Start with the system's security boundary.
These are intended application areas. Scope depends on the models, interfaces, evidence and operational environment.
Bind actions to the intended asset
A workload's permissions must identify the resource and operation. Authority for one robot does not imply authority for another.
Track the approved model version
Connect verified artifact evidence to deployment decisions. A supplied version string alone does not establish provenance.
Evaluate perception-specific threats
Adversarial sensor inputs need model-specific testing and trustworthy observations. Native sensor attack detection is not built yet.
A permission must name the equipment.
The same model can serve multiple devices with different operating limits. Authority for one asset, software version or test environment must not transfer silently to another.
Start with one integration and distinguish a proposed command, authorized dispatch and reported device state. Physical safety and perception testing require additional system-specific evidence.