This file captures the §9 chapter draft assembled on 2026-06-19. It is a working draft, not final publication copy. Final tone calibration is deferred to a later outreach pass.
Governance Consistency is the fifth and last of the structural prerequisites (ZTG-0a through ZTG-0e). The first four establish that a decision's inputs can be trusted: recorded (ZTG-0a), reproducible (ZTG-0b), temporally anchored (ZTG-0c), and attributable (ZTG-0d). ZTG-0e establishes that the governing rules themselves remain coherent — across the enforcement points that apply them and across the moments at which they change. It is the prerequisite that lets governance be amended without ever leaving a window in which action is ungoverned or inconsistently governed.
Operational Questions
ZTG-0e is the prerequisite mapped to governance continuity — the one operational question none of ZTG-0a through ZTG-0d answers. The others make a single decision trustworthy; ZTG-0e makes the governing order trustworthy through change. It also closes loops left open by the earlier prerequisites: it is where the ordering of governance-state transitions (flagged from ZTG-0c), the consistency of revocation and delegation-chain changes (flagged from ZTG-0d), and the governance of the observability substrate itself (flagged from ZTG-0a) are resolved. Governance continuity is the property that a system does not become ungoverned in the act of re-governing itself.
Normative
The boundary MUST operate against a consistent view of governance state, and governance state MUST change only through atomic, authorized, ordered transitions. When a consistent governance view cannot be established, the boundary MUST refuse.
Governance state is the complete set of governing inputs a decision is evaluated against: policy versions, the identity and credential registry, the surface and sub-surface registry, harm-class and ceiling declarations, and the configuration of the governance substrate itself. ZTG-0e governs the coherence of this set as a whole, across change and across enforcement points.
Atomic and Complete Transitions
A change to governance state MUST apply atomically and completely. No decision may be evaluated against a partially-applied change — a new policy version live for one component but not another, a revoked credential removed from one registry view but not the registry the boundary consults, a surface re-registered with a new harm-class default while its old default still routes some effects. A decision evaluated against a half-applied change is evaluated against a governance state that the ratifying principal never authorized, because the authorized state is the complete transition, not an intermediate of it.
This is the property a ZTG-0c point-in-time snapshot presupposes. ZTG-0c requires each decision to be evaluated against a coherent temporal cut of governance state; ZTG-0e is the requirement that such a coherent cut exists to be taken — that governance state is never, from the boundary's perspective, caught mid-transition.
Governance Change as a Governance Event
A change to governance state is itself a governed action. Every transition MUST be authorized under ZTG-0d, recorded under ZTG-0a, and ordered under ZTG-0c. The authority to change policy, alter a registry, adjust a ceiling, or reconfigure the governance substrate traces to a ratifying principal exactly as the authority to take any other governed action does, and the change is attributable to that principal.
This is where the introduction's claim of continuous ratifying authority (§1.2) becomes checkable at the point of change rather than only at the point of action. A governance change made without attributable authority is not a legitimate change to the governing order; it is an unauthorized mutation of it, and ZTG-0e requires that such a mutation be detectable rather than silently effective. The governing order is not self-modifying; it is modified by authority, on the record, in order.
Consistency Across Enforcement Points
Where governance is enforced at more than one point, all enforcement points MUST agree on the governance version in effect for a decision. A decision proceeds only under a governance view established as consistent across the points that bear on it; where enforcement points diverge — different policy versions, disagreeing registry state — the boundary MUST refuse rather than proceed under an indeterminate view.
This is a strong-consistency requirement on the governance plane, and it is a deliberate choice of consistency over availability when the two conflict. A system that continued to authorize action while its enforcement points disagreed about the governing rules would be permitting action under a governance state that does not single-valuedly exist — precisely the window of inconsistently-governed action ZTG-0e exists to foreclose. Eventual consistency, in which points may diverge and later reconcile, is not sufficient for the governance plane, because reconciliation after the fact does not retroactively govern the actions taken during divergence. The availability cost of refusing under partition is the fail-closed posture the framework adopts everywhere: when the system cannot establish that invariants hold, it does not proceed.
Governance of the Governance Substrate
The configuration of the governance substrate is itself governance state. Changes to the observability substrate (ZTG-0a) — its retention policy, record schema, integrity mechanism, and access configuration — and to the evaluation machinery's configuration are governance-state transitions subject to this chapter's requirements: authorized under ZTG-0d, recorded under ZTG-0a, ordered under ZTG-0c, and consistency-governed under ZTG-0e. The machinery that governs is not exempt from governance; an actor who could silently alter retention or access to the evidence store could defeat the audit on which every other guarantee rests.
ZTG-0e establishes this principle and does not specify its full mechanism. The detailed treatment — including how substrate self-governance avoids infinite regress and where its bootstrap authority is rooted — is deferred. The prerequisite-level requirement is that substrate configuration is inside the governed perimeter, not outside it. This resolves the observability-of-the-observer question raised and deferred in ZTG-0a.
Conformance Criteria
A conforming implementation can: evaluate decisions only against a complete, consistent governance state and demonstrate that no decision sees a partially- applied transition; demonstrate that every governance-state transition is authorized, recorded, and ordered; establish a consistent governance view across enforcement points and refuse when consistency cannot be established; demonstrate that divergence between enforcement points produces refusal rather than action under an indeterminate view; and demonstrate that changes to the governance substrate's own configuration are governed transitions, not ungoverned infrastructure changes.
Further Considerations
The constitutional grounding. Durable governing orders have always had to solve a specific problem: how to change the rules without dissolving the order in the interim. A constitution that could not be amended would ossify; a constitution that dissolved the legal order each time it was amended would produce a gap in which nothing governed. The solution every durable order converges on is the same in structure: the rules provide for their own amendment through an authorized, recorded, ordered procedure, and the existing order remains in force until the amendment completes. There is no moment of ungoverned interregnum. ZTG-0e is this principle for governed autonomous execution. Atomic transition is the no- interregnum requirement; governance-change-as-governance-event is the amendment-by- authorized-procedure requirement. The framework does not invent a novel solution to governing-through-change; it adopts the one that constitutional orders and durable institutions arrived at and makes it mechanical.
The distributed-systems grounding, convergent with it. The same structure arrives independently from distributed systems. A governance plane enforced at multiple points is a replicated state machine, and keeping replicas coherent under change is the consensus problem. The CAP result makes the tradeoff explicit: under partition, a replicated system must choose between remaining available and remaining consistent. ZTG-0e chooses consistency, which is the fail-closed posture in the vocabulary of distributed systems. That a constitutional tradition reasoning about legitimacy and a distributed-systems tradition reasoning about replicated state arrive at the same requirement — change through an authorized, ordered procedure that never exposes an inconsistent intermediate — is exactly the cross-tradition convergence the framework treats as strong evidence that the requirement is structural rather than stylistic.
Continuity is what makes the prerequisite set whole. ZTG-0a through ZTG-0d make any single decision trustworthy at the instant it is made. Without ZTG-0e, that trust would not survive the system's own evolution: the first policy update applied non-atomically, or the first divergence between two gates, would reopen everything the other prerequisites closed. Governance continuity is therefore not a fifth independent property bolted on; it is the requirement that the other four remain true as the system changes. The set is closed by it.
Refusal during change is the architecture working. A system that refuses while a governance transition is settling, or while enforcement points reconcile, will be read operationally as unavailability, and there will be pressure to relax ZTG-0e to preserve throughput during policy rollouts. As with the boundary under Stasis (ZTG-2), the refusal is the architecture functioning as designed. The brief unavailability of a consistent governance view is a real cost; proceeding under an inconsistent one is a governance failure. The framework does not trade the second to avoid the first.
Relationship to Stasis. Persistent inability to establish a consistent governance view is more than a momentary refusal; it is a candidate Stasis (ZTG-2) condition, in the same family as persistent loss of temporal integrity (ZTG-0c). The boundary-level response is refusal; the system-level response to sustained inconsistency belongs to ZTG-2. ZTG-0e establishes the refuse-not-proceed condition; ZTG-2 owns escalation from repeated refusal to held state.
How We Do It
Constable treats governance state as a single versioned, consistently-distributed object, changes it only through authorized atomic transitions, and refuses when its enforcement points cannot agree on the version in effect.
Versioned governance bundles. Policy, registries, harm-class and ceiling declarations, and substrate configuration are assembled into versioned governance bundles. The gate evaluates against a single bundle version, pinned at decision-time per ZTG-0c. A bundle is the unit of atomic transition: a change is a new bundle version that becomes effective as a whole, never field-by-field, so no decision sees a partially-applied change.
Authorized, recorded, ordered transitions. A bundle transition is itself an authorized action: it is signed by a ratifying principal under ZTG-0d, emitted as a governance event under ZTG-0a, and ordered against the Monotonic Logger under ZTG-0c. A bundle that does not trace to a ratifying principal is not adopted. The record of which principal moved governance from version N to version N+1, and when, is part of the evidence substrate.
Consistent distribution across gates. Where Constable runs more than one gate, all gates resolve the governance bundle version for a decision through a consistently-distributed mechanism, and a gate that cannot confirm it is operating the agreed version refuses rather than evaluating against a possibly-stale bundle. Constable chooses consistency under partition: a gate isolated from the governance plane fails closed.
Substrate configuration inside the perimeter. Changes to Monotonic Logger retention, record schema, integrity mechanism, and access configuration are carried as part of the governance bundle, so reconfiguring the evidence substrate is an authorized, recorded, ordered, consistency-governed transition rather than an out-of-band infrastructure change. The mechanism for rooting the substrate's bootstrap authority is documented separately and flagged below as not fully settled.
Conformance tests. Constable's internal testing for ZTG-0e includes: atomicity tests confirming no decision observes a partially-applied bundle transition; authorization tests confirming unsigned or unattributed transitions are not adopted; cross-gate consistency tests confirming divergent gates refuse rather than act; partition tests confirming an isolated gate fails closed; and substrate-governance tests confirming evidence-store reconfiguration is a governed transition. The protocol is documented in the conformance verification specification referenced in §22.
Draft Flags
- Resolves three inbound flags. ZTG-0c's "ordering of governance-state transitions," ZTG-0d's "revocation/delegation-chain consistency," and ZTG-0a's "observability-of-the-observer" are all resolved here: transitions are atomic, authorized, ordered events, and substrate configuration is inside the governed perimeter. If those chapters are revised, keep them pointed at ZTG-0e for the resolution.
- Substrate self-governance bootstrap / infinite regress. ZTG-0e establishes that substrate configuration is governance state but explicitly defers the mechanism, including how self-governance avoids infinite regress and where bootstrap authority is rooted. This is a genuine open architectural question, not a drafting gap; flag for a dedicated session (possibly §22 conformance or a foundations note), not for in-chapter resolution.
- Stasis (ZTG-2) escalation from sustained inconsistency. ZTG-0e sets the refuse-not-proceed condition; ZTG-2 owns escalation from repeated refusal to held state. Same handoff as ZTG-0c's temporal-integrity-loss flag — ZTG-2 should collect both. Flag for ZTG-2.
- CAP/availability stance is now explicit and global. ZTG-0e states the consistency-over-availability choice plainly. Confirm this is consistent with how later invariants (especially ZTG-2 Stasis and any availability-related discussion) present the tradeoff, so the framework speaks with one voice on it.
- §22 Conformance Verification is referenced but not yet captured in this workspace.
- The chapter is substantively complete but likely needs final tone calibration for publication register.