A.19.SelectorMechanism:5.2 - Show, U.System example
Scenario. A platform team must pick a set of deployment options for a subsystem under multiple criteria: latency, cost, and regulatory risk. Comparisons are multi-criteria and do not induce a total order.
-
CandidateSetSlot = {OptionA, OptionB, OptionC}. -
CriteriaSlotrequires Pareto selection over the three unordered pairs{A,B},{A,C}, and{B,C}, returns all non-dominated admissible candidates, and preserves the full selected set unless an explicit current criterion requires a singleton. -
The finite upstream comparison-application basis covers all three required pairs:
- exact
Compare(OptionA, OptionB, ...)hasGuardDecision = pass: OptionB is strictly better than OptionA on latency, while OptionA is strictly better than OptionB on cost under the declared comparator. ItsComparisonResultSlotrecords those strict opposite wins, so neither dominates the other; - exact
Compare(OptionA, OptionC, ...)hasGuardDecision = degradebecause OptionC lacks the required risk attestation, and its output binding contributes no relation token about OptionC; and - exact
Compare(OptionB, OptionC, ...)has the same explicitdegradebasis and likewise contributes no relation token about OptionC.
The Selector’s
ComparisonResultSlotargument is exactly the union of those justified member outputs, so its two tokens both trace to the{A,B}CPM application. No equality, worse-than, orabstaintoken is fabricated for OptionC. - exact
-
MinimalEvidenceSlot?is absent, so evidence is evaluated againstCGSpecSlot.MinimalEvidence. -
The actual selection binds the three exact CPM applications and their pair, eligibility, and output bindings; the required-pair coverage and token trace; the deployment-option claim scope and selected regulatory
U.ContextSlicemembers; the same predicate basis or explicitnone; the reference plane and evaluation interval; and adegradepolicy that permits exclusion of OptionC.
Outcome.
- Under that explicitly bound
degradepolicy,SelectEligibilityreturnsdegrade, excludes OptionC without coercing unknown evidence, andSelectionSlotreturns{OptionA, OptionB}. - If either required comparison involving OptionC instead had
GuardDecision = abstain, that basis member would have no output binding,SelectEligibilitywould returnabstain, and no selected-set value would be created. Neither guard value is a member ofComparisonResultSlotorSelectionSlot. - The dated selection
U.Work, actualSelectapplication, finite CPM application basis, evidence-policy andSelectionSlotbindings, and A.10 evidence-provenance path preserve why the reduced-set branch proceeded and why the abstain branch did not.