Simulation-first validation

Exercise the release path without sending hardware commands.

ROS 2 Shadow Mode mirrors the identity, approval, permit, and local-gate path while substituting an evidence-only sink for the final hardware dispatch.

Request a Shadow Audit

What to mirror

  • The same release manifest and content hash used by the intended path.
  • Representative device, controller, and action bindings.
  • Approval, revocation, expiry, replay, and mismatch decisions.
  • Evidence that clearly marks hardwareSignalSent as false.

What it can reveal

  • Mutable identifiers and configuration drift.
  • Unexpected fail-open handling during dependency loss.
  • Permit replay or expiry assumptions.
  • Missing evidence needed to explain a decision.

Limitations

Shadow Mode validates control-path behavior, not physical dynamics or policy performance. It cannot replace simulation coverage, hardware testing, operational review, or independent protective systems.

Continue the architecture review

Ready to map the release path? Request a Shadow Audit.