PizarraContexto de trabajoDocumentos y registrosControles críticosRegistrosPreparaciónCondiciones bloqueantesAutorización
Aseguramiento / Técnico
P0ISSUED_AWAITING_OWNERGate impact · EXT-15 -> G-PH6A · Cybersecurity forward link EXT-15 -> future G-FPSO-SEC-01

OER-04EXT-15 — Offline Signature Reconciliation

Validate how offline signatures, authority and object versions are reconciled against current central state without silent promotion of stale authority or stale object versions.

Recipient role
Digital Signature / Records Authority + IT Security Authority
Competent authority status
CLAIMED_BY_DESIGN_NOT_CONFIRMED_BY_OWNER
Scope
Offline field capture and reconciliation within CV-07 pre-start scope.
Request version
OER-04-REV1

Panel A · Design Position — READ ONLY (baseline frozen)

Design position
SignatureEvidence (immutable record of what was signed) is separated from SignatureApplicability (re-evaluated against current authority and object version) and from DecisionRight. On reconciliation, discrepancy produces REASSESS or HOLD — never READY by default.
Design recommendation
Design recommends base-version conflict detection with idempotency keys and explicit re-evaluation of DecisionRight and SignatureApplicability at reconciliation time.
Prohibitions
  • · OFFLINE_RECONCILIATION_CANNOT_SILENTLY_PROMOTE_STALE_AUTHORITY_OR_STALE_OBJECT_VERSION
  • · No silent promotion to READY, no last-write-wins, no silent authority resurrection, no silent version override
  • · No statement of legal signature validity without validated basis
Design Recommendation != Operational Decision. This panel confers no closure.

Panel B · Competent Owner Response

Editable by: Digital Signature / Records Authority only. This panel is never populated automatically, by design authority, or by AI.

AWAITING_OWNERResponses received · 0
Required decisionOwner valueState
OfflineAuthorityEvaluationNOT_PROVIDED — AWAITING_OWNERAWAITING_OWNER
OfflineCredentialValidityNOT_PROVIDED — AWAITING_OWNERAWAITING_OWNER
LocalSignatureEvidenceRuleNOT_PROVIDED — AWAITING_OWNERAWAITING_OWNER
CentralStateReconciliationRuleNOT_PROVIDED — AWAITING_OWNERAWAITING_OWNER
BaseVersionRuleNOT_PROVIDED — AWAITING_OWNERAWAITING_OWNER
VersionConflictBehaviourNOT_PROVIDED — AWAITING_OWNERAWAITING_OWNER
AuthorityRevocationBehaviourNOT_PROVIDED — AWAITING_OWNERAWAITING_OWNER
DecisionRightReevaluationRuleNOT_PROVIDED — AWAITING_OWNERAWAITING_OWNER
SignatureApplicabilityReevaluationRuleNOT_PROVIDED — AWAITING_OWNERAWAITING_OWNER
ConflictEscalationNOT_PROVIDED — AWAITING_OWNERAWAITING_OWNER
RecoveryAuthorityNOT_PROVIDED — AWAITING_OWNERAWAITING_OWNER
EvidenceCustodianNOT_PROVIDED — AWAITING_OWNERAWAITING_OWNER
Enabled only for the competent owner or an explicitly authorized delegate

Panel C · Independent Assurance Use Only

Editable by: Independent Assurance only. Generic digital-signature policy documents do not close EXT-15; all twelve decisions are tracked individually.

AWAITING_OWNERNOT_EVALUABLE_NO_EVIDENCEClosureSufficiency · INSUFFICIENT
CheckQuestionResult
C1 · AuthenticityIs the artefact genuinely from the claimed source and unaltered?NOT_EVALUABLE_NO_EVIDENCE
C2 · AuthorityDoes the submitter hold the competent authority claimed for this decision?NOT_EVALUABLE_NO_EVIDENCE
C3 · ScopeFitDoes the artefact cover the CV-07 pilot scope actually required?NOT_EVALUABLE_NO_EVIDENCE
C4 · VersionValidityIs the artefact the governing version at evaluation time?NOT_EVALUABLE_NO_EVIDENCE
C5 · TemporalValidityIs the fact effective and unexpired at DecisionTime?NOT_EVALUABLE_NO_EVIDENCE
C6 · ContradictionStatusDoes it contradict any other admitted evidence item?NOT_EVALUABLE_NO_EVIDENCE
C7 · ClosureRelevanceDoes it materially bear on the stated closure predicate?NOT_EVALUABLE_NO_EVIDENCE

Admission = Authenticity AND Authority AND ScopeFit AND VersionValidity AND TemporalValidity AND ContradictionClear AND ClosureRelevant. No weighted scoring, no averaging, no compensating controls. One material failure prevents admission. ClosureSufficiency (INSUFFICIENT | SUFFICIENT_FOR_RETEST | SUFFICIENT_FOR_CLOSURE) is evaluated separately — Admission != Closure.

Enabled only for Independent Assurance once evidence exists

Predicates · Closure Predicates & Safe Behaviour

OPENOFFLINE_RECONCILIATION_PRESERVES_AUTHORITY_AND_VERSION_INTEGRITY_UNDER_OWNER_VALIDATED_RULES = TRUE
  • · Material discrepancy => REASSESS or HOLD
  • · Stale authority or stale object version detected => HARD STOP
Related BC / EXT
EXT-15