Skip to content

Requirements Traceability Matrix (RTM)

Status: Submission-candidate trace matrix (formal evidence promotion and freeze metadata pending) Version: 1.28 Owner: BionicLoop engineering Prepared by: BionicLoop engineering Reviewer: ____ Approver: ____ Decision date: ____ Effective date: ____ Baseline freeze SHA: ____ Last updated: 2026-06-23

Revision History

Version Date Author Summary of Changes
0.1 2026-04-05 Engineering Initial controlled RTM draft
0.9 2026-04-06 BionicLoop engineering Added handoff-ready metadata and refined RA-009 cybersecurity trace mapping for the software-only handoff package
0.91 2026-04-07 BionicLoop engineering Narrowed RA-009 to the current local-security claim set, aligned RA-013 and RA-015 evidence notes with the implemented baseline, and changed high-risk freeze blockers to Rerun needed status
0.92 2026-04-08 BionicLoop engineering Added masked offline-fallback maintenance/disarm trace links for the active feasibility branch
0.93 2026-04-08 BionicLoop engineering Clarified masked-fallback renewal-window, deferred-maintenance, and restore-context trace links for the active feasibility branch
0.94 2026-04-14 BionicLoop engineering Added trace notes for reconciliation-required blocked state after offline mask expiry
0.95 2026-04-14 BionicLoop engineering Added trace notes for reconnect restore/disarm retry and explicit fresh re-arm after successful masked-fallback recovery
0.96 2026-04-14 BionicLoop engineering Updated reconnect recovery trace notes for fresh-session auto-arm and preserved fallback review history after successful masked-fallback recovery
0.97 2026-04-14 BionicLoop engineering Tightened reconnect recovery trace notes so explicit reset/loop-off keeps the loop off after restore and recovery timing reflects restore completion
0.98 2026-04-14 BionicLoop engineering Updated reconnect recovery trace notes to show same-session unreconciled resume on the current due slot after successful masked-fallback restore
0.99 2026-04-15 BionicLoop engineering Added trace notes for modeled-vs-pump-reported fallback review, pod total-delivery baseline persistence, and pre-step missing-fallback arm behavior
1.00 2026-04-15 BionicLoop engineering Added trace notes for confirmed/corrected same-session basal-only replay, persisted replay-plan state, and replay-detail Recent Dose Steps coverage
1.01 2026-04-15 BionicLoop engineering Added trace notes for dedicated loop.fallback.event cloud telemetry emission and fallback-event payload verification for BionicScout contract support
1.02 2026-04-15 BionicLoop engineering Added trace notes for replayed-step propagation into local per-step telemetry / CSV export with explicit replay markers
1.03 2026-04-27 BionicLoop engineering Added trace notes that fallback replay requires pump-reported delivered-insulin delta and does not substitute modeled expected delivery when pump reconciliation is unavailable
1.04 2026-05-06 BionicLoop engineering Added trace notes for safety q5 nominal-basal profile persistence, four-bucket fallback schedule programming, schedule-aware exposure modeling, and fallback profile/schedule cloud telemetry
1.05 2026-06-02 BionicLoop engineering Updated trace notes for pump-delta fallback missed-step algorithm replay and repeated no-active-pod critical alert verification
1.06 2026-06-06 BionicLoop engineering Added trace notes for same-pod continuity replay gating, different/new pod no-replay continuation, pod-continuity telemetry, and explicit-operator-only session lifecycle
1.07 2026-06-08 BionicLoop engineering Added trace notes for persisted-schedule-weighted pump-delta replay allocation and zero-weight replay suppression
1.08 2026-06-10 BionicLoop engineering Added trace notes for current-step masked-fallback first-arm ordering before same-step pump command application
1.09 2026-06-11 BionicLoop engineering Clarified that confirmed/corrected fallback replay is bounded to fallback-active missed slots and excludes pre-activation disconnected gaps
1.10 2026-06-11 BionicLoop engineering Added trace notes for fresh-status pre-execution fallback maintenance gating, existing-mask remask-failure recovery, pending replay-plan cleanup, and cached-idle refresh-failure regression coverage
1.11 2026-06-12 BionicLoop engineering Added trace mapping for generalized issued-dose attribution and different/new-pod no-replay disposition
1.12 2026-06-15 BionicLoop engineering Updated issued-dose different/new-pod trace mapping to assumed-delivered attribution, nonblocking replacement-pod dosing, and deferred adaptation-forget question
1.13 2026-06-17 BionicLoop engineering Added trace notes for one-step algorithm/runtime cadence reconciliation before meal-step selection and live executed-step/request-step alignment with algorithm stepTime.
1.14 2026-06-18 BionicLoop engineering Added trace notes for fallback-only replay request-step attribution and evidence-gated issued-dose attribution clearing.
1.15 2026-06-18 BionicLoop engineering Clarified resolved issued-dose attribution when the dose precedes fallback-active replay: merge into the first fallback replay row rather than replaying pre-fallback disconnected slots.
1.16 2026-06-18 BionicLoop engineering Added trace notes for retired/expired/no-active-pod fallback recovery using assumed modeled fallback exposure when pump-counter reconciliation evidence is unrecoverable.
1.17 2026-06-23 BionicLoop engineering Added provisional pod-simulation scaffold trace note and TV-SIM-POD-* working coverage expectations.
1.18 2026-06-23 BionicLoop engineering Added first pod-simulation scenario slice for shared-invariant same-pod live attribution, replacement-pod assumed delivery, and schedule-weighted fallback replay coverage.
1.19 2026-06-23 BionicLoop engineering Expanded pod-simulation trace note for canceled and consecutive-canceled meal live attribution, user-escaped unavailable-pod assumed delivery, fallback-maintenance command blocking, and relaunch fallback replay with unavailable CGM.
1.20 2026-06-23 BionicLoop engineering Added explicit pod-simulation trace coverage for unresolved correction-only and basal-only assumed-delivered replacement-pod dosing.
1.21 2026-06-23 BionicLoop engineering Added pod-simulation trace coverage for ambiguous fallback restore without replay or modeled-dose injection.
1.22 2026-06-23 BionicLoop engineering Added pod-simulation trace coverage for assumed old-pod fallback replay, missing-status/nonreplayable fallback-plan clearing, and matching meal-progress cleanup after issued-dose evidence consumption.
1.23 2026-06-23 BionicLoop engineering Added pod-simulation trace coverage for reservoir-capped partial meal delivery feeding actual delivered units without replay or unresolved meal-progress state.
1.24 2026-06-23 BionicLoop engineering Added pod-simulation trace coverage for reservoir-capped fallback replay using observed pump delta instead of modeled exposure.
1.25 2026-06-23 BionicLoop engineering Added pod-simulation trace coverage for meal/fallback overlap partition replay with the meal dose merged into the first fallback-active replay row.
1.26 2026-06-23 BionicLoop engineering Added trace coverage for app recent-dose persistence/display of merged meal/fallback replay evidence source, disposition, request step, requested units, and delivered units.
1.27 2026-06-23 BionicLoop engineering Added trace coverage for local step CSV export of merged fallback replay evidence source, disposition, and failure-reason fields.
1.28 2026-06-23 BionicLoop engineering Added trace coverage for runtime cloud step-event emission of merged fallback replay evidence source, disposition, request-step, requested-unit, and delivered-unit fields.

This matrix links risk hazards, requirements, design elements, and verification artifacts.

Current fallback replay trace note: SRS-RUN-006, SRS-PUMP-006, SRS-PUMP-008, SRS-PUMP-009, and SRS-LOG-009 remain mapped to RA-003, RA-006, RA-008, SDD-PUMP-001, SDD-LOG-001, SDD-DATA-003, TV-RUN-008, TV-PUMP-008, TV-STATE-004, and TV-LOG-009. The active replay claim is explicitly limited to missed steps whose delivery interval overlaps confirmed or explicitly assumed fallback-active time; disconnected gaps before offline fallback activation are not replayed, while explicit 0 U rows remain allowed inside the fallback-active replay interval. Pump-counter fallback replay remains limited to credible same-pod confirmed/corrected evidence. The retired/expired/no-active-pod exception records persisted-schedule modeled exposure as assumed_delivered_per_clinical_policy only when the old pod can no longer provide connected pump-counter evidence, and UI/telemetry must preserve that assumed-vs-confirmed distinction. Fallback-only replay rows feed the replayed fallback basal amount into the replay step with the algorithm input request step set to the prior step (replayStep - 1, clamped at 0 for step 0); rows may clear pending issued-dose attribution only when they include matching resolved issued-dose evidence for the original request. If a resolved meal/correction issued dose predates the first fallback-active replay row, runtime merges the resolved issued-dose requested/delivered units into that first fallback replay row and does not create pre-fallback issued-dose-only replay rows. App recent-dose rows, local step CSV export, and runtime cloud step-event emission now preserve replay evidence source/disposition/failure-reason fields for merged fallback replay evidence. Current review-fix coverage adds fresh idle pump-status gating before pre-execution masked-fallback arm/renew/refresh maintenance, reconciliation-required recovery for existing-mask remask failures, single-use cleanup for invalid/not-required/stale pending replay plans, and a cached-idle/refresh-failure regression proving runtime does not trust stale pump state. General issued-dose attribution is tracked separately through SRS-PUMP-010, SDD-POL-029, RA-017, and TV-PUMP-009.

Issued-dose missing-identity trace note: missing pod identity remains a no-guess/no-replay condition except for the explicit SRS-MEAL-012 user-confirmed unavailable-pod escape. That path may consume assumed-delivered clinical-policy evidence without pod identity only when the request step, requested units, delivered-unit bounds, and non-active pump status match.

Current cadence trace note: SRS-RUN-002 remains mapped to RA-001, SDD-POL-001, TV-RUN-001, TV-RUN-002, and TV-SIM-001. Current working coverage adds StepCadencePolicyTests.testReconcileWithAlgorithmAdvancesRuntimeWhenAlgorithmAlreadyConsumedDueStep, LoopRuntimeCoordinatorMealExecutionTests.testMealAnnounceAlignsWithAlgorithmStepWhenRuntimeIsOneStepBehind, and LoopRuntimeCoordinatorCadenceExecutionTests.testDoWorkSkipsOrdinaryWakeAfterAlgorithmAlreadyConsumedDueStep, proving persisted runtime cadence advances to the algorithm-implied last executed step before meal-step selection or ordinary wake duplicate evaluation so live executedStep, pump request-step attribution, and algorithm input stepTime remain aligned without re-running an already consumed step.

Current pod-simulation trace note: provisional TV-SIM-POD-001..004 coverage extends STP-SIM-001 with a stateful test-only DASH pod ledger. The scaffold currently supports working evidence for bolus progress/cancel math, pending issued-dose restoration, fallback 0 U/hr mask expiry/renewal, pod expiry/replacement identity transitions, production-coordinator replay from simulated pump status, and the safety rule that meal/correction delivery completed before a fallback baseline is not subtracted from fallback pump-total delta. The first shared-invariant scenario slice adds canceled and consecutive-canceled meal evidence feeding subsequent meal announcements without replay or stale evidence reuse, same-pod completed-meal live attribution without replay, reservoir-capped partial meal delivery feeding actual delivered units without replay or unresolved meal-progress state, reservoir-capped fallback replay using observed pump delta instead of modeled exposure, meal/fallback overlap coordinator replay that partitions the pump delta and merges the meal dose into the first fallback-active replay row, different/new-pod and user-escaped unavailable-pod assumed-delivered replay without blocking replacement-pod live dosing, explicit unresolved correction-only and basal-only assumed-delivered replay when pod identity cannot be recovered and policy allows, replacement after an unresolved old-pod meal dose, lost final meal response before status refresh, stale cached idle rejection when fresh refresh fails, meal/fallback pump-delta partitioning, fallback-maintenance failure blocking the live bolus command before pod ledger delivery, stale fallback evidence suppression while disconnected, ambiguous fallback restore without replay or aggregate modeled fallback-dose injection into the live step, missing-status/nonreplayable fallback plan clearing without replay rows, assumed old-pod fallback replay with no replay pump commands before replacement-pod live dosing, and persisted-schedule-weighted fallback replay allocation only after the 0 U/hr mask expires, reservoir-capped fallback replay using observed pump delta instead of modeled exposure, relaunch fallback replay with unavailable CGM after step 0, and force-quit/relaunch restoration of in-flight meal delivery knowledge before the next CGM without creating a step-0 insulin artifact. Matching pending meal-progress state is also cleared, with correlated resolved telemetry, when issued-dose evidence is consumed on same-pod reconnect, fallback-merge replay, or user-escaped old-pod recovery. These rows support RA-003, RA-004, RA-006, RA-008, and RA-017 as working evidence only until the remaining POD-SIM-* matrix is implemented and formal artifacts are promoted.

Matrix

RA-ID SRS ID SDD ID Verification (TV-ID) Evidence (STR/Logs) Status
RA-001 SRS-RUN-001, SRS-RUN-002, SRS-RUN-003 SDD-POL-001, SDD-APP-003 TV-RUN-001, TV-RUN-002, TV-RUN-003, TV-SIM-001 Partial (Docs/Quality/Evidence/Working/STR-SIM-001/2026-02-19-h5-smoke/) In progress
RA-002 SRS-CGM-001, SRS-CGM-002, SRS-CGM-003, SRS-CGM-004 SDD-POL-002, SDD-CGM-001 TV-CGM-001, TV-CGM-002, TV-CGM-003, TV-CGM-004, TV-SIM-002 Partial (Docs/Quality/Evidence/Working/STR-SIM-001/2026-02-19-h5-smoke/) In progress
RA-003 SRS-PUMP-001, SRS-PUMP-002, SRS-PUMP-005, SRS-PUMP-006, SRS-PUMP-007, SRS-PUMP-008, SRS-PUMP-009, SRS-RUN-006, SRS-STATE-005 SDD-POL-003, SDD-POL-028, SDD-PUMP-001, SDD-DATA-003 TV-PUMP-001, TV-PUMP-002, TV-PUMP-005, TV-PUMP-006, TV-PUMP-007, TV-PUMP-008, TV-STATE-005, TV-RUN-008, TV-SIM-003 Partial (Docs/Quality/Evidence/Working/STR-SIM-001/2026-02-19-h5-smoke/; current branch feasibility verification: BionicLoopRuntimeEngineMaskedFallbackMaintenanceTests, BionicLoopRuntimeEngineMaskedFallbackUnacknowledgedTests, BionicLoopRuntimeEngineFallbackRecoveryInfrastructureTests, BionicLoopRuntimeEngineReconnectInfrastructureTests, BionicLoopRuntimeEngineSessionInfrastructureTests, BionicLoopRecentDoseTimelineTests, BionicLoopMealAnnouncementPersistenceRuntimeTests, BionicLoopMealAnnouncementRuntimeTests, BionicLoopRuntimeEnginePrePumpCommandMaintenanceTests, Q5NominalBasalProfileTests, FallbackBasalExposureReconcilerTests, FallbackBasalReplayPlannerTests, LoopRuntimeCoordinatorFallbackReplayTests, LoopRuntimeCoordinatorPumpAvailabilityExecutionTests, LoopRuntimeCoordinatorExecutionTelemetryTests, LoopRuntimeCoordinatorPumpCommandClassificationTests, and BionicLoopRuntimeEngineReconnectEvidenceTests, including arm-before-step behavior for missing fallback state, current-step masked-fallback first-arm ordering before the same step's pump command when the first fallback candidate is produced at step 0 or another first successful step, pre-command first-arm skip when refreshed pump status is unavailable/unknown, pre-execution fresh idle status deferral for arm/renew/refresh maintenance, clean bolus/unsafe-state first-arm block behavior that does not suppress the normal command, same-cycle post-execution first-arm retry suppression after a pre-command fallback event, recovery-required remask failure behavior including post-schedule mask/pump blocking and existing-mask renewal/refresh remask failures that suppress ordinary stepping before additional pod mutation, stale cached-idle refresh-failure command blocking, secondary/safety q5 nominal profile-derived four six-hour schedule programming, deferred bolus-blocked renewal classification, offline-expiry blocking plus reconnect restore/disarm retry, retired/no-active-pod assumed modeled fallback exposure recovery, schedule-aware modeled exposure, confirmed/corrected no-command missed-step primary/secondary algorithm replay with CGM=-1 and per-step pump delivery weighted by the persisted programmed fallback schedule only when credible same-pod pump-reported delivered-insulin delta spans the outage or the retired-pod assumption rule explicitly records modeled exposure as assumed delivered, single-use cleanup for stale/invalid/not-required pending replay plans, equal-rate / six-hour-window / partial-slot / midnight-wrap replay allocation tests, positive-delta zero-weight no-replay behavior, zero-delta zero-row replay behavior, different/new pod and unknown pod identity no-replay continuation, ambiguous/unverified recovery without delivery reconciliation, and basal-only modeled-vs-pump-reported reconnect evidence) In progress
RA-004 SRS-MEAL-001, SRS-MEAL-002, SRS-MEAL-003, SRS-MEAL-004, SRS-MEAL-005, SRS-MEAL-006 SDD-POL-004, SDD-APP-001 TV-MEAL-001, TV-MEAL-002, TV-MEAL-003, TV-MEAL-004, TV-MEAL-005, TV-MEAL-006, TV-MEAL-007, TV-SIM-004 Partial (BUG-001 real-device closure evidence 2026-02-11: Docs/Quality/Evidence/STR-BUG-001/2026-02-11-relaunch-meal/; simulation: Docs/Quality/Evidence/Working/STR-SIM-001/2026-02-19-h5-smoke/; current branch feasibility verification adds reconnect/recovery-required meal blocking in BionicLoopMealAnnouncementPersistenceRuntimeTests and BionicLoopMealAnnouncementRuntimeTests) In progress
RA-005 SRS-PUMP-003, SRS-LOG-001 SDD-PUMP-001, SDD-LOG-001 TV-PUMP-003, TV-LOG-001 Partial (LoopRuntimeCoordinatorPumpExecutionTests.testDoWorkFeedsBackRequestedAndDeliveredWhenBelowDashMinimumQuantum) In progress
RA-006 SRS-STATE-001, SRS-STATE-002, SRS-STATE-003, SRS-STATE-004, SRS-STATE-005 SDD-DATA-001, SDD-DATA-002, SDD-DATA-003, SDD-DATA-004, SDD-POL-005, SDD-POL-028, SDD-PUMP-001 TV-STATE-001, TV-STATE-002, TV-STATE-003, TV-STATE-004, TV-STATE-005 Partial (current branch feasibility verification includes recoverable reset/disarm restore-state coverage plus persisted offline-expiry and restore-failed reconnect-retry coverage in BionicLoopRuntimeEngineSessionInfrastructureTests, BionicLoopRuntimeEngineReconnectInfrastructureTests, BionicLoopMealAnnouncementPersistenceRuntimeTests, BionicLoopRuntimeEngineMaskedFallbackMaintenanceTests, Q5NominalBasalProfileTests, LoopRuntimeCoordinatorNominalBasalProfileTests, FallbackBasalExposureReconcilerTests, BionicLoopRuntimeEngineReconnectEvidenceTests, and LoopRuntimeCoordinatorFallbackReplayTests, including persisted primary/safety q5 nominal profiles, persisted pod identity plus total-delivery baseline/timestamp, pending pump-delta reconciliation state for later reconnect comparison, confirmed/corrected missed-step algorithm replay, and different/new pod no-replay continuation without replacing the algorithm session) In progress
RA-007 SRS-PUMP-004, SRS-PUMP-005 SDD-PUMP-001 TV-PUMP-004, TV-PUMP-005 Pending In progress
RA-008 SRS-LOG-001, SRS-LOG-002, SRS-LOG-003, SRS-LOG-004, SRS-LOG-005, SRS-LOG-006, SRS-LOG-007, SRS-LOG-008, SRS-LOG-009 SDD-LOG-001, SDD-POL-017, SDD-POL-018, SDD-POL-024, SDD-POL-025, SDD-APP-007, SDD-DATA-003 TV-LOG-001, TV-LOG-002, TV-LOG-003, TV-LOG-004, TV-LOG-005, TV-LOG-006, TV-LOG-007, TV-LOG-008, TV-LOG-009 Partial (implemented baseline: authenticated cloud telemetry envelope + persistent outbox with retry/permanent-failure handling + queue-cap drop policy + non-blocking upload + expanded runtime/CGM/pump/alert emitters + structured app.log.batch; envelope now carries auth_user_sub from ID-token sub with UNSET fallback. Lifecycle telemetry now includes timezone + UTC-check context (device_timezone_id, device_utc_offset_seconds, clock_check_result, optional skew/rtt/check timestamp) with launch/foreground/time-change trigger semantics. Meal announce telemetry now records deterministic submitted, accepted, success, blocked, uncertain, and resolved lifecycle transitions without optimistic-success duplication, with flow_id + target-step correlation preserved across relaunch/session-reset closure. Clinical target telemetry now captures target-range profile changes and participant approval-capture details with stable ui.critical event contracts. The active offline-fallback feasibility branch additionally records structured fallback lifecycle review events for Home Recent Dose Steps, including arm, maintenance-deferred, renew, refresh, offline-expiry, disarm, restore/remask failure detail, pod-continuity result, modeled-vs-pump-reported reconnect recovery detail, and pump-delta reconciliation detail when confirmed/corrected recovery uses no-command missed-step primary/secondary algorithm replay. The same branch now keeps local step telemetry and CSV export anchored to real algorithm executions; confirmed/corrected reconnect recovery records replay rows with CGM=-1 and persisted-schedule-weighted per-step delivered-insulin input, then resumes the live step with actual refreshed pump status and no duplicate recovered-delivery injection, with coverage in FallbackBasalReplayPlannerTests, LoopRuntimeCoordinatorFallbackReplayTests, and BionicLoopRuntimeEngineReconnectEvidenceTests. App-side cloud telemetry now also emits dedicated loop.fallback.event payloads for BionicScout contract consumption, with stable fallback_event_id, pod-continuity, modeled-vs-actual delivery summary fields, reconciliation summary fields, programmed schedule entries, safety q5 profile metadata/rates on arm/refresh events, and duplicate suppression coverage in LoopTelemetryStoreTests and BionicLoopCloudTelemetryInfrastructureTests.) In progress
RA-009 SRS-SEC-001, SRS-SEC-002 SDD-LOG-001, SDD-POL-015, CybersecurityPlan.md, Cybersecurity_Handoff_Register.md TV-SEC-001 Support: Cybersecurity_Local_File_and_Permission_Review.md, Cybersecurity_Baseline_Acceptability_Recommendation.md, Cybersecurity_Handoff_Register.md. Formal: TV-SEC-001 / STR-SEC-001 required for freeze. Current package does not claim closure of SRS-SEC-003..009. Deferred (partial scope)
RA-010 SRS-UI-001, SRS-UI-002, SRS-UI-003, SRS-UI-004, SRS-UI-005, SRS-UI-006, SRS-UI-007, SRS-UI-008, SRS-VAL-001, SRS-BG-001 SDD-POL-006, SDD-POL-007, SDD-POL-009, SDD-POL-014, SDD-POL-018, SDD-POL-019 TV-UI-001, TV-UI-002, TV-UI-003, TV-UI-004, TV-UI-005, TV-UI-006, TV-UI-007, TV-UI-008, TV-UI-009, TV-UI-010 Partial (Docs/Quality/Evidence/STR-UI-AUTO-001/2026-02-12-f5-ui-smoke/, plus BUG-001 real-device closure evidence in Docs/Quality/Evidence/STR-BUG-001/2026-02-11-relaunch-meal/; clock-sync coverage in BionicLoopInfrastructureTests.testDeviceClockSyncMonitorFlagsSkewAndPublishesWarningAtThresholdBreach, BionicLoopInfrastructureTests.testDeviceClockSyncMonitorWithinThresholdReportsOKWithoutWarning, BionicLoopInfrastructureTests.testDeviceClockSyncMonitorRetriesAndReturnsUnavailableWithoutWarningOnNetworkFailures, BionicLoopInfrastructureTests.testDeviceClockSyncMonitorLimitsSkewWarningsToOncePer24Hours, boundary/axis coverage in BionicLoopInfrastructureTests.testG7ViewModelDisplayFormattingMapsExtremeValuesToHighLow and BionicLoopHomeStateTests.testInlineCGMChartDerivationDynamicYAxisMaximumAndValues) In progress
RA-011 SRS-ALERT-001, SRS-ALERT-002, SRS-ALERT-003, SRS-ALERT-004, SRS-ALERT-005, SRS-ALERT-006, SRS-ALERT-007, SRS-ALERT-008, SRS-ALERT-009, SRS-ALERT-010, SRS-ALERT-011, SRS-ALERT-012, SRS-ALERT-015, SRS-ALERT-016, SRS-ALERT-017 SDD-ALERT-001, SDD-POL-008, SDD-POL-026, SDD-DATA-005 TV-ALERT-001, TV-ALERT-002, TV-ALERT-003, TV-ALERT-004, TV-ALERT-005, TV-ALERT-006, TV-ALERT-007, TV-ALERT-008, TV-ALERT-009, TV-ALERT-010, TV-ALERT-011, TV-ALERT-014, TV-ALERT-015, TV-ALERT-016, TV-SIM-005 Partial (implemented: AppAlertCenter + Home alert carousel + Home bell + Settings Alert Center + signal-loss debounce/clear + pump/cgm normalized mapping + delegate persisted-alert lifecycle hooks + app-level active/recent persistence + background local notification channel for non-CGM alerts with dedupe/cooldown plus repeated no-active-pod notification attempts while the condition remains true + minute-refresh time-sensitive countdown updates; CGM availability/failure alerts remain informational in-app only and do not schedule OS notifications; app-derived ALERT-CGM-URGENT-LOW now issues only from trustworthy live G7 <55 mg/dL, preserves reviewed state while active, persists acknowledged active state across reset / reattach, and auto-clears on trustworthy recovery >=55 mg/dL; evidence: testTopAlertPrefersHigherSeverityThenMostRecent, testSortedAlertsOrdersBySeverityRecencyAndStableDedupeKey, testHomeAlertCarouselNavigatorClampsAndWrapsIndexes, testNoActivePodDebounceAddsAndClearsAlert, testNoActivePodConditionRepeatsBackgroundNotificationUntilRecovered, testHomeAlertSyncEvaluatorReflectsCombinedPumpConditions, testSignalLossDebounceAddsAndClearsAlert, testSignalLossDebounceSuppressesTransientCondition, testShowPreviewAlertsSupportsMultipleTypesAndPrecedence, testCGMAlertsNeverScheduleBackgroundNotifications, testUrgentLowAcknowledgeMarksAlertReviewedWithoutClearingActiveState, testCGMUrgentLowAcknowledgePersistsAcrossAlertCenterResetUntilRecovery, testCGMUrgentLowAlertMapperIssuesForReliableReadingBelow55, testCGMUrgentLowAlertMapperClearsAt55OrAbove, testAlertCenterTracksRecentlyClearedAlerts, testAlertCenterRestoresPersistedActiveAndClearedAlerts, testPumpPersistedAlertStoreReturnsIssuedAndRetractedAlerts, testCGMPersistedAlertStoreReturnsIssuedAndRetractedAlerts, testPumpExpirationAlertSyncPlannerReturnsRetractsWhenNoExpirationAlertsApply, testPumpAlertMapperExpiringIncludesCountdownDeadline, testTimeSensitivePumpExpiringAlertRefreshesMessageWithoutReschedulingNotification, testIssueAndRetractPumpAlertUpdatesAppAlertCenter, testIssueAndRetractIncompatiblePumpAlertUpdatesAppAlertCenter, testIssueAndRetractCGMAlertUpdatesAppAlertCenter, testUI007_HomeAlertCenterButtonOpensAlertCenter, testUI008_AlertCenterAcknowledgeMovesAlertToRecentlyCleared, testUI009_AlertCenterPersistsAcrossRelaunch, testAlertCenterClearsNotificationsWhenRetractingAbsentAlert, testRetractingAbsentAlertStillClearsNotificationRequests; simulation evidence: Docs/Quality/Evidence/Working/STR-SIM-001/2026-02-19-h5-smoke/; source mapping baseline: Docs/Quality/AlertInventoryAndMapping.md) In progress
RA-012 SRS-BG-001, SRS-BG-002, SRS-BG-003, SRS-BG-004, SRS-BG-005, SRS-BG-006, SRS-BG-007, SRS-BG-008, SRS-BG-009, SRS-BG-010, SRS-BG-011, SRS-BG-012 SDD-BG-001, SDD-POL-010, SDD-POL-011, SDD-POL-012, SDD-LOG-001 TV-BG-001, TV-BG-002, TV-BG-003, TV-BG-004, TV-BG-005, TV-BG-006, TV-BG-007, TV-BG-008, TV-BG-009, TV-BG-010, TV-BG-011, TV-BG-012 Partial (current branch feasibility verification adds blocked manual-BG execution coverage while masked-fallback reconciliation is pending in BionicLoopRuntimeEngineSessionInfrastructureTests) In progress
RA-013 SRS-CLIN-001, SRS-CLIN-002, SRS-CLIN-003, SRS-CLIN-004, SRS-CLIN-005, SRS-CLIN-006, SRS-CLIN-007, SRS-CLIN-008, SRS-CLIN-009, SRS-CLIN-010, SRS-CLIN-011, SRS-CLIN-012, SRS-VAL-001, SRS-LOG-008 SDD-CLIN-001, SDD-POL-013, SDD-POL-017, SDD-POL-025, SDD-DATA-006 TV-CLIN-001, TV-CLIN-002, TV-CLIN-003, TV-CLIN-004, TV-CLIN-005, TV-CLIN-006, TV-CLIN-007, TV-CLIN-008, TV-CLIN-009, TV-CLIN-010, TV-CLIN-011, TV-CLIN-012, TV-CLIN-013, TV-LOG-008 Support evidence demonstrates offline HMAC unlock contract-vector coverage, Keychain-backed material installation/refresh, local counter burn/expiry semantics, manual-lock storage-failure handling, UI unlock success/failure/reuse handling, selector bounds, profile gating, and approval capture. Production role-based authorization is not claimed in the current baseline. Formal clinical-settings evidence promotion is still required for freeze. Rerun needed
RA-014 SRS-ALG-001, SRS-ALG-002, SRS-ALG-003, SRS-ALG-004, SRS-ALG-005, SRS-ALG-006, SRS-ALG-007 SDD-ALG-001, SDD-QA-001 TV-ALG-001, TV-ALG-002, TV-ALG-003, TV-ALG-004, TV-ALG-005, TV-ALG-006, TV-ALG-007, TV-ALG-008, TV-ALG-009, TV-ALG-010, TV-ALG-011 Support package exists in Docs/Quality/Evidence/Working/STR-ALG-001/...; formal STR-ALG-001 execution and promotion are required for freeze. Rerun needed
RA-015 SRS-CGM-005, SRS-RUN-004, SRS-RUN-005, SRS-ALERT-013, SRS-ALERT-014, SRS-UI-001, SRS-UI-002 SDD-POL-020, SDD-POL-021, SDD-POL-022, SDD-POL-008, SDD-APP-003, SDD-CGM-001 TV-CGM-005, TV-RUN-004, TV-RUN-005, TV-RUN-006, TV-RUN-007, TV-ALERT-012, TV-ALERT-013, TV-UI-001 Support evidence exists for interruption deadline, alerting, and fresh-CGM suppression. Current implementation also permits reconnect fallback when CGM freshness is unavailable. Formal runtime evidence promotion and required live-device reconnect confirmation are still required for freeze. Rerun needed
RA-016 SRS-MEAL-007, SRS-MEAL-008, SRS-MEAL-009, SRS-MEAL-010, SRS-MEAL-011, SRS-MEAL-012, SRS-LOG-007, SRS-UI-002 SDD-POL-023, SDD-POL-024, SDD-POL-027, SDD-POL-029, SDD-APP-001, SDD-LOG-001 TV-MEAL-008, TV-MEAL-009, TV-MEAL-010, TV-MEAL-011, TV-MEAL-012, TV-MEAL-013, TV-LOG-007, TV-PUMP-003 Support automated evidence exists for pending/uncertain meal state, duplicate blocking, reconciliation, cancel-delivery handling, and user-confirmed pod replacement for unconfirmed old-pod meal delivery. Formal meal-lifecycle evidence promotion is still required for freeze. Rerun needed
RA-017 SRS-PUMP-010, SRS-MEAL-012, SRS-STATE-004, SRS-STATE-005, SRS-LOG-001 SDD-POL-029, SDD-PUMP-001, SDD-DATA-003, SDD-LOG-001 TV-PUMP-009, TV-MEAL-013, TV-STATE-004, TV-STATE-005, TV-LOG-001 Working evidence exists in FallbackBasalExposureReconcilerTests, LoopRuntimeCoordinatorMealAttributionReplayTests, LoopRuntimeCoordinatorMealAttributionLiveStepTests, LoopRuntimeCoordinatorIssuedDoseNewPodTests, LoopRuntimeCoordinatorFallbackReplayTests, BionicLoopRuntimeEngineReconnectEvidenceTests, BionicLoopRecentDoseTimelineTests, BionicLoopCloudTelemetryInfrastructureTests, BionicLoopAlgorithmInspectionTelemetryRuntimeTests, BionicLoopMealAnnouncementAvailabilityTests, BionicLoopMealAnnouncementPersistenceRuntimeTests, BionicLoopMealAnnouncementResolutionRuntimeTests, BionicLoopMealAnnouncementPodReplacementEscapeTests, BionicLoopMealDeliveryProgressPolicyTests, and the SimulatedDashPod*ScenarioTests pod-simulation slice for correction/meal issued-dose attribution, active delivery skip, same-request/same-pod missed-step replay, reservoir-capped partial meal delivery using actual delivered units, reservoir-capped fallback replay using observed pump delta instead of modeled exposure, pump-total partition of a known in-flight issued dose from fallback-basal residual, persisted partition evidence live-step consumption when replay is not required, app recent-dose persistence/display, local step CSV export, and runtime cloud step-event emission of merged meal/fallback replay source, disposition, request step, requested units, and delivered units after reload, raw pump-total telemetry without claiming fallback residual on ambiguous recovery, delivered-unit credibility rejection, fallback replay overlap, resolved issued-dose merge into the first fallback-active replay row when the issued dose predates fallback activation, fallback-only prior request-step attribution, evidence-gated pending attribution clearing, non-credible merge rejection, unresolved no-guess live-advance skip, mismatched/missing-identity no-replay, different/new pod assumed-delivered attribution with replacement-pod live input scrubbing, user-abandoned unavailable-pod meal assumed-delivered evidence, future insulin-adding command allowance including automatic resume, legacy different/new-pod hold nonblocking behavior for commands and meal availability, meal progress modal resolution after runtime consumes matching pending meal attribution including fallback-merge and user-escaped old-pod paths, and meal-availability blocking/mapping. Formal evidence promotion is still required for freeze. Rerun needed

Usage

For each PR or change batch:

  1. Add/update impacted SRS-*.
  2. Update SDD-* references.
  3. Add/update TV-* and run tests.
  4. Attach evidence references in this table.

Notes

  • Status values: Planned, In progress, Rerun needed, Complete, Blocked, Deferred (current software handoff package), and Deferred (partial scope) when only a subset of a mapped hazard/row is intentionally claimed in the current package.
  • Evidence can reference CI run IDs, local test logs, or manual protocol records.