SIF GovernanceStructural Invariant Framework · Governance layer
Public Demo · v4.5ExamplesEvidenceAbout
Public research evidence demo. This standalone page explains the SIF Governance mechanism, evidence history, tested contexts, and current boundaries. Real metrology evidence is shown only as sanitized patterns and aggregate results. Public NIST, NATO/NCIA and NASA sources are identified as research evidence contexts. No calibration source documents or real case identifiers are embedded.

SIF — Structural Invariant Framework · Governance layer

Deterministic governance for evidence-driven systems.

When a governing source, evidence item, configuration or authority state changes, SIF derives what is affected, what is not affected, what remains OPEN, which source-supported consequence follows, and why.

Determinism boundary: SIF evaluates the admitted representation deterministically; it does not certify that the representation itself is complete or correct.
Research status: Evidence to date supports bounded operation and transfer in the tested contexts shown below. SIF Governance is investigating cross-domain transfer of the frozen mechanism; it does not claim universal applicability or a completed universal governance theory.
Concrete pattern: if one upstream evidence item loses validity, SIF follows only declared dependency paths, separates graph-derived impact from bounded unresolved candidate scope, preserves insufficient evidence as OPEN, and activates only consequences supported by the governing source.
source-derived obligationsbounded impact / non-impactexplicit OPENlifecycle actionsdeterministic replaycross-domain transfer under investigation

The problem

A plausible result can lose its governing support.

The difficult question is often not whether a document or value changed, but exactly which downstream decisions that change can still support.

Why ordinary checks are not enough

A result can remain technically plausible while an upstream source is superseded, evidence expires or disappears, a configuration changes, or the runtime no longer follows the declared specification.

What SIF Governance adds

Bounded consequences. It traces only declared dependencies, preserves unresolved states instead of inventing certainty, and emits lifecycle actions only when the admitted source model supports them.

Where AI or an expert can help

Search documents, interpret domain language, propose objects, obligations, dependencies and evidence links, and help a specialist inspect the candidate governing specification.

Where SIF Governance begins

After the admitted representation is reviewed and frozen, the runtime evaluates that representation deterministically. It does not improvise hidden dependencies or silently change the governing model; the derivation remains traceable and replayable.

Core mechanism

One governed path from source to consequence

The mechanism starts from admitted sources and declared dependencies, not from a preselected expected answer.

01Governing sourceadmitted authority or evidence
02Obligationsource-derived and machine-readable
03Eventchange, expiry, mismatch, withdrawal
04Applicabilitytime, version and scope
05Dependencytraverse declared relations only
06Impactaffected + explicit non-affected
07Statebounded, including OPEN
08Action / gateonly when source-supported
09Audit / replayreconstruct the decision path
Obligation = a machine-readable condition or requirement derived from an admitted governing source and linked to the objects or relations it governs.
v1.1 rule: graph traversal remains edge-only. A separately declared, source-grounded candidate impact scope may preserve unresolved dependency membership as OPEN_INSUFFICIENT_EVIDENCE; it does not create a dependency edge and is not an expected affected set.
A

Declared dependency

The relation is represented in the admitted graph. SIF may traverse it and derive bounded impact from that declared path.

B

Dependency membership unresolved

The object is inside a source-grounded candidate scope, but the dependency itself is not established. SIF does not invent an edge; the bounded state may remain OPEN.

C

Outside both

The object is neither graph-reachable nor inside the admitted candidate scope. It is excluded from this derivation — that is not proof of non-impact.

Interactive examples

Metrology · NIST QMS · NATO / NCIA · NASA cFS

These are concrete examples of the same governance mechanism. Metrology examples are sanitized real-dossier patterns. NATO/NCIA and NASA examples use public source material and controlled experimental states.

First visit? Start with three examples.

This short route shows the core logic without removing the full evidence catalogue: bounded impact → preserved uncertainty → runtime no longer matches the governed specification.

Dependency-bounded impact · real dossier pattern

Reference evidence is withdrawn upstream

REVIEW_REQUIRED
EventReference evidence withdrawn
DependencyDeclared reference path
ImpactDependent result branch
ActionReassessment where source-supported

Affected

Only objects reachable through the declared dependency path enter the affected set.

Explicit non-impact

Independent branches are recorded as non-affected rather than swept into the same verdict.

Why this matters

A local upstream problem does not automatically invalidate an entire calibration dossier. The boundary of impact is itself part of the evidence.

event → dependency path → affected set → non-affected set → state → source-supported action → audit trace

Bounded uncertainty · real dossier pattern

A working dossier is incomplete, so the system preserves OPEN

OPEN_INSUFFICIENT_EVIDENCE
EvidenceDraft / incomplete working record
ApplicabilityCannot be established fully
StateOPEN preserved
ActionNo invented invalidity

Preserved state

The unresolved boundary remains explicit instead of being converted into PASS or INVALID.

Human-factor tolerance

A draft may remain a draft. Incomplete work is not automatically treated as a final technical defect.

Governance result

The decision remains incomplete for a known, replayable reason. Unsupported consequences are not manufactured.

source boundary → unresolved relation → OPEN → no unsupported lifecycle consequence

Cross-domain qualification · public NIST QMS sources

Historical work must be assessed, but exact equipment-use membership is unresolved

OPEN_INSUFFICIENT_EVIDENCE
EventEquipment / software nonconformity established
Governed scopeBounded historical work requires assessment
DependencyExact use relation not established
StateOPEN without invented edge

Candidate scope

Objects explicitly admitted to the bounded assessment scope remain OPEN while dependency membership is unresolved.

Unrelated object

An unconnected object outside that governed scope does not become OPEN merely because it exists in the registry.

Why this case mattered

The v1.0 transfer exposed a representation limitation: graph exclusion could not preserve uncertainty about whether a dependency existed. The response was a minimal domain-neutral representation extension, not a NIST-specific rule or a new runtime layer.

1 · Transferv1.0 entered a different public QMS context.
2 · FindingUnknown dependency existence could not be represented faithfully.
3 · AdjudicationThe limitation was preserved and treated as a general representation question.
4 · Minimal changeBounded candidate scope was added without changing edge-only traversal.
5 · Closurev1.1 regression and controls passed; v1.1.1 preserves the semantics.
source-grounded candidate scope → dependency membership unresolved → OPEN · derivation path = [] · unrelated object remains excluded

Authority / pre-action gate · public NCIA SOW

Required approval exists before implementation

ALLOW
ChangeClass I engineering change
Source obligationApproval before implementation
ObservedPurchaser approval present
GatePre-action requirement satisfied

Evidence present

Authority actor, approval, timing and required change mechanism are all satisfied.

Governance state

The controlled change is admissible under the source-grounded pre-action requirement.

Public source example

Controlled state derived from a public NCIA procurement requirement; it is not a NATO programme record or incident.

RFQ-CO-115177-SEMARCIS · SOW §5.6.7 → approval before implementation → satisfied → ALLOW

Change semantics · public NCIA SOW

A permanent departure is approved — but routed through the wrong mechanism

BLOCK
ObservedApproval present
Source obligationPermanent departure → ECP
MismatchWrong governed mechanism
GateGovernance completeness fails

What passes

Authority and approval evidence can both be valid.

What still fails

Approval does not repair use of the wrong change-control mechanism required by the governing source.

Public source example

This is a controlled state derived from a public NCIA procurement requirement, not a NATO programme incident.

RFQ-CO-115177-SEMARCIS · SOW §5.7.3 → required mechanism → observed mechanism → BLOCK

Audit / configuration status · public NCIA SOW

The actual configuration differs from the authorized recorded state

BLOCK
RecordAuthorized CSA state exists
ObservedActual CI state differs
DependencyAudit / status consistency
GateState mismatch blocks

What can look acceptable

No approval may be missing, so a shallow authorization-only check can appear satisfied.

What SIF adds

The actual controlled state must still agree with the authorized configuration-status record.

Governance result

Authorization and configuration-state integrity are treated as separate assurance questions.

RFQ-CO-115177-SEMARCIS · SOW §5.10.1 → authorized state ↔ actual state → mismatch → BLOCK

Active executable identity · NASA cFS

The trusted SCH schedule-table image is active

ALLOW
TrustedSCH.SCHED_DEF image
ObservedActive SCH.SCHED_DEF image
IdentitySHA-256 matches
GateExecutable identity satisfied

Executable evidence

cFE load, SCH validation and activation succeed.

Identity evidence

The active payload is byte-identical to the precommitted trusted image.

Public executable example

The executable image is valid, active and identical to the trusted image.

NASA SCH + cFE public source → trusted active-image identity → observed identity equal → ALLOW

Active executable identity · NASA cFS

Two valid active table images produce the same selected behavior

BLOCK
Trusted imageValid active table A
Observed imageValid active table B
BehaviorSelected output looks the same
IdentitySHA-256 differs

Behavioral check

The selected dispatch behavior can be equal under both valid images.

Identity check

Equivalent observed behavior does not establish that the trusted executable specification is the one actually active.

Why this matters

Runtime behavior and active-specification identity are different assurance properties.

NASA SCH + cFE public source → active .tbl identity → behavior equal / identity unequal → BLOCK

Specification-to-runtime binding · NASA cFS

The trusted specification remains correct while runtime stops obeying a governed field

BLOCK
SpecificationTrusted and unchanged
Governed fieldPresent in source/table
RuntimeConsumer ignores field
GateBinding broken

What still passes

Specification identity and the presence of the governed field remain valid.

What fails

Execution is no longer controlled by that field, so the declared specification has lost operational authority over the behavior.

Public executable example

The correct specification can be present while execution no longer follows it. Identity alone is not enough.

NASA cFS public source → governed field → runtime consumer → causal sensitivity lost → BLOCK

Evidence across contexts

Different sources, different structures, one mechanism

These evidence layers do different jobs. They should not be read as certification claims for NATO, NASA or any operational programme.

Public-source research use. References to NIST, NATO/NCIA and NASA identify public source contexts used for research qualification; they do not imply institutional endorsement, validation or adoption of SIF.
Real metrology

End-to-end governance and cross-case transfer

Real calibration structures supplied source registers, object registries, dependency graphs, obligations, temporal states and lifecycle consequences. Development used multiple different structures before freeze; later unseen dossiers and a cross-method replication used the frozen executable core.

Bounded acceptance contract · held-out transfer: 26/26 predefined governance gates passed across two unseen dossiers · executable-core changes = 0
Public NIST QMS

Cross-domain qualification and representation-gap closure

NIST Quality Manual and lower-level Radiation Physics Division nonconformance/corrective-action guidance were used to test transfer outside metrology. The v1.0 run preserved lifecycle obligations but exposed a gap when the existence of a dependency itself was unknown. The gap was adjudicated as a domain-neutral representation issue and closed in v1.1 without changing edge-only traversal.

v1.0 finding → v1.1 minimal representation extension → v1.1.1 evidence-corrected frozen baseline
bounded regression contract: PASS · negative control PASS · lifecycle regression PASS · no new runtime layer
Public NATO / NCIA

Authority, change semantics and configuration-state governance

Public procurement and Statement of Work requirements were converted into source-grounded controlled states covering approval timing, change mechanisms, configuration status and audit relationships.

Bounded acceptance contract · 24 public governing rules → 48 paired controlled states · SIF 48/48
Public NASA cFS

Active executable identity and runtime binding

Public SCH, CFS_TO and cFE source was used to separate active executable-image identity from runtime obedience to governed fields.

3 executable table specifications · 8 consumed fields qualified
Public NASA NPR 7123.1D

Portable-kit qualification

A bounded public engineering governance source was introduced through declarative bindings only to test whether the portable domain-neutral mechanism could execute without case-specific core logic.

Bounded acceptance contract · 11/11 portability acceptance checks passed · executable-core changes = 0
How to read the PASS counts. These are acceptance results inside predefined, bounded test contracts; they are not estimates of universal correctness or reliability. The NIST v1.0 transfer produced a representation limitation rather than a PASS, and that finding directly informed the v1.1 representation change.

Transfer ladder

The proof became harder before the core was handed out

Internal case codes are intentionally omitted from this public surface. What matters here is the experimental role of each stage.

01

Controlled mechanism laboratory

Specification identity, change impact, evidence completeness, authorization, release gating and rollback were separated and falsified under controlled evolution.

Architecture contribution isolated
02

Real-case end-to-end derivation

The system moved from supplied governance snapshots to upstream event → dependency → impact → lifecycle derivation on real calibration evidence.

Real governed source model
03

Cross-case development

Several materially different calibration structures were used to expose generic architecture gaps before freeze. Only generic repairs were permitted.

No test-specific rule admission
04

Executable core freeze

The generic executable mechanism was frozen before unseen cross-case evaluation.

Post-freeze repair budget = 0
05

Unseen held-out transfer

Two previously unopened calibration structures were processed after freeze while source boundaries remained explicit.

26/26 predefined gates · core changes 0
06

Cross-method replication

A different calibration method and dependency topology reproduced the same mechanism on the unchanged frozen core.

12/12 applicable governance gates · deterministic replay PASS
07

Controlled trust-event transfer

The higher-order event → dependency → impact → state → action mechanism was transferred through external machine-readable policy rather than hidden case branches.

Held-out 12/12 · affected-object errors 0
08

Public-source portability

A new public engineering governance source was connected through bindings only to test domain-neutral execution before external handoff.

Bounded acceptance contract · NASA portability 11/11 · core changes 0
09

NIST cross-domain challenge

A quality-management transfer exposed a real representation boundary around unknown dependency membership. The finding was preserved, adjudicated and repaired generically rather than patched to the case.

v1.0 finding reproduced → v1.1 regression PASS
10

Evidence-corrected external baseline

The qualified mechanism was frozen, independently re-executed, and its provenance bookkeeping corrected without executable semantic change.

v1.1.1 FROZEN · bounded acceptance contract 10/10 · deterministic replay PASS

SIF research family

Where Governance sits in the wider SIF line

SIF Governance is not a rename of the translation/inspection work. It is the next assurance layer that emerged when the governing specification itself became part of the problem.

SIF 2.0

Research line for deterministic structural and invariant inspection of critical outputs under a defined governing specification.

SIF Inspector

Operational pilot for output assurance: is this output admissible under the current frozen specification?

Metrology pilot · access by invitation ↗

Initial pilot access is limited to invited metrology evaluators.

SIF Governance

Governance-state assurance: does the current source/evidence/configuration state still support the decision, and what bounded consequence follows when a dependency changes?

Source provenance

Public evidence sources remain inspectable

Public NIST, NATO/NCIA and NASA sources are identified below. Real metrology source documents are not included in the public demo and are represented only through sanitized evidence patterns and derived results.

Technical source basis
Evidence contextSource basis
Real metrologyReal calibration procedures, certificates, primary measurement records and supporting reference evidence. The public demo contains only sanitized structural patterns and aggregate results; no source documents or case identifiers are embedded.
NIST QMS qualificationNIST Quality Manual for Measurement Services (NIST-QM-I, Version 11) plus admitted public Radiation Physics Division nonconformance and corrective-action guidance used for the bounded cross-domain qualification.
NATO / NCIAIFB-CO-115498-TOPFAS-BMD — Book II Part IV, Statement of Work; RFQ-CO-115177-SEMARCIS — Book II Part IV, Statement of Work; IFB-CO-14974-BMD-Amd1; IFB-CO-115735-NAGSF; IFB-CO-115115-ETEE.
NASA cFSNASA SCH commit dbaf51ebbcffe1177997880d0f555c7d489217f5; CFS_TO commit 4589edb05c0d61d5e1661b4502f13795a96a1737; cFE commit 08961026231363409546f880a6bfb6f9e289d909; selected public source/table artifacts.
NASA portability acceptanceNASA NPR 7123.1D, bounded public engineering-governance source used only for portable-kit qualification.

About / Evidence boundary

SIF Governance

Close

What it is

SIF Governance is the deterministic governance and assurance layer of the Structural Invariant Framework.

It evaluates an admitted governing representation and produces bounded, replayable consequences without inventing hidden dependencies or authority.

SIF Governance is positioned as a deterministic integration and assurance layer for source-governed technical systems, with runtime-binding cases included among its tested contexts. It is not a replacement for assurance cases, policy-as-code, or domain verification methods.

The problem

A technically plausible result may still lose governance support when an upstream source, evidence object, version, configuration or authority state changes.

The governing invariant

source → obligation → event → applicability → dependency → impact/non-impact → state → action → audit. Domain terminology may change; this higher-order mechanism is the object of transfer testing.

Investigated contribution

The investigated contribution is the integration of source-derived governance obligations, temporal applicability, bounded affected and explicit non-affected scope, preserved OPEN states, source-supported lifecycle consequences and deterministic replay within a frozen-core mechanism whose cross-domain transfer is under investigation.

Scope and evidence boundary

The present evidence supports bounded deterministic governance over declared objects, dependencies, obligations, events, lifecycle bindings and explicitly represented source-grounded candidate impact scopes. Certification, accreditation, production safety qualification and universal transfer remain outside the demonstrated scope. SIF does not discover hidden dependencies, guarantee completeness of the supplied specification, or treat exclusion from the admitted graph/scope as proof of non-impact.

Why the evidence is staged

The project first isolated the assurance functions under controlled evolution, then moved to real end-to-end metrology governance, cross-case development, executable-core freeze, unseen held-out transfer, cross-method replication, controlled trust-event transfer, public-source portability, a NIST QMS cross-domain qualification that exposed and closed a representation gap, and finally the v1.1.1 frozen external baseline.

Research positioning

The contribution is investigated at the integration level. Assurance cases, dependency graphs, change-impact analysis, provenance, policy-as-code, runtime assurance and audit are established fields. SIF Governance investigates whether its integrated source-derived governance path and frozen-core transfer methodology remain valid across independently instantiated governed systems. The present evidence does not establish a universal governance theory or universal applicability.

Method & system architecture / authors

Yurii Kuzmenko · Olena Trofimova
National Metrology Institute · Ukrmetrteststandart · Kyiv · 2026