K07 · evidence-bundled critical-infrastructure assurance
Model and autonomous-agent assurance
Direct answer
Evaluate model provenance, data lineage, adversarial robustness, tool authority, memory boundaries, drift, fallback, and runtime constraints.
Authority and evidence boundary. K07 publishes knowledge architecture, bounded reference records, procurement structures, local validation tools, signed synthetic fixtures, and point-in-time source review. It does not certify a facility, award a contract, authorize an operation, prove truth, establish deployment, or claim current operation.
Statement of work
Evaluate model provenance, data lineage, adversarial robustness, tool authority, memory boundaries, drift, fallback, and runtime constraints.
| Current package ID | WP-K07-06 |
|---|---|
| Inherited stable ID | WP-K06-06 |
| Period | To be defined by the acquiring authority; no duration is inferred by the public pattern. |
| Dependencies | WP-K06-04; WP-K06-05 |
Required outcomes
- model and data provenance baseline
- tool-authority and memory-boundary matrix
- adversarial robustness evidence
- drift, rollback and fallback plan
Owner-furnished information
- model inventory and hashes
- training/evaluation data lineage
- tool interfaces
- system prompts and policies under controlled access
- runtime telemetry and incident history
Contractor deliverables
- model assurance case
- adversarial evaluation summary
- tool-authority matrix
- drift and rollback plan
- unresolved model risks
Performance standards
- Model, data, code and evaluation artifacts are versioned and linked
- Tool and actuator permissions are explicit and testable
- Fallback and rollback operate under declared uncertainty
Quality surveillance
- hash and lineage replay
- policy enforcement test
- fault-injection exercise
Exclusions
- no claim that benchmark success proves field judgment
- no unrestricted tool use
Acceptance matrix
| Criterion | Required result | Assessment | Outcome vocabulary |
|---|---|---|---|
| Provenance | Model, data, code and evaluation artifacts are versioned and linked | hash and lineage replay | PASS, FAIL, PARTIAL, UNAVAILABLE, or NOT APPLICABLE with rationale |
| Bounded authority | Tool and actuator permissions are explicit and testable | policy enforcement test | PASS, FAIL, PARTIAL, UNAVAILABLE, or NOT APPLICABLE with rationale |
| Failure behavior | Fallback and rollback operate under declared uncertainty | fault-injection exercise | PASS, FAIL, PARTIAL, UNAVAILABLE, or NOT APPLICABLE with rationale |
Bid-evaluation criteria
- model-system assurance depth
- adversarial evaluation method
- secure evidence handling
- vendor-independent test design
- price realism and schedule credibility
- data-rights and evidence-delivery terms
- subcontractor and supply-chain transparency
Evidence rights
- The acquiring authority receives perpetual access to final reports, schemas, manifests, acceptance evidence, defects, and correction history within the negotiated data-rights regime.
- Contractor proprietary methods may remain protected only when they do not prevent independent replay of required results.
- Source artifacts, hashes, versions, tool outputs, and negative findings required for acceptance cannot be withheld merely because they are unfavorable.
- No clause transfers authority, licensing status, or ownership beyond the signed contract and governing law.
Negative-result clauses
- A failed, partial, stale, disputed, unavailable, or superseded result must be delivered and may not be converted into a pass.
- Discovery of a safety, authority, evidence, or common-cause defect triggers prompt notice and preserves stop authority.
- Acceptance of one deliverable does not waive latent defects, falsified evidence, or later-discovered nonconformance.
- The final package must distinguish work completed, work not performed, evidence unavailable, and owner decisions pending.
Data requirements
- model inventory and hashes
- training/evaluation data lineage
- tool interfaces
- system prompts and policies under controlled access
- runtime telemetry and incident history