Research records provisional
Independent research

Human control & decision authority

Research note

From Formal Authority to Practical Human Control

AUTHOR

Mark Julius Banasihan

DATE

6 September 2026

Publication status: On hold pending arXiv approval. The manuscript download is withheld pending permission for public release. It is not presented as an approved arXiv publication. Status record · 2026-09-15

What makes human control practical?

This study asks what evidence establishes that a person could affect an automated decision. It applies a six-stage assessment to three historical cases:

  1. Neither Patriot case passed, despite supported intervention authority.
  2. Oko remained unresolved because all six stages were only partially supported.
  3. A preserved correction shows how a stricter evidence rule changed the Oko findings without changing the historical packet.
Scope of the result.

Three deliberately selected, retrospective cases; one assessor. The study demonstrates a procedure. It does not establish prevalence, causal effects, independent reliability, or transfer to current AI systems.

Paper and materials.

Source material under publication review · Research repository · Registry record

Why test a claim of human control?

Institutions can assign responsibility without preserving the conditions needed to exercise it. A reviewer may have permission to stop an action yet lack usable information, sufficient time, or an effective route for changing execution. Treating the role assignment as proof can conceal a failed safeguard and place responsibility on someone who lacked practical power.

The research question is therefore documentary: what evidence would justify a claim that human authority had practical force in one consequential decision? The method evaluates the surviving record within a declared boundary. It does not assign personal blame or assess moral character.

Practical Human Control is the assessment method presented here. Trust, Autonomy & Evidence (TAE) is the broader research architecture. Source material under publication review.

Setup: cases, records, and selection

The unit of analysis is one bounded machine-mediated decision or action sequence. The study uses a functional system definition: Oko concerns early-warning inference; the Patriot cases concern automated detection, classification, and engagement support. These historical systems differ materially from present learned models.

Screening stopped when each stratum was filled. The unscreened candidates were not rejected, and the selected cases are not a representative sample. The design demonstrates how the procedure behaves under anticipated evidence conditions. Source material under publication review.

Study design & boundary

Design
Retrospective methods demonstration; one assessor
Evidence cutoff
6 August 2026, 23:59:59 UTC
Selection
Protocol and empty selection register frozen before screening
Candidate pool
928 preserved candidate records
Screening outcome
Five screened; three selected; two excluded; 923 left unscreened
Selection purpose
Fill three prespecified strata covering contrasting intervention and evidence conditions

Why these three cases?

The selection figure records five screening decisions from a preserved pool of 928 candidates. Three cases filled the predefined strata, two were excluded, and the remaining 923 were left unscreened.

Figure 1 · How to read this figure

Candidate counts describe procedure execution, not prevalence. Unscreened records have no exclusion decision.

For an assurance team, a frozen selection rule makes it possible to inspect why these cases were chosen. Use it to distinguish a method demonstration from evidence about how often a problem occurs.

Five screened candidates produce three selected cases and two exclusions; 923 candidates remain unscreened.
Figure 1. The frozen stopping rule filled three prespecified strata after five decisions.

How the assessment works

Each case packet is assessed against six connected conditions. The sequence makes it possible to ask where a claim of practical control loses support.

Missing evidence is a distinct finding

A missing log does not by itself show that an intervention never occurred. The distinction between unsupported and indeterminate prevents that inference.

Case-level rule: all required stages supported means Pass; any required stage unsupported means Fail; otherwise, partial or indeterminate support means Unresolved. The states have no numeric distance and produce no aggregate control score. Correction, repair, and reform are separate post-event propositions. Source material under publication review.

Full method and evidence requirements →
  1. Information accessDid the person receive the relevant information?
  2. Comprehension capacityCould they understand it in the operating context?
  3. Intervention authorityWere they authorized to alter the action?
  4. Intervention feasibilityCould they use that authority in time?
  5. Exercised judgmentDoes the record support an actual human judgment?
  6. Execution propagationDid that judgment reach the action that followed?

Read the evidence states

SSupported
Direct, contemporaneous evidence satisfies the condition.
PPartially supported
Some required elements are present; a material gap remains.
UUnsupported
Evidence contradicts the condition or shows it was absent.
IIndeterminate
The packet lacks enough evidence to decide.
OOutside scope
A justified boundary excludes the proposition.

Was there enough time to intervene?

For AI operations teams, intervention feasibility is a concrete design question. A stop control is useful only if a person can receive the information, interpret it, decide, transmit the instruction, and affect execution before commitment.

The manuscript proposes an intervention margin for prospective systems with complete timestamps:

The first term is the time from information access to irreversible commitment. The second is the total time needed to understand, decide, communicate, and make the intervention take effect. Every duration must use the same unit.

A nonnegative margin is a necessary timing condition under this proposed measure. It is not sufficient to establish the full control chain. Missing inputs leave timing indeterminate. The historical packets do not contain enough timestamps to calculate this margin. Source material under publication review.

Mt = (tcommittaccess)
− (tinterpret + tdecide + ttransmit + tpropagate)

Results: authority and practical force diverge

Both Patriot packets support intervention authority, while other required conditions lack support. Oko has partial support across all six stages. Figure 2 shows the proposition-level findings, including the separate post-event propositions below the horizontal rule.

The two Fail results do not erase differences in the evidence. For F/A-18C, unavailable inquiry material, logs, and displays leave several stages indeterminate. Oko’s retrospective sources support a bounded account but do not supply a located contemporaneous command record. Source material under publication review.

Figure 2 · How to read this figure

Oko uses the v0.6.0 reassessment; both Patriot cases preserve their v0.3.0 assessments. Exact state labels and source references appear below.

For technology and operations leaders, the useful distinction is between delegated authority and the conditions needed to exercise it. In a new review, ask for evidence at each stage before relying on the oversight claim.

Nine propositions across three cases: all six Oko stages are partial; both Patriot cases have supported authority and unsupported execution propagation.
Figure 2. Twenty-seven categorical findings across three selected cases. The first six rows determine the event-control result. This matrix provides no population estimate or system ranking.

Oko · 1983

Unresolved

All six event-level stages are partially supported.

Patriot ZG710 · 2003

Fail

Comprehension, feasibility, exercised judgment, and execution propagation are unsupported.

Patriot F/A-18C · 2003

Fail

Execution propagation is unsupported; comprehension, feasibility, and exercised judgment remain indeterminate.

Where did human judgment enter the sequence?

A stage classification becomes easier to interpret within the event. The reconstructed paths show the order of machine output, human judgment, and institutional action. They also expose where the public evidence stops.

For an investigation team, the practical question is whether records connect each handoff. A narrative that reaches the final outcome can still leave the point of human intervention unresolved.

Figure 3 · How to read this figure

Horizontal position indicates order, not a shared elapsed-time scale. The dotted F/A-18C segment marks missing evidence about timing, displays, source independence, and feasible challenge.

For an incident investigator, the sequence identifies the handoffs that need linked records. It helps frame requests for timestamps, displays, decisions, and execution logs while preserving gaps in the public account.

Three bounded sequences with five events each and a public evidence gap marked for F/A-18C.
Figure 3. Fifteen source-linked events across the three cases.

What does the record support about reliance?

The six control stages are one part of TAE. Separate propositions examine the evidence available for justified reliance. These findings should not be merged into a single score.

A technical leader can separate two questions: did a human have practical control over this action, and what evidence justified reliance on the system? Answering one does not automatically answer the other.

Figure 4 · How to read this figure

Conditional reliability and calibrated uncertainty are unsupported across all three packets; record integrity is indeterminate. This does not rank the systems or establish their general trustworthiness.

For a system owner, control over an action and evidence for reliance are separate questions. This matrix provides a vocabulary for recording what remains unknown before making a stronger reliability claim.

Twelve trust-evidence propositions across three cases.
Figure 4. Thirty-six proposition-level findings in the preserved packets.

How much of each control chain is supported?

The distribution of evidence states shows why these outcomes need different explanations. Partial support records evidence with a material gap. Indeterminate records insufficient evidence to decide.

Figure 6 · How to read this figure

These counts are not a missingness rate, aggregate control score, or reliability estimate. No numeric distance is assigned between states.

For a review lead, the mix of states helps explain why different findings require different follow-up. An indeterminate stage calls for better evidence; an unsupported stage calls for examining the condition the record contradicts.

Oko has six partial findings; ZG710 one supported, one partial and four unsupported; F/A-18C one supported, one partial, one unsupported and three indeterminate.
Figure 6. Eighteen findings across six required stages and three cases.

Why the Oko finding changed

The v0.3.0 assessment classified all six Oko event-level stages as supported. A later adjudication froze a stricter direct-and-contemporaneous evidence rule before reassessment. Applying that rule to the same packet changed each stage to partially supported.

This is a change in evidentiary support, not a discovery that the historical action did not happen. Preserving the earlier result makes the effect of the changed rule inspectable. Source material under publication review.

Figure A4 · How to read this figure

The packet, evidence cutoff, stage questions, and historical sources were unchanged. The table records each missing contemporaneous document or link.

For an institution maintaining an assurance record, preserve the old finding, the new rule, and the reason for the change. That makes a correction understandable without erasing the earlier assessment.

Six Oko stages move from supported in v0.3.0 to partially supported in v0.6.0.
Figure A4. A method-driven correction with no new historical evidence. Both versions and the material gaps are retained in the correction record.

What has been tested about the method?

The repository includes controlled changes to synthetic evidence. Each test asks whether the assessment changes where expected, or stays unchanged when the altered feature should not affect it.

For example, evidence arriving after an action should defeat a pre-action access finding; changing a case title should leave the assessment unchanged. These checks test internal behavior. They do not measure whether independent investigators agree or whether the classifications are accurate in the field.

Hashes and version manifests help reconstruct the artifact path. Preserving bytes cannot establish the truth or completeness of their content. Source material under publication review.

Figure A1 · How to read this figure

The same author designed the fixtures, code, mutations, and expected results. Matching those expectations does not independently reproduce the historical assessments.

For evaluation engineers, these tests illustrate how to check that relevant evidence changes affect the intended output and irrelevant changes leave it stable. Independent judgment and field validity still require separate tests.

Twelve controlled mutations contain eleven expected state changes and three invariance checks.
Figure A1. All observed responses matched the committed expectations: eleven changes and three invariances across twelve mutations. These are internal implementation checks.

Can the analysis be traced and checked?

The artifact path connects a frozen input to an assessment, a derived table, and the figure the reader sees.

A further check asks whether a claim is eligible to support a conclusion. TAE separates traceability, integrity, support, evidence fitness, and dependency closure. A well-linked claim can still lack the kind of evidence needed for a stronger inference.

Figure A2 · How to read this figure

Hashes detect changes to stored files. They cannot establish source truth or completeness.

For an AI operations team, the lineage offers a model for connecting the report people read to the exact inputs and transformations that produced it. Reproducing the artifact path is only one part of validating the conclusion.

Figure A3 · How to read this figure

Passing linkage or integrity checks does not establish independent validity. Later manuscript retrieval checkpoints are explained separately below.

For assurance reviewers, the key question is whether the evidence is fit for the conclusion. An intact citation trail alone cannot authorize a claim about independent validity or deployment readiness.

Research and figure-generation lanes connect frozen sources, assessments, plot inputs, figures and checks.
Figure A2. The preserved artifact lineage makes transformations inspectable.
Five claim gates and conclusion eligibility for forty material claims.
Figure A3. The figure preserves the v0.16.0 claim-gate state.

What the method adds, and what remains open

The proposed contribution combines a frozen selection procedure, versioned case packets, categorical missing-evidence rules, a connected control chain, claim-level evidence checks, and preserved corrections. The originality claim is bounded to the declared search and reviewed sources.

Literature-search scope and remaining coverage

The manuscript reports 2,431 deduplicated records in the formal search. Its initial screening figure records 1,087 inaccessible records. The later recovery checkpoint records outcomes for 107 of that population, leaving 980 retrieval outcomes open. Those numbers describe different checkpoints, not alternative totals.

Authenticated database searches remain open. The closed author-review queues do not establish universal originality or complete coverage. Source material under publication review.

Limits on the present findings

  • The cases were deliberately selected, and two concern the same system family and period.
  • Public retrospective records omit internal and classified evidence; sources may depend on the same earlier account.
  • One assessor designed and applied the method. Independent reliability and classification validity are unestablished.
  • The study tests neither causal or safety effects nor legal sufficiency.
  • Transfer to current learned systems requires a new test using contemporary records.

The next empirical step is independent application to richer, contemporary evidence. The manuscript proposes a sandbox setting for prospective validation; it reports no completed sandbox study. Source material under publication review.

What an institution could do with this

An assurance team, deployer, or incident investigator could use the chain as a proposed evidence request before relying on a human-control claim. Start with one consequential decision and preserve:

  • What the person knew: the information shown, system state and limits, and independent information available for challenge.
  • What the person could do: delegated intervention rights, time, workload, access, and escalation routes.
  • What happened: a contemporaneous judgment record and evidence linking intervention to execution.
  • What remains missing: unavailable records, retention rules, and any separate correction or repair evidence.

A Pass supports a bounded claim under the method’s rule. A Fail identifies a required condition that is unsupported. Unresolved means the record cannot establish the complete claim. None of these outcomes alone certifies safety, fairness, compliance, or institutional effectiveness. Source material under publication review.

Paper, data, and version history

Primary manuscript: Mark Julius Banasihan, From Formal Authority to Practical Human Control: A traceable method for reconstructing human control in automated decisions, preprint v0.17.0.

Source material under publication review

The submission watermark is not presented as a public arXiv identifier or evidence of acceptance. The earlier v0.14.0 DOI is not assigned to this manuscript. The local PDF is an unchanged copy supplied by the author.

Artifact provenance

Source figures are reproduced unchanged from revision 781f7806a626cd4e4fffbe4d453d9d5365b835f9. © 2026 Mark Julius Banasihan. The full publication set includes decision paths, trust-evidence states, selection, search, and integrity figures included in this expanded article.

This page is a web summary of the manuscript and source artifacts. Editorial admission remains provisional; this presentation does not independently validate the historical evidence.

Publication

Research release
v0.17.0 · 6 September 2026
Supplied manuscript
Preprint v0.17.0; submission watermark dated 7 September 2026

Assessment & figure versions

Source figures
Figure register v0.16.0; original numbering retained
Case assessments
Oko v0.6.0; Patriot v0.3.0
Event-control rule
v0.16.0

Web presentation: Updated 17 September 2026

Appendix: exact figure data

The records below preserve the source findings, values, and evidence references, grouped by case or procedure. Figure numbers follow the manuscript. Original CSVs retain the source field names and row order.

Figure 2 · Practical-control states across three public cases

Extract each practical_control state in protocol order and render the declared categorical state without assigning a numeric score.

Underlying records

TAE-PUB-001

Oko false launch warning, 26 September 1983

Information access
Partially supported

Evidence: O2;O3;O4

Comprehension capacity
Partially supported

Evidence: O2;O3;O4

Intervention authority
Partially supported

Evidence: O2;O3;O4

Intervention feasibility
Partially supported

Evidence: O2;O3;O4

Exercised judgment
Partially supported

Evidence: O2;O3;O4

Execution propagation
Partially supported

Evidence: O2;O3

Correction
Outside scope

Evidence: O2;O3

Repair
Outside scope

Evidence: O2;O3

Institutional reform
Partially supported

Evidence: O2;O3

TAE-PUB-002

Patriot engagement of RAF Tornado ZG710, 22 March 2003

Information access
Partially supported

Evidence: T2;T3

Comprehension capacity
Unsupported

Evidence: T2;T3;T4

Intervention authority
Supported

Evidence: T2;T3;T4

Intervention feasibility
Unsupported

Evidence: T2;T3;T4

Exercised judgment
Unsupported

Evidence: T2;T4

Execution propagation
Unsupported

Evidence: T2;T3

Correction
Outside scope

Evidence: T2;T3

Repair
Unsupported

Evidence: T2;T3

Institutional reform
Supported

Evidence: T3;T4;T7

TAE-PUB-003

Patriot engagement of U.S. Navy F/A-18C, 2 April 2003

Information access
Partially supported

Evidence: F3;F4

Comprehension capacity
Indeterminate

Evidence: F3;F4;F5

Intervention authority
Supported

Evidence: F3;F4

Intervention feasibility
Indeterminate

Evidence: F3;F4;F5

Exercised judgment
Indeterminate

Evidence: F3;F4

Execution propagation
Unsupported

Evidence: F2;F3

Correction
Outside scope

Evidence: F2;F3

Repair
Unsupported

Evidence: F2;F3

Institutional reform
Supported

Evidence: F4;F5;F6

Figure A4 · Versioned correction of the Oko practical-control states

Read each prior and current state from the correction ledger and draw the recorded version transition without changing the source packet.

Underlying records

Information access

Prior · v0.3.0

Supported

Current · v0.6.0

Partially supported

Material gapNo contemporaneous delivery, interface, or command record was located.

Evidence: O2;O3;O4

Comprehension capacity

Prior · v0.3.0

Supported

Current · v0.6.0

Partially supported

Material gapNo contemporaneous reasoning, review, or explanation record was located.

Evidence: O2;O3;O4

Intervention authority

Prior · v0.3.0

Supported

Current · v0.6.0

Partially supported

Material gapNo contemporaneous delegation or command-procedure record was located.

Evidence: O2;O3;O4

Intervention feasibility

Prior · v0.3.0

Supported

Current · v0.6.0

Partially supported

Material gapNo contemporaneous timing or operating record was located.

Evidence: O2;O3;O4

Exercised judgment

Prior · v0.3.0

Supported

Current · v0.6.0

Partially supported

Material gapNo contemporaneous decision or communication log was located.

Evidence: O2;O3;O4

Execution propagation

Prior · v0.3.0

Supported

Current · v0.6.0

Partially supported

Material gapNo contemporaneous linked action, stop, or escalation record was located.

Evidence: O2;O3

Figure A1 · Prespecified mutation responses

Compare expected and observed assessment deltas by mutation and field, then plot the resulting state or the preserved invariance condition.

Underlying records

TAE-MUT-001

Post-action evidence must defeat pre-action access.

Base case: TAE-SYN-001

Control · Information access

From

Supported

To

Unsupported

Test result: Pass

TAE-MUT-002

An advisory role must defeat exercised control authority.

Base case: TAE-SYN-001

Control · Intervention authority

From

Supported

To

Unsupported

Test result: Pass

TAE-MUT-003

Ineffective institutional authority must weaken the trust proposition.

Base case: TAE-SYN-001

Trust · Human authority

From

Supported

To

Unsupported

Test result: Pass

TAE-MUT-004

Mutable records must defeat the integrity proposition.

Base case: TAE-SYN-001

Trust · Integrity

From

Supported

To

Unsupported

Test result: Pass

TAE-MUT-005

A procedure without completed correction must reduce correction support.

Base case: TAE-SYN-001

Control · Correction

From

Supported

To

Partially supported

Test result: Pass

Trust · Harm correction

From

Supported

To

Partially supported

Test result: Pass

TAE-MUT-006

Bypassed monitoring must defeat the monitoring proposition.

Base case: TAE-SYN-001

Trust · Monitoring

From

Supported

To

Unsupported

Test result: Pass

TAE-MUT-007

Changing the title must leave every assessment invariant.

Base case: TAE-SYN-001

Assessment response: Invariant

No individual assessment field or prior state is specified in this invariance record.

Test result: Pass

TAE-MUT-008

Changing the reported outcome must leave process assessments invariant.

Base case: TAE-SYN-008

Assessment response: Invariant

No individual assessment field or prior state is specified in this invariance record.

Test result: Pass

TAE-MUT-009

Changing impact radius must alter the autonomy profile without changing evidence assessments.

Base case: TAE-SYN-001

Assessment response: Invariant

No individual assessment field or prior state is specified in this invariance record.

Test result: Pass

TAE-MUT-010

Missing source completeness evidence must produce an indeterminate finding.

Base case: TAE-SYN-001

Trust · Evidence completeness

From

Supported

To

Indeterminate

Test result: Pass

TAE-MUT-011

Failed remediation must defeat the repair finding.

Base case: TAE-SYN-001

Control · Repair

From

Supported

To

Unsupported

Test result: Pass

TAE-MUT-012

Unchanged governance after failure must defeat institutional learning findings.

Base case: TAE-SYN-001

Control · Institutional reform

From

Supported

To

Unsupported

Test result: Pass

Trust · Governance update

From

Supported

To

Unsupported

Test result: Pass

Figure 1 · Public-case selection and stopping

Read collection counts and frozen candidate order, count selected and excluded decisions, and calculate unscreened candidate records as 928 minus 5.

Underlying records

AIID incident records

1,607

AIID report records

7,452

AIID candidate records

828

OECD exported candidate records

100

Preserved candidate records

928

Source: candidate-search-output.json

Screened records

5

Selected records

3

Excluded records

2

Filled strata

3

Source: selection-decisions.json

Unscreened records

923

Source: derived: preserved minus screened

Figure 3 · Bounded decision paths and public evidence gaps

Transcribe the five bounded chronology stages declared for each case and place them in relative event order.

Underlying records

TAE-PUB-001

Oko, 1983

  1. System output

    Oko displays a launch warning

    Evidence: O2;O3;O4

  2. Evidence check

    Petrov checks context and ground radar

    Evidence: O2;O3;O4

  3. Human decision

    Petrov classifies the warning as false

    Evidence: O2;O3;O4

  4. Human action

    The false-alarm judgment is communicated

    Evidence: O2;O3;O4

  5. Bounded effect

    The warning does not advance as confirmed

    Evidence: O2;O3

Evidence boundaryPublic sources give no defensible elapsed-time estimate for this bounded sequence.

TAE-PUB-002

Patriot ZG710, 2003

  1. System output

    Patriot classifies the aircraft as hostile

    Evidence: T2;T3

  2. Evidence check

    Identification and air-picture evidence remain incomplete

    Evidence: T2;T3

  3. Human decision

    The crew authorizes engagement

    Evidence: T2;T4

  4. System action

    Patriot launches a missile

    Evidence: T2;T3

  5. Harm outcome

    ZG710 is destroyed; both aircrew die

    Evidence: T2;T3

Evidence boundaryThe public record describes about one minute for the decision.

TAE-PUB-003

Patriot F/A-18C, 2003

  1. System output

    Two batteries report a missile track

    Evidence: F3

  2. System output

    The command center correlates the reports

    Evidence: F3

  3. Human decision

    A human engagement order is issued

    Evidence: F3;F4

  4. System action

    Patriot launches a missile

    Evidence: F3;F4

  5. Harm outcome

    The F/A-18C is destroyed; the pilot dies

    Evidence: F2;F3;F4

Evidence boundaryTiming, display state, report independence, and feasible intervention remain unresolved.

Figure 4 · Trust-evidence states across three public cases

Extract each trust_evidence state in register order and render the declared categorical state without assigning a numeric score.

Underlying records

TAE-PUB-001

Oko false launch warning, 26 September 1983

Identity
Partially supported

Evidence: O2;O3

Scope
Partially supported

Evidence: O2;O3

Capability
Indeterminate

Evidence: O2;O3

Reliability
Unsupported

Evidence: O2;O3;O4

Uncertainty
Unsupported

Evidence: O2;O3;O4

Evidence completeness
Unsupported

Evidence: O2;O3

Monitoring
Partially supported

Evidence: O2;O3

Human authority
Supported

Evidence: O2;O3;O4

Integrity
Indeterminate

Evidence: O2;O3

Reconstructability
Partially supported

Evidence: O2;O3;O4

Harm correction
Outside scope

Evidence: O2;O3

Governance update
Partially supported

Evidence: O2;O3

TAE-PUB-002

Patriot engagement of RAF Tornado ZG710, 22 March 2003

Identity
Partially supported

Evidence: T2;T3

Scope
Partially supported

Evidence: T2;T3;T4

Capability
Partially supported

Evidence: T2;T3

Reliability
Unsupported

Evidence: T2;T3;T4

Uncertainty
Unsupported

Evidence: T2;T3;T4

Evidence completeness
Partially supported

Evidence: T2;T3;T4

Monitoring
Partially supported

Evidence: T2;T3

Human authority
Partially supported

Evidence: T2;T3;T4

Integrity
Indeterminate

Evidence: T2;T3

Reconstructability
Partially supported

Evidence: T2;T3;T4

Harm correction
Unsupported

Evidence: T2;T3

Governance update
Supported

Evidence: T3;T4;T7

TAE-PUB-003

Patriot engagement of U.S. Navy F/A-18C, 2 April 2003

Identity
Partially supported

Evidence: F2;F3;F4

Scope
Partially supported

Evidence: F3;F4;F5

Capability
Partially supported

Evidence: F4;F5

Reliability
Unsupported

Evidence: F3;F4;F5

Uncertainty
Unsupported

Evidence: F3;F4;F5

Evidence completeness
Unsupported

Evidence: F2;F3;F4;F6

Monitoring
Partially supported

Evidence: F3;F4

Human authority
Partially supported

Evidence: F3;F4;F5

Integrity
Indeterminate

Evidence: F2;F3;F4

Reconstructability
Partially supported

Evidence: F2;F3;F4

Harm correction
Unsupported

Evidence: F2;F3

Governance update
Supported

Evidence: F4;F5;F6

Figure 6 · Evidence boundaries across six event-level practical-control stages

Count supported, partially supported, unsupported, and indeterminate classifications across the six event-level fields for each case and render the four counts as a six-cell stacked bar.

Underlying records

TAE-PUB-001

Oko false launch warning, 26 September 1983

Denominator: 6 required control stages. Counts describe categories.

Supported
0 / 6

No stages in this category

Partially supported
6 / 6

Information access; Comprehension capacity; Intervention authority; Intervention feasibility; Exercised judgment; Execution propagation

Unsupported
0 / 6

No stages in this category

Indeterminate
0 / 6

No stages in this category

TAE-PUB-002

Patriot engagement of RAF Tornado ZG710, 22 March 2003

Denominator: 6 required control stages. Counts describe categories.

Supported
1 / 6

Intervention authority

Partially supported
1 / 6

Information access

Unsupported
4 / 6

Comprehension capacity; Intervention feasibility; Exercised judgment; Execution propagation

Indeterminate
0 / 6

No stages in this category

TAE-PUB-003

Patriot engagement of U.S. Navy F/A-18C, 2 April 2003

Denominator: 6 required control stages. Counts describe categories.

Supported
1 / 6

Intervention authority

Partially supported
1 / 6

Information access

Unsupported
1 / 6

Execution propagation

Indeterminate
3 / 6

Comprehension capacity; Intervention feasibility; Exercised judgment

Figure A2 · Reproducibility lineage

Render the declared research and figure-generation artifact graph in process order and record hashes for the committed publication artifacts.

Underlying records

Research lane · Nodes

  1. Frozen collections

    AIID and OECD inputs | SHA-256 recorded

    collections

  2. Candidate search

    928 candidate records | frozen vocabulary

    candidates

  3. Selection register

    5 decisions | 3 strata filled

    selection

  4. Case packets

    3 reports and | source manifests

    packets

  5. Assessments

    JSON states and | evidence references

    assessments

  6. Release archive

    version manifest | and archive DOI

    archive

Figures lane · Nodes

  1. Plot inputs

    Assessments, search, | mutations, audit

    plot_inputs

  2. Figure builder

    two builders | fixed ordering

    builder

  3. Derived tables

    9 CSV files | cell provenance

    derived

  4. Rendered figures

    9 SVG and | 9 PNG files

    figures

  5. Integrity check

    CSV equality and | artifact integrity

    validation

Connections · Edges

  • collectionscandidates
  • candidatesselection
  • selectionpackets
  • packetsassessments
  • assessmentsarchive
  • plot_inputsbuilder
  • builderderived
  • derivedfigures
  • figuresvalidation
  • assessmentsplot_inputs

    Assessment outputs feed figure inputs

Figure A3 · Claim-evidence integrity

Declared claim-gate states from the source figure data.

Underlying records

Claims with identical results share one group. Every claim ID is listed; the five gate findings apply to each claim in that group.

37 claims

Eligible

Conclusion eligibility

  • PAPER-C02
  • PAPER-C03
  • PAPER-C04
  • PAPER-C05
  • PAPER-C06
  • PAPER-C07
  • PAPER-C08
  • PAPER-C09
  • PAPER-C11
  • PAPER-C14
  • PAPER-C15
  • PAPER-C22
  • PAPER-C23
  • PAPER-C24
  • PAPER-C25
  • PAPER-C26
  • PAPER-C27
  • PAPER-C28
  • PAPER-C29
  • PAPER-C30
  • PAPER-C31
  • PAPER-C33
  • PAPER-C34
  • PAPER-C35
  • PAPER-C36
  • PAPER-C37
  • PAPER-C38
  • PAPER-C39
  • PAPER-C40
  • PAPER-C42
  • PAPER-C43
  • PAPER-C44
  • PAPER-C45
  • PAPER-C46
  • TAE-C21
  • TAE-C24
  • TAE-C25
Traceability
Pass
Integrity
Pass
Support
Pass
Evidence fitness
Pass
Dependency closure
Pass

1 claim

Blocked

Conclusion eligibility

  • PAPER-C32
Traceability
Pass
Integrity
Pass
Support
Pass
Evidence fitness
Indeterminate
Dependency closure
Pass

1 claim

Blocked

Conclusion eligibility

  • PAPER-C41
Traceability
Fail
Integrity
Indeterminate
Support
Indeterminate
Evidence fitness
Indeterminate
Dependency closure
Pass

1 claim

Blocked

Conclusion eligibility

  • TAE-C23
Traceability
Pass
Integrity
Pass
Support
Pass
Evidence fitness
Fail
Dependency closure
Outside scope

Figure 5 · Formal search retrieval and final screening state

Sum direct-query and citation-chain retrieval counts, preserve the pooled and deduplicated totals, apply the 89 author decisions to the queued records, combine those decisions with the previously screened classes, and plot the six final screening classes on a declared logarithmic axis.

Underlying records

Direct queries

Retrieved184

Author attention: no

Source: formal-search-v0.7.0.json

Citation chains

Retrieved2,482

Author attention: no

Source: formal-search-v0.7.0.json

Combined pool

Pooled2,666

Author attention: no

Source: formal-search-v0.7.0.json

Deduplicated pool

Deduplicated2,431

Author attention: no

Source: formal-search-v0.7.0.json

Preliminary triage

Retain-close12

Author attention: yes

Retain-background13

Author attention: no

Exclude-single-component77

Author attention: yes

Exclude-topic1,239

Author attention: no

Inaccessible1,087

Author attention: no

Exclude-outside-cutoff3

Author attention: no

Source: formal-screening-proposals-v0.7.0.json

Final screening

Retain-close27

Author attention: complete

Retain-background45

Author attention: complete

Exclude-single-component10

Author attention: complete

Exclude-topic1,259

Author attention: complete

Inaccessible1,087

Author attention: separate gate

Exclude-outside-cutoff3

Author attention: complete

Source: derived from author-screening-decisions-v0.9.0.csv and formal-screening-proposals-v0.7.0.json

Author gate

Closed queue89

Author attention: complete

Source: author-screening-gate-v0.9.0.json