The basis model fixed what a claim rests on and made it portable to the boundary. This is the method that acts there. It reads a basis record against the demand of an intended act and returns a verdict on whether that basis suffices for that act, and it is the judgement the whole discipline exists to perform: the one the review's synthesis found every surveyed field handing to a human, and the one the methodology's trap says must be made where no human is standing. It also carries the most weight of anything in the artefact: three neighbouring formalisms bear on it, the basis model leaves two judgements to it, and the evaluation defines its error over its verdict.
What follows states what the method takes, what it returns, what it weighs, and to what standard.
What the method takes
The method takes two arguments, and the basis model has already fixed that it is two rather than one. The first is the basis record: acquisition and transformation, authority with its validity, establishment time paired with rate of change, established scope, and the origin set. The second is the act's demand, which the record deliberately does not hold. The reason is not economy but category. Admissibility is a relation between a basis and an intended action, and a relation is not stored in either of the things it relates; putting the act's demand inside the record would make a claim's basis depend on what someone intends to do with the claim, which is backwards, and the basis model spine excluded it on exactly that ground.
That exclusion, however, only relocated the question. If the act's demand is the method's second argument then an account of what a demand is is required, and the account the artefact carries is structural rather than substantive. The demand is the act's side of the same axes the basis speaks on, because otherwise the two cannot be compared: where the basis carries an established scope, the act carries a required scope; where the basis carries a temporal standing, the act carries a tolerance for staleness; where the basis carries an acquisition, a transformation and an authority, the act carries a threshold on which of those and whose live authority it will accept. A demand is an act stating, on each axis the basis speaks to, what it requires. The example in the problem statement is exactly this: a claim that a circuit is de-energised is adequate for deciding what to investigate next and inadequate for deciding whether to touch it, and the difference between those two uses is a difference in what the act demands of its evidence, not a difference in confidence.
What the method weighs: four comparisons, not three
The basis record commits this method to making three comparisons against the act, and named the basis side of them as establishment time, rate of change, and established scope. That count is revised rather than inherited, because the same entry leaves two further judgements to this method by name, and both resolve into axes. Freshness is one: the record carries when a basis was established and how fast its condition moves, and whether that standing suffices is a comparison against the act, not a fact about the record. Authority validity is the other, on the same pattern: the record carries that a vouching had a validity and whether it still holds, and whether a vouching that was live when made but has since lapsed suffices for this act is decided here. Acquisition and transformation are closed categorical vocabularies built so that this method can branch on them mechanically, which is a use, not an ornament.
Read together, the comparisons the record actually equips this method to make are four rather than three, and they are stated here as four:
- Scope. The basis was established within some bounds and the act requires some bounds, and the method must judge whether the established scope covers the required scope. A claim true of a sample is not true of the population, and a basis established at one point in a plant does not reach an act on the whole plant. That fitness is relative to a use is not a new observation; the provenance literature states it directly, holding that a recorded history exists so that a user may apply their own metrics to determine whether data is acceptable (Simmhan et al., 2005). What is new here is that the metric is applied by the method rather than by the user, against a demand the act states rather than one a person forms.
- Freshness. The basis has a temporal standing given by when it was established and how fast its condition changes, and the act has a tolerance for staleness. A basis adequate for a slow condition is not adequate for a fast act.
- Production. The basis carries how its evidence was acquired and what operation produced the claim from it, and the act sets a threshold on which of those it will accept. A generated value where the act demands a measured one fails here, and this is the comparison in which False Determinism is most directly refused.
- Standing of the voucher. The basis carries an authority and that authority carries a validity, and the act sets a threshold on whose say-so it accepts and whether a lapsed vouching still counts.
Naming four where the record said three is a correction to a published count, and it is made openly rather than quietly, because the earlier count of three was fixed before the SPKI reading added authority validity to the record.
What the method does beyond the four is combine them. The axes are gates and do not trade off: any axis that refuses refuses the whole, and no axis compensates for another. Nothing is graded, because a graded axis would need a scale across axes and that scale is the confidence signal in another notation.
What the method returns
The verdict decides: this basis is admissible for this act, or it is not. That much is forced at the point of enforcement, because the act is either taken or refused. It does not follow that the verdict itself is two-valued, and the machine learning literature on declining to answer is why it is not. Selective prediction gives a model an integrated reject option, trading coverage for a bounded error rate on what it does answer (Geifman and El-Yaniv, 2019), and learning to defer hands a case to a downstream expert on the expert's expected accuracy rather than the model's own uncertainty (Mozannar and Sontag, 2020). Both are three-valued in substance: act, refuse, or hand on. Admissibility needs the third value, and the verdict carries three: admit, refuse, and undetermined. Assuming two because enforcement is binary would have assumed the answer, and the distinction that forces the third is between an axis the demand constrained but the record cannot answer and an axis the demand never mentioned. Collapsing those two is the shortest route to an unsafe admission. The discrimination test reads over accept-or-refuse decisions, and the third value is not folded into them: decision coverage counts the scenarios that reached admit or refuse, and the undetermined ones are reported separately, grouped by the axis that could not be evaluated. A system that never adjudicates has no discrimination to report, so hiding the undetermined inside a refusal rate would conceal exactly the failure decision coverage exists to expose.
The second question the basis model leaves here is whether the verdict carries more than the decision: which axis failed, by what margin, and on what basis the refusal rests. There is a real argument for it, and it is not this work's to make: the governance frameworks the review surveyed locate contestability at exactly this handover. European law requires that a high-risk system be transparent enough for a deployer to interpret its output and use it appropriately (European Union, 2024), and the international recommendation requires meaningful information sufficient to enable those affected to understand an output and to challenge it (OECD, 2019). A refusal that cannot say why it refused is a decision that cannot be challenged. Against that stands the finding, from the same survey, that explanation is where such mandates go to be approximated: the dominant post-hoc methods build simplified surrogates that give false assurances and do not evidence the acceptability of what they explain (Mittelstadt et al., 2018). A reason attached to a verdict would have to carry the basis it rests on rather than a plausible account of it, or it reproduces the failure the review documented. There is a real argument against it: a reason is not required to enforce or to evaluate, and building an explanation apparatus is how a minimal method stops being minimal. It is settled in favour of carrying the reason, on evidence rather than on the argument: the verdict returns a trace built from the very evaluations the verdict is computed over, so the reason cannot drift from the decision because it is not assembled separately from it. The cost the argument against predicted is real and bounded — the trace is the largest single part of the artefact's output — and the evaluation could not have been run without it.
One thing is settled. Whatever the verdict carries, it is a judgement about this basis and this act, and not a score on the claim. A score on the claim alone would be the confidence signal the review spent a chapter establishing is the wrong category, and a method that returned one would have rebuilt the thing the work exists to replace (Gawlikowski et al., 2021).
What three formalisms return
Three formalisms bear on this method, each against a named question it raises rather than against the field in general. Decision theory bears on the combination of the four comparisons, because a basis sufficient for a low-stakes act and insufficient for a high-stakes one is action-relativity itself, and relating sufficiency to the consequence of an act is decision theory's home question. It is engaged here against that one question, and what it returns bounds what the method may assume.
The risk in reading it was that decision theory would import the scalar. Expected-utility theory ranks options by a single number, and a verdict that reduced to one would be the confidence signal the review ruled out, expressed in a different notation. That fear turns out to be misplaced, and the reason is instructive: the scalar is not a result of the theory but a consequence of one of its axioms. Completeness, the requirement that any two options be comparable, is what makes a single ranking possible, and it is contested rather than assumed. Many hold that completeness is not rationally required, on the ground that rationality constrains the judgements an agent actually holds and does not demand that a judgement be held at all (Steele and Stefansson, 2020). Where completeness is dropped, preferences are represented not by one probability-utility pair but by a set of them, and choice is made by a function that returns an admissible subset of the available options under a constraint such as expected-utility non-dominance.
That is a combination rule that does not collapse to a number, and it is close to the shape this method needs: several considerations held simultaneously, no single scale forced across them, and a decision procedure that returns what is admissible rather than what is best. The four comparisons are treated as a set of that kind, under the strictest available constraint: an option survives only if no comparison refuses it, which is non-dominance where refusing is itself an act with consequences. What the reading settles is that combining without a scalar is a position the field already holds, so the method need neither invent it nor abandon decision theory to avoid the scalar.
The reading returned one further thing this work did not go looking for. Maxmin expected utility, the rule that picks the option with the greatest minimum expected utility, is the field's formalisation of deciding cautiously, and the field's own assessment is that it is arguably much too cautious (Steele and Stefansson, 2020). That is the over-conservatism this chapter declared a failure mode rather than a safe harbour, reached independently by a literature that had never heard of this work, which is the kind of corroboration the inherited-criteria argument was built to prefer. Evidence theory bears on the same combination from a different side: where two supports are partially dependent the record already carries the overlap in its origin sets, and what a graded combination of partially dependent evidence yields is evidence theory's question, not the record's. What it returns is that the question does not arise here, because the model declines to grade partial dependence at all. Shared origins veto corroboration mechanically, answerable from the records alone; disjoint origins lift that veto and grant nothing, since disjointness establishes only that no dependence is recorded, and reading it as established independence converts absence of evidence into evidence. A discount factor over partially dependent supports would have to be computed from an overlap the record can detect but cannot size, so the model refuses instead of grading. Epistemic logic is engaged against the verdict. It is not needed, which is a complete outcome rather than a gap: a field examined against a stated lack and found not to supply it has been answered. Epistemic logic models what an agent knows as a modality over propositions, and its central open difficulty is logical omniscience: the standard semantics closes knowledge under entailment, so an agent knows every consequence of what it knows, and a substantial literature of impossible worlds and awareness logics exists to escape an idealisation the formalism itself introduces (Rendsvig et al., 2024). The verdict this method returns is not a modality over propositions and makes no claim about what an owner knows. It evaluates a basis against an act's demand and returns whether the one suffices for the other. The field's hard problem is one this method does not have, and this method's question is not one the field poses.
Each is read under the two gates the reading fixed: name the method's specific lack in one sentence before the field is opened, and confirm on the demonstrable-lack criterion before anything is adopted. A field that cannot be given a one-sentence lack does not open, and the record reading has already shown that gate cutting three candidate fields to one.
The standard, and where the method stops
Two standards govern, both inherited. The method must be precise enough to implement and therefore precise enough to argue with, because a weighing described in vague terms is both weak prose and uncodeable. And it must not collapse into the fields the review distinguished the work from. If the verdict reduces to a threshold on a confidence value, the uncertainty survey's own conclusion refutes it (Gawlikowski et al., 2021). If the sufficiency criteria arrive from outside the method rather than being held by it, then what has been built is a policy engine evaluating attributes it did not define, and the policy literature refutes it (NIST, 2014). If the criteria are settled at design time over evidence whose standing is presupposed, it is an assurance case with extra steps (Hawkins et al., 2021). The method's whole point is that it holds the criteria for sufficiency, act by act, rather than presupposing them or importing them.
The method stops where the frame stops it. It is the minimal weighing that makes the four comparisons, combines them into a verdict, and gives the discrimination evaluation a set of decisions to read over. It does not become a general theory of decision under uncertainty. None of the three proved to need more than the question each was opened against, so none became a chapter. The gate that decided it is the same one used everywhere: a field is adopted on evidence of this method lacking a semantics it needs, and none of the three supplied one the four comparisons did not already carry.
What the method fixes
Fixed: the method takes a basis record and an act's demand; the demand is the act's side of the axes the basis speaks on; the method makes four comparisons, on scope, freshness, how the claim was produced, and standing of the voucher; it returns a three-valued verdict with the trace it was computed from; it holds the sufficiency criteria itself rather than importing them; and it is where decision theory, evidence theory, and epistemic logic are engaged, each against a named lack.
References
Rendsvig, R., Symons, J. and Wang, Y. (2024). Epistemic Logic. Stanford Encyclopedia of Philosophy. plato.stanford.edu/entries/logic-epistemic
Steele, K. and Stefansson, H. O. (2020). Decision Theory. Stanford Encyclopedia of Philosophy. plato.stanford.edu/entries/decision-theory
Geifman, Y. and El-Yaniv, R. (2019). SelectiveNet: A Deep Neural Network with an Integrated Reject Option. ICML 2019. arXiv:1901.09192. arxiv.org/abs/1901.09192
Mozannar, H. and Sontag, D. (2020). Consistent Estimators for Learning to Defer to an Expert. ICML 2020. arXiv:2006.01862. arxiv.org/abs/2006.01862
European Union (2024). Regulation (EU) 2024/1689 (Artificial Intelligence Act), Article 13. Official Journal of the European Union. eur-lex.europa.eu
OECD (2019). Recommendation of the Council on Artificial Intelligence, Principle 1.3. OECD/LEGAL/0449. legalinstruments.oecd.org
Mittelstadt, B., Russell, C. and Wachter, S. (2018). Explaining Explanations in AI. FAT* 2019. arXiv:1811.01439. arxiv.org/abs/1811.01439
Simmhan, Y. L., Plale, B. and Gannon, D. (2005). A Survey of Data Provenance Techniques. SIGMOD Record, 34(3). doi.org/10.1145/1084805.1084812
Gawlikowski, J., Njieutcheu Tassi, C. R., Ali, M., Lee, J., Humt, M., Feng, J., Kruspe, A., Triebel, R., Jung, P., Roscher, R., Shahzad, M., Yang, W., Bamler, R. and Zhu, X. X. (2021). A Survey of Uncertainty in Deep Neural Networks. Artificial Intelligence Review. arXiv:2107.03342. arxiv.org/abs/2107.03342
NIST (Hu, V. C., et al.) (2014). Guide to Attribute Based Access Control (ABAC) Definition and Considerations. NIST SP 800-162. doi.org/10.6028/NIST.SP.800-162
Hawkins, R., Paterson, C., Picardi, C., Jia, Y., Calinescu, R. and Habli, I. (2021). Guidance on the Assurance of Machine Learning in Autonomous Systems (AMLAS). University of York. arXiv:2102.01564. arxiv.org/abs/2102.01564