Assemble the CSMS, SUMS and supply-chain evidence each approval and declaration rests on, track the renewal and filing clocks, and hold the file for the officer who signs it under oath.
A fleet-wide evidence-currency figure can look settled while a small number of vehicle types carry most of the unanswered supply chain. Nestack reports the amendment rate by slice, not only in total.
Slice performance — reported separately, not only in aggregateIllustrative example
Slice
Failure rate
Lift
Lift vs. threshold
Status
Tier-2 substituted parts
9.3%
3.7×
Review
Third-country suppliers
6.4%
2.6×
Review
Model-year rollovers
4.5%
1.8×
Watch
Single-source stock parts
2.3%
0.9×
Normal
Bar: amendment-rate lift vs. single-source-part baseline · scale 0–4.0× · tick marks the 2.0× review threshold2 of 4 slices over threshold
Evidence-linked improvement
Every cycle ends by adding a case
A cycle is closed when the unsupported declaration is a case the next release must survive. That suite is what the next file assembled is measured against.
Improvement cycle · five stagesSwitchback — the path turns at Improve and returns at Learn
01Detect
Amendment rate rises in a component slice.
02Diagnose
The module whose firmware nobody upstream would put in writing is read back to a single cause.
03Improve
The change leaves with a version on it and the components that found it attached.
04Verify
While a touched declaration case is unresolved, the release does not open.
05Learn
It is held permanently, and the evidence rules shift with it.
Learn → DetectThe return edge. The next file is assembled against a suite one case longer.
Typical build scope
Twelve workstreams across six weeks
The build scope read against the delivery timeline. Week structure follows the six-week plan — discovery, sources, evidence workflow, evaluation, integration, then production validation and handover.
WorkstreamWeek 1Week 2Week 3Week 4Week 5Week 6
01Compliance workflow discovery and boundary definition.
02Item-master and supplier-portal assessment.
03Scope, evidence and reporting-clock rule mapping.
04Component-data ingestion and normalisation.
05Evidence assembly and source binding.
06Confidence scoring and gap routing.
07Cybersecurity officer approval.
08Compliance and PLM system integration.
09Evidence and audit cases.
10Guardrails and declaration controls.
11Component-trail instrumentation.
12Deployment, documentation and Agent Care handover.
12 workstreams · 6 weeks · bar shows the weeks a workstream is active — several run in parallelFinal scope and sequence confirmed in discovery
Engagement tiers
What each tier includes
Rows are the capabilities named in each tier's scope. Higher tiers include everything below them.
Capability✓ in scope · — not at this tierPilotOne vehicle type, one marketProductionProduction compliance systemsAdvancedMultiple types / authorities
Introduced at Pilot
Assembly to your parts and rules✓✓✓
Officer approval✓✓✓
Evidence-currency baseline✓✓✓
Introduced at Production
Reporting by vehicle type—✓✓
Approval workflow in your systems—✓✓
Approved write-back—✓✓
Supplier-portal integration—✓✓
Introduced at Advanced
Multiple regimes and calendars——✓
Multi-stage compliance approvals——✓
High component volume——✓
Multi-authority approval controls——✓
Build priceFrom $5,000From $8,000Custom quote
Final build priceConfirmed after discovery based on integrations, workflow complexity, transaction volume, approval controls and deployment requirements.
Separate from buildBuild pricing is separate from recurring Agent Care, which covers managed monitoring, evaluations, incidents and verified improvements after launch.
What we need from you
What you bring, and what we build with it
Each input maps to a piece of build scope and a week in the delivery timeline.
You bringWe build with it
01Your item master and component BOMs→Component-data ingestion and evidence mappingWeek 1
02Representative declarations already filed→Evidence baseline and source bindingWeek 2
03Your scope rules and reporting clocks→Scope, evidence and reporting-clock rule mappingWeek 1
04Access to relevant APIs, feeds or exports→Item-master and supplier-portal assessment, then integration setupWeek 2
05Declarations you would not want sworn→Supply-chain cases and failure-mode testingWeek 4
06What no declaration may assert→Confidence scoring, gap routing, guardrails and declaration controlsWeek 3
07A named cybersecurity officer to approve→Officer approval workflow, then pilot and production validationWeeks 5–6
Nothing else is requiredDeployment, documentation and Agent Care handover are ours.
Delivery timeline
Four phases across six weeks
Bands are set by the approval calendar, not by the plan, so week 5 carries two phases.
PhaseW1W2W3W4W5W6
DiscoveryW1
BuildW2 – W3
EvaluateW4 – W5
Pilot & LaunchW5 – W6
Week focusW1Compliance workflow discovery, rule mapping and the automation boundaryW2Item-master integration and the evidence baselineW3Evidence workflow, confidence logic and approval controlsW4Evaluation suite, scope and clock checks and failure-mode testingW5Supplier-portal integration, pilot components and targeted correctionsW6One type approval assembled under the cybersecurity officer, then handover
Reading the bandEach band covers only the weeks its work is named in. The week 5 overlap is real, not padding.
At the end of W6Once the approval validates, Agent Care owns the running agent.
DurationSix-week plan shown · typical delivery 4–6 weeks depending on scope confirmed in discovery.
Next step · Automotive AI agent
Build a vehicle cyber and SUMS agent around your approval calendar.
There is no US analogue to R155 — but under §791.318 a wilful violation reaches criminal exposure for a natural person. Show us your file and the officer who would sign it.