Fieldglass® Guided Investigation Architecture
Evidence-Governed Navigation Through Reconstructed Runtime Behavior
Operational evidence does not explain itself.
Logs, transcripts, traces, instrument findings, temporal markers, and reconstructed worldlines may contain the information required to understand a runtime, but they do not tell an operator where to begin, which relationships matter, what evidence supports a finding, or where interpretation must stop.
Most analytical systems assume that the operator already knows which dashboard to open, which metric to trust, and which question to ask. That assumption becomes increasingly fragile as computational systems operate across longer horizons, coordinate through multiple roles and tools, and produce failures that develop gradually rather than appearing as isolated events.
Fieldglass Guided Investigation Architecture provides a structured path through that complexity.
Fieldglass Guided Investigation Architecture organizes evidence authorized by the Current Evidence Run into a sequence of investigative chapters, evidence-bound questions, instrument projections, source trails, and bounded findings—allowing an operator to examine how runtime behavior developed without permitting the interface or investigator to manufacture evidence or exceed the record’s claim boundary.
Its governing principle is:
Guide the investigation. Preserve the operator’s judgment. Never manufacture the conclusion.
From Dashboards to Investigation
A dashboard presents information.
An investigation establishes a disciplined relationship among a question, a finding, the method that produced it, the evidence supporting it, and the limits of what may be concluded.
Fieldglass therefore does not present its instruments as isolated analytical surfaces. It organizes them around one reconstructed runtime and a sequence of questions that can be answered only through the evidence available to the Current Evidence Run.
The architecture moves from:
Evidence display
to
Evidence-guided inquiry
An operator does not simply receive a score or summary. The operator can examine how the finding was formed, identify which instrument produced it, inspect the relevant runtime frame or event, return to the supporting source, and determine whether the interpretation remains within the authorized claim boundary.
The Investigation Path
Guided Investigation establishes a bounded progression through the evidence:
Current Evidence Run
→ Runtime Reconstruction
→ Investigative Chapter
→ Evidence-Bound Question
→ Instrument Finding
→ Runtime Frame or Event
→ Supporting Source Evidence
→ Bounded Interpretation
→ Operator Review and Challenge
→ Preservation
The path is structured, but it is not coercive. Operators retain control over where they begin, which evidence they inspect, which findings they challenge, and whether the available record supports an operational conclusion.
Most importantly, the path is reversible.
A summary must lead back to its finding. A finding must lead back to its measurement and instrument. A measurement must lead back to the runtime coordinates and source evidence from which it was derived.
The operator can therefore move in both directions:
forward from evidence toward interpretation; and
backward from interpretation toward its evidentiary authority.
Investigative Chapters
Rather than dividing the runtime into unrelated dashboards, Guided Investigation organizes it into chapters. Each chapter addresses a distinct class of questions while examining the same canonical runtime.
Evidence Formation
What source was supplied? How was it qualified and canonicalized? What was computed? What remains unavailable? What claim boundary governs the run?
Worldline Formation
What observable trajectory formed across the record? Which events, roles, frames, transitions, and temporal markers define its development?
Runtime Formation
What patterns of continuity, recurrence, interaction, modulation, and re-anchoring became observable? Which findings support those patterns?
Stability and Transition
Where did weakening, pressure, drift, containment loss, regime transition, or recovery become observable? Did those conditions persist?
Failure Formation
What evidence supports candidate boundary formation, confirmed Basin Exit, post-exit development, or observable failure? Which markers are computed, and which are source-supplied?
Recovery and Re-entry
Did the trajectory sustainably re-establish coherent organization, or did only temporary surface correction occur?
Operational Interpretation
What do the supported findings mean within the selected Operational World? Which conclusions require external context or human authority?
Preservation
What evidence, findings, investigation state, provenance, disclosures, and claim boundaries can be sealed for reproduction and independent review?
These chapters do not impose a predetermined narrative. They establish an orderly set of observation surfaces through which the runtime can be examined.
Evidence-Bound Questions
Every investigative chapter is organized around explicit questions.
Examples include:
What trajectory is supported by the record?
When did weakening first become observable?
Which roles, events, or tool interactions accompanied the transition?
Did displacement accumulate or contract?
Was Basin Exit computed under the declared boundary method?
Is an observable failure marker available?
Is formal Lead-Time admissible?
Did apparent recovery persist across subsequent activity?
Which findings are unavailable because required evidence is missing?
Which conclusions remain outside the claim boundary?
Each question has an evidentiary contract. It must identify the evidence required, the instrument or method authorized to answer it, the applicable coordinate system, and the limits of the resulting finding.
Questions direct attention. They do not predetermine answers.
Binding Questions to Instruments
Guided Investigation connects each question to the instruments capable of providing relevant measurements and findings.
For example:
Seismo supports inspection of the worldline, disturbances, boundary formation, transition, and recovery posture.
Chronos supports inspection of temporal ordering, recurrence, compression, symbolic-time development, and marker relationships.
Drift supports inspection of displacement, persistence, attractor pull, recurrence loss, and recovery anchoring.
Pressure supports inspection of runtime strain, boundary load, collapse-precursor support, and recovery reserve.
Scope supports inspection of topology, containment, basin geometry, and possible recovery corridors.
Noesis supports inspection of observable recursive formation, modulation, continuity, and re-anchoring.
Bridge translates supported scientific findings into bounded operational significance.
The investigation layer does not recompute these findings or create an independent interpretation of the runtime. It routes the operator to findings already authorized by the Current Evidence Run and connects those findings to their supporting evidence.
The investigation may contain many questions and many instruments, but it remains governed by one runtime and one evidence authority.
Evidence Trails
Every material finding should remain inspectable through an evidence trail.
An operator should be able to move from:
Chapter summary
→ Instrument finding
→ Runtime frame
→ Recorder event
→ Source span
This prevents the interface from becoming the authority.
A visualization may help an operator perceive a pattern, but the visualization does not establish that the pattern exists. Its authority comes from the evidence object, declared computation, instrument contract, and source lineage beneath it.
When supporting evidence is incomplete, the architecture must preserve that absence. It cannot silently substitute an estimate, convert missing evidence into zero, or present a candidate condition as confirmed.
Relationship to REIM
The Runtime Evidence Interpretation Matrix evaluates authorized findings to establish an evidence-supported posture and recommend where investigation should begin.
Guided Investigation provides the environment through which that recommendation is examined.
REIM identifies a supported investigative posture. Guided Investigation provides the path through which the evidence is inspected.
REIM may route attention toward temporal formation, drift, role coordination pressure, tool-loop pressure, boundary formation, recovery, or a multi-factor incident. It does not close the investigation, establish cause, assign blame, or replace operator judgment.
Its classifications remain versioned, heuristic, and subordinate to the same evidence authority as the instruments they summarize.
Operational World Context
The same runtime may be investigated within software engineering, security operations, cloud infrastructure, workflow coordination, monitoring, research validation, or another supported Operational World.
That context may change:
the terminology used to introduce a finding;
the questions emphasized first;
the recommended instrument sequence;
the operational examples presented;
and the way supported significance is explained.
It cannot change:
the canonical runtime;
the telemetry;
the temporal markers;
instrument findings;
regime or Basin Exit computation;
evidence-support status;
claim boundaries;
or deterministic evidence identity.
The Operational World gives the investigation context. It does not give the evidence a different meaning.
Relationship to the Adaptive Evidence Cockpit
Guided Investigation defines the structure of the inquiry. The Adaptive Evidence Cockpit determines how that inquiry is presented to a particular operator.
The cockpit may alter:
the recommended starting chapter;
navigation emphasis;
question order;
explanatory depth;
terminology;
visible instrument priority;
and information density.
Guided Investigation preserves:
chapter contracts;
evidence requirements;
instrument findings;
runtime coordinates;
marker authority;
source lineage;
and claim boundaries.
Guided Investigation structures the inquiry. The Adaptive Evidence Cockpit changes how that inquiry is presented. Neither changes the evidence.
Evidence Distillation
At the conclusion of a chapter, Fieldglass may distill the evidence into a compact investigative summary.
Evidence distillation can identify:
the strongest supported findings;
the evidence authority behind them;
the instruments that contributed;
the applicable confidence posture;
material missing evidence;
unresolved contradictions;
and the boundary beyond which interpretation cannot proceed.
Distillation does not create telemetry or introduce new scientific findings. It makes the existing evidence easier to inspect without separating the summary from its lineage.
Operator Judgment and Challenge
Guided Investigation supports human judgment; it does not automate it away.
The operator can:
inspect the evidence supporting a transition;
compare findings across instruments;
challenge a classification;
review unresolved or contradictory evidence;
distinguish observed, computed, and interpreted information;
add authorized investigative context;
and determine whether an operational conclusion requires information outside Fieldglass.
This is particularly important when the evidence establishes sequence or association but does not establish cause.
Fieldglass may show that drift preceded a boundary transition, that role pressure accompanied instability, or that a tool loop persisted during collapse. It cannot infer hidden intent, determine blame, or establish unique causation from those relationships alone.
Preserving the Investigation
During active analysis, the Current Evidence Run remains the computational authority.
When the investigation is completed, its evidence-bearing state may be preserved through a Certified Runtime Evidence Record, accompanied by its Runtime Evidence Passport, provenance, disclosures, authorized findings, claim boundaries, and preservation lineage.
The preserved artifact may include:
the canonical runtime;
reconstructed worldline and frames;
authorized instrument findings;
temporal markers and coordinate definitions;
chapter state;
reviewed evidence trails;
operator-supplied context identified as such;
unresolved evidence;
claim boundaries;
and preservation metadata.
Preservation does not certify that every interpretation is true. It preserves what was supplied, computed, reviewed, and claimed—and the authority under which each element exists.
The Architectural Contribution
Guided workflows, dashboards, and investigation checklists already exist. The distinctive Fieldglass contribution is their integration within a source-bound, evidence-governed runtime architecture.
In this architecture:
questions are connected to explicit evidence requirements;
every chapter examines the same canonical reconstruction;
instruments remain subordinate to one evidence authority;
findings retain navigable source trails;
adaptive presentation cannot change computation;
unavailable evidence remains explicitly unavailable;
operator judgment remains visible and reviewable;
and the completed investigation can be preserved with its provenance and claim boundary.
Guided Investigation therefore does more than make Fieldglass easier to use. It establishes the disciplined pathway through which complex runtime evidence becomes understandable without becoming detached from its source.
Fieldglass does not merely show operators what its instruments found. It provides an evidence-governed path from investigative question to runtime finding, from finding to source, and from source to the limits of what can responsibly be concluded.
