3.8 KiB
Digital Twin: lifecycle and retirement
Lifecycle gates
- Frame: intended use, affected parties, owner, harm boundary, decision rights, simpler alternatives.
- Discover: authoritative sources, identity/time/event contracts, classifications, assumptions, gaps.
- Bootstrap: read-only twin, reproducible ingestion, lineage, access controls, reconciliation.
- Calibrate: independent truth comparison, VVUQ, uncertainty, critical-slice tests, security/privacy/agent tests.
- Shadow: recommendations without effects; measure disagreement, false confidence, escalation, and value.
- Authorize: explicit action scope, policy, credentials, approval, rollback, and observability.
- Operate: freshness, drift, integrity, model/agent behavior, cost, security, privacy, and outcome monitoring.
- Change: revalidate after material source/schema/model/agent/tool/policy/environment/authority changes.
- Retire: revoke authority, migrate consumers, preserve justified evidence, dispose of data, check orphan calls.
Every gate produces approve, conditional approve, hold, or block. Keep the decision, evidence versions, owner, and expiry/review date.
Maintenance triggers
Revalidate after source schema/API changes; event loss, reordering, or clock changes; ownership or jurisdiction changes; model, connector, prompt, tool, policy, or environment updates; unexplained residuals; calibration or critical-slice failure; security/privacy incidents; changed workload; or a new action capability.
Incident response
- Detect and declare from alerts, audits, reports, or linked-twin anomalies.
- Contain by revoking action tokens, stopping schedules, quarantining connectors/memory/models, freezing propagation, and falling back to read-only/manual mode.
- Preserve versions, policies, provenance, event order, approvals, tool calls, external effects, and clock state without unnecessary sensitive copying.
- Assess affected twins, artifacts, deployments, people, customers, and downstream systems.
- Recover by rotating credentials, removing poisoned state, rebuilding from trusted provenance, reconciling external reality, testing rollback, and restoring authority gradually.
- Learn by adding regression/adversarial cases and revising gates and authority.
Distinguish represented-system, data/twin, model, platform, policy, and agent failures. Do not call a stale or corrupted twin failure “pre-existing” without evidence.
Decommissioning
Retire when purpose disappears, ownership is lost, risk exceeds tolerance, evidence cannot be maintained, repeated validation fails, a source/provider becomes untrustworthy, cost exceeds value, or a verified successor replaces the capability.
The retirement packet records owner approval, reason, final dependency/version inventory, consumer migration, unresolved risks, retention/legal decisions, and successor or intentional absence. Then:
- freeze new authority grants;
- disable schedulers and action endpoints;
- revoke credentials, tokens, webhooks, and tool permissions;
- sever feedback/control paths;
- migrate and verify consumers;
- export required lineage and decisions;
- delete/archive data under policy and destroy unnecessary secrets/memory;
- mark registry/endpoints retired;
- monitor and reject orphan calls;
- independently verify no live policy, agent, workflow, or twin depends on it.
Sources
- NISTIR 8356: https://csrc.nist.gov/pubs/ir/8356/final
- NIST AI RMF Manage: https://airc.nist.gov/airmf-resources/playbook/manage/
- NIST Incident Response SP 800-61 Rev. 3: https://csrc.nist.gov/pubs/sp/800/61/r3/final
- NASA-STD-7009: https://standards.nasa.gov/standard/NASA/NASA-STD-7009
- NIST Digital Twins for Advanced Manufacturing: https://www.nist.gov/programs-projects/digital-twins-advanced-manufacturing