SYSE.28 - Place Qualified Controls in a Supported Platform-Use Path
Normativity: Guidance within the stated engineering use; examples are illustrative.
SYSE.28:1 - Problem frame
Use this pattern when a justified constraint already exists but engineers must decide where and how a supported path will check or enforce it. Start with the constrained subject, applicable conditions, deciding authority and the reliance that would be prohibited if the constraint were not met.
The first result is a control-placement design: an applicable check or mechanism, the subject it observes, its point of use, the meaning of its outcomes and the response to failure or uncertainty. It is not a new policy or a release decision.
A software artifact can change after an early verification; a physical dimension can change after coating; an access decision can expire before a resource is used. Place the control where it can answer the actual question. If the constraint, its justification or the authority is missing, return that question instead of inventing a platform rule.
SYSE.28:2 - Problem
Controls placed too early can report a property that is later lost. Controls placed too late can discover a prohibited effect only after it occurs. Repeating the same check at every step can add delay without covering the actual point of loss.
A second failure is to merge different results: advice, an observed property, a technical block and an authorized decision. A successful mechanism does not create authority, while an authorized exception does not turn a failed observation into a pass.
SYSE.28:3 - Forces
| Force | Practical tension |
|---|---|
| Early feedback | Early detection reduces rework, but later transformations can invalidate the result. |
| Reliance protection | A final check can protect a receiving action, but may arrive too late to explain a preventable failure cheaply. |
| Reuse and currentness | Reusing a matching result saves effort; stale subject or condition identity makes the reuse unsound. |
| Availability | A failed checker can block useful work; silently bypassing it can permit the exact reliance it was meant to prevent. |
SYSE.28:4 - Solution
SYSE.28:4.1 - Recover the supplied constraint and decision
Name the property, the subject to which it applies, its effectivity and the action that depends on it. Recover the actual deciding holder and any authorized exception conditions. Keep the constraint’s justification separate from the proposed technical implementation.
Identify what evidence or qualified procedure can answer the property question. If the domain test itself is missing, return that Method gap. A platform wrapper cannot qualify a security, measurement, safety or legal judgement by executing a script.
Use SYSE.4 for the relation between evidence and the engineering claim, and SYSE.14 when the consuming action is a release decision. This pattern determines where the supplied control can usefully act.
SYSE.28:4.2 - Find where the property can change or be lost
Follow the relevant input, construction, transfer, installation and use. Identify which operations can alter the property and where another subject can be substituted. Do not assume that one label denotes unchanged bytes, configuration or material.
Locate the last relevant change before the prohibited reliance. Place a decisive observation or enforcing mechanism so that it can still prevent that reliance. Add earlier feedback only when it can avoid meaningful rework or guide a correction.
If the property can continue to change during use, determine what continuing observation or enforcement is needed and under what conditions it remains effective. A historical check cannot guarantee an indefinitely changing subject.
SYSE.28:4.3 - Compare placements by the question they answer
Compare evidence reach, response time, user/provider burden, failure behavior and the remaining opportunity for change after each candidate placement. An input check, a provider check and a consumer check may answer different questions.
For an immutable artifact crossing a trust boundary, a producer’s check can qualify its construction while a consumer-side identity/trust check concerns the bytes actually received. For a coated component, an earlier dimensional result may guide manufacturing but cannot by itself support reliance on the final dimension.
Reuse a result only while the subject, relevant configuration, criterion and qualification conditions still match. A preserved result may be sufficient through controlled steps that cannot change the checked property of the subject. Name the specific change that requires rechecking; neither universal repetition nor universal reuse is the default.
SYSE.28:4.4 - Define every consequential outcome
Specify the mechanism’s input, how it obtains the observation, how the outcome is interpreted and what the user can do next. Distinguish at least the outcomes that change action: satisfied, failed, not applicable, insufficient evidence and unavailable mechanism.
A technical block should block the dependent action, not silently cancel unrelated work. When a decisive checker is unavailable, preserve the uncertainty and use only a separately permitted alternative or current matching result. Do not make “could not check” indistinguishable from “passed.”
Keep advice, enforcement and authority separate. An advisory warning informs a decision. A technical block can prevent an action. An authorized holder may permit a bounded exception under the applicable rule. Record that exception’s real subject, extent and conditions where needed; the failed or missing factual result remains failed or missing.
SYSE.28:4.5 - Exercise the control where it will be relied on
Use a normal case, a known violating case, a subject substitution and a checker-unavailable case. Confirm that the intended dependent action receives the right outcome and explanation. Check any authorized exception path separately.
For consequential reliance, also inspect whether the controlled property can change between observation and use. Bind the result to the actual subject or protect that interval with a qualified mechanism. A green check followed by an uncontrolled substitution does not protect the receiving action.
Return the placement, mechanism, outcome interpretation, applicable conditions and remaining gaps. Safety or compliance claims that rely on the control require their own domain evidence; placing the check is not that qualification.
SYSE.28:5 - Archetypal Grounding
A constructed software case supplies an existing requirement: before installing a service package, its receiver must establish that the actual artifact meets the configured provenance expectations. The applicable trust roots and expectations are provided by the responsible holder; the platform team does not invent them.
The build service has verified package h1. A later registry transfer returns different bytes h2 under the same human-readable version tag. A check performed only before that transfer cannot establish the property for h2.
The chosen placement keeps the early producer feedback and performs the receiving verification on the actual artifact before installation. SYSE.32 supplies the artifact-specific verification Method. If h2 has no matching qualifying provenance, installation receives a failed or insufficient result, not the old h1 success. If the verifier is unavailable, the same dependent installation waits or takes a separately authorized alternative; an unrelated already qualified test can continue.
Once the artifact is verified, a controlled transfer of those unchanged bytes can reuse that identity result under matching trust conditions. A newly downloaded package, altered artifact or changed relevant expectation reopens the affected check. None of these outcomes approves the application’s production release.
In an unlike physical case, the engineering requirement concerns a finished coated bore of 20.000 ± 0.020 mm. The case explicitly supplies a qualified measurement procedure for the finished part; developing that procedure is not the current question. Measuring the uncoated bore can guide machining, but coating can alter the final dimension.
The decisive final-dimensional check is therefore placed after coating and before the part is accepted for the dependent assembly. A pre-coating pass cannot be reused merely because the part number is unchanged. If the qualified finished-part measurement is unavailable, the result remains unestablished; faster transfer of the old report does not cure it. In a real case lacking the supplied measurement Method, that missing Method is a separate blocker.
What changes in practice is the coverage of the control. The receiver knows which subject and interval the result concerns and what is stopped when that result is absent.
SYSE.28:6 - Bias-Annotation
Teams often place controls where tools make them easy rather than where the property can be lost. A preference for early feedback or for one final approval can hide complementary needs. Inspect the actual transformation and reliance, including physical effects that no later software action can undo.
SYSE.28:7 - Conformance Checklist
- The constraint, subject, applicability and deciding authority are supplied.
- The observation or enforcement Method is adequate for its particular property, or its gap is explicit.
- Placement accounts for the operations and substitutions that can invalidate the result.
- Reuse is conditional on matching subject, criterion and qualification conditions.
- Failed, missing and unavailable outcomes reach the dependent action with a usable explanation.
- An authorized exception leaves failed or missing factual results unchanged.
- A technical block stops only the dependent action and leaves unrelated work available.
SYSE.28:8 - Common Anti-Patterns and How to Avoid Them
| Misuse | Repair |
|---|---|
| Check early and assume the property survives every later step. | Identify later changes and cover the actual receiving subject. |
| Run the same check at every step. | Separate distinct questions and reuse a matching result through protected transformations. |
| Checker failure means pass. | Preserve missing evidence and follow only an authorized fallback or stop. |
| A green badge grants release authority. | Return the bounded evidence to the actual decision holder. |
SYSE.28:9 - Consequences
Checks can provide earlier repair feedback and a more credible basis for reliance. Some placements require additional observation or protected transfer, while others become unnecessary duplicates. Explicit unavailable-result behavior can delay the dependent action, but exposes the real constraint rather than disguising a bypass.
SYSE.28:10 - Rationale
A property’s truth at one time or location does not automatically survive transformation, transfer or substitution. Control placement is therefore a question about evidence reach and prevented reliance. Keeping that question separate from policy and authority makes the mechanism useful.
SYSE.28:11 - SoTA-Echoing
For “Where should artifact verification protect consumption?”, adapt the placement comparison in SLSA v1.2, Verifying artifacts. Its producer, ecosystem, consumer and monitor alternatives cover different threat locations. Sections 4.2–4.3 reject a producer-only check as evidence for uncontrolled received bytes; the h1/h2 case demonstrates that loss. Additional checking is justified by distinct evidence reach, not by the number of pipeline stages.
The serious general alternatives are a single early control and repeated controls everywhere. The selected line uses the supplied property and its possible loss to choose between them, accepting extra effort only where it changes the reliance claim. SYSE.4 supplies that evidence-use discipline. SLSA does not supply a physical measurement procedure or release permission.
Reopen placement when a new operation can alter the property, a trust boundary changes, the checker no longer qualifies the needed claim, or the receiving action changes.
SYSE.28:12 - Relations
SYSE.26 supplies the supported interaction and failure feedback. SYSE.4 governs evidence reliance, SYSE.13 identifies configurations and SYSE.14 supplies release decision-making. SYSE.32 supplies software artifact verification and SYSE.41 supplies deployment observations. Missing policy justification, authority or specialist qualification returns to its actual holder rather than being created by a platform mechanism.