SYSE.19 - Revalidate Engineering Decisions When a Relied-on Source Changes
SYSE.19:0 - Use This When
Use this pattern when an engineering decision relied on a claim in a model, requirement, standard, MethodDescription, supplier specification, research result, or another engineering source, and a later edition or replacement may change that claim. The project needs to know which decisions remain usable and which need new Work.
Begin with the predecessor and later source epistemes. Compare the claims that can change engineering action, then recover decisions and Work results whose stated reasoning depends on those claims. Revalidate only the affected use; a new file or edition label is only a cue to inspect.
The first useful result is a bounded source-change impact decision: the engineering use supported by the current basis, with the limitation or blocker that matters to its receiver. A compatible carrier change can finish with a repaired reference. For a material claim change, preserve, narrow, reopen or withdraw only the affected use. New revalidation Work is selected when the receiving question warrants it. Identify any later performed Work, returned evidence and replacement engineering decision separately.
Use SYSE.14 when the engineered System or its release is changing, and SYSE.13 when configuration identity and
effectivity are the main question. Use SYSE.7 to maintain several descriptions used by one decision and SYSE.10
to qualify new model, experiment, or trial evidence. Use FPF E.15 when an FPF pattern edition itself changes.
SYSE.19:0.1 - Terms and Distinctions
| Name in this pattern | What it denotes |
|---|---|
| engineering source | A claim-bearing episteme that an Agent uses while performing engineering Work. Record its publication, carrier, or access relation only when that relation changes the use. |
| source edition | An episteme related to an earlier episteme by the C.2.1 edition-continuity predicate. A revision label or date is evidence to inspect, not the edition relation itself. |
| replacement source | A later episteme proposed for the predecessor’s use when edition continuity is absent or unresolved. Its applicability is decided for that use. |
| publication or carrier change | A change to availability or presentation—for example, another URL, file, layout, form, or publication occurrence. Compare claim content before treating it as a semantic change. |
| material claim change | A change in claim content or applicability that can alter engineering action—for example, a changed proposition, scope, assumption, limit, evidence status, or MethodDescription statement. |
| direct reliance | A named engineering decision or Work result whose justification or content depends on a source claim as a premise under stated conditions. A citation or link is discovery evidence until the receiving content confirms that dependence. |
| affected reach | The smallest set of decisions reached through direct-reliance relations whose engineering action can change because of the material claim change. |
| revalidation Work | Work that rechecks an affected claim or decision under the current configuration, conditions, Method, evidence needs, and authority. |
| decision disposition | One choice from the closed set used here: preserve, narrow, reopen, supersede, withdraw reliance, or blocked. |
The source episteme, its publication, the claim-change observation, planned revalidation, performed Work, returned evidence, and engineering decision have separate identities. An Agent performs revalidation Work. Equipment, models, repositories, and the engineered System are examples of other participants; state each direct relation.
SYSE.19:1 - Problem Frame
Engineering decisions depend on changing sources. For example, a supplier can revise a material limit, a standard can change an interface claim, a MethodDescription can narrow an operating range, or a research result can weaken an evidence line. The engineered System may stay unchanged while the warranted decision basis changes. Conversely, a new carrier or revision label may leave every relied-on claim intact.
The project needs two kinds of continuity. Historical source and decision identities stay recoverable so earlier Work can be understood. Current decisions reopen only where a relied-on premise changed. Repeating everything is expensive and hides the reason for change; comparing only files can miss a one-sentence change that alters release.
A source-change impact decision connects changed claims to their actual use in engineering Work and states what revalidation is needed for the current configuration.
SYSE.19:2 - Problem
Two shortcuts cause most of the damage. One repeats every downstream activity merely because the source label changed. The other keeps every decision merely because the engineered System did not change. Both avoid the central question: which relied-on claim changed enough to alter engineering action?
Other recurring failures appear when the source episteme cannot be identified, reliance is known only at document level, a semantic difference is confused with a text diff, revalidation uses the wrong configuration, or a passing test is treated as permission or release. The project then either spends effort without a decision or keeps a decision whose premise no longer applies.
SYSE.19:3 - Forces
Recurring tensions include:
- Revalidation should stay bounded, while an undeclared reliance can matter more than a declared trace link.
- Source identity must remain recoverable without turning every carrier change into a semantic event.
- One changed sentence can alter release; a large rewrite can leave the relied-on premise intact.
- Automated search can find candidate uses, while materiality and applicability still need engineering judgement.
- A newer official or popular source can fit the use worse than an older bounded source.
- Preserved decisions remain usable only when the reason for preservation is recoverable when later Work needs it.
SYSE.19:4 - Solution
Compare source claims, recover their actual engineering uses, and revalidate only what is needed to decide whether the affected engineering decisions remain usable.
SYSE.19:4.1 - Perform the Move
- Name the receiving decision. State the engineering decision at risk, any relied-on Work result, the current configuration and use, the relevant interval, and the action that could change.
- Identify the source epistemes. Recover the predecessor and later claim-bearing epistemes, their applicability, provenance, and publication or carrier facts when those facts matter. Establish an edition relation only when its predicate obtains; otherwise treat the later source as a replacement candidate or record an identity gap.
- Compare claims rather than files. State every material change in claim content or applicability—for example, proposition, scope, assumptions, limits, evidence status, or MethodDescription content. Classify the remaining differences as publication or carrier changes. When relevant meaning, applicability and access remain compatible, finish with any needed reference repair. Missing comparison facts remain a scoped gap.
- Recover direct reliance. For each material claim, inspect candidate receiving content found by means such as search, citations, traces, or AI assistance. State the decision or Work result and the direct premise or evidence-use relation that connects it to the claim.
- Bound the affected reach. Distinguish
depends,mentions onlyandunresolvedwithin the searched frame. Group equivalent irrelevant mentions; retain a short exclusion reason in the existing result when its receiver needs it. Follow adependsbranch only while a downstream engineering action can still change. UseA.10.1when several receiving uses still need discovery; retain the search coverage needed for the stated conclusion. - Choose any needed revalidation Work. Use adequate existing evidence first. A scoped limitation or blocked
use can be the completed answer. Select further Work under
C.11.DUAwhen its obtainable contribution warrants the complete programme burden within the receiving window. For selected Work, name the Agent, Method, configuration, conditions, evidence need, authority, cost and stop. Cost does not make an unsupported use safe or supply missing permission. - Perform and qualify selected Work. Identify actual performed Work and returned evidence separately. State what the result supports for the current configuration and what remains unknown.
- Decide separately for each affected engineering decision. Assign one decision disposition from the closed set in section 0.1 and state its reason, evidence and applicable interval. Name next Work only when selected for this receiving use. A passing check becomes a decision premise only when authorized decision Work uses it.
- Supply the result and preserve history. Give the Agent making the relevant engineering change or release decision the supported use, relevant revalidation evidence and material blockers. This direct return can finish the question. A further common account is needed only for a receiver who needs that overview. Keep earlier source editions and decisions recoverable for their original uses and intervals.
- Stop at the completed receiving answer. Finish a compatible reference repair directly. For material change, return the qualified in-scope decisions or exact blockers and preserve independently resolved branches. A no-impact claim requires adequate discovery coverage and actual-use support; uninspected or inaccessible surfaces remain gaps.
The numbered presentation is an A.22.CGUS learning unfolding, not a lifecycle or a required Work sequence.
Source comparison, design, testing, operation, and release Work may overlap. Only dependencies established for the
current claims impose an order.
SYSE.19:4.2 - Record the Result
Record only the content needed by the receiving decisions in their existing result. The rows below apply to the branch actually taken; a harmless reference repair needs no revalidation dossier.
| Result position | Content when needed by this receiving decision |
|---|---|
| receiving decision | Engineering decision, any relied-on Work result, current configuration and use, relevant interval, deciding Agent, and action that may change. |
| source comparison | Predecessor and later or replacement epistemes; material claim changes; publication or carrier changes; source-access and identity gaps. |
| direct reliance | Every affected decision or Work result, the source claim on which it depends, and the premise or evidence-use relation that establishes the dependence. |
| affected reach | Actual-use bases and unresolved candidates that affect the conclusion; equivalent irrelevant mentions may share one exclusion reason. Retain discovery coverage and the last action-changing decision. |
| revalidation | For selected revalidation: planned and actual performed Work, Agent, Method, configuration, conditions, evidence needs, authority, results, cost and stop. |
| decision dispositions | One disposition from section 0.1 for each affected decision, with reason, evidence and interval; next Work only when selected. |
| continuation | Material gaps and historical source/decision references; a receiving Agent or reopen condition when the actual continuation needs one. |
For example, a compact table, linked decision note, model query result, or generated report may present this episteme. Treat the form as a representation; keep the source claims and direct-reliance relations recoverable.
SYSE.19:4.3 - What Changes in Practice
Engineers stop using a source version as a proxy for impact. A source update can matter while the engineered System stays unchanged because the warranted decision basis changed. A carrier update can leave engineering decisions usable when claim content and applicability remain compatible.
Revalidation produces a bounded decision result: it identifies decisions that remain usable and decisions that need new Work. Search and AI-assisted comparison reduce discovery effort, while an Agent with suitable capability and authority judges materiality and applicability.
SYSE.19:5 - Worked Case: A Changed Sensor-Calibration MethodDescription
A pump-controller project used edition E2 of a sensor-calibration MethodDescription. E2 states that temperature
compensation for sensor module TS-2 is valid from -20 °C to 50 °C. The supplier publishes E3 under the same
edition scheme. E3 narrows ordinary validity to -10 °C through 50 °C; lower-temperature use now requires a new
calibration Method and evidence.
The source-impact team has authority to classify engineering reliance but not to release controller units. It compares the two claim-bearing epistemes and finds four candidate uses of the old temperature claim:
- the thermal model uses it as a cold-start parameter bound;
- the cold-start test MethodDescription uses it as an acceptance condition;
- the safety claim uses evidence produced under that condition; and
- the interface architecture description cites E2 only in its bibliography.
Inspection gives the first three uses depends and the bibliography citation mentions only. The interface
decision and room-temperature evidence therefore remain usable. The cold-start model, test criterion, and service-
release premise enter the affected reach.
In this constructed case, qualified planning premises show that the modeling, calibration and chamber-test results can arrive before the release decision and that their combined burden is warranted by the cold-start release question. The team chooses three revalidation Work occurrences. A modeling Agent revises the cold-start model. A calibration
Agent performs the new low-temperature calibration for units S006–S008. A test Agent performs the chamber test
under the current hardware, interface, sensor, and firmware configuration. Each Work occurrence has its own Method,
result, and evidence.
The returned evidence supports cold-start use for S006–S008 under the tested conditions. Units S009 and
S010 still lack calibration evidence. Units S001–S004 use another hardware configuration, so this changed
claim does not reach their release premise.
The bounded source-change impact decision now:
- preserves the interface decision and room-temperature evidence;
- supersedes the old cold-start model parameter and test criterion for current use;
- preserves cold-start release eligibility for
S006–S008under the new evidence; - reopens the release premise for
S009andS010; and - supplies the result to
SYSE.14, where the authorized Agent makes the service-release decision.
Carrier-only countercase. The supplier republishes the same E3 episteme at another URL with a new PDF layout. The publication and carrier facts change; claim content, applicability, access and direct use stay compatible. Updating the reference completes this change. No affected-use search, new engineering decision record or common revalidation summary is needed.
World-change boundary. Replacing an actual TS-2 sensor is a configuration and world-side engineering change.
Use SYSE.13 and SYSE.14 for that change.
SYSE.19:6 - Bias Annotation
A newer official source deserves inspection because its claims or authority may matter. Official status, publication volume, and academic attention describe the source and discourse. Project use and effectiveness need evidence about performed engineering Work and outcomes.
Search, dependency graphs, and AI summaries can find candidate uses. Actual reliance still depends on the receiving claim or decision, and authority remains with the Agent who holds it.
SYSE.19:7 - Conformance Checklist
- The predecessor and later or replacement source epistemes are identified.
-
Edition continuity is established under
C.2.1or left unresolved. - Material claim changes are separated from publication and carrier changes.
- Every affected use names the source claim, receiving decision or Work result, and direct-reliance relation.
- A searched frame distinguishes dependent, irrelevant and unresolved uses; equivalent irrelevant mentions can be grouped. Actual-use support and coverage justify any no-impact claim. Tracing stops at action-changing closure.
- Any selected revalidation Work warrants its complete burden for this receiving use and names its Agent, Method, configuration, conditions, evidence needs, authority, result and stop.
- The decision episteme, performed Work, evidence, permission, assurance, and release decision are grounded separately.
- Historical source editions and decisions remain recoverable for their original uses and intervals.
- The receiver gets the sufficient branch result and its material limits. A harmless reference repair or direct engineering answer closes without a duplicate record; next Work is included only when selected.
SYSE.19:8 - Common Failures and Repairs
| Recurring failure | Repair |
|---|---|
| A new version triggers a full rerun | Compare claims and trace actual reliance; reopen only action-changing dependent reach. |
| A small text diff is assumed harmless | Ask what a relying engineer may now do or conclude differently. |
| A new file is treated as a new source meaning | Separate source episteme, edition relation, publication, and carrier. |
| A trace link is treated as reliance | Inspect the receiving content and state the direct-reliance relation. |
| No physical change is treated as no impact | Recheck the epistemic basis of engineering decisions. |
| A passing test is treated as the decision | Ground evidence-producing Work, evidence use, decision Work, and authority separately. |
| The latest official source wins automatically | Compare applicability and evidence for the named use. |
Pending review hides the blocker | Name the missing source, claim content, applicability fact, evidence, capability, or authority. |
SYSE.19:9 - Consequences
Source refresh becomes proportional. Decisions remain stable when their premises remain compatible, while one material claim can reopen a release even if the engineered System is unchanged. Historical sources and decisions remain inspectable, and automated discovery can reduce effort while the deciding Agent retains authority.
The cost is claim-level source identification and maintenance of actual reliance. When source content or applicability cannot be obtained, the Agent applying this pattern records a named blocker. Application DPFs may add source controls for domains such as regulated products, software supply chains, clinical devices, finance, or contracting.
SYSE.19:10 - Rationale
The pattern separates a changed source claim from a world-side engineering change. A changed episteme can alter the warranted basis of a decision while the engineered System remains unchanged. Revalidation Work and later engineering change therefore receive separate identities.
The least costly adequate revalidation follows changed claims only as far as they can alter engineering action. Reopening whole files is too broad, while comparing isolated words cannot establish engineering meaning or reliance. Preserving source editions, actual uses, performed checks, and decision dispositions makes the Method replayable with project-local trace sources.
SYSE.19:11 - SoTA and Source Use
When a relied-on source changes, identify which claims, MethodDescriptions, decisions and uses may need revision. Keep source content and edition change, the Agents using it, performed Work and evidence separately recoverable. Revalidate the affected applicability and use under the current FPF distinctions.
| Source line | Retained contribution | Use boundary |
|---|---|---|
Current FPF C.2.1, A.10, E.15, and G.11 | Episteme and edition identity, claim-bound evidence, affected-use inspection, and bounded refresh. | E.15 governs FPF pattern editions; this DPF supplies the engineering source-use specialization. |
| Wu et al. 2025 | One landing-gear case demonstrates tool support for heterogeneous model semantics, conflict handling, traceability, and versioning. | Use the case for candidate impact discovery; establish reliance, configuration change, and release authority separately. |
| Hernández, Moros, and Nicolás 2023 | A multivocal mapping reports requirements Work continuing through DevOps with changing descriptions and monitoring. | The software-heavy review supports this recurring source-change problem, not a universal requirement or revalidation Method. |
| Norheim et al. 2024 | Analysis of LLM use in requirements Work exposes source, consistency, verification, and cyber-physical limits. | Use generated summaries for candidate discovery; ground engineering evidence and decisions separately. |
| Kosenkov et al. 2025 | Regulatory-compliance research connects legal interpretation, engineering descriptions, evidence, and change Work. | The mapping study supplies candidate relations; the applicable legal interpretation and permission need their own authority. |
| Bantwal and Fatahi Valilai 2026 | A brake-caliper case exposes change propagation across physical parts, descriptions, supply constraints, engineering tools, and validation. | Use its links as candidate affected reach; inspect actual reliance before reopening a decision. |
Currentness claims carry an epistemic status. Signals such as academic attention, institutional promotion, a
supplier’s latest label, or public reporting are evidence about communication. Use direct observations or
qualified expert estimates for enacted engineering practice, prevalence, and effectiveness.
SYSE.19:12 - Relations
C.2.1governs source-episteme identity and edition continuity.E.17andE.24.PUBgovern publication forms, carriers, audiences, and availability.A.10governs claim-bound evidence,B.3assurance, andC.11the later choice.A.10.1supplies needed multi-use discovery and branch-scoped completion.C.11.DUAselects further inquiry by attainable contribution and full burden. This pattern retains the engineering subject judgment and its direct receiving use.E.15applies when an FPF pattern edition changes.G.11supplies only its declared Part-G refresh results.- A compatible
SYSE.7result can supply a MethodDescription or representation use for the named claim. A compatibleSYSE.10result can supply evidence for the same engineering claim, configuration, decision, and evidence interval. SYSE.19supplies source-change feedback toSYSE.14; the authorized Agent inSYSE.14still chooses and releases any world-side engineering change.SYSE.13andSYSE.14govern configuration and world-side engineering change. An episteme edition relation is used only as source-change input.- Application profiles may specialize this Method for domains such as software supply chains, electrical parts, regulated products, medical devices, ships, or buildings. A specialization adds an action-changing source or revalidation distinction.