Capture
OwnsSensor clocks, trigger proposal and protected media window
Must not inferTrigger is not human judgment
Preserve trigger, clocks, media policy and custody without turning inference into fact.
Keep sensor trigger proposals, protected media windows, privacy representation, retrieval, human disposition, export preparation and legal hold as distinct revisioned states.
Every layer exposes an authoritative responsibility and an explicit non-authority boundary.
OwnsSensor clocks, trigger proposal and protected media window
Must not inferTrigger is not human judgment
OwnsRoad/cabin masking, metadata and eligible preview
Must not inferMedia reference never grants media access
OwnsImmutable trigger lineage, retrieval, review and custody state
Must not inferRetrieval receipt is not file export
OwnsAccountable disposition appended to evidence
Must not inferReviewer cannot rewrite source trigger
Each transition names both the action and the identity or version evidence that makes it reproducible.
Combine allowlisted sensor signals with source and monotonic clocks.
trigger/source/version · clocks · correlationPin bounded pre/post media under retention/storage policy.
segment refs · integrity · overwrite classApply role, purpose, cabin/road policy and masking before access.
policy decision · representation IDAppend human disposition at an exact evidence revision.
reviewer · reason · revision · evidence refsCreate export/custody intent only after required review and authorization.
manifest/hash · approver · no durable public URLSignals, clocks, window, device/config and integrity.
Road/cabin policy, masking, metadata and access decision.
Exact evidence revision, actor, disposition and immutable trigger.
Export preparation, hold, device health, update and rollback.
Declare unavailable/degraded capture without fabricating preview.
Protect configured windows and name overwritten unprotected segments.
Retain acknowledged chunks or mark incomplete; do not create custody.
Expose authorized metadata only; never leak bytes or durable URL.
Each product can be bought and operated independently while sharing identity, context and lifecycle contracts.
Confirm target products, vehicle and cloud boundaries, source systems, contract versions, deployment, validation and lifecycle ownership.