Fieldglass® Guided Investigation Architecture

Evidence-Governed Navigation Through Reconstructed Runtime Behavior

Operational evidence does not explain itself.

Logs, transcripts, traces, instrument findings, temporal markers, and reconstructed worldlines may contain the information required to understand a runtime, but they do not tell an operator where to begin, which relationships matter, what evidence supports a finding, or where interpretation must stop.

Most analytical systems assume that the operator already knows which dashboard to open, which metric to trust, and which question to ask. That assumption becomes increasingly fragile as computational systems operate across longer horizons, coordinate through multiple roles and tools, and produce failures that develop gradually rather than appearing as isolated events.

Fieldglass Guided Investigation Architecture provides a structured path through that complexity.

Fieldglass Guided Investigation Architecture organizes evidence authorized by the Current Evidence Run into a sequence of investigative chapters, evidence-bound questions, instrument projections, source trails, and bounded findings—allowing an operator to examine how runtime behavior developed without permitting the interface or investigator to manufacture evidence or exceed the record’s claim boundary.

Its governing principle is:

Guide the investigation. Preserve the operator’s judgment. Never manufacture the conclusion.

From Dashboards to Investigation

A dashboard presents information.

An investigation establishes a disciplined relationship among a question, a finding, the method that produced it, the evidence supporting it, and the limits of what may be concluded.

Fieldglass therefore does not present its instruments as isolated analytical surfaces. It organizes them around one reconstructed runtime and a sequence of questions that can be answered only through the evidence available to the Current Evidence Run.

The architecture moves from:

Evidence display

to

Evidence-guided inquiry

An operator does not simply receive a score or summary. The operator can examine how the finding was formed, identify which instrument produced it, inspect the relevant runtime frame or event, return to the supporting source, and determine whether the interpretation remains within the authorized claim boundary.

The Investigation Path

Guided Investigation establishes a bounded progression through the evidence:

Current Evidence Run
Runtime Reconstruction
Investigative Chapter
Evidence-Bound Question
Instrument Finding
Runtime Frame or Event
Supporting Source Evidence
Bounded Interpretation
Operator Review and Challenge
Preservation

The path is structured, but it is not coercive. Operators retain control over where they begin, which evidence they inspect, which findings they challenge, and whether the available record supports an operational conclusion.

Most importantly, the path is reversible.

A summary must lead back to its finding. A finding must lead back to its measurement and instrument. A measurement must lead back to the runtime coordinates and source evidence from which it was derived.

The operator can therefore move in both directions:

  • forward from evidence toward interpretation; and

  • backward from interpretation toward its evidentiary authority.

Investigative Chapters

Rather than dividing the runtime into unrelated dashboards, Guided Investigation organizes it into chapters. Each chapter addresses a distinct class of questions while examining the same canonical runtime.

Evidence Formation

What source was supplied? How was it qualified and canonicalized? What was computed? What remains unavailable? What claim boundary governs the run?

Worldline Formation

What observable trajectory formed across the record? Which events, roles, frames, transitions, and temporal markers define its development?

Runtime Formation

What patterns of continuity, recurrence, interaction, modulation, and re-anchoring became observable? Which findings support those patterns?

Stability and Transition

Where did weakening, pressure, drift, containment loss, regime transition, or recovery become observable? Did those conditions persist?

Failure Formation

What evidence supports candidate boundary formation, confirmed Basin Exit, post-exit development, or observable failure? Which markers are computed, and which are source-supplied?

Recovery and Re-entry

Did the trajectory sustainably re-establish coherent organization, or did only temporary surface correction occur?

Operational Interpretation

What do the supported findings mean within the selected Operational World? Which conclusions require external context or human authority?

Preservation

What evidence, findings, investigation state, provenance, disclosures, and claim boundaries can be sealed for reproduction and independent review?

These chapters do not impose a predetermined narrative. They establish an orderly set of observation surfaces through which the runtime can be examined.

Evidence-Bound Questions

Every investigative chapter is organized around explicit questions.

Examples include:

  • What trajectory is supported by the record?

  • When did weakening first become observable?

  • Which roles, events, or tool interactions accompanied the transition?

  • Did displacement accumulate or contract?

  • Was Basin Exit computed under the declared boundary method?

  • Is an observable failure marker available?

  • Is formal Lead-Time admissible?

  • Did apparent recovery persist across subsequent activity?

  • Which findings are unavailable because required evidence is missing?

  • Which conclusions remain outside the claim boundary?

Each question has an evidentiary contract. It must identify the evidence required, the instrument or method authorized to answer it, the applicable coordinate system, and the limits of the resulting finding.

Questions direct attention. They do not predetermine answers.

Binding Questions to Instruments

Guided Investigation connects each question to the instruments capable of providing relevant measurements and findings.

For example:

  • Seismo supports inspection of the worldline, disturbances, boundary formation, transition, and recovery posture.

  • Chronos supports inspection of temporal ordering, recurrence, compression, symbolic-time development, and marker relationships.

  • Drift supports inspection of displacement, persistence, attractor pull, recurrence loss, and recovery anchoring.

  • Pressure supports inspection of runtime strain, boundary load, collapse-precursor support, and recovery reserve.

  • Scope supports inspection of topology, containment, basin geometry, and possible recovery corridors.

  • Noesis supports inspection of observable recursive formation, modulation, continuity, and re-anchoring.

  • Bridge translates supported scientific findings into bounded operational significance.

The investigation layer does not recompute these findings or create an independent interpretation of the runtime. It routes the operator to findings already authorized by the Current Evidence Run and connects those findings to their supporting evidence.

The investigation may contain many questions and many instruments, but it remains governed by one runtime and one evidence authority.

Evidence Trails

Every material finding should remain inspectable through an evidence trail.

An operator should be able to move from:

Chapter summary
Instrument finding
Runtime frame
Recorder event
Source span

This prevents the interface from becoming the authority.

A visualization may help an operator perceive a pattern, but the visualization does not establish that the pattern exists. Its authority comes from the evidence object, declared computation, instrument contract, and source lineage beneath it.

When supporting evidence is incomplete, the architecture must preserve that absence. It cannot silently substitute an estimate, convert missing evidence into zero, or present a candidate condition as confirmed.

Relationship to REIM

The Runtime Evidence Interpretation Matrix evaluates authorized findings to establish an evidence-supported posture and recommend where investigation should begin.

Guided Investigation provides the environment through which that recommendation is examined.

REIM identifies a supported investigative posture. Guided Investigation provides the path through which the evidence is inspected.

REIM may route attention toward temporal formation, drift, role coordination pressure, tool-loop pressure, boundary formation, recovery, or a multi-factor incident. It does not close the investigation, establish cause, assign blame, or replace operator judgment.

Its classifications remain versioned, heuristic, and subordinate to the same evidence authority as the instruments they summarize.

Operational World Context

The same runtime may be investigated within software engineering, security operations, cloud infrastructure, workflow coordination, monitoring, research validation, or another supported Operational World.

That context may change:

  • the terminology used to introduce a finding;

  • the questions emphasized first;

  • the recommended instrument sequence;

  • the operational examples presented;

  • and the way supported significance is explained.

It cannot change:

  • the canonical runtime;

  • the telemetry;

  • the temporal markers;

  • instrument findings;

  • regime or Basin Exit computation;

  • evidence-support status;

  • claim boundaries;

  • or deterministic evidence identity.

The Operational World gives the investigation context. It does not give the evidence a different meaning.

Relationship to the Adaptive Evidence Cockpit

Guided Investigation defines the structure of the inquiry. The Adaptive Evidence Cockpit determines how that inquiry is presented to a particular operator.

The cockpit may alter:

  • the recommended starting chapter;

  • navigation emphasis;

  • question order;

  • explanatory depth;

  • terminology;

  • visible instrument priority;

  • and information density.

Guided Investigation preserves:

  • chapter contracts;

  • evidence requirements;

  • instrument findings;

  • runtime coordinates;

  • marker authority;

  • source lineage;

  • and claim boundaries.

Guided Investigation structures the inquiry. The Adaptive Evidence Cockpit changes how that inquiry is presented. Neither changes the evidence.

Evidence Distillation

At the conclusion of a chapter, Fieldglass may distill the evidence into a compact investigative summary.

Evidence distillation can identify:

  • the strongest supported findings;

  • the evidence authority behind them;

  • the instruments that contributed;

  • the applicable confidence posture;

  • material missing evidence;

  • unresolved contradictions;

  • and the boundary beyond which interpretation cannot proceed.

Distillation does not create telemetry or introduce new scientific findings. It makes the existing evidence easier to inspect without separating the summary from its lineage.

Operator Judgment and Challenge

Guided Investigation supports human judgment; it does not automate it away.

The operator can:

  • inspect the evidence supporting a transition;

  • compare findings across instruments;

  • challenge a classification;

  • review unresolved or contradictory evidence;

  • distinguish observed, computed, and interpreted information;

  • add authorized investigative context;

  • and determine whether an operational conclusion requires information outside Fieldglass.

This is particularly important when the evidence establishes sequence or association but does not establish cause.

Fieldglass may show that drift preceded a boundary transition, that role pressure accompanied instability, or that a tool loop persisted during collapse. It cannot infer hidden intent, determine blame, or establish unique causation from those relationships alone.

Preserving the Investigation

During active analysis, the Current Evidence Run remains the computational authority.

When the investigation is completed, its evidence-bearing state may be preserved through a Certified Runtime Evidence Record, accompanied by its Runtime Evidence Passport, provenance, disclosures, authorized findings, claim boundaries, and preservation lineage.

The preserved artifact may include:

  • the canonical runtime;

  • reconstructed worldline and frames;

  • authorized instrument findings;

  • temporal markers and coordinate definitions;

  • chapter state;

  • reviewed evidence trails;

  • operator-supplied context identified as such;

  • unresolved evidence;

  • claim boundaries;

  • and preservation metadata.

Preservation does not certify that every interpretation is true. It preserves what was supplied, computed, reviewed, and claimed—and the authority under which each element exists.

The Architectural Contribution

Guided workflows, dashboards, and investigation checklists already exist. The distinctive Fieldglass contribution is their integration within a source-bound, evidence-governed runtime architecture.

In this architecture:

  • questions are connected to explicit evidence requirements;

  • every chapter examines the same canonical reconstruction;

  • instruments remain subordinate to one evidence authority;

  • findings retain navigable source trails;

  • adaptive presentation cannot change computation;

  • unavailable evidence remains explicitly unavailable;

  • operator judgment remains visible and reviewable;

  • and the completed investigation can be preserved with its provenance and claim boundary.

Guided Investigation therefore does more than make Fieldglass easier to use. It establishes the disciplined pathway through which complex runtime evidence becomes understandable without becoming detached from its source.

Fieldglass does not merely show operators what its instruments found. It provides an evidence-governed path from investigative question to runtime finding, from finding to source, and from source to the limits of what can responsibly be concluded.