AQ-IOP-001 — Independent Observer Protocol
PURPOSE
This document defines how a person who is not part of the Akasha-Q programme witnesses a run, and what the programme may say afterwards. It exists for one reason: the programme intends to make claims about the measured behaviour of hardware and software it designed, built and instrumented itself, and a run witnessed only by the people who built the apparatus cannot settle whether such a claim is true. AQ-IOP-001 is an L9 (Systems Engineering & Safety Governance) instrument operating on L6 (Evidence & Provenance Fabric) records.
The protocol governs witnessing only. An observed run does not certify, accredit or approve anything, and it raises no claim by itself. It establishes a narrower and more useful thing: that a procedure written down in advance was executed as written, in the order written, on the equipment described, and that the recorded observables are what the instruments produced.
No run has been conducted under this protocol. No Akasha-Q element has reached Lab validation. Every reference below to a run, an article or an instrument describes an intended procedure applied to an intended article, not an event that has occurred. Issuing this protocol raises no element's position on the Part 12 evidence ladder and no rung on the reach ladder.
WHAT AN OBSERVER IS, AND IS NOT
- An observer is a named individual who attends in person, or over a continuous feed whose path and custody are identified in the dossier, and who signs their own record in their own words.
- An observer is not a technical reviewer. Whether the design is sound, whether the assumption set holds, and whether the evidence supports the claim are the subject of
AQ-INDEPENDENT-REVIEW. The observer answers one question: did what was written down actually happen. - An observer is not an auditor of programme finances, staffing or schedule, and is given no access to them by this protocol.
- An observer keeps their own copy of everything they sign, in a form they control. Programme storage is not the observer's copy, and the Evidence Fabric is not a substitute for it.
- Observer standing is never contingent on the conclusion the observer reaches. This is stated again, operationally, in the box at the end of this document.
THE OBSERVATION DOSSIER: SECTIONS 1 TO 9
Sections 1 to 9 are issued to every named observer at least five working days before the scheduled run start (T0). Five working days is a floor, not a target. Late issue voids the run's observed status under V-2 and cannot be waived by the observer's consent, because a consent obtained from a person who has not yet had time to read the procedure is not evidence of anything.
- 1 — Claim under observation. The single claim the run is intended to support, the evidence level it could support if the run proceeds as written, and the demonstration maturity level (DM-0 to DM-6) of the run itself.
- 2 — Scope and exclusions. Written as a list of what is not being demonstrated. A dossier whose section 2 is shorter than section 1 is returned unissued.
- 3 — Apparatus and configuration manifest. Article identifiers (AQ-NODE-n), build and revision identifiers, firmware and bitstream digests, and which trust boundaries (TB-1 to TB-5) are physically present in the article under test.
- 4 — Measurement chain. Every instrument, its calibration status and validity expiry, its position in the chain, and the DC-1 tag map: for each reported value, whether it will be
MEASURED,DERIVEDorMODELLED. - 5 — Assumption set and invalidating conditions. The assumptions the result depends on, and the observable conditions under which the programme would consider the result invalid.
- 6 — Procedure script. Step by step, with the expected observable at each step written before the run. A step with no stated expected observable cannot be observed, only watched.
- 7 — Failure modes and conflicts in scope. Which of F-1 to F-14 and CF-1 to CF-7 could arise during this run, and the intended handling of each, including which decision boundaries (B-1 to B-5) are exercised.
- 8 — Halt and abstention criteria. Who may halt, on what observation, and how; and where a DC-3 abstention (
abstain) or asafe-holdis a permitted and expected outcome rather than a failure. - 9 — Data handling and observer access rights. Retention, the observer's independent access to raw output, and any restricted-access constraint arising from the record shared with the Visvambhara programme, stated as a constraint on publication timing and redaction, never on the observer's own access to what they witnessed.
Section 10 is generated, not written: it is the question-and-answer appendix produced at IOP-4.
THE TWELVE STAGES
| Stage | What happens | Timing (working days relative to T0) | Artefact |
|---|---|---|---|
| IOP-1 | Run definition. The claim and its scope are fixed in writing before an observer is approached, so that no observer is recruited to a claim that was shaped around their availability. | T-15 or earlier | Run Definition Record |
| IOP-2 | Observer nomination. The observer declares independence and any relationship with the programme; the programme records why this observer was approached. | T-10 | Independence declaration |
| IOP-3 | Dossier issue, sections 1 to 9, with a content digest recorded in the Evidence Fabric at the moment of issue. | T-5 at the latest | Issued dossier + digest |
| IOP-4 | Written question window. The observer may ask anything about the procedure. Every question is answered in writing or is explicitly marked unanswered, with the reason. | T-5 to T-2 | Dossier section 10 |
| IOP-5 | Readiness walkthrough. The observer sees the physical setup and may require a change to the procedure text, or may decline to proceed, without giving a reason. | T-1 | Walkthrough note |
| IOP-6 | Configuration seal. Build identifiers, digests, calibration certificates and expiries, clock discipline state and the DC-1 tag map are frozen and countersigned. After the seal, the tag map cannot move a value toward stronger evidence. | T0, before first measurement | Seal record |
| IOP-7 | Execution against the section 6 script. The machine-generated run log and the observer's independent timestamped record are kept separately and are not reconciled during the run. | T0 | Run log + observer record |
| IOP-8 | Observer interventions. The observer may halt, require a step repeated, require an abstention or halt path from section 8 to be exercised, or require a listed fault injection to be performed. Each intervention and its outcome is logged, including refusals by the programme. | during T0 | Intervention log |
| IOP-9 | Immediate declaration. Before leaving the site or the feed, the observer records one of the four statuses below, in their own words. No programme representative drafts it. | T0, same day | Observed-status declaration |
| IOP-10 | Evidence Export Package (EEP) delivered to the observer. | within T+10 | EEP |
| IOP-11 | Disagreement window. The observer may file a disagreement record at any time up to ten working days after EEP receipt, and may amend a declaration made at IOP-9 in light of what the EEP shows. | EEP + 10 | Disagreement record |
| IOP-12 | Closure. The run, its status, the EEP digest and any disagreement record are written into the Evidence Fabric as one linked entry, and the observer's continuing access is confirmed in writing. | after IOP-11 closes | Fabric closure entry |
Figure 1 - Observation timeline, working days relative to run start T0
T-15 T-10 T-5 T-2 T-1 T0 T+10 T+20
| | | | | | | |
IOP-1 IOP-2 IOP-3 IOP-4 IOP-5 IOP-6,7,8 IOP-10 IOP-11,12
claim + observer dossier written walk- seal -> EEP dissent
scope named + sections question through run -> to window
fixed declared 1-9 window intervene observer closes;
(floor, IOP-9 fabric
not a same-day entry
target) status
|<----- procedure may still be changed ----->|<-- change requires re-seal -->|
|
any post-seal change without re-seal, re-declaration
and countersignature -> V-4 -> observed status VOID
THE EVIDENCE EXPORT PACKAGE
The EEP is delivered within ten working days of T0. Its test is DC-5: a competent stranger holding only the EEP must be able to reconstruct what happened without asking the programme a question. It contains, at minimum:
- raw instrument output in its native form, with checksums, not only a processed export;
- the machine run log, the seal record and the intervention log;
- the DC-1 tag map as sealed, with any post-run tag change shown as a change, with its author and reason;
- every derivation from raw to reported value, as an executable script or a written method that can be followed by hand;
- every discarded, aborted and repeated run in the same session, each with its reason — omission is a voiding condition, not an editorial choice;
- the programme's analysis, and an explicit statement of what the run does not support.
An EEP consisting only of conclusions and charts is not an EEP, and its delivery does not stop the ten-working-day clock.
DECLARED OBSERVED STATUS
- Observed — the written procedure was executed as written; the observables were recorded as described.
- Observed with exceptions — executed with departures, each listed by the observer. The exception list travels with every later citation of the run; a citation that drops it is a misquotation of the observer.
- Not observed — the observer could not establish that the written procedure is what happened. No reason is required.
- Void — a voiding condition applies. Void is a fact about the run's conduct, not a judgement about the result, and it is recorded by the programme even when the observer would have been content.
What an observed run may then support is bounded by where it was conducted. Observation never moves a claim up a rung of the reach ladder that the run did not physically occupy:
| Run setting | Highest level an observed run may support | Never supported by that run alone |
|---|---|---|
| Desk walkthrough of the design (DM-0) | Concept | any statement about hardware behaviour |
| Analysis or simulation replay, no hardware in the loop | Theory and Simulation, for the modelled configuration only | that the model corresponds to any instrument |
| Optical bench, single AQ-NODE-01 article | Lab validation for the named article under the named conditions | behaviour over any fibre or free-space path |
| Metro fibre or free-space path | Field validation for that path, with weather and alignment recorded | behaviour on any moving platform |
| Moving ground or airborne platform | Dynamic platform | anything about the HAPS relay, CubeSat, LEO or constellation rungs |
| Any setting where V-1 to V-9 applies | Void | citation at any level, including as a partial or indicative result |
VOIDING CONDITIONS V-1 TO V-9
- V-1 The claim or scope changed after IOP-3 without re-issue and a fresh five-working-day count.
- V-2 Sections 1 to 9 reached any named observer fewer than five working days before T0. Observer consent does not cure this.
- V-3 An instrument used outside its stated calibration validity, or with a calibration record the observer was not shown at IOP-6.
- V-4 Any configuration change after the seal without re-seal, re-declaration and countersignature.
- V-5 A step executed outside the observer's stated view when the dossier said it would be in view.
- V-6 A value re-tagged after the run toward stronger evidence —
MODELLEDorDERIVEDpresented asMEASURED(DC-1). - V-7 A discarded, aborted or repeated run omitted from the EEP.
- V-8 EEP not delivered within ten working days, or delivered without the primary evidence required for DC-5 reconstruction.
- V-9 Any attempt by programme personnel to obtain, negotiate or manage the observer's agreement, including offering access, work, attribution or future involvement in exchange for a conclusion.
If the programme finds itself managing an observer toward agreement, the run's observed status is void. This holds whether or not the observer felt pressured, whether or not the effort succeeded, and whether or not the underlying result was correct. The void attaches to the run, not to the observer. The remedy is to re-run under a fresh dossier with observers who have not been managed. The remedy is never to find a different observer for the same run, and never to publish the result with the observation quietly omitted.
THE DISAGREEMENT RECORD
A disagreement record is the observer's own text. The programme may attach a response, which appears after it and never above it, and may correct a factual error in a dated addendum without editing the original. Where the restricted-access record shared with the Visvambhara programme requires redaction, each redacted passage is marked, counted and given a reason; the existence of a disagreement record is never redactable. Every document that cites the run carries a reference to the disagreement record in the same place it carries the observed status.
An observer may write “I am not convinced” and nothing further. That sentence is a complete and sufficient observer record. It requires no substantiation, obliges the observer to propose no alternative explanation, and has no consequence for the observer's access — to this run, to future runs, to the restricted-access record, or to any fee already agreed. The programme may publish a response. It may not publish the run without the sentence.