ZTG does not run in isolation. It governs a reasoning system it did not build, draws time and identity from external services, reaches the world through external effect targets, and may itself sit upstream or downstream of other systems. The Composition Requirements specify what must be true of the systems ZTG composes with, so that its invariants survive composition rather than being silently weakened at the seams. Where §3 specifies the decision at the center and §22 specifies how conformance is verified, §4 specifies the architecture's perimeter: which composing systems are inside the trust boundary, which are outside it, and what each must guarantee.
Operational Questions #
§4 is not mapped to one of the seven operational questions; it is what keeps the seven true across the architecture's boundary with other systems. Each invariant holds within the governed perimeter; §4 is the requirement that nothing crossing that perimeter — an input, a time value, an identity, an effect, an evidence record — degrades the invariant it touches. A guarantee that holds internally but dissolves at the first composition seam is not a guarantee an institution can rely on, and §4 is where the seams are governed.
Normative #
Every system ZTG composes with is either inside the trust boundary or outside it, and the architecture MUST treat it accordingly. A system inside the boundary is one whose guarantees ZTG depends on; it MUST meet the composition requirement stated for its role, and that requirement MUST be one ZTG can verify, not one it assumes. A system outside the boundary is treated as untrusted: it may propose, supply candidate data, or receive derived output, but it MUST NOT be a source of any governance input ZTG relies on. There is no third category — no system trusted because trusting it is convenient, and no governance input accepted on the strength of a composing system's good behavior.
Where a composing system that would need to be inside the boundary cannot meet its requirement, the architecture MUST either relocate it outside the boundary and treat it as untrusted, or refuse to compose. It MUST NOT compose with the unmet requirement and proceed as if it were met. This is the perimeter form of fail-closed: an unverifiable composition is not a smaller guarantee, it is the absence of one.
The Reasoning System #
The reasoning system composes as a proposer only. It is inside the deployment but outside the trust boundary: it originates candidate actions and their parameters, and nothing else ZTG relies on. It MUST NOT hold an authorizing identity (ZTG-0d), supply or influence decision-time (ZTG-0c), or elevate its own memory contents into policy (ZTG-1). The reasoning system's outputs are untrusted input and are sanitized as such before they enter an authorization request (§18). Composing a more capable or better-aligned model does not move it inside the boundary; capability and alignment are Envelope properties, and the boundary's guarantees MUST NOT depend on them (§1.3).
Memory Subsystems #
A memory subsystem composes through an explicit, attested promotion protocol. Raw memory contents MUST NOT be visible to policy evaluation, and memory content becomes a policy-relevant input only by being promoted through a protocol that requires named human attestation, recorded as a governance event (ZTG-1, ZTG-0a). The structural reason is the one ZTG draws for time and identity: memory is typically writable by the same reasoning system whose outputs the boundary gates, so unpromoted memory is a governance input the governed subject controls, which is not a governance input. A composing memory subsystem that cannot expose such a promotion protocol is outside the boundary, and its contents reach policy only after passing through one that can.
Time and Identity Services #
A composing time source MUST meet ZTG-0c: attestable integrity, monotonic advance, bounded and recorded skew, and no path by which the reasoning system can set or influence it. A composing identity and credential service MUST meet ZTG-0d: non-repudiable, revocable cryptographic credentials whose delegation chains terminate at a human or institutional ratifying principal. These services are inside the trust boundary by necessity — the architecture's guarantees rest on them — so the requirement on them is not negotiable, and a service that cannot meet it cannot supply ZTG's time or identity.
Input Sources #
Every input that reaches governance evaluation MUST pass the Input Sanitization Boundary (§18) first, and the gate MUST accept only sanitized inputs. This applies to all input classes without exception: end-user input, reasoning-system output, promoted memory, and external data pulled into the decision. Input sanitization is the specific composition requirement that §18 details; §4 establishes that it is mandatory for every input-bearing composition and that there is no input path into evaluation that bypasses it.
Effect Targets #
An external system that an effect acts upon composes only through a registered surface (ZTG-3). The architecture holds no ambient capability to reach an effect target outside the enumerated surfaces, so composing a new effect target is the governed act of registering a surface for it, not the ad-hoc acquisition of a new effector. Where ZTG-4 reconciliation of an indeterminate effect requires establishing what actually happened at the target, the target's queryability is a composition property: a target that cannot be queried to establish an effect's disposition raises the cost of an indeterminate effect, which is a reason to classify effects through it conservatively (ZTG-5), not a reason to weaken the coupling requirement.
Evidence Consumers #
A system that consumes ZTG's records — a dashboard, an analytics pipeline, a downstream report — composes as a reader of derived views. It MUST NOT be the system of record (ZTG-0a owns that), and its derived outputs MUST NOT feed back as governance inputs unless they re-enter through a governed path: a metric computed downstream is not a governance fact, and an architecture that let its own dashboards become inputs to its decisions would have created a path for derived presentation to influence governance unattributably. Evidence consumers read; they do not govern.
Composition With Other Governed Systems #
The hardest seam is ZTG composing with ZTG: one governed system's effect becoming another governed system's input, or governed systems acting in concert. Across such a seam, the invariants MUST hold end-to-end, not merely within each system. A downstream governed system MUST treat an upstream system's outputs as untrusted input subject to its own sanitization and authorization, and MUST verify any attestation an upstream system carries rather than honoring it on trust — the delegation chain (ZTG-0d) must be checkable across the seam, or it does not cross it. Exposure composes across the seam rather than resetting: a sequence that crosses governed systems accumulates assessment as ZTG-5 composition does across surfaces, so that routing an action chain through multiple systems does not launder its exposure. This chapter establishes the principle; the full treatment of multi-system and multi-agent composition is larger than §4 and is flagged as partially specified.
Conformance Criteria #
A conforming implementation can: classify every composing system as inside or outside the trust boundary and demonstrate that no governance input derives from an outside system; demonstrate that the reasoning system composes as proposer-only, holding no authorizing identity, time, or unpromoted-memory authority; demonstrate that time and identity services meet ZTG-0c and ZTG-0d; demonstrate that every input path passes §18; demonstrate that effect targets are reachable only through registered surfaces; demonstrate that evidence consumers cannot feed derived views back as governance inputs unattributably; and demonstrate that, where it composes with another governed system, attestations are verified and exposure composes across the seam. Where a composing system cannot meet its requirement, the implementation can show it is treated as untrusted or that composition is refused, never composed-and-degraded.
Further Considerations #
The end-to-end grounding. Systems engineering settled, decades ago, a question about where a guarantee must live. The end-to-end argument observed that a property such as reliable or correct delivery can be completely guaranteed only by the endpoints that understand it; implementing it in a lower layer the endpoints merely trust produces a function that is, from the endpoint's standpoint, incomplete and not fully relied upon. ZTG's composition stance is this argument applied to governance. A governance property must be enforced at the layer that owns the invariant — the boundary, the gate, the evidence substrate — and MUST NOT be assumed of a composing layer that does not itself guarantee it. When ZTG accepts a time value, an identity, or an input from a composing system, it does not inherit a governance guarantee from that system; it either verifies the property at its own boundary or treats the system as untrusted. The end-to-end argument explains why: a guarantee assumed of a lower layer one does not control is not a guarantee, only a hope wearing its name.
Composition is asymmetric. ZTG is built to be composed into untrusted environments — governing a reasoning system it cannot trust is the entire point — but its guarantees do not propagate outward by composition. A system that wraps or invokes a ZTG-conformant component does not thereby become governed; it becomes governed only by meeting the requirements itself. This asymmetry is worth stating because it is easy to assume the reverse: that touching a governed system confers governance. It does not. Governance is a property of an architecture meeting the invariants, not a contagion spread by adjacency.
The perimeter is where overclaiming happens. Most overstatements of what a governance architecture provides occur at the seams: a conformant core composed with a non-conformant input source, effect target, or downstream consumer, described as if the whole were governed. §4 exists partly to make the bound honest — the guarantee holds to the perimeter and no further, and a composition that crosses the perimeter into an ungoverned system is exactly where the guarantee stops. Naming the perimeter is what keeps the claim truthful.
Multi-system governance is the open frontier. The composition of governed systems with each other — agent-to-agent, governed-pipeline-to-governed-pipeline — is where the most interesting and least settled questions live: how delegation chains compose, how exposure accumulates across organizational boundaries, how Stasis in one system propagates to those depending on it. §4 sets the principle (invariants hold end-to-end, attestations are verified not trusted, exposure composes) and is candid that the full treatment is future work.
How We Do It #
Constable's perimeter is a small set of named composition surfaces, each explicitly placed inside or outside the trust boundary.
Inside the boundary. The trusted time service (ZTG-0c), the identity and credential system (ZTG-0d), the Monotonic Logger (ZTG-0a), the surface registry and adaptors (ZTG-3), and HumanSeal (the human-authority path) are inside the boundary; each is held to the requirement its invariant states, and Constable's conformance regime (§22) verifies that it meets it rather than assuming it does.
Outside the boundary. The agent runtime composes as proposer-only; Airlock sanitizes its output and every other input (§18) before the gate sees it; Memoria exposes the attested promotion gate through which memory content may become policy-relevant input. No governance input is taken from any of these on trust.
Effect targets and consumers. External effect targets are reachable only through registered surface adaptors; Constable acquires a new effector only by registering a surface for it under governance (ZTG-0e). Evidence consumers — operator dashboards, exports — read derived views computed from the Logger and cannot write back into the decision path.
Composition checks. Constable's conformance tests for §4 confirm that no governance input resolves to an outside system, that the agent holds no time/identity/promotion authority, that every input path traverses Airlock, and that effect targets are reachable only through registered surfaces. The protocol is documented in the conformance verification specification referenced in §22.