← Stewardship & RFCs

APRF-RFC-0011 · accepted · MINOR · APRF v0.11.0

Evidence Assurance Tiers (E0–E5)

Adds normative Evidence Assurance Tiers (E0–E5) and Check evidencePolicy.minimumTier so PASS requires evidence at or above a declared floor; UNVERIFIED is a verification outcome on PARTIAL, not a sixth control status.

Created 2026-08-11

FieldValue
Statusaccepted
Author(s)StackRail
Created2026-08-11
SemVer impactMINOR
Index summaryAdds normative Evidence Assurance Tiers (E0–E5) and Check evidencePolicy.minimumTier so PASS requires evidence at or above a declared floor; UNVERIFIED is a verification outcome on PARTIAL, not a sixth control status.

Problem

Hybrid Checks already treat repository signals as incomplete and measured imports as required for PASS, but that distinction lives in collector folklore and report copy. Assessors and product UIs can still confuse “I found something in Git” with “the production control actually exists.” APRF needs a machine-checkable floor that does not invent new Checks.

Proposal

  1. Define Evidence Assurance Tiers (orthogonal to retention tiers ephemeral / digest / attested in ARCHITECTURE):
TierMeaning
E0No evidence
E1Self-attestation
E2Repository evidence
E3Configuration evidence
E4Runtime evidence
E5Independent verification
  1. Add optional Check field evidencePolicy:
  • minimumTier: E0…E5
  • acceptableEvidence: evidence-type IDs (starter registry; full Evidence Type Registry remains future work)
  1. Keep free-form evidenceRequired: string[] for human prose.
  1. Satisfaction rule: a Check may be PASS only if achievedTier >= minimumTier and existing passCondition / collector metrics hold. Below-floor evidence cannot PASS.
  1. Control statuses stay the closed five (PASS / FAIL / PARTIAL / NOT_DEMONSTRATED / NOT_APPLICABLE). When substance exists but achievedTier < minimumTier, status is PARTIAL with evidenceTier.verification: UNVERIFIED. Do not add UNVERIFIED as a sixth status (avoids scoring/SARIF/enum churn).
  1. Default minimumTier when omitted: derive from detection.capability — manual→E1, hybrid→E3, automated→E4, none→E1.
  1. Assessment emits per-control evidenceTier (minimum, achieved, acceptable, matched, verification ∈ NONE \| UNVERIFIED \| VERIFIED \| NOT_APPLICABLE). REPORT shows required vs achieved tier.

Alternatives considered

  • Sixth status UNVERIFIED — rejected; gate blockers already cover PARTIAL; enum churn across scoring, SARIF, HTML, and smokes is disproportionate.
  • Replace evidenceRequired with structured-only types — rejected for v1; keep prose lists and add evidencePolicy beside them.
  • Require every Check to annotate tiers before ship — rejected; defaults from capability unblocks the catalog while wave-1 hybrids (e.g. SEC-M4) set explicit floors.

Compatibility

  • Additive Check schema fields (evidencePolicy optional).
  • Gate semantics unchanged: below-floor remains a blocker via PARTIAL.
  • Confidence model unchanged (orthogonal floor vs score).
  • Retention tiers unchanged (different axis).
  • Check IDs and profiles unchanged.

Security considerations

Raises honesty of production-readiness claims by preventing repo-only evidence from satisfying high-floor Checks. Does not certify third-party assessment; E5 is reserved for independent verification packs.

Open questions

_(none)_

Resolved

  • aprf-spec.json check rows do project minimumTier (resolved from YAML evidencePolicy or capability defaults) via npm run aprf:sync-evidence-tiers; integrity fails on drift.
  • CI fails on unknown acceptableEvidence IDs (lintEvidencePolicy + YAML validation); add new IDs to spec/evidence-types.yaml then regenerate catalog.

Checklist

  • Problem and affected parties
  • Proposed change stated
  • SemVer impact justified
  • Compatibility / deprecation plan
  • Checks remain measurable
  • Crosswalk impact noted (N/A — no crosswalk ID changes)
  • Security / safety considered
  • Open questions listed

Comment window: 14 days from Created. Interim contact: see /aprf/rfc/.

Source markdown: /aprf/rfc/0011-evidence-assurance-tiers.md