Back to whitepaper
Appendix AAction assetv0.1FDE working framework · pending field validation About 12 min + working time
FDE Project Evidence Card v1
A copyable project record for stage claims, five evidence layers, gate decisions, publication controls, and corrections.
Updated July 19, 2026
On this page
FDE working framework: This card supports project review, case editing, and peer discussion. It is not an industry certification, a NIST/ISO checklist, or evidence of compliance.
How to use it
- State demo, pilot, launch, adoption, outcome, and transfer separately.
- Record status and evidence indexes for the problem, solution, quality, operations, and outcome-and-transfer layers.
- Choose only
Pass / Conditional pass / Hold / Stopat each gate. Every conditional pass needs an expiry date. - Mark evidence quality and publication level separately.
Not publishabledoes not mean low-quality evidence. - Never store plaintext passwords, tokens, sensitive personal data, or exploitable vulnerability details in the card. Point to protected source material instead.
Evidence status
| Status | Meaning |
|---|---|
Missing |
Required material does not exist and may block the gate |
Planned |
Collection method, owner, and date exist, but the evidence does not |
Observed |
Material was seen, but source, scope, method, or ownership is not verified |
Verified |
Source, scope, period, version, method, and confirmation were reviewed |
Contested |
Data, interpretation, or responsible parties disagree |
Not publishable |
Authorized reviewers can inspect it, but it cannot be released publicly |
Publication levels
| Level | Access |
|---|---|
P0 |
Public and authorized, with no sensitive detail |
P1 |
Public redacted, preserving method, time window, denominator relationships, and limits |
P2 |
Controlled review by named peers, customers, or NDA reviewers |
P3 |
Internal project and authorized governance roles |
P4 |
Minimum-authorized personnel and protected systems only |
Copyable template
schema: fde-project-evidence-card/v1
card_version: 0.1
updated_at: YYYY-MM-DD
project:
project_id: ""
title: ""
organization_public_name: "Anonymous / authorized public name"
period: "YYYY-MM-DD..YYYY-MM-DD"
geography: ""
owners:
sponsor: ""
business_owner: ""
delivery_owner: ""
risk_acceptance_owner: ""
operations_owner: ""
reviewers: []
stage_claims:
demo:
claimed: false
status: Missing
scope: ""
decided_at: null
pilot:
claimed: false
status: Missing
scope: ""
decided_at: null
launch:
claimed: false
status: Missing
scope: ""
decided_at: null
adoption:
claimed: false
status: Missing
scope: ""
observation_window: ""
outcome:
claimed: false
status: Missing
scope: ""
observation_window: ""
transfer:
claimed: false
status: Missing
receiving_owner: ""
accepted_at: null
layer_1_problem:
status: Missing
target_users: []
workflow_trigger: ""
current_workflow: ""
baseline_metrics:
- metric: ""
value: null
denominator: ""
time_window: ""
source_system: ""
method: ""
loss_or_opportunity: ""
current_alternatives: []
intended_use: ""
out_of_scope: []
affected_parties: []
success_conditions: []
pause_conditions: []
stop_conditions: []
evidence_ids: []
limitations: []
layer_2_solution:
status: Missing
solution_scope: ""
alternatives_considered: []
decision_records: []
architecture_version: ""
data_flows: []
model_and_dependency_versions: []
data_owners: []
permission_model: []
agent_autonomy_level: ""
human_approval_points: []
threat_scenarios: []
mcp_controls:
least_privilege_scopes: []
audience_validation: ""
token_passthrough_prohibited: true
sensitive_action_confirmation: []
assumptions: []
risks: []
rollback_and_degradation: []
evidence_ids: []
limitations: []
layer_3_quality:
status: Missing
system_version_tested: ""
task_definitions: []
success_boundaries: []
failure_taxonomy: []
dataset:
version: ""
sources: []
sample_size: null
production_relationship: ""
sensitive_data_handling: ""
graders:
deterministic: []
model_based: []
human: []
calibration_method: ""
trials_per_task: null
metrics_and_thresholds: []
final_state_checks: []
trace_checks: []
safety_and_permission_tests: []
regression_result: ""
known_limitations: []
exceptions_accepted_by: []
evidence_ids: []
layer_4_operations:
status: Missing
production_release:
version: ""
released_at: null
environment: ""
enabled_scope: ""
rollout_strategy: ""
rollback_owner: ""
rollback_last_tested_at: null
slis_slos: []
telemetry_and_audit: []
alerts_and_on_call: []
production_evals: []
adoption_metrics:
target_user_denominator: null
active_target_users: null
real_task_volume: null
repeat_use_window: ""
excluded_test_traffic: ""
cost_and_capacity: []
incidents: []
change_records: []
evidence_ids: []
limitations: []
layer_5_outcome_and_transfer:
status: Missing
outcome_metrics:
- metric: ""
baseline_value: null
observed_value: null
denominator: ""
observation_window: ""
source_system: ""
attribution_limits: ""
total_costs: []
side_effects_and_risks: []
stakeholder_confirmations: []
decision:
action: "expand | maintain | modify | hold | stop"
rationale: ""
decided_by: []
decided_at: null
transfer:
operations_owner: ""
eval_owner: ""
security_owner: ""
data_owner: ""
business_owner: ""
assets_transferred: []
credential_transfer_method: "controlled re-authorization; no plaintext secrets"
training_completed: []
drills_completed: []
open_risks_accepted: []
accepted_by: []
accepted_at: null
evidence_ids: []
limitations: []
gate_decisions:
problem_gate: "Pass | Conditional pass | Hold | Stop"
solution_gate: "Pass | Conditional pass | Hold | Stop"
quality_gate: "Pass | Conditional pass | Hold | Stop"
production_gate: "Pass | Conditional pass | Hold | Stop"
adoption_gate: "Pass | Conditional pass | Hold | Stop"
outcome_gate: "Pass | Conditional pass | Hold | Stop"
transfer_gate: "Pass | Conditional pass | Hold | Stop"
conditions: []
expires_at: null
evidence_index:
- evidence_id: EV-001
claim_supported: ""
artifact_type: ""
scope: ""
source_system: ""
time_window: ""
owner: ""
reviewer: ""
method: ""
status: Missing
publication_level: P3
location: "restricted://..."
version_or_hash: ""
limitations: []
publication:
card_level: P3
authorized_by: []
authorized_at: null
redactions:
- field_or_evidence_id: ""
reason: "privacy | confidentiality | security | contract | legal"
effect_on_claim: "none | narrows claim | claim removed"
public_claims: []
claims_not_allowed: []
corrections:
- corrected_at: null
field_or_claim: ""
previous_value: ""
new_value: ""
reason: ""
approved_by: ""
Companion chapter
Chapter 12: Project Evidence Standards explains the claims, fields, gates, and publication controls behind the card.