-
Notifications
You must be signed in to change notification settings - Fork 0
ADR 004 Quantitative Certification Outcome
Status: Accepted Date: 2026-05-16 Deciders: Michael Zargham Related: ADR-019 Derived Binary View from Quantitative Metrics; ADR-005 Adequacy and Sufficiency as Guidance Subtypes; Quantitative Outcomes; Design Spec
The Zargham 2026 paper, in TDD framing, characterizes certification as a pass/fail outcome: the RTM is complete or it isn't. Real institutional practice, however, treats RTM completeness as a gradient — coverage grows over a project's life from sparse to comprehensive, and adoption depends on stakeholders being able to see and reason about partial states. A binary-only certification outcome forces an institution into a "fail" state for the entire project life until the final claim is satisfied, which contradicts the way safety and assurance cases are actually built in industry. The question is whether the v0.1 certification outcome is binary or quantitative. See Design Spec §4 (certification model) and Quantitative Outcomes.
flexo-rtm v0.1's primary certification outcome is quantitative: coverage percentages per claim type (satisfaction, adequacy, sufficiency — see ADR-005 Adequacy and Sufficiency as Guidance Subtypes) per aspect (forward, backward, attestation), gap counts, and a per-scope coverage matrix. The binary view (see ADR-019 Derived Binary View from Quantitative Metrics) is derived from the quantitative metrics against a configurable threshold, not produced separately.
- Adoption-friendly: institutions can adopt
flexo-rtmon day-one with sparse RTM data and watch coverage grow toward thresholds - The gradient framing is what audit committees and assurance-case reviewers actually want — they need to see "where are we?" not just "are we done?"
- The configurable threshold gives institutions agency over their own definition of "complete enough"; safety-critical contexts can set 100%, exploratory contexts can set lower
- Per-aspect / per-claim-type granularity surfaces gaps in the form most actionable to engineers (e.g., "verification coverage is 80% but adequacy attestation is 30%")
- The Zargham 2026 paper's TDD-framed pass/fail language requires bridging in the design spec (see ADR-019 Derived Binary View from Quantitative Metrics)
- Threshold-tuning becomes a governance question per scope, not a global constant — institutional policy work that didn't exist with pure binary
- Reporting consumers must understand the quantitative model; tooling that just wants "pass/fail" gets a derived signal that may obscure underlying gaps
- The quantitative outcome composes cleanly with scope algebra (see ADR-007 Scope as First-Class RDF Resource): each scope has its own coverage matrix, and scopes compose as expected
- Binary pass/fail only (paper's TDD framing): Treat the RTM as either complete (all claims satisfied with valid attestation) or not. Rejected: forces a "fail" outcome for essentially every project that isn't done. Institutional adoption requires the gradient — auditors, reviewers, and engineers need to see where coverage stands today, not just whether the project has reached 100%. The binary view is still useful as a derived signal (see ADR-019 Derived Binary View from Quantitative Metrics) when stakeholders want a single number, but it's a projection of the quantitative model, not the primary outcome.
The quantitative outcome lives in v0.1's analysis layer (oracle/src/oracle/analysis/). Coverage metrics are computed via SPARQL queries against the RTM graph, parameterized by scope (see ADR-007 Scope as First-Class RDF Resource). Output is a structured coverage report (per-scope, per-aspect, per-claim-type) plus a derived binary view against a configurable threshold (see ADR-019 Derived Binary View from Quantitative Metrics). Audit reports include both views — quantitative as primary, binary as derived summary.
- Design Spec §4.1–4.3 (Certification Model, Coverage Metrics, Aspect Coverage)
- Quantitative Outcomes — the wiki page elaborating the coverage model and report structure
- ADR-019 Derived Binary View from Quantitative Metrics — how the binary view derives from this
- ADR-005 Adequacy and Sufficiency as Guidance Subtypes — the claim types this counts over
- Flexo Git Coexistence
- ADCS Prototype Lessons
- MVC Pattern from RIME TRL ANT
- Human-AI Accountability
- Multi-Agent Discourse Graph Precedent
- OSLC RM and QM Review
- INCOSE V2 Review
- OMG SysMLv2
- PROV EARL GSN P-PLAN
- Dragon Architecture and Mission Enterprise
- Traditional Forward and Backward Analysis
- Attestation Infrastructure in v0.1
- Identity Boundaries and Policy Projections
- External URI References
- Signed Envelopes and Established Standards
- Aspect Coverage with Adequacy and Sufficiency
- Federated Audit and Composition
- Certification Predicate
- Gap Taxonomy
- Quantitative Outcomes
- Engineering Lifecycle Stages (v0.2)
- Topological Framework Future Work (research phase)
- Vertices Edges Faces (research phase)
- Three-Layer Architecture
- Operational Layer UX Discipline
- Storage Layer Flexo Conventions
- Analysis Layer Scope Algebra
- OSLC Roundtrip Acceptance
- Identity Adapter Contract
- Flexo REST Binding
- SysMLv2 Ingestion Contract
- External URI Rules
- Signed Envelope Shapes
- Parsimony Manifest
- Lossless Roundtrip Definition
- Vendor Extension Carry-Through
- OSLC RM Adapter Contract
- OSLC QM Adapter Contract
- ADR Template
- ADR-001 Foundations First Approach
- ADR-002 SysMLv2 Anchoring
- ADR-003 Topological Framework Documented as Future Work
- ADR-003a v0.1 Ships Traditional Analysis Only
- ADR-004 Quantitative Certification Outcome
- ADR-005 Adequacy and Sufficiency as Guidance Subtypes
- ADR-006 Three-Layer Architecture
- ADR-007 Scope as First-Class RDF Resource
- ADR-008 Repo Name and Org Transfer Plan
- ADR-009 Two-Repo Strategy
- ADR-010 OSLC-RM and OSLC-QM in v0.1
- ADR-011 Lossless Criterion A plus C
- ADR-012 Direct RDF Properties over Reified Edges
- ADR-013 Simplicial Complex as Derived View When Built
- ADR-014 Parsimony Layer Build-Time Extraction
- ADR-015 GSN Adoption for Adequacy and Sufficiency
- ADR-016 Composable SHACL Profiles
- ADR-017 knowledgecomplex as Optional Extras
- ADR-018 V minus F Invariant Deferred with Topological Framework
- ADR-019 Derived Binary View from Quantitative Metrics
- ADR-020 Vocabulary Alignment with Zargham 2026
- ADR-021 Three Attestation Subclasses Ship in v0.1
- ADR-022 External URI References as Open-Source Foundation
- ADR-023 Cryptography by Composition of Battle-Tested Standards
- ADR-024 Identity by Thin Projection of External Sources
- ADR-025 Reproducibility is Structural and Local
- ADR-026 Cryptographic Agility via Algorithm Profiles
- ADR-027 Bit-Exactness vs Numerical Tolerances Are Both First-Class
- ADR-028 Scope-Level Adequacy and Sufficiency for Federated Audit
- ADR-029 Engineering Lifecycle Stages as Scope Metadata
- ADR-030 Polycentric ASOT Authority Model
- ADR-031 Attestation Status Pass Fail Deferred Deprecated
- ADR-032 Methodology Agnosticism as Foundational Axiom
- ADR-033 Generalized ASOT Principle for All Identified Things