6. Recover package contributions and qualify individual subjects
The incumbent “release methodology” mixes unlike material. ME.4 returns open navigation sections while preserving kinds:
- Methods: the four identified Methods;
- candidate accounts: the two reconciliation accounts,
C-AI-Trace-Review, and proposed wholeC-EC-Release-v2; - descriptions and source claims: stage table, release checklist, supplier procedure, AI prompt, bundle records, and evidence grades;
- Systems/support/access: PLM, CI, test rig, AI provider, and provider-access relation;
- capabilities/assignments: safety competence, supplier-configuration responsibility, and
ASG-TraceReview-17,ASG-SafetyReview-17, andASG-ReleaseDecision-17; - permissions/authority:
PERM-TraceAcceptReject-17,AUTH-SafetyEvidence-17, andAUTH-ReleaseDecision-17, distinct from the assignments, performed Work, and decisions; - inputs/results/premises: pinout schema, evidence bundle, verification result, and confidentiality premise;
- relations: production/use, schema correspondence, provider access, allocation, responsibility, permission, and authority.
These are dossier navigation sections, not technical kinds or Method components. Only identified Methods and candidate accounts travel to individual qualification, each with the dependency slice needed to judge it.
ME.5 returns status-preserving individual results:
| Subject | Individual return |
|---|---|
M-HW-Verify | qualified to accept the affected change/pinout version and produce the verification result under named rig and hardware-capability conditions |
M-SW-Integrate | qualified to produce an integration record that preserves the exact provisional or signed edition, uncertainty, and earlier-use history; later signed evidence supersedes provisional only for closure reliance; one-hour reversibility still applies |
M-Supplier-Approve | qualified to produce signed approval or the explicit missing-approval stop under named access and supplier responsibility |
M-Release-Authorize | qualified to return release, withhold, or next-slot authorization when ReleaseDecider-17 performs W-ReleaseDecision-17 under ASG-ReleaseDecision-17 and AUTH-ReleaseDecision-17; Work, assignment, and authority remain separate |
| two reconciliation accounts | retained as scoped candidate accounts; A.3.1 identity remains open |
C-AI-Trace-Review | retained as a human-governed candidate account that specifies a trace-suggestion contribution; TraceReviewer-17 performs accept/reject Work under ASG-TraceReview-17 and PERM-TraceAcceptReject-17 |
ME.5 cannot qualify the provider-default AI proposal as currently supplied: neither an identified Method nor a candidate Method account has been provided. Independently, implementing the proposal would expose confidential geometry to the AI provider, and the proposal names no admitted human performer, covering assignment, or permission/authority relation. Those failures would block this use even if a candidate account were supplied.
Local schema correspondence A-17 maps signed or explicitly provisional pinout-version fields to the integration bundle, preserves the exact edition and uncertainty used, and is supported on five stored bundles for the named editions. Later signed evidence does not erase a provisional basis. It is one local connection, not whole compatibility.
Another project needing only hardware verification can stop with the individual qualification of M-HW-Verify; it does not need a package-recovery or architecture-comparison result. A project whose only useful result is the bounded qualification of C-Checklist-Reconcile can retain that subject as a candidate account with A.3.1 identity still open and stop without calling it a Method. A project investigating supplier reconciliation can likewise stop with the retained supplier account. EC-417 continues because combined evidence timing, allocation, support, authority, and recovery burden change the release decision.