THE EVIDENCE THREAD
A digital thread that survives contact with hardware.
Requirements, models, partition decisions, interfaces, implementation and tests remain linked. Automation accelerates transformations; evidence and accountable review control acceptance.
EIGHT GATES
Recursive by design.
A failed target test should identify the responsible requirement, model, interface or implementation, not begin an archaeology project across disconnected documents.
PLATFORM PROFILE
Partition from measurements, not habit.
The right boundary changes with workload, device, certification burden, supply path and product roadmap. An allocation is a decision record, not an intuition.
| Candidate | Measure | Decision signal |
|---|---|---|
| CPU / GPU | Model latency, concurrency and transfer cost | Flexibility and ecosystem |
| FPGA / ASIC | Initiation rate, memory pressure, resources and clocks | Determinism, rate, power and I/O proximity |
| Firmware | Response time, interrupts, state and recovery | Control ownership and update path |
| Host / cloud | DMA, queueing, orchestration and service envelope | Scale, operability and fleet economics |
SPECIFICATION THAT EARNS ITS KEEP
Use the notation appropriate to the risk.
Not every partition needs a UML or SysML diagram. Every consequential boundary does need a testable contract.
SysML where system intent matters
Requirements, structure, behavior, allocation, interfaces, scenarios and parametric budgets tied to verification.
UML where behavior clarifies code
Components, state machines and sequences for boot, control, concurrency, recovery and service interactions.
Machine-readable source where reuse pays
SystemRDL for register intent; IP-XACT for justified packaging/integration automation; versioned schemas for data and tests.
MACHINE-CHECKABLE SYSTEM MODELS
AI-drafted views with an auditable evidence spine.
These illustrative views show the governed artifacts we deliver. On a client program, versioned model source carries persistent element IDs, requirement links, interface versions, transition guards, test references and release provenance. AI proposes changes; structural checks, simulation and accountable review decide whether they enter the baseline.
Make timing, authority and fallback visible.
The normal and alternate flows share explicit message identities. A recommendation never reaches the data plane unchecked: an independent runtime guard in firmware enforces freshness, range, deadline, authority and rollback rules.
- Messages link to interface contract IF-RF-012
- Timing assertions derive from REQ-LAT-021
- Alternate operands link to tests TST-184 through TST-189 and can drive candidate test generation
Turn every transition into a reviewable promise.
Guards, actions and fault exits are explicit. AI can flag candidate missing transitions or propose tests; protected baselines and approval policy prevent unreviewed changes to operational authority or the fallback state.
- Consequential transitions specify event, guard and action
- Declared reachability and fault-exit rules fail CI when violated
- Each accepted transition maps to scenario coverage
Narrow a failure to the decisions and artifacts that could explain it.
A test result is useful only when it identifies the requirement, scenario, interface, behavior, implementation and exact release configuration that produced it.
- Orphan requirements and tests fail the traceability gate
- Build, model, dataset, seed and instrument IDs are retained
- A fault event opens the relevant evidence paths and preserves candidate-cause links
- Cause status progresses from suspected to reproduced to confirmed
Draft views, extract candidate elements, flag candidate missing states and generate candidate transition or scenario tests from governed source.
Check IDs, schema, trace completeness, unreachable states, undefined messages, guard conflicts and requirement/test coverage in CI.
Bind transitions and sequences to assertions, simulation, emulation, HIL and target results using the same scenario identity.
Named engineers approve authority boundaries, safety behavior, waivers and the released model configuration.
BOUNDED AUTOMATION
AI output is a proposal, not evidence.
Mission-critical flight, defense and invasive medical systems cannot treat generated code as its own audit trail. AI can accelerate bounded engineering loops; persistent requirements, versioned inputs, deterministic checks, independent critique and named human release authority establish the evidence.
Test scaffolds, register collateral, documentation, bounded transformations, integration glue, workload variants and triage hypotheses.
Schema validation, compilation, lint, CDC/RDC, formal, simulation, synthesis, timing, profiling and target measurements.
A separate context challenges trace gaps, interface ownership, numerical assumptions, failure coverage and unsupported conclusions.
Engineers approve architecture, security/IP boundaries, exceptions, risk disposition and product acceptance.
ACCEPTANCE PACKAGE
The deliverable is a defensible product gate.
Requirement to result
Persistent ID, test or analysis, configuration, environment, seed/data, result, waiver and owner.
Build to evidence
Source revision, tools, dependencies, generated-artifact provenance, bitstream/firmware/driver compatibility and rerun path.
Risk to acceptance
Closed findings, accepted residual risk, known limits, operating envelope and accountable approval.