AQ-ARR-001 — Architecture Risk Register
This register tracks risks to the architecture: ways in which the Part 12 design could be wrong, unprovable or defeated, as distinct from risks to a schedule or a budget. It is deliberately led by the four ways the central thesis of the design could be falsified, because a register that tracks only implementation hazards implicitly assumes the thesis is correct, and that assumption is the largest risk the programme carries.
That a trust state assembled from provenance-tagged observations (AQ-TSE-01, layer L4) produces command-authority decisions demonstrably better than a fixed policy using Q1–Q3 alone plus a small set of interlocks — and that where it cannot, it abstains rather than guesses. Every element of that sentence is currently at Concept. R-01 through R-04 are the four ways it could be false.
SCALES
Every likelihood in this register is an engineering judgement at Concept evidence level. None is a measured frequency, and none may be quoted as one. The purpose of the scoring is to order work, and the purpose of each row is to name the observation that will eventually replace the judgement.
- Likelihood — Remote | Unlikely | Credible | Likely | Expected.
- Consequence — Minor (local rework) | Significant (a layer is re-scoped) | Severe (a design commitment cannot be met) | Thesis-invalidating (the architecture’s reason for existing does not hold).
- Detectability — By design (an instrument already reports it) | With instrumentation (an instrument must be added) | In hindsight (visible only after the event it caused) | Process-only (no instrument can see it; only a review discipline can).
GATE LADDER
Gates are the points at which risks are re-scored and, where their retiring observation exists, retired. They align the evidence ladder to the reach ladder and to demonstration maturity.
| Gate | What it is | Evidence level reached | Demo |
|---|---|---|---|
| G1 | Architecture and interface review complete; assumption register populated; falsification criteria pre-registered | Theory | DM-0 |
| G2 | Simulation campaign against the decision function and the trust-state model | Simulation | DM-1 |
| G3 | Single AQ-NODE-01 on the optical bench, instrumented | Lab validation | DM-2 |
| G4 | Two nodes across metro fibre or a short free-space span | Field validation | DM-3 |
| G5 | Terminal on a moving platform; HAPS relay rung | Dynamic platform | DM-4 |
| G6 | CubeSat demonstrator | Flight / space | DM-5 |
| G7 | Service-grade operation against an external schedule | Operational demonstration | DM-6 |
R-01 TO R-04 — FALSIFICATION OF THE CENTRAL THESIS
These four risks share one evaluation, pre-registered at G1 and executed from G2 onward. Pre-registration is the whole mechanism: the scenario sets, the comparison statistic and the response to each outcome are written and signed before any result exists, so that a disappointing result cannot be reinterpreted into a satisfactory one afterwards.
Figure 1 - Pre-registered evaluation that decides R-01, R-02, R-03 and R-04
pre-registered scenario sets, held out, fixed at G1
nominal | degraded | adversarial | ambiguous-input
|
+---------------------+---------------------+
| |
BASELINE POLICY L4 TRUST-STATE POLICY
Q1-Q3 + fixed interlocks AQ-TSE-01, DC-1 to DC-5
no trust state Q4 may only reduce
| |
+---------------------+---------------------+
|
same sets, same inputs, same operators
|
+----------+-------------+-------------+----------------+
| | | |
separation no separation worse outcomes abstention
shown R-01 CONFIRMED R-03 suspected dominates
| | | R-04 CONFIRMED
proceed re-scope L4 to adversarial |
to G4 evidence annotation input-cost decompose causes:
with the only, or delete it analysis per insufficiency /
measured (Q4 authority input, then plumbing /
separation removed) re-derive threshold error
| influence bounds
if no result could have
changed the weights at all:
R-02 CONFIRMED
The L4 trust state changes decisions no more usefully than the baseline policy. Confirming observation: across the held-out sets, the distribution of outcomes (execute, execute-restricted, safe-hold, abstain, deny) from AQ-TSE-01 is not separable from the baseline by the pre-registered statistic, or separates in the wrong direction. Pre-registered response: L4 is re-scoped from a decision input to an evidence annotation — it keeps its DC-5 value and loses Q4 authority entirely — or it is deleted. Likelihood Credible · Consequence Thesis-invalidating · Detectability With instrumentation · Retired at G4.
The function mapping observations to trust state cannot be shown wrong by any observation, because every outcome is explicable after the fact. Confirming observation: reviewers cannot state, before a run, a result that would require a weight to change; or no weight in the function traces to a measured distribution with a stated estimator and residual. Pre-registered response: every weight must be derived from measurement or removed from the function and re-declared as an operator-visible constant carrying an owner and a review date, so that it is at least visibly arbitrary rather than invisibly so. Likelihood Likely · Consequence Thesis-invalidating · Detectability Process-only · Retired at G1 for the process test, G3 for the measured derivation. This is the most dangerous of the four precisely because no instrument reports it.
An adversary moves the trust state through whichever input is cheapest to influence, rather than the one the design treats as significant. Confirming observation: an adversarial cost analysis plus bench injection shows a state transition achievable at materially lower cost through one input than through the design’s assumed attack path; or a single input can alone drive the state permissively, or alone force DENY as a denial-of-service. Pre-registered response: a per-input influence bound — no single input may alone cause a transition in the permissive direction — plus a required cost-analysis artefact for every registered input, and re-derivation of the correlation groups in AS-10. Likelihood Likely · Consequence Severe · Detectability With instrumentation · Retired at G5, because the cheapest input on a moving platform is not the cheapest input on a bench.
DC-3 abstention is correct and so frequent that operators route around the system, which converts a designed refusal into an ignored one. Confirming observation: measured abstention rate on nominal scenario sets exceeds the rate operators stated they would tolerate — a figure established with operators before the measurement, never adjusted after it — or field observation shows habitual override. Pre-registered response: decompose abstentions into genuine insufficiency, missing input plumbing, and threshold error; only genuine insufficiency may remain. Lowering the confidence bar to reduce abstention without a corresponding gain in evidence is prohibited, because it converts DC-3 into decoration. Likelihood Credible · Consequence Thesis-invalidating · Detectability By design · Retired at G4.
ARCHITECTURAL RISK REGISTER
| ID | Risk | Likelihood | Consequence | Detectability | Gate |
|---|---|---|---|---|---|
| R-05 | Correlated-input miscounting: inputs sharing a common cause are treated as independent confirmations, so confidence rises during a common-mode fault (AS-02, AS-10) | Likely | Severe | With instrumentation | G3 |
| R-06 | Trust contagion between nodes: a degraded node depresses peers that have no independent cause to degrade, or a compromised node exports NORMAL and holds peers up | Credible | Severe | In hindsight | G4 two-node, G7 fleet scale |
| R-07 | Evidence-store unavailability: L6 cannot accept a write, so DC-5 cannot be satisfied for a transition the operator wants executed | Likely | Significant | By design | G3 |
| R-08 | Configuration drift: deployed thresholds and input declarations diverge from the reviewed set, so evidence describes a configuration that is no longer running | Expected | Severe | With instrumentation | G1 mechanism, G4 fleet |
| R-09 | Threshold overfitting: thresholds are tuned until they perform on the scenario sets used to derive them and generalise to nothing | Likely | Thesis-invalidating | Process-only | G2 |
| R-10 | Override normalisation: operator override becomes the routine path, so the measured behaviour of the system is the override policy and not the designed one | Credible | Severe | By design | G4 |
| R-11 | Cross-rung evidence transfer: results from one reach rung are cited for a rung whose channel, thermal and pointing regimes were never measured (AS-18) | Expected | Severe | Process-only | G5, G6 |
| R-12 | Key custody boundary violation, including side-channel egress that no API-level audit would find (AS-06) | Credible | Severe | With instrumentation | G3 |
| R-13 | Unobserved loss of time discipline: holdover exceeds its bound without the node reporting it, corrupting evidence ordering and L4 windowing (AS-04, AS-05) | Credible | Severe | With instrumentation | G3 |
| R-14 | Advisory creep: an L8 output becomes load-bearing by habit — through an operator procedure or a default — while remaining advisory in the documentation (AS-16) | Likely | Severe | Process-only | G2 dataflow, G4 procedure |
| R-15 | Deterministic acquisition path accretes features until TB-2 is no longer reviewable as a fixed-function element, dissolving the boundary that makes MEASURED tags meaningful | Likely | Severe | Process-only | G1, re-scored every gate |
| R-16 | Claim drift: external description of the programme outruns its evidence level, so a design study is read as a validated capability | Expected | Severe | Process-only | G1, re-scored every gate |
| R-17 | Non-reproducible measurement environment: a bench result cannot be reproduced on a second build, so no measurement in the programme can be independently checked (AS-17) | Credible | Severe | With instrumentation | G3 |
MITIGATIONS AND THEIR EVIDENCE
A mitigation is only as real as the observation that shows it is working. The third column is what distinguishes a mitigation from an intention.
| ID | Design mitigation | Observation that shows the mitigation works |
|---|---|---|
| R-05 | Correlation groups declared at input registration; evidence from one group contributes once regardless of member count; group membership re-derived from measured cross-correlation whenever an input is added | A stress campaign in which a common-mode disturbance moves the trust state by the amount attributable to one input, not to the number of affected inputs |
| R-06 | Peer trust state is an input, never a substitute for local observation; a node may not enter NORMAL on peer assertion alone; peer influence is bounded by the same per-input rule adopted for R-03 | Two-node bench test: degrade one node and confirm the peer’s state moves only where it has its own observation; then hold a compromised node at NORMAL and confirm the peer does not inherit it |
| R-07 | A consequential transition that cannot be recorded does not execute; the node moves to safe-hold. This trades availability for reconstructability by design, and the cost of that trade is measured rather than assumed | Induced store outages during scheduled decisions, with the resulting hold rate measured and reported to operators as the price of DC-5 — the number is an output of G3, not a target set beforehand |
| R-08 | Running configuration is measured and carried into every evidence record, so a decision is always attributable to a specific configuration hash; divergence from the reviewed set is itself an L4 input | Deliberate drift injected on one node and detected from the evidence stream alone, without querying the node — the same path an investigator would have after the fact |
| R-09 | Derivation sets and evaluation sets are separated at G1 and never merged; evaluation sets are held out and versioned; any re-tuning invalidates prior evaluation results | Performance on a scenario set constructed after the thresholds were frozen, by someone who did not derive them |
| R-10 | Override is a first-class recorded decision with its own evidence record, its own authority check and a reason field; override rate is a reported metric of the system, not an absence of one | A measured override rate with causes classified, reviewed at every gate; a rising rate is treated as a defect in L4, not as operator error |
| R-11 | Evidence rows are bound to the reach rung at which they were produced and cannot be inherited upward; documents citing a result state its rung | A citation audit at each gate in which every capability statement resolves to an evidence record at the rung it names |
| R-12 | In-boundary generation and use; handles cross TB-3, keys do not; side-channel characterisation treated as a required measurement rather than an optional one | Enumerated egress paths each demonstrated to refuse, plus a published bound on side-channel recovery effort for the actual build |
| R-13 | Discipline state is an explicit L4 input; holdover beyond its measured bound forces degradation under DC-4 rather than continuing at NORMAL | Reference withheld without warning; node reports holdover and degrades within the interval it claims, verified against an independent reference |
| R-14 | L8 output is tagged and refused by L5 on Q1–Q3; procedures that reference an advisory output are reviewed as design artefacts, because a procedure can make an advisory load-bearing without a line of code changing | Poisoned-advisory injection leaving the decision outcome unchanged, plus a procedure audit at G4 that finds no step conditioned solely on an L8 value |
| R-15 | TB-2 carries an explicit complexity budget and a fixed-function rule; any addition requires an argument that determinism is preserved, reviewed at the gate | A boundary review at each gate in which the acquisition path remains exhaustively enumerable, with the enumeration recorded |
| R-16 | Every external statement of capability carries its evidence level and reach rung; the prohibited-claims list is a review gate, not a style preference | A claims audit at each gate in which each statement resolves to a register row or an evidence record, and unresolvable statements are withdrawn |
| R-17 | Reproducible builds plus a second, independently assembled bench; a measurement is provisional until reproduced | Bit-identical rebuild in a second environment, and a headline measurement reproduced on the second bench within a stated agreement bound |
REVIEW AND RETIREMENT
- The register is re-scored at every gate. Scores move on evidence; a score that has moved without a new observation is a defect in this document.
- A risk is retired only by its named retiring observation, recorded in the Evidence Fabric with a record identifier written into the row. No risk is retired by consensus, by elapsed time, or because the programme has moved on to the next rung.
- R-08, R-11, R-14, R-15 and R-16 are never fully retired. They are process risks that recur with every change, and each is re-scored at every gate for the life of the programme.
- Any risk scored Thesis-invalidating that is confirmed halts progression to the next gate until its pre-registered response has been executed. That is what pre-registration is for.
Three things together: the observation named in the row, recorded with its evidence-record identifier; the assumption rows in AQ-AAR-001 that the observation also touched, updated in the same pass; and a statement of the rung and build on which it was obtained. Missing any one, the row stays open.
Retiring a risk at G3 says the risk did not materialise on one node, on one bench, at one rung, under one configuration. It does not say the risk is absent from a two-node link, a moving platform, or a fleet, and it does not support describing the system as validated, flight-ready or fit for operational use. R-11 and R-16 exist to catch exactly that inference, and they apply to readers of this register first.