Why ordinary checks are not enough
A result can remain technically plausible while an upstream source is superseded, evidence expires or disappears, a configuration changes, or the runtime no longer follows the declared specification.
SIF — Structural Invariant Framework · Governance layer
When a governing source, evidence item, configuration or authority state changes, SIF derives what is affected, what is not affected, what remains OPEN, which source-supported consequence follows, and why.
The problem
The difficult question is often not whether a document or value changed, but exactly which downstream decisions that change can still support.
A result can remain technically plausible while an upstream source is superseded, evidence expires or disappears, a configuration changes, or the runtime no longer follows the declared specification.
Bounded consequences. It traces only declared dependencies, preserves unresolved states instead of inventing certainty, and emits lifecycle actions only when the admitted source model supports them.
Search documents, interpret domain language, propose objects, obligations, dependencies and evidence links, and help a specialist inspect the candidate governing specification.
After the admitted representation is reviewed and frozen, the runtime evaluates that representation deterministically. It does not improvise hidden dependencies or silently change the governing model; the derivation remains traceable and replayable.
Core mechanism
The mechanism starts from admitted sources and declared dependencies, not from a preselected expected answer.
The relation is represented in the admitted graph. SIF may traverse it and derive bounded impact from that declared path.
The object is inside a source-grounded candidate scope, but the dependency itself is not established. SIF does not invent an edge; the bounded state may remain OPEN.
The object is neither graph-reachable nor inside the admitted candidate scope. It is excluded from this derivation — that is not proof of non-impact.
Interactive examples
These are concrete examples of the same governance mechanism. Metrology examples are sanitized real-dossier patterns. NATO/NCIA and NASA examples use public source material and controlled experimental states.
This short route shows the core logic without removing the full evidence catalogue: bounded impact → preserved uncertainty → runtime no longer matches the governed specification.
Dependency-bounded impact · real dossier pattern
Only objects reachable through the declared dependency path enter the affected set.
Independent branches are recorded as non-affected rather than swept into the same verdict.
A local upstream problem does not automatically invalidate an entire calibration dossier. The boundary of impact is itself part of the evidence.
Bounded uncertainty · real dossier pattern
The unresolved boundary remains explicit instead of being converted into PASS or INVALID.
A draft may remain a draft. Incomplete work is not automatically treated as a final technical defect.
The decision remains incomplete for a known, replayable reason. Unsupported consequences are not manufactured.
Cross-domain qualification · public NIST QMS sources
Objects explicitly admitted to the bounded assessment scope remain OPEN while dependency membership is unresolved.
An unconnected object outside that governed scope does not become OPEN merely because it exists in the registry.
The v1.0 transfer exposed a representation limitation: graph exclusion could not preserve uncertainty about whether a dependency existed. The response was a minimal domain-neutral representation extension, not a NIST-specific rule or a new runtime layer.
Authority / pre-action gate · public NCIA SOW
Authority actor, approval, timing and required change mechanism are all satisfied.
The controlled change is admissible under the source-grounded pre-action requirement.
Controlled state derived from a public NCIA procurement requirement; it is not a NATO programme record or incident.
Change semantics · public NCIA SOW
Authority and approval evidence can both be valid.
Approval does not repair use of the wrong change-control mechanism required by the governing source.
This is a controlled state derived from a public NCIA procurement requirement, not a NATO programme incident.
Audit / configuration status · public NCIA SOW
No approval may be missing, so a shallow authorization-only check can appear satisfied.
The actual controlled state must still agree with the authorized configuration-status record.
Authorization and configuration-state integrity are treated as separate assurance questions.
Active executable identity · NASA cFS
cFE load, SCH validation and activation succeed.
The active payload is byte-identical to the precommitted trusted image.
The executable image is valid, active and identical to the trusted image.
Active executable identity · NASA cFS
The selected dispatch behavior can be equal under both valid images.
Equivalent observed behavior does not establish that the trusted executable specification is the one actually active.
Runtime behavior and active-specification identity are different assurance properties.
Specification-to-runtime binding · NASA cFS
Specification identity and the presence of the governed field remain valid.
Execution is no longer controlled by that field, so the declared specification has lost operational authority over the behavior.
The correct specification can be present while execution no longer follows it. Identity alone is not enough.
Evidence across contexts
These evidence layers do different jobs. They should not be read as certification claims for NATO, NASA or any operational programme.
Real calibration structures supplied source registers, object registries, dependency graphs, obligations, temporal states and lifecycle consequences. Development used multiple different structures before freeze; later unseen dossiers and a cross-method replication used the frozen executable core.
NIST Quality Manual and lower-level Radiation Physics Division nonconformance/corrective-action guidance were used to test transfer outside metrology. The v1.0 run preserved lifecycle obligations but exposed a gap when the existence of a dependency itself was unknown. The gap was adjudicated as a domain-neutral representation issue and closed in v1.1 without changing edge-only traversal.
Public procurement and Statement of Work requirements were converted into source-grounded controlled states covering approval timing, change mechanisms, configuration status and audit relationships.
Public SCH, CFS_TO and cFE source was used to separate active executable-image identity from runtime obedience to governed fields.
A bounded public engineering governance source was introduced through declarative bindings only to test whether the portable domain-neutral mechanism could execute without case-specific core logic.
Transfer ladder
Internal case codes are intentionally omitted from this public surface. What matters here is the experimental role of each stage.
Specification identity, change impact, evidence completeness, authorization, release gating and rollback were separated and falsified under controlled evolution.
The system moved from supplied governance snapshots to upstream event → dependency → impact → lifecycle derivation on real calibration evidence.
Several materially different calibration structures were used to expose generic architecture gaps before freeze. Only generic repairs were permitted.
The generic executable mechanism was frozen before unseen cross-case evaluation.
Two previously unopened calibration structures were processed after freeze while source boundaries remained explicit.
A different calibration method and dependency topology reproduced the same mechanism on the unchanged frozen core.
The higher-order event → dependency → impact → state → action mechanism was transferred through external machine-readable policy rather than hidden case branches.
A new public engineering governance source was connected through bindings only to test domain-neutral execution before external handoff.
A quality-management transfer exposed a real representation boundary around unknown dependency membership. The finding was preserved, adjudicated and repaired generically rather than patched to the case.
The qualified mechanism was frozen, independently re-executed, and its provenance bookkeeping corrected without executable semantic change.
SIF research family
SIF Governance is not a rename of the translation/inspection work. It is the next assurance layer that emerged when the governing specification itself became part of the problem.
Research line for deterministic structural and invariant inspection of critical outputs under a defined governing specification.
Operational pilot for output assurance: is this output admissible under the current frozen specification?
Metrology pilot · access by invitation ↗Initial pilot access is limited to invited metrology evaluators.
Governance-state assurance: does the current source/evidence/configuration state still support the decision, and what bounded consequence follows when a dependency changes?
Source provenance
Public NIST, NATO/NCIA and NASA sources are identified below. Real metrology source documents are not included in the public demo and are represented only through sanitized evidence patterns and derived results.
| Evidence context | Source basis |
|---|---|
| Real metrology | Real calibration procedures, certificates, primary measurement records and supporting reference evidence. The public demo contains only sanitized structural patterns and aggregate results; no source documents or case identifiers are embedded. |
| NIST QMS qualification | NIST Quality Manual for Measurement Services (NIST-QM-I, Version 11) plus admitted public Radiation Physics Division nonconformance and corrective-action guidance used for the bounded cross-domain qualification. |
| NATO / NCIA | IFB-CO-115498-TOPFAS-BMD — Book II Part IV, Statement of Work; RFQ-CO-115177-SEMARCIS — Book II Part IV, Statement of Work; IFB-CO-14974-BMD-Amd1; IFB-CO-115735-NAGSF; IFB-CO-115115-ETEE. |
| NASA cFS | NASA SCH commit dbaf51ebbcffe1177997880d0f555c7d489217f5; CFS_TO commit 4589edb05c0d61d5e1661b4502f13795a96a1737; cFE commit 08961026231363409546f880a6bfb6f9e289d909; selected public source/table artifacts. |
| NASA portability acceptance | NASA NPR 7123.1D, bounded public engineering-governance source used only for portable-kit qualification. |
About / Evidence boundary
SIF Governance is the deterministic governance and assurance layer of the Structural Invariant Framework.
It evaluates an admitted governing representation and produces bounded, replayable consequences without inventing hidden dependencies or authority.
SIF Governance is positioned as a deterministic integration and assurance layer for source-governed technical systems, with runtime-binding cases included among its tested contexts. It is not a replacement for assurance cases, policy-as-code, or domain verification methods.
A technically plausible result may still lose governance support when an upstream source, evidence object, version, configuration or authority state changes.
source → obligation → event → applicability → dependency → impact/non-impact → state → action → audit. Domain terminology may change; this higher-order mechanism is the object of transfer testing.
The investigated contribution is the integration of source-derived governance obligations, temporal applicability, bounded affected and explicit non-affected scope, preserved OPEN states, source-supported lifecycle consequences and deterministic replay within a frozen-core mechanism whose cross-domain transfer is under investigation.
The present evidence supports bounded deterministic governance over declared objects, dependencies, obligations, events, lifecycle bindings and explicitly represented source-grounded candidate impact scopes. Certification, accreditation, production safety qualification and universal transfer remain outside the demonstrated scope. SIF does not discover hidden dependencies, guarantee completeness of the supplied specification, or treat exclusion from the admitted graph/scope as proof of non-impact.
The project first isolated the assurance functions under controlled evolution, then moved to real end-to-end metrology governance, cross-case development, executable-core freeze, unseen held-out transfer, cross-method replication, controlled trust-event transfer, public-source portability, a NIST QMS cross-domain qualification that exposed and closed a representation gap, and finally the v1.1.1 frozen external baseline.
The contribution is investigated at the integration level. Assurance cases, dependency graphs, change-impact analysis, provenance, policy-as-code, runtime assurance and audit are established fields. SIF Governance investigates whether its integrated source-derived governance path and frozen-core transfer methodology remain valid across independently instantiated governed systems. The present evidence does not establish a universal governance theory or universal applicability.
Yurii Kuzmenko · Olena Trofimova
National Metrology Institute · Ukrmetrteststandart · Kyiv · 2026