A literature review earns trust not by sounding unassailable but by showing its claims under pressure and recording what survived. This register does that in the open. It lists the points at which the review, or the argument it supports, was found to overreach or to rest on prior machinery not yet examined, and it states for each whether it has been corrected, must be resolved before the formal model is frozen, or is carried forward as acknowledged debt. It is a living document: entries move from open to resolved, and new ones are added as the work is pressured further.
The organising test for triage is a single question: could this change the shape of the artefact that is to be built? If yes, it is corrected now or marked as design-threatening and reviewed before the basis model stabilises. If it affects only how the finished contribution is positioned or illustrated, it is recorded as debt and the work proceeds.
Tier 1: Corrected now (load-bearing premises)
These formed premises for later work or defined the project's novelty, so they were fixed before the formal model is built on language already known to be unsound.
| Claim under pressure | The problem | Resolution | Status |
|---|---|---|---|
| "No mature discipline produces admissibility." | A universal negative over fields not all surveyed (evidence theory, decision theory, trust management, and others). Indefensible as stated, and it inflated the novelty claim. | Narrowed in the introduction and carried into the synthesis to a claim about composition: a portable, per-claim representation of evidential basis, supporting action-relative admissibility, derivation-aware inheritance, constrained elevation, and mechanical enforcement across an ownership boundary. The claim is now that this composed capability, enforced at a machine handover, is unfilled, not that no one judges evidential sufficiency anywhere. | Resolved |
| Policy classified as "an integrity discipline." | Policy is a decision and enforcement mechanism that operates over supplied semantics; it is not an integrity mechanism. The body of the section explained this correctly, but the organising language misclassified it. | The section's synthesis line now distinguishes kinds: provenance and attestation are integrity mechanisms; policy is an evaluation and enforcement mechanism. What unites the three is not their kind but their shared silence on whether a value's basis suffices for the act. | Resolved |
| Abstention and deferral "decide from the same confidence signal." | Factually inaccurate for learning to defer, which can learn a comparative judgement of expert-versus-model performance directly rather than reading the model's own confidence. | The trustworthy-ML section now separates the two: selective prediction does gate on the confidence signal; learning to defer need not. Both still decide only at the model and carry no basis across the boundary, which is the point that survives. | Resolved |
| Weakest-ancestor inheritance as the rule for derived claims. | Taking a derived claim's standing to be that of its weakest ancestor is a safe conservative default but cannot be the full rule: independent corroboration, testing, or proof can legitimately strengthen a derived claim, and mutually dependent sources do not corroborate. Baking minimum-propagation into the basis model would make legitimate promotion look like a bolted-on exception. | Recorded as an explicit design guardrail, not yet asserted as a rule in any published text. The basis model must represent evidential independence, transformation, scope, and legitimate promotion, with weakest-ancestor propagation used only as the conservative default where those are absent. Flagged for resolution during model design (see Tier 2). | Guardrail set |
Tier 2: Design-threatening, targeted review owed before the basis model is frozen
These are not positioning debt. Each names a field that may already contain semantics this work would otherwise invent for basis, corroboration, dependence, promotion, or action-relative acceptance. The review owed is not "does this field already contain Attestable" but "does it already contain machinery I should adopt rather than reinvent." The sequence is deliberate: draft the smallest basis model, identify its load-bearing semantics (dependence, corroboration, authority, freshness, scope, consequence, promotion), pressure-test only those against these fields, then stabilise the model. Freezing the semantics before this check is the specific risk being guarded against.
| Field | The semantics it may already supply | Status |
|---|---|---|
| Evidence theory (Dempster-Shafer, subjective logic) | Representation of corroboration, conflict, and dependence between items of evidence. | Review owed |
| Decision theory | How basis sufficiency relates to consequence and to the action chosen. | Review owed |
| Trust management systems | Existing semantics for delegated authority and constrained elevation. | Review owed |
| Contract-based design and runtime assurance | Where and how a barrier of this kind is enforced; pre/post-condition and envelope machinery. | Review owed |
| Epistemic logic | Formal machinery for representing what an owner is entitled to claim. | Review owed |
| Proof-carrying code | Architectural precedent for carrying justification alongside an actionable artefact. | Review owed |
Tier 3: Carried forward as acknowledged debt (positioning and illustration)
These affect how the contribution is positioned or illustrated, not the shape of the artefact. They should be resolved before the literature review is treated as finished, but they do not block designing the model.
| Claim under pressure | Why it is debt, not a blocker | Status |
|---|---|---|
| IT "ranks confidentiality first" while OT inverts it. | Familiar OT rhetoric, not a defensible general statement about all IT. Resolved in section 4 using the authoritative NIST SP 800-82r3 formulation: OT prioritises integrity and availability, then confidentiality, with safety overarching. The imprecise "confidentiality-first inverted" shorthand is removed. | Resolved |
| "OT actions are irreversible." | Actions are often reversible; their consequences may not be. The distinction between irreversible action and irreversible consequence matters and must be drawn in the thesis, but the shorthand does not shape the model. | Open (debt) |
| A firewall "polices provenance of transit." | A firewall enforces permitted flows over observable or derived attributes; it does not track provenance. The analogy still lands; the wording overreaches. | Open (debt) |
| Triton as evidence for the AI-specific mechanism. | Triton is a strong illustration of unsupported diagnosis being acted upon at a handover, i.e. of False Determinism as a general failure. It is not evidence about probabilistic generation specifically. Keep it as illustration, not as support for the AI-specific claim. | Open (debt) |
What this register commits the work to
Two things follow from keeping this register. First, the novelty claim is now bounded and falsifiable: the contribution stands or falls on whether the composed capability can discriminate safely and usefully in realistic handover scenarios, not on an unprovable claim that no field anywhere judges evidential sufficiency. Second, the basis model will not be frozen until the Tier 2 fields have been pressure-tested against its load-bearing semantics. That is the difference between coding before the literature is perfect, which is healthy, and freezing semantics before checking relevant prior machinery, which is not.