🤖 Autonomous systems

Autonomous Patrol & Industrial Robotics

Patrol robots, drones, and autonomous inspection systems observe continuously - but observation is not evidence. A robot may see a thousand things in a single shift: weather, authorized vehicles, animals, employees. Only a small fraction become operational events that trigger a notification, a ticket, or an organizational response. EVIDE does not certify what the sensors recorded. It certifies that the application declared a specific event, with specific attributes, at a specific moment - without ever touching the vision model, the control loop, or the robot\'s runtime. The same boundary applies to remotely teleoperated systems working where direct human presence is hazardous or impossible - radioactive zones, explosive ordnance disposal, toxic or unbreathable environments - where the declared intervention may become the primary independently reconstructable record of what a remote operator decided, and why.

Six months after an incident, when the vendor calls it a false positive and the operator says no notification was received, can you show - independently - that the system declared the event, when, and what action it triggered?
Capabilities ● Standard Intake ● ESB Buffer ● External Artifacts ⚓ EVIDE ANCHOR
Without EVIDE
  • No independent record exists of which anomaly was actually flagged at the time it occurred
  • An insurance dispute can only show that a claim was filed afterward - not that an alert was generated when it mattered
  • Vendor, operator, and integrator each blame one another - no externally verifiable sequence of event, notification, and action
  • Video and sensor logs exist internally, but they document observation, not the operational decision that followed it
  • Sensor logs, camera images, thermal imagery, and maintenance records exist scattered across internal systems, with no declared, externally anchored relationship connecting them to the evidentiary record
  • An evolving incident - a collision under review, a fallback still being assessed - is captured only as whatever snapshot existed at the moment someone happened to look, with no declared window documenting how the picture stabilized
With EVIDE
  • Each declared operational event is anchored externally, independent of the robot\'s runtime, vision pipeline, or control logic
  • The evidentiary boundary sits at the business event - never inside the perception or mission-control layer
  • EVIDE does not certify what the robot saw. It certifies that the application declared a significant event, with these attributes, at this time
  • Months later, the sequence - declaration, notification, organizational response - remains independently verifiable
  • External Artifacts lets sensor logs, camera images, thermal imagery, LiDAR exports, diagnostic reports, and signed maintenance records be referenced through a declared evidentiary record - without EVIDE ever receiving, storing, or interpreting the underlying files
  • The Epistemic Stabilization Buffer opens a declared observation window so an evolving event can be documented until the evidentiary picture is complete, producing one finalized record instead of disconnected snapshots
Evidence begins after the event.
Independent Post-Event Evidence for AI Systems
Sensors → Computer Vision → AI → Mission Logic → Business Event ──── Evidentiary Boundary ──── EVIDE

EVIDE is often described as a post-execution layer. The more precise framing is: a post-event layer. It does not activate because an execution has finished - it activates when the application has recognized and declared that a significant event occurred. This shifts the focus from technical execution to applicative meaning, which is exactly where evidentiary value originates.

Not events: a person walking by, an animal, rain, an authorized vehicle
Events: after-hours access, a door left open, a fire detected, a leak, a person in a restricted area
Autonomous Patrol & Industrial Robotics
EVIDE MCP Server AI agents and autonomous systems can submit evidentiary records directly via the EVIDE MCP Server - without modifying the operational pipeline. MCP Server documentation →
Hands-on Evaluation
Are you a robotics company? Try EVIDE free in the Lab.

The EVIDE Governance Lab lets you submit real evidentiary intakes, see FCC, DWC/FAC and the Epistemic Stabilization Buffer computed live, and download the automatically generated Evidentiary Artifact Record (EAR). No DAPI identity verification. No integration. No commitment. No cost.

Open EVIDE Governance Lab →

Lab environment - for exploration and testing only, no legal or evidentiary value.

Key evidentiary questions for autonomous systems
When an autonomous decision is later disputed, can these questions be answered independently?
  • 1 Could an independent third party reconstruct why that specific strategy was selected?
  • 2 Which observations, internal state, or contextual information actually determined that decision?
  • 3 If the system modified its original plan during execution, would independent evidence survive explaining why the change occurred?
  • 4 Where is the evidentiary boundary between the planning layer and the execution layer?
  • 5 If the system recognized an out-of-distribution or uncertain situation, what independent evidence remains documenting that transition?
  • 6 Months later, could an external investigator independently reconstruct the decision process without relying solely on the original system or its developers?
Example 1
Example evidentiary record for autonomous systems
A real, API-conformant payload example - verified against the EVIDE intake schema v2.1.
{ "evide_schema": "2.1", "source_system": "FleetPatrolApp", "source_reference": "EVT-2026-0701-0847", "source_timestamp_utc": "2026-07-01T14:33:07Z", "decision": { "type": "plan_modification", "status": "finalized", "closure_timestamp_utc": "2026-07-01T14:33:07Z", "summary": "Declared plan modification following detected obstacle in patrol corridor" }, "authority": { "id": "fleet_patrol_app_A", "role": "Autonomous Fleet Operator", "dapi_number": "DAPI-XXXX", "verification": "DAPI-XXXX" }, "intervention": { "type": "declared_event", "classification_status": "stable", "classification_context": { "taxonomy_reference": "https://example.org/taxonomies/robotics-event-taxonomy-v1.0", "threshold_reference": "https://example.org/rules/mission-deviation-policy-v1.2", "threshold_status": "met" }, "rationale": "Notification dispatched to operations team following declared plan modification", "trace": { "reference": "ROBOTICS-001/mission_patrol_20260701", "access": "restricted" } }, "human_oversight": { "is_declared": true, "declared_level": "L1" }, "handoff": { "boundary_readiness": { "status": "candidate", "readiness_gate": null, "visibility_surface": null, "unresolved_signals": [] }, "reconstruction_independence": "declared", "submission_status": "not_submitted", "acceptance_status": "not_claimed" }, "extensions": ["evidence_references"], "evidence_references": [ { "artifact_type": "sensor_log", "pointer": "fleet-storage://patrol-unit-a/sensor-log-20260701-1433.json", "declared_origin": "onboard sensor logging system", "declared_description": "Obstacle-detection sensor log at the time of the declared plan modification", "hash": { "algorithm": "SHA-256", "value": "sha256:c481f0...2a67_example_not_for_submission" }, "hash_scope": "full_file", "hashed_by": "Onboard logging service" } ], "content_hash": { "algorithm": "SHA-256", "value": "sha256:9d4a...f031_example_not_for_submission" } }

EVIDE anchors the declared application event, never the internal state of the system that produced it. It does not collect raw sensor data or certify the robot\'s perception. It anchors the declared decision context and the evidentiary references needed to reconstruct the operational event independently.

Named Accountability
Named accountability across multiple remote operators

When multiple operators control the same fleet of robots across different shifts, EVIDE anchors each declared event to the specific operator who acted at that moment - not to the organization as a whole. Each intervention carries the operator\'s own DAPI-verified identity, creating a permanent, individually attributable record that survives shift changes, operator turnover, and organizational restructuring.

DAPI Identity Certification ↑
Example 2
Example evidentiary record for hazardous-environment remote operations
A domain-adapted example for teleoperated robotics in radiological, explosive ordnance disposal (EOD), or other environments unsafe for direct human presence - same schema, same boundary, different domain reference.

EVIDE anchors the declared application event, never the internal state of the system that produced it. It does not collect raw sensor data or certify the robot\'s perception. It anchors the declared decision context and the evidentiary references needed to reconstruct the operational event independently.

{ "evide_schema": "2.1", "source_system": "RemoteOpsPlatform", "source_reference": "EVT-2026-0704-1102", "source_timestamp_utc": "2026-07-04T09:15:42Z", "decision": { "type": "remote_intervention_declared", "status": "finalized", "closure_timestamp_utc": "2026-07-04T09:15:42Z", "summary": "Declared remote valve inspection completed in restricted-access radiological maintenance zone" }, "authority": { "id": "remote_operator_07", "role": "Certified Remote Operator", "dapi_number": "DAPI-XXXX", "verification": "DAPI-XXXX" }, "intervention": { "type": "declared_event", "classification_status": "stable", "classification_context": { "taxonomy_reference": "https://example.org/taxonomies/hazardous-environment-intervention-taxonomy-v1.0", "threshold_reference": "https://example.org/protocols/radiological-access-protocol-iaea-ref-v2.1", "threshold_status": "met" }, "rationale": "Remote operator declared task completion under restricted-zone access protocol; no physical human entry occurred", "trace": { "reference": "HAZOPS-004/valve-inspection-zone-c", "access": "restricted" } }, "human_oversight": { "is_declared": true, "declared_level": "L1" }, "handoff": { "boundary_readiness": { "status": "candidate", "readiness_gate": null, "visibility_surface": null, "unresolved_signals": [] }, "reconstruction_independence": "declared", "submission_status": "not_submitted", "acceptance_status": "not_claimed" }, "extensions": ["evidence_references"], "evidence_references": [ { "artifact_type": "video", "pointer": "remote-ops-storage://valve-inspection-zone-c/20260704-0915.mp4", "declared_origin": "remote operator console recording", "declared_description": "Video recording of the remote valve inspection in the restricted-access zone" } ], "content_hash": { "algorithm": "SHA-256", "value": "sha256:7ac1...e920_example_not_for_submission" } }
Example 3 - New
⚓ Example evidentiary record with EVIDE ANCHOR
Declaring the operational perimeter a patrol unit was authorized within, before it crossed into a restricted maintenance bay - same schema, same boundary, the declaration made explicit instead of assumed.
{ "evide_schema": "2.1", "source_system": "FleetPatrolApp", "source_reference": "EVT-2026-0801-1602", "source_timestamp_utc": "2026-08-01T16:02:11Z", "decision": { "type": "restricted_zone_entry", "status": "finalized", "closure_timestamp_utc": "2026-08-01T16:02:11Z", "summary": "Patrol unit entered maintenance bay under a pre-declared operational perimeter" }, "authority": { "id": "fleet_patrol_app_A", "role": "Autonomous Fleet Operator", "dapi_number": "DAPI-XXXX" }, "intervention": { "classification_context": { "threshold_status": "not_defined" } }, "handoff": { "boundary_readiness": { "status": "candidate", "readiness_gate": null, "visibility_surface": null, "unresolved_signals": [] }, "reconstruction_independence": "declared", "submission_status": "not_submitted", "acceptance_status": "not_claimed" }, "extensions": ["declarations"], "declarations": [ { "declaration_type": "environment_classification", "declared_value": "restricted maintenance bay", "declarant": "fleet-ops-lead", "declared_at": "2026-08-01T15:45:00Z", "authority_source": { "declared_attribution_status": "attributed" } }, { "declaration_type": "prohibited_operations", "declared_value": "no autonomous lift above 1.2m without operator confirmation", "declarant": "fleet-ops-lead", "declared_at": "2026-08-01T15:45:00Z" } ] }

Two separate Declarations - the zone and the prohibited maneuver - kept apart rather than merged into one, consistent with the Atomic Declaration Rule. EVIDE anchors what was declared; it does not verify that the zone classification was correct or enforce the prohibition.