Evidence decision record
Record the owner decision after the proof path is inspected.
TraceMap provides deterministic static evidence, rule context, coverage labels, and limitations. The human owner records the decision, the rejected interpretation, the follow-up owner, and the residual risk.
Public claim level: concept. No public conclusion without evidence. TraceMap provides evidence, not the decision.
Why record the decision
Keep evidence, limits, judgment, and follow-up in one place.
Evidence trailThe record keeps the decision question attached to a proof path, rule ID or family, evidence tier, coverage label, commit context, extractor version, and validation summary.
Owner judgmentThe record names the public role category that made the bounded decision after inspecting evidence. It does not let the static map make the decision.
Limits that travelThe limitation, non-claim, rejected interpretation, follow-up owner, review date placeholder, and residual risk stay visible so later readers do not repeat a stronger conclusion.
Record template
Every field stays present, even when the value is pending or private-only.
| Field | Public-safe guidance |
|---|---|
| decision question | Name the exact question being answered without expanding it into broader release, runtime, production, safety, or governance claims. |
| decision owner | Use a public role category or placeholder, such as reviewer role placeholder or service owner role. |
| public claim level | concept for this page and examples unless a separate evidence-backed upgrade is recorded. |
| proof path | Link a public-safe route, summary, documentation page, report-family summary, or named private review location without raw material. |
| rule ID/family | Name the specific public-safe rule ID, or use a rule family and keep the limitation visible. |
| evidence tier | Use only Tier1Semantic, Tier2Structural, Tier3SyntaxOrTextual, or Tier4Unknown. |
| coverage label | Transcribe the cited coverage label without strengthening it. |
| commit SHA | Use a public-safe scan commit identifier when exposed, otherwise keep a visible unavailable or not public-safe limitation. |
| extractor version | Use the public-safe extractor version when exposed, otherwise keep the field and record the limitation. |
| limitation | Name the rule, coverage, data, publication, or analysis boundary that travels with the decision. |
| non-claim | State what the decision must not imply, including runtime, production, release, safety, approval, absence-of-impact, complete-coverage, AI/LLM, or autonomous-decision claims when relevant. |
| validation evidence | Name a public-safe validation summary, review evidence, command family, test summary, or manual review note without raw output. |
| rejected interpretation | Record the stronger conclusion the owner did not make because evidence was insufficient, private-only, reduced, or outside static analysis. |
| follow-up owner | Name the role category responsible for the next answer. |
| review date placeholder | Use YYYY-MM-DD or another placeholder pattern, not a real internal review date. |
| residual risk | Record what remains unknown, reduced, private-only, runtime-only, owner-pending, or outside TraceMap evidence. |
Example safe record
Synthetic example: keep the decision bounded.
decision questionCan this public summary say reviewers have static evidence for a dependency question?
decision ownerreviewer role placeholder
public claim level
conceptproof pathguided proof-path tour plus public-safe packet summary.
rule ID/familydependency-reference rule family; exact rule ID not public-safe in this example.
evidence tier
Tier2Structuralcoverage labelreduced public-demo coverage label as cited.
commit SHA
example-public-sha; synthetic placeholder.extractor version
example-extractor-version; synthetic placeholder.limitationStatic evidence only; reduced coverage remains visible.
non-claimDoes not prove runtime behavior, release safety, production traffic, approval, complete coverage, AI analysis, or absence of impact.
validation evidencePublic-safe validation summary and manual review note; detailed output is not included.
rejected interpretationDo not say the dependency is safe, unsafe, production-proven, or approved for release.
follow-up ownerservice owner or runtime observability owner role.
review date placeholder
YYYY-MM-DDresidual riskRuntime behavior and release decision remain outside TraceMap evidence.
Unsafe record examples
Downgrade, block, or keep these records internal.
- Missing proof path: the record repeats an owner decision but drops the evidence trail.
- Hidden evidence strength: the record omits evidence tier or coverage label, then makes reduced analysis sound stronger than it is.
- Unsupported release wording: the record says static evidence approves, certifies, validates, or clears a release.
- Runtime or production proof wording: the record treats repository evidence as runtime behavior, production traffic, endpoint performance, or outage cause.
- Absence-of-impact wording: the record turns missing evidence into no-impact proof.
- Autonomous decision wording: the record says TraceMap decided, approved, certified, blocked, or replaced the owner.
- Raw/private leakage: the record shares raw facts, raw SQLite content, analyzer logs, raw source snippets, raw SQL, config values, secrets, local paths, raw remotes, generated scan directories, private sample names, raw command output, hidden validation details, or credential-like values.
- No follow-up owner: the record leaves runtime, test, security, release, review, or service questions without a public role category.
- Blame wording: the record frames a limitation as the fault of a person, vendor, reviewer, team, or codebase.
Stop conditions
Stop public reuse when a mandatory boundary is missing.
- Stop when proof path, rule ID/family, evidence tier, coverage label, limitation, non-claim, decision owner, follow-up owner, or validation evidence is missing.
- Stop when support is private-only without a public-safe summary, or when a field is silently removed instead of labeled unavailable, private-only, not public-safe, or pending.
- Stop when copy claims autonomous decisions, approval workflow, release approval, release safety, operational safety, runtime proof, production proof, endpoint performance proof, outage cause, absence-of-impact proof, complete coverage, AI/LLM analysis, embeddings, vector databases, prompt classification, or replacement of human judgment.
- Stop when the record would publish raw artifacts, private material, hidden validation details, credential-like values, or blame language.
Follow-up owners
Route remaining questions to public role categories.
service ownerOwns service behavior interpretation and code-level follow-up.
runtime observability ownerOwns logs, traces, metrics, dashboards, production traffic, endpoint performance, and runtime evidence.
release ownerOwns release gates, deployment policy, and final release decisions.
test ownerOwns test evidence, reproduction, regression coverage, and verification strategy.
reviewerOwns claim checking, proof-path review, and repeatability of public or internal statements.
security ownerOwns raw artifact sharing, secrets, sensitive configuration, and publication decisions.
repository ownerOwns repository publication boundaries, remotes, paths, and source-sharing choices.
managerOwns prioritization and coordination after evidence and owner inputs are identified.
TraceMap ownerOwns scanner or reducer evidence boundaries, rule documentation, public site copy, validation, and implementation gaps.
Non-claims
The record preserves a human decision; it does not create authority.
- TraceMap does not make autonomous decisions, run an approval workflow, approve releases, prove release safety, prove operational safety, prove runtime behavior, prove production behavior, prove endpoint performance, identify outage cause, prove absence of impact, or prove complete coverage.
- TraceMap does not use AI analysis, LLM analysis, embeddings, vector databases, or prompt classification in the core scanner or reducer.
- TraceMap does not replace tests, code review, source review, runtime observability, telemetry, release process, service-owner review, governance, or human judgment.
- The record does not publish raw facts, raw SQLite content, analyzer logs, raw source snippets, raw SQL, config values, secrets, local paths, raw remotes, generated scan directories, private sample names, raw command output, hidden validation details, or credential-like values.
Adjacent surfaces
Use the neighboring page that matches the job.
/review-room/Meeting agenda for known, partial, and missing evidence; this record captures what the owner decided after review.
/packets/assembly/Pre-handoff ingredient checklist; this record captures one owner decision and residual risk.
/review-claim-checklist/Repeatability ritual for a sentence; this record is not a claim approval verdict.
/manager-packet/Manager-facing orientation; this record is a compact evidence-to-decision artifact.
/questions/objections/Skeptical question handling; this record logs the resolved question, rejected interpretation, follow-up owner, and residual risk.
/proof-paths/tour/Proof-path education; this record cites a proof path but does not teach the whole proof-path process.
/proof-paths/, /limitations/, /validation/Use proof, boundary, and validation surfaces when the record needs public-safe support.