Research Insight · Decision Reasoning Architecture
A decision system should not turn partial evidence into premature certainty. SHEEPDOG keeps observations, identity hypotheses, intent hypotheses, and contextual threat assessments separate—then preserves the evidence for SafetySupervisor and authorized human review.
Contextual threat assessment
Human authority retained
Identity is not a label, intent is not certainty, and threat is not a synonym for identity. In mixed, communications-degraded, or rapidly changing environments, the most responsible answer may remain: unknown.
That answer is not a failure of intelligence. It is a valid system state. A mission layer that hides ambiguity can produce confident-looking output without preserving the reasons, contradictions, or missing evidence behind it. A mission layer that represents uncertainty explicitly can request verification, compare alternatives, and show an authorized operator why a recommendation changed.
One contact, four different questions
Public discussion often collapses observation, identity, intent, and threat into a single classification. SHEEPDOG treats them as different reasoning layers because each has different evidence, confidence, and consequences.
1. What was observed?
Time-stamped sensor reports, messages, track changes, and mission context—with source and transformation history attached.
2. What might it be?
Multiple identity hypotheses may coexist: friendly, neutral, unknown, or potentially hostile. Confidence is bounded and reversible.
3. What might it intend?
Intent is inferred from behavior and context over time. It remains a hypothesis, not a fact extracted from a single observation.
4. What risk exists now?
Threat is contextual: possible capability, proximity or opportunity, potential harm, uncertainty, and the consequence of delay all matter.

Preserve competing hypotheses
A system should be able to hold more than one plausible explanation at the same time. “Unknown” does not have to disappear simply because one alternative becomes more likely. New evidence may strengthen a hypothesis, weaken it, or expose a conflict that requires a different sensor, a human check, or more time.
This is especially important when observations are incomplete, identifiers are unavailable, communications are intermittent, or visually similar platforms share the same operating area. Prematurely forcing a single label makes the system appear decisive while making it harder to recover when the label is wrong.
Design principle: uncertainty should change system behavior. It can trigger verification, constrain recommendations, increase logging, or escalate review. It should not be converted silently into certainty.

Identity and threat belong on different axes
Even a high-confidence identity assessment does not, by itself, determine threat. A known object can be non-threatening in one context and create risk in another. An unknown object may justify verification or precaution without justifying a hostile label. The assessment must consider context and possible harm, not just category membership.
SHEEPDOG therefore separates the identity hypothesis from the contextual threat assessment. Recommendations can include observing, requesting verification, applying a declared safety constraint, or escalating to an authorized person. Each recommendation is recorded for authorized review.
Make the reasoning replayable
Every material recommendation should leave a record that can be inspected after the fact. We call this the Decision Chronicle: a compact evidence chain showing what was observed, which alternatives were considered, what contradicted the leading view, how confidence changed, which policy version applied, and which authorized person made the final decision.
This does more than support audit. It helps engineering teams reproduce failures, compare policy revisions, test whether a model is becoming overconfident, and distinguish a sensor problem from a reasoning problem. It also makes disagreement visible: reviewers can inspect the evidence without pretending the system knew more than it did.

What this means for edge compute partners
The candidate edge policy bundle is a signed, versioned workload that can update compact state and hypothesis graphs, run bounded inference, preserve provenance, and return a recommendation to the mission layer.
Exact latency, memory, thermal, and compiler targets remain part of Milestone 01 benchmarking with each SoC or system-on-module partner. The goal is to find the smallest reproducible workload envelope that can be verified across multiple non-China supply-chain platforms—not to claim performance before it is measured.
From milestone to method
Our earlier engineering update documented the first synthetic slice of identity under uncertainty: preserving ambiguity, requesting verification, and making the result replayable. This Insight describes the broader architecture around that milestone. Read SHEEPDOG: Identity Under Uncertainty for the dated implementation note.
Build the bounded POC with us
We are qualifying partners across the mission stack.
We welcome programmable small-UAV OEMs, edge AI SoC and SoM teams, sensor and data-link providers, simulation partners, and legal flight-test organizations. A first engagement is a bounded technical fit call—not a request to disclose secrets.



