11 User Stories — M4 (Persistent Sensing)
Planned delivery stories, keyed to PRD Appendix A and grouped by capability
Milestone M4 — Persistent Sensing (Q3 2026) restores sensor-native agentic analysis for independent RGB and thermal image modalities, deepens multi-sensor ingestion and review, and grounds it in open-standard engineering context. Stories below are grouped by the owning capability (_data/capabilities.yaml) and reference FR IDs rather than restating requirements; status labels mirror PRD Appendix A. The Q4 2026 (M5) build-out continues in m5; the 2027 autonomous-patrol robotics and dose-aware work is the directional H1 2027 horizon.
12 Evidence Intake
12.0.1 US-M4-11 — Multi-modal anomaly review
FR-SCN-01 / FR-SCN-02 / FR-SCN-03 (Q3 Target)
As an Integrity Engineer, I want OGI, calibrated thermal, and gas readings ingested and rendered natively so that I can review anomalies across modalities in one place.
- Given a campaign with OGI/thermal/gas data, when it is ingested, then each modality is parsed, associated to its asset, and viewable without external tools.
- Given a modality file is malformed or unsupported, when ingestion runs, then it is rejected with a clear reason and does not block the other modalities.
13 World Model
13.0.1 US-M4-03 — Geo-tagged assets & imagery in 3D
FR-VIS-02
As a Data Explorer, I want geo-tagged assets and imagery registered in the 3D scene so that I can see findings in physical context.
- Given geo-tagged captures, when I open the unit, then assets and images register to the same coordinate frame.
- Given a large scene, when I navigate, then the viewer streams tiles and stays interactive (no full-model load stall).
14 CAD & P&ID open standards
14.0.1 US-M4-08 — Click-through from 3D element to engineering identity
FR-CAD-01 (IFC4, In Progress Q2), FR-CAD-07 (dual-tagging, In Progress Q2)
As an Integrity Engineer, I want to select a 3D element and see its standard engineering identity so that I can move from a visual anomaly to its asset record without manual cross-referencing.
- Given an IFC4 model for the unit, when I select an equipment item, then its IFC class, tag, material/lining, and source are shown.
- Given a legacy CAD tag and an operator/DEXPI tag for the same asset, when I open either, then both resolve to the same asset record via the dual-tagging cross-reference.
- Given a tag the dual-tagging rules cannot resolve, when resolution fails, then the item is flagged for manual mapping rather than silently mismatched.
14.0.2 US-M4-09 — P&ID structure from a clicked asset
FR-CAD-06 (DEXPI ingestion, In Progress Q2)
As an Integrity Engineer, I want logical P&ID structure ingested via DEXPI so that a clicked asset shows its nozzles, connected lines, and connections.
- Given a DEXPI P&ID for the unit, when I view an equipment item, then its nozzles (with service), connected pipe runs, and source-to-target connections are listed.
- Given a non-compliant CAD export, when the DEXPI file is ingested, then it is sanitized and parsed rather than failing outright.
15 Application Surface
15.0.1 US-M4-13 — Focus the chat on an asset
FR-APP-17 (Q3 Target; builds on FR-CAD-07 dual-tagging and FR-VIS-02 geo-tagged assets)
As an Integrity Engineer, I want to set an asset — by its engineering tag, e.g. AB-106 — as my chat focus so that follow-up questions resolve against that asset without restating context each time.
- Given a tag in either its legacy CAD or operator/DEXPI form, when I set it as focus, then the scope shows the one resolved asset record (tag, class, material) via the dual-tagging cross-reference.
- Given a tag that does not resolve, when I set focus, then I get an explicit “unknown asset” response with nearest candidate tags — never a silent empty scope.
- Given an active asset focus, when I ask a question that names no asset, then the answer is scoped to the focused asset and states that scope.
15.0.2 US-M4-14 — Anomalies on an asset and its vicinity
FR-APP-17 (Q3 Target)
As an Integrity Engineer, I want to ask for all anomalies detected on the focused asset or within a stated distance around it so that I can review everything found at that location across modalities in one answer.
- Given a focused asset with associated findings, when I ask “what anomalies were detected on this asset”, then annotations linked to it (by tag or spatial association) are returned with evidence references.
- Given a stated radius (e.g. “within 5 m”), when I ask about the area around the asset, then findings within that distance of the asset’s coordinates are included, each labeled with its distance.
- Given no findings exist for the asset or radius, when I ask, then the answer states that none were detected rather than fabricating results.
16 Operator Handoff
16.0.1 US-M4-12 — One-click finding export
FR-APP-06 (Alpha (prototype))
As an Integrity Engineer, I want to export the active workspace selection and defect findings to PDF/Word so that I can share a defensible record without re-keying.
- Given a set of selected findings, when I export, then the document includes asset IDs, evidence references, severity, and recommended actions.
- Given an export is generated, when I open it, then content matches what is shown on screen (no missing or placeholder fields).
16.0.2 US-M4-05 — IDMS bidirectional integration
FR-INT-03
As an Integrity Engineer, I want a defined bidirectional IDMS integration so that an approved finding becomes planned work without re-keying — under human sign-off.
- Given an engineer-approved finding, when I hand it off, then a work item is created in the target IDMS with asset, evidence, and recommended action.
- Given Kav AI’s corrosion rate disagrees with the IDMS record, when synced, then both values are surfaced for the engineer — the existing record is not silently overwritten.
- Given a Critical finding or a Remaining-Life change, when handed off, then it requires engineer sign-off (canonical HITL rule).
16.0.3 US-M4-06 — Partner-integrated delivery
FR-PRT-01
As an Operations Supervisor, I want a single procurement vehicle covering platform plus partner integrity-engineering services so that I can buy the closed loop without stitching two contracts — while keeping the option to contract separately.
- Given a partner-integrated engagement, when scoped, then the partner provides the HITL Integrity Engineer seat and the proposal is a single vehicle.
- Given a customer that prefers separate contracts, when requested, then the platform subscription and partner services can still be split.
17 Integrity Analytical Chain
17.0.1 US-M4-15 — Raise a finding as a claim about an asset
FR-DMR-01 (Alpha (prototype))
As an Integrity Engineer, I want a finding to be a claim that a named asset exhibits a condition, grounded in one condition class or one API 571 mechanism and citing the images that show it, so that what I decide on is an engineering statement and not a tagged photo.
- Given an asset and a set of images that depict it, when I raise a finding, then it records exactly one grounding (condition class or mechanism), the cited images, and starts as “possible”.
- Given a finding with no grounding or two groundings, when it is written, then the platform rejects it rather than storing an ambiguous claim.
17.0.2 US-M4-16 — Screen an asset for credible mechanisms
FR-DMR-02 (Alpha (prototype))
As an Integrity Engineer, I want the platform to propose the API 571 mechanisms credible for an asset’s material, service and unit so that my review starts from the catalogue rather than from memory.
- Given an asset profile, when screening runs, then each credible mechanism is proposed as a Tier-2 “possible” finding with its screening rationale.
- Given a screening proposal, when I read it, then it is labelled as screening, never as evidence, and asks me to confirm or dismiss.
17.0.3 US-M4-17 — Correct a finding and curate its evidence
FR-DMR-03 (Alpha (prototype))
As an Integrity Engineer, I want to re-ground a finding, replace its notes and add or remove the images it cites, so that a finding improves as evidence improves without losing its history.
- Given an existing finding, when I change its grounding, notes or cited images, then the current row reflects the change and an edit-log row records what changed, by whom, and when.
- Given an edited finding, when I open its history, then every edit is listed in order and none has been overwritten.
18 Operator Handoff
18.0.1 US-M4-18 — Decide a finding, with reasoning, in an append-only log
FR-OPS-02 (Alpha (prototype))
As an Integrity Engineer, I want to confirm, dismiss or reinstate a finding with my reasoning recorded verbatim against my name, so that a decision is an auditable judgement and a dismissal can be reversed without erasing it.
- Given a “possible” finding, when I confirm or dismiss it with reasoning, then a decision row is appended naming me, the verdict, the reasoning and the time, and the finding’s credibility reflects the latest decision.
- Given a dismissed finding, when I reinstate it, then the dismissal is superseded (both rows remain) and the finding returns to “possible”, not to confirmed.
18.0.2 US-M4-19 — Work one campaign queue
FR-OPS-03 (Alpha (prototype))
As an Integrity Engineer, I want one worklist per campaign over its findings and notes, ordered by what changed most recently, so that I can answer “what have I not looked at” without leaving the queue.
- Given a campaign with findings and notes, when I open its worklist, then both appear in one feed ordered by last change, each showing its kind from the organisation’s note vocabulary.
- Given a note that describes a condition on an asset, when I promote it, then a finding is created from it and the note records the promotion; the reverse is not offered.
18.0.3 US-M4-20 — Record an action that names its finding
FR-OPS-04 (Alpha (prototype))
As an Integrity Engineer, I want a work order or observation to carry the finding it follows from, so that the reason for the work travels with it into the export and the hand-off.
- Given a decided finding, when I record an action from it, then the action stores the finding reference, a status of open, and my summary.
- Given an open action, when work is scheduled or completed, then its status moves open → scheduled → complete and the change is attributed.
18.0.4 US-M4-21 — Hand a campaign over, or send it back
FR-OPS-05 (Alpha (prototype))
As a Data Explorer, I want to send a campaign for review when the evidence is ready, and as an Integrity Engineer I want to return it with a reason when it is not, so that the relay between the two workspaces is a state we can both see.
- Given a campaign in indexing, when the Data Explorer sends it for review, then its lifecycle becomes ready for review and it appears under “awaiting an engineer” in the Integrity workspace.
- Given a campaign awaiting review, when the Integrity Engineer returns it, then a reason is required, the lifecycle returns to indexing, and the campaign history shows who moved it, when, and why.
19 World Model
19.0.1 US-M4-22 — Attribute an image to an asset by the tag it depicts
FR-CAD-09 (Alpha (prototype))
As a Data Explorer, I want an image attributed to an asset only when the equipment tag in the frame has been read and I have confirmed it, so that a photo of a cable beside a vessel never becomes evidence about the vessel.
- Given an image whose OCR pass read an equipment tag, when I open the asset, then the image is offered as a suggested attribution that I confirm or reject, and my decision propagates to its RGB/thermal pair.
- Given images near an asset that carry no tag, when I open the asset, then they are listed as nearby (or framed, where camera pose is known) context and are never cited as evidence unless an engineer curates them onto a finding.
20 Application Surface
20.0.1 US-M4-23 — Drive the loop through an AI agent, as myself
FR-APP-22 (Alpha (prototype))
As an Integrity Engineer, I want an AI agent connected through the MCP surface to raise, correct, decide and curate findings and record actions as me — under my permissions and with my name on every write — so that the assistant can do the legwork while the judgement stays mine.
- Given an agent acting under my session, when it reads or writes, then row-level security applies as it would in the app, and every write is attributed to me.
- Given an agent asked to decide a finding, when I have not stated my conclusion, then it reports what it sees and asks, rather than deciding on my behalf; a decision write requires explicit confirmation.
20.0.2 US-M4-24 — Carry on a conversation, and keep conversations apart
FR-APP-03 (Q3 Target; the multi-turn half of US-M3-01, whose single-turn half is delivered)
As an Integrity Engineer, I want the assistant to remember what we were just talking about — and to offer me prompts about what I am looking at — so that a follow-up question is a short sentence, not a restatement of the whole context, and so that two conversations I have open never bleed into each other.
- Given I asked about a campaign’s images, when I follow up with “only the thermal ones”, then the answer narrows the previous one — the images returned are a subset of the first answer, from the same campaign, without my naming it again.
- Given two conversations open on different threads, when I continue one of them, then nothing from the other appears in the answer, and every event in the stream carries the thread I asked on — an engine never answers on a thread of its own choosing, and a blank thread id never lands me in someone else’s session.
- Given a selected campaign, module, candidate or asset, when I open the assistant, then the prompts it offers are about that selection — the campaign by name, the asset by tag — and change when the selection does.
- Given a conversation several turns long, when I ask “which dataset did I start with”, then the answer names the first dataset I asked about, not the most recent.