PizarraContexto de trabajoDocumentos y registrosControles críticosRegistrosPreparaciónCondiciones bloqueantesAutorización
Aseguramiento / Técnico
PizarraContexto de trabajoDocumentos y registrosControles críticosRegistrosPreparaciónCondiciones bloqueantesAutorización
Aseguramiento / Técnico
Phase 6 rev.2 · controlled pilot / MVP · option C operating model

Controlled Pilot Definition — Federated Operating Model Validation

Phase 6 Rev.2 must demonstrate that Option C works as a federated operating model in the field — not merely that software functions. This record defines the pilot scope, controls, measurement method, source participation boundary, journey protocol, failure conditions and acceptance register.

Phase 6 recommendation

HOLD — PILOT DEFINED, EXECUTION NOT AUTHORIZED

Phase 6 Rev.2 is returned as a Controlled Pilot Definition and Readiness Baseline. The pilot scope, controls, measurement method, source participation boundary, journey protocol, failure conditions and acceptance register are defined and executable. Field execution is not authorized because two governing preconditions are unmet: Phase 5 Technical Solution Definition has no formal disposition, and no enterprise interface has moved beyond NOT_YET_VALIDATED. No baseline metric, value claim or adoption finding is reported, because none has been measured.

GOVERNING INPUT NOT SATISFIED: §Governing Input requires formal Phase 5 acceptance before Phase 6 begins. Phase 5 was issued 2026-08-30 with a recommendation of ACCEPT WITH CONTROLLED CONDITIONS and remains awaiting disposition. Phase 6 execution therefore remains fail-closed by construction.

HOLD POINT PRESERVED: no production-wide deployment, no live integration, no authoritative write to any enterprise source. Next decision: Controlled Pilot Acceptance → Production Readiness Authorization — which cannot be reached until the pilot is actually executed against instrumented scope.

Execution preconditions
  • P6-PRE-01 — Formal Phase 5 Technical Solution Definition disposition recorded.
  • P6-PRE-02 — At least the mandatory-decision interfaces (Q4, controlled documents, competency, critical control) moved from NOT_YET_VALIDATED to an evidenced participation class.
  • P6-PRE-03 — Named and staffed Location Stewards for every pilot Location (ADR-14 staffing).
  • P6-PRE-04 — Baseline BEFORE measurement executed with the documented method, before pilot activation.
  • P6-PRE-05 — ADR-15 (JobCard authority) and ADR-17 (TemporaryModification authority) either resolved or explicitly excluded from pilot scope in writing.
  • P6-PRE-06 — Rule set (applicability, validity, Q4 mappings, CUM rules, no-compensation classification) approved under ADR-16 before it becomes executable.

APilot scope & controls

AREA-3100 · Concentrator — Conveyor CV-07 corridor

Selected because it is operationally non-trivial: it carries concurrent multi-discipline work in shared physical space, stored energy, working at height, a live SIMOPS pattern and a genuine interdisciplinary handover. A scope without these characteristics cannot exercise the accepted model.

Required characteristicPilot provisionState
One clearly governed AreaAREA-3100 with a single accountable Area Superintendent and a defined stewardship boundary.READY TO EXECUTE
Multiple LocationsLOC-3100-CONC-CV07-TT01 (transfer tower), -TT02, -DRIVE-HSE, -GALLERY-A.READY TO EXECUTE
Mechanical + electrical + instrumentation workIdler/pulley change-out, MCC termination and belt-weightometer/speed-sensor loop checks.READY TO EXECUTE
Concurrent Job CardsJC-7701 / JC-7702 / JC-7703 with overlapping windows in TT01.READY TO EXECUTE
Real planning / lookaheadP6 3-week lookahead for the corridor; requires CONTROLLED_SNAPSHOT at minimum.BLOCKED BY PRECONDITION
EquipmentMobile elevating work platform, chain block, torque tooling, calibrated loop tester — placement context in TT01.READY TO EXECUTE
Workforce competencyHeight, LOTO, confined space, HV switching authorisations — one expiring inside the pilot window by design.BLOCKED BY PRECONDITION
Controlled documentationIsolation schematic, P&ID, loop drawing, lifting plan — version pinning required at decision time.BLOCKED BY PRECONDITION
At least one Life Critical exposureWorking at height in TT01 and stored/electrical energy on the CV-07 drive.READY TO EXECUTE
At least one SIMOPS caseOverhead mechanical work above an energised electrical termination in the same vertical envelope.READY TO EXECUTE
At least one environmental / area conditionWind threshold breach forecast inside the TT01 elevated-work window.READY TO EXECUTE
At least one Location continuity handoverMechanical completion in TT01 → electrical/instrumentation preparation reusing Location context.READY TO EXECUTE
Pilot controls
  • Integrated Readiness performs no authoritative write to any enterprise source during the pilot. Permitted writes are limited to ReadinessDecision, EvidenceEvent, governed mappings and approved configuration.
  • The pilot runs in parallel with the incumbent process. The incumbent process remains the process of record for any authorization until Pilot Acceptance.
  • A readiness verdict never replaces a statutory permit, isolation certificate or PETAR issued in its authoritative system.
  • Every pilot decision is recorded with resolved identity, authority basis, pinned source versions and rule version — or it is not recorded at all.
  • Any observed false READY halts the affected journey immediately and is recorded as a Critical pilot finding.
  • Architecture is not reopened by default; drift is recorded in the Architecture Drift Register (L), not silently absorbed.

BBaseline — before

NO BASELINE NUMBER IS INVENTED. Every metric below is NOT_YET_MEASURED. The measurement method is documented here BEFORE pilot execution, as required, so that the BEFORE capture is defensible and the AFTER comparison is attributable.

MetricUnitMeasurement methodEvidence sourceState
PackagePreparationTimehours per work packageElapsed time from package initiation to supervisor-declared prepared, from work-control records for the same corridor over the preceding 8 weeks.Work control / Q4 package historyNOT YET MEASURED
ApprovalLatencyhours from request to authorizationTimestamp delta between submission and authorization events in the authoritative work-control system.Q4 transaction logNOT YET MEASURED
RestrictionDetectionLeadTimehours before planned startTime between restriction becoming knowable and being recorded against the package; requires manual reconstruction where no event exists.Manual reconstruction + restriction registerNOT YET MEASURED
BlockerResolutionTimehours per blockerBlocker raised → blocker closed, by blocker type and owner.Work control / supervisor logNOT YET MEASURED
Reworkcount and hours per periodReworked preparation activities counted from supervisor logs; only preparation rework is counted, not construction rework.Supervisor logNOT YET MEASURED
DuplicateDataEntryentries per packageStructured observation of preparation sessions counting the same datum entered into more than one system.Timed observation studyNOT YET MEASURED
DocumentSearchEffortminutes per packageTimed observation of document location and version confirmation.Timed observation studyNOT YET MEASURED
FieldClarificationRequestscount per shiftCount of field-to-office clarification contacts recorded during the observation window.Shift logNOT YET MEASURED
LateSIMOPSDetectioncount and hours before startSIMOPS interactions identified at or after mobilisation rather than during planning.ES&H / shift recordsNOT YET MEASURED
WorkStartDelayminutes after planned startPlanned versus actual start at the workface, with primary delay cause recorded for later attribution.Field supervision recordNOT YET MEASURED
ReadinessFirstPass% of packages ready without reworkPackages authorized on first submission divided by total submitted.Q4 transaction logNOT YET MEASURED
AuthorizationQueueTimehours waiting on an authority holderTime a package spends awaiting an authority decision, separated from time awaiting a technical condition.Q4 transaction logNOT YET MEASURED
Measurement method (documented before execution)
  • BEFORE capture runs for a minimum of four full production weeks on the pilot corridor, ending before pilot activation.
  • Metrics with no existing evidence source are captured by timed observation and are labelled OBSERVED_BASELINE, never estimated.
  • Where no defensible BEFORE value can be captured, the metric is reported as UNMEASURABLE_BASELINE and is excluded from all value claims.
  • The same measurement definitions, observer protocol and shift pattern are used for AFTER capture.

CIntegration / source participation register

NO SOURCE IS DESCRIBED AS INTEGRATED WHERE IT IS ONLY SIMULATED. Critical Control participation is SIMULATED and Smart Completions, Labor Relations and analytics are NOT_CONNECTED. Object-level authority is preserved in every class: the readiness layer reads, observes, derives, snapshots and writes evidence — it never becomes the master.

SystemObjectsParticipationAuthority preservedNote
Q4 (work control)Permit, Isolation, SanctionToTest, PETAR, native lifecycle statesCONTROLLED MANUAL FEDERATIONQ4 remains authoritative and transactional; readiness layer observes onlyInterface NOT_YET_VALIDATED. Pilot proceeds by governed manual federation with dual-person state transcription and SourceNativeState preserved verbatim.
Aconex (controlled documents)ControlledDocument, revision, transmittalCONTROLLED SNAPSHOTAconex authoritative; readiness layer pins document version at decision timeSnapshot cadence and staleness window must be agreed per document class before activation.
P6 / Project ControlsP6Activity, WBS, lookaheadCONTROLLED SNAPSHOTP6 authoritative for schedule; readiness never writes datesWeekly snapshot; readiness consumes demand signal only.
Smart Completions / BCSToolsSystem, subsystem, completion statusNOT CONNECTEDUnchangedOut of pilot scope. Must not be described as integrated.
Engineering informationP&ID, loop drawing, schematic referencesCONTROLLED SNAPSHOTEngineering systems authoritativeVersion reference only; no derived engineering content.
HRPerson, assignmentCONTROLLED SNAPSHOTHR authoritative for identity and assignmentMinimum necessary attributes only.
TrainingCompetency, authorisation validityCONTROLLED SNAPSHOTTraining authoritativeExpiry inside the execution window must be visible to Forecast Readiness; snapshot staleness is decision-relevant and must be shown.
Occupational HealthFitness, RestrictionCONTROLLED MANUAL FEDERATIONOccupational Health authoritative; readiness sees fitness state, never clinical dataRestriction semantics governed by ADR-03 / CA-03. Unmapped states fail closed.
Labor RelationsRestriction, eligibilityNOT CONNECTEDUnchangedExcluded from pilot; any such restriction is handled outside the governed flow and recorded as a scope exclusion.
Critical Control platform (Forwood or equivalent)CriticalControl, verificationSIMULATEDPlatform remains authoritativeSIMULATED. This is NOT integration and must not be reported as such; Life Critical journeys therefore carry a declared evidence limitation.
Enterprise IAMIdentity, role, groupLIVE READIAM authoritative for identity; readiness layer owns operational authority attributesRequired for any real authorization record — no resolved identity, no authorization.
Analytics / Power BIRead-only projectionsNOT CONNECTEDUnchangedDeferred until after pilot acceptance to avoid publishing unvalidated readiness data.

DOperational journey results

All twenty journeys are defined, scripted and exercisable, and every one of them has been demonstrated against the prototype. NONE has been executed under real project conditions. SIMULATED_ONLY is therefore recorded as the field state — prototype demonstration is not pilot evidence and is not reported as such.

IDJourneyExpected behaviourPrototype evidenceField state
J-01Clean Job Card preparationAll mandatory conditions satisfied; verdict READY with pinned versions and named confirmer.SIMULATED — JC-7702 path in /p1SIMULATED ONLY
J-02Missing enabling conditionHOLD attributed to the specific condition, owner and action; not averaged away.SIMULATED — ECE blocker pathSIMULATED ONLY
J-03Incomplete competencyHOLD on the affected person/activity only; crew-level compensation refused.SIMULATED — competency registerSIMULATED ONLY
J-04Equipment / readiness conflictEquipment placement conflict surfaces in Location context with attribution.SIMULATED — TT01 placementSIMULATED ONLY
J-05Document revision changePinned version superseded → selective reassessment of dependent decisions only.SIMULATED — revision eventSIMULATED ONLY
J-06PETAR / work-control requirementPETAR routing to the correct authority; readiness never issues the PETAR.SIMULATED — routing pathSIMULATED ONLY
J-07Life Critical / Critical Control blockerNon-compensable STOP; no aggregate score can clear it.SIMULATED — Critical Control platform is SIMULATED, so this journey cannot be field-evidenced in pilot as scopedBLOCKED BY PRECONDITION
J-08Pairwise SIMOPSInteraction between two Job Cards identified with both parties attributed.SIMULATED — JC-7701 × JC-7702SIMULATED ONLY
J-09Cumulative SIMOPSCUM rule fires even where every pair passes.SIMULATED — CUM-2 / CUM-5 / CUM-7 in /p1SIMULATED ONLY
J-10Overlapping execution windowsConcurrency computed on windows, not on calendar day.SIMULATED — TT01 window overlapSIMULATED ONLY
J-11Forecast expiry inside work windowCurrentReadiness READY while ForecastReadiness HOLD; intervention lead time recorded.SIMULATED — competency expiry + wind breachSIMULATED ONLY
J-12Location continuity between disciplinesContext reused, applicability re-evaluated, authorization objects not inherited.SIMULATED — mechanical → electrical handoverSIMULATED ONLY
J-13Crew or equipment changeChange trigger → selective reassessment of affected conditions.SIMULATED — crew swap eventSIMULATED ONLY
J-14Selective reassessmentOnly dependent decisions reassessed; unrelated Job Cards untouched.SIMULATED — event scopingSIMULATED ONLY
J-15Unbounded changeScope of impact indeterminable → broad reassessment or fail closed.SIMULATED — rule version changeSIMULATED ONLY
J-16Source unavailableDependency marked STALE/UNVERIFIABLE; permitted decision use restricted per object.SIMULATED — degraded modeSIMULATED ONLY
J-17Offline captureCapture permitted with BaseVersion; authorization refused offline.SIMULATED — field modeSIMULATED ONLY
J-18Reconciliation after reconnectDeterministic conflict detection; no last-write-wins on critical objects.SIMULATED — pending queue replaySIMULATED ONLY
J-19Authority-denied actionServer-side denial with denied-action evidence; UI hiding is not the control.SIMULATED — /p1/authority console (Phase 2A F-05 closure)SIMULATED ONLY
J-20Stewardship unavailableAuthorityResolutionState UNRESOLVED; dependent capabilities DISABLED_SAFE.SIMULATED — G-01 vacant stewardship scenarioSIMULATED ONLY

ELocation / SIMOPS evidence

ElementValidationState
LocationConcurrentWorkSetTT01 carries JC-7701 (mechanical, height), JC-7702 (electrical termination), JC-7703 (instrumentation loop) with overlapping windows.SIMULATED ONLY
PairwiseSIMOPSEach of the three pairs assessed independently for interaction type and severity.SIMULATED ONLY
CumulativeSIMOPSCUM-1…CUM-7 evaluated across the full concurrent set after pairwise assessment completes.SIMULATED ONLY
LocationCriticalRiskContextHeight + stored energy + live electrical exposure aggregated as Location-level critical risk context.SIMULATED ONLY
JobCardBlockerAttributionEvery Location blocker names Job Card, discipline, blocker type, owner, action and evidence reference (Phase 2A F-02 closure).SIMULATED ONLY
SharedIsolationContextOne isolation boundary serving multiple Job Cards; removal by one party affects all — must be visible to all.BLOCKED BY PRECONDITION
ExclusionZoneInteractionElevated-work drop zone intersecting the electrical work position.SIMULATED ONLY
EnergyStateInteractionMechanical work requiring de-energised state versus commissioning work requiring energisation.SIMULATED ONLY

PAIRWISE PASS NEVER IMPLIES LOCATION PASS. The pilot must produce at least one observed case where every pairwise assessment passes and a cumulative rule still returns a Location-level restriction. If the pilot cannot produce such a case, the cumulative model is unproven and Phase 6 cannot recommend production readiness on that dimension.

FContinuity evidence

TT01 mechanical idler change-out completes → Location context (access route, exclusion zone geometry, isolation boundary, area conditions, equipment placement, hazard inventory) persists → electrical termination and instrumentation loop check prepare in the same Location → valid contextual information is reused → applicability is re-evaluated for the new discipline → permits, isolations, PETAR and competency authorisations are NOT inherited.

INHERIT CONTEXT — NEVER INHERIT AUTHORIZATION.

MeasureMethodState
Repeated information collection avoidedCount context items reused versus re-collected in the successor discipline's preparation.NOT YET MEASURED
Unnecessary document search avoidedTimed observation of successor preparation versus BEFORE baseline for the same document classes.NOT YET MEASURED
Duplicate verification avoidedCount of verifications reused under a still-valid basis versus repeated.NOT YET MEASURED

AVOIDED MANDATORY REVALIDATION IS NOT A PRODUCTIVITY BENEFIT. Any revalidation that governance requires per discipline, per authorization or per shift is excluded from the benefit calculation even where the system could technically have reused it.

GCurrent / forecast readiness

The pilot must show a Job Card that is CurrentReadiness = READY and ForecastReadiness = HOLD for its planned execution window — conditions valid now but insufficient at the time of work.

CaseExpected behaviour
Competency authorisation expires between now and the planned windowForecast HOLD with expiry date and named holder; current state unaffected.
Wind threshold breach forecast inside the elevated-work windowForecast HOLD on the height-dependent activity only; unrelated activities unaffected.
Document revision scheduled to supersede a pinned version before executionForecast HOLD pending re-pin and reassessment.
Isolation validity expires before the planned window closesForecast HOLD; extension routed to the isolation authority, never inferred.
Lookahead lead-time question

Is forecast information produced early enough to support lookahead intervention? Measured as the interval between forecast HOLD publication and the planned execution window start, compared against the practical lead time required by the responsible owner to resolve that condition class.

NOT YET MEASURED

HOffline / reconciliation evidence

ElementCheckState
OfflineCaptureField observations, verification results and condition evidence captured without connectivity, against a declared MinimumSafeInformationSet.SIMULATED ONLY
PendingQueueImmutable ordered queue; entries cannot be edited or deleted before reconciliation.SIMULATED ONLY
BaseVersionEvery offline capture records the source versions it was based on.SIMULATED ONLY
ReconnectReconnection triggers replay, not silent overwrite.SIMULATED ONLY
ConflictDetectionBaseVersion mismatch detected deterministically; no last-write-wins on critical objects.SIMULATED ONLY
ReconciliationConflicts routed to a named authority for disposition with evidence retained on both sides.SIMULATED ONLY
RecoveryVerificationExplicit operational verification step before work resumes on affected decisions.SIMULATED ONLY

OFFLINE CAPTURE IS PERMITTED WHERE GOVERNED. OFFLINE AUTHORIZATION IS NOT PERMITTED. The pilot must attempt an offline authorization and record the refusal as evidence.

SERVICE_RESTORED ≠ OPERATIONALLY_RECOVERED. Restoration of connectivity does not restore decision validity; reconciliation and recovery verification must complete first.

IField acceptance findings

DimensionMethodState
Supervisor usabilityTask-based observation with think-aloud during real preparation; time-on-task and error events recorded.NOT YET MEASURED
Superintendent confidenceStructured interview on whether the verdict is trusted enough to act on without independent re-checking.NOT YET MEASURED
Field comprehensionComprehension check at the workface: can the crew state why the card is READY/CONDITIONAL/HOLD and what would change it.NOT YET MEASURED
ES&H usabilityObservation of SIMOPS and Critical Control review tasks.NOT YET MEASURED
Project Controls usabilityObservation of lookahead and forecast interaction.NOT YET MEASURED
Blocker visibilityCan the responsible owner locate their own blockers unaided within a defined interval.NOT YET MEASURED
Ownership clarityPercentage of blockers where the named owner agrees they are the owner.NOT YET MEASURED
Decision latencyTime from all conditions satisfied to confirmed authorization.NOT YET MEASURED
Cognitive burdenObserved steps, screens and re-reads per decision; supplemented by subjective workload rating.NOT YET MEASURED
Bypass / workaround behaviourEvery observed attempt to work outside the governed flow is logged with context and root cause.NOT YET MEASURED
Workaround root causeMeaningGoverned response
UsabilityThe governed path is available and correct but too slow, unclear or hard to complete.Interface or interaction change; architecture unaffected.
ProcessThe governed path does not match how the work is actually sequenced.Process alignment or scope correction; may generate a controlled action.
AuthorityThe person who must act does not hold the capability, or the holder is absent.Authority model or delegation/staffing correction (ADR-14).
PerformanceThe governed path is too slow to be usable at the point of decision.Technical remediation; recorded in the incident register.
GovernanceThe rule itself is wrong, over-applied or unapproved.ADR-16 rule change through governed approval — never a local override.
ChangeResistanceThe governed path works and is understood but is not adopted.P3-TRN-01 organizational change action.

A WORKAROUND IS NEVER CLASSIFIED AS A TRAINING PROBLEM BY DEFAULT. Root cause must be determined and recorded against one of the six classes above. ChangeResistance may only be concluded after Usability, Process, Authority, Performance and Governance have been excluded with evidence.

JStewardship & support findings

ResponsibilityExercised byMeasureState
Federation mappingData StewardMapping exceptions raised per week; time to governed validation; proportion left UNRESOLVED.NOT YET MEASURED
Rule configurationRule OwnerRule change requests per week; approval turnaround; unapproved-config attempts blocked.NOT YET MEASURED
Location stewardshipNamed Location Steward per LocationSteward availability across shifts; time in UNRESOLVED state; decisions blocked by vacancy.BLOCKED BY PRECONDITION
User supportL1 SupportContacts per user per week; first-contact resolution rate.NOT YET MEASURED
Integration incidentsL2 Application / Integration SupportIncidents per week by source; mean time to detect and restore; decisions affected.NOT YET MEASURED
Authority questionsBusiness Product Owner + Area SuperintendentEscalations per week; time to resolution; recurrence.NOT YET MEASURED
Evidence questionsBusiness Product OwnerReconstruction requests served; time to reconstruct a decision end-to-end.NOT YET MEASURED

AN ARCHITECTURE THAT ONLY WORKS WHILE THE DESIGN TEAM IS PRESENT IS NOT OPERATIONALLY SUSTAINABLE. The pilot must run at least two full weeks with the design team explicitly withdrawn from operational duty. Any responsibility that silently reverts to the design team is recorded as a stewardship failure, not as a support call.

KValue measurement

Chain stageMeaningRule
TimeSavedMeasured reduction in time spent on a defined preparation task.Measured only, never inferred.
TimeReleasedSaved time that actually becomes available capacity for the same resource.Requires evidence that the resource was not immediately reabsorbed by another constraint.
ProductiveTimeCapturedReleased time demonstrably converted into productive work.Requires observed downstream productive output. Absent that evidence, the chain stops at TimeReleased.
EfficiencyNOT YET MEASURED
  • Reduced document search
  • Reduced re-entry
  • Reduced preparation rework
  • Reduced preparation effort
Operational EffectivenessNOT YET MEASURED
  • Earlier blocker detection
  • Earlier SIMOPS intervention
  • Better forecast lead time
  • Fewer late readiness surprises
AssuranceNOT YET MEASURED
  • Improved evidence completeness
  • Decision reconstruction success rate
  • Authority traceability
  • Control integrity
StrategicNOT YET MEASURED
  • Reusability across areas
  • Cross-system integration maturity
  • Governance maturity

NO SAVING IS INVENTED. Zero value is claimed in this record because no measurement has occurred. Efficiency, Operational Effectiveness, Assurance and Strategic value are reported separately and are never summed into a single headline figure.

LCausal attribution

FieldDefinition
PrimaryConstraintThe constraint that actually governed the start of work in the observed case.
ConcurrentConstraintsAll other constraints active at the same time that would have delayed work independently.
InterventionThe specific Integrated Readiness behaviour claimed to have changed the outcome.
CounterfactualWhat the evidence indicates would have happened without that intervention.
ObservedOutcomeWhat actually happened, with timestamps.
AttributableEffectThe portion of the outcome defensibly attributable to the intervention after concurrent constraints are removed.

PROHIBITED INFERENCE: WorkStartedEarlier ⇒ DigitalSolutionSavedAllDelay. Where several constraints were concurrently binding, the attributable effect is limited to the constraint the intervention actually relieved. Where the primary constraint was not addressed by Integrated Readiness, the attributable effect is zero even if the outcome improved.

MArchitecture drift register

IDDrift watchedDetectionControlState
P6-DR-01Silent simplification of Option C into Option BAny proposal to centralize an authoritative object into the readiness layer, or to hold a source master locally.Requires an explicit architecture decision per the Phase 4 fallback rule. No implementation team may simplify silently.OPEN
P6-DR-02Manual federation hardening into a shadow masterCONTROLLED_MANUAL_FEDERATION entries being edited in the readiness layer rather than re-federated from source.Manual federation records are transcriptions with SourceNativeState preserved; they carry no authority and expire.OPEN
P6-DR-03Compensation creeping in through scoring or dashboardsAny aggregate indicator that can display green while a non-compensable condition fails.No-compensation classification is enforced in the engine, not in presentation.OPEN
P6-DR-04Authorization inherited through Location continuitySuccessor discipline proceeding on a predecessor's permit, isolation or PETAR.Continuity carries context only; authorization objects are re-evaluated and re-issued.OPEN
P6-DR-05Offline authorization introduced under field pressureAny request to confirm, approve or authorize while disconnected.Fail closed. Change requires competent governance disposition, not a pilot decision.OPEN
P6-DR-06SIMULATED sources reported as integratedAny status report describing Critical Control participation as integration.Source Participation Register (C) is the single source of truth for integration claims.OPEN

NTechnical / operational incident register

IDFailure conditionSeverityHandlingState
P6-FC-01False READYCRITICALImmediate journey halt, root cause, and automatic Phase 6 failure of §17 condition 1.NOT YET MEASURED
P6-FC-02False HOLDHIGHRecorded with rule version and inputs; drives rule correction under ADR-16.NOT YET MEASURED
P6-FC-03Late SIMOPS detectionHIGHRecorded with detection point relative to mobilisation.NOT YET MEASURED
P6-FC-04Unresolved authorityHIGHRecorded with duration in UNRESOLVED and decisions blocked.NOT YET MEASURED
P6-FC-05Stale source useCRITICALAny decision made on a source beyond its permitted staleness is a critical finding.NOT YET MEASURED
P6-FC-06Incorrect federation mappingHIGHRecorded with mapping method, suggester, validator and blast radius.NOT YET MEASURED
P6-FC-07Evidence gapCRITICALAny decision that cannot be reconstructed end-to-end is a critical finding.NOT YET MEASURED
P6-FC-08Offline reconciliation conflictMODERATEExpected and acceptable if detected and dispositioned; unacceptable if silently resolved.NOT YET MEASURED
P6-FC-09Excessive manual workaroundHIGHRoot-caused against the six classes; not defaulted to training.NOT YET MEASURED
P6-FC-10Unacceptable latencyMODERATERecorded against the decision point where it occurred.NOT YET MEASURED
P6-FC-11Stewardship overloadHIGHRecorded as demand versus staffed capacity; feeds ADR-14 staffing.NOT YET MEASURED

THESE ARE LEARNING EVIDENCE AND ARE NOT HIDDEN. Every occurrence is recorded with inputs, rule version, identity and timestamp, and is reported in the Phase 6 output whether or not it is favourable.

OOption C sustainability assessment

DimensionMeasureSustainability thresholdState
FederationMaintenanceEffortSteward hours per week maintaining mappings across the nine governed keys.Sustainable if absorbable by the ADR-14 staffed roles without design-team support.NOT YET MEASURED
MappingExceptionsExceptions raised per 100 federated objects per week, and proportion needing human validation.Sustainable if exception rate is stable or declining and validation keeps pace with demand.NOT YET MEASURED
IntegrationFailureRateSource unavailability and contract failures per source per week, and decisions affected.Sustainable if failures stay localized to the dependent decision, as designed.NOT YET MEASURED
StewardshipDemandLocation steward decisions per shift and time in vacancy.Sustainable if coverage exists across all operating shifts.BLOCKED BY PRECONDITION
SupportDemandL1/L2 contacts per user per week and escalation rate to L3.Sustainable if L3 demand trends down after the first four weeks.NOT YET MEASURED
OperationalBenefitEvidence-based Efficiency, Operational Effectiveness and Assurance findings.Federation burden must be proportionate to measured benefit.NOT YET MEASURED
Option C verdict
NOT_YET_DETERMINABLE

Option C operational sustainability cannot be assessed without executed pilot measurement. No OPTION_C_REASSESSMENT_FINDING is raised, because there is no evidence to raise one on — and equally, no confirmation is claimed. If executed measurement later shows federation burden materially undermining benefit, an OPTION_C_REASSESSMENT_FINDING is raised. Migration to Option B is never automatic and requires an explicit architecture decision.

PResidual risk register

IDRiskSeverityStateControl
P6-R-01Phase 5 has no formal disposition; Phase 6 governing input is unsatisfied.HIGHOPENPilot execution is fail-closed until disposition is recorded.
P6-R-02All enterprise interfaces remain NOT_YET_VALIDATED; participation classes are intentions, not evidence.HIGHOPENP6-PRE-02 must complete before activation; unvalidated sources degrade to CONTROLLED_MANUAL_FEDERATION or NOT_CONNECTED.
P6-R-03Critical Control participation is SIMULATED, so the Life Critical journey cannot be field-evidenced as scoped.HIGHOPENEither evidence the interface or declare J-07 out of pilot evidence scope explicitly.
P6-R-04Location Stewards not yet named or staffed across shifts (ADR-14).HIGHOPENP6-PRE-03. Vacancy produces UNRESOLVED and DISABLED_SAFE by design, but a pilot spent in vacancy proves nothing.
P6-R-05ADR-15 JobCard and ADR-17 TemporaryModification authority remain UNRESOLVED.HIGHOPENResolve or exclude in writing before activation (P6-PRE-05).
P6-R-06Manual federation introduces transcription error into decision-critical state.MODERATEOPENDual-person transcription, SourceNativeState preserved verbatim, expiry on manual records.
P6-R-07Parallel running doubles preparation effort and may itself suppress adoption.MODERATEOPENMeasure separately; parallel-running overhead is excluded from adoption root-cause analysis.
P6-R-08Pressure to report benefit before measurement completes.MODERATEOPENValue rule: no saving is invented; the value chain stops where evidence stops.
P6-R-09Organizational change load (P3-TRN-01) confounds adoption findings.MODERATEOPENSix-class workaround root cause prevents defaulting to training or resistance.

QPilot acceptance register & go / hold recommendation

ID§17 acceptance conditionVerdictBasis
P6-AC-01No false READY observed for mandatory conditionsNOT YET MEASUREDNo field execution. Non-compensation is enforced in the engine and demonstrated in Phase 0C/2A, but that is design evidence, not pilot evidence.
P6-AC-02No critical authority bypass occursNOT YET MEASUREDServer-side enforcement demonstrated (Phase 2A F-05); no field attempt observed.
P6-AC-03Evidence remains reconstructableNOT YET MEASUREDReconstruction demonstrated on synthetic decisions only.
P6-AC-04Cumulative SIMOPS behaves correctlyNOT YET MEASUREDCUM-1…7 exercised synthetically (G-02); no real concurrent work set assessed.
P6-AC-05Continuity does not inherit authorizationNOT YET MEASUREDInvariant enforced in the model; no real handover observed.
P6-AC-06Offline / reconciliation operates safelyNOT YET MEASUREDSimulated only; no real network loss under field conditions.
P6-AC-07Federation burden is manageableNOT YET MEASUREDRequires executed measurement of maintenance effort and exception rate.
P6-AC-08Support / stewardship model is viableOPENStewards not yet staffed; design-team-withdrawn period not yet run.
P6-AC-09Field users can understand decisionsNOT YET MEASUREDNo comprehension check has been performed with real crews.
P6-AC-10No Critical unresolved pilot finding existsNOT YET MEASUREDNo pilot findings exist at all.
P6-AC-11Value claims are evidence-basedPASSSatisfied by construction: no value is claimed, because none is measured.
Go / hold recommendation
HOLD

Phase 6 cannot recommend Production Readiness. Ten of eleven acceptance conditions are NOT_YET_MEASURED or OPEN because the pilot has not been executed, and the governing input (formal Phase 5 acceptance) is unsatisfied. This is a fail-closed outcome, which is the correct behaviour of the accepted model — not a defect.

To proceed
  • Record the Phase 5 Technical Solution Definition disposition.
  • Close P6-PRE-01 … P6-PRE-06.
  • Authorize Controlled Pilot Execution as a separate disposition against this defined scope, controls and measurement method.
  • Execute the four-week BEFORE baseline, then the pilot with the design team withdrawn for at least two weeks.
  • Return Phase 6 Execution Results populating sections B, D–K and N–Q with measured evidence.

Technology does not create readiness — it makes readiness visible, verifiable and traceable. Integration does not transfer accountability. Application access is not operational authority. Presentation familiarity does not create source authority. Synthetic demonstration data only.