CONCEPTS

Concepts and terminology

The stable terms used by PANTAW observations, decisions, safety controls and audit records.

Observation

A structured collector result containing source, ObservationStatus, Severity, optional ReasonCode, target, metadata, timestamp and safe error information.

Status and reason

ObservationStatus values are SUCCESS, FAILURE, PARTIAL, TIMEOUT and UNAVAILABLE. A stable ReasonCode explains the machine-readable cause.

PARTIAL means useful evidence exists but some fields or facilities are unavailable. UNAVAILABLE means the requested source could not provide a usable observation.

Dry-run, SOP and verification

dry_run: true is mandatory. SOPs are declarative approved procedures, not scripts. Execution alone never proves success; verification is a separate architectural requirement.

Audit

Audit is cross-cutting evidence for observations, analysis, triage, authorization, dry-run action records, verification and failures. JSONL and SQLite represent the same logical event model.