SAFETY · GOVERNANCE · DECISION EVIDENCE

Native SafetySupervisor

Bound the action. Preserve the reason.

SHEEPDOG coordinates mission roles above approved vehicle control loops. Native safety gates, least-authority roles, human authorization, deterministic replay, and explicit maturity labels define what the system may do—and what it may only recommend.

MISSION INTENT + CAPABILITY PASSPORTProposed role and action NATIVE SAFETYSUPERVISORAllow · deny · constrain · fallback HUMAN AUTHORITYApprove or reject APPROVED CONTROLLERRetains vehicle authority DETERMINISTIC DECISION EVIDENCEWho · why · scope · outcome · recovery

Least authorityOnly the bounded role required
SafetySupervisorExplicit allow and deny gates
Human authorizationAuditable role and approval chain
Deterministic replayTrigger, choice, outcome, recovery

Safety path

Every mission recommendation passes four boundaries.

The mission layer can recommend, assign, re-plan, or release a role only inside the declared capability, policy, authority, and evidence envelope.

01 · DECLARE

Capability passport

Roles, sensors, energy, geography, communications, confidence, health, failsafes, and control limits.

02 · GATE

SafetySupervisor

Evaluate mission, platform, policy, timing, confidence, and failure-state constraints before release.

03 · AUTHORIZE

Human decision gate

Verify identity, role, scope, mission, expiry, and required approval for high-consequence actions.

04 · RECORD

Decision evidence

Retain the requester, reason, alternatives, selected action, approval, result, and recovery history.

Auditable personnel authorization

Authority belongs to a verified role—not an anonymous screen.

Operator

Supervises the bounded mission, acknowledges alerts, accepts or rejects recommendations, and can invoke an approved stop condition.

Mission authority

Defines the mission envelope, protected constraints, delegation scope, expiry, and which decisions require explicit approval.

Reviewer / auditor

Reads the immutable decision trail, compares replay with policy, and verifies that authority, evidence, and maturity claims remain aligned.

Native gate outcomes

Allow, constrain, deny, or fall back.

SafetySupervisor is part of the mission decision path. It does not depend on a slide, a post-hoc report, or an operator remembering every rule.

ALLOW

All declared capability, policy, confidence, and authority conditions are satisfied.

RECORD

CONSTRAIN

Reduce scope, duration, speed, geography, role, or autonomy before release.

RE-CHECK

DENY

Reject an action outside capability, policy, confidence, or authorization boundaries.

EXPLAIN

FALLBACK

Release a role, preserve the reserve, hand off sensing, or return authority to an approved controller.

RECOVER

SHEEPDOG deterministic event ledger preserving assignments, authorization, outcomes, and recovery evidence.
Public interface view. Internal prompts, thresholds, policy weights, credentials, and bypass conditions are not disclosed.

Validation path

Software evidence first. Physical integration follows a staged validation path.

SHEEPDOG supports deterministic scenarios, capability-aware assignment, failure injection, recovery, SafetySupervisor gates, role-based authorization, and audit history.

Current integration path
Approved autopilot integration, SIL, HIL, edge deployment, and physical multi-vehicle trials.
SHEEPDOG benchmark matrix separating deterministic simulator evidence from future physical validation.
Evidence is labeled by maturity and linked to the scenario, seed, configuration, decision trail, and result.

Validation ladder

Promote behavior only after the evidence improves.

01 · SIMULATE

Seeded scenarios and retained negative results.

02 · VERIFY

Holdout replay, SafetySupervisor gates, and Model Cards.

03 · SIL

Approved autopilot software in the loop.

04 · HIL

Edge compute, links, timing, and hardware interfaces.

05 · FIELD

Bounded trials with named authority and stop conditions.

Validation partnership

Define the authority and evidence gate before the demonstration.

We welcome technical review, autonomy-safety collaboration, authorization design, integration testbeds, and bounded validation programs.