PizarraContexto de trabajoDocumentos y registrosControles críticosRegistrosPreparaciónCondiciones bloqueantesAutorización
Aseguramiento / Técnico
PH6A-FPSO-FINAL-PROMPT-01-REV1G-PH6A · HOLDControlledPilot · NOT_AUTHORIZEDPilotExposure · PROHIBITEDBC09Protection · ACTIVE

Wave 1 Command Center — Owner Validation Program

Current authorized action: conduct the Wave 1 owner alignment kick-off and issue OER-01…OER-04 to real competent owners. Parent baseline MASTER-PH6A-FPSO-CV07-REV2_FINAL is read-only.

Requests issued
4
Owner responses
0
Evidence received
0
Evidence admitted
0
BC blocking
9
Hard stops active
9/15

W1-A · OER-01 … OER-04 — Issuance & Response Status

OER-01P0ISSUED_AWAITING_OWNERAdmission · AWAITING_OWNER

Identity / IAM / DecisionRight Validation

Recipient role
Corporate IAM Authority + Operational Decision-Rights Authority (roles named by owner organisation)
Gate impact
EXT-03 / EXT-04 -> G-PH6A
Owner decisions outstanding
17
Closure sufficiency
INSUFFICIENT
OER-02P0ISSUED_AWAITING_OWNERAdmission · AWAITING_OWNER

BC-06 — Critical Control Operating Model

Recipient role
Corporate ES&H / Critical Control Authority
Gate impact
BC-06 -> G-PH6A
Owner decisions outstanding
15
Closure sufficiency
INSUFFICIENT
OER-03P0ISSUED_AWAITING_OWNERAdmission · AWAITING_OWNER

BC-09 — Prospective BEFORE Measurement

Recipient role
Measurement Owner (operations performance authority)
Gate impact
BC-09 -> G-PH6A
Owner decisions outstanding
10
Closure sufficiency
INSUFFICIENT
OER-04P0ISSUED_AWAITING_OWNERAdmission · AWAITING_OWNER

EXT-15 — Offline Signature Reconciliation

Recipient role
Digital Signature / Records Authority + IT Security Authority
Gate impact
EXT-15 -> G-PH6A · Cybersecurity forward link EXT-15 -> future G-FPSO-SEC-01
Owner decisions outstanding
12
Closure sufficiency
INSUFFICIENT

W1-B · Owner Request Issuance Ledger (append-only)

OwnerDecisionRequestsIssued 0 -> 4. Historical frozen baseline unchanged; all downstream counters remain 0 until real events occur.

RequestIDOERIssuedRecipient roleCompetent authority statusVersionDelivery referenceStatus
REQ-W1-01OER-01FP01-EXEC-T0 (issuance event recorded at execution of PH6A-FPSO-FINAL-PROMPT-01-REV1)Corporate IAM Authority + Operational Decision-Rights Authority (roles named by owner organisation)CLAIMED_BY_DESIGN_NOT_CONFIRMED_BY_OWNEROER-01-REV1DELIVERY_REFERENCE_NOT_YET_RECORDED — to be attached by Evidence Coordinator on transmissionISSUED_AWAITING_OWNER
REQ-W1-02OER-02FP01-EXEC-T0 (issuance event recorded at execution of PH6A-FPSO-FINAL-PROMPT-01-REV1)Corporate ES&H / Critical Control AuthorityCLAIMED_BY_DESIGN_NOT_CONFIRMED_BY_OWNEROER-02-REV1DELIVERY_REFERENCE_NOT_YET_RECORDED — to be attached by Evidence Coordinator on transmissionISSUED_AWAITING_OWNER
REQ-W1-03OER-03FP01-EXEC-T0 (issuance event recorded at execution of PH6A-FPSO-FINAL-PROMPT-01-REV1)Measurement Owner (operations performance authority)CLAIMED_BY_DESIGN_NOT_CONFIRMED_BY_OWNEROER-03-REV1DELIVERY_REFERENCE_NOT_YET_RECORDED — to be attached by Evidence Coordinator on transmissionISSUED_AWAITING_OWNER
REQ-W1-04OER-04FP01-EXEC-T0 (issuance event recorded at execution of PH6A-FPSO-FINAL-PROMPT-01-REV1)Digital Signature / Records Authority + IT Security AuthorityCLAIMED_BY_DESIGN_NOT_CONFIRMED_BY_OWNEROER-04-REV1DELIVERY_REFERENCE_NOT_YET_RECORDED — to be attached by Evidence Coordinator on transmissionISSUED_AWAITING_OWNER

W1-C · Predicate & BC / EXT Impact

PredicateOERStateAffectsResidual gap
PRD-01OER-01OPENEXT-03, EXT-04, BC-02No confirmed identity source, no confirmed DecisionRight source, no delegation/revocation authority.
PRD-02OER-02OPENBC-06No owner disposition on PATH_A / PATH_B. Forwood Safety remains candidate source.
PRD-03OER-02OPENBC-06No governed source confirmed; reconstruction path unproven in operation.
PRD-04OER-03OPENBC-09MeasurementOwner unconfirmed; start authorization absent; collection NOT_STARTED.
PRD-05OER-04OPENEXT-15Twelve reconciliation decisions unanswered; signature applicability rule not owner-validated.
Next authorized action — Conduct the Wave 1 owner alignment kick-off and obtain competent-owner responses to OER-01…OER-04. Record every response as an immutable EvidenceIntakeRecord, submit each to independent Seven-Check Admission, and re-assess G-PH6A retest readiness only from admitted operational evidence. No pilot exposure until BC-09 prospective BEFORE collection is authorized and underway.

W1-D · Active Hard Stops

  • · HS-01Authority = UNKNOWN for required material decisionHOLD
  • · HS-02CriticalControlGovernance = UNRESOLVEDHOLD
  • · HS-03MaterialCriticalControl = NOT_VERIFIEDHOLD
  • · HS-04BC-09 prospective BEFORE not authorized / not startedPROHIBITED
  • · HS-05SignatureApplicability cannot be establishedHOLD
  • · HS-06Offline conflict unresolvedREASSESS
  • · HS-12Integrity uncertainty existsHOLD
  • · HS-14G-PH6A != progression-authorizing statePROHIBITED
  • · HS-15Pilot authorization absent or expiredPROHIBITED
WAVE_1_EXECUTION_ACTIVATEDEVIDENCE_REQUEST_EXECUTION_PACK = ACTIVATEDPhase 6A · HOLDBC09Protection · ACTIVEPilotExposure · PROHIBITED

Phase 6A — Wave 1 Evidence Execution Kickoff

BC-01 / BC-02 / BC-03 / BC-05 / BC-06 · Operationalizing the existing /erx Pack

Wave 1 identifies the shortest defensible path from AWAITING_OWNER to real evidence without sacrificing authority, traceability or acceptance criteria. Issuing or sequencing a request is not progress.

Source
/erx — Evidence Request Execution Pack (ACTIVATED, 28 requests reconciled)
Blocker state
BC-01 → BC-09 = OPEN
Revalidation eligibility
NOT_ELIGIBLE
Phase 6B / Phase 7
NOT_AUTHORIZED / NO_GO

A · Wave 1 Executive Summary

Wave 1 activates execution of 17 already-issued Evidence Requests across BC-01, BC-02, BC-03, BC-05 and BC-06. Nothing has been created, merged or acknowledged. The shortest defensible path starts the three long-lead external requests (ER-01, ER-06, ER-07) immediately, takes the three internally-available decisions now (ER-11, ER-16, ER-17), and escalates the BC-06 path election rather than waiting for it.

Shortest defensible path
  1. 1. Start ER-01 + ER-06 together — a participation map and its IT authorization are each unassessable alone.
  2. 2. Start ER-07 immediately — IAM provisioning is the longest lead time and blocks every real BC-02 test.
  3. 3. Take ER-11 now — lifecycle governance requires no IAM capability and is the most obtainable Wave 1 artefact.
  4. 4. Run the CA-04 decision set (ER-16, ER-17, ER-18) as one session producing three separately attributable decisions.
  5. 5. Escalate ER-19 via ESC-03 rather than treating it as a pending request; ER-20 stays dependency-held.
  • · EVIDENCE_REQUEST_EXECUTION_PACK = ACTIVATED (28 requests reconciled)
  • · BC-01 → BC-09 = OPEN
  • · Phase6A = HOLD · RevalidationEligibility = NOT_ELIGIBLE
  • · Phase6B = NOT_AUTHORIZED · Phase7 = NO_GO
  • · BC09Protection = ACTIVE · PilotExposure = PROHIBITED
  • · Wave 2 / Wave 3 / Wave 4 unchanged and not commenced

B · Exact Wave 1 Request Population

Each request retains its original EvidenceRequest_ID, OwnerPackage_ID, CompetentOwner, MinimumAcceptableEvidence, RetestTrigger and Dependency exactly as registered in /erx and /board.

Wave 1 requests
17
Blockers
BC-01 / BC-02 / BC-03 / BC-05 / BC-06
Owner packages
14
Merged
0
Replaced
0
Newly created
0
ReqBCPkgCompetent ownerMinimum acceptable evidenceRetest triggerState
ER-01BC-01OP-01Enterprise ArchitectureAttributable participation declaration per source/object.RT-01AWAITING_OWNER
ER-02BC-01OP-02Q4 System OwnerOwner statement of mode + authority boundaries.RT-01AWAITING_OWNER
ER-03BC-01OP-03Aconex / IM OwnerOwner confirmation of snapshot authority and validity window.RT-01AWAITING_OWNER
ER-04BC-01OP-04P6 / Project ControlsOwner confirmation of read mode and cadence.RT-01AWAITING_OWNER
ER-05BC-01OP-05Smart CompletionsOwner confirmation of participation mode.RT-01AWAITING_OWNER
ER-06BC-01OP-06IT / IMIT authorization statement for the declared mechanisms.RT-01AWAITING_OWNER
ER-07BC-02OP-07IAM / CyberIAM owner confirmation + provisioned identity set.RT-02AWAITING_OWNER
ER-08BC-02OP-07IAM / CyberDocumented mapping from enterprise roles to authority scopes.RT-02AWAITING_OWNER
ER-09BC-02OP-07IAM / CyberWritten enterprise behaviour statement.RT-02AWAITING_OWNER
ER-10BC-02OP-08HR / RRLLHR confirmation of authoritative source and update cadence.RT-02AWAITING_OWNER
ER-11BC-03OP-09Business Product OwnerDecision artefact per object class.RT-03AWAITING_OWNER
ER-12BC-03OP-02Q4 System OwnerOwner confirmation of who may transition what.RT-03AWAITING_OWNER
ER-16BC-05OP-12Records ManagementCompetent retention decision per class.RT-05AWAITING_OWNER
ER-17BC-05OP-13PrivacyPrivacy decision per class.RT-05AWAITING_OWNER
ER-18BC-05OP-14HealthHealth owner confirmation of exposed attribute.RT-05AWAITING_OWNER
ER-19BC-06OP-15ES&H Accountable ExecutiveAttributable path election.RT-06AWAITING_OWNER
ER-20BC-06OP-16Critical Control / Forwood OwnerOwner participation confirmation.RT-06AWAITING_OWNER

C · Critical-Path Classification

Classification is reasoned from lead time, cross-blocker dependency, authority availability, evidence availability and retest leverage. No numeric weighting is used.

ER-01BC-01CRITICAL_PATHSTART_NOWEnterprise Architecture

Federated participation map per source and object class

Lead time
Long — enterprise architecture governance cycle
Authority availability
Enterprise Architecture exists as a standing authority; scheduling is the constraint, not authority.
Evidence availability
Partially pre-existing — an enterprise integration/participation position may already exist in governed form.
Retest leverage
Highest — no BC-01 retest can be framed before a per-source participation mode exists.
Cross-blocker dependency
Frames BC-02 scope (which systems require identity), BC-03 (where lifecycle authority sits) and BC-06 Path A feasibility.
Why this class
Every other BC-01 request is assessed against the participation frame this request establishes.
ER-02BC-01CRITICAL_PATHSTART_NOWQ4 System Owner

Q4 participation, authority boundary and failure behaviour

Lead time
Long — external system owner
Authority availability
Q4 System Owner is named and reachable; response authority is not disputed.
Evidence availability
Interface/participation statements plausibly obtainable without new development.
Retest leverage
High — permit/JHA/isolation objects gate the whole work-authorization retest set.
Cross-blocker dependency
Directly constrains BC-03 (ER-12 boundary confirmation) and BC-02 authentication scope.
Why this class
Work authorization cannot be retested at all while the governing source's mode is undeclared.
ER-03BC-01HIGH_LEVERAGERUN_IN_PARALLELAconex / IM Owner

Document snapshot authority and revision-change behaviour

Lead time
Medium
Authority availability
Document/IM owner available.
Evidence availability
Snapshot governance behaviour is largely existing practice; a written confirmation is the gap.
Retest leverage
High — decision pinning retests depend only on this confirmation.
Cross-blocker dependency
Feeds BC-05 (retention/record class of snapshots) and BC-03 (document revision lifecycle).
Why this class
Single owner statement unlocks a self-contained retest thread; no upstream dependency.
ER-04BC-01PARALLEL_ACTIONRUN_IN_PARALLELP6 / Project Controls

Look-ahead read participation and refresh cadence

Lead time
Medium
Authority availability
Project Controls available inside the project organization.
Evidence availability
Governed extracts already exist for reporting purposes.
Retest leverage
Moderate — look-ahead is Degradable, not Blocking, in the readiness contract.
Cross-blocker dependency
Same owner as BC-09 ER-26; must not be bundled — BC-09 remains protected and out of Wave 1.
Why this class
Independent, low-friction, executable now without waiting for the participation frame.
ER-05BC-01PARALLEL_ACTIONRUN_IN_PARALLELSmart Completions

Subsystem completion participation mode

Lead time
Medium
Authority availability
Completions system owner available.
Evidence availability
Participation statement obtainable; no new interface required for a snapshot mode.
Retest leverage
Moderate — affects release gating scenarios only.
Cross-blocker dependency
None blocking; assessed against the ER-01 frame when it arrives.
Why this class
Executable independently; failure to obtain it narrows scope rather than halting Wave 1.
ER-06BC-01CRITICAL_PATHSTART_NOWIT / IM

Enterprise interface hosting and data-movement authorization

Lead time
Long — IT authorization and security review
Authority availability
IT / IM authority exists but decision windows are governed by review boards.
Evidence availability
Cannot pre-exist for this scope; must be issued for the declared mechanisms.
Retest leverage
Absolute — no declared participation mode is real evidence until IT authorizes it.
Cross-blocker dependency
Gates realization of ER-01 → ER-05 and any live IAM test under BC-02.
Why this class
Longest lead time combined with veto power over every BC-01 mechanism.
ER-07BC-02CRITICAL_PATHSTART_NOWIAM / Cyber

Pilot identity provisioning and authentication

Lead time
Long — longest external lead time in Wave 1
Authority availability
IAM / Cyber authority clear; provisioning capacity is the constraint.
Evidence availability
Identity provider and method are pre-existing facts; Pilot identity provisioning is new work.
Retest leverage
Absolute — IAM-01 → IAM-06 cannot begin without provisioned real identities.
Cross-blocker dependency
Blocks ER-08, ER-09 real execution; residual dependency for BC-03 technical enforcement.
Why this class
Everything real in BC-02 starts here; nothing in BC-02 can be retested before it.
ER-08BC-02HIGH_LEVERAGERUN_IN_PARALLELIAM / Cyber

Role resolution source and authority-scope mapping

Lead time
Medium — design artefact, not provisioning
Authority availability
IAM owns the mapping; HR endorsement may be required for the person source.
Evidence availability
Role model documentation may exist in part; scope mapping is the gap.
Retest leverage
High — supports IAM-02/IAM-03 framing before identities are provisioned.
Cross-blocker dependency
Depends on ER-10 for the authoritative person source; independent of ER-07 as a design artefact.
Why this class
Documentable ahead of provisioning, so it should not queue behind ER-07.
ER-09BC-02DEPENDENCY_HELDWAIT_FOR_DEPENDENCYIAM / Cyber

Delegation and revocation behaviour

Lead time
Medium after ER-07
Authority availability
IAM available; written behaviour statement can be started, demonstrated revocation cannot.
Evidence availability
Statement obtainable now; demonstration requires provisioned identities.
Retest leverage
High for IAM-05 / IAM-06, but only after real identities exist.
Cross-blocker dependency
Hard dependency on ER-07 for the demonstrated (preferred) evidence form.
Why this class
Minimum acceptable evidence is a written statement; the preferred demonstration is dependency-held.
ER-10BC-02HIGH_LEVERAGERUN_IN_PARALLELHR / RRLL

Authoritative person-to-role source for the Pilot population

Lead time
Medium
Authority availability
HR / RRLL authority available inside the organization.
Evidence availability
System of record exists; a governance note is the deliverable.
Retest leverage
High — unlocks ER-08 mapping and is reused by BC-04 in Wave 2 without merging criteria.
Cross-blocker dependency
Upstream of ER-08; shares an artefact family with the Wave 2 BC-04 requests.
Why this class
Low-friction request that removes the dependency currently held over role resolution.
ER-11BC-03HIGH_LEVERAGESTART_NOWBusiness Product Owner

Lifecycle ownership and transition authority acceptance

Lead time
Short–medium — governance decision, not technical work
Authority availability
Business Product Owner is internal and available; this is the most accessible authority in Wave 1.
Evidence availability
No pre-existing artefact, but the decision can be taken now without BC-02.
Retest leverage
High — a lifecycle authority matrix is the single artefact behind most BC-03 acceptance criteria.
Cross-blocker dependency
LifecycleGovernanceDecision is independent of BC-02; only TechnicalAuthorityEnforcement is BC-02-held.
Why this class
Obtainable now from competent operational authority; must not be queued behind IAM.
ER-12BC-03PARALLEL_ACTIONRUN_IN_PARALLELQ4 System Owner

Federation-edge lifecycle authority boundary

Lead time
Medium — same owner as ER-02
Authority availability
Q4 System Owner available; boundary confirmation is a joint statement with ER-11 authority.
Evidence availability
Can be produced alongside the ER-02 response but must be assessed separately.
Retest leverage
Moderate–high — prevents duplication of Q4 authority at the federation edge.
Cross-blocker dependency
Coupled to ER-02 by owner and to ER-11 by decision content.
Why this class
Runs with ER-02 for owner efficiency without merging acceptance criteria.
ER-16BC-05CRITICAL_PATHSTART_NOWRecords Management

Retention basis and period per record class

Lead time
Medium — records governance cycle
Authority availability
Records Management authority available.
Evidence availability
An enterprise retention schedule likely exists; the gap is a per-record-class decision for this scope.
Retest leverage
High — retention basis gates the CA-04 retest and the evidence-integrity chain.
Cross-blocker dependency
Downstream of nothing in Wave 1; upstream of BC-08/BC-09 evidence handling design.
Why this class
Material CA-04 decision with downstream gating impact on every evidence class.
ER-17BC-05CRITICAL_PATHSTART_NOWPrivacy

Personal-data classification and minimisation decision

Lead time
Medium — privacy assessment cycle
Authority availability
Privacy authority available; assessment intake is a defined process.
Evidence availability
DPIA-equivalent process exists; the scope-specific record does not.
Retest leverage
High — determines minimum attributes consumed for person, competency and fitness data.
Cross-blocker dependency
Constrains ER-10 attribute exposure and ER-18 health flag scope.
Why this class
One competent classification decision governs several downstream data paths.
ER-18BC-05PARALLEL_ACTIONRUN_IN_PARALLELHealth

Binary fitness flag confirmation

Lead time
Short
Authority availability
Health custodian available.
Evidence availability
Narrow, single-attribute confirmation.
Retest leverage
Moderate — closes the smallest and most contained CA-04 criterion.
Cross-blocker dependency
Should be consistent with, but is not blocked by, ER-17.
Why this class
Smallest defensible unit of BC-05 evidence; executable immediately.
ER-19BC-06CRITICAL_PATHESCALATE_AUTHORITYES&H Accountable Executive

Critical control path election (Path A / Path B)

Lead time
Unknown — depends on executive decision availability
Authority availability
DISPUTED / UNCONFIRMED — no competent decision owner has yet accepted the election.
Evidence availability
None; this is a decision, not a retrievable artefact.
Retest leverage
Structural — path ambiguity propagates unresolved scope into BC-01, BC-08 and Phase 7.
Cross-blocker dependency
Determines whether ER-20 is in scope at all; changes BC-01 source population and BC-08 dimensions.
Why this class
ESC-03 remains ACTIVE until a competent decision exists; escalation is the execution action.
ER-20BC-06DEPENDENCY_HELDWAIT_FOR_DEPENDENCYCritical Control / Forwood Owner

Critical control source participation authorization (Path A)

Lead time
Medium once Path A is elected
Authority availability
Critical Control / Forwood owner available, but has nothing to authorize until a path is elected.
Evidence availability
Not requestable in substance before the path decision.
Retest leverage
High under Path A; void under Path B.
Cross-blocker dependency
Hard dependency on ER-19.
Why this class
Requesting participation before the path election would presume the decision.

D · High-Leverage Evidence Artefact Register

One artefact may support multiple Evidence Requests, but each request is assessed independently. Acceptance criteria are never merged, transferred or inherited.

EAC-01Enterprise ArchitectureER-01ER-02ER-04ER-05
Evidence type
Signed federated participation map (per source / object class)
Blockers affected
BC-01, BC-03, BC-06
Acceptance criteria covered
Declared participation mode, object class and read/write boundary per source at enterprise level.
Acceptance criteria NOT covered
Per-source owner acceptance (ER-02/04/05 each still require their own owner statement) and IT authorization (ER-06).
Why high leverage
One governed artefact frames four requests; each remains independently assessed against its own minimum acceptable evidence.
EAC-02IT / IMER-06ER-02ER-03ER-04ER-05
Evidence type
IT authorization record for hosting, network path and data movement
Blockers affected
BC-01, BC-02
Acceptance criteria covered
Authorization and named constraints for the declared federation mechanisms.
Acceptance criteria NOT covered
System-owner authority statements; authentication design owned by IAM; failure behaviour per object class.
Why high leverage
Converts declared participation modes from intention into authorized mechanism for all BC-01 sources at once.
EAC-03IAM / CyberER-07ER-08ER-09
Evidence type
IAM design and provisioning record for the Pilot population
Blockers affected
BC-02, BC-03
Acceptance criteria covered
Identity provider, authentication method, role resolution source, delegation/revocation behaviour.
Acceptance criteria NOT covered
Demonstrated revocation with real identities (ER-09 preferred form) and the HR authoritative person source (ER-10).
Why high leverage
Single IAM artefact enables IAM-01 → IAM-04 framing while ER-07 provisioning proceeds.
EAC-04HR / RRLLER-10ER-08
Evidence type
Person-to-role system-of-record governance note
Blockers affected
BC-02
Acceptance criteria covered
Authoritative person source, update cadence and steward.
Acceptance criteria NOT covered
IAM endorsement of the mapping to authority scopes; Wave 2 BC-04 capacity criteria are separate.
Why high leverage
Removes the dependency currently holding ER-08 and is reusable in Wave 2 without transferring acceptance.
EAC-05Business Product OwnerER-11ER-12
Evidence type
Lifecycle authority matrix decision artefact (per object class)
Blockers affected
BC-03
Acceptance criteria covered
Accepted lifecycle ownership and transition authority per object class.
Acceptance criteria NOT covered
Q4 federation-edge boundary confirmation (ER-12 owner statement) and technical enforcement, which is BC-02-held.
Why high leverage
The single most obtainable Wave 1 artefact: internal authority, no BC-02 dependency.
EAC-06Records Management + Privacy (joint issue, separate decisions)ER-16ER-17ER-18
Evidence type
CA-04 classification decision set (record class, retention basis, personal-data scope)
Blockers affected
BC-05
Acceptance criteria covered
DataClassification, RecordClass, RetentionBasis, DataMinimisation and AccessScope per class.
Acceptance criteria NOT covered
Health custodian confirmation of the binary fitness flag remains a separate competent decision (ER-18).
Why high leverage
One classification workshop can produce three attributable decisions; each request keeps its own acceptance criterion and owner.

E · BC-01 Execution Plan — Source Participation

Obtain attributable source/system-owner confirmation of actual Pilot participation, not inferred capability.

ActualPilotParticipationMode
Declared per source and object class — live interface, controlled snapshot or controlled manual federation.
ObjectClass
Which object classes the source actually exposes for the Pilot scope.
SystemOwner
Named accountable owner able to authorize participation.
ReadAuthority
Who may read, under what governance and in which scope.
WriteAuthority
Confirmed retained by the source; readiness layer never re-authors.
SnapshotAuthority
Who may take a governed snapshot and what makes it valid.
Authentication
Enterprise-authorized authentication method — not assumed.
FailureBehaviour
What the readiness layer must do when the source is unavailable (fail-closed by default).
Highest dependency impact
ER-01 · ER-06 · ER-02
No inference rule
No API, endpoint, payload or capability may be inferred. Absence of an owner statement is treated as UNVERIFIABLE, not as available.
CONTROLLED_SNAPSHOT
Where appropriate
Aconex document revisions (ER-03), P6 look-ahead (ER-04) and Smart Completions subsystem state (ER-05).
Why it may satisfy Pilot evidence needs
Decision pinning already requires a frozen revision; a governed snapshot with attributable authority and validity window satisfies the Pilot evidence need without live integration.
Limits
Snapshot freshness must be declared; a stale snapshot must degrade the decision, never silently persist.
CONTROLLED_MANUAL_FEDERATION
Where appropriate
Low-volume Q4 permit/JHA/isolation confirmation (ER-02) if interface authorization is not obtainable in the Pilot window.
Why it may satisfy Pilot evidence needs
Preserves source authority and attribution while avoiding an unnecessary integration build for a bounded Pilot scope.
Limits
Requires a named custodian per transfer and must not create a second authoring path for Q4 objects.
LIVE_INTERFACE
Where appropriate
Only where the source owner and IT independently authorize it and the object volume makes snapshots indefensible.
Why it may satisfy Pilot evidence needs
Live integration is not a Pilot prerequisite; it is a scaling decision.
Limits
Never assumed; ER-06 authorization is mandatory before any live mechanism is treated as real.

ER-01 and ER-06 run together: a participation map without IT authorization, and IT authorization without a participation map, are each unassessable.

F · BC-02 Execution Plan — Minimum Real IAM Evidence

Establish the minimum real IAM evidence needed to begin IAM-01 → IAM-06 with enterprise-enforced identities.

PilotIdentity
Identity provider, authentication method and a provisioned Pilot identity set (ER-07).
RoleResolution
Documented mapping from enterprise roles to area / activity / shift / risk scopes (ER-08), sourced from the authoritative person system (ER-10).
AuthorityScope
Confirmation that scope attributes are enforced by IAM, not by application role context (ER-08).
Delegation
Written enterprise behaviour statement that delegation never widens scope (ER-09).
Revocation
Fail-closed revocation behaviour, demonstrated with real identities where possible (ER-09).
ItemDepends onState
PilotIdentityER-07 provisioning + ER-06 IT authorizationNOT_SATISFIED
RoleResolutionER-08 mapping + ER-10 authoritative person sourceNOT_SATISFIED
AuthorityScopeER-08NOT_SATISFIED
DelegationER-09 statementNOT_SATISFIED
RevocationER-09 statement, then ER-07 identities for demonstrationNOT_SATISFIED
IAM_REAL_TEST_EXECUTION · BLOCKED — prototype role context is explicitly not IAM evidence.
  • · No provisioned Pilot identities exist (ER-07 AWAITING_OWNER) — IAM-01 → IAM-06 cannot be executed against real subjects.
  • · No enterprise role-to-scope mapping is confirmed (ER-08) — authority scope cannot be asserted, only simulated.
  • · No authoritative person source is confirmed (ER-10) — role resolution has no defensible input.
  • · No IT authorization exists for the identity path (ER-06) — any test environment would be unauthorized.

G · BC-03 Decision-Artefact Plan

Obtain lifecycle governance decisions now, without waiting unnecessarily for BC-02.

LifecycleGovernanceDecisionOBTAINABLE_NOW
Meaning
Who owns each object class lifecycle and who may authorize each transition.
Competent authority
Business Product Owner (ER-11) with Q4 System Owner boundary confirmation (ER-12).
Note
This is an organizational decision and requires no IAM capability.
TechnicalAuthorityEnforcementDEPENDENCY_HELD
Meaning
Enterprise enforcement of those transition rights against real identities.
Competent authority
IAM / Cyber (ER-07, ER-08, ER-09).
Note
Recorded as a residual BC-02 dependency, not as a BC-03 failure.
Artefacts obtainable now
  • · Signed lifecycle authority matrix per object class (ER-11).
  • · Joint federation-edge authority boundary statement with Q4 (ER-12).
  • · Minuted governance decision with attributable authority where a signed matrix is not yet available (ER-11 alternative form).
Residual BC-02 dependency (recorded separately)
Even with ER-11 and ER-12 accepted, BC-03 cannot reach SUFFICIENT_FOR_CLOSURE until enforcement is evidenced under BC-02. It may reach SUFFICIENT_FOR_RETEST on the governance dimension alone.

H · BC-05 Classification Decision Plan

Obtain the material CA-04 decisions that gate downstream evidence handling.

DecisionScopeCompetent owner / request
DataClassificationClassification per data class consumed by the readiness layer.Privacy (ER-17)
RecordClassWhich artefacts are records versus transient decision context.Records Management (ER-16)
DataMinimisationMinimum attribute set for person, competency and fitness data.Privacy (ER-17) + Health (ER-18)
RetentionBasisLegal or policy basis and period per record class.Records Management (ER-16)
AccessScopeWho may access each class within the Pilot scope.Privacy (ER-17)
One decision, multiple requests
A single competent CA-04 classification decision session can produce the record-class, retention-basis and personal-data determinations supporting ER-16, ER-17 and ER-18.
Request-level traceability preserved
Each determination is recorded against its own Evidence Request ID with its own competent owner and acceptance criterion. No request inherits acceptance from another.
Downstream gating impact
Retention basis and access scope gate evidence integrity, audit reconstruction and the BC-08/BC-09 evidence-handling design; an unresolved CA-04 propagates into every later evidence class.

I · BC-06 Path Decision Plan

Identify the competent authority able to elect a path. The path is NOT elected here.

PathElection · NOT_ELECTEDESC-03 remains ACTIVE until a competent, attributable decision exists.
PATH_A_REAL_PARTICIPATION
Meaning
Real critical control verification records participate in the Pilot from the owning source.
Requires
ER-19 election plus ER-20 source participation authorization.
PATH_B_FORMAL_RESCOPE
Meaning
Critical control participation is formally rescoped out of the Pilot with recorded consequences.
Requires
ER-19 election with DecisionAuthority, Reason, PilotEvidenceLost, ResidualRisk and Phase7Impact recorded.
DecisionOwner
ES&H Accountable Executive (ER-19) — currently unconfirmed as having accepted the decision.
BC01ScopeImpact
Path A adds a critical control source to the BC-01 population and to the participation map; Path B removes it and narrows ER-01 scope.
BC08Impact
Path A keeps critical control verification as a live field readiness dimension; Path B marks that dimension as formally out of scope, reducing Pilot evidence value.
Phase7Impact
Path B leaves critical control effectiveness unevidenced by the Pilot; Phase 7 production readiness must then carry it as an unclosed production condition.
EvidenceRequiredToDecide
  • · Confirmation from the Critical Control / Forwood owner of whether participation is technically and contractually possible in the Pilot window (scoping input only, not the ER-20 authorization).
  • · BC-01 participation frame (ER-01) showing whether the source can be federated at all.
  • · Statement of the fatal-risk exposure present in the nominated Pilot workfront scope.

No path may be elected to facilitate closure. Path B requires the full decision record, not convenience.

J · Owner Acknowledgement Plan

Response state remains AWAITING_OWNER for every package. No acknowledgement may be recorded on behalf of an owner.

OP-01Enterprise ArchitectureCRITICAL_PATHAWAITING_OWNERER-01
First required response
Confirm the named accountable signatory and whether a governed participation position already exists.
Evidence expected
Attributable participation declaration per source and object class.
Critical dependency
Must be consistent with IT authorization (ER-06); neither is sufficient alone.
Escalation if authority disputed
ESC-02 — authority dispute is escalated, never resolved by the design team.
OP-02Q4 System OwnerCRITICAL_PATHAWAITING_OWNERER-02 · ER-12
First required response
Confirm participation mode and authority boundaries for permit / JHA / isolation objects.
Evidence expected
Owner statement or approved interface specification; controlled snapshot or manual federation is acceptable.
Critical dependency
Boundary content must align with the ER-11 lifecycle decision without merging acceptance.
Escalation if authority disputed
ESC-02 — authority dispute is escalated, never resolved by the design team.
OP-06IT / IMCRITICAL_PATHAWAITING_OWNERER-06
First required response
Confirm the review path and constraints for hosting, network and data movement.
Evidence expected
IT authorization record with named constraints.
Critical dependency
Requires the declared mechanisms from ER-01 to be authorized against.
Escalation if authority disputed
ESC-02 — authority dispute is escalated, never resolved by the design team.
OP-07IAM / CyberCRITICAL_PATHAWAITING_OWNERER-07 · ER-08 · ER-09
First required response
Confirm identity provider, authentication method and the provisioning path for Pilot identities.
Evidence expected
IAM design and provisioning record; role-to-scope mapping; delegation and revocation behaviour statement.
Critical dependency
Role mapping depends on the HR authoritative person source (ER-10); demonstration depends on provisioning (ER-07).
Escalation if authority disputed
ESC-02 — authority dispute is escalated, never resolved by the design team.
OP-12Records ManagementCRITICAL_PATHAWAITING_OWNERER-16
First required response
Confirm the retention basis and period per material record class.
Evidence expected
Signed retention schedule extract or interim decision with review date.
Critical dependency
Must be consistent with the privacy determination (ER-17) without inheriting its acceptance.
Escalation if authority disputed
ESC-02 — authority dispute is escalated, never resolved by the design team.
OP-13PrivacyCRITICAL_PATHAWAITING_OWNERER-17
First required response
Confirm personal-data classification, minimum attribute set and access scope.
Evidence expected
DPIA-equivalent record or conditional approval with narrowed attributes.
Critical dependency
Constrains ER-10 and ER-18 attribute exposure.
Escalation if authority disputed
ESC-02 — authority dispute is escalated, never resolved by the design team.
OP-15ES&H Accountable ExecutiveCRITICAL_PATHAWAITING_OWNERER-19
First required response
Confirm acceptance of the path-election decision authority.
Evidence expected
Attributable election of PATH_A or PATH_B with the full decision record.
Critical dependency
ESC-03 ACTIVE; ER-20 cannot proceed until the election exists.
Escalation if authority disputed
ESC-03 — authority dispute is escalated, never resolved by the design team.
OP-03Aconex / IM OwnerHIGH_LEVERAGEAWAITING_OWNERER-03
First required response
Confirm snapshot authority and revision-change notification behaviour.
Evidence expected
Signed snapshot governance note (ADR-05 input).
Critical dependency
Snapshot record class is constrained by the BC-05 CA-04 decision.
Escalation if authority disputed
ESC-02 — authority dispute is escalated, never resolved by the design team.
OP-08HR / RRLLHIGH_LEVERAGEAWAITING_OWNERER-10
First required response
Confirm the authoritative person-to-role source and update cadence for the Pilot population.
Evidence expected
System-of-record governance note with named steward.
Critical dependency
Attribute exposure is constrained by the BC-05 privacy decision (ER-17).
Escalation if authority disputed
ESC-02 — authority dispute is escalated, never resolved by the design team.
OP-09Business Product OwnerHIGH_LEVERAGEAWAITING_OWNERER-11
First required response
Accept lifecycle ownership and transition authority per object class.
Evidence expected
Signed lifecycle authority matrix or minuted attributable governance decision.
Critical dependency
Independent of BC-02; enforcement remains a separately recorded residual dependency.
Escalation if authority disputed
ESC-02 — authority dispute is escalated, never resolved by the design team.
OP-04P6 / Project ControlsPARALLEL_ACTIONAWAITING_OWNERER-04
First required response
Confirm look-ahead read participation mode and refresh cadence.
Evidence expected
Governed extract description with named steward.
Critical dependency
Must not be bundled with the BC-09 metric requests; BC-09 remains protected and outside Wave 1.
Escalation if authority disputed
ESC-02 — authority dispute is escalated, never resolved by the design team.
OP-05Smart CompletionsPARALLEL_ACTIONAWAITING_OWNERER-05
First required response
Confirm subsystem completion participation mode.
Evidence expected
Owner participation statement.
Critical dependency
None blocking.
Escalation if authority disputed
ESC-02 — authority dispute is escalated, never resolved by the design team.
OP-14HealthPARALLEL_ACTIONAWAITING_OWNERER-18
First required response
Confirm that only a binary fitness flag may be consumed.
Evidence expected
Signed data-exposure statement with named custodian.
Critical dependency
Consistency with ER-17; not blocked by it.
Escalation if authority disputed
ESC-02 — authority dispute is escalated, never resolved by the design team.
OP-16Critical Control / Forwood OwnerDEPENDENCY_HELDAWAITING_OWNERER-20
First required response
No response required until a path is elected; scoping input only may be provided.
Evidence expected
Source participation authorization — only under PATH_A.
Critical dependency
Hard dependency on ER-19.
Escalation if authority disputed
ESC-03 — authority dispute is escalated, never resolved by the design team.

K · Parallel Execution Sequence

No artificial due dates are assigned. Sequence positions express dependency and leverage only, and confer no schedule commitment.

S1START_NOWER-01 · ER-06 · ER-07 · ER-11 · ER-16 · ER-17
Reason
Longest lead times (ER-01, ER-06, ER-07) plus the artefacts obtainable immediately from available internal authority (ER-11, ER-16, ER-17).
Gate
None — no upstream dependency exists for any of these.
S2ESCALATE_AUTHORITYER-19
Reason
No competent decision owner has accepted the BC-06 path election; the execution action is escalation, not a further request.
Gate
ESC-03 remains ACTIVE until an attributable decision owner is confirmed.
S3RUN_IN_PARALLELER-02 · ER-03 · ER-04 · ER-05 · ER-10 · ER-12 · ER-18
Reason
Independent owners with medium lead times; each can proceed without the S1 outputs and will be assessed against them on arrival.
Gate
Assessment — not issuance — waits on ER-01 for participation-frame consistency.
S4RUN_IN_PARALLELER-08
Reason
Role-to-scope mapping is a design artefact and must not queue behind identity provisioning.
Gate
Preferred completeness depends on ER-10; a draft mapping is still assessable.
S5WAIT_FOR_DEPENDENCYER-09
Reason
Written behaviour statement can start, but the preferred demonstrated revocation requires provisioned identities.
Gate
ER-07 provisioning.
S6WAIT_FOR_DEPENDENCYER-20
Reason
Source participation authorization is meaningless before the path is elected and would presume the decision.
Gate
ER-19 election.

L · Potential First Retest Triggers

No retest is executed. Reaching SUFFICIENT_FOR_RETEST is not closure and does not change any blocker state.

BCPotentialFirstRetestTriggerEvidenceResidualDependencyState
BC-05RT-05 — CA-04 classification and retention retestER-16 · ER-17 · ER-18None outside BC-05 — this is the most likely first blocker to reach SUFFICIENT_FOR_RETEST because all three owners are internal.NOT_PREPARED
BC-03RT-03 — lifecycle authority governance retest (governance dimension only)ER-11 · ER-12Technical authority enforcement remains dependent on BC-02; closure is not reachable on ER-11/ER-12 alone.NOT_PREPARED
BC-01RT-01 — federated participation and fail-closed source retestER-01 · ER-06 · ER-02Scope is unstable until BC-06 elects a path; ER-04/ER-05 required for full source population.NOT_PREPARED
BC-02RT-02 — IAM-01 → IAM-06 with real identitiesER-07 · ER-08 · ER-10ER-06 IT authorization and provisioned identities; longest path in Wave 1.NOT_PREPARED
BC-06RT-06 — critical control participation retest (Path A) or rescope verification (Path B)ER-19No retest can be defined before the path election; ER-20 applies only under Path A.NOT_PREPARED

M · Executive Wave 1 Control Panel

NOT_DISPLAYED — aggregate progress is not a governance signal.

Wave1Requests
17
Owners
14
CriticalPathRequests
7
HighLeverageArtefacts
6
OwnerAcknowledged
0
EvidenceSubmitted
0
UnderReview
0
PotentialRetestTriggers
5
ActiveEscalations
ESC-02 · ESC-03

N · Final Boundary

  • · No evidence generated.
  • · No request acknowledged on behalf of an owner.
  • · No blocker closed, downgraded or rescoped.
  • · No targeted retest executed.
  • · Wave 2 not commenced and never treated as closure.
  • · Phase 6A Integrated Revalidation not commenced.
  • · Phase 6B not commenced.
  • · BC-09 protection unaltered — no BC-09 request is in Wave 1 and no Pilot exposure is authorized.