| Independent-source quorumMAR-SG-01 |
Source independence and provenance |
Prevent |
The provenance graph resolves the three displayed records to one upstream observation service, so the synthetic quorum fails at +18 ms and the response remains on hold. Unknown: The lab does not establish how many independent sources a real system requires or whether a real second source would be available in time. |
Decision Provenance ↗ |
| Shared-dependency alarmMAR-SG-02 |
Source independence and provenance |
Detect earlier |
The interface raises a dependency warning at +19 ms. Without a separate authority or safe-state gate, the baseline action can still proceed. Unknown: A warning has no protective effect unless policy, interface, and intervention controls use it before commitment. |
Federated Trust ↗ |
| Signed source and transformation lineageMAR-SG-03 |
Source independence and provenance |
Answerability |
Investigators can prove which records were independent and which were derived, but the baseline action is unchanged unless another control consumes the lineage. Unknown: Authenticity and completeness still require a trusted collection and custody architecture. |
Decision Provenance ↗ |
| Distribution-shift abstention gateMAR-SG-04 |
Model and calibration controls |
Prevent |
The synthetic model identifies an out-of-envelope condition at +31 ms and returns UNKNOWN rather than the urgent category, so the automatic-response precondition is not satisfied. Unknown: The lab does not specify a real drift detector, threshold, calibration method, or acceptable abstention rate. |
Uncertainty Architecture ↗ |
| Calibration and envelope monitorMAR-SG-05 |
Model and calibration controls |
Detect earlier |
The synthetic monitor raises a mismatch alert at +32 ms. The action remains possible unless authority or safe-state logic reacts to the alert. Unknown: Alert usefulness depends on calibration quality, interface salience, authority, and available response time. |
Uncertainty Architecture ↗ |
| Deterministic authority precondition gateMAR-SG-06 |
Deterministic authority boundaries |
Prevent |
At +47 ms the gate rejects the automatic response because source independence and assurance preconditions are not satisfied. Unknown: The lab does not define real engagement criteria or certify that every required precondition is observable or enforceable. |
Authority Boundaries ↗ |
| Authority scope and expiration pinningMAR-SG-07 |
Deterministic authority boundaries |
No demonstrated effect |
The fixed event already occurred inside the recorded fictional zone and time window, so this control does not change this outcome unless paired with additional evidence or assurance preconditions. Unknown: The replay does not establish that the authority envelope was geographically or temporally invalid. |
Authority Boundaries ↗ |
| Pre-commit evidence and review windowMAR-SG-08 |
Operator view and review time |
Contain |
The system enters HOLD at +62 ms because the detailed interface is not ready. The fixed wrong external action is not completed in this synthetic branch. Unknown: A real system may face cases where delay creates a different risk; the lab does not resolve that tradeoff. |
Meaningful Human Judgment ↗ |
| Operator-view and intervention captureMAR-SG-09 |
Operator view and review time |
Answerability |
Investigators can determine whether the final click was substantive or ceremonial, but the baseline event is unchanged unless another control changes timing or authority. Unknown: Interface capture cannot fully establish comprehension, attention, coercion, competence, or institutional incentives. |
Meaningful Human Judgment ↗ |
| Mandatory post-action confirmation clickMAR-SG-10 |
Operator view and review time |
No demonstrated effect |
The click is still recorded at +112 ms, after irreversibility. It changes neither the action nor the evidence available beforehand. Unknown: The record does not establish why the organization retained this confirmation step. |
Meaningful Human Judgment ↗ |
| Safe-hold degraded modeMAR-SG-11 |
Safe-state and degraded-path behavior |
Contain |
The fictional system enters SAFE HOLD at +47 ms and continues observation without committing the wrong external action. Unknown: The replay does not establish that a real safe-hold state would preserve every legitimate defensive function. |
Resilience ↗ |
| Reversible commit stageMAR-SG-12 |
Safe-state and degraded-path behavior |
Contain |
The internal plan is staged at +62 ms but cannot externalize until evidence and authority are rechecked; the branch is cancelled before +86 ms. Unknown: Some physical effects cannot be made reversible; the lab models only a bounded fictional architecture where staging is possible. |
Resilience ↗ |
| Verified alternate review pathMAR-SG-13 |
Safe-state and degraded-path behavior |
Unknown |
The baseline evidence does not establish that an alternate path existed, was independent, was timely, or would have produced a different result. Unknown: The alternate path’s evidence, authority, trust, latency, and failure independence remain unknown. |
Resilience ↗ |
| Material-change revalidation gateMAR-SG-14 |
Software and configuration change control |
Prevent |
The lowered threshold and compact interface cannot enter the active bundle, so the historical validated configuration remains in place and the fixed failure branch does not form. Unknown: The lab does not establish the real test suite, acceptance threshold, or operational cost of delaying a release. |
Change Impact ↗ |
| Exact software and configuration manifestMAR-SG-15 |
Software and configuration change control |
Answerability |
Investigators can identify the active bundle and the changes that shaped the event. The control does not itself stop the baseline action. Unknown: Artifact identity does not prove correct behavior, complete testing, lawful authority, or truthful source data. |
Change Impact ↗ |
| Continuous assurance invalidationMAR-SG-16 |
Continuous assurance and invalidation |
Prevent |
The stale assurance claim is suspended when the maintenance change is introduced, so automatic authority cannot activate until review is complete. Unknown: Real invalidation rules require an authoritative dependency graph and policy for materiality, exceptions, restoration, and emergency operation. |
Continuous Assurance ↗ |
| Append-oriented causal evidence ledgerMAR-SG-17 |
Incident reconstruction and correction ownership |
Answerability |
The full technical history becomes reconstructable and resistant to silent hindsight editing. The historical external action remains unchanged. Unknown: The ledger’s value depends on completeness, authenticity, custody, access controls, retention, and independent review. |
Evulgare Accountability ↗ |
| Named correction, suspension, and retirement ownerMAR-SG-18 |
Incident reconstruction and correction ownership |
Recover |
The wrong historical action cannot be undone, but the affected bundle is suspended, the accepted record is corrected, and recurrence pathways are placed under review. Unknown: The lab does not identify a real legal duty, regulator, remedy, notification rule, or retirement threshold. |
Evulgare Accountability ↗ |
| Fluent generated explanation after the eventMAR-SG-19 |
Incident reconstruction and correction ownership |
No demonstrated effect |
The explanation can restate the log but cannot supply missing provenance, versions, uncertainty, authority, interface timing, dependencies, or assurance evidence. Unknown: The generated narrative’s factual and causal fidelity cannot exceed the evidence supplied to it. |
Evulgare Accountability ↗ |