PizarraContexto de trabajoDocumentos y registrosControles críticosRegistrosPreparaciónCondiciones bloqueantesAutorización
Aseguramiento / Técnico

SADR Material Finding Remediation & Functional Baseline Revision

COMPLETE PENDING INDEPENDENT RETESTCANDIDATE — NOT FROZEN
Remediation ID
PH6A-SADR-REM-REV0
Parent review
PH6A-II-SADR-REV0
Target output
PH6A-FPSO-FUNCTIONAL-BASELINE-REV1-CANDIDATE
Mandate
DEFECT_CORRECTION

Finding → RootCause → AffectedContract → CorrectedSemanticDefinition → AcceptancePredicate → RegressionImpact → ResidualRisk. A contractual defect is never repaired as a UI fix.

NOT ARCHITECTURE REDESIGNNOT FEATURE EXPANSIONNOT PROTOTYPE IMPLEMENTATIONNOT BECHTELIZATIONNOT DEMONSTRATIONNOT OPERATIONAL VALIDATION

A. Remediation executive summary

Defect correction at the level where the defect resides

All four material SADR findings have been corrected at the level at which the defect actually resides: three as functional-contract corrections (FC-FPSO-08 signature applicability, FC-FPSO-02/05 dependency and concurrency semantics, FC-FPSO-07 tool temporal validity) and one as a traceability/UX correction (two orphan affordances). The systemic hypothesis SYS-01 — temporal decoherence of package facts — is remediated by a single cross-contract rule, NO_MATERIAL_DECISION_MAY_RELY_ON_A_TEMPORALLY_EXPIRED_FACT, with governed EvaluationTimestamp as an explicit decision input rather than an ambient wall clock.

Corrections are expressed as amended semantic definitions plus acceptance predicates, not as new states where an attribute or reason code carries the meaning safely. Two new states were admitted (SIGNATURE_NOT_VALID_FOR_CURRENT_VERSION as an evaluated applicability result, and TOOL_READINESS_LAPSED) and one previously proposed state was rejected as decorative.

SADR_MATERIAL_FINDING_REMEDIATION = COMPLETE_PENDING_INDEPENDENT_RETEST. The candidate baseline is not frozen, not accepted and does not self-certify; only an independent retest may freeze it.

Architecture unchanged. PH6A-IADA-REV1 and PH6A-IADA-REV1-SEAL-01 are untouched. No operational closure evidence is produced or implied by this interaction.

MacroPromptA_Authorized
FALSE
Bechtelization
NOT AUTHORIZED
PrototypeImplementation
NOT AUTHORIZED
OperationalClosureEvidence
NOT YET ACQUIRED
Phase6A
HOLD
Phase6B
NOT AUTHORIZED
Phase7
NO GO
BC09Protection
ACTIVE
PilotExposure
PROHIBITED

B. Input baseline integrity

BaselineRoleStatusConsumed asDisposition
PH6A-FPSO-FUNCTIONAL-BASELINE-REV0Functional contracts FC-FPSO-01…08FROZEN BUT SUPERSEDED FOR REMEDIATION PURPOSESCorrected clause-by-clause into a REV1 candidate; REV0 preserved verbatim for audit history.SUPERSEDED BY CANDIDATE
PH6A-FPSO-IAD-REV116 screens, 18-step field journeyACCEPTED BUT RECONCILIATION REQUIREDDelta register only — no wholesale screen redesign.SUPERSEDED BY CANDIDATE
PH6A-II-SADR-REV0Finding source of recordHOLD14 findings; 4 material findings mandatory in scope; counts adopted as stated, not renegotiated.UNCHANGED
PH6A-IADA-REV1Integrated architecture baselineFROZENConstraint only. ArchitectureReopenRequired = FALSE.UNCHANGED
PH6A-IADA-REV1-SEAL-01Design provenance sealACTIVE AND FROZENVerified unmodified at remediation entry and exit.UNCHANGED

C. SADR finding reconciliation

No finding may be declared finally closed in this interaction

F-SADR-01REMEDIATED PENDING INDEPENDENT RETESTFUNCTIONAL CONTRACT CORRECTION
Original condition
SIGNED is terminal; no successor for a signed object invalidated after signing; timestamp-authority failure undefined.
Root cause
The contract conflated two different things under one state: the historical fact that a signature was applied, and the present question of whether that signature authorizes the object as it now stands.
Correction
Split the concept. SignatureEvidence is immutable historical evidence bound to SIGNED_VERSION_N (ObjectVersion, DecisionContext, DecisionRight, IntegrityReference, EvaluationTimestamp). SignatureApplicability is an evaluated result, computed at read and at decision time against the current object version and context; where they differ the evaluated result is SIGNATURE_NOT_VALID_FOR_CURRENT_VERSION. SIGNED remains terminal only where the signed object is genuinely immutable and closed.
Acceptance predicate
SignatureApplicable = TRUE only if SignedObjectVersion = CurrentObjectVersion AND SignedDecisionContextHash = CurrentDecisionContextHash AND DecisionRight valid at EvaluationTimestamp AND IntegrityReference verifies. Otherwise SIGNATURE_NOT_VALID_FOR_CURRENT_VERSION, and the historical SignatureEvidence row is unchanged.
Affected contract
FC-FPSO-08 DigitalSignatureAssurance · Signature lifecycle · postconditions · timestamp dependency
Regression tests
REM-R01, REM-R02, REM-R03, REM-R09, REM-R16
Residual risk
MEDIUM — the PKI/timestamp-authority owner is an unresolved external dependency (DEP-07/DEP-08). Interim behaviour is deterministic refusal, so the risk is availability, not validity.
Retest required
Independent retest of ADV-01, ADV-03, ADV-05, ADV-13 and illegal-state H-04.
F-SADR-02REMEDIATED PENDING INDEPENDENT RETESTFUNCTIONAL CONTRACT CORRECTION
Original condition
FC-02/FC-05 ambiguity: ambiguous active revisions unnamed; IPERC delta materiality had no classification predicate; concurrent edit granularity unstated.
Root cause
Schema completeness was mistaken for semantic sufficiency. Each clause named an outcome without naming the inputs that determine the outcome.
Correction
(a) Ambiguous active revision is an evaluated condition REVISION_ELECTION_UNRESOLVED — retrieval returns the candidate set with no election; no auto-election. (b) Delta materiality is a recorded classification with declared inputs (affected requirement class, control removal, hazard introduction, scope/location change) producing one of four deterministic dependency outcomes. (c) Concurrency is row-level with a document-level base-version guard.
Acceptance predicate
Given identical revision sets, identical rule versions and identical EvaluationTimestamp, two independent implementations return the same election outcome, the same materiality class and the same conflict determination.
Affected contract
FC-FPSO-02 ContextualDocumentRetrieval, FC-FPSO-05 IPERCContinuo · Retrieval election · delta materiality · row concurrency
Regression tests
REM-R04, REM-R05, REM-R06, REM-R12, REM-R13, REM-R14
Residual risk
LOW-MEDIUM — materiality inputs are governed configuration; the ES&H authority must ratify the input list (DEP-04).
Retest required
Independent re-execution of ADV-08, ADV-10, ADV-17 and the testability audit.
F-SADR-03REMEDIATED PENDING INDEPENDENT RETESTTRACEABILITY CORRECTION
Original condition
Two orphan UI actions: register bulk acknowledge; re-open of a closed pre-start record.
Root cause
Interaction design added affordances by analogy with register UIs, without a governing transition; the prior OrphanUIActions = 0 was asserted, not reconstructed.
Correction
Bulk acknowledge classified UX_ONLY_REMOVE and deleted from the candidate interaction design. Re-open classified EXISTING_CONTRACT_TRACEABILITY_REPAIR and replaced by the governed supersession action already defined in FC-FPSO-03 (create successor pre-start record superseding the closed one, with reason code, authority check and event).
Acceptance predicate
Every affordance in the candidate interaction design resolves to Contract → Clause → Transition → DecisionRight → Event. OrphanUIActions = 0 by reconstruction, not declaration.
Affected contract
Interaction layer; FC-FPSO-03 PreStartPreventivePackage (existing transition reused) · IAD Rev.1 screens S07 (register) and S14 (closed record)
Regression tests
REM-R07, REM-R15
Residual risk
LOW — no contract change; the supersession path already existed and is now the only route.
Retest required
Independent recomputation of the UX→contract matrix.
F-SADR-10REMEDIATED PENDING INDEPENDENT RETESTFUNCTIONAL CONTRACT CORRECTION
Original condition
Tool inspection expiry evaluated at declaration only; TOOL_READY could persist past mandatory inspection expiry — reachable illegal state and determinism violation.
Root cause
Readiness was modelled as a declared fact rather than as an evaluated function of a temporally bounded source fact.
Correction
ToolReadiness is derived at EvaluationTimestamp from InspectionValidity, CertificationValidity, Condition and Restriction. Expiry while the package exists, while awaiting authorization, after authorization or during active work each has a governed consequence (see Tool temporal validity table). New evaluated state TOOL_READINESS_LAPSED replaces silent persistence of TOOL_READY.
Acceptance predicate
TOOL_READY is unreachable when any mandatory inspection ValidUntil < EvaluationTimestamp, for every phase of the package lifecycle, with no dependency on whether any UI was opened.
Affected contract
FC-FPSO-07 ToolReadiness · Readiness derivation · validity re-evaluation · consequence on active work
Regression tests
REM-R08, REM-R09, REM-R10, REM-R11, REM-R16
Residual risk
MEDIUM — the consequence of expiry during active work for lifting/rigging equipment awaits the equipment authority decision (DEP-11); interim behaviour is HOLD, which is safe but potentially over-restrictive.
Retest required
Independent re-execution of ADV-04, ADV-20 and the illegal-state set.

D. Temporal coherence model

XR-TEMP-01

NO_MATERIAL_DECISION_MAY_RELY_ON_A_TEMPORALLY_EXPIRED_FACT.

Cross-contract. Binds FC-FPSO-01…08 and every material authorization predicate.

EffectiveFromValidUntilLastVerifiedTemporalValidityStateRevalidationTriggerDecisionTimeEvaluationRequirement
States
CURRENT · EXPIRING · EXPIRED · UNKNOWN — retained because each drives distinct behaviour.
Behavioural justification
CURRENT permits; EXPIRING permits but emits a governed warning and a revalidation demand; EXPIRED blocks the material decision; UNKNOWN blocks and additionally names a verification owner. Collapsing EXPIRED and UNKNOWN would lose the distinction between a known-bad and an unverifiable fact — which changes who must act.
Rejected states
SIGNATURE_SUPERSEDED as a stored state was rejected as decorative — applicability is evaluated, not stored. Storing it would create two sources of truth for the same question.

E. TIME / EVENT / CHANGE / DEMAND trigger matrix

TIME
A fact validity threshold is crossed at the governed EvaluationTimestamp.
EVENT
A governed operational event is emitted (isolation lifted, SIMOPS change, shift end).
CHANGE
A material upstream object or fact changes (document revision, crew change, scope change).
DEMAND
A material decision requests re-evaluation immediately before execution.
ContractMaterial factTIMEEVENTCHANGEDEMANDNote
FC-FPSO-01 LocationAcquisitionLocation context confirmationYESYESYESGPS never creates authority; time alone does not invalidate a confirmed location.
FC-FPSO-02 ContextualDocumentRetrievalDocument effective period / revisionYESYESYESRevision change triggers dependency materiality evaluation, never blanket invalidation.
FC-FPSO-03 PreStartPreventivePackageComposite package validityYESYESYESYESThe package is the coherence point for SYS-01; all four classes apply.
FC-FPSO-04 CrewConfirmationRecordCompetency, training, fitness decisionsYESYESYESYESFitness is shift-bounded; competency is date-bounded; both revalidate on DEMAND.
FC-FPSO-05 IPERCContinuoDerived IPERC content vs source revisionYESYESYESNo pure TIME expiry; IPERC validity is bounded by the shift event and by source change.
FC-FPSO-06 FieldDeltaAssessmentOpen material deltaYESYESYESAn open material delta blocks regardless of elapsed time.
FC-FPSO-07 ToolReadinessInspection / certification validityYESYESYESPrimary TIME-driven contract; the F-SADR-10 defect lived here.
FC-FPSO-08 DigitalSignatureAssuranceCredential, decision right, object versionYESYESYESApplicability is evaluated at every read; credential expiry is TIME, version change is CHANGE.

F. Signature post-invalidation correction

F-SADR-01 · FC-FPSO-08

ConceptNatureCorrected definition
SignatureEvidenceIMMUTABLE HISTORICAL EVIDENCERecords that a named person, holding a named decision right, signed ObjectVersion N in a named decision context at a governed timestamp. Never mutated, never deleted, never re-scoped.
SIGNED_VERSION_NPRESERVED FACTThe version binding of the signature. Preserved unchanged after any subsequent object change.
SignatureApplicabilityEVALUATED RESULTComputed at EvaluationTimestamp against current ObjectVersion, DecisionContext, DecisionRight and IntegrityReference. Not stored as authority.
SIGNATURE_NOT_VALID_FOR_CURRENT_VERSIONEVALUATED RESULT VALUEReturned when the signed binding no longer matches current context. Historical evidence is untouched; the object requires a new signature to be authorized.

G. Signature failure behaviour

No failure may silently produce a valid signature status

ConditionPermitted stateProhibited transitionReason codeRetryIdempotency keyEvidenceHuman action
TimestampUnavailableSIGNATURE PENDING TIMESTAMP→ SIGNED (no committed signature without a governed timestamp)RC-SIG-TS-UNAVAILABLEBounded retry against the timestamp authority; no device clock substitution.objectId + objectVersion + signerId + signatureAttemptIdAttempt recorded with the failure reason; no signature evidence row created.Signer retries when the service returns, or escalates to the authority owner.
CredentialUnavailableSIGNATURE REFUSED→ SIGNED under any substitute identityRC-SIG-CRED-UNAVAILABLEManual only, after credential restoration.objectId + objectVersion + signerId + signatureAttemptIdRefusal event with signer identity claim unverified.Signer restores credential; no delegate substitution without a governed delegation.
SignatureServiceUnavailableSIGNATURE PENDING SERVICE→ SIGNED, and → AUTHORIZED for the dependent decisionRC-SIG-SVC-UNAVAILABLEBounded exponential retry, idempotent by attempt key.objectId + objectVersion + signerId + signatureAttemptIdService failure event; the dependent authorization remains blocked.Work control decides to wait or to route the authorization via the governed offline path.
DecisionRightExpiredBeforeSignatureCommitSIGNATURE REFUSED→ SIGNED (a signature can never create the right it lacked)RC-SIG-RIGHT-EXPIREDNone until the decision right is re-established.objectId + objectVersion + signerId + signatureAttemptIdRefusal event naming the expired right and its owner.Route to a currently entitled authority or renew the right.
ObjectVersionChangedBeforeSignatureCommitSIGNATURE REFUSED STALE VERSION→ SIGNED against the pre-change versionRC-SIG-VERSION-STALESigner must re-read the current version and sign again explicitly.objectId + objectVersion + signerId + signatureAttemptIdRefusal event recording both versions.Signer reviews the change, then signs the current version.

H. FC-02 / FC-05 dependency correction

SourceDocumentRevisionRequirement / ApplicabilityIPERCSourceDerivedContentHumanFieldValidationCurrentIPERC

A document revision change neither invalidates all IPERC nor does nothing. It always triggers DEPENDENCY_MATERIALITY_EVALUATION, whose outcome is dependency-scoped.

I. Document-to-IPERC materiality logic

Dependency-scoped invalidation preserved

OutcomeEvidence requiredReason codeAffectedReassessment boundaryAuthorization impact
NO RELEVANT DEPENDENCYDependency map showing no IPERC row derives from the changed requirement.RC-DEP-NONENo rowsNoneCONTINUE — current authorization unaffected.
DEPENDENCY NON MATERIALRecorded classification with inputs: no control removed, no hazard introduced, no scope/location change, editorial or reference-only delta.RC-DEP-NON-MATERIALNamed derived rows, flagged with the new revision referenceNotification only; no reassessmentCONTINUE — with the revision reference updated in evidence.
DEPENDENCY MATERIAL REASSESSMENT REQUIREDClassification naming the removed control or introduced hazard, plus the competent classifier.RC-DEP-MATERIALOnly the derived rows traced to the changed requirementDependency-scoped — untraced rows retain their validated stateREASSESS before the next material decision; if work is active, consequence per the continuity rule for IPERC (HOLD pending human field revalidation).
DEPENDENCY UNRESOLVEDNone available — the dependency map cannot be reconstructed for the changed requirement.RC-DEP-UNRESOLVEDThe candidate row set, conservatively boundedBroadened to the candidate set; never silently narrowedHOLD — UNKNOWN never converts to PASS.

J. Orphan UI action resolution

Before 2 · after 0

ActionScreenClassificationResolutionBound to
Register bulk acknowledgeS07 Pre-start registerUX ONLY REMOVERemoved from the candidate interaction design. Acknowledgement is a per-record act with a named actor; a bulk affordance cannot carry per-record authority or reason.NO_UI_REQUIRED — no contract loses coverage.
Re-open closed pre-start recordS14 Closed record detailEXISTING CONTRACT TRACEABILITY REPAIRReplaced by 'Create superseding pre-start record', which was already a governed transition. The closed record stays closed; a successor is created with a reason code and an event.FC-FPSO-03 · clause Supersession · transition CLOSED → (successor CREATED, predecessor SUPERSEDED) · DecisionRight WorkControlLead · event PRESTART_RECORD_SUPERSEDED

Reconstructed affordance-by-affordance, not declared.

K. Tool temporal validity correction

F-SADR-10 · FC-FPSO-07

TOOL_READY cannot remain materially valid after mandatory inspection expiry, in any lifecycle phase, independent of UI interaction.

Lifecycle phaseGoverned behaviourDetailReason code
Expiry while package exists (not yet submitted)REASSESSTool row derives to TOOL_READINESS_LAPSED; the package cannot be submitted until replaced or re-inspected.RC-TOOL-INSP-EXPIRED
Expiry while awaiting authorizationHOLDThe authorization predicate fails at decision time; the approver sees the lapsed fact, not a stale PASS.RC-TOOL-INSP-EXPIRED
Expiry after authorization, before work startHOLDAuthorization is evaluated again at execution demand; the signature for the prior version stays historical.RC-TOOL-INSP-EXPIRED-POST-AUTH
Expiry during active work — non-critical toolREASSESSGoverned reassessment by the supervisor; work may continue only on a recorded decision.RC-TOOL-INSP-EXPIRED-ACTIVE
Expiry during active work — lifting / rigging / critical-control toolEXTERNAL VALIDATION DEPENDENCYThe consequence authority is unresolved (DEP-11). Safe deterministic fallback: HOLD the affected activity and route to the equipment authority. The fallback never grants continuation.RC-TOOL-CONSEQ-UNRESOLVED

L. SYS-01 temporal decoherence remediation

Fact-by-fact classification — not a blanket assumption

Material factClassificationBasisContinuity
ToolInspectionTEMPORAL VALIDITY REQUIREDStatutory inspection interval.CONTINUOUS
EquipmentInspectionTEMPORAL VALIDITY REQUIREDStatutory inspection interval.CONTINUOUS
CertificationTEMPORAL VALIDITY REQUIREDCertificate ValidUntil.CONTINUOUS
CompetencyDecisionTEMPORAL VALIDITY REQUIREDQualification expiry.DECISION TIME ONLY
TrainingDecisionTEMPORAL VALIDITY REQUIREDTraining currency period.DECISION TIME ONLY
FitnessDecisionTEMPORAL VALIDITY REQUIREDShift-bounded declaration.CONFIGURATION DRIVEN
PETARTEMPORAL VALIDITY REQUIREDHigh-risk permit validity window.CONTINUOUS
PermitTEMPORAL VALIDITY REQUIREDPermit validity window.CONTINUOUS
IsolationEXTERNAL VALIDATION REQUIREDIsolation validity is governed by the isolation authority, not by an elapsed interval (DEP-09).CONFIGURATION DRIVEN
DecisionRightTEMPORAL VALIDITY REQUIREDAppointment period.DECISION TIME ONLY
DelegationTEMPORAL VALIDITY REQUIREDDelegation EffectiveFrom/ValidUntil.DECISION TIME ONLY
SignatureCredentialTEMPORAL VALIDITY REQUIREDCredential expiry at commit.DECISION TIME ONLY
DocumentEffectivePeriodTEMPORAL VALIDITY REQUIREDEffective/superseded dates.DECISION TIME ONLY
EnvironmentalObservationTEMPORAL VALIDITY REQUIREDObservation staleness threshold is governed configuration per parameter (wind, lightning).CONTINUOUS

M / N. Decision-time and continuity revalidation

Authorization predicate
DecisionAllowed = (∀ f ∈ MandatoryFacts(decisionType, projectConfig): ValidAt(f, EvaluationTimestamp)) ∧ AllContractPredicatesPass ∧ DecisionRightValidAt(EvaluationTimestamp)
Cache policy
A cached evaluation may be reused only when its EvaluationTimestamp, rule versions, configuration version and fact version set all match. Otherwise it is recomputed. No stale cached PASS.
Continuity rule
ContinuousValidityRequired vs ValidityRequiredOnlyAtDecisionTime is a per-fact-type rule in governed configuration, never a global assumption.

O. Concurrency correction

ConcurrencyUncontrolledPaths after = 0

Affected object
FC-FPSO-05 IPERCContinuo — concurrent row edits by supervisor and crew member on the same record

Row-level optimistic concurrency with a document-level base-version guard: every write carries BaseVersion for the row and the record; a mismatch is a detected conflict, never a merge and never a last-write-wins.

ControlDetail
BaseVersionRow version + record version carried on every write.
OptimisticConcurrencyCheckCompare-and-set at row granularity.
ConflictDetectionDeterministic on version mismatch; independent of arrival order.
ConflictReasonCodeRC-IPERC-ROW-CONFLICT / RC-IPERC-RECORD-CONFLICT
NoSilentOverwriteRejected write returns the current row for human reconciliation.
ReconciliationRequiredRecord cannot advance to authorization while any conflict is open.
GovernedOperationalEventIPERC_EDIT_CONFLICT_DETECTED

P. Implementation ambiguity resolution

ImplementationMaterialAmbiguity after = 0

IDContractInterpretation AInterpretation BCorrected normative meaningAcceptance predicateRegression
AMB-01FC-FPSO-02Ambiguous active revisions → pick the most recent effective revision automatically.Ambiguous active revisions → treat the document as unusable.Neither. Retrieval returns REVISION_ELECTION_UNRESOLVED with the full candidate set and the document-control owner named. No auto-election, no blanket unusability; the dependent decision is blocked until a human elects.Election is never performed by the readiness layer; the elected revision always carries ElectedBy and ElectionBasis.REM-R04, REM-R14
AMB-02FC-FPSO-05Delta materiality is a supervisor judgement, recorded as free text.Delta materiality is inferred from the delta type alone.Materiality is a recorded classification with four declared inputs (requirement class affected, control removed, hazard introduced, scope/location change) plus the classifier identity. The judgement stays human; the inputs make it testable and reproducible.Same inputs + same rule version ⇒ same materiality class; a classification without recorded inputs is invalid.REM-R05, REM-R06, REM-R14
AMB-03FC-FPSO-05Concurrent edits conflict at record level (any edit blocks any other).Concurrent edits merge per row with no guard.Row-level compare-and-set with a record-level base-version guard, as in the concurrency correction.Two concurrent writes to distinct rows both succeed; two to the same row produce exactly one conflict.REM-R12, REM-R13, REM-R14

Q. External dependency reconciliation

Prior 12 · independent 14 · reconciled 14

The denominator is not forced back to 12. The two dependencies missing from the prior count are DEP-11 (tool expiry consequence during active work) and DEP-14 (governed evaluation clock) — both surfaced only once time became an explicit governed input. No owner name is invented; owners are named by function where no person is appointed.

An open dependency may never grant authority, select source authority, create legal validity, bypass a mandatory control, or convert UNKNOWN to PASS.

IDAffected objectDecision requiredCompetent ownerCurrent evidenceSafe interim behaviourClosure evidence
DEP-01Location canonical authorityConfirm canonical location master for pilot scopeLocation governance steward (ADR-14, staffing unresolved)NONECONTEXT_UNRESOLVED — no authorizationSigned stewardship appointment + canonical register extract
DEP-02Document control registerAuthoritative revision effectivity sourceDocument control owner (role identified, person not appointed)NONEREVISION_ELECTION_UNRESOLVEDRegister extract + effectivity rule statement
DEP-03Requirement applicability rulesWhich requirement classes bind which activity typesEngineering authorityNONEBroadest applicable set; never narrowedApproved applicability matrix
DEP-04IPERC materiality inputsRatify the four classification inputsES&H authorityDESIGN PROPOSAL ONLYDEPENDENCY_UNRESOLVED → HOLDRatified classification rule with version
DEP-05Competency source of recordAuthoritative competency system and expiry semanticsTraining / competency ownerNONEUNKNOWN → HOLDSystem nomination + field mapping evidence
DEP-06Fitness declarationValidity window and re-declaration triggerOccupational health authorityNONEShift-bounded, re-declared each shiftApproved validity rule
DEP-07Signature credential authorityCredential issuance and revocation modelIAM / PKI ownerNONESIGNATURE_REFUSED on any credential doubtIAM design decision + revocation feed
DEP-08Timestamp authorityGoverned timestamp source and offline dispositionIAM / PKI ownerNONESIGNATURE_PENDING_TIMESTAMP; never device clockNominated timestamp service + offline rule
DEP-09Isolation validityWhether isolation validity is time-bounded or event-boundedIsolation authorityNONEEvent-bounded; expiry never inferredIsolation standard reference
DEP-10PETAR / permit interfaceSource of record and validity window feedPermit authorityNONEUNKNOWN → HOLDInterface contract + sample feed
DEP-11Tool expiry during active workConsequence for critical lifting/rigging equipmentEquipment authorityNONEHOLD affected activity (EXTERNAL_VALIDATION_DEPENDENCY)Approved consequence rule per equipment class
DEP-12Environmental observation stalenessPer-parameter staleness thresholdsES&H authorityNONEObservation older than the shortest configured threshold → UNKNOWN → HOLDApproved threshold table
DEP-13Decision-right appointment feedAuthoritative appointment and delegation sourceProject authority functionNONENo right inferred from role titleAppointment register + delegation rules
DEP-14Governed evaluation clockTrusted time source for EvaluationTimestamp and drift tolerancePlatform / infrastructure ownerNONEDecisions carry the timestamp used; drift beyond tolerance → UNKNOWN → HOLDTime source decision + drift tolerance

R. Illegal-state correction

ReachableIllegalMaterialStates after = 0

IDIllegal stateBeforeBlocking mechanismAfter
H-01AuthorizedWithoutDecisionRightUNREACHABLEDecisionRightValidAt in the authorization predicate.UNREACHABLE
H-02AuthorizedWithExpiredMandatoryFactREACHABLEXR-TEMP-01 + decision-time revalidation of all mandatory facts.UNREACHABLE
H-03IPERCAuthorizedWithMaterialDeltaOpenUNREACHABLEOpen material delta blocks the authorization predicate.UNREACHABLE
H-04SignatureApplicableToWrongVersionREACHABLESignatureApplicability evaluated against current version; SIGNATURE_NOT_VALID_FOR_CURRENT_VERSION.UNREACHABLE
H-05ToolReadyAfterMandatoryInspectionExpiryREACHABLEReadiness derived at EvaluationTimestamp; TOOL_READINESS_LAPSED.UNREACHABLE

S. Traceability repair

TraceabilityBreaks after = 0

TB-01REPAIRED
Break
Register bulk acknowledge — designed behaviour with no governing contract.
Forward chain
REQ-PS-14 acknowledge pre-start record → FC-FPSO-03 → clause Acknowledgement → transition PENDING_ACK → ACKNOWLEDGED → UIAction per-record acknowledge (S07 row) → event PRESTART_ACKNOWLEDGED → evidence AcknowledgementRecord
Reverse chain
Bulk affordance removed; no designed behaviour remains without a governing contract.
TB-02REPAIRED
Break
Re-open closed record — designed behaviour with no governing transition.
Forward chain
REQ-PS-21 correct a closed pre-start record → FC-FPSO-03 → clause Supersession → transition CLOSED → SUPERSEDED (+ successor CREATED) → UIAction 'Create superseding record' (S14) → event PRESTART_RECORD_SUPERSEDED → evidence SupersessionRecord
Reverse chain
Supersession affordance maps to exactly one clause and one transition.

T. State and reason-code normalization

NoNewDecorativeStates

Admitted states
StateKindJustification
SIGNATURE_NOT_VALID_FOR_CURRENT_VERSIONEVALUATED_RESULT (not stored)Distinct behaviour: blocks authorization while preserving historical evidence.
TOOL_READINESS_LAPSEDDERIVED_STATEDistinct behaviour per lifecycle phase; cannot be an attribute because it drives transitions.
Rejected as decorative
CandidateReason for rejection
SIGNATURE_SUPERSEDED (stored)Decorative — duplicates an evaluated result and creates a second source of truth.
DOCUMENT_STALECarried as TemporalValidityState attribute; no distinct transition.
IPERC_REVISION_FLAGGEDReason code RC-DEP-NON-MATERIAL suffices; no behavioural difference.
Reason codes
CodeCauseRequired actionOwnerEvidence requirement
RC-SIG-TS-UNAVAILABLETimestamp authority unreachableRetry or escalateSigner / IAM ownerAttempt record
RC-SIG-CRED-UNAVAILABLESigner credential unavailableRestore credentialSignerRefusal event
RC-SIG-SVC-UNAVAILABLESignature service unavailableWait or governed offline pathWork controlService failure event
RC-SIG-RIGHT-EXPIREDDecision right expired before commitRoute to entitled authorityAuthority functionRefusal event
RC-SIG-VERSION-STALEObject changed before commitRe-read and re-signSignerRefusal event with both versions
RC-SIG-NOT-APPLICABLE-CURRENT-VERSIONSignature bound to a superseded versionNew signature requiredSignerApplicability evaluation
RC-DEP-NONENo derived dependency on the changed requirementNoneDependency map
RC-DEP-NON-MATERIALDependency exists, non-material changeUpdate referenceClassifierClassification record
RC-DEP-MATERIALMaterial change to a derived requirementScoped reassessmentSupervisor / ES&HClassification record
RC-DEP-UNRESOLVEDDependency map unreconstructableBroaden and holdDocument controlUnresolved record
RC-TOOL-INSP-EXPIREDMandatory inspection expiredReplace or re-inspectEquipment custodianInspection record
RC-TOOL-INSP-EXPIRED-POST-AUTHExpiry after authorizationRe-authorizeApproverRe-evaluation record
RC-TOOL-INSP-EXPIRED-ACTIVEExpiry during active workSupervisor reassessmentSupervisorReassessment decision
RC-TOOL-CONSEQ-UNRESOLVEDConsequence authority unresolved (DEP-11)Hold and escalateEquipment authorityEscalation record
RC-IPERC-ROW-CONFLICTConcurrent row editHuman reconciliationSupervisorConflict event
RC-IPERC-RECORD-CONFLICTRecord base-version mismatchRe-read recordEditorConflict event
RC-TEMP-UNKNOWNValidity metadata unavailableVerify sourceNamed fact ownerVerification record

U. Event model delta

Event ≠ State

EventIntroducedSemantics
TEMPORAL_VALIDITY_EXPIREDYESEmitted when a mandatory fact crosses ValidUntil while a dependent decision or active work exists. Event ≠ state: the state remains derived.
PRESTART_RECORD_SUPERSEDEDYESExisting transition, newly bound to the corrected affordance.
IPERC_EDIT_CONFLICT_DETECTEDYESConcurrency conflict surfaced for human reconciliation.
SIGNATURE_APPLICABILITY_LOSTNONot introduced — applicability is evaluated on read; an event would imply stored state.

V / W. Determinism and pure core / effectful shell

SameFacts + SameRuleVersions + SameConfiguration + SameTemporalEvaluationTime + SameDecisionRights ⇒ SameMaterialDecision.

EvaluationTimestamp is a governed input supplied by the execution context and recorded in DecisionEvidence. No domain code calls now().

Pure core
validityapplicabilitymaterialitystate transitionsauthorization predicates
Effectful shell
clock acquisitionsource system readssignature/timestamp service callsevent emission

REM-R10, REM-R11 confirm no hidden wall-clock dependency and deterministic time-triggered re-evaluation.

X. Authority / security regression

AuthorityLeakage = 0

CheckResultDetail
AuthorityLeakage0No corrected clause grants a right that was not already appointed.
PrivilegeEscalation0Supersession requires the same decision right as closure.
SignatureCreatesAuthorityFALSESignature attests; the right must pre-exist and be valid at commit.
TimestampCreatesAuthorityFALSEA timestamp cannot substitute for a right or a credential.
SourceCreatesDecisionRightFALSESource systems supply facts; rights come from the appointment register (DEP-13).

Y. AI containment regression

CapabilityAIDetail
Temporal validity determinationPROHIBITEDComputed by the pure core from governed metadata.
Final applicabilityPROHIBITEDRule-evaluated; AI may surface candidates only.
DecisionRight determinationPROHIBITEDAppointment register only.
Signature validityPROHIBITEDCryptographic + rule evaluation only.
AuthorizationPROHIBITEDHuman decision on rule-evaluated inputs.
Explanation / condition surfacingPERMITTEDRead-only narration of detected conditions; never an input to a predicate.

Z. IAD Rev.2 candidate delta

PH6A-FPSO-IAD-REV2-CANDIDATE_DELTA · CANDIDATE_DELTA_NOT_ACCEPTED

Delta register only. The 18-step field journey is unchanged in sequence; only three steps gain a revalidation or conflict surface. Screens affected 9 · unchanged 7.

ScreenCurrent behaviourRequired behaviourAffected contractChange classTraceability repair
S04 Document contextMost recent effective revision shown as the revision.Show candidate set with REVISION_ELECTION_UNRESOLVED and the election owner; no default selection.FC-FPSO-02FUNCTIONAL CONTRACT CORRECTIONAMB-01
S06 IPERC continuoDelta marked material/non-material by free choice.Capture the four classification inputs before the class can be recorded.FC-FPSO-05FUNCTIONAL CONTRACT CORRECTIONAMB-02
S06 IPERC continuoConcurrent edit silently saved.Conflict surface with both row versions and explicit reconciliation.FC-FPSO-05FUNCTIONAL CONTRACT CORRECTIONAMB-03
S07 Pre-start registerBulk acknowledge affordance.Removed; per-record acknowledge only.FC-FPSO-03UX CORRECTIONTB-01
S09 Tool readinessReadiness shown as declared at package creation.Readiness derived at view time with EvaluationTimestamp; lapsed rows visibly lapsed.FC-FPSO-07FUNCTIONAL CONTRACT CORRECTIONF-SADR-10
S12 AuthorizationPrior evaluation reused when reopening the screen.Re-evaluate all mandatory facts on DEMAND before presenting the authorize action; show EvaluationTimestamp.Cross-contract XR-TEMP-01FUNCTIONAL CONTRACT CORRECTIONSYS-01
S13 SignatureSIGNED shown as terminal status.Show SignatureEvidence (historical) and SignatureApplicability (evaluated) as two distinct facts.FC-FPSO-08FUNCTIONAL CONTRACT CORRECTIONF-SADR-01
S13 SignatureFailure paths unspecified.Distinct presentation for each of the five governed failure conditions with reason code and required human action.FC-FPSO-08FUNCTIONAL CONTRACT CORRECTIONF-SADR-01
S14 Closed recordRe-open affordance.Replaced by 'Create superseding record' bound to the supersession transition.FC-FPSO-03TRACEABILITY CORRECTIONTB-02
S16 Assurance viewNo temporal provenance.Show EvaluationTimestamp, rule versions and per-fact TemporalValidityState for the decision of record.Cross-contract XR-TEMP-01TRACEABILITY CORRECTIONSYS-01

AA. REM-R01…R20 results

20/20 PASS · remediation design evidence only

IDStatementMethodResult
REM-R01Post-signature invalidation preserves historical signatureInvalidate object after signing; assert SignatureEvidence row byte-identical.PASS
REM-R02Prior signature cannot authorize new object versionVersion N+1 with signature bound to N; applicability evaluation.PASS
REM-R03Timestamp unavailable cannot produce a valid committed signatureTimestamp authority absent; assert SIGNATURE_PENDING_TIMESTAMP and no SIGNED transition.PASS
REM-R04Document revision change triggers dependency materiality evaluationPublish revision; assert evaluation invoked with one of four outcomes.PASS
REM-R05Non-material revision does not globally invalidate IPERCEditorial revision; assert untraced rows retain validated state.PASS
REM-R06Material revision triggers dependency-scoped reassessmentControl-removing revision; assert only traced rows reassessed.PASS
REM-R07Orphan UI actions = 0Reconstruct affordance→contract matrix over the candidate design.PASS
REM-R08Tool inspection expiry re-evaluates readinessAdvance EvaluationTimestamp past ValidUntil in each lifecycle phase.PASS
REM-R09Expired mandatory fact cannot support a material decisionEach TEMPORAL_VALIDITY_REQUIRED fact expired in turn against the authorization predicate.PASS
REM-R10Time-triggered re-evaluation is deterministicSame facts, same rule versions, two runs at the same EvaluationTimestamp.PASS
REM-R11No hidden wall-clock domain dependencyInspect pure-core clauses for ambient time; timestamp injected only.PASS
REM-R12Concurrency path detects conflicting versionTwo writes to one row with the same BaseVersion.PASS
REM-R13No last-write-winsAssert rejected write returns current row; no overwrite.PASS
REM-R14All three implementation ambiguities resolvedTwo-interpretation divergence test per ambiguity.PASS
REM-R15Traceability breaks = 0Forward and reverse chain reconstruction over the candidate design.PASS
REM-R16Illegal material states unreachableH-01…H-05 reachability search over corrected transitions.PASS
REM-R17External dependencies reconciledIndependent enumeration vs prior claim; 14 distinct decisions confirmed.PASS
REM-R18Unresolved dependency fails safelyEach open dependency tested against the five prohibited effects.PASS
REM-R19Architecture and seal unchangedCompare PH6A-IADA-REV1 and SEAL-01 attributes before/after.PASS
REM-R20AI containment preservedAssert no AI output reaches a predicate input in any corrected clause.PASS

AB. Candidate baseline change register

PH6A-FPSO-FUNCTIONAL-BASELINE-REV1-CANDIDATE · CANDIDATE_FOR_INDEPENDENT_RETEST

IDTargetClauseChangeChange classSource finding
CR-01FC-FPSO-08Signature lifecycleSignatureEvidence / SignatureApplicability split; SIGNED no longer unconditionally terminal.FUNCTIONAL CONTRACT CORRECTIONF-SADR-01
CR-02FC-FPSO-08Failure behaviourFive governed failure conditions with states, reason codes, retry and idempotency key.FUNCTIONAL CONTRACT CORRECTIONF-SADR-01
CR-03FC-FPSO-02Revision electionREVISION_ELECTION_UNRESOLVED; no auto-election.FUNCTIONAL CONTRACT CORRECTIONF-SADR-02 / AMB-01
CR-04FC-FPSO-02 ↔ FC-FPSO-05Dependency evaluationDEPENDENCY_MATERIALITY_EVALUATION with four deterministic outcomes.FUNCTIONAL CONTRACT CORRECTIONF-SADR-02
CR-05FC-FPSO-05Delta materialityRecorded classification with four declared inputs.FUNCTIONAL CONTRACT CORRECTIONAMB-02
CR-06FC-FPSO-05ConcurrencyRow-level compare-and-set with record base-version guard.FUNCTIONAL CONTRACT CORRECTIONAMB-03
CR-07FC-FPSO-07Readiness derivationDerived at EvaluationTimestamp; TOOL_READINESS_LAPSED; per-phase consequence.FUNCTIONAL CONTRACT CORRECTIONF-SADR-10
CR-08Cross-contractXR-TEMP-01No material decision may rely on a temporally expired fact; temporal attribute set mandated.FUNCTIONAL CONTRACT CORRECTIONSYS-01
CR-09Cross-contractEvaluation timeEvaluationTimestamp as a governed input recorded in DecisionEvidence.RULE CONFIGURATION CLARIFICATIONSYS-01
CR-10FC-FPSO-03SupersessionExisting transition bound to the corrected affordance; re-open removed.TRACEABILITY CORRECTIONF-SADR-03 / TB-02
CR-11Interaction layerS07 registerBulk acknowledge removed.UX CORRECTIONF-SADR-03 / TB-01
CR-12Dependency registerExternal dependenciesReconciled to 14 distinct decisions with safe interim behaviour each.EXTERNAL DEPENDENCY RECLASSIFICATIONF-SADR-04

Only an independent retest may freeze this candidate. No PASS is claimed for the baseline itself.

AC. Residual risk

IDRiskLevelControl
RR-01Fourteen external dependencies remain open; every corrected clause depends on at least one governed decision not yet made.HIGHDeterministic safe-failure behaviour per dependency; none can convert UNKNOWN to PASS.
RR-02Interim HOLD behaviour for critical tool expiry during active work may be operationally over-restrictive.MEDIUMExplicit EXTERNAL_VALIDATION_DEPENDENCY flag with the equipment authority named (DEP-11).
RR-03Materiality classification remains a human judgement; recorded inputs make it testable, not objective.MEDIUMClassifier identity, inputs and rule version recorded on every classification.
RR-04Temporal correctness depends on a trusted evaluation clock that has no nominated owner (DEP-14).MEDIUMTimestamp recorded on every decision; drift beyond tolerance degrades to UNKNOWN → HOLD.
RR-05Remediation is design evidence only; no operational behaviour has been observed.ACCEPTEDPhase 6A remains HOLD; pilot exposure prohibited.

AD. Independent retest readiness decision

Exit criterionRequiredActualMet
CriticalRemediationGaps00MET
HighUncontrolledRemediationGaps00MET
OpenMaterialSemanticAmbiguity00MET
ImplementationMaterialAmbiguity00MET
TraceabilityBreaks00MET
ReachableIllegalMaterialStates00MET
ConcurrencyUncontrolledPaths00MET
AuthorityLeakage00MET
ArchitectureChange00MET
REM-R01…R2020/20 PASS20/20 PASSMET
SADR_MATERIAL_FINDING_REMEDIATION
COMPLETE_PENDING_INDEPENDENT_RETEST
RemediationID
PH6A-SADR-REM-REV0
CandidateFunctionalBaseline
PH6A-FPSO-FUNCTIONAL-BASELINE-REV1-CANDIDATE
CandidateIADDelta
PH6A-FPSO-IAD-REV2-CANDIDATE_DELTA
CriticalRemediationGaps
0
HighUncontrolledRemediationGaps
0
OpenMaterialSemanticAmbiguity
0
ImplementationMaterialAmbiguity
0
ReachableIllegalMaterialStates
0
TraceabilityBreaks
0
ConcurrencyUncontrolledPaths
0
ExternalDependencyCount
14
REMRegression
20/20
ArchitectureChange
0
ParentSealChanged
FALSE
IndependentRetestReady
TRUE