Requirements Traceability Matrix (RTM)¶
Status: Build 843 verification traceability approved for IDE submission
Version: 1.86
Owner: BionicLoop engineering
Prepared by: BionicLoop engineering
Approval reference: Edward R. Damiano, PhD, Build 843 traceability acceptance
and final software-package approval, controlled email dated 2026-09-07 EDT
Baseline freeze SHA: 91c0e98a9bc9429a0486bebdebffc7d8dbbe300e
Last updated: 2026-09-08
Revision History¶
| Version | Date | Author | Summary of Changes |
|---|---|---|---|
| 0.1 | 2026-04-05 | Engineering | Initial controlled RTM draft |
| 0.9 | 2026-04-06 | BionicLoop engineering | Added controlled-document metadata and refined RA-009 cybersecurity trace mapping for the software-only package. |
| 0.91 | 2026-04-07 | BionicLoop engineering | Narrowed RA-009 to the current local-security claim set, aligned RA-013 and RA-015 evidence notes with the implemented baseline, and changed high-risk freeze blockers to Rerun needed status |
| 0.92 | 2026-04-08 | BionicLoop engineering | Added masked offline-fallback maintenance/disarm trace links. |
| 0.93 | 2026-04-08 | BionicLoop engineering | Clarified masked-fallback renewal-window, deferred-maintenance, and restore-context trace links. |
| 0.94 | 2026-04-14 | BionicLoop engineering | Added trace notes for reconciliation-required blocked state after offline mask expiry |
| 0.95 | 2026-04-14 | BionicLoop engineering | Added trace notes for reconnect restore/disarm retry and explicit fresh re-arm after successful masked-fallback recovery |
| 0.96 | 2026-04-14 | BionicLoop engineering | Updated reconnect recovery trace notes for fresh-session auto-arm and preserved fallback review history after successful masked-fallback recovery |
| 0.97 | 2026-04-14 | BionicLoop engineering | Tightened reconnect recovery trace notes so explicit reset/loop-off keeps the loop off after restore and recovery timing reflects restore completion |
| 0.98 | 2026-04-14 | BionicLoop engineering | Updated reconnect recovery trace notes to show same-session unreconciled resume on the current due slot after successful masked-fallback restore |
| 0.99 | 2026-04-15 | BionicLoop engineering | Added trace notes for modeled-vs-pump-reported fallback review, pod total-delivery baseline persistence, and pre-step missing-fallback arm behavior |
| 1.00 | 2026-04-15 | BionicLoop engineering | Added trace notes for confirmed/corrected same-session basal-only replay, persisted replay-plan state, and replay-detail Recent Dose Steps coverage |
| 1.01 | 2026-04-15 | BionicLoop engineering | Added trace notes for dedicated loop.fallback.event cloud telemetry emission and fallback-event payload verification for BionicScout contract support |
| 1.02 | 2026-04-15 | BionicLoop engineering | Added trace notes for replayed-step propagation into local per-step telemetry / CSV export with explicit replay markers |
| 1.03 | 2026-04-27 | BionicLoop engineering | Added trace notes that fallback replay requires pump-reported delivered-insulin delta and does not substitute modeled expected delivery when pump reconciliation is unavailable |
| 1.04 | 2026-05-06 | BionicLoop engineering | Added trace notes for safety q5 nominal-basal profile persistence, four-bucket fallback schedule programming, schedule-aware exposure modeling, and fallback profile/schedule cloud telemetry |
| 1.05 | 2026-06-02 | BionicLoop engineering | Updated trace notes for pump-delta fallback missed-step algorithm replay and repeated no-active-pod critical alert verification |
| 1.06 | 2026-06-06 | BionicLoop engineering | Added trace notes for same-pod continuity replay gating, different/new pod no-replay continuation, pod-continuity telemetry, and explicit-operator-only session lifecycle |
| 1.07 | 2026-06-08 | BionicLoop engineering | Added trace notes for persisted-schedule-weighted pump-delta replay allocation and zero-weight replay suppression |
| 1.08 | 2026-06-10 | BionicLoop engineering | Added trace notes for current-step masked-fallback first-arm ordering before same-step pump command application |
| 1.09 | 2026-06-11 | BionicLoop engineering | Clarified that confirmed/corrected fallback replay is bounded to fallback-active missed slots and excludes pre-activation disconnected gaps |
| 1.10 | 2026-06-11 | BionicLoop engineering | Added trace notes for fresh-status pre-execution fallback maintenance gating, existing-mask remask-failure recovery, pending replay-plan cleanup, and cached-idle refresh-failure regression coverage |
| 1.11 | 2026-06-12 | BionicLoop engineering | Added trace mapping for generalized issued-dose attribution and different/new-pod no-replay disposition |
| 1.12 | 2026-06-15 | BionicLoop engineering | Updated issued-dose different/new-pod trace mapping to assumed-delivered attribution, nonblocking replacement-pod dosing, and deferred adaptation-forget question |
| 1.13 | 2026-06-17 | BionicLoop engineering | Added trace notes for one-step algorithm/runtime cadence reconciliation before meal-step selection and live executed-step/request-step alignment with algorithm stepTime. |
| 1.14 | 2026-06-18 | BionicLoop engineering | Added trace notes for fallback-only replay request-step attribution and evidence-gated issued-dose attribution clearing. |
| 1.15 | 2026-06-18 | BionicLoop engineering | Clarified resolved issued-dose attribution when the dose precedes fallback-active replay: merge into the first fallback replay row rather than replaying pre-fallback disconnected slots. |
| 1.16 | 2026-06-18 | BionicLoop engineering | Added trace notes for retired/expired/no-active-pod fallback recovery using assumed modeled fallback exposure when pump-counter reconciliation evidence is unrecoverable. |
| 1.17 | 2026-06-23 | BionicLoop engineering | Added provisional pod-simulation scaffold trace note and TV-SIM-POD-* working coverage expectations. |
| 1.18 | 2026-06-23 | BionicLoop engineering | Added first pod-simulation scenario slice for shared-invariant same-pod live attribution, replacement-pod assumed delivery, and schedule-weighted fallback replay coverage. |
| 1.19 | 2026-06-23 | BionicLoop engineering | Expanded pod-simulation trace note for canceled and consecutive-canceled meal live attribution, user-escaped unavailable-pod assumed delivery, fallback-maintenance command blocking, and relaunch fallback replay with unavailable CGM. |
| 1.20 | 2026-06-23 | BionicLoop engineering | Added explicit pod-simulation trace coverage for unresolved correction-only and basal-only assumed-delivered replacement-pod dosing. |
| 1.21 | 2026-06-23 | BionicLoop engineering | Added pod-simulation trace coverage for ambiguous fallback restore without replay or modeled-dose injection. |
| 1.22 | 2026-06-23 | BionicLoop engineering | Added pod-simulation trace coverage for assumed old-pod fallback replay, missing-status/nonreplayable fallback-plan clearing, and matching meal-progress cleanup after issued-dose evidence consumption. |
| 1.23 | 2026-06-23 | BionicLoop engineering | Added pod-simulation trace coverage for reservoir-capped partial meal delivery feeding actual delivered units without replay or unresolved meal-progress state. |
| 1.24 | 2026-06-23 | BionicLoop engineering | Added pod-simulation trace coverage for reservoir-capped fallback replay using observed pump delta instead of modeled exposure. |
| 1.25 | 2026-06-23 | BionicLoop engineering | Added pod-simulation trace coverage for meal/fallback overlap partition replay with the meal dose merged into the first fallback-active replay row. |
| 1.26 | 2026-06-23 | BionicLoop engineering | Added trace coverage for app recent-dose persistence/display of merged meal/fallback replay evidence source, disposition, request step, requested units, and delivered units. |
| 1.27 | 2026-06-23 | BionicLoop engineering | Added trace coverage for local step CSV export of merged fallback replay evidence source, disposition, and failure-reason fields. |
| 1.28 | 2026-06-23 | BionicLoop engineering | Added trace coverage for runtime cloud step-event emission of merged fallback replay evidence source, disposition, request-step, requested-unit, and delivered-unit fields. |
| 1.29 | 2026-07-07 | BionicLoop engineering | Added trace notes for same-pod fallback recovery using persisted-schedule modeled exposure as assumed delivered when pump delivery delta is unavailable, schedule evidence matches, and no issued-dose partition is required. |
| 1.30 | 2026-07-08 | BionicLoop engineering | Added trace notes for fresh-status patience before same-pod assumed meal resolution after relaunch, algorithm-visible meal-exclusion request-step keying, and cloud/dashboard-only meal-exclusion disposal evidence. |
| 1.31 | 2026-07-08 | BionicLoop engineering | Added trace links for Algo2015 checkBG fingerstick request surfacing, dedupe, haptic feedback, BG-button emphasis, and stale-relaunch suppression. |
| 1.32 | 2026-07-08 | BionicLoop engineering | Added trace links for Algo2015 forced-open-loop characterization, command blocking, fallback-maintenance preservation, and safety-critical alert surfacing. |
| 1.33 | 2026-07-08 | BionicLoop engineering | Added trace links for Reference-host no-boundary-cancel liveness-bound proof across DASH bolus completion, disconnect/unknown state, and fresh idle issued-dose consumption. |
| 1.34 | 2026-07-09 | BionicLoop engineering | Formal freeze-candidate evidence recorded at f098a8b: 14 rows carry executed formal bundles (STR-ALG/AUTO/SIM/SEC lanes) pending sponsor designation; RA-007 hardware closure, RA-015 real-device gap, and RA-009 acceptability disposition remained open. |
| 1.35 | 2026-07-10 | BionicLoop engineering | Reopened the baseline after correcting shared algorithm state: f098a8b marked superseded across all formal-evidence row statuses; added RA-018 (connected-outage zero-insulin window, ANOM-003) and SRS-ALG-008 tracing through RA-014; linked SRS-RUN-007 into RA-003; added the explicit SRS-SEC-003..009 deferral note. |
| 1.36 | 2026-07-14 | BionicLoop engineering | Updated RA-018 for implemented fingerstick-supported CGM-outage dosing: SRS-OUTAGE-001..006 + TV-OUTAGE-001..003 traced with working evidence and formal promotion pending. |
| 1.37 | 2026-07-14 | BionicLoop engineering | RA-013 row gains SRS-CLIN-013/014 and TV-CLIN-014/015 (clinical-feedback defaults + New Participant Reset). |
| 1.38 | 2026-07-14 | BionicLoop engineering | Added SRS-PUMP-011 + TV-PUMP-010 to RA-017, corrected its evidence wording to the implemented assumed-delivered semantics, added SDD-OUTAGE-001 to RA-018, extended RA-013 defaults/reset evidence, and added RA-019 for unintended New Participant Reset. |
| 1.39 | 2026-07-15 | BionicLoop engineering | Added SRS-LOG-010 + TV-LOG-010 to RA-008 for build-designated cloud-log integration-evidence collection. |
| 1.40 | 2026-07-16 | BionicLoop engineering | RA-008 row gains SRS-LOG-011 + TV-LOG-011 (server-issued remote logging config). |
| 1.41 | 2026-07-16 | BionicLoop engineering | RA-010 row gains SRS-UI-009 + SDD-APP-008 + TV-UI-011 (server-configurable investigational badge). |
| 1.42 | 2026-07-18 | BionicLoop engineering | Added the RA-020 risk-control row: SRS-OUTAGE-006 / SDD-OUTAGE-001 / TV-OUTAGE-002 with issued-dose crediting and pod-away gap-replay working evidence. |
| 1.43 | 2026-07-18 | BionicLoop engineering | Refreshed RA-020 working evidence for persisted-credit conservation, drift-skip re-synthesis, non-flat quantized weighting, profile-time-zone weighting, and real-C++ engine-ledger conservation. Added the Algo2015 diagnostic-artifact protection regression to RA-009 and corrected its design allocation to SDD-LOG-001. |
| 1.44 | 2026-07-19 | BionicLoop engineering | Exact-step pending manual BG plus meal execution is traced through SRS-BG-004/SRS-MEAL-002, RA-004/RA-012, SDD-BG-001/SDD-POL-004, and TV-MEAL-002. Same-severity Pod signal-loss precedence is traced through SRS-ALERT-011, RA-011, SDD-ALERT-001, and TV-ALERT-002/010. |
| 1.45 | 2026-07-20 | BionicLoop engineering | Manual-BG review safety and direct-request emphasis traced through SRS-BG-001/SRS-ALERT-018/SRS-OUTAGE-003, RA-010/RA-011/RA-012/RA-018, SDD-BG-001/SDD-ALERT-001, and TV-BG-008/TV-ALERT-017/TV-OUTAGE-003/TV-UI-006. |
| 1.46 | 2026-07-20 | BionicLoop engineering | Manual-BG request emphasis rendering hardening traced through SDD-ALERT-001 and TV-ALERT-017; the localized-halo regression test closes the hardware-observed chart compositing artifact without changing request scope, alert precedence, or runtime behavior. |
| 1.47 | 2026-07-20 | BionicLoop engineering | Traced the SRS-PUMP-010 v1.48 fresh-completion upgrade rule through SDD-POL-029, RA-017, and TV-PUMP-009, with adapter restoration bounded by BionicLoopPumpEvidenceRelaunchUpgradeTests following a force-quit mid-bolus field incident. |
| 1.48 | 2026-07-21 | BionicLoop engineering | RA-008 trace note updated for SRS-LOG-009 v1.51 / SDD-LOG-001 v1.52 / TV-LOG-009 v1.47: steady-cadence schedule_checked_unchanged schedule + coverage payload (no bulk 288-rate array), per-six-hour-bucket observed-slot counts on arm/refresh/unchanged events, and Recent Dose Steps outcome-label/per-segment-provenance rows. |
| 1.49 | 2026-07-21 | BionicLoop engineering | Corrected the SRS-PUMP-010 / SDD-POL-029 / RA-017 / TV-PUMP-009 fresh-completion trace: zero bolusNotDelivered after cancel + relaunch is not full-delivery proof; only explicitly persisted in-progress-capped provenance permits a higher settled observation. Added adapter/runtime/persistence regression links and truth-synced the accepted BG centered shadow bloom after physical-device confirmation. |
| 1.50 | 2026-07-21 | BionicLoop engineering | Prospective forced-open meal blocking traced through SRS-MEAL-002, SDD-POL-004, RA-004, and TV-MEAL-002: persisted qualifying-glucose step, 12/13 blind-step boundary, fresh-CGM/exact-BG exceptions, coordinator pre-persistence backstop, no algorithm/pump activity, and explicit no-delivery copy. |
| 1.51 | 2026-07-22 | BionicLoop engineering | Connected active-delivery meal messaging traced through SRS-MEAL-002, SDD-POL-004, RA-004, and TV-MEAL-002: live .delivering status outranks pending-attribution reconnect copy; idle unresolved attribution remains blocked and unchanged. |
| 1.52 | 2026-07-22 | BionicLoop engineering | Pending-BG open-composer publication-race closure traced through SRS-MEAL-006, SDD-POL-004, RA-004, and TV-MEAL-007: qualifying-glucose publication, not an intermediate executed-step checkpoint, ends the transient wait; qualifying-glucose and pump-status changes trigger revalidation; connected delivery replaces stale backup-basal guidance. |
| 1.53 | 2026-07-24 | BionicLoop engineering | Pregnancy Temporary Target traced through SRS-CLIN-016/017 and SRS-LOG-013, SDD-CLIN-001/002 and SDD-LOG-001, RA-022, and TV-CLIN-017/018 plus TV-LOG-013, with app/core/UI/Scout working evidence and physical/live/formal promotion explicitly pending. |
| 1.54 | 2026-07-24 | BionicLoop engineering | Traced New Participant Reset concurrency and full-wipe closure through SRS-CLIN-014, SDD-CLIN-001/002, RA-019, and TV-CLIN-015: transport quiescence/timeout, durable erase failure rollback, live guard recheck, arm exclusion, and complete outgoing Temporary Target removal. Clarified that same-participant/session reset emits Temporary Target lifecycle evidence, while New Participant Reset erases outgoing identity and pending lifecycle state without a new outgoing-participant event. |
| 1.55 | 2026-07-30 | BionicLoop engineering | Extended RA-010/RA-011 trace coverage for the relocated existing Pod suspend/resume control, duplicate Pod Settings suppression, disabled unavailable/transitional states, unchanged reminder-only behavior, and direct suspend-alert navigation/copy. |
| 1.56 | 2026-07-30 | BionicLoop engineering | Recorded deferred-scope SRS-SEC-009 working evidence for persistent signed-out login recovery across Home, Alert Center, Account & Session, and notification routing without local algorithm-session interruption. |
| 1.57 | 2026-07-30 | BionicLoop engineering | Added Temporary Target draft-loss, selector-state, Settings-order, and unrelated-copy-removal working evidence to the SRS-CLIN-016 / RA-022 / TV-CLIN-017 trace. |
| 1.58 | 2026-07-30 | BionicLoop engineering | Added persistent Home Manual BG/Meal action placement and expanded-alert scrolling evidence to the SRS-UI-002 / SDD-POL-019 / RA-010 / TV-UI-005 trace. |
| 1.59 | 2026-07-30 | BionicLoop engineering | Traced SRS-LOG-012 permanent-rejection evidence through SDD-LOG-001, RA-008/RA-009, and TV-LOG-012: structured failed-permanent state and Scout gap retained, generic participant alert retired and migrated away, Subject ID Conflict remains specific, and 429 remains retryable. |
| 1.60 | 2026-07-30 | BionicLoop engineering | Traced the suspend-ended direct Resume Insulin action and exact 15-minute safety-critical escalation through SRS-CLIN-016, SDD-CLIN-002/SDD-POL-008, RA-011, and TV-CLIN-017/TV-ALERT-009, including duplicate-command suppression, retryable failure, pump-confirmed clearing, relaunch recovery, and fresh escalation notification. |
| 1.61 | 2026-07-30 | BionicLoop engineering | Traced suspended-meal incident closure through SRS-MEAL-002/SRS-PUMP-010/SRS-UI-002, SDD-POL-004/029, RA-004/017, and TV-MEAL-002/TV-PUMP-009, including idle-only preflight, immediate resume revalidation, and blocked-command cache invalidation. |
| 1.62 | 2026-07-30 | BionicLoop engineering | Added RA-023 trace for explicit/persistent G7 replacement acquisition, staleness non-adoption, ten-minute guidance, and durably deduplicated stall/adoption telemetry through SRS-CGM-006/SRS-ALERT-020/SRS-LOG-014, SDD-CGM-002, and TV-CGM-006/TV-ALERT-019/TV-LOG-014. |
| 1.63 | 2026-07-31 | BionicLoop engineering | Updated RA-015/SRS-ALERT-014/SDD-POL-022/TV-ALERT-013 trace for accurate suspension and fallback-recovery interruption diagnosis, stale blocker clearing, and stronger Home alert precedence; extended RA-019/SRS-CLIN-014/SDD-CLIN-001/TV-CLIN-015 reset trace for asynchronous G7 state isolation. |
| 1.64 | 2026-08-06 | BionicLoop engineering | Extended the RA-008 / SRS-LOG-001 / SDD-LOG-001 / TV-LOG-001 trace with Recent Dose Steps fingerstick provenance, exact value display, and concurrent CGM retention working evidence. |
| 1.65 | 2026-08-11 | BionicLoop engineering | Added reference-host total-insulin command trace through RA-014, SRS-ALG-009, SDD-ALG-001, and TV-ALG-012 after field telemetry exposed meal-step basal omission and ~I reconciliation rejection. |
| 1.66 | 2026-08-11 | BionicLoop engineering | Aligned RA-013 trace/evidence with the initial-configuration unlock exception and later-edit lock boundary; removed obsolete feature-branch labels from implemented RA-009/020/021 status notes. |
| 1.67 | 2026-08-13 | BionicLoop engineering | Extended the RA-009 / SRS-LOG-012 / SDD-LOG-001 / TV-LOG-012 trace for the field telemetry backlog incident and its update-safe incremental spool, retained-first drain, aggregate chatter-loss evidence, producer deduplication, and passive health controls. |
| 1.68 | 2026-08-17 | BionicLoop engineering | Extended RA-009 / SRS-LOG-001/012 / SDD-LOG-001 / TV-LOG-001/012 trace for complete active-session step evidence and loss-avoidant SQLite/batch telemetry recovery. |
| 1.69 | 2026-08-20 | BionicLoop engineering | Added SRS-BG-013 / TV-BG-013 trace for the persisted pending-to-used fingerstick chart transition, evidence-only fill, timestamp stability, and deduplication. |
| 1.70 | 2026-08-20 | BionicLoop engineering | Added RA-024 / SRS-LOG-015 / SDD-LOG-001 / TV-LOG-015 trace for clinical-gated, epoch-session-scoped, bounded-snapshot legacy Algo2015 recovery export; extended RA-009 export-security trace. |
| 1.71 | 2026-08-20 | BionicLoop engineering | Extended TV-LOG-015 working trace with the stable single-sheet export-flow regression that prevents picker/alert/share presentation overlap. |
| 1.72 | 2026-08-20 | BionicLoop engineering | Replaced the failed Settings presentation trace with a combined CSV/Algo2015 recovery ZIP delivered through the existing Recent Dose Steps ShareLink, including exact-session and CSV-only mismatch controls. |
| 1.73 | 2026-08-20 | BionicLoop engineering | Extended RA-015 / SRS-ALERT-014 / SDD-POL-022 / TV-ALERT-013 trace for status-refresh-only transition from stale pump-unavailable copy to proven idle-Pod recovery guidance. |
| 1.74 | 2026-08-20 | BionicLoop engineering | Extended RA-010 / SRS-UI-008 / SDD-POL-019 / TV-UI-010 trace for discrete point-only CGM rendering without connector stroke or connected area fill. |
| 1.75 | 2026-08-21 | BionicLoop engineering | Recorded exact-tag formal execution for STR-ALG-001, STR-AUTO-001, STR-SIM-001, and STR-SEC-001; added the authoritative freeze-execution overlay and retained the historical row narratives pending sponsor disposition. |
| 1.76 | 2026-08-21 | BionicLoop engineering | Replaced the conflicting exact-freeze overlay plus superseded July matrix with one canonical current 24-row matrix. Exact-freeze evidence and open dispositions now appear on every row; historical candidate states remain in controlled document history. |
| 1.77 | 2026-08-21 | BionicLoop engineering | Added the later controlled CryptoSwift 1.10 source candidate and its working dependency/crypto/core/app/security verification to the RA-009 supporting evidence posture. Preserved all exact-freeze mappings and kept CYBER-DEV-001, formal-evidence disposition, archive identity, and sponsor approval open. |
| 1.78 | 2026-08-25 | BionicLoop engineering | Recorded Camille Powe, MD's written confirmation of 0.01 U schedule-weighted fallback allocation with total conservation, fallback activation when CGM freshness cannot be established, and the 50...500 lb participant weight range with the 20...230 kg algorithm rail. Clinical policy is closed. No trace link, execution result, or product behavior changed. |
| 1.79 | 2026-08-25 | BionicLoop engineering | Added controlled companion evidence closing ALG-DEV-SA-006, AUTO-DEV-001, and AUTO-DEV-002. The exact-freeze static-analysis/linkage companion passed 6/6; the corrected serial UI companion passed 44/44. Original execution records remain unchanged. No requirement, product behavior, hazard control, or risk score changed. |
| 1.80 | 2026-08-27 | BionicLoop engineering | Recorded Camille Powe, MD's approval of seven software/IDE statements: first-step Dexcom requirement, non-synthesized CGM-gap handling, investigational Clinical Settings access, supportive Scout scope with official study sources, no separate formal hardware-validation claim, no separate formal participant usability-study claim, and protocol correction for the distinct fingerstick mode. Updated current dispositions without changing requirements, design, tests, formal results, hazards, controls, or risk scores. |
| 1.81 | 2026-08-27 | BionicLoop engineering | Replaced internal work labels, test-device shorthand, and informal evaluation terminology with direct descriptions of the traced controls and evidence. No trace link, execution result, or product behavior changed. |
| 1.82 | 2026-08-28 | BionicLoop engineering | Added SRS requirement-family child-clause traceability rules and explicit deferred/retired requirement dispositions, including the previously implicit SRS-SEC-004..008 entries. No requirement, design, test, evidence, risk, or product behavior changed. |
| 1.83 | 2026-08-28 | BionicLoop engineering | Added explicit dispositions for all supporting SDD elements and deferred security verification IDs, closing documentation-only orphan gaps found during the technical-appendix review. No requirement, design, test, evidence, risk, or product behavior changed. |
| 1.84 | 2026-08-28 | Software Developer | Added explicit current-state mappings for TV-SIM-POD-001..004, which passed in the exact-freeze simulation lane but were previously present only through a historical wildcard reference. No test, evidence, risk, or product behavior changed. |
| 1.85 | 2026-09-03 | Software Developer | Added the post-freeze RA-023 adversarial-review disposition to the current trace: exact-freeze app-integration evidence remains passed, while CGM-screen setup reentry, concurrent candidates, automatic-trigger isolation, and first-reading use remain unverified under D06. No requirement, test result, product behavior, hazard score, or formal evidence classification changed. |
| 1.86 | 2026-09-03 | Software Developer | Aligned Build 843 and CYBER-DEV-001 status with the final designation, removed retired/deferred controls from active risk rows, and replaced internal work labels in the current trace. No requirement, test result, product behavior, or hazard score changed. |
Current Exact-Freeze Evidence Boundary¶
This matrix is the canonical current traceability view for the immutable 2026-08-21 engineering freeze. All 24 IDE-scope risk-analysis rows have exact-freeze execution evidence mapped. Execution completion does not constitute sponsor-designated organizational approval, residual-risk acceptance, or approval of a physical-device claim. Working evidence remains support-only unless accepted through the sponsor-approved evidence process.
Primary exact-freeze evidence:
Evidence/Formal/STR-ALG-001/2026-08-21-ide-freeze-alg-baseline-r2/Evidence/Formal/STR-AUTO-001/2026-08-21-ide-freeze-auto-baseline-r2/Evidence/Formal/STR-SIM-001/2026-08-21-101509-14034-ide-freeze-sim-baseline/Evidence/Formal/STR-SEC-001/2026-08-21-ide-freeze-tv-sec-001/- Archive-matching CryptoSwift companion:
Evidence/Formal/STR-SEC-001/2026-08-21-ide-freeze-cryptoswift-1.9-companion/ - Build 843 controlled CryptoSwift 1.10 verification:
Cybersecurity_CryptoSwift_1_10_Candidate_Verification.md
Superseded candidate states and former working-evidence narratives remain in controlled document and source-control history; they are not current status.
SRS Requirement-Control Traceability¶
The SRS uses stable parent IDs. For a compound requirement family, each
normative shall or shall not occurrence is addressed as the parent ID plus
its two-digit textual sequence (for example, SRS-PUMP-010.01). Every child
clause inherits the parent family's SDD, RA, TV/STP, and evidence links in the
canonical matrix. A parent-family disposition applies only when every
applicable child clause has objective evidence or an explicit documented
disposition; a passing subset cannot close the parent.
Deferred and Retired Requirements¶
These identifiers are intentionally outside the frozen-baseline execution claim. They remain represented here so every SRS identifier has a traceable applicability disposition.
| Requirement | Applicability | Design / verification disposition | Current disposition |
|---|---|---|---|
SRS-BG-008 |
Deferred | SDD-BG-001; TV-BG-007 |
Step-0 fingerstick rescue is excluded; current step-0 behavior remains governed by SRS-BG-012. Scope re-entry requires SRS/SDD/RA/TV review. |
SRS-LOG-010 |
Retired | Historical SDD-LOG-001; no active verification claim |
Build-baked cloud-log profile was removed before participant release. Identifier is retained and shall not be reused. |
SRS-SEC-003 |
Deferred | SDD-AUTH-001; TV-SEC-003 |
Protected cloud API authentication is outside the claimed package; supportive Scout use is governed by SRS-SEC-001. |
SRS-SEC-004 |
Deferred | SDD-AUTH-001; TV-SEC-004 |
Multi-provider onboarding policy is outside the claimed package. |
SRS-SEC-005 |
Deferred | SDD-AUTH-001; TV-SEC-005 |
Cloud role/scope authorization enforcement is outside the claimed package. |
SRS-SEC-006 |
Deferred | SDD-AUTH-001, SDD-POL-015; TV-SEC-003..005 |
Protected-cloud authentication/session failure behavior is outside the claimed package. |
SRS-SEC-007 |
Deferred | SDD-AUTH-002; TV-SEC-006 |
Cognito password recovery is outside the claimed package; implementation or working evidence does not promote it. |
SRS-SEC-008 |
Deferred | SDD-AUTH-001, SDD-POL-016; TV-SEC-007 |
Authenticated launch session restoration is outside the claimed package; implementation or working evidence does not promote it. |
SRS-SEC-009 |
Deferred | SDD-POL-015, SDD-POL-016; TV-SEC-008 |
Signed-out local Home bypass/login recovery is outside the claimed package; existing working evidence remains support-only. |
Supporting Design-Element Disposition¶
The canonical risk rows list design controls most directly tied to each hazard. The following active supporting elements are not repeated on individual risk rows but remain traced to the requirement families shown. Deferred authentication elements remain implementation context and do not create a closure claim.
| Design element | Applicability | Trace disposition |
|---|---|---|
SDD-APP-002 |
Active | Runtime persistence support for SRS-RUN-002 and SRS-STATE-001..005 |
SDD-APP-004 |
Active | Pump signal-loss and alert-state support for SRS-PUMP-004 and SRS-ALERT-001..011 |
SDD-APP-005 |
Active | App-layer telemetry support for SRS-LOG-001..015 |
SDD-APP-006 |
Active | Work-execution sequencing support for SRS-RUN-001..003 |
SDD-CFG-001 |
Active | Configuration/dependency control supporting SRS-SEC-001..002 and the Cybersecurity Plan |
SDD-CORE-001 |
Active | Core due-step/input/algorithm/command orchestration supporting runtime, BG, meal, pump, and state requirements |
SDD-SIM-001 |
Verification support | Simulation architecture supporting TV-SIM-001..005; not a production risk control |
SDD-AUTH-001 |
Deferred context | Implementation context for SRS-SEC-003..006 and SRS-SEC-008; no current closure claim |
SDD-AUTH-002 |
Deferred context | Implementation context for SRS-SEC-007; no current closure claim |
SDD-POL-015 |
Deferred context | Authentication-failure policy context for SRS-SEC-006 and SRS-SEC-009; no current closure claim |
SDD-POL-016 |
Deferred context | Session-restore policy context for SRS-SEC-008..009; no current closure claim |
Supporting and Deferred Verification-Element Disposition¶
The exact-freeze simulation lane passed the four pod-simulation verification
elements below. They supplement the verification links in the canonical risk
rows and share the controlled STR-SIM-001 evidence locator.
| Verification element | Applicability | Trace disposition |
|---|---|---|
TV-SIM-POD-001 |
Active verification support | Stateful pod-ledger, mask, expiry, and replacement-identity coverage supporting RA-003, RA-015, and RA-017 |
TV-SIM-POD-002 |
Active verification support | Persisted issued-dose restoration and exactly-once replay coverage supporting RA-017 |
TV-SIM-POD-003 |
Active verification support | Meal/correction and fallback-total partitioning coverage supporting RA-017 and RA-020 |
TV-SIM-POD-004 |
Active verification support | High-risk relaunch, replacement-pod, fallback, meal, and evidence-preservation scenarios supporting RA-003, RA-004, RA-017, and RA-020 |
TV-SEC-002 is deferred because Scout is approved as a supportive service,
not an official outcome source or local dosing dependency. It remains the
predefined verification method if that boundary changes. TV-SEC-003..008
are dispositioned with their deferred requirements in the table above. No
deferred verification ID is represented as executed or accepted evidence.
Canonical IDE-Scope Matrix¶
RA-001¶
- Requirements: SRS-RUN-001, SRS-RUN-002, SRS-RUN-003
- Design: SDD-POL-001, SDD-APP-003
- Verification: TV-RUN-001, TV-RUN-002, TV-RUN-003, TV-SIM-001
- Exact-freeze evidence:
Evidence/Formal/STR-AUTO-001/2026-08-21-ide-freeze-auto-baseline-r2/;Evidence/Formal/STR-SIM-001/2026-08-21-101509-14034-ide-freeze-sim-baseline/ - Execution state: AUTO unit pass + SIM pass
- Remaining disposition: Sponsor trace acceptance/signature
RA-002¶
- Requirements: SRS-CGM-001, SRS-CGM-002, SRS-CGM-003, SRS-CGM-004
- Design: SDD-POL-002, SDD-CGM-001
- Verification: TV-CGM-001, TV-CGM-002, TV-CGM-003, TV-CGM-004, TV-SIM-002
- Exact-freeze evidence:
Evidence/Formal/STR-AUTO-001/2026-08-21-ide-freeze-auto-baseline-r2/;Evidence/Formal/STR-SIM-001/2026-08-21-101509-14034-ide-freeze-sim-baseline/ - Execution state: AUTO unit pass + SIM pass
- Remaining disposition: Separate formal G7 hardware-validation claim not retained; sponsor trace acceptance remains
RA-003¶
- Requirements: SRS-PUMP-001, SRS-PUMP-002, SRS-PUMP-005, SRS-PUMP-006, SRS-PUMP-007, SRS-PUMP-008, SRS-PUMP-009, SRS-RUN-006, SRS-RUN-007, SRS-STATE-005
- Design: SDD-POL-003, SDD-POL-028, SDD-PUMP-001, SDD-DATA-003
- Verification: TV-PUMP-001, TV-PUMP-002, TV-PUMP-005, TV-PUMP-006, TV-PUMP-007, TV-PUMP-008, TV-STATE-005, TV-RUN-008, TV-SIM-003
- Exact-freeze evidence:
Evidence/Formal/STR-AUTO-001/2026-08-21-ide-freeze-auto-baseline-r2/;Evidence/Formal/STR-SIM-001/2026-08-21-101509-14034-ide-freeze-sim-baseline/ - Execution state: AUTO unit pass + SIM/pod-sim pass
- Remaining disposition: Separate formal hardware-validation claim not retained; sponsor trace acceptance remains
RA-004¶
- Requirements: SRS-MEAL-001, SRS-MEAL-002, SRS-MEAL-003, SRS-MEAL-004, SRS-MEAL-005, SRS-MEAL-006
- Design: SDD-POL-004, SDD-APP-001
- Verification: TV-MEAL-001, TV-MEAL-002, TV-MEAL-003, TV-MEAL-004, TV-MEAL-005, TV-MEAL-006, TV-MEAL-007, TV-SIM-004
- Exact-freeze evidence:
Evidence/Formal/STR-AUTO-001/2026-08-21-ide-freeze-auto-baseline-r2/;Evidence/Formal/STR-SIM-001/2026-08-21-101509-14034-ide-freeze-sim-baseline/ - Execution state: AUTO unit pass + SIM/pod-sim pass
- Remaining disposition: Separate formal physical meal claim not retained; sponsor trace acceptance remains
RA-005¶
- Requirements: SRS-PUMP-003, SRS-LOG-001
- Design: SDD-PUMP-001, SDD-LOG-001
- Verification: TV-PUMP-003, TV-LOG-001
- Exact-freeze evidence:
Evidence/Formal/STR-AUTO-001/2026-08-21-ide-freeze-auto-baseline-r2/;Evidence/Formal/STR-SIM-001/2026-08-21-101509-14034-ide-freeze-sim-baseline/ - Execution state: AUTO unit pass + SIM/pod-sim pass
- Remaining disposition: Sponsor trace acceptance/signature
RA-006¶
- Requirements: SRS-STATE-001, SRS-STATE-002, SRS-STATE-003, SRS-STATE-004, SRS-STATE-005
- Design: SDD-DATA-001, SDD-DATA-002, SDD-DATA-003, SDD-DATA-004, SDD-POL-005, SDD-POL-028, SDD-PUMP-001
- Verification: TV-STATE-001, TV-STATE-002, TV-STATE-003, TV-STATE-004, TV-STATE-005
- Exact-freeze evidence:
Evidence/Formal/STR-AUTO-001/2026-08-21-ide-freeze-auto-baseline-r2/;Evidence/Formal/STR-SIM-001/2026-08-21-101509-14034-ide-freeze-sim-baseline/ - Execution state: AUTO unit pass + SIM/pod-sim pass
- Remaining disposition: Separate formal physical relaunch/reset claim not retained; sponsor trace acceptance remains
RA-007¶
- Requirements: SRS-PUMP-004, SRS-PUMP-005
- Design: SDD-PUMP-001
- Verification: TV-PUMP-004, TV-PUMP-005
- Exact-freeze evidence:
Evidence/Formal/STR-AUTO-001/2026-08-21-ide-freeze-auto-baseline-r2/ - Execution state: Automated support exists; no hardware STR executed
- Remaining disposition:
STP-HW-001not retained as a separate formal claim; sponsor trace acceptance remains
RA-008¶
- Requirements: SRS-LOG-001, SRS-LOG-002, SRS-LOG-003, SRS-LOG-004, SRS-LOG-005, SRS-LOG-006, SRS-LOG-007, SRS-LOG-008, SRS-LOG-009, SRS-LOG-012
- Design: SDD-LOG-001, SDD-POL-017, SDD-POL-018, SDD-POL-024, SDD-POL-025, SDD-APP-007, SDD-DATA-003
- Verification: TV-LOG-001, TV-LOG-002, TV-LOG-003, TV-LOG-004, TV-LOG-005, TV-LOG-006, TV-LOG-007, TV-LOG-008, TV-LOG-009, TV-LOG-012
- Exact-freeze evidence:
Evidence/Formal/STR-AUTO-001/2026-08-21-ide-freeze-auto-baseline-r2/;Evidence/Formal/STR-SEC-001/2026-08-21-ide-freeze-tv-sec-001/ - Execution state: AUTO unit pass + SEC local-control pass
- Remaining disposition: Live retained-sequence observation if retained
RA-009¶
- Requirements: SRS-SEC-001, SRS-SEC-002, SRS-LOG-012, SRS-LOG-015
- Design: SDD-LOG-001 + CybersecurityPlan.md
- Verification: TV-SEC-001, TV-LOG-012, TV-LOG-015
- Exact-freeze evidence:
Evidence/Formal/STR-SEC-001/2026-08-21-ide-freeze-tv-sec-001/;Evidence/Formal/STR-SEC-001/2026-08-21-ide-freeze-cryptoswift-1.9-companion/ - Execution state: SEC local-control pass (68/68)
- Disposition: Verification evidence and traceability accepted under
D08; cybersecurity scope and controls accepted underD09. Scout/live-sequence and physical ZIP observations remain corroborating/supporting evidence.
RA-010¶
- Requirements: SRS-UI-001, SRS-UI-002, SRS-UI-003, SRS-UI-004, SRS-UI-005, SRS-UI-006, SRS-UI-007, SRS-UI-008, SRS-UI-009, SRS-CLIN-016, SRS-VAL-001, SRS-BG-001
- Design: SDD-POL-006, SDD-POL-007, SDD-POL-009, SDD-POL-014, SDD-POL-018, SDD-POL-019, SDD-APP-008, SDD-CLIN-002
- Verification: TV-UI-001, TV-UI-002, TV-UI-003, TV-UI-004, TV-UI-005, TV-UI-006, TV-UI-007, TV-UI-008, TV-UI-009, TV-UI-010, TV-UI-011, TV-CLIN-017
- Exact-freeze evidence:
Evidence/Formal/STR-AUTO-001/2026-08-21-ide-freeze-auto-baseline-r2/;Evidence/Formal/STR-AUTO-001/2026-08-25-ui-harness-companion/ - Execution state: AUTO unit pass; corrected serial UI companion 44/44;
AUTO-DEV-002closed - Remaining disposition: Separate formal physical visual claim not retained; sponsor trace acceptance remains
RA-011¶
- Requirements: SRS-ALERT-001, SRS-ALERT-002, SRS-ALERT-003, SRS-ALERT-004, SRS-ALERT-005, SRS-ALERT-006, SRS-ALERT-007, SRS-ALERT-008, SRS-ALERT-009, SRS-ALERT-010, SRS-ALERT-011, SRS-ALERT-012, SRS-ALERT-015, SRS-ALERT-016, SRS-ALERT-017, SRS-ALERT-018, SRS-ALERT-019
- Design: SDD-ALERT-001, SDD-POL-008, SDD-POL-026, SDD-DATA-005
- Verification: TV-ALERT-001, TV-ALERT-002, TV-ALERT-003, TV-ALERT-004, TV-ALERT-005, TV-ALERT-006, TV-ALERT-007, TV-ALERT-008, TV-ALERT-009, TV-ALERT-010, TV-ALERT-011, TV-ALERT-014, TV-ALERT-015, TV-ALERT-016, TV-ALERT-017, TV-ALERT-018, TV-SIM-005
- Exact-freeze evidence:
Evidence/Formal/STR-AUTO-001/2026-08-21-ide-freeze-auto-baseline-r2/;Evidence/Formal/STR-SIM-001/2026-08-21-101509-14034-ide-freeze-sim-baseline/ - Execution state: AUTO unit pass + SIM alert pass
- Remaining disposition: Supplemental alert drill only if retained
RA-012¶
- Requirements: SRS-BG-001, SRS-BG-002, SRS-BG-003, SRS-BG-004, SRS-BG-005, SRS-BG-006, SRS-BG-007, SRS-BG-009, SRS-BG-010, SRS-BG-011, SRS-BG-012, SRS-BG-013
- Design: SDD-BG-001, SDD-POL-010, SDD-POL-011, SDD-POL-012, SDD-LOG-001
- Verification: TV-BG-001, TV-BG-002, TV-BG-003, TV-BG-004, TV-BG-005, TV-BG-006, TV-BG-008, TV-BG-009, TV-BG-010, TV-BG-011, TV-BG-012, TV-BG-013
- Exact-freeze evidence:
Evidence/Formal/STR-AUTO-001/2026-08-21-ide-freeze-auto-baseline-r2/;Evidence/Formal/STR-SIM-001/2026-08-21-101509-14034-ide-freeze-sim-baseline/ - Execution state: AUTO unit pass + SIM pass
- Remaining disposition: Sponsor trace acceptance/signature
RA-013¶
- Requirements: SRS-CLIN-001, SRS-CLIN-002, SRS-CLIN-003, SRS-CLIN-004, SRS-CLIN-005, SRS-CLIN-006, SRS-CLIN-007, SRS-CLIN-008, SRS-CLIN-009, SRS-CLIN-010, SRS-CLIN-011, SRS-CLIN-012, SRS-CLIN-013, SRS-CLIN-014, SRS-VAL-001, SRS-LOG-008
- Design: SDD-CLIN-001, SDD-POL-013, SDD-POL-017, SDD-POL-025, SDD-DATA-006
- Verification: TV-CLIN-001, TV-CLIN-002, TV-CLIN-003, TV-CLIN-004, TV-CLIN-005, TV-CLIN-006, TV-CLIN-007, TV-CLIN-008, TV-CLIN-009, TV-CLIN-010, TV-CLIN-011, TV-CLIN-012, TV-CLIN-013, TV-CLIN-014, TV-CLIN-015, TV-LOG-008
- Exact-freeze evidence:
Evidence/Formal/STR-AUTO-001/2026-08-21-ide-freeze-auto-baseline-r2/;Evidence/Formal/STR-AUTO-001/2026-08-25-ui-harness-companion/ - Execution state: AUTO unit pass; corrected serial UI companion 44/44;
AUTO-DEV-001closed - Remaining disposition: Unlock operations record
RA-014¶
- Requirements: SRS-ALG-001, SRS-ALG-002, SRS-ALG-003, SRS-ALG-004, SRS-ALG-005, SRS-ALG-006, SRS-ALG-007, SRS-ALG-008, SRS-ALG-009
- Design: SDD-ALG-001, SDD-QA-001
- Verification: TV-ALG-001, TV-ALG-002, TV-ALG-003, TV-ALG-004, TV-ALG-005, TV-ALG-006, TV-ALG-007, TV-ALG-008, TV-ALG-009, TV-ALG-010, TV-ALG-011, TV-ALG-012
- Exact-freeze evidence:
Evidence/Formal/STR-ALG-001/2026-08-21-ide-freeze-alg-baseline-r2/;Evidence/Formal/STR-ALG-001/2026-08-25-sa-006-linkage-companion/ - Execution state: ALG behavioral pass; exact-freeze static-analysis/linkage companion 6/6;
ALG-DEV-SA-006closed - Remaining disposition: None for
ALG-DEV-SA-006
RA-015¶
- Requirements: SRS-CGM-005, SRS-RUN-004, SRS-RUN-005, SRS-ALERT-013, SRS-ALERT-014, SRS-UI-001, SRS-UI-002
- Design: SDD-POL-020, SDD-POL-021, SDD-POL-022, SDD-POL-008, SDD-APP-003, SDD-CGM-001
- Verification: TV-CGM-005, TV-RUN-004, TV-RUN-005, TV-RUN-006, TV-RUN-007, TV-ALERT-012, TV-ALERT-013, TV-UI-001
- Exact-freeze evidence:
Evidence/Formal/STR-AUTO-001/2026-08-21-ide-freeze-auto-baseline-r2/;Evidence/Formal/STR-SIM-001/2026-08-21-101509-14034-ide-freeze-sim-baseline/ - Execution state: AUTO unit pass + SIM pass
- Remaining disposition: Separate formal hardware-recovery claim not retained; sponsor trace acceptance remains
RA-016¶
- Requirements: SRS-MEAL-007, SRS-MEAL-008, SRS-MEAL-009, SRS-MEAL-010, SRS-MEAL-011, SRS-MEAL-012, SRS-LOG-007, SRS-UI-002
- Design: SDD-POL-023, SDD-POL-024, SDD-POL-027, SDD-POL-029, SDD-APP-001, SDD-LOG-001
- Verification: TV-MEAL-008, TV-MEAL-009, TV-MEAL-010, TV-MEAL-011, TV-MEAL-012, TV-MEAL-013, TV-LOG-007, TV-PUMP-003
- Exact-freeze evidence:
Evidence/Formal/STR-AUTO-001/2026-08-21-ide-freeze-auto-baseline-r2/;Evidence/Formal/STR-SIM-001/2026-08-21-101509-14034-ide-freeze-sim-baseline/ - Execution state: AUTO unit pass + SIM/pod-sim pass
- Remaining disposition: Separate formal physical meal-lifecycle claim not retained; sponsor trace acceptance remains
RA-017¶
- Requirements: SRS-PUMP-010, SRS-PUMP-011, SRS-MEAL-012, SRS-STATE-004, SRS-STATE-005, SRS-LOG-001
- Design: SDD-POL-029, SDD-PUMP-001, SDD-DATA-003, SDD-LOG-001
- Verification: TV-PUMP-009, TV-PUMP-010, TV-MEAL-013, TV-STATE-004, TV-STATE-005, TV-LOG-001
- Exact-freeze evidence:
Evidence/Formal/STR-AUTO-001/2026-08-21-ide-freeze-auto-baseline-r2/;Evidence/Formal/STR-SIM-001/2026-08-21-101509-14034-ide-freeze-sim-baseline/ - Execution state: AUTO unit pass + SIM/pod-sim pass
- Remaining disposition: Separate formal physical canceled-partial claim not retained; sponsor residual-risk/trace acceptance remains
RA-018¶
- Requirements: SRS-ALERT-019, SRS-RUN-007, SRS-ALG-008, SRS-OUTAGE-001, SRS-OUTAGE-002, SRS-OUTAGE-003, SRS-OUTAGE-004, SRS-OUTAGE-005, SRS-OUTAGE-006
- Design: SDD-ALERT-001, SDD-ALG-001, SDD-PUMP-001, SDD-OUTAGE-001
- Verification: TV-ALERT-018, TV-ALG-004, TV-OUTAGE-001, TV-OUTAGE-002, TV-OUTAGE-003
- Exact-freeze evidence:
Evidence/Formal/STR-AUTO-001/2026-08-21-ide-freeze-auto-baseline-r2/;Evidence/Formal/STR-SIM-001/2026-08-21-101509-14034-ide-freeze-sim-baseline/;Evidence/Formal/STR-ALG-001/2026-08-21-ide-freeze-alg-baseline-r2/ - Execution state: AUTO unit pass + SIM/algo-sim pass
- Disposition: Residual risk accepted under
D07and traceability accepted underD08; no separate formal outage hardware claim is retained.
RA-019¶
- Requirements: SRS-CLIN-014
- Design: SDD-CLIN-001
- Verification: TV-CLIN-015
- Exact-freeze evidence:
Evidence/Formal/STR-AUTO-001/2026-08-21-ide-freeze-auto-baseline-r2/;Evidence/Formal/STR-SEC-001/2026-08-21-ide-freeze-tv-sec-001/ - Execution state: AUTO unit pass + SEC persistence support
- Remaining disposition: Sponsor trace acceptance/signature
RA-020¶
- Requirements: SRS-OUTAGE-006
- Design: SDD-OUTAGE-001
- Verification: TV-OUTAGE-002
- Exact-freeze evidence:
Evidence/Formal/STR-AUTO-001/2026-08-21-ide-freeze-auto-baseline-r2/;Evidence/Formal/STR-SIM-001/2026-08-21-101509-14034-ide-freeze-sim-baseline/;Evidence/Formal/STR-ALG-001/2026-08-21-ide-freeze-alg-baseline-r2/ - Execution state: AUTO unit pass + SIM/pod-sim/algo-sim pass
- Remaining disposition: Clinical quantization policy confirmed; sponsor-designated residual-risk/trace acceptance remains; separate formal hardware claim not retained
RA-021¶
- Requirements: SRS-CLIN-015
- Design: SDD-CLIN-001
- Verification: TV-CLIN-016
- Exact-freeze evidence:
Evidence/Formal/STR-AUTO-001/2026-08-21-ide-freeze-auto-baseline-r2/ - Execution state: AUTO unit pass
- Remaining disposition: Clinical weight range confirmed; sponsor-designated residual-risk/trace acceptance
RA-022¶
- Requirements: SRS-CLIN-016, SRS-CLIN-017, SRS-LOG-013, supporting SRS-RUN-007
- Design: SDD-CLIN-002, SDD-CLIN-001, SDD-LOG-001
- Verification: TV-CLIN-017, TV-CLIN-018, TV-LOG-013
- Exact-freeze evidence:
Evidence/Formal/STR-AUTO-001/2026-08-21-ide-freeze-auto-baseline-r2/ - Execution state: AUTO unit pass; UI target deviation does not involve Temporary Target tests
- Remaining disposition: Sponsor trace acceptance; lifecycle telemetry remains corroborating and separate formal physical evidence is not claimed
RA-023¶
- Requirements: SRS-CGM-006, SRS-ALERT-020, SRS-LOG-014
- Design: SDD-CGM-002
- Verification: TV-CGM-006, TV-ALERT-019, TV-LOG-014
- Exact-freeze evidence:
Evidence/Formal/STR-AUTO-001/2026-08-21-ide-freeze-auto-baseline-r2/ - Execution state: AUTO unit pass for the tested app-integration scope; the September 3 adversarial review identified untested implementation paths involving CGM-screen setup reentry, concurrent candidates, automatic-trigger isolation, and first-reading use
- Disposition:
D06accepts unchanged Build 843 for submission with the controlled multi-device exercise and finalRA-023disposition required before participant deployment. Separate formal multi-device hardware validation is not claimed, and live telemetry remains corroborating.
RA-024¶
- Requirements: SRS-LOG-015, SRS-SEC-001
- Design: SDD-LOG-001
- Verification: TV-LOG-015
- Exact-freeze evidence:
Evidence/Formal/STR-AUTO-001/2026-08-21-ide-freeze-auto-baseline-r2/;Evidence/Formal/STR-SEC-001/2026-08-21-ide-freeze-tv-sec-001/ - Execution state: AUTO unit pass + SEC recovery-export pass
- Remaining disposition: Sponsor trace acceptance; physical ZIP observation remains supporting evidence rather than a separate formal claim
Current Interpretation Rules¶
STP-ALG-001passed behaviorally; the exact-freeze 6/6 linkage companion closesALG-DEV-SA-006.STP-AUTO-001completed 997 app tests: 996 passed, one intentional IFU reference-table generation helper skip gated by an export directory, zero failures. The original UI run recorded 41 passes and three reproducible harness deviations; the corrected serial UI companion passed 44/44 and closesAUTO-DEV-001andAUTO-DEV-002.STP-SIM-001passed.TV-SEC-001passed 68/68 scoped controls for the exact freeze. Build 843 uses the controlled CryptoSwift 1.10.0 resolution and is the IDE submission build designated on 2026-09-03.CYBER-DEV-001is closed through the selected "designate and verify a new controlled-resolution build" path; evidence acceptance was recorded underD08andD09.- A separate formal hardware-validation study and supplemental physical/alert claims are not retained; real-Pod formative records remain supporting evidence under the 2026-08-27 clinical approval.
- Sponsor residual-risk approval, evidence acceptance, cybersecurity acceptance,
and controlled-document approval references are closed under
D07throughD09andD11. The three decisions recorded inIDE_Clinical_Policy_Confirmation_2026-08-21.mdand the seven decisions inEvidence/ClinicalPolicy/2026-08-27-software-ide-decisions/README.mdare complete.
Usage¶
For each controlled change:
- update affected
SRS-*,SDD-*,RA-*, andTV-*links - identify the controlled evidence bundle and execution result
- distinguish working evidence from formally promoted evidence
- record remaining Sponsor, Clinical/Regulatory, operator, or designated software-evidence approver disposition
- obtain the required reviewer and approver signatures before changing a row to accepted or closed