SecondMark position
Autonomy changes assurance because the important behavior is partly selected at runtime. Authority, boundaries, escalation, and recovery therefore become primary evidence objects.
The examination is bounded to defined claims, a versioned system, and evidence that can be traced to the state under review. Any material exclusion or uncertainty remains visible in the conclusion.
Core questions
What the examination needs to establish.
- 01
What actions can the system take without approval?
- 02
How are plans constrained before execution?
- 03
What happens when context, tools, or models fail?
- 04
Can operators interrupt, recover, and reconstruct decisions?
Evidence model
Evidence is assembled around the claim—not the folder structure.
Architecture and system boundaries
Collected, attributed, challenged, and connected to the exact system boundary under examination.
Implementation and model provenance
Collected, attributed, challenged, and connected to the exact system boundary under examination.
Runtime behavior and operational history
Collected, attributed, challenged, and connected to the exact system boundary under examination.
Controls, qualifications, and unresolved risk
Collected, attributed, challenged, and connected to the exact system boundary under examination.
Intended outcome
An evidence-bound conclusion on whether autonomous authority is constrained, observable, and recoverable within the defined scope.
Professional boundary
What an opinion does—and does not—mean.
It provides
A traceable independent conclusion on defined claims, grounded in the evidence and system state examined.
It does not provide
A guarantee that failure is impossible, a permanent certification, or a conclusion beyond the stated scope and validity conditions.
