C.30.LCA:4.0a - Safety-loss control-structure note
Use a SafetyLossControlStructureNote only when safety wording is being used for a loss-control claim and the practitioner first needs the architecture-side loss-control structure, not a safety-case verdict:
SafetyLossControlStructureNote:
lossOrHarm:
hazardOrUnsafeState:
unsafeControlActionOrMissingControl:
controlledProcessOrPlantRef:
controlConstraintRef:
feedbackOrObservabilityBoundary:
timingOrRateBoundary:
operationalDesignScopeOrMisuseScope:
foreseeableMisuseRefs?:
architectureStructureKindRefs:
ControlStructure | ConstraintRequirementStructure |
SecurityTrustBoundaryStructure | InformationDataStructure |
EvidenceAssuranceStructure
claimPatternUseRefs:
A.3.3 dynamics, C.27.TA temporal aspect or rate, and C.27 authored temporal-claim adequacy,
C.28 causal-use, A.10 bounded source-to-use reliance, G.6 citable provenance paths,
B.3 named assurance, A.20 internal-constraint validity, A.21 gate decisions
nonAdmissibleUse:
not safety proof, not safety-case verdict, not regulatory acceptance
The note gives a positive safety-triggered architecture move: find the loss-control structure, controlled process or plant, constraint, foreseeable misuse, operational design scope, and action-relevant boundary. It does not replace the generic control-structure view and does not replace evidence, assurance, gate, causal, dynamics, or temporal claims.
Control-participant interpretation.
| Source label | FPF recovery |
|---|---|
| Plant or controlled holon | U.Holon whose state evolves; reusable state-evolution claims use A.3.3. |
| Regulator or controller | Recover the regulation or control relation and its participant meaning. If control Work is claimed, recover the exact performer System through A.13 and admit the Work independently through A.15.1 with its enacted Method. Add an assignment occurrence and F.6 only when the control account expressly consumes precise assignment-bound attribution. Add local classification only when relied on; assignment supplies none. |
| Planner | Recover the exact reference-provision, planning, or other direct relation. A planning System and planning Work are separate; for a plan, authority, or allowed-region result, use its own pattern. |
| Observer or estimator | Recover the observation or estimation relation and participant meaning. If observation or estimation Work occurred, recover the exact performer System through A.13 and admit the dated Work and enacted Method independently through A.15.1. Add assignment and F.6 only when precise assignment-bound attribution is expressly consumed; a reading or evidence result remains separate. |
| Supervisor | Recover the exact supervision or B.2.5 supervisor-subholon relation. Use separate patterns for any constraining Work, policy change, authority, responsibility, gate, or control-mode change. |
Control-specific stratification gate. Layer, level, tier, and stack enter C.30.LCA only after C.30.STRAT or the local sentence recovers a direct control relation, inter-layer control relation, rate band, or B.2.5 supervisor-subholon relation. An assignment alone is insufficient, and the label by itself establishes neither control structure nor separation.
B.2.5 boundary. Use B.2.5 for the compound supervisor-subholon feedback assertion. The description cites its observation and returned-influence base relations in feedbackRelationRefs and the assertion in feedbackClaimRefs; it does not coerce an episteme into U.Relation. Keep the coupling rule and facts recoverable from the assertion. Use the relevant patterns for stability, safety, causality, evidence, gate and assurance claims. If action involving an episteme is claimed, recover the exact performing System through A.13 and admit the dated Work and enacted Method independently through A.15.1. Add an assignment occurrence and F.6 only when the account expressly consumes precise assignment-bound attribution; keep publication, source-to-use, and work-reliance relations separate.
Transformation-flow boundary. An E.18 transformation-flow path slice may supply flow-structure, path, crossing, or transformation-flow-structure input to the control view when that relation is being used. The transformation-flow description may use a mathematical graph expression under E.18.2; the description is a U.View only when E.17.0 conformance obtains. Neither the expression nor the description becomes the functional architecture, the control structure, or proof of control adequacy.
C.29 boundary. An LCA can be a model used for one selected control structure, or it can be used as a transferable mathematical lens. Use C.29 when a mathematical lens makes transfer, prediction, reusable cross-domain explanation, or another control-structure use more inspectable. Dynamics, rate bands, authored temporal-claim adequacy, and causal claims remain with A.3.3, C.27.TA, C.27, and C.28.
Nesting and scale rule. If a control-structure view nests without a local depth limit, the record uses scaleAuditRef? when the nesting affects latency, stability, observability, accountability, or assurance.
Worked slice A - LCA diagram used as proof. A safety note says: The Layered Control Architecture proves the plant is safe because the supervisor monitors the lower controller. A conforming repair keeps the control-structure view and names planner, controller, plant, and supervisor relations, observation and actuation boundaries, and any rate bands. Use the applicable safety pattern for the safety claim, B.3 only for a named assurance claim, A.10 for bounded source-to-use reliance, G.6 for citable provenance paths, C.27.TA for temporal aspects and rate bands, C.27 for authored temporal-claim adequacy, and A.3.3 or the applicable dynamics pattern for dynamics or stability.
Worked slice B - multi-rate controller. A source says a control stack has a slow planner, a faster regulator, and an observer with a different update period. Apply C.30.LCA only after the stack label has been recovered as exact reference-provision, regulation, observation, or other control relations with their participant meanings and rate bands; otherwise use C.30.STRAT first. Systems, classifications, assignments, Methods, and Work are added only where independently current. A C.30.LCA description establishes no rate adequacy. If the rate relation matters for oscillation, latency, stability, or safety, next use C.27.TA for temporal aspect or rate-band structure, C.27 when an authored temporal-claim adequacy question is under repair, and the dynamics or assurance pattern named by value when that claim kind is being made.
Worked slice C - supervisor-subholon loop. A subsystem is supervised by an external controller System. The C.30.LCA note cites the observation and returned-influence relations together with B.2.5’s compound assertion and its coupling basis. If that System performs mode-change Work, recover it through A.13 and admit the Work and enacted Method independently through A.15.1. Add an assignment occurrence and F.6 only when this slice also expressly represents precise assignment-bound attribution; missing or failed F.6 leaves the mode-change Work intact. Authority, responsibility, gate passage, safety, stability, and policy-constraint results remain separate claims under their own patterns; the supervisor relation establishes none of them.
Currentness and smallest reopen. When a decisive input changes, reopen only the control-structure locus and the use conclusions that depend on it. A changed selected control structure or controlled holon reopens the affected ControlStructureViewNote or full description and view; a changed direct control relation or participant meaning reopens that occurrence and its dependent structure selection; a changed classification, assignment, Method, Work, or F.6 attribution reopens only that neighboring fact and any view use that relied on it. A changed B.2.5 coupling rule, supervised set or report/return fact reopens the affected pair and interval assertion, its cited base relations where changed, and dependent structure uses. A communication break need not end an assignment; reconnection requires new supporting facts. Changed rate or control-layer relations reopen only their matching relation or boundary fields; changed view conformance reopens only the E.17.0 admission; and a changed source edition reopens its source-to-use and source-return locus. A changed authority, responsibility, safety, proof, evidence, assurance, or gate claim reopens only that neighboring claim unless a control-structure input also changed. Update the affected locus, demote full view use to a note or orientation, narrow use, or reopen the control-structure question; unrelated structures and claims stay closed.