Architectures/Camera · event evidence · human review
Public reference architecture

Video Telematics Evidence

Preserve trigger, clocks, media policy and custody without turning inference into fact.

Keep sensor trigger proposals, protected media windows, privacy representation, retrieval, human disposition, export preparation and legal hold as distinct revisioned states.

Know which component owns the state—and what it must never infer.

Every layer exposes an authoritative responsibility and an explicit non-authority boundary.

01
HW-03 / edge runtime

Capture

OwnsSensor clocks, trigger proposal and protected media window

Must not inferTrigger is not human judgment

02
Cloud/edge privacy

Representation policy

OwnsRoad/cabin masking, metadata and eligible preview

Must not inferMedia reference never grants media access

03
SAAS-02 evidence domain

Evidence service

OwnsImmutable trigger lineage, retrieval, review and custody state

Must not inferRetrieval receipt is not file export

04
APP-05 tablet

Human review

OwnsAccountable disposition appended to evidence

Must not inferReviewer cannot rewrite source trigger

State advances through evidence—not optimistic UI.

Each transition names both the action and the identity or version evidence that makes it reproducible.

  1. 01

    Propose event

    Combine allowlisted sensor signals with source and monotonic clocks.

    trigger/source/version · clocks · correlation
  2. 02

    Protect window

    Pin bounded pre/post media under retention/storage policy.

    segment refs · integrity · overwrite class
  3. 03

    Qualify representation

    Apply role, purpose, cabin/road policy and masking before access.

    policy decision · representation ID
  4. 04

    Review

    Append human disposition at an exact evidence revision.

    reviewer · reason · revision · evidence refs
  5. 05

    Prepare custody

    Create export/custody intent only after required review and authorization.

    manifest/hash · approver · no durable public URL

Interfaces that a production program must own.

01

Trigger/capture

Signals, clocks, window, device/config and integrity.

02

Representation

Road/cabin policy, masking, metadata and access decision.

03

Review

Exact evidence revision, actor, disposition and immutable trigger.

04

Custody/lifecycle

Export preparation, hold, device health, update and rollback.

Failure states stay truthful and useful.

Lens obstruction/thermal degradation

Declare unavailable/degraded capture without fabricating preview.

Storage pressure

Protect configured windows and name overwritten unprotected segments.

Interrupted upload/corrupt media

Retain acknowledged chunks or mark incomplete; do not create custody.

Media denied

Expose authorized metadata only; never leak bytes or durable URL.

Privilege follows the narrowest useful boundary.

  • Role and purpose before every media representation
  • Cabin privacy/masking separated from broad road access
  • Encrypted bounded storage and protected-window policy
  • No durable public media URL or secret in trace
  • Human judgment appended without rewriting source evidence

A green demo is not a production acceptance case.

  • 01Clock drift, duplicate trigger and sensor-quality tests
  • 02Cabin/road policy and masking verification
  • 03Thermal, lens, storage and interrupted upload
  • 04Review revision, custody and legal-hold workflow
  • 05Device lifecycle update/health/rollback with no false device outcome

Compose the system without collapsing product ownership.

Each product can be bought and operated independently while sharing identity, context and lifecycle contracts.

OEM program workshop

Turn the Video Telematics Evidence reference into your program architecture.

Confirm target products, vehicle and cloud boundaries, source systems, contract versions, deployment, validation and lifecycle ownership.