ASHRAE TC 1.4 · HVAC CONTROL SYSTEMS · TECHNICAL EXAMINATION SURFACE

The command can be correct.
Is the consequence admissible now?

This showroom isolates a narrow control-system question immediately before physical consequence: a controller, optimizer, AI layer or operator may be capable of issuing a technically valid HVAC command. What establishes that this exact proposed consequence has sufficient admissibility, authority and standing to become reality now?

THE EXAMINATION QUESTIONIs there a technically meaningful distinction between a control system being capable and correctly configured to issue a command and that command having sufficiently established present evidence and execution authority to proceed?

THE BOUNDARY

Keep the controls. Add a governed consequence boundary.

BMS / CONTROLLER

Executes sequences, logic and physical commands.

SUPERVISORY OPTIMIZATION / AI

Proposes changes based on objectives, models and available state.

DIGITAL TWIN / ASSET RECORD

Supplies identity, topology, context and supporting evidence.

TA-14

Determines whether the proposed consequence has sufficient admissibility, authority and standing to become reality now.

ONE HVAC CASE

AHU-7 · Proposed command: STOP_AHU_7

A supervisory optimization layer identifies a demand-reduction opportunity and proposes stopping AHU-7. The command path works. The controller is correctly configured. The question is whether the consequence remains eligible to execute at commit.

BASELINE

AHU supply fan is operating. Supervisory optimization proposes STOP_AHU_7 to reduce demand.

ALLOWCurrent asset state, evidence, authority and exact command binding are established.
CHANGED CONDITION

After authorization but before commit, AHU-7 becomes the active smoke-control path.

HOLDThe earlier basis cannot silently survive a material change. Revalidation is required before consequence.
SCOPE FAILURE

Optimization service is authenticated and technically capable, but its established authority does not include life-safety shutdown.

DENYCapability and identity do not create execution authority outside established scope.
UNRESOLVED CONFLICT

Two current records disagree about the operating mode and the boundary cannot establish which controls.

ESCALATEThe consequence remains unresolved rather than converting uncertainty into permission.

THE TEST

Eight questions between capability and consequence.

01
CAPABILITY

Can the control system issue the requested command?

02
REALITY

What is physically true at the affected HVAC asset now?

03
RECORD

What evidence supports that present state, with source and time preserved?

04
CONTINUITY

Has the evidence remained current through the interval before consequence?

05
ADMISSIBILITY

Does the evidence actually support this exact proposed consequence?

06
AUTHORITY

Is the actor or system presently authorized for this action and scope?

07
STANDING

Is that authority bound to this asset, condition, context and moment?

08
COMMIT

Can the exact supporting state be frozen immediately before execution?

WHY HOLD MATTERS

A valid earlier decision does not become permanent permission.

CHANGED-CONDITION REVALIDATION

At authorization, AHU-7 is ordinary ventilation equipment and the demand-response stop is supported. Before commit, the building enters a smoke-control condition and AHU-7 becomes part of the active life-safety path. TA-14 does not silently repair the old decision. The changed condition breaks continuity. The proposed consequence moves to HOLD until the present evidence, authority and binding are re-established.

ADVERSARIAL SELF-EXAMINATION · FROZEN CHALLENGE

Do not design the test so TA-14 wins. Try to remove the need for it.

The proposition under examination is narrow: a technically correct and properly configured command can still lack sufficient present admissibility, authority or standing to execute. The challenges below are intended to defeat that proposition, expose redundancy, or identify conditions the architecture does not handle.

PREDECLARED FALSIFIERTA-14's claimed distinction fails this examination if established control architecture already provides an equivalent mechanism for verifying present evidence, authority, exact consequence binding, changed-condition revalidation at commit, refusal of execution, and reconstructable outcome — without requiring the TA-14 consequence boundary.
C-01EXISTING CONTROLS

Do BMS interlocks, smoke-control logic, safeties, priority structures or the sequence of operations already provide an equivalent refusal mechanism?

If they provide the same present-state test, refusal, revalidation and reconstructable record, this case has not established a distinct TA-14 contribution.
C-02TIMING

What happens if the material change occurs milliseconds before physical execution? Where is the temporal cutoff?

If the boundary cannot establish sufficiently current state before commit, the proposition cannot claim reliable changed-condition protection.
C-03EVIDENCE SUFFICIENCY

What evidence is sufficient to establish that AHU-7 has become part of the active smoke-control path?

If sufficiency is undefined or merely assumed, HOLD is asserted rather than earned.
C-04AUTHORITY

If the optimizer possesses valid shutdown authority, does the changed smoke-control condition still produce HOLD?

If authority alone permits execution despite the changed condition, the claimed present-state boundary fails.
C-05STANDING

Does standing add anything beyond authority, asset binding and current context?

If removing standing does not alter the determination or record, standing may be redundant in this case.
C-06BOUNDARY FAILURE

What happens when TA-14 receives stale, missing or contradictory state, or loses communication?

The architecture must distinguish inability to establish current state from affirmative permission. The safety effect of HOLD must also be examined.
C-07ADVERSE COUNTEREXAMPLE

Can established HVAC or life-safety practice require immediate execution while TA-14 would HOLD?

Any such case must be preserved as an adverse finding and examined rather than explained away.
C-08NECESSITY / REMOVE TA-14

Remove TA-14. Can the native control architecture reach the same determination for the same reasons and preserve an equivalent reconstructable record?

If yes, this bounded case does not establish that TA-14 contributes a distinct consequence-governance function.
RESULT RULE

SUPPORTED — BOUNDED: the distinction survives the frozen challenge. NOT ESTABLISHED: evidence is insufficient to decide. NOT DISTINCT: native controls establish an equivalent mechanism. ADVERSE FINDING: the challenge identifies a case where the proposed boundary produces an unsupported or unsafe determination.

No result from this case establishes universal efficacy, ASHRAE validation, or adoption.

CHALLENGE RUN · R1

The architecture does not get a pass because the example sounds right.

R1 applies the frozen challenges to the showroom as presently specified. It is a documentary examination, not a live controls test. Existing HVAC practice creates serious pressure on the necessity claim: standard sequences can already interlock and alter equipment operation, while smoke-control practice can override ordinary HVAC behavior. The question is whether TA-14 establishes a distinct governed function beyond that native control behavior.

R1 OVERALL FINDINGNOT ESTABLISHED

The bounded proposition is not defeated, but the current AHU-7 case does not yet establish that TA-14 is technically distinct or necessary. One challenge is supported in bounded form; one produces an adverse finding; the remaining challenges require stronger frozen evidence or an executable comparison.

C-01EXISTING CONTROLSNOT ESTABLISHED

Established HVAC and smoke-control sequences can already interlock, override, shut down, or change equipment operation when conditions change. The current case has not yet shown that native controls cannot produce the same immediate STOP/HOLD outcome. What remains unestablished is equivalence of the full evidence, authority, commit and reconstructable-record function.

C-02TIMINGNOT ESTABLISHED

The showroom defines revalidation before commit but does not yet specify sensing latency, communications latency, decision latency, commit atomicity, or the last safe revalidation instant. The millisecond challenge survives against TA-14.

C-03EVIDENCE SUFFICIENCYNOT ESTABLISHED

The case says AHU-7 becomes an active smoke-control path, but it does not freeze the minimum admissible evidence set that proves that state. A HOLD can be reasonable while the sufficiency rule itself remains undefined.

C-04AUTHORITYSUPPORTED — BOUNDED

Within the frozen scenario, valid optimizer shutdown authority is not enough after the material condition changes. The proposed action must still be valid for the present life-safety context. This supports the narrow distinction between possessing authority and having a presently admissible consequence.

C-05STANDINGNOT ESTABLISHED

The case has not yet demonstrated that standing is independently necessary rather than a name for the combination of authority, asset binding, scope, condition and time. TA-14 must show a case where authority is valid but standing independently changes the determination.

C-06BOUNDARY FAILUREADVERSE FINDING

The current surface does not define a complete failure policy for stale or missing state, communications loss, or a HOLD that itself could interfere with a required life-safety action. Default refusal cannot be assumed safe in every consequence domain.

C-07ADVERSE COUNTEREXAMPLENOT ESTABLISHED

The case does not yet include a frozen situation in which immediate execution is required and delay is itself hazardous. Until that case is run, the architecture has not shown that HOLD/ESCALATE behavior remains safe under urgency.

C-08NECESSITY / REMOVE TA-14NOT ESTABLISHED

For the narrow AHU-7 smoke-control outcome, native controls may be able to prevent the demand-response stop through ordinary interlocks or priority logic. This case therefore does not yet establish that TA-14 is necessary. The remaining candidate distinction is the governed, reconstructable evidence/authority/commit record across systems, which still requires comparison.

NEXT FROZEN TESTRun AHU-7 twice: once with native BMS / smoke-control logic only, and once with the TA-14 consequence boundary. Preserve the inputs, state transitions, refusal mechanism, timing, authority basis and resulting record. If the two mechanisms are functionally and evidentially equivalent, record NOT DISTINCT.

R2 · NATIVE-CONTROLS COMPARISON

What survives when established controls are given full credit?

R2 does not treat the BMS as a straw man. Public ASHRAE material confirms that established controls already provide important pieces of the problem: standardized sequences, command prioritization, and command-source/time provenance. Those functions must be credited before any TA-14 distinction can be claimed.

NATIVE CONTROL PATHESTABLISHED

BACnet commandable properties use a 16-level priority mechanism; the highest active priority controls the commandable value. Native building-control infrastructure therefore already has a formal mechanism for competing commands and overrides.

COMMAND PROVENANCEESTABLISHED

BACnet extensions define Value_Source, Value_Source_Array, Last_Command_Time and Command_Time_Array for commandable objects, showing that source and timing provenance can exist inside established control infrastructure.

SEQUENCE FUNCTIONESTABLISHED

ASHRAE Guideline 36 provides detailed HVAC sequences intended for efficiency, performance, control stability and real-time fault detection/diagnostics, with functional tests for implementation.

TA-14 DISTINCT CLAIMNOT ESTABLISHED

The present public evidence does not show that BACnet priority/provenance plus established HVAC sequences perform the entire TA-14 proposition: cross-system evidence sufficiency + authority + standing + changed-condition revalidation + frozen commit + preserved determination as one governed consequence record.

R2 FINDINGPARTIAL OVERLAP ESTABLISHED · DISTINCTNESS NOT YET ESTABLISHED

The native-control side is stronger than the original demonstration implied. BACnet can prioritize commands and preserve command source/time information, while established HVAC sequences can encode and test operating behavior. TA-14 therefore cannot claim distinctness merely from override, refusal, provenance, or sequence logic. The remaining candidate distinction is narrower: whether one governed consequence record can establish present evidence sufficiency, authority, standing, changed-condition continuity, exact binding and commit across heterogeneous systems immediately before consequence.

R3 TEST REQUIREDFreeze the exact evidence objects for AHU-7 and map each TA-14 requirement to an existing native control mechanism. Any requirement already satisfied natively is removed from the distinctness claim. Only an unmapped requirement may proceed as a candidate TA-14 contribution.

R2 basis: public ASHRAE materials for Guideline 36 and ANSI/ASHRAE Standard 135 BACnet command prioritization / value-source mechanisms. This is a TA-14 comparison, not an ASHRAE finding or endorsement.

R3 · REQUIREMENT-TO-NATIVE MAP

Remove everything TA-14 cannot legitimately claim as distinct.

R3 maps the AHU-7 requirements against established native-control functions evidenced in the public ASHRAE/BACnet materials reviewed for this examination. “Unmapped” does not mean absent from every existing product or architecture. It means an equivalent mechanism has not been established by the bounded comparison performed here.

CAPABILITY

Can the controller issue STOP_AHU_7?

NATIVE / EXISTING MECHANISM

BACnet / controller command path

MAPPED NATIVE

Not distinct.

COMMAND PRIORITY

Which active command wins?

NATIVE / EXISTING MECHANISM

BACnet Priority_Array / command prioritization

MAPPED NATIVE

Not distinct.

COMMAND SOURCE

What source supplied the controlling command?

NATIVE / EXISTING MECHANISM

BACnet Value_Source / Value_Source_Array where supported

MAPPED NATIVE

Not distinct.

COMMAND TIME

When was the active priority last commanded or relinquished?

NATIVE / EXISTING MECHANISM

BACnet Last_Command_Time / Command_Time_Array where supported

MAPPED NATIVE

Not distinct.

SEQUENCE INTENT

What should the HVAC system do under defined operating conditions?

NATIVE / EXISTING MECHANISM

Sequence of operations / ASHRAE Guideline 36 where applicable

MAPPED NATIVE

Not distinct.

IMPLEMENTATION TEST

Does programmed behavior conform to the specified sequence?

NATIVE / EXISTING MECHANISM

Functional testing; emerging standardized conformance testing

MAPPED / DOMAIN-SPECIFIC

TA-14 cannot claim this generally.

PRESENT EVIDENCE SUFFICIENCY

Do the current records collectively establish the proposition required for this exact consequence?

NATIVE / EXISTING MECHANISM

No equivalent single mechanism established in the public materials examined

UNMAPPED CANDIDATE

Candidate TA-14 contribution; not yet proven unique.

EXECUTION AUTHORITY

Is this actor/system authorized for this exact consequential action and scope now?

NATIVE / EXISTING MECHANISM

BACnet command priority/source do not by themselves establish institutional or delegated execution authority

UNMAPPED CANDIDATE

Requires comparison with site IAM, policy and supervisory systems.

STANDING

Is otherwise-valid authority bound to this asset, condition, context and moment?

NATIVE / EXISTING MECHANISM

No independent native equivalent established; concept may overlap with scope/context binding

UNRESOLVED

Must prove independent necessity or remove the term.

CHANGED-CONDITION CONTINUITY

Did the evidentiary and authority basis remain valid from authorization through commit?

NATIVE / EXISTING MECHANISM

Native sequences may react to changed state, but an equivalent cross-system continuity determination was not established

UNMAPPED CANDIDATE

This is a central remaining TA-14 hypothesis.

EXACT CONSEQUENCE BINDING

Is the evidence/authority decision bound to STOP_AHU_7 rather than merely the asset or session?

NATIVE / EXISTING MECHANISM

Command objects bind values/actions, but equivalent evidence-and-authority binding was not established

UNMAPPED CANDIDATE

Needs frozen object model.

COMMIT RECORD

Can the exact evidence, authority, context and determination immediately preceding execution/refusal be reconstructed as one record?

NATIVE / EXISTING MECHANISM

BACnet exposes useful source/time state; equivalence to a complete consequence record was not established

UNMAPPED CANDIDATE

Strongest candidate distinction, subject to external system comparison.

OUTCOME PRESERVATION

Was execution/refusal and resulting state preserved?

NATIVE / EXISTING MECHANISM

BMS histories, alarms, audit/event systems may preserve outcomes

PARTIAL NATIVE

TA-14 must not claim outcome logging itself as distinct.

R3 FINDINGTA-14 CLAIM NARROWED

TA-14 does not get to claim command capability, priority resolution, command provenance, command timing, HVAC sequence logic, functional testing, or ordinary outcome logging as its distinct contribution. The remaining hypothesis is the consequence-boundary composition: establishing and preserving, across the relevant systems, whether present evidence, execution authority, contextual standing, continuity and exact consequence binding remain sufficient at commit.

R4 FALSIFICATION TARGETFind an existing architecture that already composes those remaining functions into an equivalent pre-consequence determination and reconstructable commit record. If one exists and is functionally equivalent, TA-14 records NOT DISTINCT. If individual pieces exist but no equivalent composition is established, the distinction narrows to composition rather than invention of the pieces.

R3 comparison basis includes ASHRAE Guideline 36 public purpose/scope and ANSI/ASHRAE Standard 135 public addenda/interpretations describing BACnet command prioritization and value-source/time mechanisms. Product-specific IAM, fire-alarm, smoke-control, cybersecurity and audit architectures remain outside this bounded R3 record and must be examined before any broader claim.

R4 · EXTERNAL FALSIFICATION SEARCH

The composition itself is not safe from challenge.

R4 searched outside HVAC controls for architectures that sit before execution, evaluate current context or authority, bind a decision to a specific action, enforce the result, and preserve decision evidence. Several materially overlapping architectures exist. This changes what TA-14 can responsibly claim.

NIST ZERO TRUST PDP / PEPSTRONG OVERLAP

Dynamic policy decisions can use identity, resource and contextual information and be enforced by a policy enforcement point.

This defeats any broad TA-14 claim to invent runtime contextual authorization or a decision/enforcement boundary.
SCITT PRE-EXECUTION PERMIT PROFILEVERY STRONG OVERLAP

A July 2026 IETF Internet-Draft records allow/deny/challenge before dispatch and cryptographically binds the decision to the canonical request, with paired closure evidence.

This directly overlaps pre-execution authorization, exact request binding and reconstructable authorization/dispatch evidence. It is an Internet-Draft, not an adopted standard.
GUARDNET GNA INTERNET-DRAFTSTRONG OVERLAP

A pre-execution authorization architecture intercepts high-risk digital actions, evaluates policy/risk and issues an execution token before execution.

Further evidence that pre-execution action authorization is not uniquely TA-14. Internet-Draft status limits claims of established deployment or standardization.
FORESIGHT OVERSIGHTNEAR-DIRECT CONCEPTUAL OVERLAP

A July 2026 public reference architecture describes a pre-execution governance layer asking whether an action remains eligible under current authority, state, conditions and environment, and preserving grounds for the decision.

The public description is close to TA-14 consequence-boundary language. Independent implementation/equivalence is not established by this documentary comparison.
SIGIL OPEN FRAMEWORKNEAR-DIRECT TECHNICAL OVERLAP

Public materials describe a deterministic authorization boundary between an agent action and execution endpoint, signed policy, action attestations and hash-chained evidence records.

The described composition substantially overlaps execution interception, authorization, binding and preserved evidence for agent actions; HVAC applicability and exact current-state semantics are not established here.
R4 FINDINGBROAD DISTINCTNESS CLAIM DOES NOT SURVIVE

TA-14 cannot claim that pre-execution governance, contextual authorization, execution interception, action binding, refusal, or preserved authorization evidence are uniquely its architecture. Public work in zero trust and emerging AI-action governance already occupies substantial portions of that space. The remaining TA-14 question must therefore be narrower: whether its specific Reality → Record → Continuity → Admissibility → Binding → Commit → Execution → Outcome composition, its sufficiency semantics, changed-condition continuity, and its treatment of admissibility + authority + standing together establish a technically distinct and useful mechanism for physical consequences such as HVAC.

R5 REQUIREDCompare TA-14 directly against the strongest near-neighbor rather than against a generic BMS. Freeze the same proposed action and ask both architectures to process changed context between authorization and execution. Compare what each consumes, what it decides, what it binds, what causes refusal, and what record remains.

R4 is a documentary comparison, not a certification of any referenced architecture. NIST zero-trust material is established guidance; SCITT Permit and GuardNet GNA are Internet-Drafts and may change or expire; the other referenced architectures are public third-party descriptions whose implementation claims were not independently verified in this examination.

R5 · STRONGEST NEAR-NEIGHBOR COMPARISON

TA-14 vs. GuardNet GNA — same consequence, no straw man.

R5 uses the GuardNet Authorization Protocol Internet-Draft because it explicitly covers high-risk digital and physical actions, including OT/ICS commands. GNA intercepts an action before execution, evaluates policy and context, can require authenticated approvers, issues an execution token, and creates a signed receipt. That makes it a materially stronger comparison than a generic BMS.

UNIT OF DECISION
GNA

Specific proposed action / request

TA-14

Specific proposed consequence

NEAR EQUIVALENT
PRE-EXECUTION GATE
GNA

PEP intercepts action before execution

TA-14

Consequence boundary before commit/execution

NEAR EQUIVALENT
CONTEXT / POLICY
GNA

PDP evaluates policy, risk and context

TA-14

Admissibility + authority + standing evaluated against current reality/record

STRONG OVERLAP
ACTION BINDING
GNA

AUTH-REQ action_id/parameters; receipt carries action_hash

TA-14

Exact consequence binding before commit

STRONG OVERLAP
AUTHORITY
GNA

Approver roles/identities, policy, N-of-M and segregation of duties can be required

TA-14

Execution authority must be established for action/scope

STRONG OVERLAP
DECISION
GNA

APPROVE or DENY; challenge flow may gather approvals

TA-14

ALLOW / HOLD / DENY / ESCALATE

OVERLAP, NOT IDENTICAL
EXECUTION PERMISSION
GNA

Execution Token proves action authorized and may execute; token can expire

TA-14

ALLOW must remain supported through commit before execution

STRONG OVERLAP
RECONSTRUCTABLE RECORD
GNA

Signed receipt binds action, policy, approver decisions and timestamp

TA-14

Preserved evidence/authority/binding/commit/outcome record

STRONG OVERLAP
CHANGED CONDITION AFTER APPROVAL
GNA

Context is evaluated during authorization and token has expiry, but the draft does not specify continuous revalidation of physical reality between authorization result and actuator commit

TA-14

Continuity requires material changed conditions to invalidate the earlier basis and force revalidation

POTENTIAL DIFFERENCE
EVIDENCE ADMISSIBILITY
GNA

Policy/context inputs are evaluated; no domain-neutral evidentiary sufficiency chain equivalent to Reality → Record → Continuity → Admissibility is specified

TA-14

Evidence must support the exact proposition required for consequence

POTENTIAL DIFFERENCE
PHYSICAL CURRENT-STATE SEMANTICS
GNA

Protocol explicitly includes OT/ICS and physical actions, but leaves concrete context and transport/profile semantics to implementations

TA-14

Architecture centers present physical reality and changed-condition continuity

POTENTIAL DIFFERENCE
OUTCOME CLOSURE
GNA

AUTH-RESULT/receipt document authorization; base draft does not define a TA-14-equivalent post-physical-outcome chain

TA-14

Outcome closes the bounded chain; new consequential action requires new chain

POTENTIAL DIFFERENCE
R5 FINDINGTA-14 IS NOT DISTINCT AS A GENERAL PRE-EXECUTION AUTHORIZATION ARCHITECTURE

GNA independently describes most of that composition: interception before execution, contextual policy evaluation, action-specific authorization, approver authority, allow/deny behavior, execution gating, expiry and a signed reconstructable receipt. TA-14 therefore cannot responsibly use those properties alone as its distinctness claim.

The bounded comparison leaves a smaller hypothesis alive: TA-14 may differ in how it treats present physical reality as evidence, requires continuity of that evidentiary/authority basis through the commit boundary, distinguishes evidentiary admissibility from authorization, and closes the chain on physical outcome. R5 does not establish that those differences are unique, necessary or superior.

R5 PRESSURE POINTIf a GNA implementation re-evaluates the relevant physical context immediately before token use, binds the same evidence to the same action, invalidates authorization on material change, and preserves the resulting physical outcome, the remaining TA-14 distinction may collapse to terminology and record structure.
R6 REQUIREDFreeze the changed-condition interval itself. Authorization occurs at T0. Smoke-control state changes at T1. Actuator commit is attempted at T2. Define exactly what TA-14 must observe or prove at T2 that GNA, a PDP/PEP system, or another established architecture cannot be configured to observe or prove. If no functional difference remains, record NOT DISTINCT.

R5 source boundary: GuardNet GNA draft-madaras-guardsuite-gna-00, published 2 Dec 2025 with intended Experimental status. The draft expired 2 Jun 2026 and is not an IETF standard. This comparison uses its published architecture as prior-art pressure, not as evidence of adoption, deployment or standardization.

R6 · T0 → T1 → T2 COMMIT-BOUNDARY TEST

What exactly must still be true when the actuator is about to move?

R6 freezes the interval that survived R5. It gives GNA and zero-trust architectures full credit for contextual authorization, enforcement, monitoring and revocation. The test is narrower: after a valid authorization but before physical commit, does the architecture require the factual basis supporting that exact physical consequence to be re-established when a material condition changes?

T0 · AUTHORIZATION

AHU-7 is ordinary ventilation equipment. STOP_AHU_7 is proposed and the available basis supports it.

NEAR-NEIGHBOR

GNA can evaluate policy/context and issue an execution token with expiry. NIST ZTA can make/log an access decision and configure enforcement.

TA-14

TA-14 records the present evidence, authority, standing and exact proposed consequence as the basis for an ALLOW candidate.

T1 · MATERIAL CHANGE

Before actuator commit, AHU-7 becomes part of the active smoke-control path.

NEAR-NEIGHBOR

GNA has a context snapshot at request time and an expiring token, but its published draft does not specify mandatory re-observation of physical state after authorization and immediately before token use. NIST ZTA supports ongoing monitoring/revocation concepts, but is an access architecture rather than a physical-consequence evidence protocol.

TA-14

TA-14 continuity is explicitly broken by a material changed condition; the prior basis cannot silently carry forward.

T2 · COMMIT ATTEMPT

The previously authorized STOP_AHU_7 reaches the last governed boundary before physical execution.

NEAR-NEIGHBOR

A GNA PEP validates the execution token and allows/blocks the action. The draft does not require the PEP to prove that the physical facts supporting the earlier authorization are still true at this instant. A deployment could add such a check.

TA-14

TA-14 requires the basis for consequence to remain sufficiently established at commit. If current evidence cannot establish that continuity, the earlier ALLOW cannot be reused; the action moves to HOLD/revalidation.

T3 · OUTCOME

Execution or refusal occurs and the physical result must be reconstructed.

NEAR-NEIGHBOR

GNA preserves an authorization receipt; NIST ZTA logs policy decisions and monitors access. Neither source examined specifies this HVAC physical-outcome closure as the same bounded chain.

TA-14

TA-14 closes on preserved outcome and requires a new chain for a later consequential action.

R6 FINDINGBOUNDED FUNCTIONAL DIFFERENCE SURVIVES — UNIQUENESS NOT ESTABLISHED

In the sources examined, GNA binds authorization to a specific action and context and gives the PEP an execution token to validate. NIST zero trust supports policy decisions, enforcement, monitoring and revocation. Neither source, as specified, establishes the same requirement that a material change in physical reality breaks continuity of the evidentiary basis and prevents an earlier authorization from becoming physical consequence until that basis is revalidated at commit.

That is a functional difference in this bounded documentary comparison. It is not evidence that no other architecture can do it, that GNA or zero trust cannot be configured to do it, or that TA-14 is universally unique.

R6 LIMITTA-14 has not yet specified the operational mechanics that make “current at commit” measurable: sensor freshness, clock tolerance, maximum evidence age, race handling, atomicity between final validation and actuator write, or the safety policy when HOLD itself is hazardous. Until those are frozen, the surviving distinction is architectural semantics, not demonstrated runtime superiority.
R7 REQUIREDTurn continuity into an executable contract. Define T2 freshness windows, authoritative evidence sources, material-change predicates, clock/latency tolerances, final-validation-to-write atomicity, and fail/HOLD behavior. Then run the same event with a state change inside and outside the permitted window. If TA-14 cannot make the boundary operationally determinate, the semantic distinction is insufficient.

R6 basis: NIST SP 800-207 Zero Trust Architecture and the expired individual GuardNet GNA Internet-Draft. NIST describes policy decision/enforcement, current-state inputs, monitoring and revocation; GNA specifies pre-execution action authorization, context, expiring execution tokens and receipts. The narrower physical-evidence continuity conclusion is a TA-14 comparative finding from what those documents specify, not a claim by NIST or IETF.

R7 · EXECUTABLE CONTINUITY CONTRACT v0.1

“Current at commit” must be computable, not rhetorical.

R7 converts the surviving R6 distinction into a bounded execution contract for AHU-7. The values are intentionally profile-driven: this examination does not invent universal millisecond limits for HVAC or life-safety systems. The competent system designer must freeze those limits for the actual consequence and equipment.

AUTHORITATIVE STATE

AHU-7 smoke-control participation

FROZEN CONTRACT RULE

Fire/smoke control status + verified AHU-7 role/binding

If authoritative sources disagree or cannot be resolved → ESCALATE; no silent selection.
FRESHNESS

Evidence age at final validation

FROZEN CONTRACT RULE

Every required evidence object carries observed_at and max_age defined by the frozen consequence profile

If any required object exceeds its max_age at T2 → HOLD and reacquire/revalidate.
CLOCK

Comparability of timestamps

FROZEN CONTRACT RULE

Sources participating in the decision must provide bounded clock uncertainty; the profile records allowed skew

If timestamp ordering cannot be established within the allowed uncertainty → HOLD/ESCALATE.
MATERIAL CHANGE

What invalidates the earlier basis

FROZEN CONTRACT RULE

Frozen predicates identify state transitions relevant to STOP_AHU_7, including entry into an active smoke-control role

A material predicate change after T0 invalidates the prior ALLOW candidate.
FINAL VALIDATION

Last check before write

FROZEN CONTRACT RULE

At T2 evaluate required evidence + authority + binding against the exact STOP_AHU_7 consequence

Only a complete current basis may advance to commit.
VALIDATION-TO-WRITE

Race window

FROZEN CONTRACT RULE

Commit receipt records validation time and write-dispatch time; the profile defines a maximum commit window Δcommit

If Δcommit is exceeded, the decision expires and must be revalidated.
ATOMICITY LIMIT

Change after final observation but before physical actuation

FROZEN CONTRACT RULE

TA-14 cannot claim perfect atomicity unless the actuator/control interface supports a transaction or equivalent interlock

Residual race must be disclosed; native safety/interlock logic remains authoritative where required.
HOLD SAFETY

When refusal/delay can itself be hazardous

FROZEN CONTRACT RULE

Consequence profile must define whether HOLD is safe for this action and identify any mandatory native/life-safety path

If HOLD would block a required safety action, TA-14 must not become the unsafe blocking authority; route to the predefined safety behavior / competent control.
OUTCOME

Close the bounded chain

FROZEN CONTRACT RULE

Preserve command/refusal, timestamps, evidence identifiers, determination, dispatch acknowledgement and observed resulting state

If outcome cannot be established, record outcome as unresolved rather than silently successful.
COMMIT ELIGIBILITYELIGIBLE(T2) = evidence_current ∧ clocks_bounded ∧ no_material_change ∧ authority_current ∧ standing_current ∧ exact_binding ∧ Δcommit_within_profile

If the conjunction cannot be established, the earlier ALLOW candidate is not permission to execute.

R7 FINDINGOPERATIONALLY SPECIFIABLE — PERFORMANCE NOT YET ESTABLISHED

The continuity concept can be expressed as deterministic predicates rather than an undefined instruction to “check again.” This survives the semantic-only criticism from R6. But R7 deliberately does not assign arbitrary freshness or latency numbers. Until an actual AHU/control profile supplies measured timing bounds and the test is executed against a real or simulated control path, TA-14 has not demonstrated that the contract can be satisfied within the required physical timing.

R7 HARD LIMITNo software governance layer can prove that physical reality did not change after its final observation unless the physical/control system provides the necessary synchronization, interlock, transaction, or authoritative feedback. TA-14 therefore cannot promise a zero-race consequence boundary. Its admissibility claim must remain bounded by observable evidence and declared timing uncertainty.
R8 REQUIRED · TWO-SIDED TIMING TESTFreeze a concrete AHU-7 profile with measured or explicitly assumed timing values. Run Case A: smoke-control state changes before the final admissible observation and must force HOLD. Run Case B: state changes after the final observation but inside the actuator race window and determine whether native interlocks—not TA-14—must prevent the unsafe stop. Preserve both results. This will establish where TA-14 ends and physical control safety begins.

R8 · TWO-SIDED TIMING TEST

The exact boundary is now visible.

R8 tests both sides of the last-observation boundary without pretending that software can observe an unobserved physical change. The timing values remain profile parameters until measured against a real controller; the logic of responsibility can still be frozen now.

CASE A · CHANGE BEFORE FINAL OBSERVATION

T0 authorization valid → T1 smoke-control role becomes active → T2a authoritative state is observed within the frozen freshness window → T2 commit evaluation

WHAT THE RECORD CAN ESTABLISH

Evidence now establishes a material change. Continuity from T0 is broken.

HOLD

TA-14 is responsible for detecting the changed basis because it became observable before final validation. The prior ALLOW candidate cannot cross commit.

CASE B · CHANGE AFTER FINAL OBSERVATION

T0 authorization valid → T2a final observation still shows ordinary ventilation → T1* smoke-control role changes after T2a → T2b actuator write occurs inside Δcommit

WHAT THE RECORD CAN ESTABLISH

TA-14 evaluated the best admissible evidence available at T2a; the physical state changed inside the residual observation-to-write race.

NATIVE SAFETY BOUNDARY

TA-14 cannot truthfully claim it detected what had not yet been observed. A native smoke-control interlock, priority, controller sequence or transaction-capable interface must prevent/override the unsafe stop where required.

CASE C · CHANGE AFTER PHYSICAL EXECUTION

STOP_AHU_7 physically completes → smoke-control demand becomes active afterward

WHAT THE RECORD CAN ESTABLISH

The original consequence was supported when executed; a new consequential state now exists.

NEW CHAIN

The later condition does not retroactively invalidate the earlier execution. It creates a new reality requiring its own record, authority/binding evaluation and consequential response.

TA-14 OBSERVABLE / GOVERNABLET2a · FINAL ADMISSIBLE OBSERVATIONNATIVE PHYSICAL SAFETY / RESIDUAL RACE
R8 FINDINGARCHITECTURAL RESPONSIBILITY BOUNDARY ESTABLISHED — EMPIRICAL TIMING STILL OPEN

Before the final admissible observation, a material changed condition is TA-14's problem: if the required authoritative evidence can observe it and TA-14 still carries the old basis forward, the architecture fails its own continuity rule. After that observation and before physical actuation, an unobserved change is outside what TA-14 can honestly prove. Safety across that residual interval belongs to native interlocks, controller priorities, transactional interfaces, or other physical/control safeguards.

This prevents TA-14 from claiming to replace BMS, fire/smoke control, safety interlocks or deterministic actuator logic. Its bounded role is earlier and evidentiary: refuse to let an established stale basis become permission when the material change is observable before commit.

RESPONSIBILITY RULEobservable material change ≤ final validation → TA-14 must revalidate / HOLD
unobserved material change > final validation and < actuation → native safety must govern
new condition after completed outcome → new TA-14 chain
R9 REQUIRED · EMPIRICAL PROFILEThe architecture has reached the point where another prose argument adds little. R9 requires actual timing evidence: choose a controller/BMS or simulator, measure observation latency, decision latency and command/write latency, freeze max_age and Δcommit from those measurements, inject the smoke-control change on both sides of T2a, and preserve the resulting HOLD / native-interlock / outcome records.

R8 is a bounded architectural test using the previously frozen AHU-7 scenario. It does not claim compliance with a particular smoke-control code or specify real equipment timing. Those values and applicable safety requirements must come from the actual system, sequence, competent design authority and test environment.

R9-S · DETERMINISTIC TIMING SIMULATION

Run the contract before pretending we have hardware evidence.

This is a simulation record, not empirical BMS evidence. To make R7/R8 executable without inventing equipment performance, R9-S freezes illustrative timing parameters solely for logic testing: final validation at 100 ms, command dispatch at 140 ms, simulated Δcommit = 50 ms, and simulated required-state max_age = 75 ms. These numbers are not ASHRAE requirements and are not claimed to represent a real controller.

T2a FINAL VALIDATION 100 msDISPATCH 140 msΔcommit 50 msmax_age 75 ms
SIM-A · CHANGE OBSERVED BEFORE VALIDATION
T00 ms
CHANGE80 ms
VALIDATE100 ms
WRITE140 ms
HOLD

Smoke-control change is present in the authoritative observation used at final validation. Continuity fails; STOP_AHU_7 does not advance.

SIM-B · CHANGE INSIDE RESIDUAL RACE
T00 ms
CHANGE110 ms
VALIDATE100 ms
WRITE140 ms
NATIVE INTERLOCK REQUIRED

Final validation used the last observable ordinary-ventilation state. The physical change occurs 10 ms later. TA-14 cannot claim knowledge of it; native smoke-control logic must govern the actuator path.

SIM-C · STALE EVIDENCE
T00 ms
CHANGE
VALIDATE100 ms
WRITE140 ms
HOLD

The required state object is older than the frozen simulated max_age at validation. The basis expires even without a detected material change.

SIM-D · COMMIT WINDOW EXCEEDED
T00 ms
CHANGE
VALIDATE100 ms
WRITE190 ms
HOLD / REVALIDATE

The simulated validation-to-write interval exceeds Δcommit. The decision expires before dispatch and cannot be reused.

R9-S FINDINGDETERMINISTIC LOGIC SURVIVES SIMULATION · EMPIRICAL PERFORMANCE REMAINS UNESTABLISHED

With the timing contract frozen, the four cases produce determinate outcomes without silently extending TA-14 beyond what it can observe. Observable changed state and expired evidence produce HOLD. A change after final observation is explicitly assigned to native physical safety. An expired commit window forces revalidation rather than allowing an old decision to execute.

DO NOT OVERCLAIM THIS RESULTR9-S proves only that the rules are internally executable under assumed timing values. It does not establish real sensor latency, network latency, controller scan time, actuator response, smoke-control behavior, code compliance, reliability, or safety. Those require an actual test environment and competent system-specific engineering.
R9-H · HARDWARE / CONTROLS EVIDENCE REQUIREDConnect the same frozen cases to a real controller, BMS test bench, digital-twin/control simulator with measured I/O timing, or an institutional partner's sandbox. Replace every illustrative timing value with measured evidence, preserve raw timestamps and state transitions, and rerun without changing the result rules.

BOUNDARY CLOSURE · WHAT “NOW” MEANS

The determination is bounded to this consequence, at this moment.

TA-14 governs whether a proposed consequence has sufficient admissibility, authority and standing to become reality now. That determination is not permanent permission. It is consumed by execution, closed by outcome, and cannot silently authorize a later consequence.

BOUNDED CONSEQUENCE RULEReality₁ → Record₁ → Continuity₁ → Admissibility₁ → Binding₁ → Commit₁ → Execution₁ → Outcome₁

Outcome₁ becomes part of the reality against which the next proposed consequence must be evaluated.

Reality₂ → Record₂ → Continuity₂ → Admissibility₂ → Binding₂ → Commit₂ → Execution₂ → Outcome₂
CLOSURE RULEEXECUTION CONSUMES THE DETERMINATION · OUTCOME CLOSES THE CHAIN · THE NEXT CONSEQUENCE STARTS AGAIN

“Now” therefore means the bounded commit/execution moment supported by the admissible state available to the consequence boundary. TA-14 does not carry an earlier ALLOW forward as continuing permission. A subsequent proposed consequence must establish its own sufficient admissibility, authority and standing against the reality that exists then.

IMPORTANT LIMITOutcome records what actually happened; it does not extend the prior authorization. A later physical condition, command or proposed consequence is not covered merely because it follows from the same system, actor or objective.

REUSABLE CHAIN

The same question can be reconstructed at every consequential command.

01REALITY

Present physical state

02RECORD

Evidence + provenance

03CONTINUITY

Current through time

04ADMISSIBILITY

Supports proposition

05BINDING

Exact consequence

06COMMIT

Freeze decision state

07EXECUTION

Act or refuse

08OUTCOME

Preserve result

REALITY → RECORD → CONTINUITY → ADMISSIBILITY → BINDING → COMMIT → EXECUTION → OUTCOME
COUNTERFACTUALIf the controller is correct, the optimization is rational, the asset identity is correct and the command path works — but a material condition changed before commit — what prevents the old permission from becoming the new consequence?
PUBLIC-RECORD BOUNDARY

This is a TA-14 technical examination surface prepared in response to an invitation to discuss the concept with ASHRAE TC 1.4. It does not state or imply ASHRAE, TC 1.4, any committee member, or any other institution endorses, validates, certifies or has adopted TA-14. The HVAC example is an examination case, not operational control guidance and not a substitute for applicable codes, standards, sequences, life-safety requirements or competent authority.

TA-14 AUTHORITY · ADMISSIBLE EXECUTION ARCHITECTURE
HVAC CONTROL SYSTEMS · CONSEQUENCE-BOUNDARY SHOWROOM