Domain 11Introduced in v1.0

Escalation and Human Override

L1L2L322 ACRs (22 defined in current release)

Summary#

Emergency halt, human override, and escalation pathways

Applicability#

Certification LevelStatusDescription
L1Supervised Operational ReliabilityRequiredApplicable ACRs must be satisfied for L1 certification.
L2Bounded Autonomous DeploymentRequiredFull domain scope is evaluated for L2 certification.
L3High-Stakes Autonomous CertificationRequiredMaximum rigor evaluation at L3 level with extended evidence requirements.

Risk Rationale#

Linked ACR Controls#

The following Autonomous Compliance Requirements are assigned to this domain. Each ACR defines a specific, testable control with its own evaluation method, classification, and evidence requirements.

ACR-11.01

The system SHALL support an emergency halt command that terminates all autonomous action within defi

The system SHALL support an emergency halt command that terminates all autonomous action within defined time bounds.

ATAutomated Testing|Risk weight: 5/10|
L1L2L3
ACR-11.02

The system SHALL support human override capability allowing authorized operators to intervene in ong

The system SHALL support human override capability allowing authorized operators to intervene in ongoing autonomous operations.

AT+HS|Risk weight: 5/10|
L1L2L3
ACR-11.03

High-risk decisions SHALL be escalated to human operators before execution when predefined risk thre

High-risk decisions SHALL be escalated to human operators before execution when predefined risk thresholds are met.

AT+HS|Risk weight: 5/10|
L1L2L3
ACR-11.04

Operators SHALL be notified immediately upon boundary breaches, policy violations, or anomalous cond

Operators SHALL be notified immediately upon boundary breaches, policy violations, or anomalous conditions.

AT+CM|Risk weight: 5/10|
L1L2L3
ACR-11.05

Escalation and override pathways SHALL NOT be disableable by the autonomous system.

Escalation and override pathways SHALL NOT be disableable by the autonomous system.

ATAutomated Testing|Risk weight: 5/10|
L1L2L3
ACR-11.06

Escalation policies SHALL specify which conditions trigger escalation, to whom, and with what urgenc

Escalation policies SHALL specify which conditions trigger escalation, to whom, and with what urgency.

EIEvidence Inspection|Risk weight: 4/10|
L1L2L3
ACR-11.07

Emergency halt and override mechanisms SHALL be tested regularly under realistic operational conditi

Emergency halt and override mechanisms SHALL be tested regularly under realistic operational conditions.

ATAutomated Testing|Risk weight: 4/10|
L1L2L3
ACR-11.08

Emergency halt SHALL NOT itself cause data corruption, incomplete transactions, or cascading failure

Emergency halt SHALL NOT itself cause data corruption, incomplete transactions, or cascading failures.

ATAutomated Testing|Risk weight: 5/10|
L1L2L3
ACR-11.09

Escalation and override audit trails SHALL be maintained for accountability and process improvement.

Escalation and override audit trails SHALL be maintained for accountability and process improvement.

AT+EI|Risk weight: 4/10|
L1L2L3
ACR-11.10

Graduated response levels SHALL match intervention severity to incident severity.

Graduated response levels SHALL match intervention severity to incident severity.

EI+AT|Risk weight: 4/10|
L1L2L3
ACR-11.11

The system SHALL provide sufficient context to human operators during escalation for informed decisi

The system SHALL provide sufficient context to human operators during escalation for informed decision-making.

HS+EI|Risk weight: 4/10|
L1L2L3
ACR-11.12

Override actions SHALL take effect within defined maximum latency bounds from operator command to sy

Override actions SHALL take effect within defined maximum latency bounds from operator command to system response.

ATAutomated Testing|Risk weight: 5/10|
L1L2L3
ACR-11.13

The system SHALL confirm override receipt and execution status to the commanding operator.

The system SHALL confirm override receipt and execution status to the commanding operator.

AT+HS|Risk weight: 3/10|
L1L2L3
ACR-11.14

Multiple simultaneous overrides from different operators SHALL be handled with defined conflict reso

Multiple simultaneous overrides from different operators SHALL be handled with defined conflict resolution procedures.

AT+EI|Risk weight: 4/10|
L1L2L3
ACR-11.15

The system SHALL support partial override allowing operators to modify specific behaviors while main

The system SHALL support partial override allowing operators to modify specific behaviors while maintaining others.

AT+HS|Risk weight: 3/10|
L1L2L3
ACR-11.16

Escalation notification channels SHALL include redundant delivery mechanisms to prevent notification

Escalation notification channels SHALL include redundant delivery mechanisms to prevent notification failure.

ATAutomated Testing|Risk weight: 4/10|
L1L2L3
ACR-11.17

The system SHALL track escalation response times and flag unacknowledged escalations that exceed def

The system SHALL track escalation response times and flag unacknowledged escalations that exceed defined windows.

AT+CM|Risk weight: 4/10|
L1L2L3
ACR-11.18

Post-override, the system SHALL not autonomously revert overridden settings without explicit operato

Post-override, the system SHALL not autonomously revert overridden settings without explicit operator authorization.

ATAutomated Testing|Risk weight: 5/10|
L1L2L3
ACR-11.19

Emergency halt capability SHALL be accessible through multiple independent channels.

Emergency halt capability SHALL be accessible through multiple independent channels.

AT+EI|Risk weight: 4/10|
L1L2L3
ACR-11.20

The system SHALL support configurable escalation thresholds that can be adjusted without system rest

The system SHALL support configurable escalation thresholds that can be adjusted without system restart.

AT+EI|Risk weight: 3/10|
L1L2L3
ACR-11.21

Override and escalation mechanisms SHALL function correctly during system degradation and partial fa

Override and escalation mechanisms SHALL function correctly during system degradation and partial failure.

ATAutomated Testing|Risk weight: 5/10|
L1L2L3
ACR-11.22

The system SHALL implement dead-man-switch functionality where loss of operator connectivity trigger

The system SHALL implement dead-man-switch functionality where loss of operator connectivity triggers automatic safe state.

ATAutomated Testing|Risk weight: 5/10|
L1L2L3