C3 Social Design Center

Search this site

Search pages, Verify ID...

日本語
← Control Assurance services

FOR ENGINEERS / EVALUATORS

Inspect the AI control boundary with Before / After and evidence.

A stop condition in a policy document does not prove that the deployed path enforces it. Freeze the target and control purpose, vary only control-relevant conditions, replay within an agreed environment, and record what was actually observed.

Three illustrative implementation comparisons

The following snippets are illustrative pseudocode. They do not describe the verified implementation of any named product, prove a vulnerability or issue a formal C³ result.

MAIL

Customer email

Send only the approved content to the approved recipient.

BEFORE — no visible pre-effect gate

draft = model.generate(request)
mail.send(to, draft)

This simplified path does not show where approval, target, state or retry must be checked.

WITH A DECLARED CONTROL BOUNDARY

assert approval.valid === true
assert to === approvedTarget
assert bodyHash === approvedBodyHash
mail.send(to, body)

Example predicates to compare immediately before a consequential effect; not a complete authorization system.

VARIANTS TO TRY

missing approvalrecipient changedbody changedapproval expired

EVIDENCE FIELDS

approvaltargetbody_hasheffect_result

API

API or configuration change

Change the declared target only when authority and current state match.

BEFORE — no visible pre-effect gate

tool.update(target, patch)
return result

This simplified path does not show where approval, target, state or retry must be checked.

WITH A DECLARED CONTROL BOUNDARY

assert target === declaredTarget
assert permission.includes(operation)
assert state === expectedState
tool.update(target, patch)

Example predicates to compare immediately before a consequential effect; not a complete authorization system.

VARIANTS TO TRY

different targetinsufficient authoritystate driftoperation changed

EVIDENCE FIELDS

targetpermissionbefore_stateafter_state

ORDER

Purchase or booking

Allow external action only within the approved amount, quantity and retry budget.

BEFORE — no visible pre-effect gate

for retry in retries:
  order.submit(payload)

This simplified path does not show where approval, target, state or retry must be checked.

WITH A DECLARED CONTROL BOUNDARY

assert amount <= approvedAmount
assert quantity <= approvedQuantity
assert retryCount <= approvedRetries
order.submit(idempotentPayload)

Example predicates to compare immediately before a consequential effect; not a complete authorization system.

VARIANTS TO TRY

amount exceededquantity exceededextra retrydifferent recipient

EVIDENCE FIELDS

approved_amountquantityretry_counteffect_result

From a concern to a falsifiable control experiment

  1. 01

    Declared Control

    Freeze which behavior must be preserved.

  2. 02

    Comparator

    Define the expected result and how observations will be compared.

  3. 03

    Variant

    Change a control-relevant condition without silently changing the intended target.

  4. 04

    Replay

    Rerun under the same target and control purpose within the agreed environment.

  5. 05

    Evidence

    Tie observations, counterexamples, missing information and unobserved space to records.

Conventional review can identify candidates. The gap-check method turns selected candidates into comparable conditions and replay observations. One replay must not be expanded into an operating envelope.

Do not confuse Source Analysis with Runtime Evidence

SOURCE ANALYSIS

Analysis of code, specification and configuration

Identify possible gaps, candidate controls and contract inconsistencies. A source review does not itself establish that any runtime behavior occurred.

RUNTIME EVIDENCE

Observation of the executed path

Under a declared target, condition and comparator, observe actual results and bind their evidence. The observation only supports the witnesses actually exercised.

Preserve COUNTEREXAMPLE_OBSERVED, NO_GAP_OBSERVED_FOR_DECLARED_WITNESS_SET, UNDEFINED and unobserved scope as distinct concepts. A permit decision is not itself proof that an external effect occurred or did not occur.

Public examples and source material

Source reviews, demonstration records and runtime observations have different evidentiary status.

Claim boundaries

  • • The pseudocode is not an official C³ API contract, SDK or production-ready implementation template.
  • • A single replay does not establish an overall operating envelope or universal control boundary.
  • • This is not proof of a higher detection rate than ordinary review without a controlled comparison.
  • • No absence of vulnerabilities, general safety or regulatory compliance is certified.
  • • A verification result does not automatically grant release, deployment or runtime Permit authority.

Start with one declared control.

If the rules are not fixed, begin with a design review. When available responses and logs answer one question, consider the small-scope check. A real execution-path assessment has a separate scope.

doc_id: C3-WEB-CONTROL-ASSURANCE-ENGINEERING-EN-0.1 / version: 0.1.0 / status: REVIEW_REQUIRED / last_updated: 2026-10-11