Superseded. This is an earlier draft of the methodology chapter, retained as a record of what the work believed at the time. It is not current: the composition it describes includes constrained elevation, which the design chapter withdrew after implementation established that no axis of a basis is elevatable. The current chapter is the one published under the methodology category.
The previous section established why this work proceeds by building, not what is to be built. That answer is not this chapter's to invent: the review already settled it, and what follows reads the specification off the preceding chapter rather than proposing one. The reason this is a continuation rather than a fresh start is that the composition the review found missing appears in that chapter three times in the same words: once in the introduction as the claim to be tested, once in the synthesis as the claim discharged, and once between them as the standard each field was walked against. Its parts are a portable and per-claim representation of evidential basis, action-relative admissibility, derivation-aware inheritance, constrained elevation, and mechanical enforcement across an ownership boundary. Ten literatures were read against that list, and each was found to hold one or two of its parts while none held them together at a machine handover.
A list arrived at that way is not a summary of the review. It is a requirements list derived by survey, and its authority comes from the survey rather than from the designer's sense of what would be interesting to build. This section's only liberty is to say what each part must represent with enough precision to be implemented, and to type the parts into the categories the paradigm supplies.
The categories are the paradigm's, not this chapter's
Design science research takes its artefacts to be constructs, models, methods, or instantiations (Peffers et al., 2007). Those four categories are not a scheme devised for this work, and reading the composition into them is the paradigm doing its ordinary job rather than a device for making the contribution look tidy.
The mapping is worth a moment's notice for a reason beyond bookkeeping. The composition falls into the four categories without strain: nothing has to be forced, and no part of it turns out to be the kind of thing design science has no name for. That is weak evidence, but it is evidence, that what the review found is a design problem rather than a philosophical one. Had the missing composition resolved into a question about what justification is, or about when belief is warranted in general, the paradigm would have been the wrong instrument and the strain would have shown here first.
| What the review found missing | What kind of artefact that is |
|---|---|
| A portable, per-claim representation of evidential basis | Constructs and a model |
| Derivation-aware inheritance | A method |
| Constrained elevation | A method |
| Action-relative admissibility | A method |
| Mechanical enforcement at an ownership boundary | An instantiation |
The constructs and the model
The first row carries the weight, and the others are in a real sense operations upon it. A representation of evidential basis is where the vocabulary is fixed, and fixing a vocabulary is what design science means by constructs: the terms in which the problem and its solution are subsequently stated. The model is the structure those terms compose into, which is to say what a basis is taken to consist of when it is attached to a single claim and carried.
The review is specific about what such a representation must exceed, and the specificity is inherited rather than chosen. It must exceed origin, because the provenance standard records origin in full and places the assessment built on that record outside itself, describing it as a use made by external parties rather than a function it performs (W3C, 2013a). It must exceed integrity, because the attestation framework authenticates custody and states that it does not validate whether the claims it carries are correct (in-toto, n.d.). It must exceed confidence, because the uncertainty field's own comprehensive survey concludes that estimating predictive uncertainty is not sufficient for safe decision-making (Gawlikowski et al., 2021). Three fields, three explicit statements of a limit, and together they fence the representation in from three sides without anyone in this work having proposed anything.
What has to be represented positively, rather than by exclusion, is the harder question, and the chapter commits to answering it in nameable terms. A basis is not a scalar and it is not a score. The candidate elements are what the claim rests on and by what means it was established, whether that means was observation, measurement, inference, generation, or report; what independent support exists for it, and whether the supports are genuinely independent or share an ancestor and therefore do not corroborate each other; what authority stands behind it and on whose say-so; when it was established and how quickly the underlying condition changes, since a basis has a shelf life that varies by what it is about; and the scope within which it was established, since a claim true of a sample is not thereby true of a population, and a claim true at one point in a plant is not true of the plant.
Whether those are the right elements, whether they are complete, and whether some of them collapse into others is not settled here, and this chapter does not pretend to settle it. It is the work of the design chapter, and it is the work the scheduled debt of a later section is designed to inform. What is settled here is the standard the answer will be held to, which is that each element must be nameable, must be attachable to an individual claim, and must survive being carried across a boundary to a consumer that did not produce it.
The methods
Three of the composition's parts are methods, meaning procedures over the model rather than additions to it, and the review's account of each is what fixes the problem the design chapter has to solve.
Derivation-aware inheritance governs what happens when claims become inputs to other claims. The problem statement's laundering path is the thing to be prevented: a model-inferred value feeds a human-authored assessment, the assessment is filed as a report, and the report is later retrieved as authoritative record, with no falsehood introduced at any step and the probabilistic origin of the first inference now unrecoverable. An inheritance rule is the method that makes such an ancestry survive the derivations performed upon it. The register of claims under pressure already records that the obvious rule, taking a derived claim's standing to be that of its weakest ancestor, is a conservative default rather than the rule, since independent corroboration and testing can legitimately strengthen a derived claim while mutually dependent sources do not corroborate at all. That guardrail is set and not yet discharged.
Constrained elevation is the method that answers the failure mode the work is named for. False Determinism is the unsanctioned elevation of a claim's epistemic authority at a handover, and if elevation were always illegitimate the method would be a prohibition rather than a method. It is not always illegitimate: a claim inferred and then measured has been elevated by something that warrants the elevation, and a discipline that could not represent that would forbid the ordinary business of establishing things. The method must therefore distinguish elevation that is earned from elevation that is merely asserted, and must do so mechanically, which is what makes it a method rather than a matter of judgement.
Action-relative admissibility is the method that gives the model its point, and it is where the review found the fields to be most nearly silent. The problem statement puts the case concretely: a claim that a circuit is de-energised is adequate for deciding what to investigate next and inadequate for deciding whether to touch it, and the difference between those two uses is a difference in what the act demands of its evidence rather than a difference in confidence. Admissibility is therefore a relation between a basis and an intended action, not a property of a claim. A method that returned a verdict on a claim alone would have answered a question nobody asked.
The instantiation
The fifth part is an instantiation, and it is what stops the preceding four from being a proposal. A discipline that exists only as a description of itself has not been shown to be mechanisable, and mechanisability is precisely the contested claim: the review's finding was that every surveyed field hands the judgement to a person, so a contribution that also, at the end, requires a person to apply it has not moved the boundary. The instantiation is a reference implementation as a software library, enforcing at the point where a claim crosses from one owner to another, which is the boundary the review identified as the one where nobody is standing. The question that types it is therefore whether the discipline can be enforced at a machine handover with no person present, which is what an instantiation demonstrates. Whether it discriminates well, rejecting False Determinism without rejecting too much legitimate practice, is a different question and a property of the whole discipline rather than of the instantiation alone. It is tested against the instantiation rather than answered by it, and it is deferred to the evaluation, where it is the thing the work is falsifiable on.
The review also established what the instantiation is not obliged to invent. An authenticated attestation envelope is the natural transport for a basis representation once one exists, and a runtime policy engine is the natural evaluator of it, with the attestation literature already naming automated policy engines as an attestation's intended consumers. The existing machinery composes into a pipeline from transport into evaluation with one part missing, and the missing part is the model of basis that would give the pipeline something meaningful to carry and to decide. The instantiation's job is to supply that part and to use the existing machinery for the rest, not to rebuild what already functions.
Precision, and where it stops
Two disciplines govern how this section is written, and they pull in opposite directions, which is why both have to be stated.
The first is precision. A basis model described as capturing relevant provenance factors is weak prose and unimplementable, and those are the same defect rather than two. Vagueness at this point would protect the work from criticism by making it unclear what was being claimed, and a specification that cannot be argued with cannot be shown to be wrong either. Naming what the basis represents, in the terms used above, exposes the model to the objection that it has named the wrong things or missed one, which is the objection it needs to attract while changing the answer is still cheap.
The second is that precision stops well short of design documentation. This section does not sketch interfaces, class structures, or type signatures, and the omission is deliberate rather than an economy. Those belong to the design chapter, where they can be derived from a model that has been pressure-tested rather than assumed alongside it. There is also a subtler reason. The moment a methodology chapter reads as engineering paperwork with a citation attached, it has stopped being an account of how a claim comes to be made honestly and has become an account of how a program is arranged, and the two are not the same document. What is being established here is what must be represented and why, on whose authority, and to what standard. How it is arranged in code is a later question, and answering it early would disguise an unsettled model as a settled one.
References
W3C (2013a). PROV-DM: The PROV Data Model. W3C Recommendation. w3.org/TR/prov-dm
in-toto (n.d.). in-toto Attestation Framework: Specification. github.com/in-toto/attestation
Gawlikowski, J., et al. (2021). A Survey of Uncertainty in Deep Neural Networks. Artificial Intelligence Review. arXiv:2107.03342. arxiv.org/abs/2107.03342
Peffers, K., Tuunanen, T., Rothenberger, M. A. and Chatterjee, S. (2007). A Design Science Research Methodology for Information Systems Research. Journal of Management Information Systems, 24(3), pp. 45-77. doi.org/10.2753/MIS0742-1222240302