THE EVIDENCE THREAD

A digital thread that survives contact with hardware.

Requirements, models, partition decisions, interfaces, implementation and tests remain linked. Automation accelerates transformations; evidence and accountable review control acceptance.

EIGHT GATES

Recursive by design.

A failed target test should identify the responsible requirement, model, interface or implementation, not begin an archaeology project across disconnected documents.

01 · MissionStakeholders, ConOps, operating scenarios, constraints, failure consequences and acceptance boundary.
02 · RequirementsPersistent IDs, flowdown, owners and a verification method, inspection, analysis, demonstration or test.
03 · BehaviorGolden algorithm, representative workloads, numerical envelope, corner cases and performance model.
04 · PartitionMeasured CPU/GPU/FPGA/DSP/firmware/host/cloud profiles and a scored allocation trade study.
05 · ContractsSystem structure and behavior, interface control, state/timing, registers, memory and recovery semantics.
06 · RealizationReviewed RTL/HLS, firmware, drivers, host software, integration assets and governed generation.
07 · ProofStatic, formal, simulation, co-simulation, emulation, prototype, HIL and target correlation.
08 · AcceptanceRelease configuration, requirements-to-results matrix, waivers, open risk and approving engineer.

PLATFORM PROFILE

Partition from measurements, not habit.

The right boundary changes with workload, device, certification burden, supply path and product roadmap. An allocation is a decision record, not an intuition.

Candidate Measure Decision signal
CPU / GPU Model latency, concurrency and transfer cost Flexibility and ecosystem
FPGA / ASIC Initiation rate, memory pressure, resources and clocks Determinism, rate, power and I/O proximity
Firmware Response time, interrupts, state and recovery Control ownership and update path
Host / cloud DMA, queueing, orchestration and service envelope Scale, operability and fleet economics

SPECIFICATION THAT EARNS ITS KEEP

Use the notation appropriate to the risk.

Not every partition needs a UML or SysML diagram. Every consequential boundary does need a testable contract.

SYSTEM

SysML where system intent matters

Requirements, structure, behavior, allocation, interfaces, scenarios and parametric budgets tied to verification.

SOFTWARE

UML where behavior clarifies code

Components, state machines and sequences for boot, control, concurrency, recovery and service interactions.

INTEGRATION

Machine-readable source where reuse pays

SystemRDL for register intent; IP-XACT for justified packaging/integration automation; versioned schemas for data and tests.

MACHINE-CHECKABLE SYSTEM MODELS

AI-drafted views with an auditable evidence spine.

These illustrative views show the governed artifacts we deliver. On a client program, versioned model source carries persistent element IDs, requirement links, interface versions, transition guards, test references and release provenance. AI proposes changes; structural checks, simulation and accountable review decide whether they enter the baseline.

UML SEQUENCE · SQ-RF-007

Make timing, authority and fallback visible.

The normal and alternate flows share explicit message identities. A recommendation never reaches the data plane unchecked: an independent runtime guard in firmware enforces freshness, range, deadline, authority and rollback rules.

  • Messages link to interface contract IF-RF-012
  • Timing assertions derive from REQ-LAT-021
  • Alternate operands link to tests TST-184 through TST-189 and can drive candidate test generation
UML sequence for an adaptive SDR control path Mission controller configures firmware and FPGA. Features flow to an AI supervisor in shadow mode. A bounded update is applied only when firmware-enforced authority, validity, freshness and timing guards pass; otherwise firmware applies a pre-approved fallback profile and records the event. Mission controller Embedded FW FPGA data plane AI supervisor Evidence store M01 configure(profile_rev) M02 program IF-RF-012 M03 features(seq_id, timestamp) M04 record(model + input IDs) alt [authorized ∧ values valid ∧ fresh ∧ deadline met] M05 recommendation + confidence M06 apply bounded profile else [invalid ∨ stale ∨ late]: FW applies PRE_APPROVED_PROFILE; EVT-734
Illustrative model view. IDs demonstrate the trace mechanism; client programs use their governed namespaces and repositories.
UML STATE MACHINE · SM-RF-004

Turn every transition into a reviewable promise.

Guards, actions and fault exits are explicit. AI can flag candidate missing transitions or propose tests; protected baselines and approval policy prevent unreviewed changes to operational authority or the fallback state.

  • Consequential transitions specify event, guard and action
  • Declared reachability and fault-exit rules fail CI when violated
  • Each accepted transition maps to scenario coverage
State-transition model for bounded adaptive radio authority The radio progresses from safe through boot and calibration into shadow, advise and bounded control. Representative watchdog, timestamp and out-of-distribution faults exit the adaptive path through degraded mode and then the fallback state. SAFE BOOT CALIBRATE SHADOW ADVISE BOUNDED CONTROL DEGRADED signed image self-test pass calibration valid evidence gate G1 human release + HIL G2 watchdog / stale time / OOD record + pre-approved profile
The shadow → advise → bounded-control progression prevents experimental inference from silently acquiring operational authority.
LIFECYCLE EVIDENCE GRAPH · TR-021

Narrow a failure to the decisions and artifacts that could explain it.

A test result is useful only when it identifies the requirement, scenario, interface, behavior, implementation and exact release configuration that produced it.

  • Orphan requirements and tests fail the traceability gate
  • Build, model, dataset, seed and instrument IDs are retained
  • A fault event opens the relevant evidence paths and preserves candidate-cause links
  • Cause status progresses from suspected to reproduced to confirmed
Lifecycle evidence and candidate-cause graph A mission need links to a system requirement, behavior, interface, build and test evidence. A failed event opens candidate-cause paths to the relevant requirement, model, dataset and release configuration. MISSION NEED NEED-003 REQUIREMENT REQ-LAT-021 BEHAVIOR SM-RF-004 INTERFACE IF-RF-012 BUILD REL-042 TEST EVIDENCE TST-184 / RUN-91 DATASET IQ-SET-17 MODEL ML-09 / DSP-31 FAILED EVENT EVT-734 refines governs constrains realized in tested in suspected cause: timestamp contract violation
Typed links accelerate impact analysis; reproduced evidence and engineering analysis establish root cause without reconstructing history from email and filenames.
AI generation

Draft views, extract candidate elements, flag candidate missing states and generate candidate transition or scenario tests from governed source.

Automated audit

Check IDs, schema, trace completeness, unreachable states, undefined messages, guard conflicts and requirement/test coverage in CI.

Executable evidence

Bind transitions and sequences to assertions, simulation, emulation, HIL and target results using the same scenario identity.

Human baseline

Named engineers approve authority boundaries, safety behavior, waivers and the released model configuration.

BOUNDED AUTOMATION

AI output is a proposal, not evidence.

Mission-critical flight, defense and invasive medical systems cannot treat generated code as its own audit trail. AI can accelerate bounded engineering loops; persistent requirements, versioned inputs, deterministic checks, independent critique and named human release authority establish the evidence.

Good generation targets

Test scaffolds, register collateral, documentation, bounded transformations, integration glue, workload variants and triage hypotheses.

Deterministic gates

Schema validation, compilation, lint, CDC/RDC, formal, simulation, synthesis, timing, profiling and target measurements.

Independent critique

A separate context challenges trace gaps, interface ownership, numerical assumptions, failure coverage and unsupported conclusions.

Human authority

Engineers approve architecture, security/IP boundaries, exceptions, risk disposition and product acceptance.

ACCEPTANCE PACKAGE

The deliverable is a defensible product gate.

TRACE

Requirement to result

Persistent ID, test or analysis, configuration, environment, seed/data, result, waiver and owner.

REPRODUCE

Build to evidence

Source revision, tools, dependencies, generated-artifact provenance, bitstream/firmware/driver compatibility and rerun path.

DECIDE

Risk to acceptance

Closed findings, accepted residual risk, known limits, operating envelope and accountable approval.

Need a product-realization plan before committing the full program?

Start with a diagnostic sprint