SYSE.4:4 - Solution
SYSE.4:4.1 - Select one load-bearing claim and decision question
Start with one named claim episteme already used by a current engineering question. It may come, for
example, from a project-system choice account, a linked use-and-system concept, a C.30 or C.32 architecture
result, a SYSE.3 realization branch, or a specialist result. Recover:
- the claim’s subject and predicate;
- its scope, conditions, configuration or version, and temporal stance;
- the result or source account from which the claim came;
- the current uncertainty or failure mode; and
- the decision or intended Work that would change if reliance narrows, stops, or becomes stronger.
A claim is load-bearing when the decision depends on it. The same claim may be load-bearing for one decision and incidental for another. Name the decision question before selecting a challenge; a generic wish to increase confidence does not yet select assurance Work.
The decision may still be contemplated. For a selected future challenge, record in the plan what result is meant to inform it. Establish any later decision occurrence, choice, gate passage, permission, acceptance, or release through its direct relation and evidence.
SYSE.4:4.2 - Reuse current evidence or choose a challenge that can change reliance
Before selecting or planning new challenge Work, check whether current engineering result epistemes already contain or cite evidence and relations the practitioner can use:
- a compatible
SYSE.10engineering claim assessment may contain evidence-use relations for the same claim, decision, subject, configuration, use, conditions, interval, and evidence window; - a compatible
SYSE.11bounded usable-increment result may contain integration and observed-use evidence for the same actual System, configuration, use, conditions, interval, and evidence window; and - a compatible
SYSE.14change-and-release decision may cite evidence, configuration and effectivity basis, and unresolved conditions for the same release question, configuration, effectivity, interval, and evidence window.
Use only the compatible claims and cited evidence, not a neighbouring decision or authority. If the needed
evidence already exists, recover the direct result and its descriptive A.10 evidence/provenance path, then reuse
or update the engineering-assurance account without creating another WorkPlan. Without a compatible current
result, use a qualified direct source. If that still leaves a gap, state how it limits the present answer.
Availability or a familiar result name establishes no evidence use.
For a remaining evidence gap, ask: what attainable result could change reliance or make a needed use
admissible? Use C.11.DUA to compare obtaining it with proceeding on the present basis, narrowing the claim,
deferring, or stopping. Include cost, delay, displaced work, access and applicable evidence requirements. If the
current basis already supports the bounded answer, give that answer. If no worthwhile attainable challenge is
available, keep the unsupported claim unresolved and identify any continuation whose premises are supplied.
Neither outcome requires a new WorkPlan.
When further inquiry is selected, choose a challenge sufficient for its stated purpose. Examples include:
- a
C.16measurement of one declared Characteristic; - a
C.32.ACEevaluation over existing architecture-characteristic criteria; - a model, simulation, or analysis whose applicability and uncertainty are explicit;
- a component, integration, or system test against one stated expectation;
- an inspection or review with an identified subject and criterion;
- an operating observation under the configuration and conditions named by the claim; or
- a specialist safety, security, legal, ethical, financial, certification, or acceptance result required by the decision question.
State the challenge’s intended Method, subject, configuration, conditions, scale or criterion, uncertainty
treatment, time window, intended result form, and intended evidence use. When Work is still intended, put performer,
local system-role-kind condition, Method, window, capability needs, resources, dependencies, and result target
in a separate A.15.2 WorkPlan. The engineering-assurance plan cites that WorkPlan; it is not the WorkPlan.
Apply any independence or authorization requirement governing the decision. Even without such a requirement, independent criticism can be useful when it exposes a consequential blind spot or conflict of interest; choose it by its attainable contribution and burden. Establish the performer’s needed competence, authority and any required approval separately. A job title or organizational boundary alone establishes none of these.
SYSE.4:4.3 - Write the engineering-assurance plan
When a future challenge is selected, describe it using the five entries from the Problem frame. Reuse a sufficient existing plan. The plan is usable when a practitioner can recover:
- one named claim and its current use conditions;
- one decision question;
- one challenge and, when future Work needs coordination, a reference to its separately identified
A.15.2WorkPlan; - the configuration, validity, uncertainty, and currentness boundary; and
- the earlier answer the practitioner must reassess if the challenge does not support present reliance.
The engineering-assurance plan is a C.2.1 claim-bearing episteme. Its one EntityOfConcern is the named
load-bearing claim episteme. Its ClaimGraph states the planned challenge, decision question, validity boundary,
and possible affected earlier answer as claims and references concerning that target claim. The other named
entities remain participants in those claims rather than a composite subject. Use C.2.1 to identify the claim
content, target claim, and effective reference scheme. The plan performs no Work. Changed identity-bearing content
can identify another episteme. A later engineering-assurance account is not automatically an edition of the plan
merely because a file or identifier is reused; claim identity and any edition relation remain with C.2.1.
Stop at this plan when it makes the next evidence-producing Work and possible revision target explicit. Expand to a fuller artifact—for example, a test matrix, evidence graph, assurance case, or release process—only when the receiving decision needs it.
SYSE.4:4.4 - Recover performed Work, direct results, and evidence use
When the challenge is performed, identify the dated Work and performer through A.15.1 and the applicable
assignment and Work-attribution patterns. Then use the direct pattern for the result:
C.16for a measurement result, its uncertainty, and comparability;C.32.ACEfor an architecture-characteristic eval programme and its separately typed result;A.1.1for model applicability, actual model use in assigned Work, or fixed-content coherence;C.28when the conclusion is causal rather than merely observational;- the applicable test, comparison, acceptance, safety, security, legal, certification, or other specialist result pattern when that is the actual claim.
Use A.10 to make the descriptive claim-bound evidence/provenance path replayable. Keep the source, carrier,
performed Work, result, result episteme, provenance relation, currentness assessment, evidence use, assurance
result, and decision question distinct. The path represents independently established relations; it moves no
result and creates no evidence relation. Use G.11 and C.27.TA when source currentness, evidence age, calibration,
configuration time, observation window, or decay changes admissible use.
A planned challenge is not evidence. A performed test is not its result. A result becomes evidence for this claim only through the named use and its conditions. Provenance, repetition, automation, or a familiar tool does not widen that use.
SYSE.4:4.5 - Update the engineering-assurance account
After evidence is available, reuse a sufficient engineering-assurance account. Otherwise update or write the account so that the practitioner can recover:
- the named target claim and decision question;
- the actual challenge Work and its direct result;
- the descriptive
A.10evidence/provenance path and currentness basis; - the result’s configuration, condition, scale, uncertainty, and applicability limits;
- the practical change in reliance for this decision; and
- the smaller earlier answer, specialist question, or next challenge affected by that change.
The account remains a C.2.1 episteme about the named target claim. Its ClaimGraph adds claims about performed Work, direct results, evidence use, changed reliance, and the affected earlier answer. Those named participants do not become a composite EntityOfConcern.
State the reliance change in ordinary language, using a conclusion that fits the case: for example, the claim
remains usable for the decision within the stated limits; the practitioner must narrow reliance; the practitioner
must replace or withdraw the claim for this use; or available evidence leaves the question unresolved. When the current question is an assurance claim or material reliance threshold, use B.3 for the
named assurance-result claim or no-assurance disposition. The engineering-assurance account cites that result;
it does not replace it.
When the result is unresolved, identify the missing input that limits this answer—for example, a configuration, comparator, observation window, calibration, causal link, specialist criterion, or independent challenge. Return to the inquiry choice in §4.2 before planning further Work. A narrower supported answer or a justified stop can complete the current question. Missing information establishes neither the target claim nor its negation.
SYSE.4:4.6 - Combine evidence only for the decision question
Some decisions depend on several evidence lines—for example, model predictions, physical tests, integration
results, operating observations, and specialist arguments. Keep each direct result and evidence use visible. Combine them
only through the composition or assurance rule needed by the decision question, including congruence and scope
limits when B.3 is current.
Representations and automation—for example, digital twins, evidence dashboards, traceability graphs, assurance cases, test-report collections, or continuous pipelines—can help maintain these relations. Name the contribution used by the account, then establish model applicability, physical correspondence, evidence completeness, and any downstream acceptance, certification, permission, release, or target-claim use independently.
SYSE.4:4.7 - Apply the result to the smallest affected answer
The practitioner uses the changed reliance to reassess only the smallest earlier answer to which it applies:
- reassess
SYSE.1when evidence changes the selected project referent, project reason, or boundary; - reassess
SYSE.2when observed participation, conditions, effects, benefit, or harm change the linked use or system concept; - reassess
C.30,C.32, or the applicable architecture decision when criteria, bearers, structures, or trade-offs must change; - reassess
SYSE.3when capability, integration, configuration, production, access, or another realization branch fails; - use the specialist practice when its safety, security, legal, ethical, financial, certification, acceptance, permission, or release question remains open.
Stop when the account makes the evidence use, its limits, changed reliance, and affected answer clear. Reassess a wider answer only when the narrower answer also fails. The result can become available at any time. The stated relations are claim-dependency and revision relations; they impose no lifecycle stage or prescribed Work order.