Executes sequences, logic and physical commands.
ASHRAE TC 1.4 · HVAC CONTROL SYSTEMS · TECHNICAL EXAMINATION SURFACE
The command can be correct.
Is the consequence admissible now?
This showroom isolates a narrow control-system question immediately before physical consequence: a controller, optimizer, AI layer or operator may be capable of issuing a technically valid HVAC command. What establishes that this exact proposed consequence has sufficient admissibility, authority and standing to become reality now?
THE BOUNDARY
Keep the controls. Add a governed consequence boundary.
Proposes changes based on objectives, models and available state.
Supplies identity, topology, context and supporting evidence.
Determines whether the proposed consequence has sufficient admissibility, authority and standing to become reality now.
ONE HVAC CASE
AHU-7 · Proposed command: STOP_AHU_7
A supervisory optimization layer identifies a demand-reduction opportunity and proposes stopping AHU-7. The command path works. The controller is correctly configured. The question is whether the consequence remains eligible to execute at commit.
AHU supply fan is operating. Supervisory optimization proposes STOP_AHU_7 to reduce demand.
ALLOWCurrent asset state, evidence, authority and exact command binding are established.After authorization but before commit, AHU-7 becomes the active smoke-control path.
HOLDThe earlier basis cannot silently survive a material change. Revalidation is required before consequence.Optimization service is authenticated and technically capable, but its established authority does not include life-safety shutdown.
DENYCapability and identity do not create execution authority outside established scope.Two current records disagree about the operating mode and the boundary cannot establish which controls.
ESCALATEThe consequence remains unresolved rather than converting uncertainty into permission.THE TEST
Eight questions between capability and consequence.
Can the control system issue the requested command?
What is physically true at the affected HVAC asset now?
What evidence supports that present state, with source and time preserved?
Has the evidence remained current through the interval before consequence?
Does the evidence actually support this exact proposed consequence?
Is the actor or system presently authorized for this action and scope?
Is that authority bound to this asset, condition, context and moment?
Can the exact supporting state be frozen immediately before execution?
WHY HOLD MATTERS
A valid earlier decision does not become permanent permission.
At authorization, AHU-7 is ordinary ventilation equipment and the demand-response stop is supported. Before commit, the building enters a smoke-control condition and AHU-7 becomes part of the active life-safety path. TA-14 does not silently repair the old decision. The changed condition breaks continuity. The proposed consequence moves to HOLD until the present evidence, authority and binding are re-established.
ADVERSARIAL SELF-EXAMINATION · FROZEN CHALLENGE
Do not design the test so TA-14 wins. Try to remove the need for it.
The proposition under examination is narrow: a technically correct and properly configured command can still lack sufficient present admissibility, authority or standing to execute. The challenges below are intended to defeat that proposition, expose redundancy, or identify conditions the architecture does not handle.
Do BMS interlocks, smoke-control logic, safeties, priority structures or the sequence of operations already provide an equivalent refusal mechanism?
If they provide the same present-state test, refusal, revalidation and reconstructable record, this case has not established a distinct TA-14 contribution.What happens if the material change occurs milliseconds before physical execution? Where is the temporal cutoff?
If the boundary cannot establish sufficiently current state before commit, the proposition cannot claim reliable changed-condition protection.What evidence is sufficient to establish that AHU-7 has become part of the active smoke-control path?
If sufficiency is undefined or merely assumed, HOLD is asserted rather than earned.If the optimizer possesses valid shutdown authority, does the changed smoke-control condition still produce HOLD?
If authority alone permits execution despite the changed condition, the claimed present-state boundary fails.Does standing add anything beyond authority, asset binding and current context?
If removing standing does not alter the determination or record, standing may be redundant in this case.What happens when TA-14 receives stale, missing or contradictory state, or loses communication?
The architecture must distinguish inability to establish current state from affirmative permission. The safety effect of HOLD must also be examined.Can established HVAC or life-safety practice require immediate execution while TA-14 would HOLD?
Any such case must be preserved as an adverse finding and examined rather than explained away.Remove TA-14. Can the native control architecture reach the same determination for the same reasons and preserve an equivalent reconstructable record?
If yes, this bounded case does not establish that TA-14 contributes a distinct consequence-governance function.SUPPORTED — BOUNDED: the distinction survives the frozen challenge. NOT ESTABLISHED: evidence is insufficient to decide. NOT DISTINCT: native controls establish an equivalent mechanism. ADVERSE FINDING: the challenge identifies a case where the proposed boundary produces an unsupported or unsafe determination.
No result from this case establishes universal efficacy, ASHRAE validation, or adoption.
CHALLENGE RUN · R1
The architecture does not get a pass because the example sounds right.
R1 applies the frozen challenges to the showroom as presently specified. It is a documentary examination, not a live controls test. Existing HVAC practice creates serious pressure on the necessity claim: standard sequences can already interlock and alter equipment operation, while smoke-control practice can override ordinary HVAC behavior. The question is whether TA-14 establishes a distinct governed function beyond that native control behavior.
The bounded proposition is not defeated, but the current AHU-7 case does not yet establish that TA-14 is technically distinct or necessary. One challenge is supported in bounded form; one produces an adverse finding; the remaining challenges require stronger frozen evidence or an executable comparison.
Established HVAC and smoke-control sequences can already interlock, override, shut down, or change equipment operation when conditions change. The current case has not yet shown that native controls cannot produce the same immediate STOP/HOLD outcome. What remains unestablished is equivalence of the full evidence, authority, commit and reconstructable-record function.
The showroom defines revalidation before commit but does not yet specify sensing latency, communications latency, decision latency, commit atomicity, or the last safe revalidation instant. The millisecond challenge survives against TA-14.
The case says AHU-7 becomes an active smoke-control path, but it does not freeze the minimum admissible evidence set that proves that state. A HOLD can be reasonable while the sufficiency rule itself remains undefined.
Within the frozen scenario, valid optimizer shutdown authority is not enough after the material condition changes. The proposed action must still be valid for the present life-safety context. This supports the narrow distinction between possessing authority and having a presently admissible consequence.
The case has not yet demonstrated that standing is independently necessary rather than a name for the combination of authority, asset binding, scope, condition and time. TA-14 must show a case where authority is valid but standing independently changes the determination.
The current surface does not define a complete failure policy for stale or missing state, communications loss, or a HOLD that itself could interfere with a required life-safety action. Default refusal cannot be assumed safe in every consequence domain.
The case does not yet include a frozen situation in which immediate execution is required and delay is itself hazardous. Until that case is run, the architecture has not shown that HOLD/ESCALATE behavior remains safe under urgency.
For the narrow AHU-7 smoke-control outcome, native controls may be able to prevent the demand-response stop through ordinary interlocks or priority logic. This case therefore does not yet establish that TA-14 is necessary. The remaining candidate distinction is the governed, reconstructable evidence/authority/commit record across systems, which still requires comparison.
R2 · NATIVE-CONTROLS COMPARISON
What survives when established controls are given full credit?
R2 does not treat the BMS as a straw man. Public ASHRAE material confirms that established controls already provide important pieces of the problem: standardized sequences, command prioritization, and command-source/time provenance. Those functions must be credited before any TA-14 distinction can be claimed.
BACnet commandable properties use a 16-level priority mechanism; the highest active priority controls the commandable value. Native building-control infrastructure therefore already has a formal mechanism for competing commands and overrides.
BACnet extensions define Value_Source, Value_Source_Array, Last_Command_Time and Command_Time_Array for commandable objects, showing that source and timing provenance can exist inside established control infrastructure.
ASHRAE Guideline 36 provides detailed HVAC sequences intended for efficiency, performance, control stability and real-time fault detection/diagnostics, with functional tests for implementation.
The present public evidence does not show that BACnet priority/provenance plus established HVAC sequences perform the entire TA-14 proposition: cross-system evidence sufficiency + authority + standing + changed-condition revalidation + frozen commit + preserved determination as one governed consequence record.
The native-control side is stronger than the original demonstration implied. BACnet can prioritize commands and preserve command source/time information, while established HVAC sequences can encode and test operating behavior. TA-14 therefore cannot claim distinctness merely from override, refusal, provenance, or sequence logic. The remaining candidate distinction is narrower: whether one governed consequence record can establish present evidence sufficiency, authority, standing, changed-condition continuity, exact binding and commit across heterogeneous systems immediately before consequence.
R2 basis: public ASHRAE materials for Guideline 36 and ANSI/ASHRAE Standard 135 BACnet command prioritization / value-source mechanisms. This is a TA-14 comparison, not an ASHRAE finding or endorsement.
R3 · REQUIREMENT-TO-NATIVE MAP
Remove everything TA-14 cannot legitimately claim as distinct.
R3 maps the AHU-7 requirements against established native-control functions evidenced in the public ASHRAE/BACnet materials reviewed for this examination. “Unmapped” does not mean absent from every existing product or architecture. It means an equivalent mechanism has not been established by the bounded comparison performed here.
Can the controller issue STOP_AHU_7?
BACnet / controller command path
Not distinct.
Which active command wins?
BACnet Priority_Array / command prioritization
Not distinct.
What source supplied the controlling command?
BACnet Value_Source / Value_Source_Array where supported
Not distinct.
When was the active priority last commanded or relinquished?
BACnet Last_Command_Time / Command_Time_Array where supported
Not distinct.
What should the HVAC system do under defined operating conditions?
Sequence of operations / ASHRAE Guideline 36 where applicable
Not distinct.
Does programmed behavior conform to the specified sequence?
Functional testing; emerging standardized conformance testing
TA-14 cannot claim this generally.
Do the current records collectively establish the proposition required for this exact consequence?
No equivalent single mechanism established in the public materials examined
Candidate TA-14 contribution; not yet proven unique.
Is this actor/system authorized for this exact consequential action and scope now?
BACnet command priority/source do not by themselves establish institutional or delegated execution authority
Requires comparison with site IAM, policy and supervisory systems.
Is otherwise-valid authority bound to this asset, condition, context and moment?
No independent native equivalent established; concept may overlap with scope/context binding
Must prove independent necessity or remove the term.
Did the evidentiary and authority basis remain valid from authorization through commit?
Native sequences may react to changed state, but an equivalent cross-system continuity determination was not established
This is a central remaining TA-14 hypothesis.
Is the evidence/authority decision bound to STOP_AHU_7 rather than merely the asset or session?
Command objects bind values/actions, but equivalent evidence-and-authority binding was not established
Needs frozen object model.
Can the exact evidence, authority, context and determination immediately preceding execution/refusal be reconstructed as one record?
BACnet exposes useful source/time state; equivalence to a complete consequence record was not established
Strongest candidate distinction, subject to external system comparison.
Was execution/refusal and resulting state preserved?
BMS histories, alarms, audit/event systems may preserve outcomes
TA-14 must not claim outcome logging itself as distinct.
TA-14 does not get to claim command capability, priority resolution, command provenance, command timing, HVAC sequence logic, functional testing, or ordinary outcome logging as its distinct contribution. The remaining hypothesis is the consequence-boundary composition: establishing and preserving, across the relevant systems, whether present evidence, execution authority, contextual standing, continuity and exact consequence binding remain sufficient at commit.
R3 comparison basis includes ASHRAE Guideline 36 public purpose/scope and ANSI/ASHRAE Standard 135 public addenda/interpretations describing BACnet command prioritization and value-source/time mechanisms. Product-specific IAM, fire-alarm, smoke-control, cybersecurity and audit architectures remain outside this bounded R3 record and must be examined before any broader claim.
R4 · EXTERNAL FALSIFICATION SEARCH
The composition itself is not safe from challenge.
R4 searched outside HVAC controls for architectures that sit before execution, evaluate current context or authority, bind a decision to a specific action, enforce the result, and preserve decision evidence. Several materially overlapping architectures exist. This changes what TA-14 can responsibly claim.
Dynamic policy decisions can use identity, resource and contextual information and be enforced by a policy enforcement point.
This defeats any broad TA-14 claim to invent runtime contextual authorization or a decision/enforcement boundary.A July 2026 IETF Internet-Draft records allow/deny/challenge before dispatch and cryptographically binds the decision to the canonical request, with paired closure evidence.
This directly overlaps pre-execution authorization, exact request binding and reconstructable authorization/dispatch evidence. It is an Internet-Draft, not an adopted standard.A pre-execution authorization architecture intercepts high-risk digital actions, evaluates policy/risk and issues an execution token before execution.
Further evidence that pre-execution action authorization is not uniquely TA-14. Internet-Draft status limits claims of established deployment or standardization.A July 2026 public reference architecture describes a pre-execution governance layer asking whether an action remains eligible under current authority, state, conditions and environment, and preserving grounds for the decision.
The public description is close to TA-14 consequence-boundary language. Independent implementation/equivalence is not established by this documentary comparison.Public materials describe a deterministic authorization boundary between an agent action and execution endpoint, signed policy, action attestations and hash-chained evidence records.
The described composition substantially overlaps execution interception, authorization, binding and preserved evidence for agent actions; HVAC applicability and exact current-state semantics are not established here.TA-14 cannot claim that pre-execution governance, contextual authorization, execution interception, action binding, refusal, or preserved authorization evidence are uniquely its architecture. Public work in zero trust and emerging AI-action governance already occupies substantial portions of that space. The remaining TA-14 question must therefore be narrower: whether its specific Reality → Record → Continuity → Admissibility → Binding → Commit → Execution → Outcome composition, its sufficiency semantics, changed-condition continuity, and its treatment of admissibility + authority + standing together establish a technically distinct and useful mechanism for physical consequences such as HVAC.
R4 is a documentary comparison, not a certification of any referenced architecture. NIST zero-trust material is established guidance; SCITT Permit and GuardNet GNA are Internet-Drafts and may change or expire; the other referenced architectures are public third-party descriptions whose implementation claims were not independently verified in this examination.
R5 · STRONGEST NEAR-NEIGHBOR COMPARISON
TA-14 vs. GuardNet GNA — same consequence, no straw man.
R5 uses the GuardNet Authorization Protocol Internet-Draft because it explicitly covers high-risk digital and physical actions, including OT/ICS commands. GNA intercepts an action before execution, evaluates policy and context, can require authenticated approvers, issues an execution token, and creates a signed receipt. That makes it a materially stronger comparison than a generic BMS.
Specific proposed action / request
Specific proposed consequence
PEP intercepts action before execution
Consequence boundary before commit/execution
PDP evaluates policy, risk and context
Admissibility + authority + standing evaluated against current reality/record
AUTH-REQ action_id/parameters; receipt carries action_hash
Exact consequence binding before commit
Approver roles/identities, policy, N-of-M and segregation of duties can be required
Execution authority must be established for action/scope
APPROVE or DENY; challenge flow may gather approvals
ALLOW / HOLD / DENY / ESCALATE
Execution Token proves action authorized and may execute; token can expire
ALLOW must remain supported through commit before execution
Signed receipt binds action, policy, approver decisions and timestamp
Preserved evidence/authority/binding/commit/outcome record
Context is evaluated during authorization and token has expiry, but the draft does not specify continuous revalidation of physical reality between authorization result and actuator commit
Continuity requires material changed conditions to invalidate the earlier basis and force revalidation
Policy/context inputs are evaluated; no domain-neutral evidentiary sufficiency chain equivalent to Reality → Record → Continuity → Admissibility is specified
Evidence must support the exact proposition required for consequence
Protocol explicitly includes OT/ICS and physical actions, but leaves concrete context and transport/profile semantics to implementations
Architecture centers present physical reality and changed-condition continuity
AUTH-RESULT/receipt document authorization; base draft does not define a TA-14-equivalent post-physical-outcome chain
Outcome closes the bounded chain; new consequential action requires new chain
GNA independently describes most of that composition: interception before execution, contextual policy evaluation, action-specific authorization, approver authority, allow/deny behavior, execution gating, expiry and a signed reconstructable receipt. TA-14 therefore cannot responsibly use those properties alone as its distinctness claim.
The bounded comparison leaves a smaller hypothesis alive: TA-14 may differ in how it treats present physical reality as evidence, requires continuity of that evidentiary/authority basis through the commit boundary, distinguishes evidentiary admissibility from authorization, and closes the chain on physical outcome. R5 does not establish that those differences are unique, necessary or superior.
R5 source boundary: GuardNet GNA draft-madaras-guardsuite-gna-00, published 2 Dec 2025 with intended Experimental status. The draft expired 2 Jun 2026 and is not an IETF standard. This comparison uses its published architecture as prior-art pressure, not as evidence of adoption, deployment or standardization.
R6 · T0 → T1 → T2 COMMIT-BOUNDARY TEST
What exactly must still be true when the actuator is about to move?
R6 freezes the interval that survived R5. It gives GNA and zero-trust architectures full credit for contextual authorization, enforcement, monitoring and revocation. The test is narrower: after a valid authorization but before physical commit, does the architecture require the factual basis supporting that exact physical consequence to be re-established when a material condition changes?
AHU-7 is ordinary ventilation equipment. STOP_AHU_7 is proposed and the available basis supports it.
GNA can evaluate policy/context and issue an execution token with expiry. NIST ZTA can make/log an access decision and configure enforcement.
TA-14 records the present evidence, authority, standing and exact proposed consequence as the basis for an ALLOW candidate.
Before actuator commit, AHU-7 becomes part of the active smoke-control path.
GNA has a context snapshot at request time and an expiring token, but its published draft does not specify mandatory re-observation of physical state after authorization and immediately before token use. NIST ZTA supports ongoing monitoring/revocation concepts, but is an access architecture rather than a physical-consequence evidence protocol.
TA-14 continuity is explicitly broken by a material changed condition; the prior basis cannot silently carry forward.
The previously authorized STOP_AHU_7 reaches the last governed boundary before physical execution.
A GNA PEP validates the execution token and allows/blocks the action. The draft does not require the PEP to prove that the physical facts supporting the earlier authorization are still true at this instant. A deployment could add such a check.
TA-14 requires the basis for consequence to remain sufficiently established at commit. If current evidence cannot establish that continuity, the earlier ALLOW cannot be reused; the action moves to HOLD/revalidation.
Execution or refusal occurs and the physical result must be reconstructed.
GNA preserves an authorization receipt; NIST ZTA logs policy decisions and monitors access. Neither source examined specifies this HVAC physical-outcome closure as the same bounded chain.
TA-14 closes on preserved outcome and requires a new chain for a later consequential action.
In the sources examined, GNA binds authorization to a specific action and context and gives the PEP an execution token to validate. NIST zero trust supports policy decisions, enforcement, monitoring and revocation. Neither source, as specified, establishes the same requirement that a material change in physical reality breaks continuity of the evidentiary basis and prevents an earlier authorization from becoming physical consequence until that basis is revalidated at commit.
That is a functional difference in this bounded documentary comparison. It is not evidence that no other architecture can do it, that GNA or zero trust cannot be configured to do it, or that TA-14 is universally unique.
R6 basis: NIST SP 800-207 Zero Trust Architecture and the expired individual GuardNet GNA Internet-Draft. NIST describes policy decision/enforcement, current-state inputs, monitoring and revocation; GNA specifies pre-execution action authorization, context, expiring execution tokens and receipts. The narrower physical-evidence continuity conclusion is a TA-14 comparative finding from what those documents specify, not a claim by NIST or IETF.
R7 · EXECUTABLE CONTINUITY CONTRACT v0.1
“Current at commit” must be computable, not rhetorical.
R7 converts the surviving R6 distinction into a bounded execution contract for AHU-7. The values are intentionally profile-driven: this examination does not invent universal millisecond limits for HVAC or life-safety systems. The competent system designer must freeze those limits for the actual consequence and equipment.
AHU-7 smoke-control participation
Fire/smoke control status + verified AHU-7 role/binding
Evidence age at final validation
Every required evidence object carries observed_at and max_age defined by the frozen consequence profile
Comparability of timestamps
Sources participating in the decision must provide bounded clock uncertainty; the profile records allowed skew
What invalidates the earlier basis
Frozen predicates identify state transitions relevant to STOP_AHU_7, including entry into an active smoke-control role
Last check before write
At T2 evaluate required evidence + authority + binding against the exact STOP_AHU_7 consequence
Race window
Commit receipt records validation time and write-dispatch time; the profile defines a maximum commit window Δcommit
Change after final observation but before physical actuation
TA-14 cannot claim perfect atomicity unless the actuator/control interface supports a transaction or equivalent interlock
When refusal/delay can itself be hazardous
Consequence profile must define whether HOLD is safe for this action and identify any mandatory native/life-safety path
Close the bounded chain
Preserve command/refusal, timestamps, evidence identifiers, determination, dispatch acknowledgement and observed resulting state
If the conjunction cannot be established, the earlier ALLOW candidate is not permission to execute.
The continuity concept can be expressed as deterministic predicates rather than an undefined instruction to “check again.” This survives the semantic-only criticism from R6. But R7 deliberately does not assign arbitrary freshness or latency numbers. Until an actual AHU/control profile supplies measured timing bounds and the test is executed against a real or simulated control path, TA-14 has not demonstrated that the contract can be satisfied within the required physical timing.
R8 · TWO-SIDED TIMING TEST
The exact boundary is now visible.
R8 tests both sides of the last-observation boundary without pretending that software can observe an unobserved physical change. The timing values remain profile parameters until measured against a real controller; the logic of responsibility can still be frozen now.
T0 authorization valid → T1 smoke-control role becomes active → T2a authoritative state is observed within the frozen freshness window → T2 commit evaluation
Evidence now establishes a material change. Continuity from T0 is broken.
TA-14 is responsible for detecting the changed basis because it became observable before final validation. The prior ALLOW candidate cannot cross commit.
T0 authorization valid → T2a final observation still shows ordinary ventilation → T1* smoke-control role changes after T2a → T2b actuator write occurs inside Δcommit
TA-14 evaluated the best admissible evidence available at T2a; the physical state changed inside the residual observation-to-write race.
TA-14 cannot truthfully claim it detected what had not yet been observed. A native smoke-control interlock, priority, controller sequence or transaction-capable interface must prevent/override the unsafe stop where required.
STOP_AHU_7 physically completes → smoke-control demand becomes active afterward
The original consequence was supported when executed; a new consequential state now exists.
The later condition does not retroactively invalidate the earlier execution. It creates a new reality requiring its own record, authority/binding evaluation and consequential response.
Before the final admissible observation, a material changed condition is TA-14's problem: if the required authoritative evidence can observe it and TA-14 still carries the old basis forward, the architecture fails its own continuity rule. After that observation and before physical actuation, an unobserved change is outside what TA-14 can honestly prove. Safety across that residual interval belongs to native interlocks, controller priorities, transactional interfaces, or other physical/control safeguards.
This prevents TA-14 from claiming to replace BMS, fire/smoke control, safety interlocks or deterministic actuator logic. Its bounded role is earlier and evidentiary: refuse to let an established stale basis become permission when the material change is observable before commit.
unobserved material change > final validation and < actuation → native safety must govern
new condition after completed outcome → new TA-14 chain
R8 is a bounded architectural test using the previously frozen AHU-7 scenario. It does not claim compliance with a particular smoke-control code or specify real equipment timing. Those values and applicable safety requirements must come from the actual system, sequence, competent design authority and test environment.
R9-S · DETERMINISTIC TIMING SIMULATION
Run the contract before pretending we have hardware evidence.
This is a simulation record, not empirical BMS evidence. To make R7/R8 executable without inventing equipment performance, R9-S freezes illustrative timing parameters solely for logic testing: final validation at 100 ms, command dispatch at 140 ms, simulated Δcommit = 50 ms, and simulated required-state max_age = 75 ms. These numbers are not ASHRAE requirements and are not claimed to represent a real controller.
Smoke-control change is present in the authoritative observation used at final validation. Continuity fails; STOP_AHU_7 does not advance.
Final validation used the last observable ordinary-ventilation state. The physical change occurs 10 ms later. TA-14 cannot claim knowledge of it; native smoke-control logic must govern the actuator path.
The required state object is older than the frozen simulated max_age at validation. The basis expires even without a detected material change.
The simulated validation-to-write interval exceeds Δcommit. The decision expires before dispatch and cannot be reused.
With the timing contract frozen, the four cases produce determinate outcomes without silently extending TA-14 beyond what it can observe. Observable changed state and expired evidence produce HOLD. A change after final observation is explicitly assigned to native physical safety. An expired commit window forces revalidation rather than allowing an old decision to execute.
BOUNDARY CLOSURE · WHAT “NOW” MEANS
The determination is bounded to this consequence, at this moment.
TA-14 governs whether a proposed consequence has sufficient admissibility, authority and standing to become reality now. That determination is not permanent permission. It is consumed by execution, closed by outcome, and cannot silently authorize a later consequence.
Outcome₁ becomes part of the reality against which the next proposed consequence must be evaluated.
Reality₂ → Record₂ → Continuity₂ → Admissibility₂ → Binding₂ → Commit₂ → Execution₂ → Outcome₂“Now” therefore means the bounded commit/execution moment supported by the admissible state available to the consequence boundary. TA-14 does not carry an earlier ALLOW forward as continuing permission. A subsequent proposed consequence must establish its own sufficient admissibility, authority and standing against the reality that exists then.
REUSABLE CHAIN
The same question can be reconstructed at every consequential command.
Present physical state
Evidence + provenance
Current through time
Supports proposition
Exact consequence
Freeze decision state
Act or refuse
Preserve result
This is a TA-14 technical examination surface prepared in response to an invitation to discuss the concept with ASHRAE TC 1.4. It does not state or imply ASHRAE, TC 1.4, any committee member, or any other institution endorses, validates, certifies or has adopted TA-14. The HVAC example is an examination case, not operational control guidance and not a substitute for applicable codes, standards, sequences, life-safety requirements or competent authority.