No LockedIn-qualified FDE reaches a client field role on coursework.
No LockedIn-qualified FDE reaches the field without candidate-owned work that was deployed to production, operated against real use, independently reviewed, and transferred with an inspectable evidence chain.
This page describes what the standard requires and what is running today. It does not claim a customer outcome, a placement, a certification body, or an accredited qualification.
- 10
- Conjunctive gates
- 6
- Proof-chain phases
- 5/10
- Capabilities live today
- NOT SET
- Current qualification instrument
One real release, operated, reviewed, and handed over.
At least one exact candidate-owned release must reach a real production environment, serve real users or operators, remain observable long enough to produce operating evidence, and carry a verified rollback or recovery path.
- Exact repository and commit identity
- CI result and immutable build or artifact digest
- Production deployment record and environment identity
- Real-user or real-operator observation with an accountable owner
- Health, outcome, guardrail, cost, and incident evidence
- Rollback or recovery exercise
- Named-owner handoff and teach-back
- Course completion, attendance, or watch time
- A local demo, screenshot, prototype, or unobserved preview
- A simulation or production-equivalent decision without a separate real production release
- A teammate's deployment when the candidate's decisions and ownership are not traceable
- An AI-generated score without cited evidence and independent human review
- D · Diagnose
What consequential workflow and user problem are we actually changing?
- Observed current-state workflow
- User and decision-owner interviews
- Constraints, assumptions, and unknowns
Stop rule. Stop when the problem is only a technology preference or cannot be investigated inside the approved data boundary.
- E · Establish
What outcome, guardrail, authority, and kill condition govern the work?
- Versioned business requirements
- Acceptance and non-acceptance criteria
- Scope, identity, data, risk, and ownership contract
Stop rule. Stop when no accountable business owner can accept, reject, constrain, or terminate the mission.
- P · Prove
What is the smallest repository-backed wedge that can falsify value safely?
- Traceable requirements and architecture decisions
- Working code, tests, evaluations, and threat model
- Pull-request history and disclosed AI assistance
Stop rule. Hold when the evaluator cannot reproduce the exact commit or when a critical requirement has no executable or inspectable evidence.
- L · Land
Can this exact candidate move through a reversible production release?
- Pinned CI and release candidate
- Deployment, approval, migration, and rollback records
- Production smoke result and release provenance
Stop rule. Hold when the deployed artifact cannot be bound to the reviewed commit or rollback is not credible for the change's consequence.
- O · Operate
Does the system create accepted outcomes while its failures remain detectable and containable?
- Health, outcome, adoption, cost, and guardrail signals
- Incident or game-day timeline
- Containment, recovery, and invalidated-gate reruns
Stop rule. Hold when infrastructure health is substituted for user outcome, critical failures are hidden, or no human owns the operating decision.
- Y · Yield
Can a named owner change, recover, and explain the system without hidden FDE intervention?
- Runbook, architecture, known-limits, and escalation package
- Owner-executed change and recovery
- Permission-bounded field memo and after-action review
Stop rule. Hold when the handoff depends on undocumented knowledge, personal credentials, or continued access by the candidate.
| Gate | Weight | Standard |
|---|---|---|
| C01Requirements traceability | CRITICAL | Every material requirement, exclusion, assumption, and acceptance decision is versioned and traceable to implementation and evidence. |
| C02Repository craftsmanship | NONCRITICAL | The exact commit shows coherent branching, reviewable changes, ownership, reproducible setup, dependency discipline, and disclosed AI assistance. |
| C03Architecture and interoperability | CRITICAL | System, identity, data, model, and tool boundaries are explicit; business logic is portable and consequential crossings are owned. |
| C04Testing and AI evaluation | CRITICAL | Deterministic tests, model evaluations, held-out cases, failure clusters, and rerun rules are proportionate to consequence. |
| C05Security, privacy, and authority | CRITICAL | Identity, authorization, secrets, data handling, abuse cases, retention, audit, and human control fail closed under adversarial review. |
| C06Release integrity | CRITICAL | The reviewed commit, CI result, build artifact, approvals, production deployment, and rollback path form one reproducible chain. |
| C07Operability and resilience | CRITICAL | The system exposes meaningful health and outcome signals, bounded cost, alerts, support ownership, and tested containment and recovery. |
| C08Business outcome and adoption | CRITICAL | Real users or operators produce an observed outcome; the record distinguishes adoption, value, guardrails, uncertainty, and the no-build alternative. |
| C09Ownership transfer | CRITICAL | A named owner can operate, change, recover, and explain the system; open risk and debt retain owners and dates. |
| C10Integrated defense | CRITICAL | The candidate defends the evidence chain and adapts under a live requirement change, failure injection, and cross-functional questioning. |
The agent proposes. A person decides.
Deterministic checks and an assessment agent may collect evidence, reproduce checks, and propose cited findings. They cannot issue qualification, waive a gate, resolve a conflict, or turn missing evidence into a pass.
- R1
Deterministic evidence collector
Project review runner
Exact commit, tree, pull requests, checks, test reports, dependency and security records, build provenance, deployment references, and content digests.
Collects facts. No score or decision authority.
- R2
Evidence-citing assessment agent
LockedIn assessment agent
Gate-by-gate proposed scores, cited files and records, contradictions, missing evidence, adversarial probes, and questions for the candidate.
Advisory finding only. Never qualification authority.
- R3
Independent human review
Authorized reviewers
Two evidence-bound decisions, visible disagreement, and separate adjudication when required.
Human gate authority under the active review policy.
- R4
Live integrated defense
Independent panel
Requirement change, failure injection, architecture and risk defense, and a unanimous evidence-bound verdict.
Final project review verdict only; professional qualification remains a separate governed decision.
What is running, what needs a person, and what is not switched on.
Three states and nothing in between. A capability is LIVE only when a reader can open it today, MANUAL when a deliberate human act is required before it does anything, and NOT ACTIVE when it is specified and not switched on.
- LIVE
Published review standard and downloads
The ten-gate standard, its scoring scale, its decision rule, the reviewer pack, and the manifest schema are published and versioned.
Inspect → - LIVE
Exact-commit public repository evidence
A candidate registers an authorized public repository at one exact 40-character commit. The collector accepts no credential, reads a bounded allowlisted text manifest, and binds every file by digest.
Inspect → - LIVE
AI Project Audit against the ten gates
The assessment agent scores each published gate 0–4 with cited files and line ranges. It is advisory by construction: it never returns a pass, and a deterministic collector hold cannot be scored away.
Inspect → - NOT ACTIVE
Human Project Review of a submitted project
The governed workflow is shipped but not activated on this deployment. Activation requires the database-backed intake flag, one effective bounded reviewer authorization selected by private deployment configuration, and an explicitly admitted frozen-instrument submission. Nothing enters a reviewer's queue automatically.
- NOT ACTIVE
Private and continuously connected repository evidence
Specified as a selected-repository, read-only GitHub App with short-lived tokens and no learner-supplied credential. The shipped collector reads authorized public repositories only.
Inspect → - NOT ACTIVE
Live integrated defense panel
The published review stack requires an independent panel, a requirement change, and failure injection under questioning. The panel is specified and is not staffed as a running service.
Inspect → - NOT ACTIVE
FDE-P qualification issuance
Ten evidence gates are mapped, but the current qualification instrument is not preregistered. The 4 published categories describe what a new instrument must define; they are not current reviewer, panel, adjudication, or lifecycle mechanics. Issuance is unavailable, and no completion, audit, or human review issues a qualification today.
Inspect → - LIVE
Public credential verification surface
Issued credentials resolve to a public entry with the evidence trail behind them. The registry currently shows specimens, because issuance is not active.
Inspect → - LIVE
Machine-readable readiness endpoint
A machine-readable readiness endpoint an evaluator can call themselves. It reports which subsystems this deployment has configured. It is operations evidence, not a service-level commitment, an uptime claim, or a customer outcome.
Inspect → - MANUAL
Enterprise engagement and residency
Formation for a client organization is scoped in a signed agreement. Capacity, schedule, staffing, and field evidence are set there, not advertised here.
Inspect →
CURRENT INSTRUMENT NOT PREREGISTERED · NON-ISSUING. 10 evidence gates are mapped. The current instrument is not preregistered; the 4 visible categories describe what a new instrument must define, not current reviewer counts, panel size, adjudication policy, or lifecycle mechanics. Governed qualification issuance is not active.
FDE-S/1.0 v1.0.1 cannot activate through the frozen v2 instrument. A separately preregistered instrument, exact digest binding, reviewer calibration, field authority, and lifecycle controls are required before any qualification decision can operate. These are minimum preregistration categories, not current instrument mechanics. Exact reviewer counts, panel size, adjudication policy, and lifecycle transitions remain unset. This public dossier loads no operating record, so no candidate gate decision or FDE-P standing can issue from it.
Open the evidence yourself. No call, no login.
Each entry is a live surface in this product, not a screenshot standing in for one. Nothing below is fetched while this page renders.
- Standard
FDE Production Project Review standard
Mission classes, the six-phase proof chain, the ten conjunctive gates, the 0–4 scale, and the decision rule.
Open → - Download
Reviewer pack
The authored reviewer pack behind the standard, in Markdown.
Download → - Download
Evidence manifest schema
The JSON Schema an evidence manifest must satisfy before review.
Download → - Download
FDE formation operating kit
How a cohort is formed, supervised, and measured, in Markdown.
Download → - Standard
Qualification constitution and preregistration dossier
The ten current-standard gates, the current-instrument-not-preregistered boundary, and the minimum categories a new instrument must define before qualification can operate.
Open → - Controls
Security posture
Authentication, tenancy, data handling, and the controls behind evidence custody.
Open → - Controls
Privacy and data boundary
What is collected, what is retained, and what is never taken.
Open → - Registry
Public verification surface
Where an issued credential would resolve, and what it would carry.
Open → - Endpoint
Readiness endpoint
A machine-readable readiness endpoint an evaluator can call themselves. It reports which subsystems this deployment has configured. It is operations evidence, not a service-level commitment, an uptime claim, or a customer outcome.
/api/health →
Any reference on this page to Anthropic, Claude, OpenAI, AWS, Google, Microsoft, DXC, or any other company describes a tool a candidate may be trained on, curriculum relevance, or a party we expect to inspect this evidence. It is not a partnership, an authorization, an endorsement, a hiring relationship, a certification, or a claim of any commercial arrangement.
Bring the workflow you would actually stake a quarter on.
Bring a consequential workflow and the authority to accept or reject the result. Scope, capacity, supervision, and evidence terms are agreed in writing before any build work begins.
