Library / Method Engineering Principles Framework
Jump to passage
In this reading

Link to current text

Published source confirmed at last check

Source changed 2026-10-03 07:42:37 UTC · snapshot created 2026-10-03 07:43:27 UTC · last check 2026-10-03 08:00:10 UTC

8. Return a proposed-whole account and a bounded trial

ME.7 receives C-EC-Release-v2 with:

  • intended result: a traceable safety-relevant release under named evidence and authority conditions;
  • reusable invariant: reconcile the exact provisional or signed evidence edition with the integration bundle before safety closure;
  • participants and contributions: the four identified Methods, two reconciliation accounts, the three admitted decision Systems, their decision Work/results and covering assignments, and separately governed support/capability/permission/authority subjects;
  • inputs/results: pinout/evidence state, implementation revision, verification result, signed approval or stop, and release authorization;
  • variation: signed-first A or bounded provisional-first B2 before entry; post-entry recovery R;
  • bounds: confidentiality, human AI-suggestion decision, evidence edition/uncertainty/history, signed-before-closure reliance, peak burden, board duration, rollback, covering assignments, and named permission/authority relations;
  • reidentification rule: the account changes when its receiving result, invariant, participant contribution, evidence branch, or authority/stop rule changes materially.

The four participant Methods are identified, but the proposed whole is not. The result is therefore a prospective candidate Method account, proposed relation sets, guards, adapters, fallbacks, stops, variation points, and a trial WorkPlan. Writing or selecting that account creates neither a world-side Method, obtaining composition, ArchitectureRelation, nor MethodDescription.

At D-21, ReleaseDecider-17 performs W-ReleaseDecision-17 under ASG-ReleaseDecision-17 and AUTH-ReleaseDecision-17, after SafetyReviewer-17 performs the needed evidence decision under ASG-SafetyReview-17 and AUTH-SafetyEvidence-17. B2 entry also requires TraceReviewer-17 to perform accept/reject Work under ASG-TraceReview-17 and the current PERM-TraceAcceptReject-17 for every AI suggestion actually used by the branch. The filled baseline is W-TraceAcceptReject-17-01 and PEX-TraceAcceptReject-17-01 from section 5; any additional used suggestion would require a distinct dated Work, result, currentness check, and exercise relation.

The decision chooses A before integration if signed evidence is already available or if versioned provisional evidence, supplier preparation, confidentiality, the trace-review assignment or permission, or a safety/release assignment or authority condition for B2 is absent. Under the baseline D-8 assumption and with every B2 entry condition satisfied, it may authorize only three B2 releases.

Each B2 occurrence must keep confidential geometry outside the provider, record TraceReviewer-17 accept/reject for every AI suggestion under ASG-TraceReview-17 and PERM-TraceAcceptReject-17, hold its boards on the named days, stay at or below 3.20 h peak safety effort, obtain signed evidence before closure, and reach the target slot or record why it did not. A confidentiality, assignment, permission, or authority breach stops B2 immediately.

If signed evidence is missing at D-8, withhold release and enter R. R preserves the performed integration record, provisional edition, uncertainty, and earlier decision use. If signed evidence arrives by D0 while the existing evidence and reversibility guards still hold, the team records its relation and delta to provisional, re-baselines the bundle, repeats the comparison and affected verification, and records whether early integration was retained, rolled back, or repeated.

If closure is still unresolved at D0, ReleaseDecider-17 returns withhold/next-slot and this application’s R occurrence ends as a failed B2 trial. All AI-supported continuation stops at D0. Any later non-AI recovery is outside this application and follows the future-recovery boundary in section 5.

These boundaries do not rewrite any earlier Work or evidence basis. Signed evidence supersedes provisional only for safety-closure reliance. For the constructed series of at most three B2 trials, count one failed trial when that release has a capacity or mismatch failure or enters R. Count that trial only once even if several categories or events occur; retain all categories as reasons for analysis. Entering R counts once for its trial even if recovery later succeeds. After two distinct failed trials, ReleaseDecider-17, within the applicable AUTH-ReleaseDecision-17 scope, returns B2 for revision or rejects further B2 use before any fourth release. The required safety-evidence accept/reject remains a separate SafetyReviewer-17 result under AUTH-SafetyEvidence-17; revising the candidate account is separate work, not an authority granted by this release decision. The existing decision covers at most three trials regardless of the failure count: any further release requires a new applicable decision. The immediate confidentiality, assignment, permission, and authority stops above do not wait for two failures.