Skip to main content

HAIEC Methodology

How does HAIEC reach a conclusion?

The method follows the supported consequence path, not just an isolated model, prompt, policy document, or tool-call event. Every conclusion stays tied to its evaluated scope and evidence boundary.

From question to evidence-bound conclusion

1

Question

Start with one consequential AI system, one decision, and one primary assurance question.

2

Scope

Define the evaluated system, source, identities, environments, evidence access, exclusions, and time basis.

3

Reconstruct

Use supported source and connected evidence producers to map relationships among agents, tools, handlers, resources, services, and consequences.

4

Compare

Keep requested, policy-authorized, effectively granted, code-capable, and observed evidence separate.

5

Bound

Record coverage, provenance, limitations, unknowns, partial relationships, and producer frontiers.

6

Assure

Where the applicable evidence and evaluation contract support it, produce bounded assurance artifacts and decision context.

What makes the method defensible?

  • Repository-first: implementation evidence can establish capability, not execution.
  • Runtime optional: runtime testing is authorized and scoped; it is not assumed.
  • Exact identity: joins require canonical source, scan, relation, and scope identity.
  • Historical basis: current source and evaluated assurance basis remain distinct.
  • Explicit frontiers: missing producers narrow the claim rather than increasing confidence.

What the method does not claim

HAIEC does not claim universal discovery, complete visibility, automatic safety, compliance certification, or proof that every possible delegation or runtime action occurred. Framework mapping is not certification. Unknown is not pass.