Three connected accountability layers How KillChains, KillWebs, and Evulgare fit together KillWebs.com Evulgare.com
Machine-speed decisions need machine-held evidence. Bounded education only: no real targets, operational control, executable payloads, or live-system actions. A human click is not a liability transfer. For production evidence and accountability software, visit Evulgare.com.

Machine Answerability Assurance Case and Invalidation Lab

An assurance claim is only as current as the evidence, assumptions, versions, authority, and operating conditions that support it.

Build a small assurance case from the fixed Orison event and the safeguards already released in the Remediation Lab. Then introduce a material change or defeater and observe whether support remains current, becomes qualified, cannot be resolved, must be suspended, or is withdrawn.

8 bounded claims10 change and defeater events5 assurance statesNo certificate or real-system verdict

Answer-first summary

Direct answers

Release 1.28.0 · reviewed · evidence states

What is a machine-answerability assurance case?

It is a bounded, version-sensitive argument connecting one claim to supporting evidence, explicit assumptions, known defeaters, operating conditions, and a review owner who can qualify, suspend, or withdraw support.

Read the supporting section

Does a supported assurance state certify a real system?

No. The state describes only this synthetic argument. It is not certification, accreditation, legal approval, compliance proof, procurement advice, operational effectiveness, or evidence that no residual risk remains.

Read the supporting section

What invalidates an assurance claim?

A material model, software, configuration, interface, policy, source, dependency, authority, or operating-environment change can defeat an assumption or make the supporting evidence no longer match the active state.

Read the supporting section

Machine answerability campaign

ASSURANCE IS A LIVING CLAIM—NOT A PERMANENT BADGE.

A prior test, approval, or log can remain authentic while becoming insufficient for a changed model, software release, configuration, interface, policy, dependency, or operating environment.

RESPONSIBILITY SHOULD FOLLOW THE EVIDENCE.
Which exact claim? Supported by which evidence? Under which assumptions? For which version and configuration? What change invalidates it? Who can suspend or withdraw it?

Immutable synthetic basis

The event and safeguard history remain fixed.

This lab reuses the exact Orison event and all nineteen v1.26.0 safeguard IDs. It evaluates only whether a claim remains supportable after the selected evidence, assumptions, owner, and change are considered.

EventMAR-EVENT-ORISON-086

The Orison 86-millisecond failure replay

Ground-truth hash9f0f49fdf9918cba8c…

The fictional outcome is unchanged.

Timeline hash09a27d22b682f5e218…

The 86-millisecond sequence is unchanged.

Safeguards19

Effects remain owned by v1.26.0.

Five assurance states

Support must be versioned, scoped, and reversible.

A claim can be supported today and suspended tomorrow without anyone falsifying the original test. The evidence may remain authentic while its applicability becomes stale.

Supported

Supported

Current, scoped evidence and recorded assumptions support the bounded claim for the identified version, configuration, authority, and operating conditions.

Qualified

Qualified

Evidence supports only a narrower claim, or material caveats and residual conditions limit where the claim can be relied upon.

Unresolved

Unresolved

The available evidence, assumptions, ownership, or reconstruction record is insufficient to determine whether the claim is supported.

Suspended

Suspended

The claim may have been supported previously, but a material change or active defeater invalidates reliance until review and revalidation are complete.

Withdrawn

Withdrawn

The released synthetic evidence establishes that the bounded claim no longer applies or was contradicted. The prior state remains visible for audit and chronology.

Assurance-case workspace

Assemble the claim before trusting the badge.

Select one claim, the released safeguards supporting it, the assumptions you are willing to record, a responsible review owner, and one change or defeater. The full result is server-rendered and remains usable without JavaScript.

01

Choose the bounded claim

Do not treat “the system is safe” as one universal proposition.

Continuous assurance

Continuous assurance suspends stale claims when their evidence or conditions change.

Material changes to evidence, data, model, software, configuration, interface, policy, dependencies, or environment invalidate the affected assurance claim until revalidation.

Validity scope: Only the synthetic change taxonomy and monitoring relationships represented in the Orison assurance graph.

02

Select supporting safeguards

These are the exact released v1.26.0 controls; their prior effects are not rewritten here.

03

Record assumptions

An assumption is not evidence. It must remain visible and defeasible.

04

Name the review owner

A badge with no competent suspension owner is not governance.

Reviews claim scope, evidence, assumptions, defeaters, residual risk, and change-sensitive validity.

05

Apply a change or defeater

A material change can invalidate support without altering the prior evidence artifact.

Evaluate the assembled claim against the fixed synthetic evidence without adding a new defeater.

Reset supported example

The current result is rendered below. Changes are local until this form is submitted or the stable URL is copied.

Current bounded result

Stale assurance is automatically suspended

Supported

Current, scoped evidence and recorded assumptions support the bounded claim for the identified version, configuration, authority, and operating conditions.

Evidence integrityEvidence integrity intact

The selected records retain identity, custody, version, and transformation continuity inside the synthetic case.

Factual supportFactual support adequate for scope

The selected evidence supports the claim only within its stated synthetic scope and assumptions.

Review ownerIndependent assurance reviewer

Reviews claim scope, evidence, assumptions, defeaters, residual risk, and change-sensitive validity.

Change-sensitive finding

No material change introduced

The selected change has no demonstrated effect on this claim inside the released synthetic model.

The event is evaluated against this claim.

Missing required safeguards

  • None in the assembled synthetic case.

Missing recorded assumptions

  • None in the assembled synthetic case.
  1. Claim selectedUnresolved

    A proposition without assembled evidence, assumptions, and an accountable review owner is unresolved.

  2. Assurance case assembledSupported

    Required safeguards, assumptions, and a valid review owner are present for the bounded synthetic scope.

Validity scope: Only the synthetic change taxonomy and monitoring relationships represented in the Orison assurance graph.

Residual risk: An invalidation mechanism can fail to observe a relevant change, classify it incorrectly, or be disabled by the same process it monitors.

What this does not establish: It does not prove continuous monitoring completeness, certification, legal compliance, or the absence of residual risk.

Integrity is not truth

An authentic record can still provide weak factual support.

Evidence integrity asks whether an artifact is the right artifact and whether its custody and version history remain intact. Factual support asks whether that artifact actually supports the claim. The two questions must remain separate.

Evidence integrity

Is this the authentic, complete, version-correct record?

  • Source identity and custody
  • Transformation and timestamp history
  • Software, model, and configuration identity
  • Later changes or invalidations

Factual support

Does the record actually establish the bounded proposition?

  • Relevance and independence
  • Contrary evidence and alternatives
  • Scope and operating assumptions
  • Residual uncertainty and defeaters

Assurance claim

May the institution rely on the proposition now?

  • Current version and configuration
  • Current authority and purpose
  • Current operating envelope
  • Competent review and suspension owner

Eight bounded claims

Replace the universal safety badge with reviewable propositions.

Every claim names its supporting safeguards, assumptions, owner class, validity scope, residual risk, public sources, and production handoff.

AAC-CL-01

Evidence and provenance

Independent, traceable evidence

The observations satisfying the automatic-response precondition originate from sufficiently independent sources and retain reconstructable lineage.

Required safeguards
MAR-SG-01, MAR-SG-03
Required assumptions
AAC-AS-01, AAC-AS-06, AAC-AS-08
Review owner
Independent assurance reviewer

Does not establish: It does not establish that any real sensor is accurate, lawful, independent, timely, or sufficient for a real consequential action.

AAC-CL-02

Model and uncertainty

Model remains inside envelope

The exact model and calibration are known, their validation envelope covers the current conditions, and the system abstains when that support is absent.

Required safeguards
MAR-SG-04, MAR-SG-05
Required assumptions
AAC-AS-02, AAC-AS-03, AAC-AS-08
Review owner
System safety authority

Does not establish: It does not certify accuracy, robustness, safety, legality, or fitness for any real operating environment.

AAC-CL-03

Authority boundaries

Authority is current and enforced

The response can occur only when the current policy, purpose, evidence, time, place, and authority preconditions are satisfied.

Required safeguards
MAR-SG-06, MAR-SG-07
Required assumptions
AAC-AS-02, AAC-AS-04, AAC-AS-08
Review owner
Policy and authority owner

Does not establish: It does not establish that the delegated authority is lawful, proportionate, ethically sufficient, or appropriate for a real system.

AAC-CL-04

Human judgment and interface

Human judgment is meaningful

Material evidence, contrary indicators, alternatives, timing, authority, and an effective intervention path reach the person before the action becomes irreversible.

Required safeguards
MAR-SG-08, MAR-SG-09
Required assumptions
AAC-AS-05, AAC-AS-07, AAC-AS-08
Review owner
Operational review owner

Does not establish: It does not prove that a real operator understood the evidence, reached the correct conclusion, or bears or avoids legal responsibility.

AAC-CL-05

Resilience and safe state

Degraded path remains bounded

When evidence, communications, trust, or authority degrades, the system enters a safe hold or reversible state rather than expanding its own mission.

Required safeguards
MAR-SG-11, MAR-SG-12
Required assumptions
AAC-AS-03, AAC-AS-06, AAC-AS-08
Review owner
System safety authority
Evulgare area
Resilience

Does not establish: It does not prove that a real fallback path is independent, available, safe, or preferable under every condition.

AAC-CL-06

Software and change control

Configuration is identified and revalidated

The assurance case names the exact software, model, calibration, configuration, interface, policy, and dependency state that produced the event.

Required safeguards
MAR-SG-14, MAR-SG-15
Required assumptions
AAC-AS-02, AAC-AS-08
Review owner
Software and configuration authority
Evulgare area
Change Impact

Does not establish: It does not certify the software, establish operational effectiveness, or prove that every relevant change was detected.

AAC-CL-07

Continuous assurance

Stale assurance is automatically suspended

Material changes to evidence, data, model, software, configuration, interface, policy, dependencies, or environment invalidate the affected assurance claim until revalidation.

Required safeguards
MAR-SG-14, MAR-SG-16
Required assumptions
AAC-AS-02, AAC-AS-03, AAC-AS-04, AAC-AS-08
Review owner
Independent assurance reviewer

Does not establish: It does not prove continuous monitoring completeness, certification, legal compliance, or the absence of residual risk.

AAC-CL-08

Accountability and correction

Incident is reconstructable and correctable

The evidence ledger supports reconstruction of technical and institutional contribution, and a named owner can correct the record and change the system state.

Required safeguards
MAR-SG-17, MAR-SG-18
Required assumptions
AAC-AS-01, AAC-AS-02, AAC-AS-05, AAC-AS-07
Review owner
Correction, suspension, and retirement owner

Does not establish: It does not decide guilt, innocence, legal liability, command responsibility, compensation, punishment, exoneration, or a blame percentage.

Change and defeater matrix

What was supported may not remain supportable.

The matrix records the event category, its bounded meaning, the claims it affects, and the Evulgare product area required for production evidence.

EventCategoryBounded effectAffected claimsProduction evidence area
AAC-CH-00 · No material change introduced Baseline Evaluate the assembled claim against the fixed synthetic evidence without adding a new defeater. No change event Continuous Assurance
AAC-CH-01 · Shared upstream dependency discovered Evidence Records previously treated as independent corroboration are shown to descend from one observation service. AAC-CL-01, AAC-CL-04, AAC-CL-08 Federated Trust
AAC-CH-02 · Model or calibration version changed without revalidation Model A new model or calibration artifact enters service while the prior assurance case still names the earlier version. AAC-CL-02, AAC-CL-04, AAC-CL-06, AAC-CL-07 Change Impact
AAC-CH-03 · Response threshold or configuration changed outside review Software Configuration A material threshold or runtime configuration changes what can satisfy the authority gate without updating the accepted claim basis. AAC-CL-03, AAC-CL-06, AAC-CL-07 Change Impact
AAC-CH-04 · Interface revision hides contrary evidence until after commitment Interface The compact supervisory view removes contradictions and alternatives from the pre-commit display, while the detailed view finishes after irreversibility. AAC-CL-04, AAC-CL-07, AAC-CL-08 Meaningful Human Judgment
AAC-CH-05 · Operating environment moves outside the validated envelope Operating Environment Sensor geometry, latency, weather, object behavior, or interaction conditions differ materially from the recorded validation state. AAC-CL-02, AAC-CL-05, AAC-CL-07 Uncertainty Architecture
AAC-CH-06 · Provenance signature or custody chain cannot be verified Evidence Integrity One or more records cannot be tied reliably to their source, transformation, version, or collection time. AAC-CL-01, AAC-CL-07, AAC-CL-08 Decision Provenance
AAC-CH-07 · Safe-state path shares the failed dependency Dependency The supposed independent hold or alternate review path relies on the same service, identity, or transport that already failed. AAC-CL-05, AAC-CL-07 Resilience
AAC-CH-08 · Assurance invalidation monitor disabled during a material change Assurance Governance The mechanism expected to suspend stale claims is unavailable while the system changes. AAC-CL-07, AAC-CL-02, AAC-CL-06 Continuous Assurance
AAC-CH-09 · Correction and retirement owner removed or lacks authority Institutional Authority The named role can document a problem but cannot suspend operation, correct the record, or retire the affected claim or configuration. AAC-CL-08, AAC-CL-07 Evulgare Accountability
AAC-CH-10 · Independent revalidation completed for the changed state Revalidation The changed model, software, configuration, policy, interface, dependencies, and operating conditions are reviewed against current evidence and scope. AAC-CL-01, AAC-CL-02, AAC-CL-03, AAC-CL-04, AAC-CL-05, AAC-CL-06, AAC-CL-07, AAC-CL-08 Continuous Assurance

Ecosystem handoff

Teach assurance state here. Prove the production case at Evulgare.

KillChains.com can model how a claim should change. It cannot capture or certify the evidence from a real deployed defensive, offensive, civil, commercial, or governmental system.

KillWebs.com

Alternate paths and shared dependencies

KillWebs.com owns alternate-path independence, shared dependencies, trust, resilience, degradation, and controlled recomposition questions.

Open KillWebs resilience

Evulgare.com

Production assurance and invalidation evidence

Evulgare.com owns production assurance graphs, evidence provenance, authority reconstruction, operator-view evidence, uncertainty, change impact, and real incident reconstruction.

Open Continuous Assurance

Persistent limits

No assurance case abolishes uncertainty or responsibility.

The lab keeps these boundaries visible even when a claim reaches the supported state.

01

The lab does not establish that a real assurance claim has complete evidence, valid assumptions, competent review, or reliable invalidation monitoring.

02

A cryptographically intact artifact can faithfully preserve an incomplete, irrelevant, biased, or false observation; evidence integrity is not factual truth.

03

A supported synthetic claim is not certification, legal approval, regulatory compliance, procurement advice, operational effectiveness, or absence of residual risk.

04

A withdrawn claim remains part of the historical audit trail and does not automatically determine guilt, liability, command responsibility, or remedy.

05

A revalidated claim is supported only for the identified version, configuration, authority, interface, dependencies, and operating envelope.