | Does the artefact demonstrate this specific criterion, not the topic in general? | YES | Criterion coverage not yet demonstrated. |
| A7 | NO_MATERIAL_CONTRADICTION | Is the artefact free of material conflict with other authoritative evidence? | YES | No comparison population exists yet. |
All seven checks PASS.
No FAIL; at least one PASS_WITH_LIMITATION; every mandatory check demonstrated.
Any FAIL, or a mandatory check NOT_DEMONSTRATED. NOT_ADMISSIBLE is a state of the evidence, never a judgement of the owner.
DEAP DLayer 2 — Deep Assurance
Layer 2 executes only where Layer 1 returned ADMISSIBLE or ADMISSIBLE_WITH_LIMITATION. Deep assurance uses the same four states and no numerical scoring; a weighted or averaged result would be a no-compensation violation.
| ID | Check | Assessment question | Mandatory | NOT_DEMONSTRATED means |
|---|---|---|---|---|
| D1 | AUTHORITY | Is the asserted decision right real, valid, delegable and currently held? | YES | Authority Engine query returns UNRESOLVED — capability stays DISABLED_SAFE. |
| D2 | SOURCE_INTEGRITY | Is the authoritative source confirmed by its owner, and is the participation mode governed? | YES | Source remains CANDIDATE_SOURCE. |
| D3 | TEMPORAL_VALIDITY | Is validity, expiry and re-verification behaviour defined for the fact, not only for the document? | YES | Validity window not yet owner-confirmed. |
| D4 | BOUNDARY_MINIMISATION | Is the data exchanged the minimum decision fact, with privacy and classification boundaries respected? | CONDITIONAL | Boundary not yet described; assessed against BC-05. |
| D5 | SEMANTIC_CONSISTENCY | Do source terms map to canonical terms with a recorded TransformationRule and SemanticOwner? | YES | Mapping absent → SEMANTIC_MAPPING_REQUIRED. |
| D6 | TRACEABILITY | Is the full ProvenanceChain reconstructable, including the rule version where a derivation occurred? | YES | Chain incomplete; the assessment cannot be relied upon for retest. |
| D7 | FAILURE_BEHAVIOUR | Is the owner-confirmed behaviour on source unavailability or control non-verifiability defined and bounded to affected scope? | YES | Failure behaviour not yet confirmed; fail-closed default applies to design only. |
DEAP EEvidenceCriterionAssessment
Never assign one global quality to an artefact without criterion context. The same artefact may be SUFFICIENT for Criterion A, PARTIAL for Criterion B and NOT_APPLICABLE for Criterion C, each with its own provenance and rule version.
DEAP FEvidence Quality Aggregation
EvidenceQuality = product(C1…C7), weighted averages, percentages and readiness scores are prohibited. Aggregation is rule-based and non-compensable: a single unmet mandatory criterion cannot be offset by strength elsewhere.
No operational evidence has been assessed against any criterion of the request.
Some criteria are demonstrated, but one or more mandatory criteria remain NOT_DEMONSTRATED, PASS_WITH_LIMITATION or otherwise incomplete.
All mandatory pre-retest criteria demonstrated; no material FAIL; no unresolved material contradiction; required authority established; required provenance reconstructable.
Evidence plus the applicable targeted retest satisfy the blocker closure predicate in full.
| ER | BC | Competent owner | Criteria assessed | Mandatory demonstrated | EvidenceQuality | Basis |
|---|---|---|---|---|---|---|
| ER-01 | BC-01 | Enterprise Architecture | 0 | 0 | NONE | No operational closure evidence assessed; the request remains AWAITING_OWNER. |
| ER-06 | BC-01 | IT / IM | 0 | 0 | NONE | No operational closure evidence assessed; the request remains AWAITING_OWNER. |
| ER-07 | BC-02 | IAM / Cyber | 0 | 0 | NONE | No operational closure evidence assessed; the request remains AWAITING_OWNER. |
| ER-11 | BC-03 | Business Product Owner | 0 | 0 | NONE | No operational closure evidence assessed; the request remains AWAITING_OWNER. |
| ER-16 | BC-05 | Records Management | 0 | 0 | NONE | No operational closure evidence assessed; the request remains AWAITING_OWNER. |
| ER-17 | BC-05 | Privacy | 0 | 0 | NONE | No operational closure evidence assessed; the request remains AWAITING_OWNER. |
DEAP GBlocker Closure Predicate Linkage
- · DocumentReceived → BlockerClosed is prohibited.
- · OwnerAcknowledged → BlockerClosed is prohibited.
- · EvidenceAccepted → BlockerClosed is prohibited.
NoMaterialContradiction is vacuously true only because no evidence population exists; it is not a satisfied operand.
NoMaterialContradiction is vacuously true only because no evidence population exists; it is not a satisfied operand.
NoMaterialContradiction is vacuously true only because no evidence population exists; it is not a satisfied operand.
NoMaterialContradiction is vacuously true only because no evidence population exists; it is not a satisfied operand.
NoMaterialContradiction is vacuously true only because no evidence population exists; it is not a satisfied operand.
- BC-01 — C1 ∧ C2 ∧ C3 ∧ RetestPassed ∧ AuthorityValid ∧ NoMaterialContradiction
- BC-02 — IAM-01 ∧ IAM-02 ∧ IAM-03 ∧ IAM-04 ∧ IAM-05 ∧ IAM-06 ∧ RetestPassed ∧ AuthorityValid
- BC-03 — LifecycleGovernanceDecision ∧ TechnicalEnforcement ∧ RetestPassed ∧ AuthorityValid
- BC-04 — StewardshipAssigned ∧ StewardshipAccepted ∧ AuthorityValid ∧ NoVacancy
- BC-05 — CA04Classification ∧ Retention ∧ DataMinimisation ∧ AuthorityValid
- BC-06 — PathElection(A|B) ∧ DecisionAuthorityRecorded ∧ ResidualRiskRecorded
- BC-07 — L1 ∧ L2 ∧ L3 support model ∧ DrillEvidence ∧ AuthorityValid
- BC-08 — FieldPrerequisites(all dimensions) ∧ RetestPassed ∧ AuthorityValid
- BC-09 — ProspectiveBaselineStarted ∧ MetricSourcesConfirmed ∧ NoContaminationEvent
DEAP HProvenance Chain View
No single technical identifier is mandated. Traceability is satisfied by any owner-confirmed mechanism that permits reconstruction; requiring a specific technology would be a preselected implementation and is prohibited.
Assessment ← Criterion ← Evidence ← SourceRecord ← SourceSystemOrProcess ← SourceOwner ← EffectiveTimestamp ← RuleVersion (where a derivation occurred).
DEAP IGoverned Evidence Events
EventDomain = ASSURANCE. These events must never be read as operational work authorization events; they carry no operational state transition and no authorization semantics.
| At | Event | ER | Actor | Detail |
|---|---|---|---|---|
| 2026-08-31T00:00Z | PROTOCOL_INTEGRATED | — | Assurance configuration (no owner attribution) | PH6A-W1-DEAP-REV1 integrated over PH6A-AHP-REV1.1. No evidence event has occurred. |
DEAP JRule Versioning
Assessment history preserves the exact rule and configuration version used. Historical evidence is never silently recalculated after a rule update; re-assessment creates a new assessment event linked to the new version, with the prior result retained.
| Rule | Version | Statement | Effective | Config | Owner | Approval |
|---|---|---|---|---|---|---|
| DEAP-R-01 | 1.0 | Layer 1 admission disposition derivation (A1–A7 → ADMISSIBLE / ADMISSIBLE_WITH_LIMITATION / NOT_ADMISSIBLE). | 2026-08-31 → OPEN | CFG-DEAP-1.0 | Assurance Rule Owner | PH6A-W1-DEAP-REV1 §5 |
| DEAP-R-02 | 1.0 | Layer 2 sequencing: deep assurance executes only on admissible evidence. | 2026-08-31 → OPEN | CFG-DEAP-1.0 | Assurance Rule Owner | PH6A-W1-DEAP-REV1 §5 |
| DEAP-R-03 | 1.0 | Criterion-scoped sufficiency: SUFFICIENT / PARTIAL / NOT_DEMONSTRATED / NOT_APPLICABLE per Evidence × Criterion pair. | 2026-08-31 → OPEN | CFG-DEAP-1.0 | Assurance Rule Owner | PH6A-W1-DEAP-REV1 §6 |
| DEAP-R-04 | 1.0 | ER-level EvidenceQuality aggregation, non-arithmetic and non-compensable. | 2026-08-31 → OPEN | CFG-DEAP-1.0 | Assurance Rule Owner | PH6A-W1-DEAP-REV1 §7 |
| DEAP-R-05 | 1.0 | Negative and limiting owner response classification (§19 mapping). | 2026-08-31 → OPEN | CFG-DEAP-1.0 | Governance Owner | PH6A-W1-DEAP-REV1 §19 |
| DEAP-R-06 | 1.0 | Targeted retest eligibility gate: eligible only at EvidenceQuality = SUFFICIENT_FOR_RETEST. | 2026-08-31 → OPEN | CFG-DEAP-1.0 | Assurance Rule Owner | PH6A-W1-DEAP-REV1 §22 |
DEAP KCanonical Semantic Mapping
Source terminology differs and no owner-approved TransformationRule exists.
Source terminology asserts a canonical meaning the source cannot support (e.g. Approved rendered as Authorized).
DEAP LER-01 Assessment View — BC-01
Competent owner: Enterprise Systems / Object Authority Owner
DEAP MER-06 Assessment View — BC-02
Competent owner: Enterprise IAM / Identity Authority Owner
DEAP NER-07 Assessment View — BC-02
Competent owner: People & Training / Competency Data Owner
DEAP OER-11 Assessment View — BC-03
Competent owner: Work Control Lifecycle Authority Owner
DEAP PER-16 Assessment View — BC-03 + BC-05
Competent owner: Data Governance / Records Authority Owner
DEAP QER-17 Assessment View — BC-06
Competent owner: Critical Control / Fatal Risk Authority Owner
DEAP RNegative / Limiting Response Handling
None of these responses automatically closes or fails a blocker. A limiting response is information about the operating reality, and is assessed against the criterion like any other evidence.
| Owner response | DEAP handling | Closes blocker |
|---|---|---|
| NOT_MY_AUTHORITY | GOVERNANCE_EVIDENCE — routed to authority dispute; the statement itself is evidence about the authority map. | NO |
| SOURCE_NOT_AUTHORITATIVE | EVIDENCE_CORRECTION / POTENTIAL_CONTRADICTION — raises a Contradiction_ID against the assumed source. | NO |
| NO_LIVE_INTEGRATION | Evaluate CONTROLLED_SNAPSHOT / CONTROLLED_MANUAL_FEDERATION / OTHER_GOVERNED_MODE as valid participation modes. | NO |
| DATA_NOT_AVAILABLE | EVIDENCE_GAP — criterion remains NOT_DEMONSTRATED; never FAIL. | NO |
| CONTROL_NOT_VERIFIABLE | Apply the owner-confirmed failure behaviour to the owner-confirmed affected scope. | NO |
| PATH_B_REQUIRED | GOVERNANCE_DECISION_CANDIDATE — recorded for BC-06 Path A/B decision authority; never selected by DEAP. | NO |
DEAP SAI Boundary
All AI output is stored as AI_ADVISORY_OUTPUT with advisory provenance only. AI-generated explanation text is excluded from the deterministic outcome and cannot alter an assessment state.
- · Evidence summarisation
- · Gap identification
- · Semantic comparison
- · Draft assessment rationale
- · Mark OWNER_COMPETENT
- · Create DecisionRight
- · Change the authoritative source
- · Promote evidence to OperationalClosureEvidence without deterministic assessment
- · Execute blocker closure
- · Execute operational authorization
SameEvidence + SameCriterion + SameRuleVersion + SameConfiguration = SameAssessment
AI-generated explanation text is excluded from the deterministic outcome comparison. Violation code: DETERMINISM_VIOLATION. Status: VERIFIED_IN_DESIGN — evidenced by DEAP-R10; operational verification requires real evidence.
DEAP TTargeted Retest Queue
A criterion or ER becomes eligible for targeted retest only at EvidenceQuality = SUFFICIENT_FOR_RETEST. Preparation sets RetestStatus = PREPARED; execution is never automatic and always requires named participants and competent authority.
DEAP UDEAP Integration Regression
SIMULATION_EVIDENCE — integration verification only; closes no blocker and demonstrates no operational fact.
| ID | Scenario | Expected | Observed | Result |
|---|---|---|---|---|
| DEAP-R01 | Criterion with no submitted artefact | NOT_DEMONSTRATED, not FAIL | Layer 1 returned NOT_DEMONSTRATED on A1–A7; disposition NOT_ADMISSIBLE with reason EVIDENCE_GAP | PASS |
| DEAP-R02 | Competent owner supplies partial coverage of mandatory criteria | EvidenceQuality = PARTIAL | Two criteria SUFFICIENT, one mandatory NOT_DEMONSTRATED → PARTIAL; no promotion | PASS |
| DEAP-R03 | One artefact supports Criterion A but not Criterion B | Independent per-criterion results | SUFFICIENT for A, NOT_DEMONSTRATED for B, NOT_APPLICABLE for C — three ECA records, one artefact | PASS |
| DEAP-R04 | Evidence admitted at ADMISSIBLE | No work authorization | No operational state emitted; Decision Engine received a qualified evidence input only | PASS |
| DEAP-R05 | Owner acknowledges without submitting artefact | EvidenceQuality unchanged | OWNER_ACKNOWLEDGED event emitted; quality remained NONE | PASS |
| DEAP-R06 | Two authoritative owners assert conflicting source authority | Contradiction_ID raised | A7 FAIL, Contradiction_ID created and routed to the dispute register; no blocker verdict | PASS |
| DEAP-R07 | Owner states NO_LIVE_INTEGRATION | Path B not forced | Controlled snapshot and manual governed federation evaluated as valid participation modes | PASS |
| DEAP-R08 | AI recommends OWNER_COMPETENT | Authority criterion unsatisfied | Firewall rejected the promotion; output retained as AI_ADVISORY_OUTPUT; D1 remained NOT_DEMONSTRATED | PASS |
| DEAP-R09 | All but one mandatory criterion satisfied | Blocker cannot close | MandatoryCriteriaSatisfied = false → predicate UNSATISFIED; no compensation applied | PASS |
| DEAP-R10 | Re-run identical evidence, criterion, rule version and configuration | Identical assessment | Identical dispositions and sufficiency; only advisory narrative text differed and is excluded | PASS |
| DEAP-R11 | Rule version incremented after an assessment | History preserved | Prior assessment retained against v1.0; re-assessment created a new event against v1.1 | PASS |
| DEAP-R12 | Evidence reaches SUFFICIENT_FOR_RETEST | Retest prepared, not executed | RetestStatus = PREPARED with participants and expected invariant; no execution triggered | PASS |
DEAP VIntegration Findings Register
Any ARCHITECTURE_DEFECT, STATE_MODEL_DEFECT or material AUTHORITY_DEFECT returns DEAP_INTEGRATION_HOLD. Findings are never erased, overwritten or silently resolved by integration.
Provenance view rendered an advisory node without its SemanticOwner label; the underlying chain was complete.
Governed operating validity remains TO_BE_GOVERNED for several object classes; configuration cannot be owner-approved before BC-05 evidence exists.
Approved (source transactional) and Authorized (competent authority act) were previously conflated in narrative surfaces.
Mandatory-criterion designation per ER is derived from the frozen questionnaire acceptance criteria and has not yet been owner-approved as configuration.
ER-level quality tiles necessarily read NONE for every request, which can be misread as an owner failure rather than an absence of submission.
DEAP WChange History & Freeze
Protocol acceptance criteria are frozen before the first real evidence assessment. No silent change of acceptance criteria after evidence receipt; historical assessments remain linked to their original RuleVersion and ConfigurationVersion.
Two-layer assessment, criterion-scoped ECA population, rules DEAP-R-01…06 at v1.0, configuration CFG-DEAP-1.0.
State impact: NONE — no request state, evidence quality, blocker predicate or phase state changed.
DEAP XIntegration Acceptance & Final State
- · Evidence demonstrates a criterion; it does not grant authority.
- · Evidence quality belongs to the Evidence × Criterion relationship, not to a document in isolation.
- · Missing evidence is not failure.
- · Accepted evidence cannot directly authorize work.
- · Blockers close through explicit predicates.
- · Assessment rules are versioned and reconstructable.
- · Probabilistic AI may assist interpretation; deterministic governance controls disposition.
FP01-I · Operational Evidence Intake — PH6A Final Prompt 01
EvidenceIntakeRecord is immutable on creation. InitialStatus must be RESPONSE_RECEIVED or EVIDENCE_RECEIVED — never EVIDENCE_ADMITTED. Zero records exist: no owner response or supporting artefact has been received.
SIM-1 · Simulation Evidence Register (non-operational)
Simulation and operational counters are physically separate registers. A simulation intake can never increment an operational counter.
| Evidence ID | OER / Control | Class | Source authority | Eligibility | Disposition |
|---|---|---|---|---|---|
| TEST-EVID-OER02-0001 | OER-02 · BC-06 | SIMULATION_EVIDENCE NOT OPERATIONAL EVIDENCE | CANDIDATE_SOURCE_ONLY | NOT_ELIGIBLE | EVIDENCE_ADMITTED_AS_SUPPORTING_ONLY |