Section 71 of 102
70. Command, Action and Feedback Model
Stable section ID: S05-CON-010-SECTION-71 · 26 content blocks
Every consequential operational command shall be represented through a controlled command–action–feedback process.
A command should define:
- Command identity.
- Issuing agent or person.
- Authority basis.
- Target component or system.
- Requested outcome.
- Permitted execution window.
- Preconditions.
- Safety constraints.
- Expected response.
- Verification method.
- Cancellation or rollback method.
- Expiration condition.
Before execution, the receiving system shall verify that the command is authentic, current, compatible, authorized, and applicable to the present operational state.
System05 shall distinguish among:
- Requested action.
- Authorized action.
- Issued command.
- Accepted command.
- Physical execution.
- Reported completion.
- Independently verified outcome.
- Failed or partial execution.
Command acknowledgment shall not be treated as proof of physical completion. Feedback should be obtained from the controlled device, related sensors, or another suitable verification source.
Where execution differs from the requested outcome, the discrepancy shall generate an operational event and risk-appropriate response. Repeated commands shall not be used to conceal an unresolved failure.