C.3.A:Annex C - ESG and Method–Work guards

Preface node heading:c-3-a-annex-c-esg-and-method-work-guards:45766

What this page is

This is generated FPF reference text from the specification preface or supporting sections. It helps interpret FPF; it is not FPF Reference product documentation.

Methodology

Use it to understand how the specification wants to be read, then return to a route, pattern, or work packet for active work. Cite generated IDs only when the wording changes the task decision.

Content

C.3.A:C.1 ESG obligations (normative)

When a state transition publishes or relies on a claim quantified over kinds, the ESG guard SHALL:

  1. pin the claim, exact quantified claim kind, receiving kind, and both needed KindSignature editions;
  2. establish the correct same-context restriction direction or the exact source-claim to target-receiving KindBridge relation and separate assertion;
  3. check Claim scope and explicit Gamma_time;
  4. when one or more actual candidates are part of the transition, evaluate each exact four-input target receiving-kind judgment and preserve all three values;
  5. when a RoleMask is used, recover its declaration edition and evaluate the exact masked judgment;
  6. apply justified bridge consequences to R only;
  7. check formality and freshness on their actual owners; and
  8. return a separate state-transition disposition.

ESG MUST NOT widen G to hide incompatibility, treat a label as a candidate judgment, or convert unknown to false.

C.3.A:C.2 Method–Work obligations (normative)

This Method–Work slice is conditional; it is not a definition that makes every actual change agentic, capability-held, planned, method-mediated, or Work. Open its capability/method/WorkPlan entry checks only when those objects and an A.15.1 Work use are current. A natural, spontaneous, formal, jointly caused, or non-separable U.Transformation remains under A.3/A.3.4 and does not acquire a fictive performer, role assignment, method, capability, plan, or Work to satisfy this guard. A broader scale-free-agency or Work decision remains with A.13, C.9, and A.15.1; this annex neither settles nor forbids it. Reflexive cases require separately grounded acting and affected positions, while joint or non-separable cases keep their direct dynamics, interaction, or causality governors rather than forcing one arbitrary actor-target split.

When the Method–Work use is current, it has two different boundaries.

Prospective entry. Before execution, a guard may decide that a holder capability, method, intended U.WorkPlan, JobSlice, and candidate inputs are sufficient to start. That decision SHALL NOT claim that Work already occurred. The capability instance, capability statements or currentness assessments, fit predicates, WorkPlan, JobSlice, and entry record remain distinct.

Actual result or acceptance. When performed Work is current, the guard SHALL identify exact W : U.Work as an independently grounded, world-side, dated 4D Work occurrence under A.15.1. W is not the U.Work kind, JobSlice, capability, plan item, log, card, row, or assertion. Any plan, log, result record, or assurance record about W is a separate episteme that designates W.

A conforming Method–Work check SHALL:

  1. require the capability's governed Work scope to cover exact JobSlice with explicit time;
  2. check capability measures, qualification/currentness, and fit as separately governed predicates;
  3. pin every expected input/output local kind and signature edition;
  4. for every actual input candidate, evaluate J(inputCandidate, expectedInputKind, inputSignatureEdition, JobSlice) and preserve all three values;
  5. use exact RoleMask declarations and masked judgments when procedural tailoring is current;
  6. establish exact target bridges/declarations and fresh target judgments for cross-context candidates;
  7. before execution, return only an entry disposition and keep W absent;
  8. after execution, identify W independently and, for every actual output candidate relied on, evaluate the exact output judgment;
  9. keep W, inputs, outputs, JobSlice, capability, plan, logs, and assertions distinct; and
  10. refuse fail-closed on false or unknown without rewriting either value.

C.3.A:C.3 Ready-to-use skeletons

ESG_TypedGate(Claim, claimKind, claimSignatureEdition, receiveKind, receiveSignatureEdition, TargetSlice, candidates?). Apply Guard_TypedClaim to the exact claim and receiving kinds; for each actual candidate apply Guard_CandidateUse with both declaration editions; apply bridge, freshness, and policy predicates; return the separate transition disposition.

MethodWork_EntryGate(Capability, WorkPlanRef, JobSlice, inputCandidates, inputDeclarations). Check Work scope, capability/qualification/fit predicates, exact input judgments, masks, bridges, and freshness. Return “entry allowed/refused”. Do not create or identify W.

MethodWork_ResultGate(W, JobSlice, actualInputs, actualOutputs, declarations, ResultRecordRef?). First recover the independently grounded dated W under A.15.1. Then evaluate exact input/output candidate judgments, check scope and any acceptance predicates, and keep any ResultRecordRef as a separate episteme designating W.

C.3.A:C.4 Worked examples [I]

ESG braking policy. The claim pins VehicleSignature@v4 and the dry/wet TargetSlice. The consumer is restricted to PassengerCar, and SubkindOfObtains(PassengerCar, Vehicle; plantVehicleScheme) holds under the paired exact declaration editions. For VIN-17, evaluate J(VIN-17, PassengerCar, passengerCarEdition, TargetSlice)=true; C.3.1 monotonicity then supplies the Vehicle-side classification needed by the universal claim. An unavailable brake-configuration dependency would yield unknown, and the transition would refuse separately.

Risk-score Work entry and occurrence. ComputeRiskScore capability is considered for request req-884 in JobSlice api-v2.3/eu-west/t-204. The entry guard evaluates the request under the pinned AuthenticatedRequest signature. If true, it may admit execution; no Work occurrence yet follows. After execution, actual W = RiskScoreRun-2026-07-22T10:03Z-884 : U.Work is independently grounded as the dated world-side occurrence. RiskScoreRunLog-884 is a separate episteme designating W. The output score value is a separate candidate evaluated under its declared output kind and signature edition.

Cross-context plant use. The source claim and source kind cross via separate Scope and KindBridge channels. Plant-B recovers its own target declaration and evaluates exact TransportUnit candidate TU-9. Bridge assertions affect R; they do not classify TU-9 or create the later Work occurrence.

C.3.A:C.5 Anti-patterns and remedies

Anti-patternRemedy
widening Work scope to hide an input mismatchrepair declaration compatibility, adapter, mask, or bridge; otherwise refuse
calling JobSlice or WorkPlan the workbefore execution keep W absent; after execution identify the independently grounded dated W
treating a log or result row as Wkeep it as a separate episteme that designates W
omitting the exact candidate or signature editionpin all four judgment inputs
converting unavailable support to falseretain unknown and refuse separately
treating bridge or adapter records as target truthrecover target declarations and evaluate candidates afresh

Last Updated: 2026-07-28 — upstream FPF commit 17edd955 (github.com/ailev/FPF)