PizarraContexto de trabajoDocumentos y registrosControles críticosRegistrosPreparaciónCondiciones bloqueantesAutorización
Aseguramiento / Técnico
PizarraContexto de trabajoDocumentos y registrosControles críticosRegistrosPreparaciónCondiciones bloqueantesAutorización
Aseguramiento / Técnico
Phase 5 rev.2 · technical solution definition · option C

Technical Solution Definition — Hybrid / Federated Enterprise Model

Phase 4 Rev.2 is accepted and not reopened. This record determines whether Option C can be industrialized as a technically coherent, governable, resilient and supportable solution. It implements the accepted model; it does not redefine it. This is not production deployment.

Phase 5 recommendation

RECOMMEND ACCEPTANCE WITH CONTROLLED CONDITIONS

Option C can be industrialized as a technically coherent, governable, resilient and supportable solution. Thirteen acceptance conditions are met, two with conditions: enterprise IAM capability validation, and staffed stewardship under ADR-14 / P3-TRN-01. All source interfaces remain NOT_YET_VALIDATED and interface validation is a mandatory precondition to any pilot.

HOLD POINT RESPECTED — no Pilot/MVP work has started. No API, database, deployment or live integration is authorized. Next decision: Technical Solution Definition Acceptance → Controlled Pilot/MVP Authorization.

Pilot preconditions
  • Validate every NOT_YET_VALIDATED interface before pilot scoping
  • Name and staff Location Stewards per area (ADR-14)
  • Resolve or explicitly exclude JobCard (ADR-15) and TemporaryModification (ADR-17) authority from pilot scope
  • Confirm enterprise IAM support for the 7-dimension ABAC model
  • Confirm statutory evidence retention scope (CA-04)

ATarget logical architecture

Integrated Readiness is a bounded decision layer. Enterprise systems retain their objects and transactions. The readiness layer owns only integrated decision context, decision baselines and evidence. Every cross-boundary flow is federated by governed identity mapping — never by replication of an enterprise master.

Federation & Identity Tier

Governed cross-system identity mapping, mapping versions, mapping state machine, conflict detection.

No enterprise master object is created or mastered here.

CONFLICT / UNRESOLVED / missing mandatory mapping fails closed for the dependent decision only.

Source Projection Tier

Read-only projections of source objects with SourceNativeState preserved and NormalizedOperationalState derived under approved mappings.

No authoritative write. No normalization by textual similarity.

Unmapped native state in a decision-critical path yields UNKNOWN → fail closed.

Decision Services Tier

CRE, ECE, PACE, IRDE, EAE, GAE. Deterministic core; no-compensation enforced structurally.

No source-of-record ownership; no autonomous authorization.

Missing/stale critical input yields HOLD or STOP, never a compensated PASS.

Authority & Enforcement Tier

ABAC evaluation over Role × Project × Area × Activity × Shift × RiskLevel × RegisterType, delegation, expiry, vacancy, SoD, denied-action evidence.

Never a UI-only control; UI hiding is presentation, not enforcement.

Unresolved identity or authority → capability DISABLED_SAFE; no authorization record may be created.

Evidence & Reconstruction Tier

Immutable evidence events, decision baselines, pinned source versions, denied actions, degraded-mode entries and exits.

No mutation, no back-dating, no deletion.

Evidence-write failure blocks the authorization it would have recorded.

Edge / Offline Tier

MinimumSafeInformationSet, immutable pending capture queue, encrypted local store, reconciliation client.

No offline authorization. No last-write-wins for critical objects.

Base version divergence on reconnection routes the item to governed reconciliation, not auto-merge.

Invariants preserved
  • Object-level authority and source-of-record integrity
  • Bounded Integrated Readiness ownership
  • Federation, not uncontrolled replication
  • Deterministic decision behaviour and no-compensation
  • Human authority — system prepopulates, humans authorize
  • Location Operational Context; multi-Job-Card SIMOPS
  • Current / Forecast Readiness and selective reassessment
  • Location Continuity and evidence reconstruction
  • Fail-closed behaviour and safe degraded operation

BEnterprise system context

No API or interface capability is invented. Every interface is classified NOT_YET_VALIDATED until evidenced.

SystemObjectClassAuthorityClassRead / Transactional / WriteEventAvailabilityFailureConsequenceValidation
Q4 (Control of Work)Permit, PETAR, Isolation, SanctionToTest, RiskAssessment, WorkPackTRANSACTIONAL_AUTHORITY
R: Required — permit/isolation lifecycle states
T: Required — authorization transactions remain in Q4
W: EVIDENCE_WRITE only (decision reference back-link, if interface confirmed)
State-change events preferred; polling fallbackCRITICALPermit/isolation state UNVERIFIABLE → dependent Job Cards fail closed (HOLD/STOP).NOT_YET_VALIDATED
AconexControlledDocument, Revision, TransmittalAUTHORITATIVE_REFERENCE
R: Required — current revision and status
T: None
W: None
Revision-changed events preferredHIGHVersion pinning cannot be revalidated → document-dependent requirements degrade to STALE.NOT_YET_VALIDATED
P6 / Project ControlsP6Activity, WBS, Schedule windowAUTHORITATIVE_REFERENCE
R: Required — planned windows and activity identity
T: None
W: None
Baseline/rebaseline change eventsHIGHForecast readiness degrades to CURRENT-only; lookahead marked UNVERIFIABLE.NOT_YET_VALIDATED
Smart Completions / BCSToolsIWP, WorkPackage, completion statusAUTHORITATIVE_REFERENCE
R: Required — package scope and progress
T: None
W: None
Package status changeHIGHWork demand composition incomplete → PACE emits INCOMPLETE_INPUT, not a partial pass.NOT_YET_VALIDATED
Engineering information systemsEquipment, Tag, RequirementAUTHORITATIVE_REFERENCE
R: Required — equipment/tag identity and hierarchy
T: None
W: None
Tag/equipment changeMODERATEEquipment placement context degrades; SIMOPS equipment rules fail closed where tag identity is unresolved.NOT_YET_VALIDATED
HRPerson, Assignment, Org unitAUTHORITATIVE_REFERENCE
R: Required — person identity and assignment
T: None
W: None
Joiner/mover/leaverCRITICALPerson identity unresolved → no authorization record may be created (Phase 3 condition).NOT_YET_VALIDATED
Labor RelationsRestriction (labour), working-time constraintAUTHORITATIVE_REFERENCE
R: Required — active restrictions
T: None
W: None
Restriction raised/liftedHIGHRestriction state UNVERIFIABLE is treated as restricting for decision-critical assignment.NOT_YET_VALIDATED
TrainingCompetency, Certification, ExpiryAUTHORITATIVE_REFERENCE
R: Required — competency validity windows
T: None
W: None
Competency granted/expiredCRITICALExpired or unverifiable competency on a critical control task is non-compensable → HOLD.NOT_YET_VALIDATED
Occupational HealthFitness, medical RestrictionAUTHORITATIVE_REFERENCE (privacy-constrained)
R: Required — fitness verdict only, never clinical detail
T: None
W: None
Fitness status changeCRITICALFitness unverifiable → person not eligible for the restricted activity; fail closed.NOT_YET_VALIDATED
Forwood or equivalent Critical Control platformCriticalControl, verification recordAUTHORITATIVE_REFERENCE
R: Required — control definition and verification currency
T: None
W: None
Verification recorded / lapsedCRITICALCritical control unverified is non-compensable — no aggregate score may offset it.NOT_YET_VALIDATED
Enterprise IAMIdentity, Group, Session, Assurance levelAUTHORITATIVE_REFERENCE
R: Required — authentication and identity assertion
T: Required — session/token issuance
W: None
Revocation / session terminationCRITICALNo identity assertion → read-only degraded mode; no confirm/authorize capability at all.NOT_YET_VALIDATED
Analytics / Power BI or equivalentDerived reporting extractsDERIVED_CONSUMER
R: Outbound only
T: None
W: None
Scheduled extractLOWReporting only. No operational decision depends on analytics availability.NOT_YET_VALIDATED

CObject authority / source-of-record matrix

Unresolved authority remains UNRESOLVED. No master is assigned merely to complete the matrix.

ObjectAuthoritativeSource / TransactionalAuthorityDerivedOwnerRead / WriteStewardFallback / OfflineReconciliationRule
ControlledDocument
Aconex
Aconex
Integrated Readiness (pinned version reference)
Federated read
NONE
Document Control
Pinned version usable while source STALE
Pinned revision cached read-only
Revision change triggers selective reassessment of dependent requirements only
Requirement
Engineering / regulatory register
Requirement owner
Integrated Readiness applicability projection (PACE)
Federated read
NONE
RuleOwner
Approved rule version usable
Approved requirement set cached
New approved version supersedes; in-flight decisions keep pinned version
P6Activity
P6
P6
Integrated Readiness window projection
Federated read
NONE
Project Controls
STALE window permitted for forecast only, never for authorization
Snapshot read-only
Window change → forecast reassessment; current decisions unaffected unless window overlaps
WBS
P6
P6
Integrated Readiness mapping only
Federated read
NONE
Project Controls
Cached structure
Read-only
Structural change requires mapping revalidation
IWP
Smart Completions / BCSTools
Work packaging owner
Integrated Readiness demand composition
Federated read
NONE
Work Packaging
Snapshot for planning view only
Read-only
Scope change → broad reassessment of the package
WorkPackage
Work packaging system
Work packaging owner
Integrated Readiness readiness context
Federated read
NONE
Construction Management
Snapshot
Read-only
Composition change → recompose PACE inputs
JobCard
UNRESOLVED — enterprise decision required (ADR-15)
UNRESOLVED
Integrated Readiness decision context
Federated read where a source exists
UNRESOLVED
Construction Management
Not eligible until authority is resolved
Read + governed capture; no authorization
Deferred pending ADR-15 closure — no master assigned to complete the matrix
Location
Federated Canonical Location Register (ADR-14 Option C)
Location Steward
Integrated Readiness LocationWorkContext
Federated read
Steward-governed register write
Location Steward (named, staffed)
Canonical register cached; vacancy → DISABLED_SAFE
Context read-only; no stewardship acts offline
Register change → location continuity record and recontextualization of affected Job Cards
Equipment
Engineering information systems
Engineering
Integrated Readiness placement/energy-state context
Federated read
NONE
DataSteward (asset)
Cached identity only
Read-only
Tag change → mapping revalidation before decision use
Person
HR
HR
Integrated Readiness actor projection
Federated read
NONE
HR DataSteward
Cached identity for view only
Identity assertion required for any capture attribution
Leaver event revokes capability immediately; historical evidence unchanged
Competency
Training
Training
Integrated Readiness validity projection
Federated read
NONE
Training DataSteward
Cached validity window with explicit asOf
Expiry evaluated against pinned asOf; expiry inside window → fail closed
Expiry/revocation → selective reassessment of affected assignments
Fitness
Occupational Health
Occupational Health
Integrated Readiness eligibility flag only
Verdict-only federated read (no clinical data)
NONE
OH DataSteward
Not eligible when UNVERIFIABLE
Verdict cached; unverifiable → not eligible
Status change → immediate selective reassessment
Restriction
Labor Relations / OH / Q4 (per restriction type) — ADR-03
Respective source
Integrated Readiness restriction projection
Federated read
NONE
RuleOwner + source steward
UNVERIFIABLE treated as restricting
Cached; conservative interpretation
Restriction change → selective reassessment of affected persons/activities
RiskAssessment
Q4
Q4
Integrated Readiness readiness input
Federated read
NONE
ES&H
Pinned version only
Read-only
Revision → selective reassessment of dependent Job Cards
CriticalControl
Critical Control platform
Critical Control platform
Integrated Readiness non-compensable gate
Federated read
NONE
ES&H CriticalControlOwner
None — unverified is non-compensable
Verification currency evaluated against pinned asOf
Lapse → immediate HOLD on dependent decisions
Permit
Q4
Q4
Integrated Readiness state projection
Federated read
NONE (authorization stays in Q4)
Permit Authority
None for authorization; STALE view permitted read-only
View only; no offline authorization
State change → selective reassessment; unmapped state → fail closed
PETAR
Q4
Q4 / designated authority
Integrated Readiness routing context
Federated read
NONE
ES&H
None
Routing proposal capture only
Approval state change → selective reassessment
Isolation
Q4
Q4
Integrated Readiness energy-state context
Federated read
NONE
Isolation Authority
None
Read-only
Isolation change → SIMOPS re-evaluation for the Location
SanctionToTest
Q4
Q4
Integrated Readiness context
Federated read
NONE
Commissioning Authority
None
Read-only
State change → SIMOPS and readiness re-evaluation
TemporaryModification
UNRESOLVED — candidate Q4 or engineering MoC (ADR-17)
UNRESOLVED
Integrated Readiness context flag
Federated read where evidenced
UNRESOLVED
Engineering / MoC owner
Not eligible
Read-only
Deferred pending ADR-17 closure
ReadinessDecision
Integrated Readiness
Integrated Readiness (human confirm/authorize)
Integrated Readiness
Owned
AUTHORITATIVE_WRITE (own object only)
BusinessProductOwner
No offline authorization
Not creatable offline
Decision baselines are immutable; supersession creates a new pinned baseline
EvidenceEvent
Integrated Readiness
Integrated Readiness
Integrated Readiness
Owned
AUTHORITATIVE_WRITE, append-only
BusinessProductOwner + CyberOwner
Queued capture permitted; authorization events are not
Immutable pending queue with base version
Append on sync with original capture time and sync time both retained

DFederation & identity architecture — ADR-13 / CA-01 closure

KeyCandidate authorityMappingMethodMandatory forFail-closed scope
Project_IDEnterprise project registerDETERMINISTICAll decisionsProject scope only
Location_IDFederated Canonical Location RegisterGOVERNED_REGISTERLocation context, SIMOPSAffected Location only
Equipment_IDEngineering information systemsDETERMINISTIC + SEMANTIC_PROPOSALEquipment/energy-state rulesRules depending on that tag only
P6_Activity_IDP6DETERMINISTICForecast readinessForecast dimension only
WBS_IDP6DETERMINISTICScope roll-upRoll-up reporting only
IWP_NOSmart Completions / BCSToolsDETERMINISTICDemand compositionAffected package only
WorkPackage_IDWork packaging systemDETERMINISTICPackage readinessAffected package only
JobCard_IDUNRESOLVED (ADR-15)UNRESOLVEDJob Card decisionsAffected Job Card only
Person_IDHR + enterprise IAM correlationDETERMINISTICAny attributable actThat actor's capabilities only
Mapping record — preserved fields
  • MappingState (PROPOSED | SEMANTIC_PROPOSAL | VALIDATED | CONFLICT | UNRESOLVED | RETIRED)
  • MappingMethod
  • OriginMappingMethod
  • CurrentMappingMethod
  • SuggestedBy
  • ValidatedBy
  • AuthorityBasis
  • ValidatedAt
  • MappingVersion
Governed behaviour
  • SEMANTIC_PROPOSAL is never consumable by IRDE. It is visible to stewards for validation only, and a decision that would require it is treated as missing mandatory mapping.
  • CONFLICT, UNRESOLVED or missing mandatory mapping fails closed for the dependent decision only. Unrelated Job Cards and Locations continue to be decided normally.
  • Mapping validation is an attributable act: ValidatedBy, AuthorityBasis and ValidatedAt are mandatory and produce an evidence event.
  • MappingVersion is pinned into every decision baseline that consumed it, so a later remap never silently rewrites history.
  • OriginMappingMethod is retained even after human validation, so AI/semantic provenance remains auditable forever.

EIntegration contract architecture

Integrated Readiness performs AUTHORITATIVE_WRITE on exactly two object classes it owns: ReadinessDecision and EvidenceEvent (plus governed federation mappings and approved rule configuration). Every other interaction is READ, OBSERVE, DERIVE, SNAPSHOT or EVIDENCE_WRITE. There is no undocumented authoritative write path.
SourceObjectOperationsRead / Event contractWrite contractFailure / ReconciliationEvidenceValidation
Q4Permit / Isolation / PETAR / SanctionToTest
READOBSERVEDERIVESNAPSHOTEVIDENCE_WRITE
Object + SourceNativeState + SourceVersion + asOf
State-change notification; polling fallback with explicit staleness
No authoritative write. Optional decision back-reference is EVIDENCE_WRITE and only if the interface is confirmed.
Unavailable → SourceAvailabilityState=UNVERIFIABLE → dependent decisions fail closed
On restore, re-read all objects referenced by open decisions; mismatch invalidates the affected baseline
Source read evidence with version and asOfNOT_YET_VALIDATED
AconexControlledDocument revision
READOBSERVESNAPSHOT
Document ID, revision, status, issued date
Revision-change event preferred
None
STALE permitted for pinned revisions; UNVERIFIABLE blocks new pinning
Revision delta triggers selective reassessment of dependent requirements
Version pin evidenceNOT_YET_VALIDATED
P6Activity / WBS
READSNAPSHOTDERIVE
Activity ID, window, WBS path, baseline ID
Rebaseline notification
None
Forecast dimension degrades to UNVERIFIABLE; current decisions unaffected
Window delta triggers forecast reassessment only
Forecast basis evidenceNOT_YET_VALIDATED
Training / OH / Labor Relations / HRCompetency / Fitness / Restriction / Person
READOBSERVEDERIVE
Verdict + validity window + asOf. No clinical or personal detail beyond eligibility.
Change notification required for revocation to be timely
None
UNVERIFIABLE is conservative: not eligible for the restricted activity
Change event → selective reassessment of affected assignments
Eligibility basis evidence (verdict-level only)NOT_YET_VALIDATED
Critical Control platformCriticalControl verification
READOBSERVEDERIVE
Control ID, verification currency, verifier role
Verification recorded / lapsed
None
Unverified/unverifiable is non-compensable → HOLD
Lapse → immediate selective reassessment
Critical control basis evidenceNOT_YET_VALIDATED
Enterprise IAMIdentity / session
READOBSERVE
Authenticated subject, assurance level, group claims
Revocation / session termination
None
No assertion → read-only degraded mode; confirm/authorize capabilities disabled
Revocation applies immediately; historical evidence unchanged
Authentication context in every attributable actNOT_YET_VALIDATED
AnalyticsDerived extract
SNAPSHOT
Outbound extract of derived readiness data only
Scheduled
None
No operational impact
Re-extract
Extract logNOT_YET_VALIDATED

FIAM / authority enforcement model

ABAC dimensions
RoleProjectAreaActivityShiftRiskLevelRegisterType
CapabilityMeaningEnforcement
CanViewRead decision contextServer-side ABAC on every query
CanProposeCreate SYSTEM/HUMAN proposals with no decision effectServer-side; proposals never alter verdicts
CanConfirmAttributable confirmation of a prepopulated itemRequires resolved identity + evidence write success
CanValidateValidate mappings and normalized statesSteward capability, SoD-separated from CanApprove
CanApproveApprove rules/configuration versionsRuleOwner; approval creates an executable version
CanAuthorizeAuthorize work-affecting decisionsOnline only; never offline; never inferred from role name
CanAdministerPlatform/config administrationPrivileged access, separately audited, no operational authorization rights
  • UI hiding is never an authority control. Every capability is evaluated server-side at the point of effect, and a forged direct call is denied and recorded.
  • Delegation is explicit, time-bounded, scoped to the same or narrower attribute set, and cannot escalate the delegator's own capability.
  • Temporary authority carries mandatory expiry; expiry is enforced at evaluation time, not by a batch job.
  • Vacant authority yields AuthorityResolutionState=UNRESOLVED and capabilities DISABLED_SAFE. Work is not silently permitted.
  • Segregation of duties: the same identity may not both propose and authorize the same decision, nor both validate a mapping and approve the rule that consumes it.
  • Denied actions generate evidence (actor, attempted capability, object, reason, timestamp).
  • Phase 3 condition satisfied structurally: no authorization record can exist without a resolved identity and a resolved authority basis — the write is rejected before persistence.

GDecision services architecture

CREContext Resolution Engine
InputContract Work demand, Location, Equipment, Crew, window
ProcessingBoundary Resolves federated identity and builds the decision context. No verdicts.
RuleDependencies Location inheritance rules
SourceDependencies Location register, engineering, HR, P6
OutputContract Resolved decision context with pinned mapping versions
FailureContract Unresolved mandatory mapping → CONTEXT_UNRESOLVED → dependent decision fails closed
EvidenceGenerated Context resolution record
Observability Mapping conflicts, resolution latency
RecoveryBehaviour Re-resolve on mapping validation; affected decisions re-queued
ECEEnabling Conditions Engine
InputContract Resolved context
ProcessingBoundary Determines which enabling conditions apply and their current state
RuleDependencies Approved applicability and validity rules
SourceDependencies Q4, Training, OH, Labor Relations, Critical Control platform
OutputContract Condition set with state, validity and asOf
FailureContract Unverifiable condition marked UNVERIFIABLE — never assumed satisfied
EvidenceGenerated Condition evaluation record
Observability Unverifiable condition rate by source
RecoveryBehaviour Re-evaluate on source restore
PACEPreventive Applicability & Composition Engine
InputContract Condition set + work characterization
ProcessingBoundary Composes the preventive package as SYSTEM_PROPOSED only
RuleDependencies Approved requirement applicability and frequency rules
SourceDependencies Requirement register, documents
OutputContract SYSTEM_PROPOSED preventive package
FailureContract Incomplete input → INCOMPLETE_INPUT, never a partial pass
EvidenceGenerated Composition basis with rule versions
Observability Rule execution failures, composition latency
RecoveryBehaviour Recompose on rule/version change
IRDEIntegrated Readiness Decision Engine
InputContract Confirmed package + conditions + SIMOPS assessment
ProcessingBoundary Deterministic verdict: READY / CONDITIONAL / HOLD / STOP. No-compensation enforced structurally.
RuleDependencies No-compensation classification, Q4 state mappings, CUM rules
SourceDependencies All decision-critical sources via projections
OutputContract Decision baseline with pinned versions
FailureContract Missing critical input or unmapped state → fail closed
EvidenceGenerated Decision baseline + full basis
Observability Decision latency, fail-closed rate, verdict distribution
RecoveryBehaviour Re-decide only through selective or broad reassessment; prior baselines immutable
EAEEvidence & Audit Engine
InputContract All attributable acts and decision baselines
ProcessingBoundary Append-only evidence; reconstruction queries
RuleDependencies Retention and integrity rules
SourceDependencies None at decision time
OutputContract Reconstructable decision history
FailureContract Evidence-write failure blocks the act it would record
EvidenceGenerated Self-evidencing
Observability Evidence-write failure rate, integrity checks
RecoveryBehaviour No back-fill of authorization events; gaps are declared
GAEGovernance & Authority Engine
InputContract Actor, capability request, object attributes
ProcessingBoundary ABAC evaluation, delegation, expiry, vacancy, SoD
RuleDependencies Authority configuration versions
SourceDependencies IAM, HR
OutputContract PERMIT / DENY with reason
FailureContract Unresolved authority → DISABLED_SAFE
EvidenceGenerated Permit and deny records
Observability Denied actions, unresolved authority count, delegation expiries
RecoveryBehaviour Re-evaluate on identity restore; no retroactive permits

HRule / configuration governance — ADR-16

Governed rule domains
  • Requirement applicability
  • Frequency
  • Validity
  • Authority
  • No-compensation classification
  • Q4 state mappings
  • SIMOPS CUM rules
  • Location inheritance
  • Alert semantics
  • Critical Control mappings
Mandatory rule record fields
  • Rule_ID
  • Project_ID
  • RuleType
  • AuthorityBasis
  • Version
  • ApprovedBy
  • EffectiveFrom
  • EffectiveTo
  • Supersedes
  • ApprovalState
  • Only ApprovalState=APPROVED with an effective window covering the evaluation instant is executable. DRAFT and PROPOSED configuration is never executable operational logic.
  • Rule execution pins Rule_ID + Version into the decision baseline, so a later rule change never rewrites a past decision.
  • No-compensation classification is configuration, not code, but it is approval-gated at the highest authority basis and is fail-closed when unclassified: an unclassified requirement is treated as non-compensable.
  • Rule authoring, approval and administration are SoD-separated (RuleOwner approves; administrator cannot approve).
ADR-03 / CA-03 — restriction & Q4 transaction semantics
  • SourceNativeState is stored verbatim and never overwritten. NormalizedOperationalState is a derived value produced only by an approved mapping rule version.
  • An unmapped native state resolves to NormalizedOperationalState=UNKNOWN. Where the state is decision-critical this fails closed (HOLD/STOP) and raises a mapping conflict to the steward.
  • APPROVED, AUTHORIZED or equivalent is never inferred from textual similarity, label matching, or AI proposal. Only an approved deterministic mapping can produce an enabling normalized state.
  • Restriction objects remain authoritative in their source. Integrated Readiness projects them; UNVERIFIABLE restriction state is interpreted conservatively as restricting.
  • Both states are surfaced in the UI so field users can see the native source language alongside the normalized decision meaning.

ILocation / SIMOPS technical model

EntityTechnical role
CanonicalLocationFederated register entry (ADR-14 Option C). Identity, hierarchy, steward, state.
LocationWorkContextInherited context for work at the location. Context inherits; authorization never does.
LocationConcurrentWorkSetAll Job Cards whose execution windows intersect at the location.
LocationCriticalRiskContextAggregated critical controls, energy states, exclusion zones and isolations in force.
SIMOPSAssessmentPairwise interaction results plus the cumulative CUM-1…CUM-7 evaluation.
LocationContinuityRecordSection X continuity across shifts, handovers and context changes.
  • Multiple Job Cards in one Location are evaluated as a set, not as independent decisions.
  • Overlapping execution windows are computed on the pinned window projection; a window change is a SIMOPSContextChanged event.
  • Pairwise interactions are computed for every intersecting pair; results are retained individually for attribution.
  • Cumulative CUM-1…CUM-7 rules run over the whole concurrent set after pairwise evaluation.
  • Blocker attribution is per Job Card: ID, discipline, blocker type, owner, action and evidence reference.
  • Equipment placement, isolation interaction, energy-state conflicts and exclusion zones are context inputs to both pairwise and cumulative evaluation.
  • Location continuity records survive shift change; a new shift inherits context and must re-establish authorization.
  • PAIRWISE PASS NEVER IMPLIES LOCATION PASS — the cumulative verdict is computed independently and can be STOP with all pairs passing.
  • INHERIT CONTEXT — NEVER INHERIT AUTHORIZATION.

JData & persistence architecture

ClassContentMutabilityRetentionReplication stance
AUTHORITATIVE_REFERENCEReference to source objects by identity + version; not the master itselfImmutable reference, refreshed projectionAs long as any decision references itNo enterprise-master replication; identity + version only
TRANSACTIONALReadinessDecision lifecycle owned by the readiness layerAppend-only state transitionsProject lifetime + statutoryOwned
DERIVEDProjections, normalized states, composed packages, SIMOPS resultsRecomputableCurrent + basis for pinned baselinesDerived, never authoritative
OPERATIONAL_SNAPSHOTPinned source versions consumed by a decisionImmutableWith the decision baselineMinimal, decision-scoped
EVIDENCEAll attributable acts, denials, degraded entries/exitsAppend-only, integrity-protectedStatutory maximumOwned
CONFIGURATIONRules, mappings, authority configuration, versions and approvalsVersioned, superseded never overwrittenPermanentOwned
  • Historical source versions are retained only where a decision pinned them; the readiness layer does not become a shadow archive of enterprise systems.
  • Offline queues persist as immutable pending items with base version and capture identity.
  • Reconciliation results are first-class records: what diverged, how it was resolved, by whom, under what authority.

KEvent / change architecture

EventTriggerReassessmentScope
WorkDemandChangedDEMAND_TRIGGERBROAD_REASSESSMENTAffected package composition
SourceObjectChangedCHANGE_TRIGGERSELECTIVE_REASSESSMENTDecisions that pinned the changed object
DocumentRevisionChangedCHANGE_TRIGGERSELECTIVE_REASSESSMENTRequirements dependent on the revision
LocationChangedCHANGE_TRIGGERBROAD_REASSESSMENTAll Job Cards at the location + continuity record
CrewChangedEVENT_TRIGGERSELECTIVE_REASSESSMENTCompetency/fitness gates for the affected persons
EquipmentChangedCHANGE_TRIGGERSELECTIVE_REASSESSMENTEquipment-dependent rules and SIMOPS energy state
RestrictionChangedEVENT_TRIGGERSELECTIVE_REASSESSMENTAffected assignments
CriticalControlChangedEVENT_TRIGGERFAIL_CLOSEDLapse immediately holds dependent decisions
AuthorizationChangedEVENT_TRIGGERSELECTIVE_REASSESSMENTDecisions relying on the changed authority
ValidityChangedTIME_TRIGGERSELECTIVE_REASSESSMENTItems whose validity window closed
SIMOPSContextChangedCHANGE_TRIGGERBROAD_REASSESSMENTWhole concurrent work set at the location
SourceAvailabilityChangedEVENT_TRIGGERFAIL_CLOSEDDecisions dependent on the unavailable source only
  • SELECTIVE_REASSESSMENT is allowed only when the change is traceably scoped to specific pinned inputs and no cumulative rule input changed.
  • BROAD_REASSESSMENT is required when the change alters set membership, location context or package composition — anything that can change a cumulative outcome.
  • FAIL_CLOSED is required when the change makes a critical input unverifiable or removes an authority basis.

LOffline / reconciliation architecture

OFFLINE CAPTURE IS PERMITTED WHERE GOVERNED. OFFLINE AUTHORIZATION IS NOT PERMITTED. This holds unless future competent governance explicitly changes the rule.
ElementDesign
MinimumSafeInformationSetThe bounded set a field user needs to work safely: current verdict, active blockers, critical controls, isolations, exclusion zones, contacts, and the asOf of each.
BaseVersionEvery offline package pins the exact source and rule versions it was built from.
OfflineCapturePackageStructured capture only; no verdict change, no authorization, no rule execution that would create an enabling state.
ImmutablePendingQueueCaptures are append-only with capture identity and capture time; they cannot be edited to look like online acts.
EncryptionLocal store encrypted at rest; device-bound keys; wipe on revocation.
SyncOrdered, idempotent, resumable; sync time recorded separately from capture time.
ConflictDetectionBase version comparison on every item; divergence is a detected conflict, never an overwrite.
ReconciliationDeterministic: no last-write-wins for critical objects. Conflicts route to the accountable steward with both versions visible.
RecoveryVerificationExplicit human verification step before the location returns to normal decision operation.
SERVICE_RESTORED ≠ OPERATIONALLY_RECOVERED. Restoring connectivity only re-enables reads. The location returns to normal operation only after queued captures are reconciled, affected decisions are reassessed against current source state, and an authorized person records the recovery verification.

MResilience / degraded mode architecture

DependencyCriticalityPermitted decision useDegraded modeActivation / Exit authorityRecovery evidence
Q4 permit/isolation stateCRITICALCURRENT only for authorization; STALE view-only; UNVERIFIABLE blocksRead-only safety view with explicit asOf
Automatic on detection
Authorized supervisor after re-read
Re-read record per open decision
Critical Control verificationCRITICALCURRENT onlyDependent decisions HOLD
Automatic
ES&H authority
Verification currency re-confirmed
Competency / FitnessCRITICALCURRENT; STALE only within the object's own configured validityRestricted activity not eligible
Automatic
Supervisor after source restore
Eligibility re-evaluated
Location registerCRITICALCached canonical entriesNo new location context creation; existing contexts read-only
Automatic
Location Steward
Continuity record entry
P6 windowsHIGHSTALE acceptable for forecastForecast marked UNVERIFIABLE; current decisions unaffected
Automatic
Planner
Forecast basis refreshed
Aconex documentsHIGHPinned revisions usableNo new version pinning
Automatic
Document Control
Revision re-check on open decisions
Enterprise IAMCRITICALValid session onlyRead-only; all confirm/authorize capabilities disabled
Automatic
Automatic on restore
Session re-establishment logged
AnalyticsLOWAnyReporting delayed
Automatic
Automatic
Extract log

No universal freshness window is defined. Validity is object- and decision-specific and is carried in approved configuration, because a competency validity and an isolation state validity are not comparable quantities.

NCyber architecture

AreaDesignStatus
Identity / SSOEnterprise IAM federation; no local password storeENTERPRISE_ASSUMPTION
MFARequired for CanAuthorize and CanAdminister capability classesENTERPRISE_ASSUMPTION
Device trustManaged-device posture required for offline packagesENTERPRISE_ASSUMPTION
Mobile / offline protectionEncrypted local store, device-bound keys, remote wipe on revocationCONFIRMED_CONTROL
Encryption in transit / at restTLS in transit; encryption at rest for all evidence and offline storesCONFIRMED_CONTROL
Service identitiesPer-integration service identity, least privilege, read-scoped by defaultCONFIRMED_CONTROL
SecretsManaged secret store; no secrets in configuration or client bundlesCONFIRMED_CONTROL
Privileged accessAdministration separated from operational authorization; time-bounded elevationCONFIRMED_CONTROL
Audit loggingAppend-only, tamper-evident, includes denials and degraded transitionsCONFIRMED_CONTROL
Evidence integrityHash-chained evidence events; integrity verification is part of reconstructionCONFIRMED_CONTROL
Administrative configuration accessApproval-gated; administrator cannot approve the rules they authorCONFIRMED_CONTROL

OObservability model

SignalClassification
Source availabilityTechnologyFailure
Integration failureTechnologyFailure
Mapping conflictOperationalReadinessFailure
Rule execution failureTechnologyFailure
Decision latencyTechnologyFailure
Evidence-write failureTechnologyFailure
Sync failureTechnologyFailure
Stale projectionOperationalReadinessFailure
Degraded mode activeOperationalReadinessFailure
Unresolved authorityOperationalReadinessFailure
SIMOPS evaluation outcomeOperationalReadinessFailure

TechnologyFailure and OperationalReadinessFailure are never merged into a single health indicator. A perfectly healthy platform can be reporting a legitimately unready location, and a degraded platform must never be read as a safety signal.

PAI boundary

Permitted — proposal only
  • Extraction from documents (proposal only)
  • Semantic search
  • Classification proposal
  • Mapping proposal (always SEMANTIC_PROPOSAL)
  • Document comparison
  • Anomaly detection
  • Contextual recommendation
AI may not
  • Create a requirement
  • Determine legal applicability independently
  • Authorize
  • Approve
  • Accept risk
  • Override HOLD / STOP
  • Modify authoritative data autonomously

The deterministic core operates fully with AI unavailable. AI output enters the system only as a proposal object carrying OriginMappingMethod=SEMANTIC, which IRDE cannot consume until a human with the required capability validates it.

QTechnical support / operating model

RoleScope
L1 SupportAccess, navigation, incident intake, degraded-mode guidance
L2 Application / Integration SupportIntegration failures, sync failures, mapping conflict triage, projection staleness
L3 Engineering / ProductDefects, rule engine behaviour, performance, releases
BusinessProductOwnerCapability priorities, decision semantics, acceptance
DataStewardPer-domain federation mapping validation and source data quality
RuleOwnerApproves executable rule versions including no-compensation classification
IntegrationOwnerContract ownership per source system, availability targets
PlatformOwnerRuntime, capacity, resilience, degraded-mode readiness
CyberOwnerIdentity, evidence integrity, privileged access, offline device posture
EnterpriseArchitectureOwnerGuards SoR integrity and prevents authority drift over the lifecycle
  • ADR-14 stewardship staffing remains CONTROLLED_OPEN. Location Stewards must be named and staffed per area before pilot; an unstaffed steward makes location capabilities DISABLED_SAFE by design, which is safe but not operable.
  • P3-TRN-01 organizational change remains CONTROLLED_OPEN. The shift from 'system reports' to 'system prepopulates, humans authorize' is a role change, not a training task.
  • A technically functional system with unstaffed governance is not production-ready. This is a Phase 5 acceptance condition, not an implementation detail.

ROpen ADR closure / dependency register

IDSubjectPhase 5 treatmentState
ADR-03 / CA-03Restriction & Q4 transaction semanticsNative/normalized separation, unmapped=UNKNOWN fail-closed, no textual inferenceTECHNICAL_PATH_DEFINED
ADR-13 / CA-01Federation & identityGoverned mapping record, state machine, SEMANTIC_PROPOSAL non-consumable, decision-scoped fail-closedTECHNICAL_PATH_DEFINED
ADR-14Location governance stewardship staffingDesign complete; staffing is an organizational dependencyCONTROLLED_OPEN
ADR-15JobCard authorityLeft UNRESOLVED in the SoR matrix — no master assigned to complete the tableENTERPRISE_DECISION_REQUIRED
ADR-16Rule & configuration governanceVersioned, approval-gated executable configuration with pinningTECHNICAL_PATH_DEFINED
ADR-17TemporaryModification authorityUNRESOLVED; candidate sources documented onlyENTERPRISE_DECISION_REQUIRED
ADR-18…24Remaining architectural dependenciesCarried unchanged; none is closed by technical design aloneCONTROLLED_OPEN
CA-04Evidence retention scopeRetention classes defined; statutory scope requires legal confirmationCONTROLLED_OPEN
OfflineAuthorizationOffline authorization prohibitionEnforced structurally: no authorization path exists offlineTECHNICALLY_CLOSED
P3-TRN-01Organizational change loadCarried into the operating model as a pilot preconditionCONTROLLED_OPEN

STechnical risk register

IDRiskSeverityControlResidual
P5-R-01All source interfaces are NOT_YET_VALIDATED; assumed read/event capability may not existHIGHInterface validation is a mandatory pilot precondition; no design depends on an invented capability, and polling fallbacks are specifiedCONTROLLED
P5-R-02Federation mapping backlog exceeds steward capacity, causing widespread fail-closedHIGHDecision-scoped fail-closed limits blast radius; mapping conflict rate is an observability signal with staffing triggerCONTROLLED
P5-R-03Q4 state mapping drift after a source upgrade silently changes normalized meaningHIGHUnmapped state → UNKNOWN → fail closed; mapping versions pinned in baselines; drift raises a conflict rather than a verdictCONTROLLED
P5-R-04Offline reconciliation volume after long outages overwhelms stewardsMEDIUMImmutable queue, deterministic conflict routing, recovery verification gate; no auto-mergeCONTROLLED
P5-R-05Evidence store growth and integrity verification costMEDIUMRetention classes; hash-chained append-only design; snapshots scoped to pinned decisions onlyCONTROLLED
P5-R-06ABAC configuration complexity across 7 dimensions becomes unmaintainableHIGHAuthority configuration is versioned and approval-gated like rules; vacancy and expiry are fail-closed by defaultCONTROLLED
P5-R-07Unstaffed stewardship makes the system safe but inoperableHIGHNamed staffing is a pilot precondition (ADR-14, P3-TRN-01)OPEN
P5-R-08JobCard and TemporaryModification authority unresolved limits end-to-end operationHIGHLeft explicitly UNRESOLVED; scope of pilot must exclude decisions depending on those masters until resolvedOPEN
P5-R-09SIMOPS cumulative evaluation latency at high concurrencyMEDIUMSet-scoped recomputation on SIMOPSContextChanged; latency is an observability signalCONTROLLED
P5-R-10Analytics consumers treat derived readiness data as authoritativeLOWExtracts are labelled DERIVED with asOf and decision baseline referenceCONTROLLED

No risk is classified Critical. Two High risks (P5-R-07, P5-R-08) remain OPEN as organizational and enterprise-decision dependencies rather than technical defects, and both are pilot preconditions.

TOption C vs Option B technical escape test

DimensionOption BOption CAssessment
IntegrationCount~11 sources, most mediated through Q4~12 sources integrated directly by the readiness layerMarginal increase. Option B's mediation does not remove integrations, it relocates and hides them.
FederationComplexityLower in the readiness layer, higher inside Q4 configurationExplicit, versioned, observable federation tierOption C's complexity is visible and governable; Option B's is embedded in a platform not designed to steward it.
CustomLogicReadiness logic split between Q4 extension and the readiness capabilityReadiness logic bounded in one owned deterministic coreOption C owns less total logic and owns it in one place.
SupportBurdenTwo-team diagnosis for most failuresClear ownership per tier; L2 triage maps to IntegrationOwnerComparable headcount, better attribution under Option C.
FailureDependenciesQ4 availability becomes a single point of failure for readiness decisionsSource loss is localized and decision-scopedDecisive advantage for Option C — matches the fail-closed-but-bounded requirement.
OperatingSkillRequirementDeep Q4 configuration skillIntegration and data stewardship skillDifferent, not greater. Stewardship skill is required by ADR-14 under either option.
LifecycleTechnicalDebtReadiness semantics coupled to one vendor's upgrade cycleReadiness semantics independent of any single vendor lifecycleOption C materially lower over an EPC lifecycle.
ScalabilityScales with Q4 platform limitsScales per tier; SIMOPS compute isolatedOption C better, though neither is currently constrained by evidenced volumes.
OPTION_C_TECHNICALLY_CONFIRMED

Phase 5 technical evidence shows Option C's additional federation burden is proportionate. The increase is concentrated in one explicitly designed, versioned and observable federation tier, and it buys localized failure behaviour, bounded owned logic and vendor-independent decision semantics. No material technical contradiction of the Phase 4 Rev.2 decision was found, so no ENTERPRISE OPTION REOPEN REQUEST is raised. Option B remains the controlled fallback and may only be adopted through an explicit architecture decision.

UTechnical solution acceptance register (§22)

Acceptance conditionVerdictBasis
Option C remains technically defensiblePASSSection T escape test — OPTION_C_TECHNICALLY_CONFIRMED
No uncontrolled SoR is introducedPASSSection C matrix; unresolved masters left UNRESOLVED rather than assigned
ADR-13 / CA-01 has a technically governed pathPASSSection D mapping record, state machine and decision-scoped fail-closed
ADR-16 has a governable configuration architecturePASSSection H versioned approval-gated executable rules
Authoritative write paths are explicitPASSSection E — writes limited to ReadinessDecision, EvidenceEvent, mappings and approved configuration
IAM enforcement is technically crediblePASS_WITH_CONDITIONSection F server-side ABAC is credible; enterprise IAM capabilities remain NOT_YET_VALIDATED
Decision evidence is reconstructablePASSSection G EAE + pinned versions in every baseline
Offline behaviour is boundedPASSSection L — capture permitted, authorization structurally impossible
Reconciliation is deterministicPASSSection L — base version conflict detection, no last-write-wins for critical objects
No-compensation is enforceablePASSSections G and H — unclassified requirements default to non-compensable
Location / SIMOPS architecture remains intactPASSSection I — pairwise plus cumulative, context inherited, authorization never inherited
Stewardship / support ownership is crediblePASS_WITH_CONDITIONSection R model defined; ADR-14 staffing and P3-TRN-01 remain pilot preconditions
No Critical unresolved technical risk existsPASSSection S — zero Critical; two High risks open as organizational/enterprise dependencies
Hold point

HOLD POINT RESPECTED — no Pilot/MVP work has started. No API, database, deployment or live integration is authorized. Next decision: Technical Solution Definition Acceptance → Controlled Pilot/MVP Authorization.

Technology does not create readiness — it makes readiness visible, verifiable and traceable. Integration does not transfer accountability. Application access is not operational authority. Presentation familiarity does not create source authority. Synthetic demonstration data only.