Change impact without certification theater

JADC2 Mission-Thread Change Impact and Assurance Case Lab

Connect one fixed fictional Joint All-Domain Command and Control mission-thread replay to claims, evidence, assumptions, counterclaims, defeaters, verification, residual risk, and independent review—then see what remains supportable after a later change.

Research basis KW-RPT-007 KW-RPT-013 KW-RPT-040 KW-RPT-041 KW-RPT-042 KW-RPT-043 KW-RPT-044 KW-RPT-046 KW-RPT-047

Assurance argument, not approval

A complete graph can show why a bounded claim is supportable. It cannot certify a real system.

JADC2 means Joint All-Domain Command and Control. CJADC2 means Combined Joint All-Domain Command and Control. A kill chain is one selected ordered mission process; a kill web is the changing graph of possible mission threads; JADC2 is the wider enterprise that enables, secures, governs, tests, and sustains those threads.

The lab preserves the original fictional case and derives a separate current view. A source correction, software change, purpose withdrawal, authority expiry, missing interface record, contradictory assessment, or unresolved partition cannot be averaged away by favorable component tests.

Input
One fixed case and one allowlisted later change
Output
Claim states, invalidated evidence, defeaters, re-verification, and review duties
Never
Targeting, force authorization, legal review, readiness, certification, or deployment approval
Score
None—serious defects remain decisive

Sixteen independent elements

Keep evidence, authority, review, and reconciliation separately inspectable.

A favorable state in one element cannot compensate for invalid evidence, withdrawn purpose, expired authority, inadequate human review, or unreconciled state.

  1. JMA-EL-01Stable identifiersCase, claim, evidence, event, thread, and data-product identifiers remain stable and separately addressable.
  2. JMA-EL-02Declared scopeSystem, mission-thread, purpose, organizational, temporal, and publication scope are explicit.
  3. JMA-EL-03Claim hierarchyOne bounded top-level claim is decomposed into independently reviewable subclaims.
  4. JMA-EL-04Supporting evidenceEvery supporting record links to replay provenance and a declared scope.
  5. JMA-EL-05Contradictory and missing evidenceContradictions and gaps remain visible instead of being absorbed into a fluent rationale.
  6. JMA-EL-06Assumptions and operating boundsEnvironmental, software, data, authority, and human-review assumptions are explicit.
  7. JMA-EL-07Counterclaims and defeatersThe graph preserves reasons a claim may be wrong or unusable.
  8. JMA-EL-08Verification identityVerification activities identify exact fictional method, software, schema, policy, and configuration versions.
  9. JMA-EL-09Artifact and policy identitySoftware, schema, model, policy, and configuration identities are not collapsed into product names.
  10. JMA-EL-10Release and permitted purposeReleasability, minimization, permitted use, expiry, and revocation remain distinct.
  11. JMA-EL-11Authority and human reviewDelegation, expiry, revocation, evidence access, time, competence, and intervention power are separately recorded.
  12. JMA-EL-12Reconciliation and return of controlTechnical reconnection is followed by explicit state reconciliation and bounded return of control.
  13. JMA-EL-13Residual risk and unknownsUnresolved limitations remain visible after favorable verification.
  14. JMA-EL-14Review-role qualityIndependence, competence, evidence access, available time, and corrective authority are explicit.
  15. JMA-EL-15Change impactEvery allowlisted later change identifies affected evidence, claims, tests, and reviewers.
  16. JMA-EL-16Current state and limitationsOriginal and current views remain separate, with no certification or readiness inference.

Fourteen non-equivalences

Do not let documentation become authority by appearance.

Claim stated

Claim supported

Evidence present

Evidence sufficient or accurate

Passing component test

Supported system claim

Replayable history

Validated decision quality

Complete assurance graph

Certification

Supported claim

Operational readiness

Original evidence

Current evidence

Source correction

Complete downstream re-verification

Software signature

Permission to deploy

Partner release once permitted

Current permitted use

Historical authority

Current authority

Human acknowledgment

Meaningful merits review

Technical reconciliation

Institutional or legal resolution

Independent review opened

Independent review completed

Six fixed case families

The assurance cases align with the immutable replay histories.

No real organization, mission, platform, target, log, evidence package, authority instrument, or software artifact can be submitted.

JMA-1-CASE

Disaster-response information routing

A fictional multi-organization network routes infrastructure-damage observations to a bounded coordination service.

Replay: JMR-H1

JMA-2-CASE

Infrastructure-protection coordination

A fictional protective network coordinates sensor, maintenance, and service-continuity information without modeling force.

Replay: JMR-H2

JMA-3-CASE

Mission-partner awareness and releasability

A fictional mission partner contributes a minimized awareness product under explicit releasability and purpose conditions.

Replay: JMR-H3

JMA-4-CASE

Logistics recovery after gateway loss

A fictional logistics thread reroutes status data after a gateway fails and later reconnects with divergent state.

Replay: JMR-H4

JMA-5-CASE

Cyber-defense interpretation with contradictory evidence

A fictional defensive system compares anomaly evidence and a benign explanation before recommending containment.

Replay: JMR-H5

JMA-6-CASE

Time-critical protective support

A fictional protective thread operates under a short authority window and explicit human-review conditions.

Replay: JMR-H6

Fixed change-impact exercise

Select one case and one later change.

Synthetic only

Joint emergency support

Disaster-response information routing

A fictional multi-organization network routes infrastructure-damage observations to a bounded coordination service.

Case
JMA-1-CASE
History
JMR-H1
Thread
JMR-H1-THREAD-01
Data product
JMR-H1-DP-04
Restore fixed baseline

The ordinary POST form is complete without JavaScript. Enhanced mode calls only the same-origin API. Nothing is stored, uploaded, profiled, sent to Evulgare, or transmitted to an external service.

Original fixed case posture

Case supported with declared qualifications

qualified

Current posture after selected change

Case supported with declared qualifications

qualified

The fixed fictional assurance case remains supported only with declared qualifications. Its graph is not certification, readiness, legal review, or force authority.

No composite assurance, JADC2, interoperability, trust, authority, readiness, confidence, legality, safety, accountability, mission-success, or certification score is calculated.

8Supported
2Qualified
0Unresolved
0Suspended
0Withdrawn
NoCertification

Warnings

  • No additional warning beyond the standing public boundary.

Required actions

  • Monitor declared assumptions and change triggers.

Required re-verification

  • No additional re-verification in this fixed state.

Required review roles

  • Assurance case owner — Maintains scope, claim decomposition, and current disposition without self-certifying the case.
  • Independent assurance reviewer — Reviews merits outside the original decision chain and may require correction, suspension, or withdrawal.

Claim hierarchy

Original and current claim states

ClaimTypeOriginalCurrentReplay eventsReason
JMA-1-CLM-TOP
The fixed fictional mission thread remains supportable within its declared bounds
top-levelSupported with qualificationsSupported with qualificationsOriginal fixed teaching state: Supported with qualifications.
JMA-1-CLM-EVIDENCE
Evidence lineage is complete enough for the bounded teaching claim
subclaimSupported within declared boundsSupported within declared boundsJMR-H1-E01 JMR-H1-E02 JMR-H1-E03 JMR-H1-E05 Original fixed teaching state: Supported within declared bounds.
JMA-1-CLM-SEMANTIC
Semantic translation and interface meaning remain compatible
subclaimSupported within declared boundsSupported within declared boundsJMR-H1-E04 Original fixed teaching state: Supported within declared bounds.
JMA-1-CLM-TRUST
Identity, workload trust, and provenance assertions remain current
subclaimSupported within declared boundsSupported within declared boundsJMR-H1-E06 Original fixed teaching state: Supported within declared bounds.
JMA-1-CLM-RELEASE
Release, minimization, and permitted purpose remain valid for this scope
subclaimSupported within declared boundsSupported within declared boundsJMR-H1-E07 Original fixed teaching state: Supported within declared bounds.
JMA-1-CLM-TIMING
Timing, capacity, reachability, and failure-domain assumptions remain within bounds
subclaimSupported within declared boundsSupported within declared boundsJMR-H1-E08 Original fixed teaching state: Supported within declared bounds.
JMA-1-CLM-AUTHORITY
Current delegated authority remains valid and separately enforced
subclaimSupported within declared boundsSupported within declared boundsJMR-H1-E09 Original fixed teaching state: Supported within declared bounds.
JMA-1-CLM-HUMAN
The recorded human review qualifies as meaningful merits review
subclaimSupported within declared boundsSupported within declared boundsJMR-H1-E11 Original fixed teaching state: Supported within declared bounds.
JMA-1-CLM-ASSESS
Assessment does not contradict the bounded interpretation
subclaimSupported with qualificationsSupported with qualificationsJMR-H1-E10 JMR-H1-E12 Original fixed teaching state: Supported with qualifications.
JMA-1-CLM-RECON
State reconciliation and return-of-control conditions remain satisfied
subclaimSupported within declared boundsSupported within declared boundsOriginal fixed teaching state: Supported within declared bounds.

Evidence and replay-event ledger

Invalidated records remain visible

EvidenceReplay eventData productExact versionsOriginalCurrent
JMA-1-EV-01
Source observation created
JMR-H1-E01JMR-H1-DP-01collector-2.4.1
observation-3.0
collection-policy-4
currentcurrent
JMA-1-EV-02
Custody and provenance registered
JMR-H1-E02JMR-H1-DP-01provenance-ledger-1.9.0
prov-envelope-2.2
custody-policy-3
currentcurrent
JMA-1-EV-03
Data minimized and transformed
JMR-H1-E03JMR-H1-DP-02transform-service-5.1.2
semantic-profile-7.1
minimization-policy-6
currentcurrent
JMA-1-EV-04
Semantic and software versions locked
JMR-H1-E04JMR-H1-DP-02translator-4.6.0
mission-thread-schema-5.0
compatibility-policy-5
currentcurrent
JMA-1-EV-05
Evidence and contrary evidence qualified
JMR-H1-E05JMR-H1-DP-03evidence-service-3.8.4
evidence-contract-4.2
evidence-policy-8
currentcurrent
JMA-1-EV-06
Identity and workload trust evaluated
JMR-H1-E06JMR-H1-DP-03trust-engine-2.7.3
trust-assertion-3.1
zero-trust-policy-7
currentcurrent
JMA-1-EV-07
Release and permitted purpose decided
JMR-H1-E07JMR-H1-DP-04release-gate-3.4.2
release-contract-6.0
partner-use-policy-9
currentcurrent
JMA-1-EV-08
Reachability, timing, capacity, and failure domains checked
JMR-H1-E08JMR-H1-THREAD-01path-service-6.2.1
thread-state-4.0
capacity-policy-5
currentcurrent
JMA-1-EV-09
Delegated authority and expiry checked
JMR-H1-E09JMR-H1-THREAD-01authority-gate-4.3.0
delegation-contract-3.4
authority-policy-12
currentcurrent
JMA-1-EV-10
Bounded machine coordination output produced
JMR-H1-E10JMR-H1-THREAD-01option-composer-5.5.0
recommendation-contract-4.1
coordination-policy-10
currentcurrent
JMA-1-EV-11
Human merits review recorded
JMR-H1-E11JMR-H1-THREAD-01review-console-3.6.8
interface-state-2.9
human-review-policy-11
currentcurrent
JMA-1-EV-12
Assessment and residual unknowns recorded
JMR-H1-E12JMR-H1-ASSESS-01assessment-service-2.8.2
assessment-contract-3.3
assessment-policy-6
currentcurrent

Assumptions and bounds

  • Declared scope remains unchanged — The fictional purpose, participants, data products, timing, and non-force boundary remain as declared.
  • Exact fictional versions are known — Software, schema, policy, and configuration identities remain the exact versions linked to the replay.
  • Evidence custody remains verifiable — Source, custody, transformation, and correction records remain available.
  • Authority remains current — Delegation, scope, expiry, and revocation state remain current for the bounded decision.
  • Human review remains meaningful — Evidence access, contrary evidence, time, competence, authority, and intervention capability remain recorded.
  • Reconciliation remains complete — No divergent state, duplicate ownership, or unresolved return-of-control condition exists.

Counterclaims

  • A coherent replay may still preserve a flawed decision — Reproducibility and graph completeness do not prove evidence accuracy, good judgment, or operational suitability.
  • A component test may not support the end-to-end claim — Local verification can miss semantic, organizational, human, and cross-system interactions.

Active defeaters

  • No additional defeater activated by this selected change.

Residual risks

  • Synthetic abstraction risk — The fixed catalog cannot establish behavior of any real joint or combined system.
  • Open-world evidence risk — Unrecorded or unavailable evidence may change the interpretation.
  • Human-machine interaction risk — A recorded interface state cannot prove comprehension or judgment quality by itself.
  • Change and drift risk — Later software, data, policy, authority, environment, or organizational changes may invalidate current support.

Residual unknowns

  • The fixed public case cannot establish real-system behavior, legal permission, operational acceptance, or deployment suitability.

Independent review state

not-opened

Verification activities

Exact fictional versions and current test state

ActivityMethodVersionBaseline resultCurrent state
JMA-1-VER-00
End-to-end assurance review
Fixed deterministic synthetic verificationassurance-review-1.20.0qualifiedcurrent
JMA-1-VER-01
Evidence lineage replay
Fixed deterministic synthetic verificationlineage-check-4.2.0passed-within-declared-boundscurrent
JMA-1-VER-02
Semantic compatibility test
Fixed deterministic synthetic verificationsemantic-suite-5.0.1passed-within-declared-boundscurrent
JMA-1-VER-03
Identity and provenance test
Fixed deterministic synthetic verificationtrust-suite-3.7.2passed-within-declared-boundscurrent
JMA-1-VER-04
Release and purpose test
Fixed deterministic synthetic verificationrelease-suite-6.1.0passed-within-declared-boundscurrent
JMA-1-VER-05
Timing and capacity test
Fixed deterministic synthetic verificationthread-suite-4.4.0passed-within-declared-boundscurrent
JMA-1-VER-06
Authority-state test
Fixed deterministic synthetic verificationauthority-suite-3.5.0passed-within-declared-boundscurrent
JMA-1-VER-07
Meaningful-review evidence test
Fixed deterministic synthetic verificationreview-suite-2.9.1passed-within-declared-boundscurrent
JMA-1-VER-08
Assessment contradiction test
Fixed deterministic synthetic verificationassessment-suite-3.3.2qualifiedcurrent
JMA-1-VER-09
Reconciliation and return-of-control test
Fixed deterministic synthetic verificationreconciliation-suite-2.6.0passed-within-declared-boundscurrent

Assurance case loaded.

Direct answers

What this lab proves—and what it cannot prove

What is a JADC2 mission-thread assurance case?

It is a bounded argument connecting one fixed fictional Joint All-Domain Command and Control mission-thread claim to replay events, supporting and contradictory evidence, assumptions, counterclaims, defeaters, verification activities, residual risks, and responsible review roles.

Does a complete assurance graph certify a JADC2 system?

No. It organizes bounded reasoning and makes evidence, assumptions, defeaters, versions, review roles, and limitations inspectable. It does not create safety, readiness, legality, command authority, force permission, accreditation, certification, or deployment approval.

What happens after a source, schema, software, policy, or authority change?

The original record remains visible. Affected evidence and verification become stale, missing, invalidated, suspended, or withdrawn; dependent claims change state; and named reviewers must repeat the relevant activities before current reliance can resume.

Can a passing component test support the whole mission thread?

Not by itself. End-to-end support also depends on evidence lineage, semantics, identity, trust, permitted purpose, timing, capacity, current authority, meaningful human review, assessment, reconciliation, and the exact tested versions.

Does opening an independent review resolve the assurance case?

No. Opening review identifies a fresh institutional process. It does not complete merits review, repair evidence, restore authority, or create a new supported conclusion.

Can this lab receive real evidence or create an Evulgare project?

No. KillWebs.com accepts only one allowlisted fictional case and change. It performs no external request or evidence transfer and creates no real-system project, legal conclusion, authority, certification, or deployment state.

Public synthetic boundary

The output is a teaching posture, not a real-system determination.

The lab cannot select or rank targets, assign weapons, recommend engagement, calculate probability of kill, allocate force, plan routes, authorize force, determine lawfulness, certify safety, approve deployment, assign liability, or validate an operational mission thread.

No composite assurance score is calculated. A favorable result in one claim cannot offset invalid evidence, expired authority, inadequate human review, or unresolved reconciliation.