AAC-CL-01
Supported
Evidence and provenance
Independent, traceable evidence
The observations satisfying the automatic-response precondition originate from sufficiently independent sources and retain reconstructable lineage.
- Evidence integrity
- Evidence integrity intact
- Factual support
- Factual support adequate for scope
- Review owner
- Independent assurance reviewer
- Active change effect
- The selected change has no demonstrated effect on this claim inside the released synthetic model.
- Missing safeguards
- None in the assembled synthetic packet
- Missing assumptions
- None in the assembled synthetic packet
Validity scope: Only the synthetic Orison observation chain and the named source, derivative, and quorum controls.
Residual risk: Independent sources can still share training data, environmental bias, timing errors, or a common institutional assumption.
Does not establish: It does not establish that any real sensor is accurate, lawful, independent, timely, or sufficient for a real consequential action.
Production evidence: Decision Provenance ↗
AAC-CL-02
Suspended
Model and uncertainty
Model remains inside envelope
The exact model and calibration are known, their validation envelope covers the current conditions, and the system abstains when that support is absent.
- Evidence integrity
- Evidence integrity intact
- Factual support
- Factual support stale after change
- Review owner
- System safety authority
- Active change effect
- A new model or calibration artifact enters service while the prior assurance case still names the earlier version.
- Missing safeguards
- None in the assembled synthetic packet
- Missing assumptions
- None in the assembled synthetic packet
Validity scope: Only the identified fictional model, calibration, sensor conditions, and recorded Orison distribution.
Residual risk: A recorded validation envelope can omit interaction effects, adversarial conditions, or rare observations not represented in testing.
Does not establish: It does not certify accuracy, robustness, safety, legality, or fitness for any real operating environment.
Production evidence: Uncertainty Architecture ↗
AAC-CL-03
Supported
Authority boundaries
Authority is current and enforced
The response can occur only when the current policy, purpose, evidence, time, place, and authority preconditions are satisfied.
- Evidence integrity
- Evidence integrity intact
- Factual support
- Factual support adequate for scope
- Review owner
- Policy and authority owner
- Active change effect
- The selected change has no demonstrated effect on this claim inside the released synthetic model.
- Missing safeguards
- None in the assembled synthetic packet
- Missing assumptions
- None in the assembled synthetic packet
Validity scope: Only the declared synthetic Orison purpose, authority state, time window, object category, and deterministic gate.
Residual risk: A formally current rule can still encode an overbroad, mistaken, unlawful, or poorly understood policy choice.
Does not establish: It does not establish that the delegated authority is lawful, proportionate, ethically sufficient, or appropriate for a real system.
Production evidence: Authority Boundaries ↗
AAC-CL-04
Qualified
Human judgment and interface
Human judgment is meaningful
Material evidence, contrary indicators, alternatives, timing, authority, and an effective intervention path reach the person before the action becomes irreversible.
- Evidence integrity
- Evidence integrity intact
- Factual support
- Factual support stale after change
- Review owner
- Operational review owner
- Active change effect
- A new model or calibration artifact enters service while the prior assurance case still names the earlier version.
- Missing safeguards
- None in the assembled synthetic packet
- Missing assumptions
- None in the assembled synthetic packet
Validity scope: Only the specified fictional interface, evidence set, review window, workload, authority, and reversible commitment stage.
Residual risk: Time and information do not guarantee correct judgment; workload, training, organizational pressure, and automation bias may still matter.
Does not establish: It does not prove that a real operator understood the evidence, reached the correct conclusion, or bears or avoids legal responsibility.
Production evidence: Meaningful Human Judgment ↗
AAC-CL-05
Supported
Resilience and safe state
Degraded path remains bounded
When evidence, communications, trust, or authority degrades, the system enters a safe hold or reversible state rather than expanding its own mission.
- Evidence integrity
- Evidence integrity intact
- Factual support
- Factual support adequate for scope
- Review owner
- System safety authority
- Active change effect
- The selected change has no demonstrated effect on this claim inside the released synthetic model.
- Missing safeguards
- None in the assembled synthetic packet
- Missing assumptions
- None in the assembled synthetic packet
Validity scope: Only the declared fictional degraded conditions, safe-hold mechanism, reversible stage, and documented dependencies.
Residual risk: A safe state can create service loss, exposure, or other consequences and may share hidden dependencies with the primary path.
Does not establish: It does not prove that a real fallback path is independent, available, safe, or preferable under every condition.
Production evidence: Resilience ↗
AAC-CL-06
Suspended
Software and change control
Configuration is identified and revalidated
The assurance case names the exact software, model, calibration, configuration, interface, policy, and dependency state that produced the event.
- Evidence integrity
- Evidence integrity intact
- Factual support
- Factual support stale after change
- Review owner
- Software and configuration authority
- Active change effect
- A new model or calibration artifact enters service while the prior assurance case still names the earlier version.
- Missing safeguards
- None in the assembled synthetic packet
- Missing assumptions
- None in the assembled synthetic packet
Validity scope: Only the fingerprinted fictional release, configuration, interface, policy, dependencies, and reviewed material changes.
Residual risk: Exact identity and successful revalidation can still miss emergent interactions, latent defects, or conditions outside the test basis.
Does not establish: It does not certify the software, establish operational effectiveness, or prove that every relevant change was detected.
Production evidence: Change Impact ↗
AAC-CL-07
Suspended
Continuous assurance
Stale assurance is automatically suspended
Material changes to evidence, data, model, software, configuration, interface, policy, dependencies, or environment invalidate the affected assurance claim until revalidation.
- Evidence integrity
- Evidence integrity intact
- Factual support
- Factual support stale after change
- Review owner
- Independent assurance reviewer
- Active change effect
- A new model or calibration artifact enters service while the prior assurance case still names the earlier version.
- Missing safeguards
- None in the assembled synthetic packet
- Missing assumptions
- None in the assembled synthetic packet
Validity scope: Only the synthetic change taxonomy and monitoring relationships represented in the Orison assurance graph.
Residual risk: An invalidation mechanism can fail to observe a relevant change, classify it incorrectly, or be disabled by the same process it monitors.
Does not establish: It does not prove continuous monitoring completeness, certification, legal compliance, or the absence of residual risk.
Production evidence: Continuous Assurance ↗
AAC-CL-08
Supported
Accountability and correction
Incident is reconstructable and correctable
The evidence ledger supports reconstruction of technical and institutional contribution, and a named owner can correct the record and change the system state.
- Evidence integrity
- Evidence integrity intact
- Factual support
- Factual support adequate for scope
- Review owner
- Correction, suspension, and retirement owner
- Active change effect
- The selected change has no demonstrated effect on this claim inside the released synthetic model.
- Missing safeguards
- None in the assembled synthetic packet
- Missing assumptions
- None in the assembled synthetic packet
Validity scope: Only the fictional evidence ledger, institutional roles, correction authority, and preserved Orison event history.
Residual risk: A complete record can still support competing legal, ethical, command, and engineering interpretations that require independent adjudication.
Does not establish: It does not decide guilt, innocence, legal liability, command responsibility, compensation, punishment, exoneration, or a blame percentage.
Production evidence: Evulgare Accountability ↗