Match every hazard to the control raised against it, track which of the four retention clocks in 14 CFR 5.97 governs each artefact, and hold the declaration package for the accountable executive.
A hazard is reported, and subpart C of 14 CFR part 5 decides what risk control it earns.
02
A control is raised, and 14 CFR 5.97(a) keeps its output while that control stays relevant.
Reason
03
An assurance output is filed, and 14 CFR 5.97(b) holds it a minimum of five years.
04
A safety message goes out, and 14 CFR 5.97(d) holds it twenty-four calendar months.
05
A person is trained, and 14 CFR 5.97(c) keeps that record for the term of employment.
Decide
06
A control loses relevance, and the output behind it stops carrying the declaration.
07
A declaration falls due, and 14 CFR 5.9 sets 28 May 2027 for part 135 and 91.147 operators.
Out
08
A safety policy is signed, and 14 CFR 5.21(b) reserves that act to the accountable executive.
09
Execute write actions only inside the approval boundaries agreed during implementation.
→Product statement
The agent assembles the package and tracks the clocks. The accountable executive designated under 14 CFR 5.25(a) signs the safety policy, and that act cannot be delegated.
Example workflow
One hazard, evidence to signature
AgentHuman
1Hazard evidence receivedOccurrence reports, risk assessments, assurance outputs or training records
2Hazard context assembledThe hazard, the control raised against it, the subpart it answers to and the clock it runs on
3Declaration evidence draftedThe hazards, the controls behind them, the gaps and completeness
4Controls appliedRelevance checks, retention-clock checks, subpart-coverage checks and completeness confidence
No human action required
Stages 1 to 4 run unaided, and nothing is signed at any of them — the agent is assembling, and the safety lane opens at the completeness gate.
5DecisionSplits at the completeness gate
Evidence sufficient
Goes to the accountable executive to sign.
Anything thin
Adds a safety manager read first.
Safety review
The package is held with its hazards, its controls and the outputs behind them.
Sign · Append evidence · Send to safety review
Signed — by the accountable executive▼
6Hazard and control records updatedOnly where write access and records policy allow it
7Outcome evaluatedControl currency, retention coverage, reviewer corrections and what the read found
Corrections
Each safety correction is counted in the evaluation.
What should not run autonomously
Human approval stays in control
Outside the boundary — human approval required8 items
Signing the safety policy under 14 CFR 5.21(b).
Submitting the declaration of compliance to the FAA.
Deciding that a risk control is no longer relevant.
Judging safety performance substandard under 14 CFR 5.75.
Automation boundaryAgent acts unaided
✓Hold each hazard against the risk control raised.
✓Track which of the four retention clocks governs every artefact.
✓Mark the control whose relevance lapsed, and why.
✓Flag the missing record that the declaration package still needs.
Nothing is signed or submitted except by a named person, inside the agreed boundaries.
Judging whether an SMS meets part 5.
Telling the FAA the operator is compliant.
Setting the safety objectives the policy states.
Changes to hazards, controls or retention records.
Example output
One hazard, annotated
The declaration of compliance falls due on 28 May 2027; this record is what one hazard carried into the package.
Declaration evidence · single hazardIllustrative example
Hazard
Recorded as
Subpart
Evidence of record
Confidence
Held for
Runway excursion risk, subpart C
Control raised, relevance confirmed
Subpart C output
Risk assessment, 3 August 2026
Held unsigned
The accountable executive, by name
As receivedTaken from the occurrence report and the risk assessment — it reaches as far as those sources do.
What the record holdsOccurrence reportRisk assessmentControl relevance note
Why no signature hereSigning the safety policy is reserved to the accountable executive.
ActionSignAppend evidenceSend to safety review
What the score decidesBelow the configured threshold the package takes a safety read before the executive sees it.
Value
Where AI adds value
The same four claims, placed at the point in the workflow where each one applies.
Where the value landsValue 01 – 04
Every hazardFrom the system that reported it
03Evidence
Where the evidence is used
Nothing else in the corpus answers to a named accountable executive who carries a whole certificate, so this page collides with no other agent we ship.
01Approved path
One signature, four clocks
14 CFR 5.21(b) leaves no room to spread it: "The safety policy must be signed by the accountable executive described in § 5.25." One human, personally, for the certificate entire.
02Human review
What was checked, and not found
The part 21 compliance dates, the DATES paragraph of 89 FR 33068 word for word, the signer of that rule and an eCFR stamp reading last amended 17 August 2026 were each checked and none was confirmed; no delay or withdrawal of the rule was found either.
04Build an evidence trail
The hazard, the control raised against it and the executive who signed stay on the policy.
Integrations
Typical integrations
Five system groups connect to the same agent. Which of them are in scope is decided in discovery.
Integration availability depends on the client's existing systems and API access.
Agent controls
Six barriers between the model and the executive
Six barriers, and one hazard must clear every one of them. What gets past is named in the map below.
L6 · Outermost — last line of defenceInward → L1 · closest to the model
L6Rollback / safe modeNarrow the agent to evidence assembly when evaluation or production signals degrade.Roll back
L5Version monitoringTrack model, prompt and part 5 rules; as of 24 August 2026 no delay, extension or withdrawal of the 2024 SMS rule was found, and 28 May 2027 stands.Track
L4TraceabilityRecord each hazard, the control raised against it, the clock it runs on and every read of the package.Record
L3Executive releaseHold the package for the accountable executive of 14 CFR 5.25(a); the hold governs release, not whether the system beneath it conforms.Gate
L2Scope guardrailsTest the evidence against subparts B to E of 14 CFR part 5 as configured, and against the four clocks in 5.97.Restrict
L1Confidence thresholdsRoute a thin package to a safety read first; part 21 compliance dates went unverified in research and are not worked here.Require review
Model coreEvidence assembled — the hazards, the controls, the clocks and completeness
L1 – L2Test whether a package may stand
L3Puts the signature in a person's hands
L4 – L5Keep the hazard and the control behind it
L6Retreats to record assembly when signals degrade
How Nestack evaluates it
Evaluate the whole assembly — not only the declaration package that comes out.
Coverage runs the whole depth of the workflow, and every layer is cut by slice.
Surface — the package an inspector reads
Depth of coverage ▼
E1Final-output evaluationDid the package record what each hazard actually raised?
E2Step-level evaluationDid the agent read the right hazard, the right control and the live retention clock?
E3Tool evaluationDid it read and write the correct hazard and the correct control?
E4Confidence calibrationDo low-confidence packages actually attract more safety corrections?
E5Slice evaluationHow does performance change across specific hazard classes?
E6Business outcomeHow many packages needed a correction before the executive signed?
Floor — the certificate the operator answers for
Failure modes
Where each failure originates in the agent
Seven failure modes, each pinned to the stage where it surfaces first.
Agent lifecycleDirection of processing →
01 · Retrieval1 mode
JY-03
Stale hazard read
The risk register read is not the one now in force.
Stage gathersThe hazards, the controls, the clocks and the dates
02 · Reasoning2 modes
JY-04
Control asserted, not shown
A control is called current without its output.
JY-06
Lapsed control read as live
A control past relevance still carries the package.
Stage proposesThe hazards, their controls and completeness
03 · Tool / write2 modes
JY-02
Thin package passed forward
A package moves on without the safety read.
JY-05
Bound to the wrong control
An output is filed against the wrong hazard.
Stage writesOnly where write access and approval policy allow it
04 · Output1 mode
JY-01
Signed, evidence unrecorded
The package shows a signature but not what supported it.
Stage returnsThe package an executive signs and the FAA reads
05 · Change / Version1 mode
JY-07
Silent clock regression
A configuration change moves the clock, not the record.
Stage tracksModel, prompt, part 5 rules and package fields
Sev-1 · a policy signed on no evidenceSev-2 · wrong evidence reaches the packageSev-3 · source degrades, package unsigned
A control-level currency figure can read clean while flight operations hazards carry most of the rework. Nestack reports the correction rate by hazard class, not only in total.
Slice performance — reported separately, not only in aggregateIllustrative example
Slice
Failure rate
Lift
Lift vs. threshold
Status
Flight operations hazards
10.0%
3.6×
Review
Maintenance and airworthiness
7.2%
2.6×
Review
Ground and ramp operations
4.5%
1.6×
Watch
Training and communication records
1.9%
0.7×
Normal
Bar: correction-rate lift vs. training-record baseline · scale 0–4.0× · tick marks the 2.0× review threshold2 of 4 slices over threshold
Evidence-linked improvement
What a lapsed control costs
A loop ends when the stale control has become a case the next release must pass. That suite is what the next declaration built is measured against.
Improvement cycle · five stagesSwitchback — the path turns at Improve and returns at Learn
01Detect
Correction rate rises on flight operations hazards.
02Diagnose
The safety policy signed once, for a hazard register that has moved on since, is read back until one cause remains.
03Improve
Number the change; the hazards that drove it are filed underneath it.
04Verify
Each touched hazard case is run once more, and one red holds it back.
05Learn
It stays on as a standing test, and the retention rules move alongside it.
Learn → DetectThe return edge. The next assurance year is measured against a suite one case longer.
Typical build scope
Twelve workstreams across six weeks
The build scope read against the delivery timeline. Week structure follows the six-week plan — discovery, sources, package assembly, evaluation, integration, then production validation and handover.
WorkstreamWeek 1Week 2Week 3Week 4Week 5Week 6
01Hazard-register and automation-boundary discovery.
02Occurrence, risk and training sources.
03Hazard-to-control and retention-clock mapping.
04Hazard and control ingestion.
05Hazard, control and clock binding.
06Completeness scoring and review routing.
07Accountable executive signing workflow.
08Safety and training-system integration.
09Assurance and retention cases.
10Guardrails and executive controls.
11Policy-trail instrumentation.
12Deployment, documentation and Agent Care handover.
12 workstreams · 6 weeks · bar shows the weeks a workstream is active — several run in parallelFinal scope and sequence confirmed in discovery
Engagement tiers
What each tier includes
Rows are the capabilities named in each tier's scope. Higher tiers include everything below them.
Capability✓ in scope · — not at this tierPilotOne certificate, one yearProductionProduction assurance workflowAdvancedMultiple certificates / entities
Introduced at Pilot
Package assembly to your hazards✓✓✓
Accountable executive release✓✓✓
Hazard-register baseline✓✓✓
Introduced at Production
Reporting by control—✓✓
Signing workflow in your systems—✓✓
Approved write-back—✓✓
Occurrence-report integration—✓✓
Introduced at Advanced
Multi-certificate groups——✓
Cross-subpart evidence packs——✓
Large hazard registers——✓
Multi-clock retention controls——✓
Build priceFrom $5,000From $8,000Custom quote
Final build priceConfirmed after discovery based on integrations, workflow complexity, reporting volume, approval controls and deployment requirements.
Separate from buildBuild pricing is separate from recurring Agent Care, which covers managed monitoring, evaluations, incidents and verified improvements after launch.
What we need from you
What you bring, and what we build with it
Each input maps to a piece of build scope and a week in the delivery timeline.
You bringWe build with it
01Your certificates and the operations under each→Hazard-register mapping and evidence captureWeek 1
02Representative occurrence, risk and training records→Record binding, clock logic and the package baselineWeek 2
03Your risk acceptance criteria under subpart C→Hazard mapping, control binding and the automation boundaryWeek 1
04Access to relevant APIs, feeds or exports→Reporting, risk and training-source assessment, then integration setupWeek 2
05Declarations you would not want audited→Retention cases and the evaluation runWeek 4
06What no safety policy may prove→Completeness scoring, review routing, guardrails and release controlsWeek 3
07An accountable executive designated under 14 CFR 5.25(a)→Signing workflow, then pilot and production validationWeeks 5–6
Nothing else is requiredDeployment, documentation and Agent Care handover are ours.
Delivery timeline
Four phases across six weeks
Each width is the time a phase truly takes and not a layout choice, so week five holds two of them.
PhaseW1W2W3W4W5W6
DiscoveryW1
BuildW2 – W3
EvaluateW4 – W5
Pilot & LaunchW5 – W6
Week focusW1SMS workflow discovery, hazard mapping and the automation boundaryW2Source integration and the control-currency baselineW3Package assembly, retention logic and release controlsW4Evaluation suite, relevance cases and failure-mode testingW5Records integration, pilot packages and targeted correctionsW6One assurance year run under the accountable executive, then Agent Care handover
Reading the bandEach bar covers only the weeks its own work is named for. Week five takes a pair because the work does.
At the end of W6When the safety record validates, Agent Care takes the agent on.
DurationSix-week plan shown · typical delivery 4–6 weeks depending on scope confirmed in discovery.
Next step · Travel & Hospitality AI agent
Build an SMS agent around the policy your accountable executive has to sign.
Show us one hazard and the control raised against it. The accountable executive of 14 CFR 5.25(b)(2) develops and signs the safety policy, and may hand that to nobody. Part 135 and 91.147 operators declare compliance by 28 May 2027; part 121 fell due on 28 May 2025.