MissionSAFE / Design study

Model change evaluation: build a useful decision record

Civilian and Air Force software leaders discuss projects around a table with open laptops.

The operational question

In this illustrative missionsafe scenario, a assurance reviewer uses AI to organize a model-change assessment. The workflow draws on MissionSAFE scenarios and recorded outputs. Its central risk is a previous benchmark being assumed to cover a new model version. The design question is how to submit the assessment for review for the deployment decision group while preserving the separation between evaluated behavior and release authority. This is a proposed evaluation scenario, not a report of an Archetypal customer deployment or a demonstrated operational outcome.

Build a useful decision record

An audit trail earns its value by explaining a consequential decision after the original context has changed. Record the request’s governed purpose, the decisive facts, the applicable rule version, the disposition, and the responsible reviewer or system. Include conditions, unresolved questions, and the observed outcome when available. Keep the difference between a proposed action and a completed action explicit. Retain enough information to reconstruct the decision without treating unlimited capture as the default. Consider who may inspect the record, which source material can be linked rather than copied, and how the record should respond when a source is corrected or a policy is retired.

Put the control in the workflow

Place this review immediately before the team can submit the assessment for review. The assurance reviewer should see the proposed result beside the relevant parts of MissionSAFE scenarios and recorded outputs. Identify which statement is supported by a source, which is an interpretation, and which remains unresolved. Carry the separation between evaluated behavior and release authority into the decision record rather than relying on a reviewer to remember it from another screen. If the evidence does not establish the condition required for release, route the case to its owner with a concrete question. The interface should make the missing fact discoverable and the next action clear.

A test that can change the design

A reviewer examines the record after the policy has changed. The expected result is a reconstructable account of the version and conditions that applied at decision time. Run the case using a fixed version of the scenario and the policy under review. Ask an independent reviewer to identify the decisive fact before seeing the system’s disposition. Compare that interpretation with the result. Where they disagree, preserve both explanations and inspect whether the difference comes from the rule, the available evidence, or the interface. For model change evaluation, include model revision, scenario scope, and responsible reviewer in the review packet. Repeat the test after a correction and retain the original failure as part of the evidence.

Evidence to retain

The minimum useful record connects the purpose of the task, model revision, scenario scope, and responsible reviewer, the applicable policy version, and the final disposition. Add the identity or role of the responsible reviewer, the conditions attached to approval, and the unresolved questions. If the team proceeds, distinguish the approval from an observed completion. If it stops, explain what evidence or authorization would allow another review. Keep source permissions attached to the record when it moves to the deployment decision group. Do not assume that permission to read the initial source includes permission to reproduce it in every downstream system.

What a result would establish

A successful run would show that this configuration recognizes the tested boundary for model change evaluation and gives the assurance reviewer an interpretable next step. It would not establish complete coverage of other audiences, source conditions, applications, or mission environments. Report the scope with the finding. Review any decision to submit the assessment for review under changed conditions as a new applicability question. The strongest next experiment is usually the smallest change that could make the current conclusion false.

Review before wider use

Ask the workflow owner whether the proposed control is understandable at the point of use. Ask the policy owner whether it preserves the source requirement. Ask the evaluator whether the test can distinguish a real improvement from a change in presentation. Finally, ask the deployment owner what happens when MissionSAFE scenarios and recorded outputs are unavailable or the integration no longer observes the required event. Agreement among these roles should be documented as a set of decisions and remaining conditions, not compressed into an unsupported statement that the system is universally ready.

Purpose in this scenario

State the immediate task and the downstream use separately. The same output may be acceptable for an internal draft but unsuitable for a consequential decision or a broader audience. In model change evaluation, the assurance reviewer should apply this check to the proposed decision to submit the assessment for review. Use model revision, scenario scope, and responsible reviewer to make the review concrete. Explain how the result changes if the condition is absent, disputed, or no longer current. Record the expected disposition before running the scenario so that the evaluator cannot quietly redefine success after seeing the output. The receiving audience is the deployment decision group; preserve the limitations they need to interpret the result.

Authority in this scenario

Identify the role empowered to make the decision. Record the source of that authority and any conditions attached to a delegation. In model change evaluation, the assurance reviewer should apply this check to the proposed decision to submit the assessment for review. Use model revision, scenario scope, and responsible reviewer to make the review concrete. Explain how the result changes if the condition is absent, disputed, or no longer current. Record the expected disposition before running the scenario so that the evaluator cannot quietly redefine success after seeing the output. The receiving audience is the deployment decision group; preserve the limitations they need to interpret the result.

Audience in this scenario

Name the intended receiving group. Reassess the decision if the result is forwarded, summarized for another group, or included in a new workflow. In model change evaluation, the assurance reviewer should apply this check to the proposed decision to submit the assessment for review. Use model revision, scenario scope, and responsible reviewer to make the review concrete. Explain how the result changes if the condition is absent, disputed, or no longer current. Record the expected disposition before running the scenario so that the evaluator cannot quietly redefine success after seeing the output. The receiving audience is the deployment decision group; preserve the limitations they need to interpret the result.

Freshness in this scenario

Record when a source was observed and when its current applicability was checked. A recently generated summary does not make old evidence current. In model change evaluation, the assurance reviewer should apply this check to the proposed decision to submit the assessment for review. Use model revision, scenario scope, and responsible reviewer to make the review concrete. Explain how the result changes if the condition is absent, disputed, or no longer current.

Exercise 3: audience

Name the intended receiving group.

Archetypal film

Documentary footage · No dialogue · Source credits