CONCEPTS
Concepts and terminology
The stable terms used by PANTAW observations, decisions, safety controls and audit records.
Observation
A structured collector result containing source, ObservationStatus, Severity, optional ReasonCode, target, metadata, timestamp and safe error information.
Status and reason
ObservationStatus values are SUCCESS, FAILURE, PARTIAL, TIMEOUT and UNAVAILABLE. A stable ReasonCode explains the machine-readable cause.
PARTIAL means useful evidence exists but some fields or facilities are unavailable. UNAVAILABLE means the requested source could not provide a usable observation.
Dry-run, SOP and verification
dry_run: true is mandatory. SOPs are declarative approved procedures, not scripts. Execution alone never proves success; verification is a separate architectural requirement.
Audit
Audit is cross-cutting evidence for observations, analysis, triage, authorization, dry-run action records, verification and failures. JSONL and SQLite represent the same logical event model.