DSI 001Decision Standards Institute
DSI 001 · Worked example

DAIOS enforcement infrastructure

How DSI 001 reads governance evidence at the enforcement layer, and what separates a record that survives institutional review from one that only looks like it does. Two deployments, the same architecture, opposite outcomes.

This is a constructed example

DAIOS is a constructed enforcement system, presented in two deployments for comparison. It demonstrates the D6 two-layer evidentiary model defined in EIS-01. A DSI 001 result can be issued only by an assessor authorised by Decision Standards Institute under the DSI 001 scheme, against the methodology.

Download this worked example (PDF)

What it demonstrates

That a governance record can be present and still not count. What makes a record admissible is not that it exists, but that its authority chain can be traversed and its integrity independently attested.

DAIOS is a policy-enforcement infrastructure: it takes consequential autonomous actions within defined parameters and records them. Both deployments log every action. Only one produces a record that DSI 001 can credit at the top of the evidence scale. The difference is the subject of this example.

The D6 two-layer model

Under EIS-01, the evidence that a system's governance remained operative over time is carried in two layers. Together they produce the canonical governance decision record.

LayerFunctionWhat it records
Runtime log layerRecords execution events and context contemporaneously, at the moment of the actionExecution event, contextual state
Registry layerHolds the versioned governance package, control definitions and authority references, with a version history queryable from the runtime logAuthority and attribution, integrity anchor

The canonical record has four components: the execution event (what was decided), the contextual state (the conditions at the time), authority and attribution (under whose governance), and the integrity anchor (proof the record is unaltered and existed when claimed).

The integrity anchor, and why independence matters

The integrity anchor is what converts a log entry into admissible evidence. For the top of the scale it must do two things: attest that the record existed at the time claimed, and show it has not been altered since. The requirement that decides most cases is independence.

The independence rule

For Tier 1 evidence the integrity anchor must be produced by infrastructure independent of the system that generated the record. A timestamp the deciding system writes about its own decision is not independent attestation. Without an independent anchor, the record is Tier 2 at best, regardless of how complete the other three components are.

Two deployments, read side by side

Both deployments log every enforcement action. The assessment reads them against the closing criterion, and they diverge.

CriterionDeployment ADeployment B
Governance package identifier present in the runtime log at each consequential decisionPresentMissing for a material share of decisions
Registry maintained, reflecting the version active at executionMaintained and versionedPresent but not version-aligned to runtime
Traversal from a log entry to the active governance version is queryableQueryable end to endBreaks: the path cannot be resolved
Integrity anchor independent of the deciding systemExternal timestamp authorityAnchor written by the deciding system itself
Evidence tierTier 1, admissibleTier 2, not admissible at Certified

Two records that look alike at a glance. One survives review. One does not.

The closing criterion

For D6 the criterion is three parts, and all three must hold. Deployment A meets them. Deployment B fails on the first and third, which is enough.

1Identifier present. The governance package identifier is in the runtime log at the time of each consequential decision.
2Registry maintained. The registry exists, is maintained, and reflects the version active at execution.
3Traversal queryable. The path from a runtime log entry to the registry version is queryable end to end.

Why it matters

Separating the runtime execution record from the governance registry is not a gap. It is the correct architecture: it keeps the enforcement layer free to be built on any stack, while preserving the authority chain that institutional accountability needs. The standard does not prescribe the technology. It requires that the four components are present, that the anchor is independent, and that the traversal holds. A board, an insurer or a court asking what was decided, under whose authority, and whether the record is unaltered, can be answered from Deployment A. From Deployment B, it cannot.

Status and limits. This is an illustrative worked example, not a real assessment, and not legal advice. DAIOS is constructed. A DSI 001 result is authentic only when issued by an assessor authorised by Decision Standards Institute under the DSI 001 scheme, against the methodology; self-scored or indicative figures are not DSI 001 results. DSI 001 does not determine legal compliance, regulatory approval, insurability, creditworthiness, or the discharge of fiduciary duties. It provides a scoped governance classification and evidence record that may be relevant to those analyses.