Composition
Subsystems
4 subsystems, all resolving at their pinned revisions
- paymentresolvespurchasing-terminalrevision
87be9f07boundseftpossecure-elementreceipt-printercard-reader - beverageresolvescoffee-machinerevision
1ec97db8bounds_2026x_1_12a70364_1789363229077_574630_3720_2026x_1_12a70364_1789357175665_504215_3638 - foodresolvessandwich-toasterrevision
0399697dboundsheating-elementlower-platelatch - floor-careresolvesfloor-robotrevision
8e42ad84boundscamera-modulecup-detectorcollectorbeni
What the gate proves — and what it does not
Measured — proved
- every subsystem reference resolves at its pinned revision
- every cross-model edge resolves at its pinned revision (the named element exists within that revision)
- every integrated revision was itself gated
- every platform requirement is covered within the platform model
Not measured — asserted, not proved
- the combined system-of-systems, as a whole, has the global graph property (connected, coverage-complete, orphan-free); proving it would require importing every subsystem, which is the copy R1 forbids
Process
The link from a platform activity to a specific element inside a subsystem is the typed crossModelEdges declared on the subsystem reference (implementedBy / satisfiedBy), resolved at its pinned revision; the activity's allocatedTo attribute still names the role for this flow view.
Take Order
Take Payment
satisfies CS-2 · One Paymentparallel
Provision Beverage
Provision Food
Clear the Floor
satisfies CS-4 · Floor Kept ClearComplete Order
satisfies CS-3 · No Provision Before Paymentsatisfies CS-1 · Service Time