Library / First Principles Framework (FPF) - Core Conceptual Specification
Jump to passage
In this reading

Link to current text

Published source confirmed at last check

Source changed 2026-10-03 10:39:28 UTC · snapshot created 2026-10-03 10:40:04 UTC · last check 2026-10-03 11:05:10 UTC

A.2.6:10 - Guard Patterns (ESG & Method–Work)

A.2.6:10.1 - Common guard shape

A claim-scope guard starts with one exact judgment:

membershipResult := evaluateMembership(TargetSlice, ClaimScope, InterpretationBasis)

Admit the scope condition only when the result is true. Stop on false. On unknown, abstain, obtain the missing input, narrow the attempted use, or apply a separately governed reliance policy. Evaluate any required freshness, formality-threshold, time-currentness and assurance conditions separately. The gate decision remains under A.21.

Add a translation branch only when the membership predicate uses exact local senses that ordinary designation resolution cannot align. Require the obtaining F.9 Bridge and the separate affirmative C.2.1 claim for this translation before deriving a scope, then require the current A.10 or B.3 reliance branch before the receiving guard relies on it. A different reference scheme or location label alone is not such a trigger.

A.2.6:10.2 - Claim-scope guard family

EG-1 - Exact membership.

member(TargetSlice, ClaimScope) = true

Name the exact claim-bearing episteme, exact U.ClaimScope, and exact target slice. The episteme, scope, and slice remain different values.

EG-2 - Formality or evidence, only when current. A receiving state may separately require a C.2.3 formality threshold or an A.10 freshness judgment.

EG-3 - Unknown evaluation. When a required selector, designation resolution, or translation input is unavailable, return unknown as the result binding of the exact evaluateMembership application, or as the result of the directly governed evaluation when no reusable application is current. Abstain or follow the exact receiving reliance policy; do not assert member = false. Add a C.2.1 result episteme only when a named receiving use needs the conclusion to persist. Use A.15.PROD only when the current claim is that dated work first constituted that episteme.

EG-4 - Translation. When exact local senses differ, require the obtaining F.9 Bridge and the separate affirmative C.2.1 claim naming this scope translation’s direction, rule, and tolerance. After the exact A.10 or B.3 branch supports reliance for that use, derive the scope with deriveTranslatedScope(SourceScope, ExactBridgeOccurrence, ExactUseClaim, TargetReferenceScheme), then use that returned scope in evaluateMembership. Scheme difference alone does not select this branch.

EG-5 - Scope-value versus declaration change. Widen or narrow only when the extension gains or loses at least one independently identified slice; that extension change identifies another U.ClaimScope. A changed predicate expression with the same exact extension is a refit: it preserves the exact scope value and may require another scope declaration or claim-bearing episteme edition under its direct governor. A result-record, table, or selected-structure change alone changes neither the scope value nor its declaration.

A.2.6:10.3 - Method–Work guard families (capabilities)

WG‑1 - WorkScopeCoverage (mandatory). Reliance on a holder-ability claim for a Work step requires coverage by the WorkScope that claim designates:

WorkScope(holderAbilityClaim) covers JobSlice

WG‑2 - work-measure target set satisfied (mandatory for deliverables). Guards MUST compare the claimed attained bounds with the quantitative targets required for the JobSlice:

SLO and target measures satisfied (latency ≤ L, throughput ≥ T, tolerance ≤ ε, … )

WG‑3 - qualification-window policy holds (mandatory for operational use). Operational guards MUST assert that the exact qualification-window predicate (qualification, inspection, or recertification) holds at the receiving guard’s exact evaluation time:

qualificationWindowHolds(holderAbilityClaim, qualificationWindowPolicy, evaluationTime) = true

WG-4 - Translation branch for capability use.

Translate U.WorkScope only when its condition predicates use exact local senses that differ from those needed by the job slice. Require the obtaining F.9 Bridge and a separate affirmative C.2.1 claim naming this Work-scope translation’s direction, rule, and tolerance; establish the exact A.10 or B.3 reliance branch before the capability guard uses the result. Neither the holder-ability claim nor the job slice supplies a hidden .Context field that automatically selects this branch.

Observed mapping loss is evidence about the use claim, and permitted loss is its tolerance. If the claim’s rule and tolerance permit translation only for part of the source Work scope, identify that part and return its target image.

WG‑5 - Δ(WorkScope). When widening Work scope (new operating ranges/platforms), the guard MUST require evidence at the new slices (measures + qualification windows). A membership-preserving refit does not itself require new deliverability evidence for the unchanged slices.

A.2.6:10.4 - Translation guard

Use this branch only after the exact local-sense translation need, the obtaining F.9 Bridge, and the separate affirmative C.2.1 claim for this translation are current. The claim names the source-to-receiving direction, scope-correspondence rule, and tolerated loss. Before the receiving guard relies on it, require the exact passing A.10 branch or, when an actual named assurance claim is current, a B.3 AssuranceResult that carries the same bounded use with disposition=supported-for-use.

translatedScope := deriveTranslatedScope(SourceScope, ExactBridgeOccurrence, ExactUseClaim, TargetReferenceScheme)
membershipResult := evaluateMembership(TargetSlice, translatedScope, InterpretationBasis)

The source claim-bearing episteme designates SourceScope. The Bridge relates exact local senses under F.9. The C.2.1 claim supplies this translation’s rule and tolerance, and A.10 or B.3 supplies the separate reliance basis. An unmapped slice yields unknown for the attempted evaluation unless the returned scope explicitly excludes it; it is not silently dropped and reported as false.

A.2.6:10.5 - Time selector

When membership depends on time, name an exact gammaTime point, interval, or policy and the boundary that changes membership. Keep every selector already declared in the slice schema, even when this predicate does not inspect it. If a work qualification or evidence-freshness condition varies with time, name its exact evaluation time and interval or policy under that condition’s direct governor rather than copying it into scope. For example, qualificationWindowHolds(holderAbilityClaim, Recertification90d, evaluationTime) is a separate guard; it is not a scope selector.

Do not write implicit “latest.” Do not invent a time selector merely to complete a new slice declaration.