1. Decision and target
Name the system, release, environment, operating mode, owner, decision date, and scope exclusions.
Method / Evidence
Connect a deployment claim to a system model, explicit invariant, controlled exploration, inspectable evidence, finding, remediation, and retest decision.
Name the system, release, environment, operating mode, owner, decision date, and scope exclusions.
State the property that must hold, why it matters, and the conditions under which it is expected to hold.
Map the actors, identities, permissions, state, trust boundaries, commands, enforcement points, and possible physical effect.
Record the baseline, controlled variation, expected observation, stop conditions, actual observation, and reproducible procedure.
Label design, configuration, simulation, runtime reachability, command acceptance, physical consequence, detection, stop, and recovery evidence separately.
Separate observed fact, inference, hypothesis, and missing evidence. State the impact boundary and what the evidence does not prove.
Tie the proposed enforcement change to the violated invariant and define the exact evidence needed to close the retest.
Supported / unsupported / unknown / blocked—followed by the evidence and remaining uncertainty that justify the status.
Delivered through Attify
The Attify checklist turns this CFSE evidence structure into a concrete cross-layer review across firmware, ROS 2, cloud, autonomy, actuation, stop, and recovery.