Aseguramiento / Técnico
Technical Solution Definition — Hybrid / Federated Enterprise Model
Phase 4 Rev.2 is accepted and not reopened. This record determines whether Option C can be industrialized as a technically coherent, governable, resilient and supportable solution. It implements the accepted model; it does not redefine it. This is not production deployment.
RECOMMEND ACCEPTANCE WITH CONTROLLED CONDITIONS
Option C can be industrialized as a technically coherent, governable, resilient and supportable solution. Thirteen acceptance conditions are met, two with conditions: enterprise IAM capability validation, and staffed stewardship under ADR-14 / P3-TRN-01. All source interfaces remain NOT_YET_VALIDATED and interface validation is a mandatory precondition to any pilot.
HOLD POINT RESPECTED — no Pilot/MVP work has started. No API, database, deployment or live integration is authorized. Next decision: Technical Solution Definition Acceptance → Controlled Pilot/MVP Authorization.
- Validate every NOT_YET_VALIDATED interface before pilot scoping
- Name and staff Location Stewards per area (ADR-14)
- Resolve or explicitly exclude JobCard (ADR-15) and TemporaryModification (ADR-17) authority from pilot scope
- Confirm enterprise IAM support for the 7-dimension ABAC model
- Confirm statutory evidence retention scope (CA-04)
ATarget logical architecture
Integrated Readiness is a bounded decision layer. Enterprise systems retain their objects and transactions. The readiness layer owns only integrated decision context, decision baselines and evidence. Every cross-boundary flow is federated by governed identity mapping — never by replication of an enterprise master.
Governed cross-system identity mapping, mapping versions, mapping state machine, conflict detection.
No enterprise master object is created or mastered here.
CONFLICT / UNRESOLVED / missing mandatory mapping fails closed for the dependent decision only.
Read-only projections of source objects with SourceNativeState preserved and NormalizedOperationalState derived under approved mappings.
No authoritative write. No normalization by textual similarity.
Unmapped native state in a decision-critical path yields UNKNOWN → fail closed.
CRE, ECE, PACE, IRDE, EAE, GAE. Deterministic core; no-compensation enforced structurally.
No source-of-record ownership; no autonomous authorization.
Missing/stale critical input yields HOLD or STOP, never a compensated PASS.
ABAC evaluation over Role × Project × Area × Activity × Shift × RiskLevel × RegisterType, delegation, expiry, vacancy, SoD, denied-action evidence.
Never a UI-only control; UI hiding is presentation, not enforcement.
Unresolved identity or authority → capability DISABLED_SAFE; no authorization record may be created.
Immutable evidence events, decision baselines, pinned source versions, denied actions, degraded-mode entries and exits.
No mutation, no back-dating, no deletion.
Evidence-write failure blocks the authorization it would have recorded.
MinimumSafeInformationSet, immutable pending capture queue, encrypted local store, reconciliation client.
No offline authorization. No last-write-wins for critical objects.
Base version divergence on reconnection routes the item to governed reconciliation, not auto-merge.
- Object-level authority and source-of-record integrity
- Bounded Integrated Readiness ownership
- Federation, not uncontrolled replication
- Deterministic decision behaviour and no-compensation
- Human authority — system prepopulates, humans authorize
- Location Operational Context; multi-Job-Card SIMOPS
- Current / Forecast Readiness and selective reassessment
- Location Continuity and evidence reconstruction
- Fail-closed behaviour and safe degraded operation
BEnterprise system context
No API or interface capability is invented. Every interface is classified NOT_YET_VALIDATED until evidenced.
| System | ObjectClass | AuthorityClass | Read / Transactional / Write | Event | Availability | FailureConsequence | Validation |
|---|---|---|---|---|---|---|---|
| Q4 (Control of Work) | Permit, PETAR, Isolation, SanctionToTest, RiskAssessment, WorkPack | TRANSACTIONAL_AUTHORITY | R: Required — permit/isolation lifecycle states T: Required — authorization transactions remain in Q4 W: EVIDENCE_WRITE only (decision reference back-link, if interface confirmed) | State-change events preferred; polling fallback | CRITICAL | Permit/isolation state UNVERIFIABLE → dependent Job Cards fail closed (HOLD/STOP). | NOT_YET_VALIDATED |
| Aconex | ControlledDocument, Revision, Transmittal | AUTHORITATIVE_REFERENCE | R: Required — current revision and status T: None W: None | Revision-changed events preferred | HIGH | Version pinning cannot be revalidated → document-dependent requirements degrade to STALE. | NOT_YET_VALIDATED |
| P6 / Project Controls | P6Activity, WBS, Schedule window | AUTHORITATIVE_REFERENCE | R: Required — planned windows and activity identity T: None W: None | Baseline/rebaseline change events | HIGH | Forecast readiness degrades to CURRENT-only; lookahead marked UNVERIFIABLE. | NOT_YET_VALIDATED |
| Smart Completions / BCSTools | IWP, WorkPackage, completion status | AUTHORITATIVE_REFERENCE | R: Required — package scope and progress T: None W: None | Package status change | HIGH | Work demand composition incomplete → PACE emits INCOMPLETE_INPUT, not a partial pass. | NOT_YET_VALIDATED |
| Engineering information systems | Equipment, Tag, Requirement | AUTHORITATIVE_REFERENCE | R: Required — equipment/tag identity and hierarchy T: None W: None | Tag/equipment change | MODERATE | Equipment placement context degrades; SIMOPS equipment rules fail closed where tag identity is unresolved. | NOT_YET_VALIDATED |
| HR | Person, Assignment, Org unit | AUTHORITATIVE_REFERENCE | R: Required — person identity and assignment T: None W: None | Joiner/mover/leaver | CRITICAL | Person identity unresolved → no authorization record may be created (Phase 3 condition). | NOT_YET_VALIDATED |
| Labor Relations | Restriction (labour), working-time constraint | AUTHORITATIVE_REFERENCE | R: Required — active restrictions T: None W: None | Restriction raised/lifted | HIGH | Restriction state UNVERIFIABLE is treated as restricting for decision-critical assignment. | NOT_YET_VALIDATED |
| Training | Competency, Certification, Expiry | AUTHORITATIVE_REFERENCE | R: Required — competency validity windows T: None W: None | Competency granted/expired | CRITICAL | Expired or unverifiable competency on a critical control task is non-compensable → HOLD. | NOT_YET_VALIDATED |
| Occupational Health | Fitness, medical Restriction | AUTHORITATIVE_REFERENCE (privacy-constrained) | R: Required — fitness verdict only, never clinical detail T: None W: None | Fitness status change | CRITICAL | Fitness unverifiable → person not eligible for the restricted activity; fail closed. | NOT_YET_VALIDATED |
| Forwood or equivalent Critical Control platform | CriticalControl, verification record | AUTHORITATIVE_REFERENCE | R: Required — control definition and verification currency T: None W: None | Verification recorded / lapsed | CRITICAL | Critical control unverified is non-compensable — no aggregate score may offset it. | NOT_YET_VALIDATED |
| Enterprise IAM | Identity, Group, Session, Assurance level | AUTHORITATIVE_REFERENCE | R: Required — authentication and identity assertion T: Required — session/token issuance W: None | Revocation / session termination | CRITICAL | No identity assertion → read-only degraded mode; no confirm/authorize capability at all. | NOT_YET_VALIDATED |
| Analytics / Power BI or equivalent | Derived reporting extracts | DERIVED_CONSUMER | R: Outbound only T: None W: None | Scheduled extract | LOW | Reporting only. No operational decision depends on analytics availability. | NOT_YET_VALIDATED |
CObject authority / source-of-record matrix
Unresolved authority remains UNRESOLVED. No master is assigned merely to complete the matrix.
| Object | AuthoritativeSource / TransactionalAuthority | DerivedOwner | Read / Write | Steward | Fallback / Offline | ReconciliationRule |
|---|---|---|---|---|---|---|
| ControlledDocument | Aconex Aconex | Integrated Readiness (pinned version reference) | Federated read NONE | Document Control | Pinned version usable while source STALE Pinned revision cached read-only | Revision change triggers selective reassessment of dependent requirements only |
| Requirement | Engineering / regulatory register Requirement owner | Integrated Readiness applicability projection (PACE) | Federated read NONE | RuleOwner | Approved rule version usable Approved requirement set cached | New approved version supersedes; in-flight decisions keep pinned version |
| P6Activity | P6 P6 | Integrated Readiness window projection | Federated read NONE | Project Controls | STALE window permitted for forecast only, never for authorization Snapshot read-only | Window change → forecast reassessment; current decisions unaffected unless window overlaps |
| WBS | P6 P6 | Integrated Readiness mapping only | Federated read NONE | Project Controls | Cached structure Read-only | Structural change requires mapping revalidation |
| IWP | Smart Completions / BCSTools Work packaging owner | Integrated Readiness demand composition | Federated read NONE | Work Packaging | Snapshot for planning view only Read-only | Scope change → broad reassessment of the package |
| WorkPackage | Work packaging system Work packaging owner | Integrated Readiness readiness context | Federated read NONE | Construction Management | Snapshot Read-only | Composition change → recompose PACE inputs |
| JobCard | UNRESOLVED — enterprise decision required (ADR-15) UNRESOLVED | Integrated Readiness decision context | Federated read where a source exists UNRESOLVED | Construction Management | Not eligible until authority is resolved Read + governed capture; no authorization | Deferred pending ADR-15 closure — no master assigned to complete the matrix |
| Location | Federated Canonical Location Register (ADR-14 Option C) Location Steward | Integrated Readiness LocationWorkContext | Federated read Steward-governed register write | Location Steward (named, staffed) | Canonical register cached; vacancy → DISABLED_SAFE Context read-only; no stewardship acts offline | Register change → location continuity record and recontextualization of affected Job Cards |
| Equipment | Engineering information systems Engineering | Integrated Readiness placement/energy-state context | Federated read NONE | DataSteward (asset) | Cached identity only Read-only | Tag change → mapping revalidation before decision use |
| Person | HR HR | Integrated Readiness actor projection | Federated read NONE | HR DataSteward | Cached identity for view only Identity assertion required for any capture attribution | Leaver event revokes capability immediately; historical evidence unchanged |
| Competency | Training Training | Integrated Readiness validity projection | Federated read NONE | Training DataSteward | Cached validity window with explicit asOf Expiry evaluated against pinned asOf; expiry inside window → fail closed | Expiry/revocation → selective reassessment of affected assignments |
| Fitness | Occupational Health Occupational Health | Integrated Readiness eligibility flag only | Verdict-only federated read (no clinical data) NONE | OH DataSteward | Not eligible when UNVERIFIABLE Verdict cached; unverifiable → not eligible | Status change → immediate selective reassessment |
| Restriction | Labor Relations / OH / Q4 (per restriction type) — ADR-03 Respective source | Integrated Readiness restriction projection | Federated read NONE | RuleOwner + source steward | UNVERIFIABLE treated as restricting Cached; conservative interpretation | Restriction change → selective reassessment of affected persons/activities |
| RiskAssessment | Q4 Q4 | Integrated Readiness readiness input | Federated read NONE | ES&H | Pinned version only Read-only | Revision → selective reassessment of dependent Job Cards |
| CriticalControl | Critical Control platform Critical Control platform | Integrated Readiness non-compensable gate | Federated read NONE | ES&H CriticalControlOwner | None — unverified is non-compensable Verification currency evaluated against pinned asOf | Lapse → immediate HOLD on dependent decisions |
| Permit | Q4 Q4 | Integrated Readiness state projection | Federated read NONE (authorization stays in Q4) | Permit Authority | None for authorization; STALE view permitted read-only View only; no offline authorization | State change → selective reassessment; unmapped state → fail closed |
| PETAR | Q4 Q4 / designated authority | Integrated Readiness routing context | Federated read NONE | ES&H | None Routing proposal capture only | Approval state change → selective reassessment |
| Isolation | Q4 Q4 | Integrated Readiness energy-state context | Federated read NONE | Isolation Authority | None Read-only | Isolation change → SIMOPS re-evaluation for the Location |
| SanctionToTest | Q4 Q4 | Integrated Readiness context | Federated read NONE | Commissioning Authority | None Read-only | State change → SIMOPS and readiness re-evaluation |
| TemporaryModification | UNRESOLVED — candidate Q4 or engineering MoC (ADR-17) UNRESOLVED | Integrated Readiness context flag | Federated read where evidenced UNRESOLVED | Engineering / MoC owner | Not eligible Read-only | Deferred pending ADR-17 closure |
| ReadinessDecision | Integrated Readiness Integrated Readiness (human confirm/authorize) | Integrated Readiness | Owned AUTHORITATIVE_WRITE (own object only) | BusinessProductOwner | No offline authorization Not creatable offline | Decision baselines are immutable; supersession creates a new pinned baseline |
| EvidenceEvent | Integrated Readiness Integrated Readiness | Integrated Readiness | Owned AUTHORITATIVE_WRITE, append-only | BusinessProductOwner + CyberOwner | Queued capture permitted; authorization events are not Immutable pending queue with base version | Append on sync with original capture time and sync time both retained |
DFederation & identity architecture — ADR-13 / CA-01 closure
| Key | Candidate authority | MappingMethod | Mandatory for | Fail-closed scope |
|---|---|---|---|---|
| Project_ID | Enterprise project register | DETERMINISTIC | All decisions | Project scope only |
| Location_ID | Federated Canonical Location Register | GOVERNED_REGISTER | Location context, SIMOPS | Affected Location only |
| Equipment_ID | Engineering information systems | DETERMINISTIC + SEMANTIC_PROPOSAL | Equipment/energy-state rules | Rules depending on that tag only |
| P6_Activity_ID | P6 | DETERMINISTIC | Forecast readiness | Forecast dimension only |
| WBS_ID | P6 | DETERMINISTIC | Scope roll-up | Roll-up reporting only |
| IWP_NO | Smart Completions / BCSTools | DETERMINISTIC | Demand composition | Affected package only |
| WorkPackage_ID | Work packaging system | DETERMINISTIC | Package readiness | Affected package only |
| JobCard_ID | UNRESOLVED (ADR-15) | UNRESOLVED | Job Card decisions | Affected Job Card only |
| Person_ID | HR + enterprise IAM correlation | DETERMINISTIC | Any attributable act | That actor's capabilities only |
- MappingState (PROPOSED | SEMANTIC_PROPOSAL | VALIDATED | CONFLICT | UNRESOLVED | RETIRED)
- MappingMethod
- OriginMappingMethod
- CurrentMappingMethod
- SuggestedBy
- ValidatedBy
- AuthorityBasis
- ValidatedAt
- MappingVersion
- SEMANTIC_PROPOSAL is never consumable by IRDE. It is visible to stewards for validation only, and a decision that would require it is treated as missing mandatory mapping.
- CONFLICT, UNRESOLVED or missing mandatory mapping fails closed for the dependent decision only. Unrelated Job Cards and Locations continue to be decided normally.
- Mapping validation is an attributable act: ValidatedBy, AuthorityBasis and ValidatedAt are mandatory and produce an evidence event.
- MappingVersion is pinned into every decision baseline that consumed it, so a later remap never silently rewrites history.
- OriginMappingMethod is retained even after human validation, so AI/semantic provenance remains auditable forever.
EIntegration contract architecture
| Source | Object | Operations | Read / Event contract | Write contract | Failure / Reconciliation | Evidence | Validation |
|---|---|---|---|---|---|---|---|
| Q4 | Permit / Isolation / PETAR / SanctionToTest | READOBSERVEDERIVESNAPSHOTEVIDENCE_WRITE | Object + SourceNativeState + SourceVersion + asOf State-change notification; polling fallback with explicit staleness | No authoritative write. Optional decision back-reference is EVIDENCE_WRITE and only if the interface is confirmed. | Unavailable → SourceAvailabilityState=UNVERIFIABLE → dependent decisions fail closed On restore, re-read all objects referenced by open decisions; mismatch invalidates the affected baseline | Source read evidence with version and asOf | NOT_YET_VALIDATED |
| Aconex | ControlledDocument revision | READOBSERVESNAPSHOT | Document ID, revision, status, issued date Revision-change event preferred | None | STALE permitted for pinned revisions; UNVERIFIABLE blocks new pinning Revision delta triggers selective reassessment of dependent requirements | Version pin evidence | NOT_YET_VALIDATED |
| P6 | Activity / WBS | READSNAPSHOTDERIVE | Activity ID, window, WBS path, baseline ID Rebaseline notification | None | Forecast dimension degrades to UNVERIFIABLE; current decisions unaffected Window delta triggers forecast reassessment only | Forecast basis evidence | NOT_YET_VALIDATED |
| Training / OH / Labor Relations / HR | Competency / Fitness / Restriction / Person | READOBSERVEDERIVE | Verdict + validity window + asOf. No clinical or personal detail beyond eligibility. Change notification required for revocation to be timely | None | UNVERIFIABLE is conservative: not eligible for the restricted activity Change event → selective reassessment of affected assignments | Eligibility basis evidence (verdict-level only) | NOT_YET_VALIDATED |
| Critical Control platform | CriticalControl verification | READOBSERVEDERIVE | Control ID, verification currency, verifier role Verification recorded / lapsed | None | Unverified/unverifiable is non-compensable → HOLD Lapse → immediate selective reassessment | Critical control basis evidence | NOT_YET_VALIDATED |
| Enterprise IAM | Identity / session | READOBSERVE | Authenticated subject, assurance level, group claims Revocation / session termination | None | No assertion → read-only degraded mode; confirm/authorize capabilities disabled Revocation applies immediately; historical evidence unchanged | Authentication context in every attributable act | NOT_YET_VALIDATED |
| Analytics | Derived extract | SNAPSHOT | Outbound extract of derived readiness data only Scheduled | None | No operational impact Re-extract | Extract log | NOT_YET_VALIDATED |
FIAM / authority enforcement model
| Capability | Meaning | Enforcement |
|---|---|---|
| CanView | Read decision context | Server-side ABAC on every query |
| CanPropose | Create SYSTEM/HUMAN proposals with no decision effect | Server-side; proposals never alter verdicts |
| CanConfirm | Attributable confirmation of a prepopulated item | Requires resolved identity + evidence write success |
| CanValidate | Validate mappings and normalized states | Steward capability, SoD-separated from CanApprove |
| CanApprove | Approve rules/configuration versions | RuleOwner; approval creates an executable version |
| CanAuthorize | Authorize work-affecting decisions | Online only; never offline; never inferred from role name |
| CanAdminister | Platform/config administration | Privileged access, separately audited, no operational authorization rights |
- UI hiding is never an authority control. Every capability is evaluated server-side at the point of effect, and a forged direct call is denied and recorded.
- Delegation is explicit, time-bounded, scoped to the same or narrower attribute set, and cannot escalate the delegator's own capability.
- Temporary authority carries mandatory expiry; expiry is enforced at evaluation time, not by a batch job.
- Vacant authority yields AuthorityResolutionState=UNRESOLVED and capabilities DISABLED_SAFE. Work is not silently permitted.
- Segregation of duties: the same identity may not both propose and authorize the same decision, nor both validate a mapping and approve the rule that consumes it.
- Denied actions generate evidence (actor, attempted capability, object, reason, timestamp).
- Phase 3 condition satisfied structurally: no authorization record can exist without a resolved identity and a resolved authority basis — the write is rejected before persistence.
GDecision services architecture
HRule / configuration governance — ADR-16
- Requirement applicability
- Frequency
- Validity
- Authority
- No-compensation classification
- Q4 state mappings
- SIMOPS CUM rules
- Location inheritance
- Alert semantics
- Critical Control mappings
- Rule_ID
- Project_ID
- RuleType
- AuthorityBasis
- Version
- ApprovedBy
- EffectiveFrom
- EffectiveTo
- Supersedes
- ApprovalState
- Only ApprovalState=APPROVED with an effective window covering the evaluation instant is executable. DRAFT and PROPOSED configuration is never executable operational logic.
- Rule execution pins Rule_ID + Version into the decision baseline, so a later rule change never rewrites a past decision.
- No-compensation classification is configuration, not code, but it is approval-gated at the highest authority basis and is fail-closed when unclassified: an unclassified requirement is treated as non-compensable.
- Rule authoring, approval and administration are SoD-separated (RuleOwner approves; administrator cannot approve).
- SourceNativeState is stored verbatim and never overwritten. NormalizedOperationalState is a derived value produced only by an approved mapping rule version.
- An unmapped native state resolves to NormalizedOperationalState=UNKNOWN. Where the state is decision-critical this fails closed (HOLD/STOP) and raises a mapping conflict to the steward.
- APPROVED, AUTHORIZED or equivalent is never inferred from textual similarity, label matching, or AI proposal. Only an approved deterministic mapping can produce an enabling normalized state.
- Restriction objects remain authoritative in their source. Integrated Readiness projects them; UNVERIFIABLE restriction state is interpreted conservatively as restricting.
- Both states are surfaced in the UI so field users can see the native source language alongside the normalized decision meaning.
ILocation / SIMOPS technical model
| Entity | Technical role |
|---|---|
| CanonicalLocation | Federated register entry (ADR-14 Option C). Identity, hierarchy, steward, state. |
| LocationWorkContext | Inherited context for work at the location. Context inherits; authorization never does. |
| LocationConcurrentWorkSet | All Job Cards whose execution windows intersect at the location. |
| LocationCriticalRiskContext | Aggregated critical controls, energy states, exclusion zones and isolations in force. |
| SIMOPSAssessment | Pairwise interaction results plus the cumulative CUM-1…CUM-7 evaluation. |
| LocationContinuityRecord | Section X continuity across shifts, handovers and context changes. |
- Multiple Job Cards in one Location are evaluated as a set, not as independent decisions.
- Overlapping execution windows are computed on the pinned window projection; a window change is a SIMOPSContextChanged event.
- Pairwise interactions are computed for every intersecting pair; results are retained individually for attribution.
- Cumulative CUM-1…CUM-7 rules run over the whole concurrent set after pairwise evaluation.
- Blocker attribution is per Job Card: ID, discipline, blocker type, owner, action and evidence reference.
- Equipment placement, isolation interaction, energy-state conflicts and exclusion zones are context inputs to both pairwise and cumulative evaluation.
- Location continuity records survive shift change; a new shift inherits context and must re-establish authorization.
- PAIRWISE PASS NEVER IMPLIES LOCATION PASS — the cumulative verdict is computed independently and can be STOP with all pairs passing.
- INHERIT CONTEXT — NEVER INHERIT AUTHORIZATION.
JData & persistence architecture
| Class | Content | Mutability | Retention | Replication stance |
|---|---|---|---|---|
| AUTHORITATIVE_REFERENCE | Reference to source objects by identity + version; not the master itself | Immutable reference, refreshed projection | As long as any decision references it | No enterprise-master replication; identity + version only |
| TRANSACTIONAL | ReadinessDecision lifecycle owned by the readiness layer | Append-only state transitions | Project lifetime + statutory | Owned |
| DERIVED | Projections, normalized states, composed packages, SIMOPS results | Recomputable | Current + basis for pinned baselines | Derived, never authoritative |
| OPERATIONAL_SNAPSHOT | Pinned source versions consumed by a decision | Immutable | With the decision baseline | Minimal, decision-scoped |
| EVIDENCE | All attributable acts, denials, degraded entries/exits | Append-only, integrity-protected | Statutory maximum | Owned |
| CONFIGURATION | Rules, mappings, authority configuration, versions and approvals | Versioned, superseded never overwritten | Permanent | Owned |
- Historical source versions are retained only where a decision pinned them; the readiness layer does not become a shadow archive of enterprise systems.
- Offline queues persist as immutable pending items with base version and capture identity.
- Reconciliation results are first-class records: what diverged, how it was resolved, by whom, under what authority.
KEvent / change architecture
| Event | Trigger | Reassessment | Scope |
|---|---|---|---|
| WorkDemandChanged | DEMAND_TRIGGER | BROAD_REASSESSMENT | Affected package composition |
| SourceObjectChanged | CHANGE_TRIGGER | SELECTIVE_REASSESSMENT | Decisions that pinned the changed object |
| DocumentRevisionChanged | CHANGE_TRIGGER | SELECTIVE_REASSESSMENT | Requirements dependent on the revision |
| LocationChanged | CHANGE_TRIGGER | BROAD_REASSESSMENT | All Job Cards at the location + continuity record |
| CrewChanged | EVENT_TRIGGER | SELECTIVE_REASSESSMENT | Competency/fitness gates for the affected persons |
| EquipmentChanged | CHANGE_TRIGGER | SELECTIVE_REASSESSMENT | Equipment-dependent rules and SIMOPS energy state |
| RestrictionChanged | EVENT_TRIGGER | SELECTIVE_REASSESSMENT | Affected assignments |
| CriticalControlChanged | EVENT_TRIGGER | FAIL_CLOSED | Lapse immediately holds dependent decisions |
| AuthorizationChanged | EVENT_TRIGGER | SELECTIVE_REASSESSMENT | Decisions relying on the changed authority |
| ValidityChanged | TIME_TRIGGER | SELECTIVE_REASSESSMENT | Items whose validity window closed |
| SIMOPSContextChanged | CHANGE_TRIGGER | BROAD_REASSESSMENT | Whole concurrent work set at the location |
| SourceAvailabilityChanged | EVENT_TRIGGER | FAIL_CLOSED | Decisions dependent on the unavailable source only |
- SELECTIVE_REASSESSMENT is allowed only when the change is traceably scoped to specific pinned inputs and no cumulative rule input changed.
- BROAD_REASSESSMENT is required when the change alters set membership, location context or package composition — anything that can change a cumulative outcome.
- FAIL_CLOSED is required when the change makes a critical input unverifiable or removes an authority basis.
LOffline / reconciliation architecture
| Element | Design |
|---|---|
| MinimumSafeInformationSet | The bounded set a field user needs to work safely: current verdict, active blockers, critical controls, isolations, exclusion zones, contacts, and the asOf of each. |
| BaseVersion | Every offline package pins the exact source and rule versions it was built from. |
| OfflineCapturePackage | Structured capture only; no verdict change, no authorization, no rule execution that would create an enabling state. |
| ImmutablePendingQueue | Captures are append-only with capture identity and capture time; they cannot be edited to look like online acts. |
| Encryption | Local store encrypted at rest; device-bound keys; wipe on revocation. |
| Sync | Ordered, idempotent, resumable; sync time recorded separately from capture time. |
| ConflictDetection | Base version comparison on every item; divergence is a detected conflict, never an overwrite. |
| Reconciliation | Deterministic: no last-write-wins for critical objects. Conflicts route to the accountable steward with both versions visible. |
| RecoveryVerification | Explicit human verification step before the location returns to normal decision operation. |
MResilience / degraded mode architecture
| Dependency | Criticality | Permitted decision use | Degraded mode | Activation / Exit authority | Recovery evidence |
|---|---|---|---|---|---|
| Q4 permit/isolation state | CRITICAL | CURRENT only for authorization; STALE view-only; UNVERIFIABLE blocks | Read-only safety view with explicit asOf | Automatic on detection Authorized supervisor after re-read | Re-read record per open decision |
| Critical Control verification | CRITICAL | CURRENT only | Dependent decisions HOLD | Automatic ES&H authority | Verification currency re-confirmed |
| Competency / Fitness | CRITICAL | CURRENT; STALE only within the object's own configured validity | Restricted activity not eligible | Automatic Supervisor after source restore | Eligibility re-evaluated |
| Location register | CRITICAL | Cached canonical entries | No new location context creation; existing contexts read-only | Automatic Location Steward | Continuity record entry |
| P6 windows | HIGH | STALE acceptable for forecast | Forecast marked UNVERIFIABLE; current decisions unaffected | Automatic Planner | Forecast basis refreshed |
| Aconex documents | HIGH | Pinned revisions usable | No new version pinning | Automatic Document Control | Revision re-check on open decisions |
| Enterprise IAM | CRITICAL | Valid session only | Read-only; all confirm/authorize capabilities disabled | Automatic Automatic on restore | Session re-establishment logged |
| Analytics | LOW | Any | Reporting delayed | Automatic Automatic | Extract log |
No universal freshness window is defined. Validity is object- and decision-specific and is carried in approved configuration, because a competency validity and an isolation state validity are not comparable quantities.
NCyber architecture
| Area | Design | Status |
|---|---|---|
| Identity / SSO | Enterprise IAM federation; no local password store | ENTERPRISE_ASSUMPTION |
| MFA | Required for CanAuthorize and CanAdminister capability classes | ENTERPRISE_ASSUMPTION |
| Device trust | Managed-device posture required for offline packages | ENTERPRISE_ASSUMPTION |
| Mobile / offline protection | Encrypted local store, device-bound keys, remote wipe on revocation | CONFIRMED_CONTROL |
| Encryption in transit / at rest | TLS in transit; encryption at rest for all evidence and offline stores | CONFIRMED_CONTROL |
| Service identities | Per-integration service identity, least privilege, read-scoped by default | CONFIRMED_CONTROL |
| Secrets | Managed secret store; no secrets in configuration or client bundles | CONFIRMED_CONTROL |
| Privileged access | Administration separated from operational authorization; time-bounded elevation | CONFIRMED_CONTROL |
| Audit logging | Append-only, tamper-evident, includes denials and degraded transitions | CONFIRMED_CONTROL |
| Evidence integrity | Hash-chained evidence events; integrity verification is part of reconstruction | CONFIRMED_CONTROL |
| Administrative configuration access | Approval-gated; administrator cannot approve the rules they author | CONFIRMED_CONTROL |
OObservability model
| Signal | Classification |
|---|---|
| Source availability | TechnologyFailure |
| Integration failure | TechnologyFailure |
| Mapping conflict | OperationalReadinessFailure |
| Rule execution failure | TechnologyFailure |
| Decision latency | TechnologyFailure |
| Evidence-write failure | TechnologyFailure |
| Sync failure | TechnologyFailure |
| Stale projection | OperationalReadinessFailure |
| Degraded mode active | OperationalReadinessFailure |
| Unresolved authority | OperationalReadinessFailure |
| SIMOPS evaluation outcome | OperationalReadinessFailure |
TechnologyFailure and OperationalReadinessFailure are never merged into a single health indicator. A perfectly healthy platform can be reporting a legitimately unready location, and a degraded platform must never be read as a safety signal.
PAI boundary
- Extraction from documents (proposal only)
- Semantic search
- Classification proposal
- Mapping proposal (always SEMANTIC_PROPOSAL)
- Document comparison
- Anomaly detection
- Contextual recommendation
- Create a requirement
- Determine legal applicability independently
- Authorize
- Approve
- Accept risk
- Override HOLD / STOP
- Modify authoritative data autonomously
The deterministic core operates fully with AI unavailable. AI output enters the system only as a proposal object carrying OriginMappingMethod=SEMANTIC, which IRDE cannot consume until a human with the required capability validates it.
QTechnical support / operating model
| Role | Scope |
|---|---|
| L1 Support | Access, navigation, incident intake, degraded-mode guidance |
| L2 Application / Integration Support | Integration failures, sync failures, mapping conflict triage, projection staleness |
| L3 Engineering / Product | Defects, rule engine behaviour, performance, releases |
| BusinessProductOwner | Capability priorities, decision semantics, acceptance |
| DataSteward | Per-domain federation mapping validation and source data quality |
| RuleOwner | Approves executable rule versions including no-compensation classification |
| IntegrationOwner | Contract ownership per source system, availability targets |
| PlatformOwner | Runtime, capacity, resilience, degraded-mode readiness |
| CyberOwner | Identity, evidence integrity, privileged access, offline device posture |
| EnterpriseArchitectureOwner | Guards SoR integrity and prevents authority drift over the lifecycle |
- ADR-14 stewardship staffing remains CONTROLLED_OPEN. Location Stewards must be named and staffed per area before pilot; an unstaffed steward makes location capabilities DISABLED_SAFE by design, which is safe but not operable.
- P3-TRN-01 organizational change remains CONTROLLED_OPEN. The shift from 'system reports' to 'system prepopulates, humans authorize' is a role change, not a training task.
- A technically functional system with unstaffed governance is not production-ready. This is a Phase 5 acceptance condition, not an implementation detail.
ROpen ADR closure / dependency register
| ID | Subject | Phase 5 treatment | State |
|---|---|---|---|
| ADR-03 / CA-03 | Restriction & Q4 transaction semantics | Native/normalized separation, unmapped=UNKNOWN fail-closed, no textual inference | TECHNICAL_PATH_DEFINED |
| ADR-13 / CA-01 | Federation & identity | Governed mapping record, state machine, SEMANTIC_PROPOSAL non-consumable, decision-scoped fail-closed | TECHNICAL_PATH_DEFINED |
| ADR-14 | Location governance stewardship staffing | Design complete; staffing is an organizational dependency | CONTROLLED_OPEN |
| ADR-15 | JobCard authority | Left UNRESOLVED in the SoR matrix — no master assigned to complete the table | ENTERPRISE_DECISION_REQUIRED |
| ADR-16 | Rule & configuration governance | Versioned, approval-gated executable configuration with pinning | TECHNICAL_PATH_DEFINED |
| ADR-17 | TemporaryModification authority | UNRESOLVED; candidate sources documented only | ENTERPRISE_DECISION_REQUIRED |
| ADR-18…24 | Remaining architectural dependencies | Carried unchanged; none is closed by technical design alone | CONTROLLED_OPEN |
| CA-04 | Evidence retention scope | Retention classes defined; statutory scope requires legal confirmation | CONTROLLED_OPEN |
| OfflineAuthorization | Offline authorization prohibition | Enforced structurally: no authorization path exists offline | TECHNICALLY_CLOSED |
| P3-TRN-01 | Organizational change load | Carried into the operating model as a pilot precondition | CONTROLLED_OPEN |
STechnical risk register
| ID | Risk | Severity | Control | Residual |
|---|---|---|---|---|
| P5-R-01 | All source interfaces are NOT_YET_VALIDATED; assumed read/event capability may not exist | HIGH | Interface validation is a mandatory pilot precondition; no design depends on an invented capability, and polling fallbacks are specified | CONTROLLED |
| P5-R-02 | Federation mapping backlog exceeds steward capacity, causing widespread fail-closed | HIGH | Decision-scoped fail-closed limits blast radius; mapping conflict rate is an observability signal with staffing trigger | CONTROLLED |
| P5-R-03 | Q4 state mapping drift after a source upgrade silently changes normalized meaning | HIGH | Unmapped state → UNKNOWN → fail closed; mapping versions pinned in baselines; drift raises a conflict rather than a verdict | CONTROLLED |
| P5-R-04 | Offline reconciliation volume after long outages overwhelms stewards | MEDIUM | Immutable queue, deterministic conflict routing, recovery verification gate; no auto-merge | CONTROLLED |
| P5-R-05 | Evidence store growth and integrity verification cost | MEDIUM | Retention classes; hash-chained append-only design; snapshots scoped to pinned decisions only | CONTROLLED |
| P5-R-06 | ABAC configuration complexity across 7 dimensions becomes unmaintainable | HIGH | Authority configuration is versioned and approval-gated like rules; vacancy and expiry are fail-closed by default | CONTROLLED |
| P5-R-07 | Unstaffed stewardship makes the system safe but inoperable | HIGH | Named staffing is a pilot precondition (ADR-14, P3-TRN-01) | OPEN |
| P5-R-08 | JobCard and TemporaryModification authority unresolved limits end-to-end operation | HIGH | Left explicitly UNRESOLVED; scope of pilot must exclude decisions depending on those masters until resolved | OPEN |
| P5-R-09 | SIMOPS cumulative evaluation latency at high concurrency | MEDIUM | Set-scoped recomputation on SIMOPSContextChanged; latency is an observability signal | CONTROLLED |
| P5-R-10 | Analytics consumers treat derived readiness data as authoritative | LOW | Extracts are labelled DERIVED with asOf and decision baseline reference | CONTROLLED |
No risk is classified Critical. Two High risks (P5-R-07, P5-R-08) remain OPEN as organizational and enterprise-decision dependencies rather than technical defects, and both are pilot preconditions.
TOption C vs Option B technical escape test
| Dimension | Option B | Option C | Assessment |
|---|---|---|---|
| IntegrationCount | ~11 sources, most mediated through Q4 | ~12 sources integrated directly by the readiness layer | Marginal increase. Option B's mediation does not remove integrations, it relocates and hides them. |
| FederationComplexity | Lower in the readiness layer, higher inside Q4 configuration | Explicit, versioned, observable federation tier | Option C's complexity is visible and governable; Option B's is embedded in a platform not designed to steward it. |
| CustomLogic | Readiness logic split between Q4 extension and the readiness capability | Readiness logic bounded in one owned deterministic core | Option C owns less total logic and owns it in one place. |
| SupportBurden | Two-team diagnosis for most failures | Clear ownership per tier; L2 triage maps to IntegrationOwner | Comparable headcount, better attribution under Option C. |
| FailureDependencies | Q4 availability becomes a single point of failure for readiness decisions | Source loss is localized and decision-scoped | Decisive advantage for Option C — matches the fail-closed-but-bounded requirement. |
| OperatingSkillRequirement | Deep Q4 configuration skill | Integration and data stewardship skill | Different, not greater. Stewardship skill is required by ADR-14 under either option. |
| LifecycleTechnicalDebt | Readiness semantics coupled to one vendor's upgrade cycle | Readiness semantics independent of any single vendor lifecycle | Option C materially lower over an EPC lifecycle. |
| Scalability | Scales with Q4 platform limits | Scales per tier; SIMOPS compute isolated | Option C better, though neither is currently constrained by evidenced volumes. |
Phase 5 technical evidence shows Option C's additional federation burden is proportionate. The increase is concentrated in one explicitly designed, versioned and observable federation tier, and it buys localized failure behaviour, bounded owned logic and vendor-independent decision semantics. No material technical contradiction of the Phase 4 Rev.2 decision was found, so no ENTERPRISE OPTION REOPEN REQUEST is raised. Option B remains the controlled fallback and may only be adopted through an explicit architecture decision.
UTechnical solution acceptance register (§22)
| Acceptance condition | Verdict | Basis |
|---|---|---|
| Option C remains technically defensible | PASS | Section T escape test — OPTION_C_TECHNICALLY_CONFIRMED |
| No uncontrolled SoR is introduced | PASS | Section C matrix; unresolved masters left UNRESOLVED rather than assigned |
| ADR-13 / CA-01 has a technically governed path | PASS | Section D mapping record, state machine and decision-scoped fail-closed |
| ADR-16 has a governable configuration architecture | PASS | Section H versioned approval-gated executable rules |
| Authoritative write paths are explicit | PASS | Section E — writes limited to ReadinessDecision, EvidenceEvent, mappings and approved configuration |
| IAM enforcement is technically credible | PASS_WITH_CONDITION | Section F server-side ABAC is credible; enterprise IAM capabilities remain NOT_YET_VALIDATED |
| Decision evidence is reconstructable | PASS | Section G EAE + pinned versions in every baseline |
| Offline behaviour is bounded | PASS | Section L — capture permitted, authorization structurally impossible |
| Reconciliation is deterministic | PASS | Section L — base version conflict detection, no last-write-wins for critical objects |
| No-compensation is enforceable | PASS | Sections G and H — unclassified requirements default to non-compensable |
| Location / SIMOPS architecture remains intact | PASS | Section I — pairwise plus cumulative, context inherited, authorization never inherited |
| Stewardship / support ownership is credible | PASS_WITH_CONDITION | Section R model defined; ADR-14 staffing and P3-TRN-01 remain pilot preconditions |
| No Critical unresolved technical risk exists | PASS | Section S — zero Critical; two High risks open as organizational/enterprise dependencies |
HOLD POINT RESPECTED — no Pilot/MVP work has started. No API, database, deployment or live integration is authorized. Next decision: Technical Solution Definition Acceptance → Controlled Pilot/MVP Authorization.