Library / Method Engineering Principles Framework
Jump to passage
In this reading

Link to current text

Published source confirmed at last check

Source changed 2026-10-03 02:22:15 UTC · snapshot created 2026-10-03 03:38:22 UTC · last check 2026-10-03 04:30:10 UTC

ME.3:5 - Archetypal Grounding — EC-417 Situational Criteria

The situation family is a safety-relevant controller change combining firmware and supplier-originated harness geometry under a fixed release calendar. The intended Work produces one released change with traceable affected requirements, implementation revisions, verification results, evidence status, and human release authority. Some cases have signed supplier evidence before integration; others have only versioned provisional evidence until later. AI support may suggest trace links but may not receive confidential geometry or decide release.

Three views describe the same release Work. The project view exposes dates, allocations, and authority; the process view exposes recurring supplier-evidence, integration, verification, and release-result correspondences; the case view exposes how new evidence changes the next decision for one release. These views help find criteria. They create neither additional Work nor a Method.

Required Method contributions are stated without selecting an architecture: produce the affected hardware verification result; integrate the implementation against an explicitly versioned evidence state; produce signed supplier approval or an explicit missing-approval stop; and return release, withhold, or next-slot authorization under named human authority. Evidence reconciliation and trace review are additional candidate contributions, not pre-admitted Methods.

The alternative labels refer to the timing and capacity comparison in ME.6 §5.3. In A, the team waits for signed supplier evidence before integrating the software. In B2, it integrates from a versioned provisional edition and reconciles it with signed evidence before safety closure. Most preparation of the changes between those editions goes to the supplier-configuration role, keeping the safety engineer within the peak limit. A is a choice before integration; recovery R applies when closure fails after B2 integration.

The case admits three human Systems and keeps their decision Work, assignments, permissions, authority, and results explicit:

Admitted human SystemPerformed decision Work and resultCovering Work assignmentIndependently obtaining permission or direct decision-authority relation
TraceReviewer-17named W-TraceAcceptReject-17 occurrences issue one accept/reject result for each AI trace suggestionASG-TraceReview-17 covers that Work for EC-417 from D-21 through D0PERM-TraceAcceptReject-17 permits subject TraceReviewer-17 to accept or reject EC-417 AI trace suggestions in that window, on the basis of TraceReviewCharter-17; reliance requires a current matching entry in DecisionRightsRegister-17 and the linked human-decision record
SafetyReviewer-17W-SafetyEvidenceDecision-17 issues accept/reject of the evidence conditions for B2 entry, safety closure, or recoveryASG-SafetyReview-17 covers that Work from D-21 through the next authorized slotAUTH-SafetyEvidence-17 is the direct decision-authority relation for subject SafetyReviewer-17, that evidence-decision scope, and that window, on the basis of SafetyDecisionCharter-17; reliance requires a current matching DecisionRightsRegister-17 entry and linked safety-decision record
ReleaseDecider-17W-ReleaseDecision-17 issues the branch-entry and release, withhold, or next-slot decision resultsASG-ReleaseDecision-17 covers that Work from the D-21 checkpoint through the next authorized slotAUTH-ReleaseDecision-17 is the direct decision-authority relation for subject ReleaseDecider-17, selection of A or authorization of at most three B2 trials and the named release disposition, and that window, on the basis of ReleaseDecisionCharter-17; reliance requires a current matching DecisionRightsRegister-17 entry and linked release-decision record

Assignments, permission relations, and authority relations each need their own basis. Each performed Work occurrence and decision result also needs its own record; none is established by an assignment, permission, or authority relation alone. Responsibility, access, capability, assignment, permission, authority, performed Work, and decision result therefore remain separately testable. The AI provider is a separate System and is holder or subject of none of these assignments or relations.

CriterionActual subject and decision levelRequirement, variation, and boundEvidence needed and truthful stop
SC-TRACE-01EC-417 receiving result and its requirement/implementation/verification correspondenceevery affected safety requirement links to one or more named current implementation revisions and one or more named verification results; every correspondence link remains inspectable, while representation format may varyversioned trace record; an affected requirement with no current implementation-revision link or no verification-result link is failed and stops safety closure
SC-CONF-01supplier-geometry information and AI-provider access relationconfidential supplier geometry stays outside the AI provider; using no AI is allowableaccess configuration and handling record; any provider exposure is failed and stops the AI-supported route
SC-ASSIGN-01the three admitted human Systems, their decision Work, and ASG-TraceReview-17, ASG-SafetyReview-17, and ASG-ReleaseDecision-17every performed decision-Work occurrence has a named System that matches the holder, Work scope, and window of its covering assignmentassignment and Work records; a missing assignment, holder mismatch, uncovered Work, or out-of-window occurrence is failed without erasing the Work occurrence
SC-AUTH-01PERM-TraceAcceptReject-17, AUTH-SafetyEvidence-17, AUTH-ReleaseDecision-17, and the governed decision resultsevery AI suggestion receives TraceReviewer-17 accept/reject within the permission scope; safety and release decisions remain within their named subjects, scopes, windows, and bases; the AI provider has no release authoritycurrent matching DecisionRightsRegister-17 entries plus linked human, safety, and release decision records; missing permission or authority, an unnamed result, an out-of-scope decision, or authority delegated to the AI provider is failed
SC-EVID-01provisional and signed hardware-evidence inputs, their relation, and the safety-closure guardprovisional evidence may be used before closure only with explicit edition and uncertainty; signed evidence supersedes it for safety-closure reliance, while the provisional edition, uncertainty, earlier Work use, and relation to the later signed evidence remain traceableversion/uncertainty fields, earlier-use record, signed supplier evidence, and inspectable provisional-to-signed relation; missing signed evidence at closure stops release
SC-REV-01integration Work and the implementation staterollback remains possible within one hour until D-1; the project may choose a signed-first or provisional-first branch before entryreplayable rollback demonstration for the current toolchain; inability to restore within one hour is failed for an early-integration route
SC-CAP-01hardware-verification and safety-evidence capabilities of the named performershardware verification and safety evidence judgment require current capability for the named controller, rig, and safety scope; capability grants neither assignment, permission, nor release authoritycurrent capability evidence for each named performer; the separate assignment, permission, and decision-authority conditions must also hold, and missing capability stops the contribution that needs it
SC-TECH-01PLM/CI support, pinout schema, test-rig access, and their relations to Workthe evidence version used by integration remains recoverable; required verification has a named rig/access route; equivalent tools are allowed when they preserve the same result and evidence conditionsconfiguration, schema-edition, and access records; an unknown input edition or unavailable verification route is unknown and blocks reliance
SC-BURDEN-01safety-engineer allocation on the peak safety daysafety demand stays at or below 0.40 of an eight-hour day (3.20 h); burden shifted to another performer remains visible rather than disappearingallocation and time estimate for the selected day; demand above 0.40 is failed for the proposed structure, not proof that any one Method is unfit
SC-BOARD-01each joint-board Work occurrenceeach board lasts at most 45 minutes; one or two boards are allowable when the evidence and burden criteria remain satisfiedcalendar and actual-duration record; a planned board above 45 minutes fails the coordination-burden criterion
SC-STOP-01W-ReleaseDecision-17, its covering assignment, AUTH-ReleaseDecision-17, and the receiving resultno release occurs without signed evidence, required verification, a covering assignment, and the direct release-decision authority relation; delay to a later authorized slot is allowablerelease record citing evidence, assignment, authority relation, and decision result; any missing non-negotiable yields withhold or next-slot, not silent waiver

The criteria leave serious alternatives open. A signed-first alternative may wait for supplier evidence; a provisional-first alternative may integrate earlier and reconcile later; preparation may sit with the safety engineer or with the supplier-configuration role. ME.3 does not choose among them. A later individual qualification may apply contribution, capability, access, and evidence criteria to each identified Method or candidate account. A later architecture comparison must inspect combined peak demand, timing, covering assignments, permission and decision-authority relations, provider access, and burden transfer. Passing one row or staying below 0.40 does not establish fit of the whole proposed structure.

The criteria set is adequate for its next use when every non-negotiable row has an observable test, the remaining variations are explicit, and unknowns are routed to their actual subject. It stops the current route immediately on missing signed evidence at closure, confidential geometry exposure, a missing or mismatched covering assignment, permission, or direct decision-authority relation, unavailable required capability or verification route, rollback beyond one hour for an early-integration proposal, peak safety demand above 0.40, or a joint board above 45 minutes. Reopen when the change class, supplier information boundary, evidence timing, toolchain, performer assignment, release authority, capacity window, or receiving-result acceptance rule changes.

ME.3:5.1 - Retain Approval and Question a Duplicate Trace Record

Consider two disputed requirements in the same release situation. The supplier’s signed approval establishes which pinout the supplier endorses; the provisional file alone leaves a material possibility of implementing an unendorsed connection. That protective contribution supports retaining the approval condition for release. A cheaper trace procedure does not supply the missing supplier decision, and the present release authority still withholds release when the required approval is absent.

The other requirement is a second manual copy of every trace link. In this constructed case, the versioned authoritative trace already exposes the same links and failed correspondences to the review, and the duplicate copy adds no check or independent information. Producing it consumes time needed to inspect a changed safety requirement. On those supplied facts, the criteria author can finish with a recommendation to remove the duplicate-copy obligation while preserving the trace and review that detect the actual defect. A different case in which the second check detects a consequential omission can support retention.

The recommendation names the governing trace-record rule and the authority needed to amend it. It does not treat the release decider’s authority as authority to change that rule. If timely amendment is unavailable, the current rule remains in force and the release arrangement must use a permissible continuation or a later slot. The present recommendation and its limit are complete; a new experiment is selected only if an obtainable result could change the appraisal enough to warrant its full burden.