Library / Systems Engineering Principles Framework
Jump to passage
In this reading

Link to current text

Published source confirmed at last check

Source changed 2026-10-03 02:22:15 UTC · snapshot created 2026-10-03 03:38:22 UTC · last check 2026-10-03 03:55:20 UTC

SYSE.4:4 - Solution

SYSE.4:4.1 - Select one load-bearing claim and decision question

Start with one named claim episteme already used by a current engineering question. It may come, for example, from a project-system choice account, a linked use-and-system concept, a C.30 or C.32 architecture result, a SYSE.3 realization branch, or a specialist result. Recover:

  • the claim’s subject and predicate;
  • its scope, conditions, configuration or version, and temporal stance;
  • the result or source account from which the claim came;
  • the current uncertainty or failure mode; and
  • the decision or intended Work that would change if reliance narrows, stops, or becomes stronger.

A claim is load-bearing when the decision depends on it. The same claim may be load-bearing for one decision and incidental for another. Name the decision question before selecting a challenge; a generic wish to increase confidence does not yet select assurance Work.

The decision may still be contemplated. For a selected future challenge, record in the plan what result is meant to inform it. Establish any later decision occurrence, choice, gate passage, permission, acceptance, or release through its direct relation and evidence.

SYSE.4:4.2 - Reuse current evidence or choose a challenge that can change reliance

Before selecting or planning new challenge Work, check whether current engineering result epistemes already contain or cite evidence and relations the practitioner can use:

  • a compatible SYSE.10 engineering claim assessment may contain evidence-use relations for the same claim, decision, subject, configuration, use, conditions, interval, and evidence window;
  • a compatible SYSE.11 bounded usable-increment result may contain integration and observed-use evidence for the same actual System, configuration, use, conditions, interval, and evidence window; and
  • a compatible SYSE.14 change-and-release decision may cite evidence, configuration and effectivity basis, and unresolved conditions for the same release question, configuration, effectivity, interval, and evidence window.

Use only the compatible claims and cited evidence, not a neighbouring decision or authority. If the needed evidence already exists, recover the direct result and its descriptive A.10 evidence/provenance path, then reuse or update the engineering-assurance account without creating another WorkPlan. Without a compatible current result, use a qualified direct source. If that still leaves a gap, state how it limits the present answer. Availability or a familiar result name establishes no evidence use.

For a remaining evidence gap, ask: what attainable result could change reliance or make a needed use admissible? Use C.11.DUA to compare obtaining it with proceeding on the present basis, narrowing the claim, deferring, or stopping. Include cost, delay, displaced work, access and applicable evidence requirements. If the current basis already supports the bounded answer, give that answer. If no worthwhile attainable challenge is available, keep the unsupported claim unresolved and identify any continuation whose premises are supplied. Neither outcome requires a new WorkPlan.

When further inquiry is selected, choose a challenge sufficient for its stated purpose. Examples include:

  • a C.16 measurement of one declared Characteristic;
  • a C.32.ACE evaluation over existing architecture-characteristic criteria;
  • a model, simulation, or analysis whose applicability and uncertainty are explicit;
  • a component, integration, or system test against one stated expectation;
  • an inspection or review with an identified subject and criterion;
  • an operating observation under the configuration and conditions named by the claim; or
  • a specialist safety, security, legal, ethical, financial, certification, or acceptance result required by the decision question.

State the challenge’s intended Method, subject, configuration, conditions, scale or criterion, uncertainty treatment, time window, intended result form, and intended evidence use. When Work is still intended, put performer, local system-role-kind condition, Method, window, capability needs, resources, dependencies, and result target in a separate A.15.2 WorkPlan. The engineering-assurance plan cites that WorkPlan; it is not the WorkPlan.

Apply any independence or authorization requirement governing the decision. Even without such a requirement, independent criticism can be useful when it exposes a consequential blind spot or conflict of interest; choose it by its attainable contribution and burden. Establish the performer’s needed competence, authority and any required approval separately. A job title or organizational boundary alone establishes none of these.

SYSE.4:4.3 - Write the engineering-assurance plan

When a future challenge is selected, describe it using the five entries from the Problem frame. Reuse a sufficient existing plan. The plan is usable when a practitioner can recover:

  1. one named claim and its current use conditions;
  2. one decision question;
  3. one challenge and, when future Work needs coordination, a reference to its separately identified A.15.2 WorkPlan;
  4. the configuration, validity, uncertainty, and currentness boundary; and
  5. the earlier answer the practitioner must reassess if the challenge does not support present reliance.

The engineering-assurance plan is a C.2.1 claim-bearing episteme. Its one EntityOfConcern is the named load-bearing claim episteme. Its ClaimGraph states the planned challenge, decision question, validity boundary, and possible affected earlier answer as claims and references concerning that target claim. The other named entities remain participants in those claims rather than a composite subject. Use C.2.1 to identify the claim content, target claim, and effective reference scheme. The plan performs no Work. Changed identity-bearing content can identify another episteme. A later engineering-assurance account is not automatically an edition of the plan merely because a file or identifier is reused; claim identity and any edition relation remain with C.2.1.

Stop at this plan when it makes the next evidence-producing Work and possible revision target explicit. Expand to a fuller artifact—for example, a test matrix, evidence graph, assurance case, or release process—only when the receiving decision needs it.

SYSE.4:4.4 - Recover performed Work, direct results, and evidence use

When the challenge is performed, identify the dated Work and performer through A.15.1 and the applicable assignment and Work-attribution patterns. Then use the direct pattern for the result:

  • C.16 for a measurement result, its uncertainty, and comparability;
  • C.32.ACE for an architecture-characteristic eval programme and its separately typed result;
  • A.1.1 for model applicability, actual model use in assigned Work, or fixed-content coherence;
  • C.28 when the conclusion is causal rather than merely observational;
  • the applicable test, comparison, acceptance, safety, security, legal, certification, or other specialist result pattern when that is the actual claim.

Use A.10 to make the descriptive claim-bound evidence/provenance path replayable. Keep the source, carrier, performed Work, result, result episteme, provenance relation, currentness assessment, evidence use, assurance result, and decision question distinct. The path represents independently established relations; it moves no result and creates no evidence relation. Use G.11 and C.27.TA when source currentness, evidence age, calibration, configuration time, observation window, or decay changes admissible use.

A planned challenge is not evidence. A performed test is not its result. A result becomes evidence for this claim only through the named use and its conditions. Provenance, repetition, automation, or a familiar tool does not widen that use.

SYSE.4:4.5 - Update the engineering-assurance account

After evidence is available, reuse a sufficient engineering-assurance account. Otherwise update or write the account so that the practitioner can recover:

  1. the named target claim and decision question;
  2. the actual challenge Work and its direct result;
  3. the descriptive A.10 evidence/provenance path and currentness basis;
  4. the result’s configuration, condition, scale, uncertainty, and applicability limits;
  5. the practical change in reliance for this decision; and
  6. the smaller earlier answer, specialist question, or next challenge affected by that change.

The account remains a C.2.1 episteme about the named target claim. Its ClaimGraph adds claims about performed Work, direct results, evidence use, changed reliance, and the affected earlier answer. Those named participants do not become a composite EntityOfConcern.

State the reliance change in ordinary language, using a conclusion that fits the case: for example, the claim remains usable for the decision within the stated limits; the practitioner must narrow reliance; the practitioner must replace or withdraw the claim for this use; or available evidence leaves the question unresolved. When the current question is an assurance claim or material reliance threshold, use B.3 for the named assurance-result claim or no-assurance disposition. The engineering-assurance account cites that result; it does not replace it.

When the result is unresolved, identify the missing input that limits this answer—for example, a configuration, comparator, observation window, calibration, causal link, specialist criterion, or independent challenge. Return to the inquiry choice in §4.2 before planning further Work. A narrower supported answer or a justified stop can complete the current question. Missing information establishes neither the target claim nor its negation.

SYSE.4:4.6 - Combine evidence only for the decision question

Some decisions depend on several evidence lines—for example, model predictions, physical tests, integration results, operating observations, and specialist arguments. Keep each direct result and evidence use visible. Combine them only through the composition or assurance rule needed by the decision question, including congruence and scope limits when B.3 is current.

Representations and automation—for example, digital twins, evidence dashboards, traceability graphs, assurance cases, test-report collections, or continuous pipelines—can help maintain these relations. Name the contribution used by the account, then establish model applicability, physical correspondence, evidence completeness, and any downstream acceptance, certification, permission, release, or target-claim use independently.

SYSE.4:4.7 - Apply the result to the smallest affected answer

The practitioner uses the changed reliance to reassess only the smallest earlier answer to which it applies:

  • reassess SYSE.1 when evidence changes the selected project referent, project reason, or boundary;
  • reassess SYSE.2 when observed participation, conditions, effects, benefit, or harm change the linked use or system concept;
  • reassess C.30, C.32, or the applicable architecture decision when criteria, bearers, structures, or trade-offs must change;
  • reassess SYSE.3 when capability, integration, configuration, production, access, or another realization branch fails;
  • use the specialist practice when its safety, security, legal, ethical, financial, certification, acceptance, permission, or release question remains open.

Stop when the account makes the evidence use, its limits, changed reliance, and affected answer clear. Reassess a wider answer only when the narrower answer also fails. The result can become available at any time. The stated relations are claim-dependency and revision relations; they impose no lifecycle stage or prescribed Work order.