11  User Stories — M4 (Persistent Sensing)

Planned delivery stories, keyed to PRD Appendix A and grouped by capability

Published

June 23, 2026

Milestone M4 — Persistent Sensing (Q3 2026) restores sensor-native agentic analysis for independent RGB and thermal image modalities, deepens multi-sensor ingestion and review, and grounds it in open-standard engineering context. Stories below are grouped by the owning capability (_data/capabilities.yaml) and reference FR IDs rather than restating requirements; status labels mirror PRD Appendix A. The Q4 2026 (M5) build-out continues in m5; the 2027 autonomous-patrol robotics and dose-aware work is the directional H1 2027 horizon.

12 Evidence Intake

12.0.1 US-M4-11 — Multi-modal anomaly review

FR-SCN-01 / FR-SCN-02 / FR-SCN-03 (Q3 Target)

As an Integrity Engineer, I want OGI, calibrated thermal, and gas readings ingested and rendered natively so that I can review anomalies across modalities in one place.

  • Given a campaign with OGI/thermal/gas data, when it is ingested, then each modality is parsed, associated to its asset, and viewable without external tools.
  • Given a modality file is malformed or unsupported, when ingestion runs, then it is rejected with a clear reason and does not block the other modalities.

13 World Model

13.0.1 US-M4-03 — Geo-tagged assets & imagery in 3D

FR-VIS-02

As a Data Explorer, I want geo-tagged assets and imagery registered in the 3D scene so that I can see findings in physical context.

  • Given geo-tagged captures, when I open the unit, then assets and images register to the same coordinate frame.
  • Given a large scene, when I navigate, then the viewer streams tiles and stays interactive (no full-model load stall).

14 CAD & P&ID open standards

14.0.1 US-M4-08 — Click-through from 3D element to engineering identity

FR-CAD-01 (IFC4, In Progress Q2), FR-CAD-07 (dual-tagging, In Progress Q2)

As an Integrity Engineer, I want to select a 3D element and see its standard engineering identity so that I can move from a visual anomaly to its asset record without manual cross-referencing.

  • Given an IFC4 model for the unit, when I select an equipment item, then its IFC class, tag, material/lining, and source are shown.
  • Given a legacy CAD tag and an operator/DEXPI tag for the same asset, when I open either, then both resolve to the same asset record via the dual-tagging cross-reference.
  • Given a tag the dual-tagging rules cannot resolve, when resolution fails, then the item is flagged for manual mapping rather than silently mismatched.

14.0.2 US-M4-09 — P&ID structure from a clicked asset

FR-CAD-06 (DEXPI ingestion, In Progress Q2)

As an Integrity Engineer, I want logical P&ID structure ingested via DEXPI so that a clicked asset shows its nozzles, connected lines, and connections.

  • Given a DEXPI P&ID for the unit, when I view an equipment item, then its nozzles (with service), connected pipe runs, and source-to-target connections are listed.
  • Given a non-compliant CAD export, when the DEXPI file is ingested, then it is sanitized and parsed rather than failing outright.

15 Application Surface

15.0.1 US-M4-13 — Focus the chat on an asset

FR-APP-17 (Q3 Target; builds on FR-CAD-07 dual-tagging and FR-VIS-02 geo-tagged assets)

As an Integrity Engineer, I want to set an asset — by its engineering tag, e.g. AB-106 — as my chat focus so that follow-up questions resolve against that asset without restating context each time.

  • Given a tag in either its legacy CAD or operator/DEXPI form, when I set it as focus, then the scope shows the one resolved asset record (tag, class, material) via the dual-tagging cross-reference.
  • Given a tag that does not resolve, when I set focus, then I get an explicit “unknown asset” response with nearest candidate tags — never a silent empty scope.
  • Given an active asset focus, when I ask a question that names no asset, then the answer is scoped to the focused asset and states that scope.

15.0.2 US-M4-14 — Anomalies on an asset and its vicinity

FR-APP-17 (Q3 Target)

As an Integrity Engineer, I want to ask for all anomalies detected on the focused asset or within a stated distance around it so that I can review everything found at that location across modalities in one answer.

  • Given a focused asset with associated findings, when I ask “what anomalies were detected on this asset”, then annotations linked to it (by tag or spatial association) are returned with evidence references.
  • Given a stated radius (e.g. “within 5 m”), when I ask about the area around the asset, then findings within that distance of the asset’s coordinates are included, each labeled with its distance.
  • Given no findings exist for the asset or radius, when I ask, then the answer states that none were detected rather than fabricating results.

16 Operator Handoff

16.0.1 US-M4-12 — One-click finding export

FR-APP-06 (Alpha (prototype))

As an Integrity Engineer, I want to export the active workspace selection and defect findings to PDF/Word so that I can share a defensible record without re-keying.

  • Given a set of selected findings, when I export, then the document includes asset IDs, evidence references, severity, and recommended actions.
  • Given an export is generated, when I open it, then content matches what is shown on screen (no missing or placeholder fields).

16.0.2 US-M4-05 — IDMS bidirectional integration

FR-INT-03

As an Integrity Engineer, I want a defined bidirectional IDMS integration so that an approved finding becomes planned work without re-keying — under human sign-off.

  • Given an engineer-approved finding, when I hand it off, then a work item is created in the target IDMS with asset, evidence, and recommended action.
  • Given Kav AI’s corrosion rate disagrees with the IDMS record, when synced, then both values are surfaced for the engineer — the existing record is not silently overwritten.
  • Given a Critical finding or a Remaining-Life change, when handed off, then it requires engineer sign-off (canonical HITL rule).

16.0.3 US-M4-06 — Partner-integrated delivery

FR-PRT-01

As an Operations Supervisor, I want a single procurement vehicle covering platform plus partner integrity-engineering services so that I can buy the closed loop without stitching two contracts — while keeping the option to contract separately.

  • Given a partner-integrated engagement, when scoped, then the partner provides the HITL Integrity Engineer seat and the proposal is a single vehicle.
  • Given a customer that prefers separate contracts, when requested, then the platform subscription and partner services can still be split.

17 Integrity Analytical Chain

17.0.1 US-M4-15 — Raise a finding as a claim about an asset

FR-DMR-01 (Alpha (prototype))

As an Integrity Engineer, I want a finding to be a claim that a named asset exhibits a condition, grounded in one condition class or one API 571 mechanism and citing the images that show it, so that what I decide on is an engineering statement and not a tagged photo.

  • Given an asset and a set of images that depict it, when I raise a finding, then it records exactly one grounding (condition class or mechanism), the cited images, and starts as “possible”.
  • Given a finding with no grounding or two groundings, when it is written, then the platform rejects it rather than storing an ambiguous claim.

17.0.2 US-M4-16 — Screen an asset for credible mechanisms

FR-DMR-02 (Alpha (prototype))

As an Integrity Engineer, I want the platform to propose the API 571 mechanisms credible for an asset’s material, service and unit so that my review starts from the catalogue rather than from memory.

  • Given an asset profile, when screening runs, then each credible mechanism is proposed as a Tier-2 “possible” finding with its screening rationale.
  • Given a screening proposal, when I read it, then it is labelled as screening, never as evidence, and asks me to confirm or dismiss.

17.0.3 US-M4-17 — Correct a finding and curate its evidence

FR-DMR-03 (Alpha (prototype))

As an Integrity Engineer, I want to re-ground a finding, replace its notes and add or remove the images it cites, so that a finding improves as evidence improves without losing its history.

  • Given an existing finding, when I change its grounding, notes or cited images, then the current row reflects the change and an edit-log row records what changed, by whom, and when.
  • Given an edited finding, when I open its history, then every edit is listed in order and none has been overwritten.

18 Operator Handoff

18.0.1 US-M4-18 — Decide a finding, with reasoning, in an append-only log

FR-OPS-02 (Alpha (prototype))

As an Integrity Engineer, I want to confirm, dismiss or reinstate a finding with my reasoning recorded verbatim against my name, so that a decision is an auditable judgement and a dismissal can be reversed without erasing it.

  • Given a “possible” finding, when I confirm or dismiss it with reasoning, then a decision row is appended naming me, the verdict, the reasoning and the time, and the finding’s credibility reflects the latest decision.
  • Given a dismissed finding, when I reinstate it, then the dismissal is superseded (both rows remain) and the finding returns to “possible”, not to confirmed.

18.0.2 US-M4-19 — Work one campaign queue

FR-OPS-03 (Alpha (prototype))

As an Integrity Engineer, I want one worklist per campaign over its findings and notes, ordered by what changed most recently, so that I can answer “what have I not looked at” without leaving the queue.

  • Given a campaign with findings and notes, when I open its worklist, then both appear in one feed ordered by last change, each showing its kind from the organisation’s note vocabulary.
  • Given a note that describes a condition on an asset, when I promote it, then a finding is created from it and the note records the promotion; the reverse is not offered.

18.0.3 US-M4-20 — Record an action that names its finding

FR-OPS-04 (Alpha (prototype))

As an Integrity Engineer, I want a work order or observation to carry the finding it follows from, so that the reason for the work travels with it into the export and the hand-off.

  • Given a decided finding, when I record an action from it, then the action stores the finding reference, a status of open, and my summary.
  • Given an open action, when work is scheduled or completed, then its status moves open → scheduled → complete and the change is attributed.

18.0.4 US-M4-21 — Hand a campaign over, or send it back

FR-OPS-05 (Alpha (prototype))

As a Data Explorer, I want to send a campaign for review when the evidence is ready, and as an Integrity Engineer I want to return it with a reason when it is not, so that the relay between the two workspaces is a state we can both see.

  • Given a campaign in indexing, when the Data Explorer sends it for review, then its lifecycle becomes ready for review and it appears under “awaiting an engineer” in the Integrity workspace.
  • Given a campaign awaiting review, when the Integrity Engineer returns it, then a reason is required, the lifecycle returns to indexing, and the campaign history shows who moved it, when, and why.

19 World Model

19.0.1 US-M4-22 — Attribute an image to an asset by the tag it depicts

FR-CAD-09 (Alpha (prototype))

As a Data Explorer, I want an image attributed to an asset only when the equipment tag in the frame has been read and I have confirmed it, so that a photo of a cable beside a vessel never becomes evidence about the vessel.

  • Given an image whose OCR pass read an equipment tag, when I open the asset, then the image is offered as a suggested attribution that I confirm or reject, and my decision propagates to its RGB/thermal pair.
  • Given images near an asset that carry no tag, when I open the asset, then they are listed as nearby (or framed, where camera pose is known) context and are never cited as evidence unless an engineer curates them onto a finding.

20 Application Surface

20.0.1 US-M4-23 — Drive the loop through an AI agent, as myself

FR-APP-22 (Alpha (prototype))

As an Integrity Engineer, I want an AI agent connected through the MCP surface to raise, correct, decide and curate findings and record actions as me — under my permissions and with my name on every write — so that the assistant can do the legwork while the judgement stays mine.

  • Given an agent acting under my session, when it reads or writes, then row-level security applies as it would in the app, and every write is attributed to me.
  • Given an agent asked to decide a finding, when I have not stated my conclusion, then it reports what it sees and asks, rather than deciding on my behalf; a decision write requires explicit confirmation.

20.0.2 US-M4-24 — Carry on a conversation, and keep conversations apart

FR-APP-03 (Q3 Target; the multi-turn half of US-M3-01, whose single-turn half is delivered)

As an Integrity Engineer, I want the assistant to remember what we were just talking about — and to offer me prompts about what I am looking at — so that a follow-up question is a short sentence, not a restatement of the whole context, and so that two conversations I have open never bleed into each other.

  • Given I asked about a campaign’s images, when I follow up with “only the thermal ones”, then the answer narrows the previous one — the images returned are a subset of the first answer, from the same campaign, without my naming it again.
  • Given two conversations open on different threads, when I continue one of them, then nothing from the other appears in the answer, and every event in the stream carries the thread I asked on — an engine never answers on a thread of its own choosing, and a blank thread id never lands me in someone else’s session.
  • Given a selected campaign, module, candidate or asset, when I open the assistant, then the prompts it offers are about that selection — the campaign by name, the asset by tag — and change when the selection does.
  • Given a conversation several turns long, when I ask “which dataset did I start with”, then the answer names the first dataset I asked about, not the most recent.