-
Notifications
You must be signed in to change notification settings - Fork 0
ADR 005 Adequacy and Sufficiency as Guidance Subtypes
Status: Accepted Date: 2026-05-16 Deciders: Michael Zargham Related: ADR-015 GSN Adoption for Adequacy and Sufficiency; ADR-021 Three Attestation Subclasses Ship in v0.1; Aspect Coverage with Adequacy and Sufficiency; Design Spec
A satisfaction claim ("design element D satisfies requirement R") is mechanically checkable in principle but rests on two engineering judgments that are not: (a) adequacy — is the model itself adequate to make the claim? (i.e., is D the right kind of artifact for this claim?); (b) sufficiency — is the evidence sufficient to support the claim? (i.e., does the cited verification actually demonstrate what the claim says?). These judgments are where institutional reviewers and assurance-case authors spend their attention, but a flat rtm:satisfies relation hides them. The question is whether to surface adequacy and sufficiency as first-class Guidance subtypes in the v0.1 ontology, or to fold them into a single Guidance type and rely on tagging. See Design Spec §4.4 and Aspect Coverage with Adequacy and Sufficiency.
flexo-rtm v0.1 ontology defines two explicit Guidance subtypes: rtm:AdequacyGuidance and rtm:SufficiencyGuidance. The corresponding attestation subclasses (rtm:AdequacyAttestation, rtm:SufficiencyAttestation) — see ADR-021 Three Attestation Subclasses Ship in v0.1 — surface the engineer-judgment checkpoints as named, queryable, attestable claim types alongside rtm:SatisfactionAttestation. Coverage metrics (see ADR-004 Quantitative Certification Outcome) report coverage per type per aspect.
- Engineer judgment is surfaced, not hidden: an audit report can show "satisfaction coverage is 100% but adequacy attestation coverage is 30%" — which is exactly the gap a reviewer needs to see
- GSN integration (see ADR-015 GSN Adoption for Adequacy and Sufficiency) maps cleanly to these subtypes — GSN's adequacy and sufficiency arguments become RDF-projectable
- Attestation infrastructure (see ADR-021 Three Attestation Subclasses Ship in v0.1) is uniform across all three claim types: same SHACL named-approver enforcement, same coverage metrics, same audit report format
- Vocabulary aligns with the topological research line (see ADR-032 Methodology Agnosticism as Foundational Axiom and ADR-003 Topological Framework Documented as Future Work) as forward-compatible interop: an adopter who chooses to run topological analysis as a downstream-analysis mode can consume adequacy and sufficiency attestations directly. The same vocabulary is equally consumable by other downstream-analysis paths (SLSA, GSN, ARP4754A, in-house) — it is not topology-specific
- Two more vocabulary commitments to maintain and explain; adopters must understand the distinction between adequacy (about the model) and sufficiency (about the evidence)
- Some institutions conflate the two informally — they will need to either adopt the distinction or carry attestations of both type uniformly
- The split aligns with how INCOSE and assurance-case communities already discuss the topic — it's a vocabulary commitment to an existing distinction, not an invention
-
Single Guidance type with tagging: Define one
rtm:Guidanceclass and tag instances asadequacyorsufficiencyvia a property. Rejected: tagging is structurally weaker than subclassing — SHACL profiles cannot enforce per-type constraints as cleanly, and downstream consumers (audit reports, GSN tooling, any topological or other downstream analysis adopters may choose to run) have to dispatch on tag values. Explicit subtypes make the distinction first-class in the ontology and in the attestation infrastructure that consumes it.
rtm:AdequacyGuidance and rtm:SufficiencyGuidance are defined as subclasses of rtm:Guidance in the v0.1 ontology. Corresponding attestation subclasses (see ADR-021 Three Attestation Subclasses Ship in v0.1) carry named-approver enforcement via SHACL. Aspect-coverage queries in oracle/src/oracle/analysis/ report coverage per type. GSN parsimony imports (see ADR-015 GSN Adoption for Adequacy and Sufficiency) map GSN's adequacy and sufficiency arguments onto these subtypes.
- Design Spec §4.4 (Adequacy and Sufficiency Surfacing), §9.A.3 (Attestation Coverage)
- Aspect Coverage with Adequacy and Sufficiency — the coverage model and SPARQL recipes
- ADR-015 GSN Adoption for Adequacy and Sufficiency — GSN as the elaborated argument structure
- ADR-021 Three Attestation Subclasses Ship in v0.1 — the attestation subclasses that surface these
-
ADR-032 Methodology Agnosticism as Foundational Axiom — methodology-neutral framing; vocabulary alignment with the topological research line is forward-compatible interop, not commitment to it as
flexo-rtm's destination
- Flexo Git Coexistence
- ADCS Prototype Lessons
- MVC Pattern from RIME TRL ANT
- Human-AI Accountability
- Multi-Agent Discourse Graph Precedent
- OSLC RM and QM Review
- INCOSE V2 Review
- OMG SysMLv2
- PROV EARL GSN P-PLAN
- Dragon Architecture and Mission Enterprise
- Traditional Forward and Backward Analysis
- Attestation Infrastructure in v0.1
- Identity Boundaries and Policy Projections
- External URI References
- Signed Envelopes and Established Standards
- Aspect Coverage with Adequacy and Sufficiency
- Federated Audit and Composition
- Certification Predicate
- Gap Taxonomy
- Quantitative Outcomes
- Engineering Lifecycle Stages (v0.2)
- Topological Framework Future Work (research phase)
- Vertices Edges Faces (research phase)
- Three-Layer Architecture
- Operational Layer UX Discipline
- Storage Layer Flexo Conventions
- Analysis Layer Scope Algebra
- OSLC Roundtrip Acceptance
- Identity Adapter Contract
- Flexo REST Binding
- SysMLv2 Ingestion Contract
- External URI Rules
- Signed Envelope Shapes
- Parsimony Manifest
- Lossless Roundtrip Definition
- Vendor Extension Carry-Through
- OSLC RM Adapter Contract
- OSLC QM Adapter Contract
- ADR Template
- ADR-001 Foundations First Approach
- ADR-002 SysMLv2 Anchoring
- ADR-003 Topological Framework Documented as Future Work
- ADR-003a v0.1 Ships Traditional Analysis Only
- ADR-004 Quantitative Certification Outcome
- ADR-005 Adequacy and Sufficiency as Guidance Subtypes
- ADR-006 Three-Layer Architecture
- ADR-007 Scope as First-Class RDF Resource
- ADR-008 Repo Name and Org Transfer Plan
- ADR-009 Two-Repo Strategy
- ADR-010 OSLC-RM and OSLC-QM in v0.1
- ADR-011 Lossless Criterion A plus C
- ADR-012 Direct RDF Properties over Reified Edges
- ADR-013 Simplicial Complex as Derived View When Built
- ADR-014 Parsimony Layer Build-Time Extraction
- ADR-015 GSN Adoption for Adequacy and Sufficiency
- ADR-016 Composable SHACL Profiles
- ADR-017 knowledgecomplex as Optional Extras
- ADR-018 V minus F Invariant Deferred with Topological Framework
- ADR-019 Derived Binary View from Quantitative Metrics
- ADR-020 Vocabulary Alignment with Zargham 2026
- ADR-021 Three Attestation Subclasses Ship in v0.1
- ADR-022 External URI References as Open-Source Foundation
- ADR-023 Cryptography by Composition of Battle-Tested Standards
- ADR-024 Identity by Thin Projection of External Sources
- ADR-025 Reproducibility is Structural and Local
- ADR-026 Cryptographic Agility via Algorithm Profiles
- ADR-027 Bit-Exactness vs Numerical Tolerances Are Both First-Class
- ADR-028 Scope-Level Adequacy and Sufficiency for Federated Audit
- ADR-029 Engineering Lifecycle Stages as Scope Metadata
- ADR-030 Polycentric ASOT Authority Model
- ADR-031 Attestation Status Pass Fail Deferred Deprecated
- ADR-032 Methodology Agnosticism as Foundational Axiom
- ADR-033 Generalized ASOT Principle for All Identified Things