Library / Systems Engineering Principles Framework
Jump to passage
In this reading

Link to current text

Published source confirmed at last check

Source changed 2026-10-03 02:22:15 UTC · snapshot created 2026-10-03 03:38:22 UTC · last check 2026-10-03 04:00:05 UTC

SYSE.21:5 - Worked Case: Continue an AI-Assisted Release Method

PumpWorks is a constructed case. Two release cells prepare controller and mixed physical-control changes for a district-heating pump station. A practice council must decide whether to continue an AI-assisted release Method after one trial. The decision concerns PumpWorks during 2026-Q4 and 2027-Q1; it makes no field-wide prevalence claim.

The case supports two B.1.5 Method-part relations inside the candidate Method:

  1. an AI Agent generates claim-sized change-impact candidates with source, configuration, and effectivity references; and
  2. an assigned engineering Agent accepts or rejects each candidate with a recorded reason before separate integration, assurance, and release decisions.

The Method stops when a required source or configuration reference cannot be recovered, suitable independent review is unavailable, or a specialist safety result is missing. Its description, examples, review criteria, and demonstration result are carriers held in an engineering repository.

The first release cell enacts the Method during one 2026-Q4 release-preparation Work occurrence. The AI Agent generates candidates; an assurance pair reviews them; the cell prepares the evidence set. One previously missed controller-to-sensor dependency is found before integration. Review effort increases because source checking, configuration binding, and rejection explanations are now explicit.

An enablement team then performs Work that makes the MethodDescription, examples, criteria, and demonstration result retrievable by the second release cell. Retrieval establishes transmission of the carriers. The second cell’s later release-preparation Work establishes one receiving-enactment observation.

During 2027-Q1 the two release cells choose and enact the same Method for three further eligible changes. Every evidence set keeps the required references, independent review, and manual fallback. Review effort is 5.2, 5.8, and 5.5 person-hours, below the project’s six-hour limit.

The case asserts the following seven cultural claims; this is the complete claim set used by the current decision:

ClaimEvidence and boundary
variant generationMethod-design Work produced the MethodDescription, while A.3.1 and the reusable action identify the Method itself.
transmissionEnablement Work and repository access made the carriers retrievable by the second release cell.
receiving enactmentThe second cell performed release-preparation Work that enacted the Method under compatible conditions.
local cultural selectionBoth cells chose the Method over the manual fallback for all three eligible 2027-Q1 changes.
memoryThe cells repeatedly retrieved and used the same description, examples, and criteria editions.
retentionFour later enactments across both cells continued through the stated period with the same fallback and review conditions.
local carrier lossThe repository stopped presenting an older prompt-only instruction; the claim concerns access through that repository only.

The practice council considers three admitted alternatives as its fixed option set:

OptionDecision-bearing changeExpected gainMoved burden or limit
A — retain manual impact reviewUse the incumbent search and checklist without AI candidate generation.Familiar evidence and authority arrangement.More candidate-generation effort and the previously observed missed-dependency risk.
B — continue bounded AI assistanceKeep AI candidate generation with source and configuration references, recorded review reasons, independent review, and a replayable rejected-candidate sample.Faster, more inspectable candidate generation.More provenance, review, and replay Work.
C — stop and revertRemove the AI Agent from the arrangement and restore the incumbent description.Removes AI-source and integration uncertainty.Loses the observed candidate-generation contribution.

A candidate in which the AI Agent issues release recommendations is screened out before the option set is fixed: the practice council lacks that authority and compatible assurance evidence. That finding becomes a separate future authority and assurance question rather than a disguised current option.

The comparison rejects any option that loses configuration identity, source provenance, independent review, safety or release authority, or service protection. Among survivors it prefers fewer unexamined impact hypotheses, lower total burden, and reversibility. The council selects B, retains A as the manual fallback, and uses C as the stop condition when references or review fail.

For the ordinary continuation decision, suppose another replay would displace necessary release review without changing use of B under these same supported conditions. The council’s bounded continuation is complete; the 5.2, 5.8 and 5.5 person-hour observations retain their force against the six-hour limit. No additional experiment is needed to close that result.

Now change the receiving condition: a different AI provider is proposed for physical-control changes whose impact references must remain recoverable. The old observations do not qualify that provider. If permitted source material, the qualified assurance pair, a protected preparation window and a worthwhile comparison are available, select a bounded replay before widening supported use. The proposal is not a performed test. If those conditions fail, withhold the new branch and use the qualified current arrangement or manual fallback; source, configuration, independent-review and safety stops remain binding.

The original two-cell observations support a bounded repertoire update from defer after the first trial to retain for this change class with references, independent review, and fallback. It does not yet supply an HCD.1 input: the case has team-level review burden but no observation identifying which human-holder capability needs development. No human-capability inquiry is needed to complete this continuation. If a later decision depends on such a demand, select useful obtainable inquiry into the holders, representative Work and limiting capability.

District-heating service continues during the case. This is a service observation; the short case does not attribute it causally to the Method. Reopen when the profile, population, Method or carrier edition, six-hour burden limit, safety authority, or a consequence for a named affected System changes.