← Part 12

AQ-ARR-001

Architectural risks with likelihood, consequence, detectability, mitigation and retiring gate — including the four falsification modes that would invalidate the central thesis of the trust architecture.

Charter artifact · gated by Part 12 · revision 0, draft for internal review

AQ-ARR-001 — Architecture Risk Register

This register tracks risks to the architecture: ways in which the Part 12 design could be wrong, unprovable or defeated, as distinct from risks to a schedule or a budget. It is deliberately led by the four ways the central thesis of the design could be falsified, because a register that tracks only implementation hazards implicitly assumes the thesis is correct, and that assumption is the largest risk the programme carries.

THE THESIS UNDER TEST

That a trust state assembled from provenance-tagged observations (AQ-TSE-01, layer L4) produces command-authority decisions demonstrably better than a fixed policy using Q1–Q3 alone plus a small set of interlocks — and that where it cannot, it abstains rather than guesses. Every element of that sentence is currently at Concept. R-01 through R-04 are the four ways it could be false.

SCALES

Every likelihood in this register is an engineering judgement at Concept evidence level. None is a measured frequency, and none may be quoted as one. The purpose of the scoring is to order work, and the purpose of each row is to name the observation that will eventually replace the judgement.

  • Likelihood — Remote | Unlikely | Credible | Likely | Expected.
  • Consequence — Minor (local rework) | Significant (a layer is re-scoped) | Severe (a design commitment cannot be met) | Thesis-invalidating (the architecture’s reason for existing does not hold).
  • Detectability — By design (an instrument already reports it) | With instrumentation (an instrument must be added) | In hindsight (visible only after the event it caused) | Process-only (no instrument can see it; only a review discipline can).

GATE LADDER

Gates are the points at which risks are re-scored and, where their retiring observation exists, retired. They align the evidence ladder to the reach ladder and to demonstration maturity.

GateWhat it isEvidence level reachedDemo
G1Architecture and interface review complete; assumption register populated; falsification criteria pre-registeredTheoryDM-0
G2Simulation campaign against the decision function and the trust-state modelSimulationDM-1
G3Single AQ-NODE-01 on the optical bench, instrumentedLab validationDM-2
G4Two nodes across metro fibre or a short free-space spanField validationDM-3
G5Terminal on a moving platform; HAPS relay rungDynamic platformDM-4
G6CubeSat demonstratorFlight / spaceDM-5
G7Service-grade operation against an external scheduleOperational demonstrationDM-6

R-01 TO R-04 — FALSIFICATION OF THE CENTRAL THESIS

These four risks share one evaluation, pre-registered at G1 and executed from G2 onward. Pre-registration is the whole mechanism: the scenario sets, the comparison statistic and the response to each outcome are written and signed before any result exists, so that a disappointing result cannot be reinterpreted into a satisfactory one afterwards.

Figure 1 - Pre-registered evaluation that decides R-01, R-02, R-03 and R-04

        pre-registered scenario sets, held out, fixed at G1
     nominal  |  degraded  |  adversarial  |  ambiguous-input
                              |
        +---------------------+---------------------+
        |                                           |
  BASELINE POLICY                          L4 TRUST-STATE POLICY
  Q1-Q3 + fixed interlocks                 AQ-TSE-01, DC-1 to DC-5
  no trust state                           Q4 may only reduce
        |                                           |
        +---------------------+---------------------+
                              |
            same sets, same inputs, same operators
                              |
     +----------+-------------+-------------+----------------+
     |          |                           |                |
  separation  no separation            worse outcomes     abstention
  shown       R-01 CONFIRMED           R-03 suspected     dominates
     |          |                           |             R-04 CONFIRMED
  proceed    re-scope L4 to            adversarial          |
  to G4      evidence annotation       input-cost        decompose causes:
  with the   only, or delete it        analysis per      insufficiency /
  measured   (Q4 authority             input, then       plumbing /
  separation removed)                  re-derive         threshold error
              |                        influence bounds
           if no result could have
           changed the weights at all:
           R-02 CONFIRMED
R-01 — NO DECISION ADVANTAGE

The L4 trust state changes decisions no more usefully than the baseline policy. Confirming observation: across the held-out sets, the distribution of outcomes (execute, execute-restricted, safe-hold, abstain, deny) from AQ-TSE-01 is not separable from the baseline by the pre-registered statistic, or separates in the wrong direction. Pre-registered response: L4 is re-scoped from a decision input to an evidence annotation — it keeps its DC-5 value and loses Q4 authority entirely — or it is deleted. Likelihood Credible · Consequence Thesis-invalidating · Detectability With instrumentation · Retired at G4.

R-02 — UNFALSIFIABLE WEIGHTING

The function mapping observations to trust state cannot be shown wrong by any observation, because every outcome is explicable after the fact. Confirming observation: reviewers cannot state, before a run, a result that would require a weight to change; or no weight in the function traces to a measured distribution with a stated estimator and residual. Pre-registered response: every weight must be derived from measurement or removed from the function and re-declared as an operator-visible constant carrying an owner and a review date, so that it is at least visibly arbitrary rather than invisibly so. Likelihood Likely · Consequence Thesis-invalidating · Detectability Process-only · Retired at G1 for the process test, G3 for the measured derivation. This is the most dangerous of the four precisely because no instrument reports it.

R-03 — MANIPULABILITY VIA THE CHEAPEST INPUT

An adversary moves the trust state through whichever input is cheapest to influence, rather than the one the design treats as significant. Confirming observation: an adversarial cost analysis plus bench injection shows a state transition achievable at materially lower cost through one input than through the design’s assumed attack path; or a single input can alone drive the state permissively, or alone force DENY as a denial-of-service. Pre-registered response: a per-input influence bound — no single input may alone cause a transition in the permissive direction — plus a required cost-analysis artefact for every registered input, and re-derivation of the correlation groups in AS-10. Likelihood Likely · Consequence Severe · Detectability With instrumentation · Retired at G5, because the cheapest input on a moving platform is not the cheapest input on a bench.

R-04 — UNACCEPTABLE ABSTENTION RATE

DC-3 abstention is correct and so frequent that operators route around the system, which converts a designed refusal into an ignored one. Confirming observation: measured abstention rate on nominal scenario sets exceeds the rate operators stated they would tolerate — a figure established with operators before the measurement, never adjusted after it — or field observation shows habitual override. Pre-registered response: decompose abstentions into genuine insufficiency, missing input plumbing, and threshold error; only genuine insufficiency may remain. Lowering the confidence bar to reduce abstention without a corresponding gain in evidence is prohibited, because it converts DC-3 into decoration. Likelihood Credible · Consequence Thesis-invalidating · Detectability By design · Retired at G4.

ARCHITECTURAL RISK REGISTER

IDRiskLikelihoodConsequenceDetectabilityGate
R-05Correlated-input miscounting: inputs sharing a common cause are treated as independent confirmations, so confidence rises during a common-mode fault (AS-02, AS-10)LikelySevereWith instrumentationG3
R-06Trust contagion between nodes: a degraded node depresses peers that have no independent cause to degrade, or a compromised node exports NORMAL and holds peers upCredibleSevereIn hindsightG4 two-node, G7 fleet scale
R-07Evidence-store unavailability: L6 cannot accept a write, so DC-5 cannot be satisfied for a transition the operator wants executedLikelySignificantBy designG3
R-08Configuration drift: deployed thresholds and input declarations diverge from the reviewed set, so evidence describes a configuration that is no longer runningExpectedSevereWith instrumentationG1 mechanism, G4 fleet
R-09Threshold overfitting: thresholds are tuned until they perform on the scenario sets used to derive them and generalise to nothingLikelyThesis-invalidatingProcess-onlyG2
R-10Override normalisation: operator override becomes the routine path, so the measured behaviour of the system is the override policy and not the designed oneCredibleSevereBy designG4
R-11Cross-rung evidence transfer: results from one reach rung are cited for a rung whose channel, thermal and pointing regimes were never measured (AS-18)ExpectedSevereProcess-onlyG5, G6
R-12Key custody boundary violation, including side-channel egress that no API-level audit would find (AS-06)CredibleSevereWith instrumentationG3
R-13Unobserved loss of time discipline: holdover exceeds its bound without the node reporting it, corrupting evidence ordering and L4 windowing (AS-04, AS-05)CredibleSevereWith instrumentationG3
R-14Advisory creep: an L8 output becomes load-bearing by habit — through an operator procedure or a default — while remaining advisory in the documentation (AS-16)LikelySevereProcess-onlyG2 dataflow, G4 procedure
R-15Deterministic acquisition path accretes features until TB-2 is no longer reviewable as a fixed-function element, dissolving the boundary that makes MEASURED tags meaningfulLikelySevereProcess-onlyG1, re-scored every gate
R-16Claim drift: external description of the programme outruns its evidence level, so a design study is read as a validated capabilityExpectedSevereProcess-onlyG1, re-scored every gate
R-17Non-reproducible measurement environment: a bench result cannot be reproduced on a second build, so no measurement in the programme can be independently checked (AS-17)CredibleSevereWith instrumentationG3

MITIGATIONS AND THEIR EVIDENCE

A mitigation is only as real as the observation that shows it is working. The third column is what distinguishes a mitigation from an intention.

IDDesign mitigationObservation that shows the mitigation works
R-05Correlation groups declared at input registration; evidence from one group contributes once regardless of member count; group membership re-derived from measured cross-correlation whenever an input is addedA stress campaign in which a common-mode disturbance moves the trust state by the amount attributable to one input, not to the number of affected inputs
R-06Peer trust state is an input, never a substitute for local observation; a node may not enter NORMAL on peer assertion alone; peer influence is bounded by the same per-input rule adopted for R-03Two-node bench test: degrade one node and confirm the peer’s state moves only where it has its own observation; then hold a compromised node at NORMAL and confirm the peer does not inherit it
R-07A consequential transition that cannot be recorded does not execute; the node moves to safe-hold. This trades availability for reconstructability by design, and the cost of that trade is measured rather than assumedInduced store outages during scheduled decisions, with the resulting hold rate measured and reported to operators as the price of DC-5 — the number is an output of G3, not a target set beforehand
R-08Running configuration is measured and carried into every evidence record, so a decision is always attributable to a specific configuration hash; divergence from the reviewed set is itself an L4 inputDeliberate drift injected on one node and detected from the evidence stream alone, without querying the node — the same path an investigator would have after the fact
R-09Derivation sets and evaluation sets are separated at G1 and never merged; evaluation sets are held out and versioned; any re-tuning invalidates prior evaluation resultsPerformance on a scenario set constructed after the thresholds were frozen, by someone who did not derive them
R-10Override is a first-class recorded decision with its own evidence record, its own authority check and a reason field; override rate is a reported metric of the system, not an absence of oneA measured override rate with causes classified, reviewed at every gate; a rising rate is treated as a defect in L4, not as operator error
R-11Evidence rows are bound to the reach rung at which they were produced and cannot be inherited upward; documents citing a result state its rungA citation audit at each gate in which every capability statement resolves to an evidence record at the rung it names
R-12In-boundary generation and use; handles cross TB-3, keys do not; side-channel characterisation treated as a required measurement rather than an optional oneEnumerated egress paths each demonstrated to refuse, plus a published bound on side-channel recovery effort for the actual build
R-13Discipline state is an explicit L4 input; holdover beyond its measured bound forces degradation under DC-4 rather than continuing at NORMALReference withheld without warning; node reports holdover and degrades within the interval it claims, verified against an independent reference
R-14L8 output is tagged and refused by L5 on Q1–Q3; procedures that reference an advisory output are reviewed as design artefacts, because a procedure can make an advisory load-bearing without a line of code changingPoisoned-advisory injection leaving the decision outcome unchanged, plus a procedure audit at G4 that finds no step conditioned solely on an L8 value
R-15TB-2 carries an explicit complexity budget and a fixed-function rule; any addition requires an argument that determinism is preserved, reviewed at the gateA boundary review at each gate in which the acquisition path remains exhaustively enumerable, with the enumeration recorded
R-16Every external statement of capability carries its evidence level and reach rung; the prohibited-claims list is a review gate, not a style preferenceA claims audit at each gate in which each statement resolves to a register row or an evidence record, and unresolvable statements are withdrawn
R-17Reproducible builds plus a second, independently assembled bench; a measurement is provisional until reproducedBit-identical rebuild in a second environment, and a headline measurement reproduced on the second bench within a stated agreement bound

REVIEW AND RETIREMENT

  • The register is re-scored at every gate. Scores move on evidence; a score that has moved without a new observation is a defect in this document.
  • A risk is retired only by its named retiring observation, recorded in the Evidence Fabric with a record identifier written into the row. No risk is retired by consensus, by elapsed time, or because the programme has moved on to the next rung.
  • R-08, R-11, R-14, R-15 and R-16 are never fully retired. They are process risks that recur with every change, and each is re-scored at every gate for the life of the programme.
  • Any risk scored Thesis-invalidating that is confirmed halts progression to the next gate until its pre-registered response has been executed. That is what pre-registration is for.
WHAT RETIREMENT REQUIRES

Three things together: the observation named in the row, recorded with its evidence-record identifier; the assumption rows in AQ-AAR-001 that the observation also touched, updated in the same pass; and a statement of the rung and build on which it was obtained. Missing any one, the row stays open.

WHAT RETIREMENT DOES NOT LICENSE

Retiring a risk at G3 says the risk did not materialise on one node, on one bench, at one rung, under one configuration. It does not say the risk is absent from a two-node link, a moving platform, or a fleet, and it does not support describing the system as validated, flight-ready or fit for operational use. R-11 and R-16 exist to catch exactly that inference, and they apply to readers of this register first.