Native SafetySupervisor
Bound the action. Preserve the reason.
SHEEPDOG coordinates mission roles above approved vehicle control loops. Native safety gates, least-authority roles, human authorization, deterministic replay, and explicit maturity labels define what the system may do—and what it may only recommend.
Safety path
Every mission recommendation passes four boundaries.
The mission layer can recommend, assign, re-plan, or release a role only inside the declared capability, policy, authority, and evidence envelope.
Capability passport
Roles, sensors, energy, geography, communications, confidence, health, failsafes, and control limits.
SafetySupervisor
Evaluate mission, platform, policy, timing, confidence, and failure-state constraints before release.
Human decision gate
Verify identity, role, scope, mission, expiry, and required approval for high-consequence actions.
Decision evidence
Retain the requester, reason, alternatives, selected action, approval, result, and recovery history.
Auditable personnel authorization
Authority belongs to a verified role—not an anonymous screen.
Operator
Supervises the bounded mission, acknowledges alerts, accepts or rejects recommendations, and can invoke an approved stop condition.
Mission authority
Defines the mission envelope, protected constraints, delegation scope, expiry, and which decisions require explicit approval.
Reviewer / auditor
Reads the immutable decision trail, compares replay with policy, and verifies that authority, evidence, and maturity claims remain aligned.
Native gate outcomes
Allow, constrain, deny, or fall back.
SafetySupervisor is part of the mission decision path. It does not depend on a slide, a post-hoc report, or an operator remembering every rule.
All declared capability, policy, confidence, and authority conditions are satisfied.
RECORD
Reduce scope, duration, speed, geography, role, or autonomy before release.
RE-CHECK
Reject an action outside capability, policy, confidence, or authorization boundaries.
EXPLAIN
Release a role, preserve the reserve, hand off sensing, or return authority to an approved controller.
RECOVER

Validation path
Software evidence first. Physical integration follows a staged validation path.
SHEEPDOG supports deterministic scenarios, capability-aware assignment, failure injection, recovery, SafetySupervisor gates, role-based authorization, and audit history.
Approved autopilot integration, SIL, HIL, edge deployment, and physical multi-vehicle trials.

Validation ladder
Promote behavior only after the evidence improves.
Seeded scenarios and retained negative results.
Holdout replay, SafetySupervisor gates, and Model Cards.
Approved autopilot software in the loop.
Edge compute, links, timing, and hardware interfaces.
Bounded trials with named authority and stop conditions.
Validation partnership
Define the authority and evidence gate before the demonstration.
We welcome technical review, autonomy-safety collaboration, authorization design, integration testbeds, and bounded validation programs.