RLSOK

01 Robot software execution authorization

Deployment is not execution authorization.

A deployed release can remain present after its approval is revoked. RLSOK checks again before the next command.

Deployment is a state.
Authorization is a decision.

Execution boundaryPublic Shadow reference
Release
release-a · PRESENT
Gate reason
release_revoked
Hardware dispatch
NO

02 One continuous decision

The artifact stays. Authority does not.

Public reference scenario · no customer or live robot data.

  1. 01

    Deployment

    PRESENTrelease-a remains in the deployment map.
  2. 02

    Approval

    REVOKEDAuthority is withdrawn; the historical artifact remains.
  3. 03

    Next command

    BLOCKEDrelease_revoked · Hardware dispatch: NO.
  4. 04

    Evidence

    RECORDEDThe denied decision remains inspectable.

03 Shadow / zero dispatch

See the decision.
Send nothing.

Shadow uses the authorization and Evidence path without a dispatcher. It sends no controller command—not a stop command and not a zero command.

Inspect the reference path
ModeSHADOW — OBSERVATION ONLY

Policy result: ALLOWED

Execution gateBLOCKED — Shadow observation only

The controller path stays interrupted.

Controller boundaryHARDWARE DISPATCH: NO

No controller call for this exact proposal.

ArtifactEVIDENCE RECORDED

Verification is a separate, scoped result.