Claim supported
Change impact without certification theater
JADC2 Mission-Thread Change Impact and Assurance Case Lab
Connect one fixed fictional Joint All-Domain Command and Control mission-thread replay to claims, evidence, assumptions, counterclaims, defeaters, verification, residual risk, and independent review—then see what remains supportable after a later change.
Research basis KW-RPT-007 KW-RPT-013 KW-RPT-040 KW-RPT-041 KW-RPT-042 KW-RPT-043 KW-RPT-044 KW-RPT-046 KW-RPT-047
Assurance argument, not approval
A complete graph can show why a bounded claim is supportable. It cannot certify a real system.
JADC2 means Joint All-Domain Command and Control. CJADC2 means Combined Joint All-Domain Command and Control. A kill chain is one selected ordered mission process; a kill web is the changing graph of possible mission threads; JADC2 is the wider enterprise that enables, secures, governs, tests, and sustains those threads.
The lab preserves the original fictional case and derives a separate current view. A source correction, software change, purpose withdrawal, authority expiry, missing interface record, contradictory assessment, or unresolved partition cannot be averaged away by favorable component tests.
- Input
- One fixed case and one allowlisted later change
- Output
- Claim states, invalidated evidence, defeaters, re-verification, and review duties
- Never
- Targeting, force authorization, legal review, readiness, certification, or deployment approval
- Score
- None—serious defects remain decisive
Sixteen independent elements
Keep evidence, authority, review, and reconciliation separately inspectable.
A favorable state in one element cannot compensate for invalid evidence, withdrawn purpose, expired authority, inadequate human review, or unreconciled state.
JMA-EL-01Stable identifiersCase, claim, evidence, event, thread, and data-product identifiers remain stable and separately addressable.JMA-EL-02Declared scopeSystem, mission-thread, purpose, organizational, temporal, and publication scope are explicit.JMA-EL-03Claim hierarchyOne bounded top-level claim is decomposed into independently reviewable subclaims.JMA-EL-04Supporting evidenceEvery supporting record links to replay provenance and a declared scope.JMA-EL-05Contradictory and missing evidenceContradictions and gaps remain visible instead of being absorbed into a fluent rationale.JMA-EL-06Assumptions and operating boundsEnvironmental, software, data, authority, and human-review assumptions are explicit.JMA-EL-07Counterclaims and defeatersThe graph preserves reasons a claim may be wrong or unusable.JMA-EL-08Verification identityVerification activities identify exact fictional method, software, schema, policy, and configuration versions.JMA-EL-09Artifact and policy identitySoftware, schema, model, policy, and configuration identities are not collapsed into product names.JMA-EL-10Release and permitted purposeReleasability, minimization, permitted use, expiry, and revocation remain distinct.JMA-EL-11Authority and human reviewDelegation, expiry, revocation, evidence access, time, competence, and intervention power are separately recorded.JMA-EL-12Reconciliation and return of controlTechnical reconnection is followed by explicit state reconciliation and bounded return of control.JMA-EL-13Residual risk and unknownsUnresolved limitations remain visible after favorable verification.JMA-EL-14Review-role qualityIndependence, competence, evidence access, available time, and corrective authority are explicit.JMA-EL-15Change impactEvery allowlisted later change identifies affected evidence, claims, tests, and reviewers.JMA-EL-16Current state and limitationsOriginal and current views remain separate, with no certification or readiness inference.
Fourteen non-equivalences
Do not let documentation become authority by appearance.
Evidence sufficient or accurate
Supported system claim
Validated decision quality
Certification
Operational readiness
Current evidence
Complete downstream re-verification
Permission to deploy
Current permitted use
Current authority
Meaningful merits review
Institutional or legal resolution
Independent review completed
Six fixed case families
The assurance cases align with the immutable replay histories.
No real organization, mission, platform, target, log, evidence package, authority instrument, or software artifact can be submitted.
Disaster-response information routing
A fictional multi-organization network routes infrastructure-damage observations to a bounded coordination service.
Replay: JMR-H1
Infrastructure-protection coordination
A fictional protective network coordinates sensor, maintenance, and service-continuity information without modeling force.
Replay: JMR-H2
Mission-partner awareness and releasability
A fictional mission partner contributes a minimized awareness product under explicit releasability and purpose conditions.
Replay: JMR-H3
Logistics recovery after gateway loss
A fictional logistics thread reroutes status data after a gateway fails and later reconnects with divergent state.
Replay: JMR-H4
Cyber-defense interpretation with contradictory evidence
A fictional defensive system compares anomaly evidence and a benign explanation before recommending containment.
Replay: JMR-H5
Time-critical protective support
A fictional protective thread operates under a short authority window and explicit human-review conditions.
Replay: JMR-H6
Original fixed case posture
Case supported with declared qualifications
qualifiedCurrent posture after selected change
Case supported with declared qualifications
qualifiedThe fixed fictional assurance case remains supported only with declared qualifications. Its graph is not certification, readiness, legal review, or force authority.
No composite assurance, JADC2, interoperability, trust, authority, readiness, confidence, legality, safety, accountability, mission-success, or certification score is calculated.
Warnings
- No additional warning beyond the standing public boundary.
Required actions
- Monitor declared assumptions and change triggers.
Required re-verification
- No additional re-verification in this fixed state.
Required review roles
- Assurance case owner — Maintains scope, claim decomposition, and current disposition without self-certifying the case.
- Independent assurance reviewer — Reviews merits outside the original decision chain and may require correction, suspension, or withdrawal.
Claim hierarchy
Original and current claim states
| Claim | Type | Original | Current | Replay events | Reason |
|---|---|---|---|---|---|
JMA-1-CLM-TOPThe fixed fictional mission thread remains supportable within its declared bounds | top-level | Supported with qualifications | Supported with qualifications | Original fixed teaching state: Supported with qualifications. | |
JMA-1-CLM-EVIDENCEEvidence lineage is complete enough for the bounded teaching claim | subclaim | Supported within declared bounds | Supported within declared bounds | JMR-H1-E01 JMR-H1-E02 JMR-H1-E03 JMR-H1-E05 | Original fixed teaching state: Supported within declared bounds. |
JMA-1-CLM-SEMANTICSemantic translation and interface meaning remain compatible | subclaim | Supported within declared bounds | Supported within declared bounds | JMR-H1-E04 | Original fixed teaching state: Supported within declared bounds. |
JMA-1-CLM-TRUSTIdentity, workload trust, and provenance assertions remain current | subclaim | Supported within declared bounds | Supported within declared bounds | JMR-H1-E06 | Original fixed teaching state: Supported within declared bounds. |
JMA-1-CLM-RELEASERelease, minimization, and permitted purpose remain valid for this scope | subclaim | Supported within declared bounds | Supported within declared bounds | JMR-H1-E07 | Original fixed teaching state: Supported within declared bounds. |
JMA-1-CLM-TIMINGTiming, capacity, reachability, and failure-domain assumptions remain within bounds | subclaim | Supported within declared bounds | Supported within declared bounds | JMR-H1-E08 | Original fixed teaching state: Supported within declared bounds. |
JMA-1-CLM-AUTHORITYCurrent delegated authority remains valid and separately enforced | subclaim | Supported within declared bounds | Supported within declared bounds | JMR-H1-E09 | Original fixed teaching state: Supported within declared bounds. |
JMA-1-CLM-HUMANThe recorded human review qualifies as meaningful merits review | subclaim | Supported within declared bounds | Supported within declared bounds | JMR-H1-E11 | Original fixed teaching state: Supported within declared bounds. |
JMA-1-CLM-ASSESSAssessment does not contradict the bounded interpretation | subclaim | Supported with qualifications | Supported with qualifications | JMR-H1-E10 JMR-H1-E12 | Original fixed teaching state: Supported with qualifications. |
JMA-1-CLM-RECONState reconciliation and return-of-control conditions remain satisfied | subclaim | Supported within declared bounds | Supported within declared bounds | Original fixed teaching state: Supported within declared bounds. |
Evidence and replay-event ledger
Invalidated records remain visible
| Evidence | Replay event | Data product | Exact versions | Original | Current |
|---|---|---|---|---|---|
JMA-1-EV-01Source observation created | JMR-H1-E01 | JMR-H1-DP-01 | collector-2.4.1 observation-3.0 collection-policy-4 | current | current |
JMA-1-EV-02Custody and provenance registered | JMR-H1-E02 | JMR-H1-DP-01 | provenance-ledger-1.9.0 prov-envelope-2.2 custody-policy-3 | current | current |
JMA-1-EV-03Data minimized and transformed | JMR-H1-E03 | JMR-H1-DP-02 | transform-service-5.1.2 semantic-profile-7.1 minimization-policy-6 | current | current |
JMA-1-EV-04Semantic and software versions locked | JMR-H1-E04 | JMR-H1-DP-02 | translator-4.6.0 mission-thread-schema-5.0 compatibility-policy-5 | current | current |
JMA-1-EV-05Evidence and contrary evidence qualified | JMR-H1-E05 | JMR-H1-DP-03 | evidence-service-3.8.4 evidence-contract-4.2 evidence-policy-8 | current | current |
JMA-1-EV-06Identity and workload trust evaluated | JMR-H1-E06 | JMR-H1-DP-03 | trust-engine-2.7.3 trust-assertion-3.1 zero-trust-policy-7 | current | current |
JMA-1-EV-07Release and permitted purpose decided | JMR-H1-E07 | JMR-H1-DP-04 | release-gate-3.4.2 release-contract-6.0 partner-use-policy-9 | current | current |
JMA-1-EV-08Reachability, timing, capacity, and failure domains checked | JMR-H1-E08 | JMR-H1-THREAD-01 | path-service-6.2.1 thread-state-4.0 capacity-policy-5 | current | current |
JMA-1-EV-09Delegated authority and expiry checked | JMR-H1-E09 | JMR-H1-THREAD-01 | authority-gate-4.3.0 delegation-contract-3.4 authority-policy-12 | current | current |
JMA-1-EV-10Bounded machine coordination output produced | JMR-H1-E10 | JMR-H1-THREAD-01 | option-composer-5.5.0 recommendation-contract-4.1 coordination-policy-10 | current | current |
JMA-1-EV-11Human merits review recorded | JMR-H1-E11 | JMR-H1-THREAD-01 | review-console-3.6.8 interface-state-2.9 human-review-policy-11 | current | current |
JMA-1-EV-12Assessment and residual unknowns recorded | JMR-H1-E12 | JMR-H1-ASSESS-01 | assessment-service-2.8.2 assessment-contract-3.3 assessment-policy-6 | current | current |
Assumptions and bounds
- Declared scope remains unchanged — The fictional purpose, participants, data products, timing, and non-force boundary remain as declared.
- Exact fictional versions are known — Software, schema, policy, and configuration identities remain the exact versions linked to the replay.
- Evidence custody remains verifiable — Source, custody, transformation, and correction records remain available.
- Authority remains current — Delegation, scope, expiry, and revocation state remain current for the bounded decision.
- Human review remains meaningful — Evidence access, contrary evidence, time, competence, authority, and intervention capability remain recorded.
- Reconciliation remains complete — No divergent state, duplicate ownership, or unresolved return-of-control condition exists.
Counterclaims
- A coherent replay may still preserve a flawed decision — Reproducibility and graph completeness do not prove evidence accuracy, good judgment, or operational suitability.
- A component test may not support the end-to-end claim — Local verification can miss semantic, organizational, human, and cross-system interactions.
Active defeaters
- No additional defeater activated by this selected change.
Residual risks
- Synthetic abstraction risk — The fixed catalog cannot establish behavior of any real joint or combined system.
- Open-world evidence risk — Unrecorded or unavailable evidence may change the interpretation.
- Human-machine interaction risk — A recorded interface state cannot prove comprehension or judgment quality by itself.
- Change and drift risk — Later software, data, policy, authority, environment, or organizational changes may invalidate current support.
Residual unknowns
- The fixed public case cannot establish real-system behavior, legal permission, operational acceptance, or deployment suitability.
Independent review state
not-opened
Verification activities
Exact fictional versions and current test state
| Activity | Method | Version | Baseline result | Current state |
|---|---|---|---|---|
JMA-1-VER-00End-to-end assurance review | Fixed deterministic synthetic verification | assurance-review-1.20.0 | qualified | current |
JMA-1-VER-01Evidence lineage replay | Fixed deterministic synthetic verification | lineage-check-4.2.0 | passed-within-declared-bounds | current |
JMA-1-VER-02Semantic compatibility test | Fixed deterministic synthetic verification | semantic-suite-5.0.1 | passed-within-declared-bounds | current |
JMA-1-VER-03Identity and provenance test | Fixed deterministic synthetic verification | trust-suite-3.7.2 | passed-within-declared-bounds | current |
JMA-1-VER-04Release and purpose test | Fixed deterministic synthetic verification | release-suite-6.1.0 | passed-within-declared-bounds | current |
JMA-1-VER-05Timing and capacity test | Fixed deterministic synthetic verification | thread-suite-4.4.0 | passed-within-declared-bounds | current |
JMA-1-VER-06Authority-state test | Fixed deterministic synthetic verification | authority-suite-3.5.0 | passed-within-declared-bounds | current |
JMA-1-VER-07Meaningful-review evidence test | Fixed deterministic synthetic verification | review-suite-2.9.1 | passed-within-declared-bounds | current |
JMA-1-VER-08Assessment contradiction test | Fixed deterministic synthetic verification | assessment-suite-3.3.2 | qualified | current |
JMA-1-VER-09Reconciliation and return-of-control test | Fixed deterministic synthetic verification | reconciliation-suite-2.6.0 | passed-within-declared-bounds | current |
Assurance case loaded.
Direct answers
What this lab proves—and what it cannot prove
What is a JADC2 mission-thread assurance case?
It is a bounded argument connecting one fixed fictional Joint All-Domain Command and Control mission-thread claim to replay events, supporting and contradictory evidence, assumptions, counterclaims, defeaters, verification activities, residual risks, and responsible review roles.
Does a complete assurance graph certify a JADC2 system?
No. It organizes bounded reasoning and makes evidence, assumptions, defeaters, versions, review roles, and limitations inspectable. It does not create safety, readiness, legality, command authority, force permission, accreditation, certification, or deployment approval.
What happens after a source, schema, software, policy, or authority change?
The original record remains visible. Affected evidence and verification become stale, missing, invalidated, suspended, or withdrawn; dependent claims change state; and named reviewers must repeat the relevant activities before current reliance can resume.
Can a passing component test support the whole mission thread?
Not by itself. End-to-end support also depends on evidence lineage, semantics, identity, trust, permitted purpose, timing, capacity, current authority, meaningful human review, assessment, reconciliation, and the exact tested versions.
Does opening an independent review resolve the assurance case?
No. Opening review identifies a fresh institutional process. It does not complete merits review, repair evidence, restore authority, or create a new supported conclusion.
Can this lab receive real evidence or create an Evulgare project?
No. KillWebs.com accepts only one allowlisted fictional case and change. It performs no external request or evidence transfer and creates no real-system project, legal conclusion, authority, certification, or deployment state.
Public synthetic boundary
The output is a teaching posture, not a real-system determination.
The lab cannot select or rank targets, assign weapons, recommend engagement, calculate probability of kill, allocate force, plan routes, authorize force, determine lawfulness, certify safety, approve deployment, assign liability, or validate an operational mission thread.
No composite assurance score is calculated. A favorable result in one claim cannot offset invalid evidence, expired authority, inadequate human review, or unresolved reconciliation.