{
  "schema_version": "pointer-methodology-instance-0.2.1",
  "document_type": "pointer_public_methodology",
  "name": "3Dogs Pointer A2A Evidence Method",
  "version": "0.2.1-candidate",
  "status": "public-candidate-human-approval-required",
  "updated": "2026-08-08",
  "canonical": "https://3dogs.ai/pointer/methodology.json",
  "purpose": "Test whether an authorized AI agent can discover, understand, execute within declared limits, recover, and produce confirmable evidence for a bounded business task.",
  "non_claims": [
    "This document is not a certification.",
    "Presence of a protocol endpoint is not proof of successful execution.",
    "A discovery-only score is not proof of operational readiness.",
    "A document can prove that a capability was represented; it cannot by itself prove that the capability exists, executes, or enforces authorization.",
    "No organization is ranked without comparable evidence captured under the same method and time window.",
    "Payment is not required to obtain or rerun the measurement, and payment cannot improve an evidence state."
  ],
  "layers": [
    {"id": "discover", "question": "Can an agent locate authoritative identity, policy, task, and contract surfaces?", "critical": true},
    {"id": "execute", "question": "Can an agent complete a bounded non-destructive task against the declared contract?", "critical": true},
    {"id": "govern", "question": "Are identity, authority, consent, limits, audit, and human control explicit and enforced?", "critical": true},
    {"id": "recover", "question": "Do denial, timeout, replay, revocation, and partial failure resolve within documented contract limits and visibility requirements?", "critical": true},
    {"id": "confirm", "question": "Can a separate evaluator run repeat the task and confirm equivalent evidence?", "critical": true}
  ],
  "evidence_states": ["confirmed", "observed", "claimed", "not_evidenced", "contradicted", "not_applicable"],
  "assurance_progression": [
    "NOT_EVALUATED",
    "DISCOVERY_ONLY",
    "L1_EXECUTABLE",
    "L2_GOVERNED",
    "L3_CONFIRMED"
  ],
  "level_definitions": {
    "L1_EXECUTABLE": "Discover and Execute pass every applicable critical control.",
    "L2_GOVERNED": "L1 is inherited and Govern passes every applicable critical control.",
    "L3_CONFIRMED": "L2 is inherited, Recover passes every applicable critical control, and a separate evaluator run confirms equivalent evidence. Confirmed does not mean independently certified."
  },
  "ineligible_status": "NOT_RANKABLE",
  "progression_rule": "Each higher level inherits every lower-level applicable control. One applicable critical failure prevents advancement. Controls are not averaged into a compensating weighted score.",
  "confirmation_evaluator_definition": "A separate evaluator run that did not produce the original evidence. It may be operated by the assessed organization. Independent external confirmation is a distinct, separately evidenced claim and is not implied by L3_CONFIRMED.",
  "hard_gate_examples": [
    "advertised_surface_not_observed_live_or_authorization_not_enforced",
    "deceptive_success_or_soft_404",
    "unsafe_failure_or_recovery",
    "unbound_or_unverifiable_audit_evidence",
    "material_claim_not_confirmable_by_separate_run"
  ],
  "hard_gate_classification": {
    "rule": "Documentation may establish a representation, schema, or consistency defect. A gate about availability, execution, or authorization requires a request against the declared live surface or equivalent controlled runtime evidence.",
    "consequential_write_rule": "Do not casually exercise consequential production writes. Use an authorized sandbox or canary, or bind attested runtime evidence that proves the declared operation and authorization behavior.",
    "withdrawal_rule": "An advertised API or protocol surface must exist and enforce its declared authorization, or every machine-readable advertisement and reference to that surface must be withdrawn.",
    "legal_claim_boundary": "Use technical outcomes such as ADVERTISED_SURFACE_NOT_OBSERVED. Do not convert a technical measurement into an unqualified legal conclusion."
  },
  "subject_runnable": {
    "required": true,
    "rule": "The assessed organization must be able to take its report, apply fixes, and rerun the same published measurement without buying a 3Dogs service.",
    "portable_bundle_requires": [
      "method_and_collector_versions",
      "subject_environment_and_scope",
      "normalized_inputs_and_configuration",
      "complete_findings_and_failure_reasons",
      "exact_acceptance_tests",
      "positive_and_negative_test_vectors",
      "normalized_outputs_and_result_derivation",
      "evidence_urls_and_sha256",
      "expiry_and_supersession_state"
    ],
    "failure_effect": "If the measurement cannot be rerun by the subject, the result is NOT_SHAREABLE and is not eligible for any public assurance level or ranking. An internal diagnostic state may be retained but must not be presented as a Pointer result."
  },
  "commercial_boundary": {
    "measurement_and_same_method_remeasurement_require_payment": false,
    "no_fee_outputs_include": ["complete_findings", "failure_reasons", "exact_acceptance_tests", "result_derivation", "rerun_instructions"],
    "paid_services_may_include": ["interpretation", "prioritization", "remediation", "implementation", "managed_evidence_collection"],
    "paid_interpretation_may_be_required_to_understand_self_fix_or_rerun": false,
    "payment_may_change_result_gate_waiver_publication_or_appeal": false,
    "rule": "3Dogs may charge for work. It may not charge for a better measurement outcome."
  },
  "shareable_summary": {
    "required_fields": ["subject", "assurance_state", "method_version", "observed_at", "expires_at", "evidence_bundle_sha256", "limitations_url", "human_release_decision_ref"],
    "label_template": "POINTER SUMMARY · {SUBJECT} · {ASSURANCE_STATE} · METHOD {METHOD_VERSION} · OBSERVED {OBSERVED_AT} · EXPIRES {EXPIRES_AT} · EVIDENCE SHA256:{EVIDENCE_BUNDLE_SHA256} · LIMITS {LIMITATIONS_URL} · RELEASE {HUMAN_RELEASE_DECISION_REF}",
    "ineligible_label_template": "POINTER SUMMARY · {SUBJECT} · NOT_SHAREABLE · {INELIGIBLE_STATUS} · METHOD {METHOD_VERSION} · REASON {REASON}",
    "incomplete_required_field_result": "NOT_SHAREABLE",
    "display_rule": "Use the bounded assurance state and complete evidence metadata. Do not render a shareable label when a required field is missing or pending. Do not convert the state into an unsupported numeric score or certification badge."
  },
  "required_task_definition": [
    "business_problem",
    "bounded_task",
    "authorized_actor",
    "allowed_inputs",
    "expected_outcome",
    "prohibited_actions",
    "failure_expectations",
    "evidence_requirements",
    "human_escalation",
    "expiry_and_freshness_window"
  ],
  "required_claim_record": [
    "claim_id",
    "normalized_predicate",
    "subject_and_environment",
    "applicability",
    "source_urls_and_sha256",
    "observed_at_and_expires_at",
    "collector_and_verifier_versions",
    "authority_and_consent_references",
    "positive_and_negative_control_results",
    "recovery_and_revocation_evidence_if_applicable",
    "separate_confirmation_evidence_for_L3",
    "status",
    "limitations_and_supersession_history"
  ],
  "claim_statuses": ["confirmed", "observed", "claimed", "not_evidenced", "contradicted", "not_applicable"],
  "release_gate": {
    "authorized_environment": "LOCAL_AND_DEV_REMEDIATION_ONLY",
    "dev_promotion_requires": [
      "HG_ADVERTISED_SURFACES_EXIST_AND_ENFORCE_AUTHORIZATION_OR_ARE_WITHDRAWN",
      "HG_SOFT404_CLOSED",
      "SUBJECT_RUNNABLE_BUNDLE_RELEASED",
      "COMMERCIAL_FIREWALL_BOUND",
      "RELEASE_EVIDENCE_BOUND"
    ],
    "production_promotion_requires": [
      "ALL_DEV_PROMOTION_REQUIREMENTS",
      "PUBLIC_L1_EXECUTION_ARTIFACT",
      "STRUCTURED_INTAKE_ENFORCED",
      "EXACT_HASH_REVIEW",
      "RESPONSIVE_AND_ACCESSIBILITY_GATES",
      "EXPLICIT_HUMAN_RELEASE_APPROVAL",
      "POST_DEPLOY_LIVE_VERIFICATION"
    ],
    "current_state": {
      "HG_ADVERTISED_SURFACES_EXIST_AND_ENFORCE_AUTHORIZATION_OR_ARE_WITHDRAWN": false,
      "HG_SOFT404_CLOSED": false,
      "SUBJECT_RUNNABLE_BUNDLE_RELEASED": false,
      "COMMERCIAL_FIREWALL_BOUND": false,
      "RELEASE_EVIDENCE_BOUND": false,
      "dev_promotion_eligible": false,
      "production_promotion_eligible": false
    },
    "rule": "A missing or false required state blocks promotion. Local and DEV remediation work may proceed without implying DEV or production promotion."
  },
  "release_control": {
    "assessment_may_mutate_target": false,
    "implementation_requires_separate_authorization": true,
    "public_release_requires_human_approval": true,
    "commercial_status_may_change_evidence_result": false
  }
}
