← Part 26

AQ-DEMO-ARCH-001

The eleven-stage AQ-NODE demonstration loop, the layer and trust boundary owning each stage, and the six distinctions D-1..D-6 the demonstration must make visible to an observer.

Charter artifact · gated by Part 26 · revision 0, draft for internal review

AQ-DEMO-ARCH-001 — AQ-NODE demonstration architecture

STATUS AND SCOPE

EVIDENCE STATUS

Nothing in this document has been built. No stage below has reached laboratory validation. The architecture is specified at tier CA with the acquisition and evidence stages scoped for Y1 implementation. Programme evidence level for the loop as a whole: Concept for the integrated loop, Theory for the authority and trust-state logic. No performance figure appears in this document because none has been measured.

This document specifies the demonstration architecture of AQ-NODE-01 (canonical; the same articles appear as AKQ-NODE-01 in Parts up to 12). Its subject is not a product demonstration. Its subject is the observable reconstruction of a single decision cycle: what was measured, what was inferred, what was not known, what was permitted, what was authorised, and what physically happened. The demonstration exists to make the design commitments DC-1 through DC-5 visible rather than asserted.

The loop is defined once and reused at every demonstration maturity level. DM-0 through DM-6 differ only in the realism of the stimulus at stage S1, in whether stage S8 drives a controlled physical effect or a simulated one, and in who is present. They do not differ in the stages, the boundaries, or the record. A demonstration that reaches a higher DM level by removing a stage is not the same demonstration.

THE ELEVEN-STAGE LOOP

StageOwning layerBoundaryWhat the observer seesEvidence record
S1 multi-source inputL1 Sensing & Entropy TrustTB-1 → TB-2Each source separately, with its identifier, its acquisition timestamp and its provenance class. No merged value is shown at this stage; a source that reports nothing is listed as reporting nothing.EV-S1
S2 time alignmentL2 Timing & Temporal IntegrityTB-2Each sample placed on the common timebase, the identity of the reference used, and the alignment residual per sample. Samples that cannot be aligned appear as unaligned; they are not discarded and not back-filled.EV-S2
S3 quality evaluationL1 with L2TB-2A three-valued verdict per source — usable, degraded, undetermined — and the named check that produced it, with the applicable failure-mode code from F-1..F-14 where one applies.EV-S3
S4 state constructionL4 Dynamic Trust State (AQ-TSE-01)TB-3The resulting trust state (NORMAL, RESTRICTED, CRITICAL, DENY, RECOVERING) together with every input that contributed and the direction of each contribution.EV-S4
S5 uncertainty representationL4TB-3An explicit uncertainty object. Every field carries MEASURED, DERIVED or MODELLED, and every field with no defined bound says so in those words.EV-S5
S6 decisionL5 Command AuthorityTB-3The Q4 evaluation and the proposed outcome drawn from execute, execute-restricted, safe-hold, abstain, deny — with the reason expressed as a decision boundary crossing (B-1..B-5) or as an unresolved conflict (CF-1..CF-7).EV-S6
S7 authorisation separationL3 with L5TB-3 → TB-4The Q1–Q3 result and the Q4 result rendered apart, never combined into one verdict, with the conjunction rule stated on the surface the observer is looking at.EV-S7
S8 simulated or controlled responseL5 acting on L0TB-4 (hardware-gated)The interlock state, the actuation attempt, and an unambiguous label distinguishing a controlled bench effect from a simulated stimulus. The label is part of the record, not a caption added for the audience.EV-S8
S9 telemetryL7 Network & OrchestrationTB-5The emitted stream carrying the same values that crossed TB-4, with no re-derivation, re-rounding or re-ordering between the decision and the stream.EV-S9
S10 traceabilityL6 Evidence & Provenance FabricTB-5The record identifiers for S1..S9 and their chain linkage, presented as identifiers an observer can write down and later quote back.EV-S10
S11 replayL6 with L9 Systems Engineering & Safety GovernanceTB-5The same cycle reconstructed from the Evidence Fabric alone, and the replayed outcome placed beside the live outcome. A divergence is a finding, not a display artefact.EV-S11

Figure 1 - the eleven-stage loop across the AQ-NODE-01 trust boundaries

  TB-1 physical / system        TB-2 deterministic acquisition (FPGA)
  +---------------------+      +----------------------------------------+
  | S1 multi-source     | ---> | S2 time alignment           (L2)       |
  |    input      (L1)  |      | S3 quality evaluation       (L1 + L2)  |
  +---------------------+      +----------------------------------------+
                                                |
                                                v
                               TB-3 trust reasoning
                               +----------------------------------------+
                               | S4 state construction       (L4)       |
                               | S5 uncertainty representation (L4)     |
                               | S6 decision                 (L5)       |
                               +----------------------------------------+
                                                |
         Q1-Q3 validity (L3) ----------------> S7 <---------- Q4 authority (L5)
                                                |
                                                v
                               TB-4 decision / physical effect (gated)
                               +----------------------------------------+
                               | S8 controlled or simulated response    |
                               +----------------------------------------+
                                                |
                                                v
                               TB-5 runtime / evidence
                               +----------------------------------------+
                               | S9  telemetry               (L7)       |
                               | S10 traceability            (L6)       |
                               | S11 replay                  (L6 + L9)  |
                               +----------------------------------------+
                                                |
                    next acquisition cycle <----+     (S11 is read-only:
                                                       replay never writes
                                                       to live trust state)

STAGE NOTES

  • S3 is three-valued by construction. A boolean quality flag cannot express DC-2. A source that fails to report is undetermined; it is never carried forward as nominal, and no stage downstream is permitted to treat undetermined as usable for the sake of producing a state.
  • S5 exists as a separate stage on purpose. If uncertainty is computed inside the decision it becomes invisible, and the demonstration loses its central claim. The uncertainty object is emitted before S6 reads it and is recorded whether or not the decision uses it.
  • S7 enforces the conjunction, not a score. Q1 (who sent it), Q2 (cryptographically valid) and Q3 (authorised now) are hard constraints. Q4 asks only whether the system should execute under the current trust state, and can only reduce what Q1–Q3 already allowed. There is no path by which a favourable trust state repairs a Q1–Q3 failure.
  • S8 is gated in hardware at TB-4. The gate is a physical element, not a software predicate, so that a fault in trust reasoning cannot by itself produce an effect. In Y1 the effect is a bench effect or a simulated stimulus; both are labelled in the record.
  • S11 must not close the loop. Replay reconstructs; it does not restore. A replayed cycle is marked as replay in the Evidence Fabric and cannot raise a trust state. Recovery from RECOVERING follows the full recovery sequence under DC-4 and no other path.

Figure 2 - authorisation held apart from validity (S7)

  Q1 who sent it       -> pass / fail  |
  Q2 signature valid   -> pass / fail  |  HARD CONSTRAINTS: all must pass
  Q3 authorised now    -> pass / fail  |
                              |
              all pass? ------+------> no  -> deny
                              |               (Q4 is not consulted and
                             yes               cannot reverse this)
                              |
     Q4 should the system execute under the current trust state?
                              |
     NORMAL      -> execute                 |
     RESTRICTED  -> execute-restricted      |  Q4 may only REDUCE
     CRITICAL    -> safe-hold or abstain    |  the permission set
     RECOVERING  -> abstain                 |  granted by Q1-Q3
     DENY        -> deny                    |

THE SIX DISTINCTIONS THE DEMONSTRATION MUST MAKE VISIBLE

D-1 PROVENANCE CLASS

Every value the observer sees is tagged MEASURED, DERIVED or MODELLED (DC-1), at the point of display and in the record. An untagged value is a defect, not a simplification.

D-2 SYSTEM OUTPUT VERSUS DEMONSTRATION SCAFFOLDING

Injected stimulus, bench fixtures and simulated actuation are distinguishable from system-produced values without asking the presenter. The scaffolding boundary is recorded in EV-S1 and EV-S8 and survives into replay.

D-3 WHAT THE SYSTEM DID NOT KNOW

The demonstration shows absence as a first-class value (DC-2). For the cycle on screen the observer can enumerate: which sources did not report, which fields are undetermined, which bounds are undefined, and which of those absences changed the outcome. A cycle in which nothing was unknown is reported as such explicitly; silence is never the representation of completeness. This is the distinction most easily lost to a tidy display, and it is the one that most directly evidences DC-2.

D-4 THE NON-EXECUTE OUTCOMES ARE NOT INTERCHANGEABLE

safe-hold, abstain and deny arise from different causes and are displayed as different outcomes. abstain means insufficient confidence to authorize (DC-3) and is a permitted, non-failure output; deny means a constraint was violated. Collapsing them into “did not run” destroys the distinction the loop exists to demonstrate.

D-5 AUTHORISATION HELD APART FROM VALIDITY

The observer sees, as two separate results, that a command was valid (Q1–Q3) and whether it was authorised to execute now (Q4). The demonstration must include at least one cycle in which a fully valid, correctly signed, properly authorised command is not executed because the trust state does not permit it — and at least one in which a favourable trust state does not rescue a Q1–Q3 failure. Until an observer has seen both, D-5 has not been demonstrated.

D-6 ASYMMETRY AND RECONSTRUCTION

Trust falls on a single qualifying observation and rises only through the complete recovery sequence (DC-4); the demonstration shows the fall and then shows the recovery as a sequence of steps, never as a reset control. Separately, any consequential transition on screen is reconstructable from the Evidence Fabric alone (DC-5), with no access to the live node.

WHAT THE DEMONSTRATION MUST NOT IMPLY

PROHIBITED IMPLICATIONS

No stage, caption, label or narration may imply that the loop is interception-proof, unbreakable, information-theoretically sound at system level, flight-qualified, space-proven or operational. The reach ladder position of any demonstration is stated plainly: bench, or metro fibre and free-space, and no rung above the one actually occupied. Advisory analysis (L8) may appear in the loop only as an input to human interpretation and never as a stage that produces, modifies or gates a decision. No evidence level above the stated tier may be implied

ACCEPTANCE

The demonstration architecture is accepted when an observer who has not read this document can, unaided, (a) name the provenance class of any value shown, (b) list what the system did not know in the cycle just run, (c) state separately whether the command was valid and whether it was authorised, and (d) select any consequential transition and have it reconstructed from the Evidence Fabric alone. Acceptance is not defined against any performance figure. No timing, throughput or detection metric is asserted at this tier; targets for each will be established from measurement once bench acquisition exists, and will be recorded against the Part 12 evidence ladder at the level actually reached.