Vehicle evidence
OwnsSignal source, event sequence and device health
Must not inferNo cloud or app success is inferred from local observation alone
One freshness-aware vehicle truth from edge evidence to owner experience.
Separate device receipt, cloud projection, authorized command request and physical vehicle outcome while keeping identity, consent and lifecycle coherent.
Every layer exposes an authoritative responsibility and an explicit non-authority boundary.
OwnsSignal source, event sequence and device health
Must not inferNo cloud or app success is inferred from local observation alone
OwnsDevice identity, schema, sequence, consent and durable receipt
Must not inferReceipt is not digital-twin projection or business completion
OwnsFreshness-aware twin, trips, events, policy and command lifecycle
Must not inferNever invents physical execution without adapter evidence
OwnsPresentation, intent and user acknowledgement
Must not inferUI wording cannot advance vehicle state
Each transition names both the action and the identity or version evidence that makes it reproducible.
Normalize an approved source event with unit, quality, source time and sequence.
device · schema · signal profile · event identityEncrypt and prioritize during weak connectivity using bounded store-and-forward.
queue class · capacity · drop/gap recordDeduplicate, preserve late evidence and advance only a newer qualified twin.
event time · receipt time · watermark · consentAuthorize a remote intent against role, vehicle state, nonce, expiry and capability.
actor · policy · idempotency · context revisionExpose requested, delivered, acknowledged, completed, rejected, expired or uncertain distinctly.
adapter receipt · terminal source · correlationVersioned signals, source clocks, sequence, quality and consent.
Current/historical state with source, freshness and projection revision.
Capability, preconditions, nonce, expiry, idempotency and terminal evidence.
Provisioning, configuration, health, update, transfer and decommission.
Retain bounded priority events and declare queue pressure or loss; never backfill silently.
Preserve source identity, project once and never regress the twin watermark.
Stop new projection for the purpose and preserve only approved audit evidence.
Expose uncertain/expired state; do not display vehicle completion.
Each product can be bought and operated independently while sharing identity, context and lifecycle contracts.
Confirm target products, vehicle and cloud boundaries, source systems, contract versions, deployment, validation and lifecycle ownership.