Part 5 · The Governance Matrix
The 190 control objectives
Ten ingredients × nineteen structural primitives. Every intersection is one named control objective — a single “shall” statement. Read down an ingredient to see its full governance profile.
155 evidence-grounded 35 coverage gaps 1 challenged
01
Purpose
What the system is for, declared where it can be pointed at.intentThe apex objective shall be a single, named intent record from which all subordinate objectives derive.M
evidenceThe apex objective shall carry empirically anchored success criteria comprising both leading and trailing signals.S
authorityThe apex objective's authority holder shall be the constituting authority from which all delegation originates.B
workThe apex objective shall generate at least one traceable work specification that operationalizes intent into executable governance activity.M
constraintEvery operational constraint shall inherit from the apex objective's negation clause under tighten-only propagation.B
decisionRevision of the apex objective shall be the most tightly governed decision surface in the system.B
accountGovernance findings at the apex level shall resolve to the constituting authority through self-referential closure.T
commitmentThe apex objective shall carry explicit commitments that bind the constituting authority before they bind anyone else.B
capacityThe apex objective shall be scoped to the system's assessed capacity, with capacity gaps documented as governance findings.M
identifierThe apex objective shall carry a stable, system-unique identifier that all downstream records reference when tracing to purpose.T
entityThe apex objective shall name the entity or entity class that holds constituting authority over it.B
contextThe apex objective shall declare the operational context within which it applies, including domain boundaries and jurisdictional scope.S
namespaceThe apex objective shall anchor the root namespace from which all governed terms derive their resolution authority.B
orientationThe apex objective shall declare the system's epistemic orientation — the foundational stance from which observations are interpreted.S
learningThe apex objective shall specify the conditions under which accumulated evidence warrants revising purpose itself.S
activationThe apex objective's activation conditions shall be the system's entry gate — the threshold that initiates governed operation.B
interpretationThe apex objective shall specify interpretation rules for resolving ambiguity in its own terms.B
environment-interfaceThe apex objective shall declare the system's environment-interface boundary — what the governed system treats as internal versus external.B
cycleThe apex objective shall specify its governance review cadence and the conditions under which the review cycle itself is revised.T
02
Distinctions
The categories it draws and treats as real.intentEvery distinction shall trace to an intent that justifies its existence in the governed vocabulary.M
evidenceEvery operative term shall resolve to a specific definition source through an auditable resolution chain.S
authorityNamespace authority (who defines terms) shall be separated from content authority (who uses terms).B
workChanges to the governed vocabulary shall be governed work — scoped, authorized, and evidenced like any other state transition.M
constraintNamespace constraints shall propagate through inheritance such that parent-level definitions bind child records under tighten-only rules, with opaque terms protected from premature resolution.B
decisionCreation of identifiers, assignment of artifacts to namespaces, and resolution of terms to definitions shall each be governed decision surfaces.B
accountNamespace conflicts shall resolve by following the authority chain to the nearest authority with jurisdiction over both namespaces.T
commitmentThe governed vocabulary shall carry a stability commitment specifying which terms are frozen, which are mutable, and the conditions for promotion between states.B
capacityThe governed vocabulary's capacity — the number of terms, depth of hierarchy, and resolution precision — shall be assessed against the governance demands placed on it.M
identifierEvery governed term shall carry a unique, stable identifier that persists through definition changes and namespace migrations.T
entityEvery governed term shall be attributable to an authoring entity whose namespace authority is registered.B
contextEvery governed term shall declare the contexts in which it is operative and the contexts in which it is inoperative or carries a different meaning.S
namespaceThe namespace hierarchy shall be explicit, rooted at the apex, and navigable such that any term can be resolved to its authoritative definition by traversing the namespace tree.B
orientationThe governed vocabulary shall declare its epistemic orientation — whether it is descriptive, prescriptive, or normative — at the namespace level.S
learningThe governed vocabulary shall evolve through a declared learning process: observation of usage gaps, proposal of new terms, and governed adoption.S
activationNew terms shall not be operative until activation conditions are met — at minimum, definition, namespace assignment, and authority registration.B
interpretationInterpretation of governed terms shall follow declared resolution rules, with ambiguity resolved by ascending the namespace hierarchy to the nearest authoritative definition.B
environment-interfaceThe governed vocabulary shall declare which terms name internal system states and which name environment-observable phenomena, with the boundary explicit.B
cycleThe governed vocabulary shall undergo periodic review at a declared cadence, with obsolete terms retired and emerging terms assessed for adoption.T
03
Entities
The things it tracks, and how they're registered.intentEvery registered entity shall carry a declared intent specifying the entity's purpose within the governance system.M
evidenceEvery entity shall be traceable to a registration record specifying type, authority bindings, delegation source, and (for computational actors) underlying model.S
authorityEvery authority chain shall terminate at a registered entity, with the three-layer behavioral-contract architecture operating on entities as subjects.B
workWork assignment shall be traceable to a registered entity with sufficient authority and capacity to execute the assigned work.M
constraintEntity-level constraints shall propagate through role envelopes and behavioral contracts under tighten-only rules.B
decisionCreation of entities, assignment of authority, and assessment of capacity shall each be governed decision surfaces.B
accountAccountability for governance failure shall follow a deterministic entity chain from the acting entity through delegation to the granting authority.T
commitmentEvery entity shall carry explicit commitments that bind its behavior across engagements, distinct from per-interaction contracts.B
capacityEvery entity shall carry a current capacity assessment specifying what the entity can be authorized to do, with capacity limits enforced as structural constraints.M
identifierEvery entity shall carry a stable, system-unique identifier that persists through role changes, authority reassignments, and lifecycle transitions.T
entityThe entity registry shall enforce type classification (human, computational, organizational, composite) with each type carrying distinct governance constraints.B
contextEvery entity's authority and capacity shall be context-qualified — specifying the domains, periods, and conditions under which the entity is authorized to act.S
namespaceEvery entity shall be registered within a namespace that determines the entity's resolution scope and prevents identifier collisions across governance domains.B
orientationEvery entity shall declare or inherit an epistemic orientation that governs how the entity's observations and claims are weighted in governance decisions.S
learningEvery entity shall have a declared learning pathway specifying how the entity's capacity and authority evolve based on accumulated performance evidence.S
activationEntity activation — the transition from registered to operative — shall require satisfaction of declared preconditions including authority grant, capacity verification, and commitment acknowledgment.B
interpretationDisputes about entity authority, capacity, or accountability shall be resolved through declared interpretation rules that reference the entity registry and delegation chain.B
environment-interfaceComputational entities shall declare their environment-interface specification — what the entity can observe, what it can act upon, and what lies outside its perception surface.B
cycleEntity registrations shall be reviewed at a declared cadence, with inactive entities retired, capacity assessments refreshed, and authority bindings revalidated.T
04
Constraints
The rules that bind it, and which one wins.intentEvery constraint shall trace to an intent that it serves — the objective whose achievement the constraint protects or enables.M
evidenceEvery constraint shall specify an observable violation condition and a detection mechanism.S
authorityAuthority to create, modify, or waive a constraint shall be a distinct governance surface separate from content authority.B
workConstraint enforcement shall be traceable to specific work — the operational activity that detects violations and triggers governance responses.M
constraintConstraint propagation shall operate through six defined patterns: tighten-only, halt-and-escalate, explicit composition, negation propagation, lateral inheritance with weights, and effective constraint set.B
decisionImposition of a constraint and granting of an exception shall each be named decision surfaces with documented alternatives and rationale.B
accountConstraint violation accountability shall follow the authority chain from violating act through delegation, including the granting authority where a waived exception exists.T
commitmentEvery constraint shall carry a commitment classification specifying whether it is absolute (never waivable), conditional (waivable under stated conditions), or advisory (informational only).B
capacityThe effective constraint set at any governance point shall be computationally deterministic — an actor with the constraint specification and the relation graph shall be able to compute the active constraints.M
identifierEvery constraint shall carry a stable identifier that persists through amendments, enabling constraint-level audit trails and cross-reference.T
entityEvery constraint shall name the entity class or specific entities to which it applies, with applicability scope explicit.B
contextEvery constraint shall declare the contexts in which it is active and the contexts in which it is suspended or modified.S
namespaceConstraints shall be organized within the namespace hierarchy such that constraint scope aligns with namespace scope and inheritance follows the namespace tree.B
orientationConstraints shall declare their epistemic basis — whether derived from principle, from observed risk, from regulatory requirement, or from constituting authority direct.S
learningThe constraint architecture shall evolve through a declared learning process: constraint effectiveness review, gap identification, and governed amendment.S
activationConstraint activation shall follow a declared process: creation, review, approval, and activation as distinct lifecycle stages.B
interpretationConstraint ambiguity shall be resolved by ascending the authority chain to the constraint's author or to the nearest authority with jurisdiction over the ambiguous scope.B
environment-interfaceConstraints that reference environment-observable conditions shall declare the observation mechanism and the confidence threshold for determining that the condition obtains.B
cycleThe constraint register shall undergo periodic review at a declared cadence, with effectiveness assessed, obsolete constraints retired, and gap analysis performed.T
05
Time
How it stays continuous and current across change.intentEvery governance cycle shall trace to an intent that justifies its cadence — the governance purpose that the cycle serves.M
evidenceEvery decision shall carry temporal evidence establishing when it was made relative to available information, with timeliness auditable.S
authorityAuthority to set cycle cadence shall be a strategic governance surface distinct from content authority.B
workTemporally governed work shall carry explicit start conditions, duration constraints, and completion criteria with each transition auditable.M
constraintTemporal constraints shall propagate through lifecycles such that terminated directives cannot bind after termination and period-of-performance constraints specify active windows.B
decisionEvery cycle transition — start of review, disposition of finding at cycle-end, extension, and termination — shall be a governed decision boundary.B
accountAccountability resolution shall establish temporal causation: whether the entity had needed information before failure and whether corrective action was timely.T
commitmentTemporal commitments — review deadlines, response windows, carry-forward obligations — shall be explicit and enforceable, with missed deadlines producing governance findings.B
capacityThe governance system's temporal capacity — the number of cycles, reviews, and dispositions it can process per period — shall be assessed against its governance workload.M
identifierEvery governance period, cycle instance, and lifecycle stage shall carry a unique identifier enabling temporal cross-reference and historical audit.T
entityEvery governance cycle shall name the entity or entities responsible for initiating, conducting, and closing the cycle.B
contextTemporal governance requirements shall be context-qualified — different governance contexts may warrant different cycle cadences and lifecycle definitions.S
namespaceTemporal constructs (periods, cycles, stages) shall be defined in the namespace with stable identifiers, enabling cross-system temporal alignment.B
orientationThe governance system shall declare its temporal orientation — whether it is forward-looking (planning), concurrent (monitoring), or retrospective (auditing) — at each governance surface.S
learningGovernance cycle parameters (cadence, duration, scope) shall be revisable based on accumulated evidence about governance effectiveness at prior cadences.S
activationGovernance cycle activation shall require satisfaction of preconditions — at minimum, availability of required evidence from the prior period and assignment of responsible entities.B
interpretationTemporal ambiguity — disputes about when a decision was made, whether a deadline was met, or which period an event falls in — shall be resolved through declared interpretation rules referencing the temporal identifier registry.B
environment-interfaceThe governance system's temporal awareness shall be bounded by its environment-interface — the system can only govern temporal relationships for events within its observation surface.B
cycleThe governance cycle shall be self-governing: the cadence, scope, and effectiveness of the cycle itself shall be reviewed at a declared meta-cycle cadence.T
06
Observation
How it takes the world in, and on whose authority.intentEvery observation capability shall trace to an intent — the governance purpose that justifies what the system observes and at what resolution.M
evidenceObservations shall preserve capture-time immutability: what was observed and the conditions of observation shall be retained as-is.S
authorityInterpretive authority shall be a distinct governance surface separated from observation authority and action authority.B
workObservation activities shall be governed work — scoped, scheduled, authorized, and evidenced — not ambient background processes exempt from governance oversight.M
constraintObservation constraints shall propagate through the interface specification such that no downstream record can claim evidence about a domain not covered by the perception surface.B
decisionEvery interpretation of an ambiguous signal shall be a governed decision where the assigned meaning and alternative interpretations are documented.B
accountDisputed observations shall be resolved by examining orientation, interface, context, and interpretation as independent factors.T
commitmentThe observation system shall carry explicit commitments regarding observation frequency, coverage scope, and reporting obligations.B
capacityThe observation system's capacity — resolution, coverage, and throughput — shall be assessed against governance demands and documented with capacity gaps as findings.M
identifierEvery observation event shall carry a unique identifier enabling traceability from raw observation through interpretation to governance action.T
entityEvery observation shall be attributable to an observing entity whose capacity, authority, and potential biases are registered.B
contextEvery observation shall carry context metadata — the conditions under which the observation was made — that qualifies the observation's applicability and reliability.S
namespaceObservations shall be classified within the governed namespace such that observed phenomena resolve to governed terms and unclassifiable observations are flagged as vocabulary gaps.B
orientationThe observation system shall declare its epistemic orientation — the assumptions, models, and frameworks that shape what it looks for and how it interprets what it finds.S
learningThe observation system shall evolve through a declared learning process: observation effectiveness review, coverage gap identification, and governed recalibration.S
activationObservation mechanisms shall activate only when declared preconditions are met — at minimum, calibration verification, authority grant, and scope confirmation.B
interpretationInterpretation of observations shall follow declared rules specifying how raw signals map to governed meanings, with interpretation disputes resolvable by examining the rules themselves.B
environment-interfaceThe observation system shall declare its environment-interface specification — the boundary between what it can observe and what lies outside its perception surface.B
cycleObservation activities shall operate within a declared cycle — observation windows, reporting periods, and review cadences — with out-of-cycle observations requiring justified exceptions.T
07
Relations
How its things connect and commit to each other.intentEvery relation shall trace to an intent that justifies its existence — the governance purpose served by connecting these two objects.M
evidenceEvery relation shall be auditable: cross-references shall resolve, parent references shall form a valid chain to the apex, and class memberships shall satisfy applicability scope.S
authorityAuthority shall flow through the relation structure — hierarchical and class-membership — such that traversable authority chains are determined by the relation graph.B
workRelation maintenance — creation, modification, retirement, and integrity verification — shall be governed work, not a side effect of other operations.M
constraintRelations shall serve as the channels through which all six constraint-propagation patterns operate.B
decisionCreation or modification of any relation — parent reference, class membership, cross-reference — shall be a governed decision that alters the governance graph.B
accountThe quality of accountability resolution shall be proportional to the quality of the relation graph, with broken relations constituting findings.T
commitmentThe relation architecture shall carry stability commitments specifying which structural relationships are frozen and which are subject to governed change.B
capacityThe relation graph's capacity — depth of hierarchy, breadth of cross-reference, and navigability under load — shall be assessed against governance demands.M
identifierEvery relation shall carry a stable identifier enabling relation-level audit trails, modification history, and cross-reference from governance findings.T
entityEvery relation shall connect registered entities or governed objects — no relation endpoint shall be unregistered.B
contextRelations shall declare the contexts in which they are active — a relation that applies in one governance context but not another must declare both states.S
namespaceRelations shall be scoped within the namespace hierarchy such that cross-namespace relations are explicitly declared and their resolution rules are specified.B
orientationThe relation architecture shall declare its orientation — whether relations represent structural hierarchy, temporal sequence, causal dependency, or associative reference — at the class level.S
learningThe relation architecture shall evolve through a declared learning process: graph integrity review, navigation efficiency assessment, and governed restructuring.S
activationNew relations shall activate only after structural validation — at minimum, endpoint verification, constraint compatibility check, and authority confirmation.B
interpretationAmbiguous relations — edges whose type, direction, or scope is unclear — shall be resolved through declared interpretation rules referencing the relation type system.B
environment-interfaceThe relation graph shall declare which relations connect internal system nodes and which span the environment-interface boundary, with boundary-spanning relations carrying additional governance requirements.B
cycleThe relation graph shall undergo periodic integrity review at a declared cadence, with broken references repaired, orphaned nodes identified, and structural health assessed.T
08
Transition Logic
How one state becomes the next, legibly.intentEvery state transition shall trace to an intent — the governance purpose that the transition serves or advances.M
evidenceEvery work specification shall name the evidence it will produce, at what granularity, and with what verification surface.S
authorityAuthority to define work, set activation conditions, and modify transition rules shall be three distinct governance surfaces separated from operational authority.B
workWork specifications shall be structurally complete: named inputs, named outputs, success criteria, constraint set, authority binding, and evidence commitment.M
constraintWork shall inherit its effective constraint set from the parent objective, class memberships, and local declarations.B
decisionEvery activation and every state transition in the lifecycle of governed work shall be a governed decision boundary.B
accountAccountability for work failure shall follow the delegation chain from executor through authorizing authority to the served objective, with transition rules establishing where in the lifecycle failure occurred.T
commitmentWork specifications shall carry explicit completion commitments — what "done" means — that are testable before the work's output enters the governance system.B
capacityWork assignments shall be validated against the executing entity's capacity before activation, with capacity insufficiency producing a governance finding rather than silent degradation.M
identifierEvery work instance, state transition, and lifecycle stage shall carry a unique identifier enabling work-level audit trails and cross-reference.T
entityEvery work instance shall be bound to a registered entity (executor) and traceable to an authorizing entity, with both bindings auditable.B
contextWork specifications shall declare the context in which they operate — the governance domain, temporal period, and environmental conditions that scope the work.S
namespaceWork-related terms (statuses, transition names, output types) shall be defined in the namespace with stable identifiers, ensuring consistent usage across work instances.B
orientationWork specifications shall declare whether the work is investigative (seeking evidence), constructive (producing output), corrective (addressing findings), or evaluative (assessing other work).S
learningTransition logic shall evolve through a declared learning process: lifecycle effectiveness review, bottleneck identification, and governed rule amendment.S
activationWork activation shall require satisfaction of declared preconditions — at minimum, authority grant, constraint set inheritance, and evidence commitment registration.B
interpretationDisputes about work completion, state transitions, or lifecycle stage shall be resolved through declared interpretation rules referencing the work specification and transition rule definitions.B
environment-interfaceWork that interacts with the system's environment — producing external outputs, consuming external inputs, or modifying external state — shall declare its environment-interface requirements explicitly.B
cycleWork lifecycles shall operate within declared temporal cycles, with work that persists beyond its expected cycle producing a carry-forward finding.T
09
Memory
What it retains, and what it is architecturally allowed to hold true.intentThe memory system shall trace to an explicit intent: the governance purpose of retaining evidence, crystallizing learning, and preserving institutional knowledge.M
evidenceThe evidence-retention discipline shall be reflexively evidenced: the system shall retain evidence that its own evidence-retention discipline is functioning.S
authorityAuthority over retention policy, retention duration, and evidence sufficiency shall be a distinct governance surface separated from observation and operational authority.B
workMemory operations — evidence capture, triage, crystallization, and decay — shall be governed work with traceable work specifications and evidence commitments.M
constraintRetention constraints shall propagate such that no downstream record specifies shorter retention than the apex requires, and learning constraints propagate through class-membership review obligations.B
decisionEvery learning-lifecycle transition — capture, triage, crystallize, or decay — shall be a governed decision, with decay decisions documented because crystallization was the alternative.B
accountAccountability for memory failure — evidence not retained, findings that did not trigger learning, corrective actions lost — shall follow the authority chain responsible for the memory system.T
commitmentThe memory system shall carry explicit retention commitments specifying minimum retention periods, evidence quality thresholds, and conditions under which decay is permissible.B
capacityThe memory system's capacity — storage, retrieval speed, and evidence integrity maintenance — shall be assessed against governance demands, with capacity shortfalls producing findings.M
identifierEvery retained evidence artifact shall carry a unique identifier enabling retrieval, cross-reference, and lifecycle tracking across governance periods.T
entityEvery evidence artifact shall be attributable to a capturing entity whose observation authority and capacity are registered.B
contextEvery retained evidence artifact shall carry context metadata — the conditions of capture, the governance period, and the observation circumstances — that qualifies its applicability.S
namespaceEvidence artifacts shall be classified within the governed namespace such that evidence types, retention categories, and learning outcomes resolve to governed terms.B
orientationThe memory system shall declare its epistemic orientation toward retained evidence — whether evidence is treated as immutable historical record, as input to learning, or as both.S
learningThe memory system shall implement a declared learning process: pattern detection across retained evidence, proposal of systemic changes, and governed crystallization of learning into system modifications.S
activationLearning crystallization — the transition from accumulated evidence to system modification — shall activate only when declared thresholds are met, preventing premature generalization from insufficient evidence.B
interpretationDisputes about evidence quality, retention sufficiency, or learning validity shall be resolved through declared interpretation rules referencing the evidence taxonomy and retention commitments.B
environment-interfaceThe memory system shall declare its environment-interface — what evidence the system can retain about its own state versus what evidence it can retain about the external environment.B
cycleThe memory system shall operate within a declared review cycle — evidence review, retention assessment, learning review, and decay disposition — with cycle-level evidence produced about the memory system's health.T
10
Uncertainty
What it knows vs. declares vs. derives vs. cannot see.intentThe uncertainty management architecture shall trace to an explicit intent: the governance purpose of making the system's unknowns visible, classifiable, and actionable.M
evidenceEvery claim's truth type shall be documented and auditable as meta-evidence — evidence about the quality of the system's other evidence.S
authorityAuthority to assign truth types shall be a distinct governance surface separated from content authority.B
workInvestigation of uncertainty — the work of resolving opaque or declared claims toward authoritative status — shall be governed work with explicit scope, authority, and evidence commitments.M
constraintTruth types shall constrain derivation such that authoritative findings cannot issue from opaque inputs without declaring the derivation chain and epistemic limitations.B
decisionAssignment of truth types, resolution of investigative queries, and promotion of claims along the opaque-declared-authoritative chain shall each be governed decision surfaces.B
accountAccountability for epistemic failure shall examine the truth-type chain to establish whether the decision-maker knew the reliability limits of the claims on which they relied.T
commitmentThe governance system shall carry explicit commitments regarding epistemic standards — what truth-type thresholds are required for different classes of governance decisions.B
capacityThe governance system's capacity to assess, classify, and track uncertainty shall be assessed against its epistemic demands, with capacity shortfalls producing findings.M
identifierEvery investigative query shall carry a unique identifier enabling lifecycle tracking from creation through investigation to resolution or retirement.T
entityEvery truth-type assignment shall be attributable to a registered entity whose epistemic authority is documented.B
contextTruth-type classifications shall be context-qualified — a claim may be authoritative in one context and declared or opaque in another.S
namespaceEpistemic constructs (truth types, query statuses, derivation chain labels) shall be defined in the namespace with stable identifiers, ensuring consistent usage across governance domains.B
orientationThe uncertainty management architecture shall declare its epistemic orientation — the philosophical stance (e.g., closed-world, open-world, or hybrid) that governs how absence of evidence is interpreted.S
learningThe uncertainty management architecture shall evolve through a declared learning process: review of truth-type classification effectiveness, query resolution patterns, and epistemic propagation accuracy.S
activationTruth-type promotion — the transition from opaque to declared, or from declared to authoritative — shall activate only when declared evidentiary thresholds are met.B
interpretationEpistemic disputes — disagreements about truth-type classifications, derivation chain validity, or investigation adequacy — shall be resolved through declared interpretation rules referencing the epistemic taxonomy and evidentiary standards.B
environment-interfaceThe uncertainty management architecture shall declare which uncertainties arise from internal system limitations and which arise from environment-interface limitations, with different governance treatments for each.B
cycleThe uncertainty register — the system's inventory of acknowledged unknowns, open queries, and epistemic gaps — shall undergo periodic review at a declared cadence, with stale queries dispositioned and emergent uncertainties captured.T
← the framework155 of 190 evidence-grounded · 412 findings · 20 reports