Intended cognitive model · six domains · 30 pairs · 180 questions

Solution Assurance Engine Thinking Flow

The Solution Assurance Engine creates evidence-gated readiness analysis from digital solutions by comparing declared purpose, documentation, implementation, testing, and observed behaviour under deterministic controls, using AI only in a bounded role, and reserving final authority for humans.
Cognitive model
Cognitive contract 3.1.0
ReadinessPackageV2 2.6.0
6 domains · 7 lifecycle stages
30 capabilities · 30 anti-patterns
3 questions each · 180 work items
119 approved tactics
How to read this visual: this is the intended thinking flow — the complete cognitive and control architecture, including the assessment instrument. Use it as a completeness check: every capability, anti-pattern and primary question the Engine is designed to ask is listed under stage 4. Open a card for the key question, reasoning logic, grounding basis and reliability control. Open a pair for the three criteria and the paired anti-pattern. Prompts and provider-specific configuration stay abstracted.
AI reasoning Deterministic control Gate / verification Knowledge / action support Human / publication boundary
Governed assessment universe

Six domains, thirty pairs, three evidence dimensions.

Every applicable capability and anti-pattern receives an explicit result. Each object is asked the same three questions: is the requirement defined, is it implemented in the actual system, and does current evidence show that it works? Claims become findings only after independent verification. Tactics appear only from locked findings mapped to these object IDs. Missing evidence stays UNKNOWN. Named humans retain formal authority.

Instrument

30 × 30 × 3

30 capabilities A1–F5, 30 anti-patterns AP-A1–AP-F5, 180 primary questions. Source: AI Governance Categories and Anti-Patterns v1.1.

Playbook

119 approved tactics

Every capability and anti-pattern has at least one mapped tactic. Retrieval is exact object-id matching from locked findings — not keywords.

Evidence dimensions

Define · implement · evidence

Q1 definition and intent. Q2 implementation and operation. Q3 evidence and effectiveness. Design cannot be treated as operational proof.

Authority

Human remains outside

The user is the only Intake authority. The Engine never issues legal conclusions, residual-risk acceptance or formal approval.

1. Source-first intake, local parsing & safety boundary

The Engine begins with the evidence itself. Files are parsed locally, screened, registered with stable provenance, and converted into redacted bounded packets before any governance inference is permitted.

Evidence boundary first
Critical trust idea: uploaded material is untrusted evidence, never executable instruction. Raw bytes remain outside the reasoning contract. Provider packets carry deterministic summaries and the user-approved Intake — not source text, code, cells, pixels, names or quotes.
SRC
Open logic
Source preparation

Multi-format parsing

Normalizes code, text, JSON, CSV, HTML, PDF, DOCX, XLSX and supported images into source units through versioned acquisition lanes.

Local parseArchive safetyNo execution
Key question
What evidence can be extracted safely without executing uploaded scripts, formulas, links, macros, or embedded instructions?
Reasoning logic
Convert heterogeneous files into inert machine-readable units while preserving source path, locator, artifact class, and parse limitations. Documents, code/configuration, tabular data and media follow separate local-analysis lanes, including bounded OCR for sparse PDF pages and images.
Grounding basis
File type, extracted content, archive inspection, media metadata, byte/hash identity, acquisition-manifest lineage, and parsing diagnostics.
Reliability control
Unsupported or unsafe source-like content becomes an explicit coverage limitation; it is not silently treated as successfully assessed.
DLP
Open logic
Safety control

DLP, secrets & redaction

Detects sensitive values and prepares only approved redacted evidence packets for external reasoning calls.

SecretsSummaries onlyNo raw to providers
Key question
Can this evidence cross the model boundary without exposing secrets or unnecessary sensitive information?
Reasoning logic
Screen source text, record findings, redact restricted content, and preserve a visible transmission policy for every packet. Approved Intake declaration units are stamped with raw content excluded.
Grounding basis
Deterministic secret patterns, content-policy sanitation, source sensitivity tags, packet previews, and transmission state.
Reliability control
Hashed HTTP bodies stay canonical so integrity hashes are not mutated in transit. Model reasoning never receives an unrestricted copy of the uploaded evidence.
ID
Open logic
Provenance

Content-addressed source registry

Registers source units, hashes, locators, exclusions and extraction lineage before assessment begins.

SHA-256Source unit IDsManifest
Key question
Can every later claim and finding be traced to the exact evidence unit that supports or contradicts it?
Reasoning logic
Create a Source Ingestion Manifest and stable source-unit identities before any cognitive stage can use the evidence. Durable checkpoints store only provider-eligible summaries and approved Intake — never raw units.
Reliability control
Unattributed narrative cannot become deterministic decision evidence merely because it sounds plausible.
KB
Open logic
Knowledge boundary

Governed criteria, never case evidence

Assessment asks the 30 capability / 30 anti-pattern instrument. Tactics retrieve from locked findings mapped to those object IDs. Methodology stays separate from the assessed solution.

Normative sourcesRequirementsControlsAnti-patternsTactics
Key question
Which governance definitions, requirements, controls, anti-patterns and tactics may shape assessment logic?
Reasoning logic
Load versioned runtime collections only after manifest, hash and reference validation. Treat them as criteria and response knowledge. Production fails closed if the governed knowledge cannot be verified.
Grounding basis
Five runtime collections: normative sources, requirements, controls, anti-patterns and tactics. Object IDs are A1–F5 and AP-A1–AP-F5. Question IDs are A1-Q1…F5-Q3 and AP-A1-Q1…AP-F5-Q3.
Reliability control
Knowledge is criteria, never proof of the assessed solution. Claims mapped to IDs that are not in the governed snapshot are rejected.

2. Deterministic discovery, semantic recheck & confirmed intake

Before the main assessment, the Engine constructs a field-level understanding of intended use, shows it to the user, preserves conflicts, and creates an immutable confirmed intake boundary. Analysis does not start until that user action.

Human-confirmed assessment scope
Deterministic discoveryOptional cited recheck / proposalsUser confirmationImmutable confirmed intake
DISC
Open logic
Case understanding

Field-level solution profile

Extracts purpose, lifecycle, users, data, autonomy and other case facts with explicit provenance and uncertainty. Unknown is a valid resolution.

DeclaredObservedUnknown
Key question
What does the submitted evidence actually establish about the intended use and current system boundary?
Reasoning logic
Build a structured profile from source evidence and the dossier, preserving contradictions rather than smoothing them away. Semantic observations may support editable wording; only user acceptance places wording in approved Intake.
Reliability control
Lexical discovery remains an indicator; it cannot independently establish implemented assurance or erase conflicting documentary evidence. Missing evidence stays UNKNOWN.
AI?
Open logic
Optional semantic verification

Cited discovery recheck

Uses bounded AI reasoning to challenge the deterministic intake draft without overwriting deterministic or user-entered values.

CitedAdvisoryExplicit request
Key question
Did deterministic discovery miss a material interpretation that is actually supported by the submitted sources?
Reasoning logic
Optional retrieval planning and one bounded local re-read run on privacy-safe metrics only. Discover-recheck may propose missing-field wording from field-mapped semantic observations or selected acquired facts. Prefill lands only in still-empty fields and stays editable until final approval.
Reliability control
The semantic recheck cannot silently rewrite the intake, approve it, or manufacture documentary support. Skipping proposals does not block confirmation.
H
Open logic
Human boundary

Confirm intended-use dossier

The user reviews detected facts, may Accept-as-Unknown, and is the only actor who can freeze Intake and start analysis.

User-only approvalAccept-as-UnknownHashed snapshot
Key question
What exact case description is the Engine authorized to assess?
Reasoning logic
Require solution name and accountable owner, plus an explicit resolution — including Unknown — for every other applicable field. Confirmation creates a hashed approved Intake snapshot bound to the acquisition-manifest hash. Remaining field unknowns are preserved as analysis limitations, not blockers.
Reliability control
User confirmation creates an attributable declaration; it does not turn an unsupported statement into documentary evidence.
LOCK
Open logic
Execution boundary

Packet / transmission approval

Only the redacted packets bound after confirm, and the configured provider route, may cross the external reasoning boundary.

Packet hashesApproved routeNo raw content
Key question
Exactly which redacted evidence packets may be transmitted for analysis?
Reasoning logic
After confirm, a run-level packet manifest binds packet ids and hashes to the approved snapshot and acquisition-manifest hash. Execute verifies that manifest before enqueue.
Reliability control
The browser does not choose arbitrary providers or send raw source files.

3. Solution understanding, independent fact verification & evidence routing

The confirmed dossier is turned into a candidate solution model, externally observed facts are independently checked, and source units are routed into bounded governance-domain packets.

Interpretation before domain judgment
Core separation: a solution fact must survive independent verification before it can become shared cognitive context. Unverified or conflicting facts stay visible as limitations rather than being upgraded through repetition.
SOL
Open logic
Solution model

Candidate system understanding

Builds a structured view of purpose, actors, data, architecture, autonomy, lifecycle and material dependencies.

Candidate factsContradictionsUnknowns
Key question
What solution model best explains the confirmed dossier and attributable evidence?
Reasoning logic
Generate candidate solution facts with source references, then normalize them against deterministic dossier facts.
Reliability control
Failure falls back to a deterministic dossier-only solution model rather than inventing missing system context.
V
Open logic
Independent verification

Solution-fact check

Observed candidate facts are challenged by an independent reasoning route before entering the shared model.

Verified factsUnresolved factsIndependent route
Key question
Do the cited source units really establish this solution fact?
Reasoning logic
Check observed candidates separately from the model that first proposed them and preserve unresolved items explicitly. Fixed roles: WORKHORSE, REASONER, QUALITY_CHECKER — each with a primary and fallback provider.
Reliability control
Primary-model confidence cannot substitute for independent evidentiary support.
A–F
Open logic
Routing

Local domain classification

Deterministic signals route source units to A–F; only ambiguous units receive semantic routing assistance.

Local firstAmbiguity onlyBounded packets
Key question
Which governance domains genuinely need each source unit?
Reasoning logic
Use local routing first, invoke semantic routing only for ambiguous units, and default unresolved ambiguity conservatively across domains.
Reliability control
Domain assessors receive only approved relevant evidence packets instead of an unrestricted source dump.
LIN
Open logic
Derived evidence

Local media summaries only

Image pixels never enter provider packets. Visual evidence may produce derived text linked to an immutable parent source unit.

Parent lineageOCR QUALIFIEDNo pixels to providers
Key question
How can visual evidence enter the reasoning path without becoming an untraceable interpretation?
Reasoning logic
Bounded local OCR may produce derived text linked to the parent source unit. Low-confidence OCR is REVIEW_REQUIRED and does not populate Intake. Provider-eligible media bytes fail before transport.
Reliability control
Derived evidence cannot silently replace the immutable raw source.

4. Parallel A–F governance assessment & complete coverage accounting

Six domain assessments run over bounded evidence and the governed instrument. The universe is 30 capabilities, 30 paired anti-patterns and 180 primary questions. Every applicable object receives an explicit result, including “no evidence found.”

Parallel evidence-bounded reasoning
Coverage contract: analysis does not invent A–F questions. It batches the instrument — requirements, controls, anti-patterns and their three primary questions — and rejects claims mapped to IDs that are not in that snapshot. Object IDs are A1–F5 and AP-A1–AP-F5. Question IDs are A1-Q1 / AP-A1-Q1 and the matching Q2 / Q3. Applicability filters (always, uses data, personal data, agents, third parties, affected people, human interaction) decide which pairs apply to the confirmed dossier.
Q1 · Definition & intent

Is the requirement specified?

Purpose, roles, boundaries, classification, rights, authority and acceptance criteria must be explicit enough to govern design and evaluation. Vague wording is not a definition.

Q2 · Implementation & operation

Is it built into the actual system?

Contracts, workflows, data paths, access, tools, monitoring and product behaviour must instantiate the definition. Policy text is not implementation.

Q3 · Evidence & effectiveness

Does current evidence show that it works?

Tests, operational records, reconstruction, rights fulfilment and scoped absence tests. Design artefacts cannot raise assurance to TESTED or OPERATIONALLY_OBSERVED.

A
Open domain
Governance domain

Purpose, value & classification

Intended purpose, value rationale, roles, system boundary and regulatory/governance classification.

Work items
Five capability / anti-pattern pairs. Each pair is assessed on the same three dimensions: definition & intent, implementation & operation, evidence & effectiveness.
Object IDs
A1 / AP-A1 — Intended purpose and use boundaries · A2 / AP-A2 — AI suitability, proportionality and value hypothesis · A3 / AP-A3 — Value-chain roles and responsibility boundaries · A4 / AP-A4 — Risk, legal and regulatory classification · A5 / AP-A5 — Lifecycle stage and transition boundary
B
Open domain
Governance domain

Data, privacy, confidentiality & IP

Data provenance, lawful handling, privacy, confidentiality and intellectual-property controls.

Work items
Five capability / anti-pattern pairs. Each pair is assessed on the same three dimensions: definition & intent, implementation & operation, evidence & effectiveness.
Object IDs
B1 / AP-B1 — Data inventory, provenance and lineage · B2 / AP-B2 — Purpose limitation and data minimization · B3 / AP-B3 — Privacy and data-subject governance · B4 / AP-B4 — Confidentiality and information-boundary control · B5 / AP-B5 — Intellectual property, licensing and content rights
C
Open domain
Governance domain

Models, agents, providers & supply chain

Model and provider selection, agent/tool boundaries, provenance and third-party risk.

Work items
Five capability / anti-pattern pairs. Each pair is assessed on the same three dimensions: definition & intent, implementation & operation, evidence & effectiveness.
Object IDs
C1 / AP-C1 — Model, agent and component inventory · C2 / AP-C2 — Model and provider suitability · C3 / AP-C3 — Agent autonomy and tool permissioning · C4 / AP-C4 — Provider, vendor and contractual governance · C5 / AP-C5 — AI supply-chain integrity and change control
D
Open domain
Governance domain

Architecture, security, robustness & evaluation

Technical architecture, security, resilience, safety, testing and evaluation sufficiency.

Work items
Five capability / anti-pattern pairs. Each pair is assessed on the same three dimensions: definition & intent, implementation & operation, evidence & effectiveness.
Object IDs
D1 / AP-D1 — Secure and isolated AI architecture · D2 / AP-D2 — Functional quality, accuracy and reliability · D3 / AP-D3 — AI-specific security and adversarial resilience · D4 / AP-D4 — Traceability, reproducibility and observability · D5 / AP-D5 — Safety, failure handling and recovery
E
Open domain
Governance domain

Human impact, fairness & oversight

Affected-person impact, fairness, transparency, meaningful human oversight and recourse.

Work items
Five capability / anti-pattern pairs. Each pair is assessed on the same three dimensions: definition & intent, implementation & operation, evidence & effectiveness.
Object IDs
E1 / AP-E1 — Human and fundamental-rights impact · E2 / AP-E2 — Fairness and non-discrimination · E3 / AP-E3 — Transparency and communication · E4 / AP-E4 — Meaningful human oversight · E5 / AP-E5 — Contestability, correction, accessibility and AI literacy
F
Open domain
Governance domain

Accountability, evidence & lifecycle

Decision authority, evidence quality, risk decisions, monitoring, reassessment and lifecycle governance.

Work items
Five capability / anti-pattern pairs. Each pair is assessed on the same three dimensions: definition & intent, implementation & operation, evidence & effectiveness.
Object IDs
F1 / AP-F1 — Ownership and accountable operating model · F2 / AP-F2 — Compliance evidence and documentation integrity · F3 / AP-F3 — Risk, control and residual-risk management · F4 / AP-F4 — Decision rights, authorization and escalation · F5 / AP-F5 — Monitoring, incidents, change, re-evaluation and retirement
12
Open logic
Bounded work

Object batches from the instrument

Work items are batched and paired only with the domain knowledge those objects need. Each item’s question wording is exact — not rewritten, merged or invented.

30 + 30 objects3 questions each180 work items
Key question
What is the smallest governance/evidence context required to assess this explicit set of objects?
Reasoning logic
Assess only listed work items. Stamp the capability or anti-pattern ID plus the question ID. Missing evidence is recorded as assessed-but-unknown. Generated claims are rejected if their mappings do not exist in the governed snapshot.
Reliability control
Incomplete cognitive coverage becomes a visible hard-gate input; successful domains do not hide failed ones.
COV
Open logic
Completeness control

Assessment coverage matrix

Records whether every applicable governance object was assessed, had no evidence, or failed due to a domain-stage problem.

Explicit coveragePartial domainsFail closed
Key question
Did the assessment cover the full governed universe required for this dossier and lifecycle stage?
Reliability control
A thin Intake typically yields unknowns, not locked findings. Unknown is a result. Silence is not safety, compliance, or absence of an anti-pattern.
A
Domain A · 5 capabilities · 5 anti-patterns · 30 questions

Purpose, value & classification

Intended purpose, value rationale, roles, system boundary and regulatory/governance classification.

A1 Intended purpose and use boundaries Always applicable · HIGH · paired AP-A1 · 3+4 tactics Open criteria

The intended purpose, users, affected persons, operating context, expected outputs, permitted uses, prohibited uses and foreseeable misuse are precise enough to govern design and evaluation.

Q1 · Definition & intentA1-Q1
Is the intended purpose and decision context specific, bounded and testable?
Q2 · Implementation & operationA1-Q2
Are purpose and use boundaries implemented consistently in workflows, data use, access and product behavior?
Q3 · Evidence & effectivenessA1-Q3
Does current evidence show that actual and foreseeable use remains within the declared boundary?
Indicators
Named users and affected personsExplicit permitted and prohibited usesMeasurable output and outcome expectationsPurpose reflected in architecture and evaluations
AP-A1
Undefined or elastic intended purposeAnti-pattern · HIGH · undefined-purpose · 4 tactics

The purpose is vague, technically framed, inconsistent or expands without requalification.

Q1 · Definition & intentAP-A1-Q1
Is the declared purpose vague, inconsistent or missing material use boundaries?
Q2 · Implementation & operationAP-A1-Q2
Do implemented or operational uses materially diverge from the declared purpose?
Q3 · Evidence & effectivenessAP-A1-Q3
Has a scoped current comparison tested declared and actual uses for divergence?
Indicators
General-purpose wording without use constraintsConflicting purpose statementsNo affected-person boundaryPrototype features become accepted use without review
A2 AI suitability, proportionality and value hypothesis Always applicable · HIGH · paired AP-A2 · 3+4 tactics Open criteria

The organization demonstrates that AI is a proportionate mechanism for a defined problem and that expected value is measurable against cost, alternatives and risk.

Q1 · Definition & intentA2-Q1
Is the problem, desired outcome and measurable value hypothesis defined independently of the AI solution?
Q2 · Implementation & operationA2-Q2
Has the chosen AI approach been compared with simpler alternatives and implemented with explicit cost-risk trade-offs?
Q3 · Evidence & effectivenessA2-Q3
Do representative trials show sufficient value and feasibility to justify progression, with stop criteria applied?
Indicators
Non-AI baseline existsValue metrics and owners are namedCost and operational consequences are consideredContinuation and stop criteria are enforced
AP-A2
AI-first solutionism or value theatreAnti-pattern · HIGH · value-theatre · 4 tactics

AI is adopted for novelty, availability or signalling without evidence that it is the best proportionate mechanism.

Q1 · Definition & intentAP-A2-Q1
Does the case exhibit AI-first solutionism or value theatre: AI is adopted for novelty, availability or signalling without evidence that it is the best proportionate mechanism.
Q2 · Implementation & operationAP-A2-Q2
Do implemented workflows, data paths or operations show a predetermined AI solution, missing baseline comparison, or activity metrics substituting for value?
Q3 · Evidence & effectivenessAP-A2-Q3
Does current evidence test presence or scoped absence of AI-first solutionism or value theatre, or does it remain unknown?
Indicators
The use case starts with a predetermined AI solutionNo baseline or alternative comparisonActivity metrics substitute for valueProgress continues despite poor outcome evidence
A3 Value-chain roles and responsibility boundaries Always applicable · HIGH · paired AP-A3 · 3+4 tactics Open criteria

Organizational, contractual and regulatory roles across the complete AI value chain are identified and matched to real control and accountability.

Q1 · Definition & intentA3-Q1
Are system, business, provider, deployer, integrator and component roles explicitly determined?
Q2 · Implementation & operationA3-Q2
Are responsibilities implemented through contracts, operating procedures, access and ownership assignments?
Q3 · Evidence & effectivenessA3-Q3
Does evidence show that each party can and does discharge the responsibilities assigned to it?
Indicators
System and business owners are namedProvider and deployer duties are separatedContract and operating model agreeComponent responsibility is traceable
AP-A3
Role ambiguity and responsibility displacementAnti-pattern · HIGH · responsibility-displacement · 4 tactics

Parties assume that governance, compliance or operational control belongs to someone else.

Q1 · Definition & intentAP-A3-Q1
Does the case exhibit Role ambiguity and responsibility displacement: Parties assume that governance, compliance or operational control belongs to someone else.
Q2 · Implementation & operationAP-A3-Q2
Do implemented workflows, data paths or operations show vendor assurance treated as deployer assurance, overlapping ownership, or unowned integrated components?
Q3 · Evidence & effectivenessAP-A3-Q3
Does current evidence test presence or scoped absence of Role ambiguity and responsibility displacement, or does it remain unknown?
Indicators
Vendor assurance is treated as deployer assuranceOverlapping or contradictory ownershipNo owner for integrated componentsResponsibility disappears across subcontracting
A4 Risk, legal and regulatory classification Always applicable · HIGH · LEGAL · paired AP-A4 · 3+4 tactics Open criteria

The complete system and actual use are classified through a reviewable applicability analysis covering role, risk, jurisdiction, data, impact and sector obligations.

Q1 · Definition & intentA4-Q1
Are applicable jurisdictions, roles, prohibited-practice screens, risk classes and adjacent legal regimes identified from actual use?
Q2 · Implementation & operationA4-Q2
Are classification outcomes implemented as controls, documentation duties, review routes and transition constraints?
Q3 · Evidence & effectivenessA4-Q3
Is the rationale current, evidence-backed, independently reviewed where needed and linked to reclassification triggers?
Indicators
System-level classification recordUncertainty and dissent are visibleAdjacent regimes are screenedMaterial change triggers reclassification
AP-A4
Superficial or static classificationAnti-pattern · HIGH · static-classification · 4 tactics

Classification is copied, model-centric, overconfident or treated as a one-time formality.

Q1 · Definition & intentAP-A4-Q1
Does the case exhibit Superficial or static classification: Classification is copied, model-centric, overconfident or treated as a one-time formality.
Q2 · Implementation & operationAP-A4-Q2
Do implemented workflows, data paths or operations show copied vendor categories, internal ratings treated as legal class, or missing reclassification after change?
Q3 · Evidence & effectivenessAP-A4-Q3
Does current evidence test presence or scoped absence of Superficial or static classification, or does it remain unknown?
Indicators
Vendor category copied without use analysisInternal rating confused with legal classUnknown legal questions stated as factsNo reclassification after change
A5 Lifecycle stage and transition boundary Always applicable · HIGH · paired AP-A5 · 3+4 tactics Open criteria

The current stage, permitted activities, target stage, acceptance criteria and authorization boundary are explicit from qualification through retirement.

Q1 · Definition & intentA5-Q1
Are current and target lifecycle stages, scope and permitted activities explicitly defined?
Q2 · Implementation & operationA5-Q2
Are environment, data, access and user boundaries technically and operationally enforced for the current stage?
Q3 · Evidence & effectivenessA5-Q3
Does evidence demonstrate that transition criteria are met and the correct authority has approved progression?
Indicators
Stage-specific boundary recordExperiment and production separationTransition acceptance criteriaRetirement and rollback remain possible
AP-A5
Prototype-to-production driftAnti-pattern · CRITICAL · prototype-production-drift · 4 tactics

An experiment accumulates real users, data, integrations or dependency without formal transition and reassessment.

Q1 · Definition & intentAP-A5-Q1
Does the case exhibit Prototype-to-production drift: An experiment accumulates real users, data, integrations or dependency without formal transition and reassessment.
Q2 · Implementation & operationAP-A5-Q2
Do implemented workflows, data paths or operations show production data or credentials in an experiment, indefinite prototypes, or development approval treated as deployment approval?
Q3 · Evidence & effectivenessAP-A5-Q3
Does current evidence test presence or scoped absence of Prototype-to-production drift, or does it remain unknown?
Indicators
Temporary prototype runs indefinitelyProduction data or credentials enter an experimentDevelopment approval is treated as deployment approvalShadow infrastructure becomes business critical
B
Domain B · 5 capabilities · 5 anti-patterns · 30 questions

Data, privacy, confidentiality & IP

Data provenance, lawful handling, privacy, confidentiality and intellectual-property controls.

B1 Data inventory, provenance and lineage When the system uses data · HIGH · paired AP-B1 · 3+4 tactics Open criteria

Training, tuning, retrieval, prompt, evaluation, operational and output data are separately identifiable from origin through transformation, storage, transfer and deletion.

Q1 · Definition & intentB1-Q1
Are material data classes, sources, owners, destinations and uses inventoried with stable identifiers?
Q2 · Implementation & operationB1-Q2
Are lineage, transformation, quality, licensing and transfer controls implemented across the actual data flow?
Q3 · Evidence & effectivenessB1-Q3
Can representative outputs and decisions be traced to current, authorized and sufficiently reliable data evidence?
Indicators
Data-flow and lineage recordsStable dataset identifiersOwners and rights are recordedOutputs preserve provenance where material
AP-B1
Invisible or untraceable data flowsAnti-pattern · HIGH · untraceable-data · 4 tactics

Data origin, ownership, transformation, transmission, retention or reuse cannot be reliably established.

Q1 · Definition & intentAP-B1-Q1
Does the case exhibit Invisible or untraceable data flows: Data origin, ownership, transformation, transmission, retention or reuse cannot be reliably established.
Q2 · Implementation & operationAP-B1-Q2
Do implemented workflows, data paths or operations show unknown prompt sources, undocumented provider fields, or outputs reused without provenance?
Q3 · Evidence & effectivenessAP-B1-Q3
Does current evidence test presence or scoped absence of Invisible or untraceable data flows, or does it remain unknown?
Indicators
Unknown sources mixed in promptsRetrieval stores lack dataset recordsUndocumented fields reach providersOutputs are reused without provenance
B2 Purpose limitation and data minimization When the system uses data · HIGH · paired AP-B2 · 3+4 tactics Open criteria

Only data demonstrably necessary and proportionate for the declared purpose and lifecycle stage are processed and retained.

Q1 · Definition & intentB2-Q1
Is necessity defined for each material data category, field and retention period?
Q2 · Implementation & operationB2-Q2
Are minimization, abstraction, tokenization, synthetic-data and deletion controls implemented in every relevant store and interface?
Q3 · Evidence & effectivenessB2-Q3
Do tests and operational evidence show that unnecessary content is excluded and deletion or scope changes propagate?
Indicators
Field-level necessity recordMinimized or synthetic prototype dataRetention tied to purposeScope reassessed after design change
AP-B2
Convenience-driven data accumulationAnti-pattern · HIGH · data-accumulation · 4 tactics

Data is collected, transmitted or retained because it may be useful rather than because it is necessary.

Q1 · Definition & intentAP-B2-Q1
Does the case exhibit Convenience-driven data accumulation: Data is collected, transmitted or retained because it may be useful rather than because it is necessary.
Q2 · Implementation & operationAP-B2-Q2
Do implemented workflows, data paths or operations show whole-database copies, full documents sent when fields suffice, or missing deletion propagation?
Q3 · Evidence & effectivenessAP-B2-Q3
Does current evidence test presence or scoped absence of Convenience-driven data accumulation, or does it remain unknown?
Indicators
Whole databases copied for narrow useFull documents sent when fields sufficeNo deletion propagationMore context is assumed to be inherently better
B3 Privacy and data-subject governance When personal data is processed · HIGH · PRIVACY · paired AP-B3 · 3+4 tactics Open criteria

Personal-data processing, lawful basis, transparency, rights, privacy risks and impact-assessment duties are operationalized in the system and its lifecycle.

Q1 · Definition & intentB3-Q1
Are personal-data categories, purposes, lawful basis, rights and impact-assessment triggers determined?
Q2 · Implementation & operationB3-Q2
Are privacy requirements implemented across architecture, access, logging, retention, providers and user workflows?
Q3 · Evidence & effectivenessB3-Q3
Do tests and operational records demonstrate rights fulfilment, deletion, restriction and privacy-control effectiveness?
Indicators
Data categories are classifiedContext-specific privacy analysisRights can be fulfilled end to endPrivacy controls are tested
AP-B3
Privacy-by-documentation onlyAnti-pattern · CRITICAL · privacy-by-documentation · 4 tactics

Privacy exists in policy text but is not reflected in actual data flows, controls or operations.

Q1 · Definition & intentAP-B3-Q1
Does the case exhibit Privacy-by-documentation only: Privacy exists in policy text but is not reflected in actual data flows, controls or operations.
Q2 · Implementation & operationAP-B3-Q2
Do implemented workflows, data paths or operations show personal data in logs or embeddings, rights that cannot propagate, or pseudonymization treated as anonymization?
Q3 · Evidence & effectivenessAP-B3-Q3
Does current evidence test presence or scoped absence of Privacy-by-documentation only, or does it remain unknown?
Indicators
Privacy statement without inventoryPersonal data persists in logs or embeddingsRights cannot propagatePseudonymization is treated as anonymization
B4 Confidentiality and information-boundary control Always applicable · HIGH · paired AP-B4 · 3+4 tactics Open criteria

Confidential, restricted, customer-controlled and security-sensitive information remains within approved identity, tenant, provider, logging and contractual boundaries.

Q1 · Definition & intentB4-Q1
Are information classes, confidentiality obligations and prohibited disclosure paths explicitly defined?
Q2 · Implementation & operationB4-Q2
Are secrets isolation, least privilege, tenant separation, provider settings and leakage controls technically enforced?
Q3 · Evidence & effectivenessB4-Q3
Do leakage, cross-tenant, unauthorized reuse and output-disclosure tests demonstrate effective boundaries?
Indicators
AI inputs follow classification rulesSecrets are excluded from model-visible contextTenant isolation is testedProvider retention and training settings are known
AP-B4
Confidentiality leakage through AI channelsAnti-pattern · CRITICAL · confidentiality-leakage · 4 tactics

Sensitive information enters or leaves models, prompts, logs, caches, retrieval stores or tools without adequate protection.

Q1 · Definition & intentAP-B4-Q1
Does the case exhibit Confidentiality leakage through AI channels: Sensitive information enters or leaves models, prompts, logs, caches, retrieval stores or tools without adequate protection.
Q2 · Implementation & operationAP-B4-Q2
Do implemented workflows, data paths or operations show secrets in prompts, unapproved provider transfers, or outputs revealing source-system content?
Q3 · Evidence & effectivenessAP-B4-Q3
Does current evidence test presence or scoped absence of Confidentiality leakage through AI channels, or does it remain unknown?
Indicators
Secrets embedded in promptsUnapproved provider receives restricted dataShared retrieval store lacks tenant isolationOutputs reveal source-system content
B5 Intellectual property, licensing and content rights Always applicable · HIGH · LEGAL · paired AP-B5 · 3+4 tactics Open criteria

The organization has a defensible and traceable basis to use, transform, train on, retrieve, generate and distribute relevant data, models, code and outputs.

Q1 · Definition & intentB5-Q1
Are rights, licences, restrictions, attribution and ownership conditions identified for all material assets and outputs?
Q2 · Implementation & operationB5-Q2
Are those conditions implemented in ingestion, training, retrieval, generation, review and distribution workflows?
Q3 · Evidence & effectivenessB5-Q3
Does current evidence demonstrate compliance with restrictions and effective detection or review of infringement risk?
Indicators
Licence and rights inventoryRestricted content is blocked or permissionedOutput-use conditions are explicitCustomer IP boundaries are preserved
AP-B5
Unverified rights and output ownershipAnti-pattern · HIGH · unverified-rights · 4 tactics

Accessible content is assumed to be available for AI use, transformation or redistribution without rights analysis.

Q1 · Definition & intentAP-B5-Q1
Does the case exhibit Unverified rights and output ownership: Accessible content is assumed to be available for AI use, transformation or redistribution without rights analysis.
Q2 · Implementation & operationAP-B5-Q2
Do implemented workflows, data paths or operations show scraped material without rights review, confidential tuning data, or generated output claimed as proprietary without review?
Q3 · Evidence & effectivenessAP-B5-Q3
Does current evidence test presence or scoped absence of Unverified rights and output ownership, or does it remain unknown?
Indicators
Scraped material lacks rights reviewConfidential material used for tuningLicence conflicts with commercial useGenerated output is claimed as proprietary without review
C
Domain C · 5 capabilities · 5 anti-patterns · 30 questions

Models, agents, providers & supply chain

Model and provider selection, agent/tool boundaries, provenance and third-party risk.

C1 Model, agent and component inventory Always applicable · HIGH · paired AP-C1 · 3+4 tactics Open criteria

Models, agents, prompts, tools, APIs, datasets, providers, infrastructure, versions and owners are registered and linked to the assessed system.

Q1 · Definition & intentC1-Q1
Are all material AI and supporting components, versions, configurations, owners and roles inventoried?
Q2 · Implementation & operationC1-Q2
Is inventory capture integrated with build, deployment, routing and change processes?
Q3 · Evidence & effectivenessC1-Q3
Can a specific run, decision or incident be reconstructed from the component baseline actually used?
Indicators
Component manifest existsModel and prompt versions are traceableTools and permissions are visibleObsolete components can be identified
AP-C1
Shadow AI component usageAnti-pattern · HIGH · shadow-ai · 4 tactics

Unregistered or uncontrolled models, tools, providers, prompts or agent capabilities are used.

Q1 · Definition & intentAP-C1-Q1
Does the case exhibit Shadow AI component usage: Unregistered or uncontrolled models, tools, providers, prompts or agent capabilities are used.
Q2 · Implementation & operationAP-C1-Q2
Do implemented workflows, data paths or operations show models selected directly in code, unofficial AI services, or tool sets that differ from architecture?
Q3 · Evidence & effectivenessAP-C1-Q3
Does current evidence test presence or scoped absence of Shadow AI component usage, or does it remain unknown?
Indicators
Model selected directly in codeUnofficial AI service processes dataTool set differs from architectureNo owner for a critical component
C2 Model and provider suitability Always applicable · HIGH · paired AP-C2 · 3+4 tactics Open criteria

Model and provider selections are evidence-based for task quality, language, latency, security, privacy, resilience, cost, contract and risk.

Q1 · Definition & intentC2-Q1
Are task-specific model and provider requirements and selection criteria defined?
Q2 · Implementation & operationC2-Q2
Are approved choices, routing, fallbacks and contractual constraints implemented in configuration and operation?
Q3 · Evidence & effectivenessC2-Q3
Do representative evaluations and provider evidence demonstrate continued suitability against alternatives?
Indicators
Selection criteria are documentedSuitability is tied to test resultsFallbacks are controlledProvider limitations are known
AP-C2
Convenience- or brand-driven model selectionAnti-pattern · HIGH · brand-driven-selection · 4 tactics

Models or providers are selected by familiarity, availability, prestige or generic benchmarks rather than contextual evidence.

Q1 · Definition & intentAP-C2-Q1
Does the case exhibit Convenience- or brand-driven model selection: Models or providers are selected by familiarity, availability, prestige or generic benchmarks rather than contextual evidence.
Q2 · Implementation & operationAP-C2-Q2
Do implemented workflows, data paths or operations show one model used for every task, missing provider comparison, or generic benchmarks replacing system testing?
Q3 · Evidence & effectivenessAP-C2-Q3
Does current evidence test presence or scoped absence of Convenience- or brand-driven model selection, or does it remain unknown?
Indicators
One model is used for every taskNo provider comparisonGeneric benchmark replaces system testingFallback is untested
C3 Agent autonomy and tool permissioning When agents are used · CRITICAL · paired AP-C3 · 3+4 tactics Open criteria

Agent authority is explicit, least-privilege, stage-appropriate, budgeted, observable and bounded by deterministic authorization for consequential actions.

Q1 · Definition & intentC3-Q1
Are each agent's tools, credentials, data access, action scope, budgets and approval points defined?
Q2 · Implementation & operationC3-Q2
Are least privilege, deterministic authorization, reversibility, rate limits and interruption implemented outside model discretion?
Q3 · Evidence & effectivenessC3-Q3
Do negative tests and runtime evidence show that unauthorized, recursive or cross-boundary actions are prevented and detected?
Indicators
Per-tool permission modelConsequential actions require approvalRead and write privileges differKill switch and rollback exist
AP-C3
Unbounded or implicit agent authorityAnti-pattern · CRITICAL · excessive-agency · 4 tactics

An agent receives broad access and can choose independently how to exercise it without enforceable limits.

Q1 · Definition & intentAP-C3-Q1
Does the case exhibit Unbounded or implicit agent authority: An agent receives broad access and can choose independently how to exercise it without enforceable limits.
Q2 · Implementation & operationAP-C3-Q2
Do implemented workflows, data paths or operations show shared administrative credentials, unrestricted tool access, or model-controlled authorization?
Q3 · Evidence & effectivenessAP-C3-Q3
Does current evidence test presence or scoped absence of Unbounded or implicit agent authority, or does it remain unknown?
Indicators
Shared administrative credentialsUnrestricted browser or database accessModel controls authorizationNo approval for external messages or record changes
C4 Provider, vendor and contractual governance When third-party components are used · HIGH · paired AP-C4 · 3+4 tactics Open criteria

Third-party AI services are evaluated, contractually governed, monitored and replaceable in the context of the actual system.

Q1 · Definition & intentC4-Q1
Are provider terms, data practices, subprocessors, service limits, audit rights and exit needs defined?
Q2 · Implementation & operationC4-Q2
Are contractual controls, approved configurations, monitoring and contingency arrangements implemented?
Q3 · Evidence & effectivenessC4-Q3
Does current evidence show that material provider changes and service failures are detected, assessed and acted upon?
Indicators
Approved-vendor statusTerms and subprocessors are versionedRetention and training use are confirmedExit and portability plans exist
AP-C4
Vendor assurance substitutionAnti-pattern · HIGH · vendor-assurance-substitution · 4 tactics

Vendor claims, certifications or marketing are treated as proof that the integrated system is governed.

Q1 · Definition & intentAP-C4-Q1
Does the case exhibit Vendor assurance substitution: Vendor claims, certifications or marketing are treated as proof that the integrated system is governed.
Q2 · Implementation & operationAP-C4-Q2
Do implemented workflows, data paths or operations show enterprise-grade used as evidence, assumed transfer of provider compliance, or missing exit plans?
Q3 · Evidence & effectivenessAP-C4-Q3
Does current evidence test presence or scoped absence of Vendor assurance substitution, or does it remain unknown?
Indicators
No contract-specific reviewEnterprise-grade is used as evidenceProvider compliance is assumed to transferNo exit plan or term-change monitoring
C5 AI supply-chain integrity and change control Always applicable · HIGH · paired AP-C5 · 3+4 tactics Open criteria

AI models, datasets, libraries, tools, services and update channels have verifiable provenance, controlled baselines and risk-based change gates.

Q1 · Definition & intentC5-Q1
Are component provenance, versions, vulnerabilities, update sources and material-change triggers defined?
Q2 · Implementation & operationC5-Q2
Are integrity checks, approved update channels, testing, rollback and replacement processes implemented?
Q3 · Evidence & effectivenessC5-Q3
Does evidence show that drift, compromise, deprecation and material change are detected and reauthorized when required?
Indicators
Software/model/data bills of materialsControlled baselines and update channelsIntegrity and vulnerability checksTested rollback or replacement
AP-C5
Silent supply-chain driftAnti-pattern · HIGH · supply-chain-drift · 4 tactics

Components or dependencies change without the organization understanding or authorizing their effect on behavior and risk.

Q1 · Definition & intentAP-C5-Q1
Does the case exhibit Silent supply-chain drift: Components or dependencies change without the organization understanding or authorizing their effect on behavior and risk.
Q2 · Implementation & operationAP-C5-Q2
Do implemented workflows, data paths or operations show latest aliases in production, untested automatic updates, or silent provider behavior changes?
Q3 · Evidence & effectivenessAP-C5-Q3
Does current evidence test presence or scoped absence of Silent supply-chain drift, or does it remain unknown?
Indicators
Latest aliases in productionAutomatic updates lack regression testsProvider behavior changes silentlyNo provenance or component baseline
D
Domain D · 5 capabilities · 5 anti-patterns · 30 questions

Architecture, security, robustness & evaluation

Technical architecture, security, resilience, safety, testing and evaluation sufficiency.

D1 Secure and isolated AI architecture Always applicable · HIGH · paired AP-D1 · 3+4 tactics Open criteria

The system uses defense in depth, explicit trust boundaries and enforced identity, network, environment, tenant, secrets and data-flow controls.

Q1 · Definition & intentD1-Q1
Are assets, identities, data flows, trust boundaries, environments and external connections defined?
Q2 · Implementation & operationD1-Q2
Are authentication, authorization, network restriction, secrets isolation and tenant/environment separation enforced?
Q3 · Evidence & effectivenessD1-Q3
Do architecture review and technical tests demonstrate that stated boundaries resist unauthorized access and cross-environment movement?
Indicators
Trust-boundary architectureEnvironment-specific credentialsNetwork and identity least privilegeTenant and isolation tests
AP-D1
Implicit-trust AI architectureAnti-pattern · CRITICAL · unsafe-experiment-boundary · 4 tactics

The system relies on prompts, conventions or developer intent instead of enforceable architectural controls.

Q1 · Definition & intentAP-D1-Q1
Does the case exhibit Implicit-trust AI architecture: The system relies on prompts, conventions or developer intent instead of enforceable architectural controls.
Q2 · Implementation & operationAP-D1-Q2
Do implemented workflows, data paths or operations show shared credentials across environments, prompts used as security boundaries, or prototypes reaching production resources?
Q3 · Evidence & effectivenessAP-D1-Q3
Does current evidence test presence or scoped absence of Implicit-trust AI architecture, or does it remain unknown?
Indicators
Shared credentials across environmentsSystem prompt used as security boundaryPrototype reaches production resourcesNo tenant or architecture separation
D2 Functional quality, accuracy and reliability Always applicable · HIGH · paired AP-D2 · 3+4 tactics Open criteria

End-to-end performance is evaluated on representative tasks, users, contexts and failure modes against consequence-based acceptance thresholds.

Q1 · Definition & intentD2-Q1
Are quality attributes, representative cases, failure classes and acceptance thresholds defined for the intended context?
Q2 · Implementation & operationD2-Q2
Are evaluation, fallback, human review and release controls implemented in the delivery lifecycle?
Q3 · Evidence & effectivenessD2-Q3
Do repeated, independent where needed, end-to-end tests and operational data demonstrate acceptable performance and reliability?
Indicators
Representative evaluation setRepeated-run and subgroup analysisRisk-based thresholdsProduction performance compared with baseline
AP-D2
Demo-based quality assuranceAnti-pattern · HIGH · demo-quality · 4 tactics

Successful examples or generic model benchmarks are treated as proof of end-to-end reliability.

Q1 · Definition & intentAP-D2-Q1
Does the case exhibit Demo-based quality assurance: Successful examples or generic model benchmarks are treated as proof of end-to-end reliability.
Q2 · Implementation & operationAP-D2-Q2
Do implemented workflows, data paths or operations show happy-path-only examples, a single successful run, or average scores hiding critical failures?
Q3 · Evidence & effectivenessAP-D2-Q3
Does current evidence test presence or scoped absence of Demo-based quality assurance, or does it remain unknown?
Indicators
Only happy-path examplesSingle successful runNo domain-expert reviewAverage score hides critical failure
D3 AI-specific security and adversarial resilience Always applicable · HIGH · paired AP-D3 · 6+5 tactics Open criteria

The system identifies and controls attack paths that exploit AI models, prompts, training or retrieval data, generated outputs, tools and feedback loops, and verifies resilience through representative adversarial testing and monitoring.

Q1 · Definition & intentD3-Q1
Does a system-specific threat model cover applicable AI attack surfaces, attacker goals, assets, trust boundaries and consequences?
Q2 · Implementation & operationD3-Q2
Are enforceable controls implemented outside model discretion for untrusted inputs, retrieval, outputs, tools, data, models and privileged actions?
Q3 · Evidence & effectivenessD3-Q3
Do representative adversarial tests, regression evidence and operational monitoring demonstrate control effectiveness and expose residual limitations?
Indicators
AI-specific threat model and abuse casesDeterministic validation and authorization boundariesRepresentative adversarial regression suiteAI-security telemetry and response playbook
AP-D3
Prompt-only or model-mediated security boundaryAnti-pattern · HIGH · missing-adversarial-evaluation · 5 tactics

Security-critical restrictions depend mainly on instructions, refusals, model behavior or unverified filters instead of enforceable external controls and adversarial evidence.

Q1 · Definition & intentAP-D3-Q1
Does the case exhibit Prompt-only or model-mediated security boundary: Security-critical restrictions depend mainly on instructions, refusals, model behavior or unverified filters instead of enforceable external controls and adversarial evidence.
Q2 · Implementation & operationAP-D3-Q2
Do implemented workflows, data paths or operations show safety prompts as the principal control, model output reaching tools directly, or missing adversarial testing?
Q3 · Evidence & effectivenessAP-D3-Q3
Does current evidence test presence or scoped absence of Prompt-only or model-mediated security boundary, or does it remain unknown?
Indicators
Safety prompt is the principal controlModel output reaches tools or interpreters directlyUntrusted retrieved content can alter privileged behaviorNo representative adversarial testing
D4 Traceability, reproducibility and observability Always applicable · HIGH · paired AP-D4 · 3+4 tactics Open criteria

Material outputs and actions can be reconstructed from evidence, data, component versions, prompts, tools, validations and human decisions with sufficient operational telemetry.

Q1 · Definition & intentD4-Q1
Are required trace events, identifiers, lineage, retention and reconstruction outcomes defined?
Q2 · Implementation & operationD4-Q2
Are run manifests, evidence links, component versions, tool logs and governance events captured with integrity controls?
Q3 · Evidence & effectivenessD4-Q3
Can representative outputs, failures and decisions be reconstructed and compared across versions and time?
Indicators
Run manifest and evidence IDsModel, prompt and tool versions recordedMaterial actions loggedPrior runs can be compared
AP-D4
Opaque and non-reproducible executionAnti-pattern · HIGH · opaque-execution · 4 tactics

The organization cannot determine how a material result or action was produced.

Q1 · Definition & intentAP-D4-Q1
Does the case exhibit Opaque and non-reproducible execution: The organization cannot determine how a material result or action was produced.
Q2 · Implementation & operationAP-D4-Q2
Do implemented workflows, data paths or operations show missing run history, overwritten prompts, or evidence not linked to claims?
Q3 · Evidence & effectivenessAP-D4-Q3
Does current evidence test presence or scoped absence of Opaque and non-reproducible execution, or does it remain unknown?
Indicators
No run historyOverwritten prompts or mutable aliasesEvidence is not linked to claimsManual steps are undocumented
D5 Safety, failure handling and recovery Always applicable · HIGH · paired AP-D5 · 3+4 tactics Open criteria

Foreseeable unsafe states are constrained through fail-safe behavior, interruption, fallback, rollback, human takeover, incident response and recovery testing.

Q1 · Definition & intentD5-Q1
Are failure modes, unsafe states, recovery objectives and control-transfer conditions defined?
Q2 · Implementation & operationD5-Q2
Are fail-safe states, interruption, fallback, rollback, human takeover and incident procedures implemented?
Q3 · Evidence & effectivenessD5-Q3
Do fault-injection, recovery and operational exercises demonstrate controlled degradation and timely restoration?
Indicators
Defined fail-safe statesFallback and interruption controlsTested rollback and recoveryIncident ownership and human takeover
AP-D5
Fail-open AI operationAnti-pattern · CRITICAL · missing-failsafe · 4 tactics

When confidence, controls, components or evidence fail, the system continues without safe limitation.

Q1 · Definition & intentAP-D5-Q1
Does the case exhibit Fail-open AI operation: When confidence, controls, components or evidence fail, the system continues without safe limitation.
Q2 · Implementation & operationAP-D5-Q2
Do implemented workflows, data paths or operations show errors becoming plausible outputs, control outages bypassing validation, or undefined rollback?
Q3 · Evidence & effectivenessAP-D5-Q3
Does current evidence test presence or scoped absence of Fail-open AI operation, or does it remain unknown?
Indicators
Errors become plausible outputsControl outage bypasses validationAgent continues after tool failureRollback or manual takeover is undefined
E
Domain E · 5 capabilities · 5 anti-patterns · 30 questions

Human impact, fairness & oversight

Affected-person impact, fairness, transparency, meaningful human oversight and recourse.

E1 Human and fundamental-rights impact When people are affected · HIGH · paired AP-E1 · 3+4 tactics Open criteria

The organization evaluates direct, indirect and cumulative benefits and harms for users, non-users, affected groups and rights across the actual context.

Q1 · Definition & intentE1-Q1
Are affected persons, rights, benefit-harm pathways, severity, likelihood, reversibility and vulnerability defined?
Q2 · Implementation & operationE1-Q2
Are impact mitigations, stakeholder input, escalation and review integrated into design and operation?
Q3 · Evidence & effectivenessE1-Q3
Do evaluation and post-deployment evidence show impacts are monitored, mitigated and reassessed after change?
Indicators
Affected-person mapIndirect and vulnerable-group impactsHarm scenarios and mitigationsMaterial change triggers reassessment
AP-E1
User-only impact framingAnti-pattern · HIGH · user-only-impact · 4 tactics

The system is evaluated only from the buyer's or operator's perspective while affected non-users and rights are ignored.

Q1 · Definition & intentAP-E1-Q1
Does the case exhibit User-only impact framing: The system is evaluated only from the buyer's or operator's perspective while affected non-users and rights are ignored.
Q2 · Implementation & operationAP-E1-Q2
Do implemented workflows, data paths or operations show omitted non-users, missing vulnerable-group analysis, or rights considered only after complaint?
Q3 · Evidence & effectivenessAP-E1-Q3
Does current evidence test presence or scoped absence of User-only impact framing, or does it remain unknown?
Indicators
Affected non-users omittedEfficiency outweighs unassessed harmNo vulnerable-group analysisRights considered only after complaint
E2 Fairness and non-discrimination When people are affected · HIGH · paired AP-E2 · 3+4 tactics Open criteria

Contextual fairness objectives, relevant groups, data and decision pathways are defined, measured and governed for unacceptable disparity.

Q1 · Definition & intentE2-Q1
Are context-specific fairness objectives, relevant groups, harms, metrics and unacceptable thresholds defined?
Q2 · Implementation & operationE2-Q2
Are data, model, workflow and human-review mitigations implemented without creating new inequities?
Q3 · Evidence & effectivenessE2-Q3
Do subgroup, intersectional and operational results demonstrate acceptable disparity and effective mitigation?
Indicators
Contextual fairness objectiveSubgroup and proxy analysisValidated mitigationsUnresolved disparity is escalated
AP-E2
Aggregate-performance fairnessAnti-pattern · HIGH · aggregate-bias-blindness · 4 tactics

Overall performance or removal of explicit protected attributes is treated as proof of fairness.

Q1 · Definition & intentAP-E2-Q1
Does the case exhibit Aggregate-performance fairness: Overall performance or removal of explicit protected attributes is treated as proof of fairness.
Q2 · Implementation & operationAP-E2-Q2
Do implemented workflows, data paths or operations show missing subgroup testing, ignored proxy effects, or human override assumed to remove bias?
Q3 · Evidence & effectivenessAP-E2-Q3
Does current evidence test presence or scoped absence of Aggregate-performance fairness, or does it remain unknown?
Indicators
No subgroup testingProxy effects are ignoredSmall groups disappear from analysisHuman override is assumed to remove bias
E3 Transparency and communication When the system interacts with people · HIGH · paired AP-E3 · 3+4 tactics Open criteria

Users and affected persons receive timely, accurate and actionable information about AI use, purpose, limitations, data use, human involvement and relevant consequences.

Q1 · Definition & intentE3-Q1
Are audience-specific transparency objectives, content, timing and communication responsibilities defined?
Q2 · Implementation & operationE3-Q2
Are disclosures, labels, limitations, contact and correction routes implemented in the actual interaction and workflow?
Q3 · Evidence & effectivenessE3-Q3
Do comprehension, accessibility and consistency checks show that people can understand and act on the information?
Indicators
AI interaction is disclosed when requiredPurpose and limits are understandableHuman-review status is clearContact and challenge paths exist
AP-E3
Decorative or incomplete transparencyAnti-pattern · HIGH · missing-transparency · 4 tactics

Generic disclosures exist but do not accurately explain the system or enable informed action.

Q1 · Definition & intentAP-E3-Q1
Does the case exhibit Decorative or incomplete transparency: Generic disclosures exist but do not accurately explain the system or enable informed action.
Q2 · Implementation & operationAP-E3-Q2
Do implemented workflows, data paths or operations show vague AI-may-be-used wording, hidden or mistimed disclosure, or omitted limitations?
Q3 · Evidence & effectivenessAP-E3-Q3
Does current evidence test presence or scoped absence of Decorative or incomplete transparency, or does it remain unknown?
Indicators
Vague AI-may-be-used wordingDisclosure hidden or mistimedConsequences and limitations omittedTransparency record conflicts with operation
E4 Meaningful human oversight Always applicable · CRITICAL · paired AP-E4 · 3+4 tactics Open criteria

Competent humans have sufficient information, authority, time and technical ability to review, intervene, override and escalate at material decision points.

Q1 · Definition & intentE4-Q1
Are oversight purpose, reviewer competence, information needs, intervention points and authority defined?
Q2 · Implementation & operationE4-Q2
Can reviewers actually inspect evidence, pause, correct, override and escalate without undue friction or incentive bias?
Q3 · Evidence & effectivenessE4-Q3
Do intervention, disagreement, error and workload data demonstrate that oversight is effective rather than nominal?
Indicators
Explicit oversight pointsReviewer sees evidence and uncertaintyOverride is technically possibleEffectiveness and automation bias are monitored
AP-E4
Rubber-stamp oversightAnti-pattern · CRITICAL · rubber-stamp-oversight · 4 tactics

A human is nominally present but lacks information, capacity, authority or incentive for independent judgment.

Q1 · Definition & intentAP-E4-Q1
Does the case exhibit Rubber-stamp oversight: A human is nominally present but lacks information, capacity, authority or incentive for independent judgment.
Q2 · Implementation & operationAP-E4-Q2
Do implemented workflows, data paths or operations show review volume preventing scrutiny, AI recommendation as default, or untracked override?
Q3 · Evidence & effectivenessAP-E4-Q3
Does current evidence test presence or scoped absence of Rubber-stamp oversight, or does it remain unknown?
Indicators
Review volume prevents scrutinyAI recommendation is the defaultEvidence cannot be inspectedOverride is discouraged or untracked
E5 Contestability, correction, accessibility and AI literacy When the system interacts with people · HIGH · paired AP-E5 · 4+5 tactics Open criteria

Material outcomes can be questioned and corrected through accessible human recourse, while users, reviewers and decision-makers have role-appropriate competence.

Q1 · Definition & intentE5-Q1
Are correction, appeal, accessibility and role-specific competence requirements defined?
Q2 · Implementation & operationE5-Q2
Are timely human recourse, accessible interfaces, correction propagation and training implemented?
Q3 · Evidence & effectivenessE5-Q3
Do case outcomes, accessibility checks, competence evidence and complaint trends show that recourse works in practice?
Indicators
Appeal and correction workflowAccessible human reviewRole-specific AI competenceErrors feed into improvement
AP-E5
No practical recourse or competenceAnti-pattern · HIGH · no-recourse · 5 tactics

Outcomes are functionally final or relevant people lack the means and understanding to question them.

Q1 · Definition & intentAP-E5-Q1
Does the case exhibit No practical recourse or competence: Outcomes are functionally final or relevant people lack the means and understanding to question them.
Q2 · Implementation & operationAP-E5-Q2
Do implemented workflows, data paths or operations show no correction channel, appeals that repeat automated logic, or accessibility barriers?
Q3 · Evidence & effectivenessAP-E5-Q3
Does current evidence test presence or scoped absence of No practical recourse or competence, or does it remain unknown?
Indicators
No correction channelAppeal repeats the same automated logicAccessibility barriersTraining covers tool use but not limits and duties
F
Domain F · 5 capabilities · 5 anti-patterns · 30 questions

Accountability, evidence & lifecycle

Decision authority, evidence quality, risk decisions, monitoring, reassessment and lifecycle governance.

F1 Ownership and accountable operating model Always applicable · HIGH · paired AP-F1 · 3+1 tactics Open criteria

One accountable system owner and clearly assigned business, technical, data, model, security, privacy, operations and decision roles exercise authority throughout the lifecycle.

Q1 · Definition & intentF1-Q1
Are accountable ownership, delegated responsibilities, decision rights and continuity obligations defined?
Q2 · Implementation & operationF1-Q2
Are ownership and role assignments embedded in work queues, access, reviews, incidents and change processes?
Q3 · Evidence & effectivenessF1-Q3
Do records show that named owners act, resolve gaps and remain accountable after deployment?
Indicators
Accountable system ownerCurrent authority/RACI modelGaps and decisions have ownersOwnership persists through retirement
AP-F1
Committee accountability without individual ownershipAnti-pattern · HIGH · committee-accountability · 1 tactics

Governance bodies exist but no identifiable person is operationally accountable for the system.

Q1 · Definition & intentAP-F1-Q1
Does the case exhibit Committee accountability without individual ownership: Governance bodies exist but no identifiable person is operationally accountable for the system.
Q2 · Implementation & operationAP-F1-Q2
Do implemented workflows, data paths or operations show unowned tasks, absent business owner, or incidents exposing responsibility confusion?
Q3 · Evidence & effectivenessAP-F1-Q3
Does current evidence test presence or scoped absence of Committee accountability without individual ownership, or does it remain unknown?
Indicators
The board owns itUnresolved tasks lack ownersBusiness owner is absentIncidents expose responsibility confusion
F2 Compliance evidence and documentation integrity Always applicable · HIGH · paired AP-F2 · 3+4 tactics Open criteria

Material claims, requirements, controls and readiness conclusions are linked to current, scoped, attributable and sufficient evidence that matches implementation and operation.

Q1 · Definition & intentF2-Q1
Are required evidence types, provenance, scope, freshness, owners and validation rules defined for each material claim?
Q2 · Implementation & operationF2-Q2
Are evidence capture, versioning, integrity, expiry, contradiction and claim-linking implemented?
Q3 · Evidence & effectivenessF2-Q3
Can the decision package be reproduced and shown to reflect the current implemented and operated system?
Indicators
Requirement-to-evidence mappingDeclarations separated from observationsMissing and expired evidence visibleDecision package is reproducible
AP-F2
Compliance by assertion or document volumeAnti-pattern · CRITICAL · approval-without-evidence · 4 tactics

Documents and checkboxes create apparent assurance without demonstrating implementation or effectiveness.

Q1 · Definition & intentAP-F2-Q1
Does the case exhibit Compliance by assertion or document volume: Documents and checkboxes create apparent assurance without demonstrating implementation or effectiveness.
Q2 · Implementation & operationAP-F2-Q2
Do implemented workflows, data paths or operations show policy used as implementation proof, undated screenshots, or green status despite unresolved controls?
Q3 · Evidence & effectivenessAP-F2-Q3
Does current evidence test presence or scoped absence of Compliance by assertion or document volume, or does it remain unknown?
Indicators
Policy used as implementation proofScreenshots lack source or dateEvidence copied across systemsGreen status despite unresolved controls
F3 Risk, control and residual-risk management Always applicable · HIGH · paired AP-F3 · 3+4 tactics Open criteria

System-specific risks are linked to controls, evidence, owners, treatment criteria, residual uncertainty and authorized acceptance.

Q1 · Definition & intentF3-Q1
Are inherent risk, treatment objectives, residual risk, tolerance and acceptance authority defined?
Q2 · Implementation & operationF3-Q2
Are controls, owners, deadlines, exceptions and acceptance criteria implemented and tracked?
Q3 · Evidence & effectivenessF3-Q3
Does effectiveness evidence justify residual-risk status and any acceptance by an authorized human?
Indicators
System-specific risk registerControls linked to acceptance criteriaResidual risk and uncertainty visibleExceptions expire and acceptance is attributable
AP-F3
Risk inventory without risk controlAnti-pattern · HIGH · risk-inventory-only · 4 tactics

Risks are listed but not operationally treated, tested, reassessed or accepted by the correct authority.

Q1 · Definition & intentAP-F3-Q1
Does the case exhibit Risk inventory without risk control: Risks are listed but not operationally treated, tested, reassessed or accepted by the correct authority.
Q2 · Implementation & operationAP-F3-Q2
Do implemented workflows, data paths or operations show generic risk lists, intended-only mitigations, or expired exceptions remaining active?
Q3 · Evidence & effectivenessAP-F3-Q3
Does current evidence test presence or scoped absence of Risk inventory without risk control, or does it remain unknown?
Indicators
Generic risk listMitigation is an intentionSeverity drops without evidenceExpired exceptions remain active
F4 Decision rights, authorization and escalation Always applicable · HIGH · paired AP-F4 · 4+4 tactics Open criteria

The correct human authority makes timely, proportional and recorded lifecycle decisions, clearly separated from automated recommendations.

Q1 · Definition & intentF4-Q1
Are decision types, delegated authority, quorum, escalation, service levels, expiry and separation from AI recommendation defined?
Q2 · Implementation & operationF4-Q2
Are asynchronous review, conditions, dissent, reminders, escalation and immutable decision records implemented?
Q3 · Evidence & effectivenessF4-Q3
Do decision records show timely review by authorized people and enforcement of conditions before progression?
Indicators
Decision authority matrixAI recommendation separated from authorizationConditions and dissent are recordedMaterial change expires prior decisions
AP-F4
Calendar-driven or ambiguous governance decisionsAnti-pattern · HIGH · calendar-driven-decision · 4 tactics

Progress depends on periodic forums, silent assent or unclear authority, or automated recommendations are mistaken for approval.

Q1 · Definition & intentAP-F4-Q1
Does the case exhibit Calendar-driven or ambiguous governance decisions: Progress depends on periodic forums, silent assent or unclear authority, or automated recommendations are mistaken for approval.
Q2 · Implementation & operationAP-F4-Q2
Do implemented workflows, data paths or operations show green output treated as authorization, silence counted as approval, or untracked approval conditions?
Q3 · Evidence & effectivenessAP-F4-Q3
Does current evidence test presence or scoped absence of Calendar-driven or ambiguous governance decisions, or does it remain unknown?
Indicators
Routine decisions wait for a monthly forumGreen output is treated as authorizationSilence counts as approvalApproval conditions are not tracked
F5 Monitoring, incidents, change, re-evaluation and retirement Always applicable · HIGH · paired AP-F5 · 4+5 tactics Open criteria

Quality, risk, security, impact and compliance are monitored; incidents and material changes trigger response, reassessment, reauthorization or controlled retirement.

Q1 · Definition & intentF5-Q1
Are monitoring objectives, incident thresholds, material-change triggers, review cadence and retirement duties defined?
Q2 · Implementation & operationF5-Q2
Are telemetry, incident workflows, reassessment, rollback, decommissioning, deletion and vendor exit implemented?
Q3 · Evidence & effectivenessF5-Q3
Do operational records show timely detection, response, reauthorization and complete retirement when required?
Indicators
Monitoring spans quality and riskChange triggers are codifiedIncidents create governance actionsRetirement removes access and data while preserving decisions
AP-F5
Approval-as-end-state governanceAnti-pattern · HIGH · missing-reassessment · 5 tactics

Governance effectively stops after initial approval while operation, change and retirement remain uncontrolled.

Q1 · Definition & intentAP-F5-Q1
Does the case exhibit Approval-as-end-state governance: Governance effectively stops after initial approval while operation, change and retirement remain uncontrolled.
Q2 · Implementation & operationAP-F5-Q2
Do implemented workflows, data paths or operations show no post-deployment monitoring, model changes bypassing review, or retired systems retaining access?
Q3 · Evidence & effectivenessAP-F5-Q3
Does current evidence test presence or scoped absence of Approval-as-end-state governance, or does it remain unknown?
Indicators
No post-deployment monitoringModel changes bypass reviewIncidents are handled only technicallyRetired systems retain access, data or contracts

5. Independent claim verification, targeted rescan, adjudication & finding lock

Domain claims remain provisional. They must pass citation integrity, independent semantic verification and — when disputed — bounded re-analysis before they can become deterministic findings. Playbook retrieval consumes only this locked set.

Claims do not become facts by generation
Candidate claimIndependent verificationTargeted rescan / adjudicationLocked finding or unresolved ledger
CIT
Open logic
Local integrity

Citation & mapping validation

Rejects structurally invalid claims before an independent model is asked to judge their semantics.

Source IDsExact mappingsLocal first
Key question
Does the claim cite real source units and governed assessment objects?
Reliability control
Broken citations or knowledge mappings produce a local integrity failure rather than consuming semantic verification as a repair mechanism.
IV
Open logic
Independent verifier

Semantic evidence check

An independent reasoning route evaluates whether the cited evidence supports, conflicts with, or cannot verify each claim.

SupportedUnsupportedConflicting
Key question
Does the cited source mean what the candidate claim says it means?
Reliability control
The verifier is selected independently from the original extractor wherever the configured approved route permits. Independent-provider constraints override role preference.
Open logic
Bounded re-analysis

Targeted rescan & adjudication

Weak, contradictory or integrity-sensitive claims receive a focused second pass rather than an unrestricted rerun.

Disputed claim onlyRecheckThird perspective
Key question
Can focused re-reading resolve a disputed claim without changing the assessment scope?
Reasoning logic
Rescan the affected evidence, verify again, and invoke bounded adjudication only when the disagreement remains unresolved.
Reliability control
Provider disagreement is not decided by majority vote. High-impact unresolved disagreement remains unresolved or requires named human authority.
LOCK
Open logic
Deterministic evidence transition

Finding lock

Only decision-eligible adjudicated claims become locked findings. Gaps and unknowns are not locked findings and cannot retrieve tactics.

Evidence ceilingsAnti-pattern semanticsUnresolved ledger
Key question
Is this claim sufficiently supported, correctly mapped and assurance-bounded to influence governance decisions?
Reasoning logic
Apply evidence-state ceilings and absence-test rules, create a finding lock record, or route the claim to the unresolved ledger. This locked set is the only input to Playbook selection.
Grounding basis
Adjudicated status, exact evidence links, governed object IDs, lifecycle relevance and evidence class.
Reliability control
Missing evidence remains UNKNOWN. An anti-pattern cannot become TESTED_ABSENT without a valid scoped absence test. Thin material yields few or zero locked findings — and therefore no tactics.

6. Deterministic governance decision, hard gates & exact action permissioning

Once findings are locked, generative reasoning no longer owns the decision. Applicability, controls, anti-pattern state, hard gates, readiness dimensions and tactic eligibility are calculated from governed rules and locked evidence.

Decision authority moves to rules
Core rule: readiness scores are diagnostic. They cannot override a blocker, create residual-risk acceptance, or authorize lifecycle progression. An empty playbook means no locked finding mapped to an instrument object ID — not that tactics are absent from the catalog.
APP
Open logic
Governance applicability

Requirements & controls

Evaluates applicable requirements and controls for the confirmed lifecycle transition and evidence state across seven stages from qualification to retirement.

ApplicabilityAssurance ceilingControl gaps
Key question
What governance obligations and assurance targets apply to this exact intended use and target lifecycle stage?
Reliability control
Code/configuration cannot establish TESTED assurance; tests/scans cannot establish operational observation; evidence type sets the ceiling. Incomplete Intake enforces an Isolated Sandbox operating boundary.
GATE
Open logic
Progression control

Hard gates

Creates BLOCK / REVIEW conditions for documentation, source coverage, required human authority and incomplete cognitive assessment.

BLOCKREVIEWDeterministic
Key question
Is there any condition that forbids or constrains progression regardless of the aggregate readiness score?
Reasoning logic
Evaluate explicit rules over confirmed dossier, evidence, controls, documentation alignment, source coverage and cognitive completeness.
Reliability control
Generated narrative cannot clear or soften a hard gate.
R
Open logic
Readiness calculation

Evidence, assurance & risk dimensions

Separates evidence coverage, verified-evidence coverage, control assurance, assurance deficit and potential risk determination.

CoverageAssuranceResidual risk undetermined
Key question
What readiness recommendation does the verified deterministic evidence permit?
Reasoning logic
Calculate dimensions separately, then derive READY_FOR_NEXT_STAGE, READY_WITH_CONDITIONS, REMEDIATE_BEFORE_NEXT_STAGE, HUMAN_REVIEW_REQUIRED or BLOCKED_IN_CURRENT_FORM.
Critical note
Assurance deficit is not residual risk. Residual risk remains NOT_DETERMINED until authorized risk evaluation occurs.
TAC
Open logic
Action grounding

Exact approved tactic mapping

119 approved tactics become candidate actions only when a locked finding carries a mapped capability or anti-pattern ID from the instrument.

119 tacticsExact object IDsReassessment required
Key question
Which approved actions are actually authorized by the locked finding set?
Reasoning logic
Select tactics only when status is APPROVED and assessmentMappings intersect the finding’s assessmentObjectIds / antiPatternIds. Signal, domain, keyword and similarity matches are not mapping authority. Grounding records bind the action back to the locked findings and evidence. Every A1–F5 and AP-A1–AP-F5 ID has at least one mapped tactic.
Reliability control
Tactic completion never closes a finding automatically; new evidence and reassessment are required. Empty playbook after a thin run is the correct fail-closed result.

7. Controlled synthesis, independent fact-check & bounded re-analysis

Only after deterministic readiness exists does the Engine create decision-ready narrative. Synthesis receives locked findings, deterministic results and already-selected actions. It cannot invent tactics or rewrite scores.

Narrative after decision
SYN
Open logic
Controlled narrative

Readiness synthesis

Explains the deterministic result, evidence-backed drivers, limitations and candidate actions without recalculating readiness.

Locked inputs onlyNo score rewriteSanitized structure
Key question
How should the verified readiness package be explained to decision-makers without adding new authority?
Reasoning logic
Generate narrative from solution model, locked findings, deterministic package and already-grounded actions; then sanitize unsupported structural additions. If no actions were selected, synthesis must not fabricate a playbook.
Reliability control
If synthesis fails, the Engine retains a deterministic narrative rather than failing the entire assessment.
FC
Open logic
Independent challenge

Item-level fact-check

A separate reasoning route checks generated narrative and actions against locked findings and the deterministic package.

SupportGroundingCompleteness
Key question
Did the report introduce a statement or implication that the evidence and deterministic assessment do not support?
Reliability control
The fact-check cannot change deterministic readiness directly; it can quarantine prose, request bounded wording repair, or challenge the grounding of a specific finding.
Open logic
Evidence challenge

Claim re-adjudication

A grounding error can reopen only the affected claim, re-adjudicate it, and recompute the deterministic package from the revised finding set.

Affected finding onlyRecompute packageTrace reason
Key question
If the report reveals a real grounding defect, should the underlying finding itself be changed?
Reasoning logic
Route a specific challenged finding back through adjudication, update the finding lock if justified, then rerun deterministic assessment rather than editing the conclusion narratively.
Reliability control
Repair operates on the evidence chain; it cannot “fix” a wrong finding by merely rewriting prose.
Q
Open logic
Narrative quarantine

Bounded wording repair

Unsupported prose can be corrected once and rechecked; unresolved items are quarantined from the published narrative.

One bounded repairSecond checkQuarantine
Key question
Can the narrative be corrected without changing the underlying evidence or decision?
Reliability control
If the fact-check stage fails, generated prose is discarded and the deterministic narrative is retained with an explicit limitation.

8. Publication gate, canonical readiness package & human decision boundary

The final stage decides whether generated narrative is publishable, then returns one canonical package containing deterministic results, cognitive evidence, unresolved claims, traceability and named human decision requirements.

Publication integrity is separate from readiness
Final authority rule: REPORT_READY / REPORT_WITH_LIMITATIONS / REPORT_WITHHELD describe publication integrity only. They cannot improve readiness, accept risk, or authorize deployment.
PUB
Open logic
Publication control

Deterministic publication gate

Combines coverage, finding-lock integrity, unresolved claims, fact-check integrity, action grounding and re-analysis outcomes.

REPORT_READYWITH_LIMITATIONSWITHHELD
Key question
Is the generated narrative safe and complete enough to publish alongside the deterministic assessment?
Reliability control
A withheld report does not change the underlying deterministic package; the Engine can fall back to the deterministic narrative.
JSON
Open logic
Canonical output

ReadinessPackageV2

One hashed JSON package drives the Assessment Workspace and the Assurance Summary. HTML/PDF do not calculate a second result.

Single source of truthPackage hashNo second calculation
Key question
What complete audit object must exist so every rendered view can be reproduced from the same outcome?
Reasoning logic
Bind solution, confirmed intake, source ingestion, evidence, applicability, domains, hard gates, actions, cognitive ledgers, publication gate and trace into one hashed package.
Reliability control
HTML/PDF views render the package; they do not calculate an alternative readiness result.
TRACE
Open logic
Auditability

Model / transmission / re-analysis trace

Records packet hashes, stage events, reasoning executions, budgets, unresolved claims and recomputation history without storing credentials.

Run tracePacket hashesBudget
Key question
Can a reviewer explain how the assessment was produced and where uncertainty remained?
Reliability control
Audit evidence records actual execution; it does not treat a successful model call as proof that its content was valid.
H
Open logic
Human authority

Named decisions remain outside the Engine

Legal, privacy, security, governance, residual-risk and lifecycle approval remain attributable human acts.

Decision supportNo formal approvalNamed authority
Key question
What does the Engine recommend, and what must an authorized human still decide?
Reasoning logic
Generate explicit human-decision requirements from hard gates and applicability decisions rather than impersonating formal governance approval.
Reliability control
The Engine cannot issue legal conclusions, accept residual risk, or mark formal approval. Isolated Sandbox is an operating-boundary enum when Intake is incomplete. OCR QUALIFIED is an evidence-qualification state. Neither is a product-status label.

Assessment Workspace

Detailed intake, evidence, controls, anti-patterns, findings, diagnostics and remediation context.

Assurance Summary

Decision-ready view of recommendation, dimensions, transition boundary, gates and required human decisions.

Locked Findings

Decision-eligible claims with exact evidence. The only input that can retrieve Playbook tactics.

Grounded Actions

Approved tactics activated only by locked findings mapped to A1–F5 / AP-A1–AP-F5.

Audit Ledger

Claims, verifications, adjudications, unresolved items, publication integrity and execution trace.

Cognitive chain: raw source → derived source → candidate fact / claim → independent verification → adjudicated claim → locked finding → deterministic decision / playbook retrieval → controlled narrative → fact-check → publication gate.
Assessment chain: confirmed Intake → 30 capability / 30 anti-pattern pairs → Q1 definition · Q2 implementation · Q3 evidence → coverage matrix → finding lock → exact tactic mapping.
Interpretation boundaryThis visual is the intended cognitive/control skeleton — including the full A–F instrument
Open scope note
Use this document to check whether the thinking flow already covers every idea that should exist: six domains, thirty pairs, three evidence dimensions, verification before lock, deterministic gates, exact tactic mapping, and a human authority boundary. Lower-level prompt text, schemas and provider-specific configuration are abstracted on purpose.

Reasoning implementation

  • Structured-output stages for solution understanding, routing, A–F claims, verification, rescan, adjudication, synthesis and fact-check
  • Fixed role-based provider routing and independent-provider constraints
  • Run-level model call/token budgets, retries and execution traces
  • Multimodal derived-source handling and bounded packet transmission

Deterministic governance

  • Applicability, controls, anti-pattern state, lifecycle targets and evidence ceilings
  • Hard gates, readiness dimensions and transition recommendations
  • Exact finding-to-tactic mapping and action grounding
  • Coverage matrix, finding lock and publication-gate logic

Knowledge & authority

  • Immutable runtime collections: sources, requirements, controls, anti-patterns, tactics
  • Knowledge is criteria and action knowledge, never case evidence
  • Instrument IDs A1–F5 / AP-A1–AP-F5 are the mapping authority for tactics
  • Named human authorities retain legal, privacy, security, governance and lifecycle decisions

Designed operating constraints

  • Raw evidence stays process-local; provider packets are summaries plus approved Intake
  • Image pixels never enter provider packets
  • Missing evidence remains UNKNOWN; Isolated Sandbox is the incomplete-Intake operating boundary
  • Formal approval is a named human act, not an Engine output
Design principle: minimize free model trust. AI is used for bounded interpretation, claim extraction, verification, adjudication and explanation. Deterministic services own source lineage, applicability, evidence ceilings, finding lock, hard gates, readiness, tactic eligibility, action grounding and publication status. Humans retain formal governance authority.