AI observability
Aplark Monitor
Know when deployed intelligence drifts.
Aplark Monitor is intended to detect when a deployed system has drifted outside the operational domain its assurance argument was built against — and to say which claim that invalidates.
The problem
An assurance case has a shelf life
An assurance argument is valid for a declared operational domain and a declared system. The world moves: the domain shifts, sensors age, the operating picture changes. At some point the argument stops describing the system that is flying, and nothing in the argument itself announces that.
The useful signal is not that a distribution moved. It is that a distribution moved in a way that invalidates a specific claim in a specific assurance case.
How it works
How it is intended to work
Aplark Monitor is being scoped to compare observed operating conditions against the declared ODD and its exposure weights, and to propagate a stale marker upward through the affected claims, readiness dimensions and dossier sections.
A constraint shapes the whole design: it must work without telemetry leaving the installation. Product metrics are never collected from a customer deployment, and this would be no exception.
Capabilities
What it does
ODD excursion detection
Intended to flag operation outside the declared domain against the ODD specification the assurance case was built on.
Claim-level staleness
Planned to propagate staleness to the specific claims a drift invalidates, loudly and in text, rather than reporting a drift metric nobody can action.
No outbound telemetry
Designed to operate entirely inside the installation. Nothing about a deployment is reported back to us, under any configuration.
Who it is for
- Programmes with fielded systems under a live assurance argument
- Certification leads who need to know when a package has gone stale