APRF-RFC-0011 · accepted · MINOR · APRF v0.11.0
Evidence Assurance Tiers (E0–E5)
Adds normative Evidence Assurance Tiers (E0–E5) and Check evidencePolicy.minimumTier so PASS requires evidence at or above a declared floor; UNVERIFIED is a verification outcome on PARTIAL, not a sixth control status.
Created 2026-08-11
| Field | Value |
|---|---|
| Status | accepted |
| Author(s) | StackRail |
| Created | 2026-08-11 |
| SemVer impact | MINOR |
| Index summary | Adds normative Evidence Assurance Tiers (E0–E5) and Check evidencePolicy.minimumTier so PASS requires evidence at or above a declared floor; UNVERIFIED is a verification outcome on PARTIAL, not a sixth control status. |
Problem
Hybrid Checks already treat repository signals as incomplete and measured imports as required for PASS, but that distinction lives in collector folklore and report copy. Assessors and product UIs can still confuse “I found something in Git” with “the production control actually exists.” APRF needs a machine-checkable floor that does not invent new Checks.
Proposal
- Define Evidence Assurance Tiers (orthogonal to retention tiers
ephemeral/digest/attestedin ARCHITECTURE):
| Tier | Meaning |
|---|---|
| E0 | No evidence |
| E1 | Self-attestation |
| E2 | Repository evidence |
| E3 | Configuration evidence |
| E4 | Runtime evidence |
| E5 | Independent verification |
- Add optional Check field
evidencePolicy:
minimumTier:E0…E5acceptableEvidence: evidence-type IDs (starter registry; full Evidence Type Registry remains future work)
- Keep free-form
evidenceRequired: string[]for human prose.
- Satisfaction rule: a Check may be
PASSonly ifachievedTier >= minimumTierand existing passCondition / collector metrics hold. Below-floor evidence cannot PASS.
- Control statuses stay the closed five (
PASS/FAIL/PARTIAL/NOT_DEMONSTRATED/NOT_APPLICABLE). When substance exists butachievedTier < minimumTier, status isPARTIALwithevidenceTier.verification: UNVERIFIED. Do not addUNVERIFIEDas a sixth status (avoids scoring/SARIF/enum churn).
- Default
minimumTierwhen omitted: derive fromdetection.capability—manual→E1,hybrid→E3,automated→E4,none→E1.
- Assessment emits per-control
evidenceTier(minimum,achieved,acceptable,matched,verification∈NONE\|UNVERIFIED\|VERIFIED\|NOT_APPLICABLE). REPORT shows required vs achieved tier.
Alternatives considered
- Sixth status
UNVERIFIED— rejected; gate blockers already cover PARTIAL; enum churn across scoring, SARIF, HTML, and smokes is disproportionate. - Replace
evidenceRequiredwith structured-only types — rejected for v1; keep prose lists and addevidencePolicybeside them. - Require every Check to annotate tiers before ship — rejected; defaults from capability unblocks the catalog while wave-1 hybrids (e.g. SEC-M4) set explicit floors.
Compatibility
- Additive Check schema fields (
evidencePolicyoptional). - Gate semantics unchanged: below-floor remains a blocker via
PARTIAL. - Confidence model unchanged (orthogonal floor vs score).
- Retention tiers unchanged (different axis).
- Check IDs and profiles unchanged.
Security considerations
Raises honesty of production-readiness claims by preventing repo-only evidence from satisfying high-floor Checks. Does not certify third-party assessment; E5 is reserved for independent verification packs.
Open questions
_(none)_
Resolved
aprf-spec.jsoncheck rows do projectminimumTier(resolved from YAMLevidencePolicyor capability defaults) vianpm run aprf:sync-evidence-tiers; integrity fails on drift.- CI fails on unknown
acceptableEvidenceIDs (lintEvidencePolicy+ YAML validation); add new IDs tospec/evidence-types.yamlthen regenerate catalog.
Checklist
- Problem and affected parties
- Proposed change stated
- SemVer impact justified
- Compatibility / deprecation plan
- Checks remain measurable
- Crosswalk impact noted (N/A — no crosswalk ID changes)
- Security / safety considered
- Open questions listed
Comment window: 14 days from Created. Interim contact: see /aprf/rfc/.
Source markdown: /aprf/rfc/0011-evidence-assurance-tiers.md