Section 53 of 83
52. Upgrade
Stable section ID: S05-CON-005-SECTION-53 · 34 content blocks
An Upgrade increases, extends, or changes Cartridge capability while preserving authorized compatibility with the host and building system.
Upgrades may involve:
full Cartridge replacement;
replacement of an approved sub-Cartridge;
addition of an optional module;
increased capacity;
improved energy efficiency;
new sensing or control capability;
firmware or software change;
cybersecurity improvement;
adaptation to a newer protocol version;
modification required by regulation or building use.
Every Upgrade shall be classified as:
configuration-only;
software;
replaceable subcomponent;
functional;
capacity-affecting;
interface-affecting;
safety-affecting;
structural.
An Upgrade shall not be treated as ordinary maintenance if it changes declared capability, performance, interface behavior, control authority, structural resistance, safety response, or certified configuration.
Before implementation, the upgrade process shall verify:
host compatibility;
dependency compatibility;
power, data, fluid, thermal, and spatial capacity;
software and protocol compatibility;
effect on safety functions;
effect on certification;
rollback or recovery procedure;
required recommissioning.
Software updates shall preserve version history and configuration. Failed or interrupted updates shall place the Cartridge into a defined recoverable state rather than an ambiguous partially updated condition.
AI capability shall not be added through an upgrade without defining its authority, inputs, outputs, limitations, human oversight, data governance, and safe fallback behavior.
Following the Upgrade, the Cartridge shall receive an updated configuration record and, where necessary, a revised Type Identity, version, or certification status.