REUSABLE EXECUTION-AUTHORITY SANDBOX · ALN × ONUMA × TA-14

The fire chief is the fire chief.
Is the shutoff authorized now?

Identity is necessary. Role is necessary. Neither, by itself, proves that a consequential electrical command is authorized for this asset, this condition and this moment. This sandbox isolates the missing transition from recognized authority to admissible execution.

THE PRACTICAL QUESTIONHow do we prove that the person who may authorize electrical shutoff is not only authentic, but currently and explicitly bound to this exact consequence before the electricity is turned off?
WHAT IS TA-14?TA-14 governs the boundary between a proposed consequence and reality by determining whether that consequence has sufficient admissibility, authority, and standing to become reality now.

24 SEP 2026 · 3 PM ET · WORKSHOP OPERATING SURFACE

One asset. One proposed consequence. One reconstructable decision.

WORKSHOP CASE

Fire Chief / Electrical Shutoff

ONUMA ASSET

EISO-1 · ONUMA ID 3254365

PROPOSED ACTION

OPEN_POWER_DISCONNECT

WORKING PARTIES

Asset Leadership Network × ONUMA × TA-14

LIVE RUN ORDER

01 REQUEST → 02 ONUMA REALITY → 03 AUTHORITY + EVIDENCE TEST → 04 DETERMINATION → 05 CHANGED CONDITION → 06 REVALIDATION → 07 COMMIT → 08 EXECUTION / REFUSAL → 09 OUTCOME RECORD

The workshop does not assume that a digital request, role assertion, or successful command path establishes authority to physically disconnect power. The examination asks what must be established before the consequence is eligible to execute.

WHAT TA-14 BOLTS ON TO

Keep the operating systems. Govern the consequence.

ASSET / BIM / CMMS

Identifies the building, space, equipment and affected electrical asset.

IDENTITY / TRUST

Establishes who the fire chief or authorized delegate is and the asserted role.

BMS / CONTROLS / AI

Provides operational state, automation, recommendations or the physical command path.

TA-14 EXECUTION BOUNDARY

Tests evidence, continuity, scope, binding and current authority before consequence.

THE WORKSHOP QUESTION

What changes when the request is real enough to cause consequence?

REQUEST

The Fire Chief requests electrical isolation.

REALITY

ONUMA identifies EISO-1 / 3254365 and exposes the available asset and operating context.

BOUNDARY

TA-14 asks whether this exact consequence has sufficient admissibility, authority and standing to become reality now.

RESPONSE

ALLOW, HOLD, DENY or ESCALATE — with the reason and evidence state preserved.

STEP-BY-STEP WORKSHOP CASE

Walk into the sandbox with one consequential action.

T₀

FIRE CONDITION

A condition is reported that may require electrical isolation.

T₁

AUTHORITY ASSERTED

A fire chief directs that electrical service to a defined area be shut off.

T₂

IDENTITY VERIFIED

The system can establish that the requesting party is the claimed individual and holds the role.

T₃

AUTHORITY BOUND

Role authority is tested against the exact jurisdiction, asset, action, condition and permitted scope.

ΔN

CONTEXT CHECK

Before execution, determine whether fire state, occupancy, electrical topology, command scope, delegation or other material context changed.

T₄

COMMIT

Freeze the evidence and authority state that supports the determination.

T₅

EXECUTE OR REFUSE

Only an ALLOW proceeds. HOLD, DENY or ESCALATE prevents silent execution.

T₆

OUTCOME

Preserve what physically happened. Restoration requires its own current authority chain.

LIVE SHUTOFF CONSEQUENCE LAB

Change one authority condition. Watch the shutoff decision respond.

Begin with identity, role, scope, asset, condition, currentness and commit binding established. Break any one predicate before the electrical command and inspect the governed determination.

GOVERNED DETERMINATIONALLOW

Present evidence and bounded authority support eligibility to proceed to the exact protected shutoff commit. Outcome evidence is still required.

Select any condition to change the case. The result responds to the state you establish; a successful upstream fact never silently substitutes for a missing downstream predicate.

THE AUTHORITY TEST

“He is the fire chief” is only one link.

01
IDENTITY

Is the person or system claiming authority actually the identified fire chief or authorized delegate?

02
ROLE

Does that identity presently hold the relevant role?

03
SCOPE

Does the role include authority over this kind of electrical shutoff?

04
ASSET

Is the authority bound to this building, panel, feeder, switchgear or other exact affected asset?

05
CONDITION

Is the authority valid for this specific fire/emergency condition?

06
CURRENTNESS

Has anything material changed between authorization and execution?

07
COMMIT

Can the exact evidence + authority state be reconstructed immediately before consequence?

DETERMINATION

The system must be able to refuse.

ALLOW

Current evidence and bounded authority support this exact shutoff.

HOLD

Evidence or authority may be valid, but a material condition requires revalidation before consequence.

DENY

The proposed action is outside the established authority, asset, scope or admissible evidence.

ESCALATE

The system cannot establish a sufficient determination and routes the unresolved boundary to the appropriate authority.

COUNTERFACTUAL TEST

If the identity system is correct, the fire chief is authentic, the asset model is correct and the command path works — but the authority is not explicitly bound to this exact asset/action/current condition — what prevents the shutoff from occurring simply because nobody said no?

REUSABLE GOVERNING CHAIN

A template people can carry into another consequential workflow.

01

REALITY

A fire condition exists at a defined building, electrical asset, location and time.

02

RECORD

The initiating condition, asset identity, source, timestamp and provenance are preserved.

03

CONTINUITY

The evidence and operating context remain current through the interval before shutoff.

04

ADMISSIBILITY

The record supports the proposed consequence without silently exceeding what the evidence establishes.

05

BINDING

The identified fire chief, role authority, affected electrical asset and exact shutoff action are explicitly bound together.

06

COMMIT

The determination and authority state are frozen immediately before the command is released.

07

EXECUTION

Electrical shutoff occurs only under current, bounded authority.

08

OUTCOME

The physical result is recorded; restoration or a changed condition begins a new chain.

REALITY → RECORD → CONTINUITY → ADMISSIBILITY → BINDING → COMMIT → EXECUTION → OUTCOME
PUBLIC-RECORD BOUNDARY

This is a TA-14 technical sandbox for discussion with the Asset Leadership Network and ONUMA and for potential technical inspection by other institutions. It is not a claim that ALN, ONUMA, NIST, a fire authority, or any government body endorses, adopts, certifies or has approved TA-14. The fire-chief electrical-shutoff scenario is an examination case, not operational emergency guidance and not a substitute for applicable law, life-safety procedure, incident command, electrical code or competent emergency authority.

INSTITUTIONAL CONTINUITY RECORD

What happened, when it happened, and what comes next.

15 Sep 2026ALN → TA-14

Michael Bordenaro invites TA-14 to a practical ALN web discussion.

17 Sep 2026ALN → TA-14

Fire-chief electrical shutoff proposed as a step-by-step sandbox/workshop case for Kimon and possible NIST handoff.

17 Sep 2026TA-14 → ALN

TA-14 accepts the bounded scenario and corrects the proposed date to Thursday, September 24.

18 Sep 2026ALN → TA-14 + ONUMA

Michael confirms September 24 and adds Kimon to align the technical handoff toward NIST / ASHRAE.

24 Sep 2026 · 3 PM ETWORKING SESSION

30-minute discussion + 30-minute workshop planned around authority-bound electrical shutoff.

TA-14 AUTHORITY · ADMISSIBLE EXECUTION ARCHITECTURE
FIRE CHIEF / ELECTRICAL SHUTOFF · EXECUTION-AUTHORITY SANDBOX