What the documents describe must let later phases proceed: the system, its parts, what it does and how well it must perform, together with every functional insufficiency already known, the conditions that provoke it and the countermeasures, and the design applies those countermeasures to blunt the impact of known insufficiencies. Each iteration of SOTIF activity updates the specification and design at every relevant level so it reflects everything learned. Development parties cooperate to discover insufficiencies of the integrated system and pass relevant design sections, assumptions of use, foreseeable misuse and insufficiencies up and down the tiers after each cycle. SOTIF work products are linked to the specification and design, which supports traceability and completeness, for example through model-based design tools.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.