The previous section established why this work proceeded by building, not what was built. That answer is not this chapter's to invent: the review already settled it, and what follows reads the specification off the preceding chapter rather than proposing one. The reason this is a continuation rather than a fresh start is that the composition the review found missing appears in that chapter three times in the same words: once in the introduction as the claim to be tested, once in the synthesis as the claim discharged, and once between them as the standard each field was walked against. Its parts are a portable and per-claim representation of evidential basis, action-relative admissibility, derivation-aware basis preservation, and mechanical evaluation across an ownership boundary. Ten literatures were read against that list, and each was found to hold one or two of its parts while none held them together at a machine handover.
A list arrived at that way is not a summary of the review. It is a requirements list derived by survey, and its authority comes from the survey rather than from the designer's sense of what would be interesting to build. This section's only liberty is to say what each part must represent with enough precision to be implemented, and to type the parts into the categories the paradigm supplies.
The categories are the paradigm's, not this chapter's
Design science research takes its artefacts to be constructs, models, methods, or instantiations (Peffers et al., 2007). Those four categories are not a scheme devised for this work, and reading the composition into them is the paradigm doing its ordinary job rather than a device for making the contribution look tidy.
The mapping is worth a moment's notice for a reason beyond bookkeeping. The composition falls into the four categories without strain: nothing has to be forced, and no part of it turns out to be the kind of thing design science has no name for. That is weak evidence, but it is evidence, that what the review found is a design problem rather than a philosophical one. Had the missing composition resolved into a question about what justification is, or about when belief is warranted in general, the paradigm would have been the wrong instrument and the strain would have shown here first.
| What the review found missing | What kind of artefact that is |
|---|---|
| A portable, per-claim representation of evidential basis | Constructs and a model |
| Derivation-aware basis preservation | A method |
| Action-relative admissibility | A method |
| Mechanical evaluation across an ownership boundary | An instantiation |
The constructs and the model
The first row carries the weight, and the others are in a real sense operations upon it. A representation of evidential basis is where the vocabulary is fixed, and fixing a vocabulary is what design science means by constructs: the terms in which the problem and its solution are subsequently stated. The model is the structure those terms compose into, which is to say what a basis is taken to consist of when it is attached to a single claim and carried.
The review is specific about what such a representation must exceed, and the specificity is inherited rather than chosen. It must exceed origin, because the provenance standard records origin in full and places the assessment built on that record outside itself, describing it as a use made by external parties rather than a function it performs (W3C, 2013a). It must exceed integrity, because the attestation framework authenticates custody and states that it does not validate whether the claims it carries are correct (in-toto, n.d.). It must exceed confidence, because the uncertainty field's own comprehensive survey concludes that estimating predictive uncertainty is not sufficient for safe decision-making (Gawlikowski et al., 2021). Three fields, three explicit statements of a limit, and together they fence the representation in from three sides without anyone in this work having proposed anything.
What has to be represented positively, rather than by exclusion, is the harder question, and the chapter commits to answering it in nameable terms. A basis is not a scalar and it is not a score. The candidate elements are what the claim rests on and by what means it was established — named here, as a first candidate the design chapter tests and later splits, as one of observation, measurement, inference, generation, or report; what independent support exists for it, and whether the supports are genuinely independent or share an ancestor and therefore do not corroborate each other; what authority stands behind it and on whose say-so; when it was established and how quickly the underlying condition changes, since a basis has a shelf life that varies by what it is about; and the scope within which it was established, since a claim true of a sample is not thereby true of a population, and a claim true at one point in a plant is not true of the plant.
Whether those are the right elements, whether they are complete, and whether some of them collapse into others is not settled here, and this chapter does not pretend to settle it. It is the work of the design chapter, informed by the targeted reading that section commissions. What is settled here is the standard the answer will be held to, which is that each element must be nameable, must be attachable to an individual claim, and must survive being carried across a boundary to a consumer that did not produce it.
The methods
Two of the composition's parts are methods, meaning procedures over the model rather than additions to it, and the review's account of each is what fixes the problem the design chapter has to solve.
Derivation-aware inheritance governs what happens when claims become inputs to other claims. The problem statement's laundering path is the thing to be prevented: a model-inferred value feeds a human-authored assessment, the assessment is filed as a report, and the report is later retrieved as authoritative record, with no falsehood introduced at any step and the probabilistic origin of the first inference now unrecoverable. An inheritance rule is the method that makes such an ancestry survive the derivations performed upon it. This was originally recorded as a question about when a derived claim's standing may exceed its weakest ancestor's. The design chapter answers it differently, and the answer narrows the method rather than widening it: no descriptive field of a basis is ever raised. What changes is which supports a basis contains, through composition, fresh acquisition or an explicit ancestry reset, and the verdict follows from reevaluating the changed basis. Mutually dependent sources still do not corroborate at all, which the origin set settles mechanically.
An earlier version of this chapter named a third method, constrained elevation, on the reasoning that False Determinism is an unsanctioned elevation and that some elevations are warranted. The design chapter withdrew it, and the withdrawal is a finding rather than a simplification. The motivating case does not survive inspection as an elevation. A claim inferred and then independently measured has not had its earlier basis raised: the measurement establishes a new evidential ground. Where that ground replaces rather than supplements generated ancestry, the replacement is explicit and its reset travels with the record.
So the artefact must distinguish basis preservation, composition and re-establishment from unrecorded ancestry loss. It need not distinguish earned elevation from asserted elevation, because no elevation operation exists. What the receiving system does with a claim it should not have acted on is still an elevation, and that is the failure the work is named for; it is not an operation the artefact performs.
Action-relative admissibility is the method that gives the model its point, and it is where the review found the fields to be most nearly silent. The problem statement puts the case concretely: a claim that a circuit is de-energised is adequate for deciding what to investigate next and inadequate for deciding whether to touch it, and the difference between those two uses is a difference in what the act demands of its evidence rather than a difference in confidence. Admissibility is therefore a relation between a basis and an intended action, not a property of a claim. A method that returned a verdict on a claim alone would have answered a question nobody asked.
The instantiation
The fourth part is an instantiation, and it is what stops the preceding three from being a proposal. A discipline that exists only as a description of itself has not been shown to be mechanisable, and mechanisability is precisely the contested claim: the review's finding was that every surveyed field hands the judgement to a person, so a contribution that also, at the end, requires a person to apply it has not moved the boundary. The instantiation is a reference implementation as a software library, enforcing at the point where a claim crosses from one owner to another, which is the boundary the review identified as the one where nobody is standing. The question that types it is therefore whether the discipline can be enforced at a machine handover with no person present, which is what an instantiation demonstrates. Whether it discriminates well, rejecting False Determinism without rejecting too much legitimate practice, is a different question and a property of the whole discipline rather than of the instantiation alone. It is tested against the instantiation rather than answered by it, and it is deferred to the evaluation, where it is the thing the work is falsifiable on.
The review also established what the instantiation is not obliged to invent. An authenticated attestation envelope is the natural transport for a basis representation once one exists, and a runtime policy engine is the natural evaluator of it, with the attestation literature already naming automated policy engines as an attestation's intended consumers. The existing machinery composes into a pipeline from transport into evaluation with one part missing, and the missing part is the model of basis that would give the pipeline something meaningful to carry and to decide. The instantiation's job is to supply that part and to use the existing machinery for the rest, not to rebuild what already functions.
Precision, and where it stops
A basis model described as capturing relevant provenance factors is weak prose and unimplementable, and those are the same defect. Naming what the basis represents exposes the model to the objection that it has named the wrong things, which is the objection it needs while changing the answer is still cheap. Interfaces, class structures and type signatures belong to the instantiation and are not sketched here.
References
W3C (2013a). PROV-DM: The PROV Data Model. W3C Recommendation. w3.org/TR/prov-dm
in-toto (n.d.). in-toto Attestation Framework: Specification. github.com/in-toto/attestation
Gawlikowski, J., et al. (2021). A Survey of Uncertainty in Deep Neural Networks. Artificial Intelligence Review. arXiv:2107.03342. arxiv.org/abs/2107.03342
Peffers, K., Tuunanen, T., Rothenberger, M. A. and Chatterjee, S. (2007). A Design Science Research Methodology for Information Systems Research. Journal of Management Information Systems, 24(3), pp. 45-77. doi.org/10.2753/MIS0742-1222240302