Assessment · specification 1.0.0 · runs in your browser

Assess your system.

Define the scope, examine the evidence and the five gears, test the intervention, and record a scoped decision with its review triggers. Velocity with vigilance, on a Monday morning.

This assessment organizes evidence for a scoped decision. Its ratio band is a policy indicator, not a safety certification or permission to operate.

Explore a completed example Fictional composite. Illustrative figures. No operational permission. Starting a new assessment clears the example.
1 · ScopeRequested activity and exact system version

One assessment covers exactly one requested activity for one system version, environment and authority boundary. A separately bounded activity needs its own assessment.

2 · StakesFive separate judgments, no default midpoint

Qualitative routing judgments, not measured probabilities. Any dimension at 4 or 5, fundamental rights affected, or RSI relevance requires independent review. There is no summed score.

Fundamental rights affected?
RSI-relevant (can help design, train or improve AI)?

3 · Claims and hazardsThe critical oversight claim and the unacceptable consequence

An invalidated critical claim, or an unacceptable hazard without adequate preventive controls, blocks the activity whatever the ratio says. A reactive response cannot control a consequence that completes before intervention takes effect.

Claim status
Is this consequence unacceptable or irreversible?
Are preventive controls sufficient?

4 · TimingIntervention latency L and oversight validity horizon H

Intervention latency L runs from the first point at which the deviation should be detectable under the documented monitoring design to confirmation that the required intervention has taken effect: detection delay + decision delay + execution delay. Oversight validity horizon H is how long the critical evidence supporting this scope is estimated to remain reliable from the assessment time, unless an invalidating event occurs sooner. Why H is no longer called a half-life, and why legacy values must be reassessed.

Enter lower, central and upper planning bounds. Equal bounds are a point estimate. Leave a quantity blank if it cannot be defensibly estimated; blanks are Unknown, never zero. The policy band uses R upper = L upper / H lower; the central value and range are shown beside it.

5 · GEARSGovernance · Equity · Aligned incentives · Resilience · Steering

Rate each gear from evidence for this activity. Any red blocks the activity assessed. Unknown means not established; it is never rounded to green. Each rated gear needs a rationale and at least one evidence reference before a favorable result. Colors are never averaged.

6 · Required interventionThe circuit breaker this activity depends on

A required intervention that failed its test blocks the activity. One that was never tested, or was tested on a different system version, leaves the evidence insufficient. A button click is not necessarily effective intervention.

Test result on this version

7 · Evidence registerWhat the references above point to

A reference is not an upload. Record the stable ID used above, a title or locator, how the evidence was produced, when it was captured, and whether it is still current. Reported is not verified; illustrative evidence can only support an illustrative assessment.

8 · ReviewAssessor, accountable owner, independent review, expiry

9 · ConditionsOwned actions for every yellow gear and for amber timing

Each condition names what it addresses, who owns it, when it is due and how it will be verified. A generic action does not complete the assessment. Recording a future action never clears a known blocker.

10 · PermissionAccountable human decision, separate from eligibility

Nothing here is filled in by the result. A name typed into this page records an assertion; it is not a signature, a verified identity or an enforced permission.

One veto and permit table

How the advisory result is chosen

Evaluate all conditions, retain all reasons, then choose the most restrictive applicable result. Known blockers outrank missing information. Published identically in section 5 of the specification.

One veto and permit table: precedence, condition, advisory result and required action
PrecedenceCondition for the requested scopeAdvisory resultRequired action
1Any critical claim invalidated; an unacceptable hazard has inadequate controls; or a required intervention test failedBlockedWithhold the requested permission. If already operating, the accountable owner applies the predefined containment or restriction plan. Consider harms from abrupt shutdown.
2Any GEARS rating red, or known R upper at or above 1BlockedRedesign, restrict or pause the requested activity and reassess. A differently bounded activity needs its own assessment.
3No known blocker, but timing, a critical claim, a gear, stakes, current evidence, a required test, owner, scope or required independent review is missingInsufficient evidenceCollect the named evidence. Do not grant new permission from this assessment. A separately authorized evidence-gathering experiment is possible.
4Complete evidence, no blocker, and either amber timing or any yellow gearEligible with conditionsSpecify each condition, owner, due time and verification test. An accountable person must record scoped permission before use. Missing conditions produce insufficient evidence.
5Complete evidence, no blocker, green timing, and all five gears greenEligible for scoped permissionAn accountable person may grant the described scope and expiry. No automatic expansion of autonomy.

Known blockers outrank missing information. All reds apply to the activity actually assessed. A veto on public deployment does not automatically prohibit a separately bounded research activity, which needs its own assessment; no gear is omitted because an activity is research. Human authorization is a separate record: awaiting decision, withheld, granted, granted with conditions, revoked or expired. A name typed into a client-side tool records an assertion, not a signature, a verified identity or an enforced permission.

Circuit-breaker cards

If-Then cards for the interventions you will pre-commit

A circuit breaker you design after you need it is just an apology. Pre-commit the tripwires while the room is calm. The required one belongs in section 6 above; use cards for the rest.

Quick audit

Five questions, one per gear

A fast read before a full assessment. A "no" or a shrug is a finding, not a score.

Drift between versions

Compare this version against the last one

A rising R upper, or any gear moving toward red, is a regression. Legacy half-life values are not comparable: reassess H under the 1.0.0 definition before comparing.

Previous version (assessed under specification 1.0.0)
Current version

Read from the assessment above after you evaluate it.

Disclosure

Six comparable lines

Publishable summary of the evaluated assessment, with the specification version it was read against.

The book is the argument; this is the instrument. From The Acceleration Paradox, implementing the Open Control Surface Specification 1.0.0. Assessment entries are processed in your browser and are not sent to our servers. Reloading clears unsaved entries. See the Edition 1 errata for what changed.