Governance model
Two axes that are never conflated. Risk class describes the consequence of an action. Trust state describes the maturity of data. The authority matrix binds them, and every control in this sandbox routes through it.
SRS section 3, governance taxonomy
Unverified
Raw ingested content. No extraction has been attempted and nothing may cite it as evidence.
AI Extracted
Produced by the extraction model with a source anchor. Never gate-effective on its own.
Human Reviewed
An engineer has read the claim against its source anchor but has not accepted it.
Engineer Accepted
Accepted by a named engineer. Usable for downstream engineering work, not yet canonical.
Canonical
Single authoritative value selected by an Engineer Lead where claims conflicted.
Baselined
Frozen inside an approved baseline. Changing it requires a controlled change with impact analysis.
Read
Reads records. No state change, no audit consequence beyond access logging.
Draft
Creates or edits draft data and AI claims. The only class an AI agent may ever reach.
Propose
Submits work for review, raises open items, requests a check run.
Accept
Promotes data trust: accepting a claim, resolving a conflict, selecting a canonical fact.
Requires data at L1 or above.
Approve
Passes a workflow gate or approves a document revision for issue.
Requires data at L3 or above.
Baseline
Freezes a contractual baseline or releases to production. Highest consequence action.
Requires data at L4 or above.
| Role | C0Read | C1Draft | C2Propose | C3Accept | C4Approve | C5Baseline |
|---|---|---|---|---|---|---|
| ViewerRead-only access to project records and audit history. | ||||||
| EngineerDrafts engineering data, reviews and accepts extraction claims, raises open items. | ||||||
| Engineer LeadEverything an Engineer may do, plus canonical selection on conflict and gate approval. | ||||||
| ManagerBaseline freeze and production release authority. | ||||||
| AI AgentMay only produce draft claims. Structurally incapable of accepting, approving or baselining. | ||||||
| Deterministic CheckerThe only actor whose verdicts are gate-effective. Proposes findings, never approves. |
| From | To | Action | Risk | Minimum role | Note |
|---|---|---|---|---|---|
| L0 | L1 | Run extraction | C1 | AI Agent | Extraction produces claims with source anchors. It cannot promote further than L1. |
| L1 | L2 | Mark reviewed | C1 | Engineer | Records that a human compared the claim against its anchor. |
| L2 | L3 | Accept claim | C3 | Engineer | Attributes the value to a named engineer. Reversible only by a new accepted claim. |
| L1 | L3 | Accept claim directly | C3 | Engineer | Permitted when the engineer reviews and accepts in one step from the workbench. |
| L3 | L4 | Select canonical fact | C3 | Engineer Lead | Resolves competing accepted claims into one authoritative value. |
| L4 | L5 | Freeze in baseline | C5 | Manager | Baseline membership is immutable. Later change requires impact analysis. |
Role
Action risk
Data trust
Permitted
Engineer is authorised for C3 Accept.
AICEED-GOV-004 (section 3.4 authority matrix)