5. Build the repertoire and criteria without preselecting an architecture
ME.2 returns an inspectable repertoire for the relation comparison:
| Subject | Exact current inputs for this replay | Source use | Limit |
|---|---|---|---|
M-HW-Verify | A.3.1 identity result IDR-HW-Verify-17; description edition MD-HW-Verify-4.2; evidence window EW-HW-Verify-EC397-416 covering EC-397 through EC-416; established input/result relation IR-HW-Verify-17 | accepts the named harness/pinout edition and returns VR-EC417-H17 | no established family or Method-lineage relation follows from co-listing |
M-SW-Integrate | A.3.1 identity result IDR-SW-Integrate-17; description edition MD-SW-Integrate-4.8; evidence window EW-SW-Integrate-EC397-416 covering EC-397 through EC-416; established input/result relation IR-SW-Integrate-17 | consumes the named firmware, harness, and evidence edition and returns an integration record that preserves edition, uncertainty, and use | no evidence-reconciliation or whole-Method identity follows |
M-Supplier-Approve | A.3.1 identity result IDR-Supplier-Approve-17; description edition MD-Supplier-Approve-H17.3; evidence window EW-Supplier-Approve-12 covering the twelve preceding supplier-originated releases; established input/result relation IR-Supplier-Approve-17 | consumes the supplier revision and evidence bundle and returns signed approval or the explicit missing-approval stop | supplier transfer beyond the named source window remains open |
M-Release-Authorize | A.3.1 identity result IDR-Release-Authorize-17; description edition MD-Release-Authorize-2026Q3; evidence window EW-Release-Authorize-20 covering the named twenty releases; established input/result relation IR-Release-Authorize-17 | consumes the named evidence, verification, assignment, and authority results and returns release, withhold, or next-slot authorization | it does not perform the safety-evidence decision or create release authority |
C-Evidence-Reconcile-Internal | candidate-account edition CA-ER-Internal-1; source window EW-ER-Internal-8 covering four firmware-only and four internal harness-plus-firmware releases | derived from those eight internal cases and their artifacts | Method identity and supplier transfer remain open |
C-Evidence-Reconcile-Supplier | candidate-account edition CA-ER-Supplier-1; source window EW-ER-Supplier-4+1 covering four supplier cases plus the held-out thirteenth case | derived from that bounded source set | Method identity, population scope, and relation to the internal account remain open |
C-AI-Trace-Review | candidate-account edition CA-AI-Trace-Review-1; exact source contents ATP-2, HDR-TraceAcceptReject-17, and RES-TraceAcceptReject-17 | ATP-2 contributes prompt-and-guard description content; HDR-TraceAcceptReject-17 documents the one dated human Work occurrence in this filled case, W-TraceAcceptReject-17-01, and identifies its distinct exercise-evidence carrier EV-PEX-TraceAcceptReject-17-01; RES-TraceAcceptReject-17 records its result RES-TraceAcceptReject-17-01; the AI provider and its input suggestion remain separate Systems/content | no autonomous authority, effectiveness, transfer, Method identity, family, causation, superiority, applicability, or composition claim |
The four Methods alone remain in local comparison locator LG-EC417-ReleaseMethods; the three accounts are adjacent repertoire entries with preserved statuses. The values in the table are pinned for reliance from D-21 through D0. For an identified Method, rely on its current A.3.1 identity result, description edition, evidence window, and only each established relation needed by the use. For a candidate account, rely on its current account edition, named source contents or source window, preserved status and limits, and only already-established relations needed by the use; missing Method identity or a generic input/result relation remains an open limit, not a required field. If a required value is absent or has changed, stop repertoire reliance and reopen only that ME.2 entry.
At D0 this application’s reliance window ends. It supplies no post-D0 recovery plan, Work, or results establishing the conditions for later recovery.
For later non-AI recovery, create a new A.15.2 WorkPlan when coordination needs one; a plan is not a prerequisite for every valid Work occurrence. Whether planned or unplanned, the later action needs its applicable independent ME.2 qualification/currentness, readiness, assignment, and permission/authority results. A WorkPlan describes possible Work and establishes none of those results or an A.15.1 dated occurrence. Absence of a plan alone neither establishes nor prohibits later Work.
This application ends with withhold/next-slot. C-EC-Release-v2 stays outside the membership table as a proposed-whole architecture subject; missing family, Method-lineage, account-identity, and AI-transfer bases block only the claims that require them.
ME.3 states candidate-neutral contributions and locates every condition with its actual subject. The case separately names the Systems, performed decision Work and results, covering assignments, and independently obtaining permission or direct decision-authority relations:
| Human System and performed decision Work | Covering assignment | Permission or direct decision-authority relation |
|---|---|---|
TraceReviewer-17; bounded set W-TraceAcceptReject-17 returns accept/reject for each AI suggestion actually used; this filled case contains W-TraceAcceptReject-17-01 | ASG-TraceReview-17, D-21 through D0 | exact grant occurrence PERM-TraceAcceptReject-17 and its currentness result CUR-PERM-TraceAcceptReject-17-D21-D0; the register entry is evidence, and the dated Work-to-grant exercise is a separate relation |
SafetyReviewer-17; W-SafetyEvidenceDecision-17 returns accept/reject for B2 entry, closure, or recovery evidence | ASG-SafetyReview-17, D-21 through the next authorized slot | AUTH-SafetyEvidence-17: subject SafetyReviewer-17, named evidence-decision scope and that window, basis SafetyDecisionCharter-17; reliance needs the matching register entry and linked safety-decision record |
ReleaseDecider-17; W-ReleaseDecision-17 returns branch-entry and release/withhold/next-slot decisions | ASG-ReleaseDecision-17, D-21 through the next authorized slot | AUTH-ReleaseDecision-17: subject ReleaseDecider-17, selection of A or at most three B2 trials and the release disposition in that window, basis ReleaseDecisionCharter-17; reliance needs the matching register entry and linked release-decision record |
The baseline B2 branch relies on one filled A.2.8.PER grant occurrence rather than inferring permission from a charter or register:
| Grant field | Filled case value |
|---|---|
| relation and beneficiary participant | PERM-TraceAcceptReject-17 : GrantedPermissionRelation@Context; PermissionBeneficiarySlot selects beneficiarySystemRoleAssignmentRef=ASG-TraceReview-17. TraceReviewAssignment is declared as a U.SystemRoleAssignment species; occurrence ASG-TraceReview-17 has admitted System TraceReviewer-17 as holder, HumanTraceReviewer as assigned kind, and covers W-TraceAcceptReject-17-01 within D-21 through D0. |
| permitted-action participant | PermittedActionSpecificationSlot=ACT-TraceAcceptReject-EC417-e1: inspect one non-confidential provider-generated requirement-to-test-link suggestion for EC-417 and return accept or reject. It grants no safety-closure or release decision. |
| instituting act and grantor assignment | At D-22 16:00, admitted System EngineeringAssuranceLead-17 performs speech act SA-GrantTraceAcceptReject-17 under ASG-TracePermissionGrantor-17 : TracePermissionGrantorAssignment, a declared U.SystemRoleAssignment species whose holder is that System and whose assigned kind is TracePermissionGrantor; the act records institutes.permissions=PERM-TraceAcceptReject-17. The assignment grounds the holder and kind but neither acts nor supplies decision authority by form. |
| policy, scope, and window | grantValidityPolicyRef=TraceReviewCharter-17-e1; its predicate admits the exact grantor assignment and speech act for scope=CS-EC417-AITraceSuggestions. validityWindow=D-21 00:00..D0 23:59; the policy is not single-use. |
| currentness and ending | CUR-PERM-TraceAcceptReject-17-D21-D0 checks the exact participants, instituting act, grantor assignment, policy edition, ClaimScope, and window and records no revocation or supersession at each EC-417 trace-decision checkpoint through D0. DRE-TraceAcceptReject-17-e1 in DecisionRightsRegister-17 carries evidence for that result; it neither institutes nor equals the grant. revocationOrSupersessionRef=absent; the occurrence expires at D0 and has no carry-forward. |
The occurrence identity is the tuple SA-GrantTraceAcceptReject-17, beneficiary assignment ref ASG-TraceReview-17, action-specification edition ACT-TraceAcceptReject-EC417-e1, policy edition TraceReviewCharter-17-e1, ClaimScope CS-EC417-AITraceSuggestions, and the D-21..D0 effective interval. A change in any member ends or splits the occurrence.
Only one provider suggestion is used in the filled case: AI-TraceSuggestion-EC417-01. At D-21 10:00..10:20, admitted System TraceReviewer-17 performs W-TraceAcceptReject-17-01 under ASG-TraceReview-17; the Work instantiates ACT-TraceAcceptReject-EC417-e1 within the grant scope and returns RES-TraceAcceptReject-17-01=accept. PEX-TraceAcceptReject-17-01 : PermissionExerciseRelation@Context connects that dated Work to the exact PERM-TraceAcceptReject-17 occurrence, with beneficiarySystemRoleAssignmentRef=ASG-TraceReview-17, exerciseScope=CS-EC417-AITraceSuggestions, and exerciseInterval=D-21 10:00..10:20. EV-PEX-TraceAcceptReject-17-01 is the ledger evidence about this exercise and remains distinct from the exercise relation. No second suggestion, Work result, or exercise is asserted; every later used suggestion would require its own dated Work, result, currentness check, and Work-to-grant exercise relation.
Assignment, permission/authority relation, performed Work, and decision result imply none of one another. Capability, responsibility, access, currentness, readiness, and evidence remain separate as well. The AI provider holds none of the human assignments or relations. ASG-TraceReview-17 and PERM-TraceAcceptReject-17 end at D0; continuing safety or release assignments and authority extend neither trace relation. For this worked application, after D0 no new AI suggestion is requested, accepted, or used, and no later trace-review assignment, permission, Work, result, or exercise is claimed. Every earlier trace-review occurrence and result remains in the evidence history.
| Criterion | Actual subject and bound | Evidence or stop |
|---|---|---|
| trace correspondence | released result: each affected safety requirement links to one or more named current implementation revisions and one or more named verification results; every correspondence link is inspectable | versioned trace record; absence of either required link kind stops safety closure |
| confidentiality | supplier geometry and AI-provider access relation | geometry remains outside the provider; any exposure stops the AI-supported route |
| decision-Work assignments | the three admitted human Systems and their three baseline ASG-* occurrences | every performed occurrence matches its covering assignment’s holder, Work scope, and window; missing or mismatched assignment fails without erasing the Work |
| permission and decision authority | PERM-TraceAcceptReject-17, AUTH-SafetyEvidence-17, AUTH-ReleaseDecision-17, and their governed results | APP section 5 records the grant participants and grounds once; CUR-PERM-TraceAcceptReject-17-D21-D0 supports pre-Work currentness, PEX-TraceAcceptReject-17-01 relates dated Work to that grant, and EV-PEX-TraceAcceptReject-17-01 remains evidence about the exercise; missing, out-of-scope, circularly supported, or AI-provider authority fails |
| evidence state | provisional/signed evidence inputs, their relation, and safety-closure guard | signed evidence supersedes the explicit provisional edition only for safety-closure reliance; provisional uncertainty, earlier Work use, and the provisional-to-signed relation remain traceable; missing signed evidence stops closure |
| reversibility | integration Work and implementation state | rollback within one hour until D-1; failure stops an early-integration route |
| capability/support | named hardware/safety capabilities, PLM/CI edition recovery, pinout schema, and rig access | missing capability, unknown input edition, or unavailable verification route blocks the contribution that relies on it |
| peak burden | safety-engineer allocation on the selected peak day | at most 0.40 of an eight-hour day, or 3.20 h; transferred burden remains visible |
| board burden | each joint-board Work occurrence | at most 45 minutes per board |
| release stop | W-ReleaseDecision-17, ASG-ReleaseDecision-17, AUTH-ReleaseDecision-17, and receiving result | missing signed evidence, required verification, covering assignment, or direct authority relation yields withhold or next-slot, never silent waiver |
These criteria admit no Method and select no alternative. Signed-first, provisional-first, supplier-preparation, and safety-preparation variants remain serious possibilities.