§5.1 Matrix D: Control Objective Register
The governance matrix crosses the ten ingredients (columns) against the nineteen DLP primitives (rows) to produce one hundred ninety named control objectives. Each control objective is a "shall" statement specifying the structural requirement at that intersection. The naming convention is CO-{INGREDIENT}-{PRIMITIVE} where ingredient codes are PU, DI, EN, CO, TI, OB, RE, TL, ME, UN and primitive codes are INT, EVD, AUT, WRK, CST, DEC, ACT, CMT, CAP, IDN, ENT, CTX, NSP, ORI, LRN, ACV, ITP, EIF, CYC.
The five governance disciplines (Authority Mapping, Decision Boundary, Constraint Propagation, Evidence Obligations, Accountability Resolution) remain as a COSO-bridged navigational overlay. Each discipline groups a subset of the nineteen primitives for practitioners familiar with COSO IC 2013. But the primary test surface is the full nineteen-primitive matrix — every ingredient tested against every primitive.
Summary Table — 190 Control Objective IDs
| INT | EVD | AUT | WRK | CST | DEC | ACT | CMT | CAP | IDN | ENT | CTX | NSP | ORI | LRN | ACV | ITP | EIF | CYC | |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| PU | CO-PU-INT | CO-PU-EVD | CO-PU-AUT | CO-PU-WRK | CO-PU-CST | CO-PU-DEC | CO-PU-ACT | CO-PU-CMT | CO-PU-CAP | CO-PU-IDN | CO-PU-ENT | CO-PU-CTX | CO-PU-NSP | CO-PU-ORI | CO-PU-LRN | CO-PU-ACV | CO-PU-ITP | CO-PU-EIF | CO-PU-CYC |
| DI | CO-DI-INT | CO-DI-EVD | CO-DI-AUT | CO-DI-WRK | CO-DI-CST | CO-DI-DEC | CO-DI-ACT | CO-DI-CMT | CO-DI-CAP | CO-DI-IDN | CO-DI-ENT | CO-DI-CTX | CO-DI-NSP | CO-DI-ORI | CO-DI-LRN | CO-DI-ACV | CO-DI-ITP | CO-DI-EIF | CO-DI-CYC |
| EN | CO-EN-INT | CO-EN-EVD | CO-EN-AUT | CO-EN-WRK | CO-EN-CST | CO-EN-DEC | CO-EN-ACT | CO-EN-CMT | CO-EN-CAP | CO-EN-IDN | CO-EN-ENT | CO-EN-CTX | CO-EN-NSP | CO-EN-ORI | CO-EN-LRN | CO-EN-ACV | CO-EN-ITP | CO-EN-EIF | CO-EN-CYC |
| CO | CO-CO-INT | CO-CO-EVD | CO-CO-AUT | CO-CO-WRK | CO-CO-CST | CO-CO-DEC | CO-CO-ACT | CO-CO-CMT | CO-CO-CAP | CO-CO-IDN | CO-CO-ENT | CO-CO-CTX | CO-CO-NSP | CO-CO-ORI | CO-CO-LRN | CO-CO-ACV | CO-CO-ITP | CO-CO-EIF | CO-CO-CYC |
| TI | CO-TI-INT | CO-TI-EVD | CO-TI-AUT | CO-TI-WRK | CO-TI-CST | CO-TI-DEC | CO-TI-ACT | CO-TI-CMT | CO-TI-CAP | CO-TI-IDN | CO-TI-ENT | CO-TI-CTX | CO-TI-NSP | CO-TI-ORI | CO-TI-LRN | CO-TI-ACV | CO-TI-ITP | CO-TI-EIF | CO-TI-CYC |
| OB | CO-OB-INT | CO-OB-EVD | CO-OB-AUT | CO-OB-WRK | CO-OB-CST | CO-OB-DEC | CO-OB-ACT | CO-OB-CMT | CO-OB-CAP | CO-OB-IDN | CO-OB-ENT | CO-OB-CTX | CO-OB-NSP | CO-OB-ORI | CO-OB-LRN | CO-OB-ACV | CO-OB-ITP | CO-OB-EIF | CO-OB-CYC |
| RE | CO-RE-INT | CO-RE-EVD | CO-RE-AUT | CO-RE-WRK | CO-RE-CST | CO-RE-DEC | CO-RE-ACT | CO-RE-CMT | CO-RE-CAP | CO-RE-IDN | CO-RE-ENT | CO-RE-CTX | CO-RE-NSP | CO-RE-ORI | CO-RE-LRN | CO-RE-ACV | CO-RE-ITP | CO-RE-EIF | CO-RE-CYC |
| TL | CO-TL-INT | CO-TL-EVD | CO-TL-AUT | CO-TL-WRK | CO-TL-CST | CO-TL-DEC | CO-TL-ACT | CO-TL-CMT | CO-TL-CAP | CO-TL-IDN | CO-TL-ENT | CO-TL-CTX | CO-TL-NSP | CO-TL-ORI | CO-TL-LRN | CO-TL-ACV | CO-TL-ITP | CO-TL-EIF | CO-TL-CYC |
| ME | CO-ME-INT | CO-ME-EVD | CO-ME-AUT | CO-ME-WRK | CO-ME-CST | CO-ME-DEC | CO-ME-ACT | CO-ME-CMT | CO-ME-CAP | CO-ME-IDN | CO-ME-ENT | CO-ME-CTX | CO-ME-NSP | CO-ME-ORI | CO-ME-LRN | CO-ME-ACV | CO-ME-ITP | CO-ME-EIF | CO-ME-CYC |
| UN | CO-UN-INT | CO-UN-EVD | CO-UN-AUT | CO-UN-WRK | CO-UN-CST | CO-UN-DEC | CO-UN-ACT | CO-UN-CMT | CO-UN-CAP | CO-UN-IDN | CO-UN-ENT | CO-UN-CTX | CO-UN-NSP | CO-UN-ORI | CO-UN-LRN | CO-UN-ACV | CO-UN-ITP | CO-UN-EIF | CO-UN-CYC |
§5.2 Reading the Matrix
By column — an ingredient's governance profile. Reading the Purpose column shows all nineteen structural tests that Purpose must satisfy: how intent is constituted at the apex, what evidence the apex must produce, who holds authority over it, what work it generates, how its constraints propagate, and so on through all nineteen primitives. An ingredient is governable only if all nineteen cells are populated.
By row — a primitive's coverage map. Reading the intent row shows how intent manifests differently across all ten ingredients: as the apex objective itself (Purpose), as the naming objective behind distinctions (Distinctions), as the delegation objective behind entity registration (Entities), and so on. A primitive's governance contribution is structurally complete only if it addresses every ingredient.
By cell — a control objective. The fundamental unit of the framework. Each cell names one structural requirement that is both ingredient-specific (it tests something particular to that ingredient) and primitive-specific (it tests through the lens of one structural primitive). The one hundred ninety cells are the audit surface of the framework.
By discipline — the COSO overlay. The five governance disciplines (§3.1-§3.5) group the nineteen primitives into five thematic clusters. Reading a discipline's group of primitives across all ten ingredients produces the discipline's coverage map. The COSO overlay table in §3.6 maps each discipline to its constituent primitives and COSO IC 2013 principles.
§5.3 The Forcing-Function Discipline
Every cell must have a declared position. This is the same discipline that OMB Compliance Supplement Part 3 applies: every compliance type must be evaluated against every control objective category. A blank cell is a governance gap — it means either the ingredient has not been tested against that primitive (an incompleteness), or the test was performed and the cell was deliberately declared inapplicable (a position that must be documented and justified).
In this matrix, no cell is inapplicable. Every ingredient has structural requirements under every primitive. Some cells are thick — the primitive is central to the ingredient's governance architecture — and some are thin — the primitive applies but is not the primary structural surface. Thin cells carry concise control objectives; the forcing-function discipline requires their existence, not their verbosity. The one hundred ninety control objectives below are the declared positions.
§5.4 Control Objectives by Ingredient
§5.4.1 Purpose (PU)
Primary primitive: intent. Purpose is the apex objective — what the governed world model exists to achieve.
CO-PU-INT: The apex objective shall be a single, named intent record from which all subordinate objectives derive.
Purpose IS intent at the system level. The apex intent must be explicit, singular, and the root of the intent hierarchy — every other objective traces to it. Without a declared apex intent, subordinate work lacks a normative anchor.
CO-PU-EVD: The apex objective shall carry empirically anchored success criteria comprising both leading and trailing signals.
Leading signals are early indicators that purpose is being served. Trailing signals are outcome indicators that purpose has been achieved. An apex without success criteria cannot be assessed — it is an aspiration, not an objective. (Preserved from CO-PU-EO.)
CO-PU-AUT: The apex objective's authority holder shall be the constituting authority from which all delegation originates.
The apex is the only record that can have a null parent reference. The authority to hold the apex is inherent, not delegated — it is the source of delegation. (Preserved from CO-PU-AM.)
CO-PU-WRK: The apex objective shall generate at least one traceable work specification that operationalizes intent into executable governance activity.
An apex that generates no work is inert. The connection from purpose to work is the bridge between aspiration and operation — the apex must name what work it authorizes, even if that work is delegated.
CO-PU-CST: Every operational constraint shall inherit from the apex objective's negation clause under tighten-only propagation.
If the apex says "we will not do X," no downstream record can authorize doing X without a documented override decision that traces to the constituting authority. Tighten-only inheritance means operational constraints can narrow the apex negation but cannot loosen it. (Preserved from CO-PU-CP.)
CO-PU-DEC: Revision of the apex objective shall be the most tightly governed decision surface in the system.
Revising the apex changes the direction against which everything else is evaluated. The decision boundary around apex revision must be the highest-stakes surface — the narrowest gate, the most senior authority, the most complete evidence requirements. (Preserved from CO-PU-DB.)
CO-PU-ACT: Governance findings at the apex level shall resolve to the constituting authority through self-referential closure.
When the system is found to be pursuing what its purpose excludes, the accountability path leads to the constituting authority. There is nowhere else to escalate. (Preserved from CO-PU-AR.)
CO-PU-CMT: The apex objective shall carry explicit commitments that bind the constituting authority before they bind anyone else.
Purpose without commitment is aspiration. The commitments embedded in the apex — ethical bounds, methodological pledges, stakeholder obligations — bind downward from the apex, and the constituting authority bears them first.
CO-PU-CAP: The apex objective shall be scoped to the system's assessed capacity, with capacity gaps documented as governance findings.
An apex that exceeds the system's capacity to pursue it is structurally dishonest. The gap between purpose and capacity must be visible and managed, not hidden behind ambitious language.
CO-PU-IDN: The apex objective shall carry a stable, system-unique identifier that all downstream records reference when tracing to purpose.
Without a stable identifier, references to "the purpose" are ambiguous across versions and contexts. The identifier makes purpose-traceability auditable.
CO-PU-ENT: The apex objective shall name the entity or entity class that holds constituting authority over it.
Purpose without an identified holder is orphaned. The entity binding ensures that there is always a registered subject who can be held accountable for purpose-level decisions.
CO-PU-CTX: The apex objective shall declare the operational context within which it applies, including domain boundaries and jurisdictional scope.
Purpose that claims to apply everywhere applies nowhere testably. Context-bounding makes the apex auditable by specifying where it holds and where it does not.
CO-PU-NSP: The apex objective shall anchor the root namespace from which all governed terms derive their resolution authority.
The apex is the namespace root. Terms used in subordinate records resolve upward through the namespace hierarchy to definitions anchored at or authorized by the apex. A namespace without an apex anchor has no authoritative resolution path.
CO-PU-ORI: The apex objective shall declare the system's epistemic orientation — the foundational stance from which observations are interpreted.
Orientation at the purpose level determines what the system treats as signal versus noise. An undeclared orientation means the system's interpretive frame is implicit and unauditable.
CO-PU-LRN: The apex objective shall specify the conditions under which accumulated evidence warrants revising purpose itself.
A purpose that cannot learn from its own evidence is brittle. The learning conditions at the apex are the system's highest-level adaptation criteria — the threshold at which evidence forces purpose revision.
CO-PU-ACV: The apex objective's activation conditions shall be the system's entry gate — the threshold that initiates governed operation.
Activation at the purpose level defines when the system is "on" — when governance commitments take effect. An apex without activation conditions has no defined boundary between governed and ungoverned states.
CO-PU-ITP: The apex objective shall specify interpretation rules for resolving ambiguity in its own terms.
The apex is the final interpretive authority. When a governed term is ambiguous, the interpretation rules declared at the purpose level determine how resolution proceeds. Without these rules, interpretive disputes have no resolution mechanism.
CO-PU-EIF: The apex objective shall declare the system's environment-interface boundary — what the governed system treats as internal versus external.
Purpose without an interface boundary cannot distinguish between the system's own state and its environment. The boundary declaration makes observable what the system monitors and what it leaves unobserved.
CO-PU-CYC: The apex objective shall specify its governance review cadence and the conditions under which the review cycle itself is revised.
A purpose without a review cycle is permanently static. The cycle declaration ensures that purpose is periodically re-examined against accumulated evidence, and that the cadence itself can be adjusted as the system matures.
§5.4.2 Distinctions (DI)
Primary primitives: identifier, namespace. Distinctions are what the model can tell apart — the vocabulary through which the world model represents the world.
CO-DI-INT: Every distinction shall trace to an intent that justifies its existence in the governed vocabulary.
Terms that exist without justifying intent accumulate as governance debt. Every distinction in the vocabulary must answer: what governance purpose does this term serve?
CO-DI-EVD: Every operative term shall resolve to a specific definition source through an auditable resolution chain.
The evidence obligation is not "we defined our terms" but "every term in every governance commitment resolves to a specific definition, and the resolution chain is auditable." Term resolution failures are governance findings. (Preserved from CO-DI-EO.)
CO-DI-AUT: Namespace authority (who defines terms) shall be separated from content authority (who uses terms).
Redefining a term that downstream records depend on is a high-stakes governance act. The authority to create, modify, or retire a distinction must be explicitly mapped and traceable through the authority chain. (Preserved from CO-DI-AM.)
CO-DI-WRK: Changes to the governed vocabulary shall be governed work — scoped, authorized, and evidenced like any other state transition.
Term creation, redefinition, and retirement are not administrative acts. They are work that alters the governance substrate and must carry the same structural rigor as any other governed transition.
CO-DI-CST: Namespace constraints shall propagate through inheritance such that parent-level definitions bind child records under tighten-only rules, with opaque terms protected from premature resolution.
A child record can narrow a term's scope but cannot redefine it to mean something the parent did not intend. Opaque terms carry their uncertainty structurally rather than collapsing into premature definitions. (Preserved from CO-DI-CP.)
CO-DI-DEC: Creation of identifiers, assignment of artifacts to namespaces, and resolution of terms to definitions shall each be governed decision surfaces.
Each of these is a point where an alternative existed and the choice is auditable. Identifier creation, namespace assignment, and term resolution are structural decisions, not administrative acts. (Preserved from CO-DI-DB.)
CO-DI-ACT: Namespace conflicts shall resolve by following the authority chain to the nearest authority with jurisdiction over both namespaces.
The conflict cannot be resolved by one side unilaterally redefining the term; it must be resolved by an authority with scope over the boundary. (Preserved from CO-DI-AR.)
CO-DI-CMT: The governed vocabulary shall carry a stability commitment specifying which terms are frozen, which are mutable, and the conditions for promotion between states.
Without stability commitments, downstream records cannot rely on term definitions. The commitment surface declares the vocabulary's change contract.
CO-DI-CAP: The governed vocabulary's capacity — the number of terms, depth of hierarchy, and resolution precision — shall be assessed against the governance demands placed on it.
A vocabulary that is too sparse to express the governance distinctions required of it is a structural gap. Capacity assessment ensures the vocabulary is fit for its governance purpose.
CO-DI-IDN: Every governed term shall carry a unique, stable identifier that persists through definition changes and namespace migrations.
Identifier stability is the primary structural surface for distinctions. Without stable identifiers, cross-references break when terms are refined, and auditability across versions is lost.
CO-DI-ENT: Every governed term shall be attributable to an authoring entity whose namespace authority is registered.
Terms that enter the vocabulary without attribution have unknown provenance. The entity binding ensures that vocabulary authority is traceable.
CO-DI-CTX: Every governed term shall declare the contexts in which it is operative and the contexts in which it is inoperative or carries a different meaning.
Context-sensitivity in vocabulary is structural, not incidental. A term that means one thing in one context and another thing elsewhere must declare both meanings and the boundary between them.
CO-DI-NSP: The namespace hierarchy shall be explicit, rooted at the apex, and navigable such that any term can be resolved to its authoritative definition by traversing the namespace tree.
The namespace is the primary structural surface for distinctions. Without an explicit hierarchy, term resolution depends on convention rather than structure, and naming collisions are undetectable. (Thick cell — primary primitive.)
CO-DI-ORI: The governed vocabulary shall declare its epistemic orientation — whether it is descriptive, prescriptive, or normative — at the namespace level.
Orientation governs how vocabulary is used. A descriptive vocabulary names what is observed; a prescriptive vocabulary names what should be done; a normative vocabulary names what is valued. Mixing these without declaration produces undecidable disputes.
CO-DI-LRN: The governed vocabulary shall evolve through a declared learning process: observation of usage gaps, proposal of new terms, and governed adoption.
A vocabulary that cannot learn is frozen. The learning process for distinctions must be declared so that vocabulary evolution is governed rather than ad hoc.
CO-DI-ACV: New terms shall not be operative until activation conditions are met — at minimum, definition, namespace assignment, and authority registration.
Premature activation of incompletely defined terms corrupts the vocabulary. Activation conditions prevent terms from entering governance use before they are structurally ready.
CO-DI-ITP: Interpretation of governed terms shall follow declared resolution rules, with ambiguity resolved by ascending the namespace hierarchy to the nearest authoritative definition.
Interpretation is the bridge between vocabulary and governance action. Without declared resolution rules, the same term can be interpreted differently by different actors, producing inconsistent governance outcomes.
CO-DI-EIF: The governed vocabulary shall declare which terms name internal system states and which name environment-observable phenomena, with the boundary explicit.
Terms that confuse internal state with external observation produce unverifiable claims. The interface boundary in vocabulary separates what the system asserts about itself from what it asserts about the world.
CO-DI-CYC: The governed vocabulary shall undergo periodic review at a declared cadence, with obsolete terms retired and emerging terms assessed for adoption.
A vocabulary without a review cycle accumulates dead terms and misses emerging needs. The review cadence ensures the vocabulary remains fit for governance purpose over time.
§5.4.3 Entities (EN)
Primary primitives: entity, authority, capacity, account. Entities are the persistent subjects of governance — the actors who hold authority, bear accountability, and execute work.
CO-EN-INT: Every registered entity shall carry a declared intent specifying the entity's purpose within the governance system.
An entity without declared intent has no basis for evaluating whether it is fulfilling its role. Intent at the entity level answers: why does this entity exist in the governance architecture?
CO-EN-EVD: Every entity shall be traceable to a registration record specifying type, authority bindings, delegation source, and (for computational actors) underlying model.
The registration is the evidence that the entity exists in the governance system and has been assigned its authority through proper delegation. (Preserved from CO-EN-EO.)
CO-EN-AUT: Every authority chain shall terminate at a registered entity, with the three-layer behavioral-contract architecture operating on entities as subjects.
Without persistent entities, the behavioral-contract architecture (actor type, role envelope, per-interaction contract) has nothing to bind to. Entities is where authority mapping gets its subjects. (Preserved from CO-EN-AM.)
CO-EN-WRK: Work assignment shall be traceable to a registered entity with sufficient authority and capacity to execute the assigned work.
Work assigned to unregistered or incapable entities is ungoverned by construction. The work-entity binding ensures that every piece of governed work has an identifiable executor with appropriate standing.
CO-EN-CST: Entity-level constraints shall propagate through role envelopes and behavioral contracts under tighten-only rules.
An entity-level prohibition cannot be overridden by a role envelope or contract. The tighten-only rule applies across the behavioral-contract stack — each layer narrows, never expands. (Preserved from CO-EN-CP.)
CO-EN-DEC: Creation of entities, assignment of authority, and assessment of capacity shall each be governed decision surfaces.
Creating a new entity in the governance system, assigning it authority, and assessing its capacity are each decisions with alternatives and audit trail. (Preserved from CO-EN-DB.)
CO-EN-ACT: Accountability for governance failure shall follow a deterministic entity chain from the acting entity through delegation to the granting authority.
The chain must be deterministic. If the chain is broken (an entity cannot be identified, a delegation cannot be traced), the break itself is a governance finding. (Preserved from CO-EN-AR — thick cell.)
CO-EN-CMT: Every entity shall carry explicit commitments that bind its behavior across engagements, distinct from per-interaction contracts.
Entity-level commitments are durable — they persist across roles and engagements. The commitment surface at the entity level is the floor that no per-interaction contract can breach.
CO-EN-CAP: Every entity shall carry a current capacity assessment specifying what the entity can be authorized to do, with capacity limits enforced as structural constraints.
For computational actors, capacity assessment includes the underlying model's authority ceiling. For human actors, it includes competence and availability. Capacity is the upper bound on what delegation can grant. (Thick cell — primary primitive.)
CO-EN-IDN: Every entity shall carry a stable, system-unique identifier that persists through role changes, authority reassignments, and lifecycle transitions.
Entity identity must survive structural changes. An entity that loses its identifier during a role change becomes untraceable, breaking every authority chain and accountability path that references it.
CO-EN-ENT: The entity registry shall enforce type classification (human, computational, organizational, composite) with each type carrying distinct governance constraints.
Entity type determines the governance ceiling. Computational actors cannot hold authority that requires human judgment. Organizational entities delegate through their members. The type system is structural, not descriptive. (Thick cell — primary primitive.)
CO-EN-CTX: Every entity's authority and capacity shall be context-qualified — specifying the domains, periods, and conditions under which the entity is authorized to act.
Authority without context qualification is unbounded. Context-qualifying entity authority prevents the governance failure where an entity authorized in one domain exercises authority in another.
CO-EN-NSP: Every entity shall be registered within a namespace that determines the entity's resolution scope and prevents identifier collisions across governance domains.
Namespace registration for entities ensures that entity references resolve unambiguously, even when multiple governance domains coexist.
CO-EN-ORI: Every entity shall declare or inherit an epistemic orientation that governs how the entity's observations and claims are weighted in governance decisions.
An entity's orientation — whether it is a disinterested observer, an interested party, or an adversarial challenger — affects how its evidence is treated. Undeclared orientation makes evidence weighting arbitrary.
CO-EN-LRN: Every entity shall have a declared learning pathway specifying how the entity's capacity and authority evolve based on accumulated performance evidence.
Entities that cannot learn are static fixtures. The learning pathway ensures that entity assessments are updated as evidence accumulates — promotions, demotions, and capacity adjustments are governed transitions.
CO-EN-ACV: Entity activation — the transition from registered to operative — shall require satisfaction of declared preconditions including authority grant, capacity verification, and commitment acknowledgment.
An entity that is registered but not yet activated is not yet a governance subject. Activation conditions prevent entities from exercising authority before their standing is confirmed.
CO-EN-ITP: Disputes about entity authority, capacity, or accountability shall be resolved through declared interpretation rules that reference the entity registry and delegation chain.
Entity disputes must resolve structurally, not politically. The interpretation rules for entities reference the registry and delegation records — not narrative claims about who should have authority.
CO-EN-EIF: Computational entities shall declare their environment-interface specification — what the entity can observe, what it can act upon, and what lies outside its perception surface.
For computational actors, the environment-interface is a structural constraint on the entity's governance participation. An entity cannot produce evidence about domains outside its interface specification.
CO-EN-CYC: Entity registrations shall be reviewed at a declared cadence, with inactive entities retired, capacity assessments refreshed, and authority bindings revalidated.
Entity registrations that are never reviewed accumulate stale authority grants and outdated capacity assessments. The review cycle ensures the entity registry reflects current governance reality.
§5.4.4 Constraints (CO)
Primary primitives: constraint, commitment. Constraints are the prohibitions and requirements that bound what the governed system may and must do.
CO-CO-INT: Every constraint shall trace to an intent that it serves — the objective whose achievement the constraint protects or enables.
A constraint without a traceable intent is a rule without a reason. The intent linkage ensures that every prohibition or requirement can answer: what governance purpose does this constraint serve?
CO-CO-EVD: Every constraint shall specify an observable violation condition and a detection mechanism.
The evidence obligation is not "we have constraints" but "we can demonstrate, for each constraint, what would violate it and how we would detect the violation." Untestable constraints are governance theater. (Preserved from CO-CO-EO.)
CO-CO-AUT: Authority to create, modify, or waive a constraint shall be a distinct governance surface separate from content authority.
Constraint authority — who can impose prohibitions and grant exceptions — must be explicitly mapped. An exception is a delegation from the constraint's author; it must be traceable and revocable. (Preserved from CO-CO-AM.)
CO-CO-WRK: Constraint enforcement shall be traceable to specific work — the operational activity that detects violations and triggers governance responses.
A constraint that nobody checks is a wish. The work binding ensures that every constraint has an enforcement mechanism traceable to authorized work.
CO-CO-CST: Constraint propagation shall operate through six defined patterns: tighten-only, halt-and-escalate, explicit composition, negation propagation, lateral inheritance with weights, and effective constraint set.
This ingredient is where the constraint propagation discipline originates. The Controls charter record is the structural home of the constraint architecture. (Preserved from CO-CO-CP — thick cell.)
CO-CO-DEC: Imposition of a constraint and granting of an exception shall each be named decision surfaces with documented alternatives and rationale.
Exceptions that are not documented as decisions are governance failures — they are silent constraint erosion. (Preserved from CO-CO-DB.)
CO-CO-ACT: Constraint violation accountability shall follow the authority chain from violating act through delegation, including the granting authority where a waived exception exists.
The question "who authorized this violation?" must have a deterministic answer. (Preserved from CO-CO-AR.)
CO-CO-CMT: Every constraint shall carry a commitment classification specifying whether it is absolute (never waivable), conditional (waivable under stated conditions), or advisory (informational only).
Commitment classification prevents the governance failure where all constraints appear equal. The classification determines the severity of violation and the authority required to waive. (Thick cell — primary primitive.)
CO-CO-CAP: The effective constraint set at any governance point shall be computationally deterministic — an actor with the constraint specification and the relation graph shall be able to compute the active constraints.
Constraints that require human judgment to determine whether they apply are governance ambiguity. The capacity to compute the effective constraint set is a structural requirement.
CO-CO-IDN: Every constraint shall carry a stable identifier that persists through amendments, enabling constraint-level audit trails and cross-reference.
Without constraint identifiers, audit findings cannot reference specific constraints, exception grants cannot name what they waive, and version-over-version tracking is impossible.
CO-CO-ENT: Every constraint shall name the entity class or specific entities to which it applies, with applicability scope explicit.
A constraint that applies to "everyone" applies to no one testably. Entity-scoping ensures that constraint testing has a defined subject population.
CO-CO-CTX: Every constraint shall declare the contexts in which it is active and the contexts in which it is suspended or modified.
Context-sensitivity in constraints is structural. A constraint that applies during normal operations but is suspended during emergency operations must declare both states and the transition conditions.
CO-CO-NSP: Constraints shall be organized within the namespace hierarchy such that constraint scope aligns with namespace scope and inheritance follows the namespace tree.
Namespace alignment ensures that constraints inherited from parent namespaces bind child namespaces predictably and that constraint resolution follows the same path as term resolution.
CO-CO-ORI: Constraints shall declare their epistemic basis — whether derived from principle, from observed risk, from regulatory requirement, or from constituting authority direct.
Orientation in constraints determines how the constraint is evaluated and revised. A constraint derived from observed risk is revisable when the risk assessment changes; a constraint derived from constituting authority is revisable only by that authority.
CO-CO-LRN: The constraint architecture shall evolve through a declared learning process: constraint effectiveness review, gap identification, and governed amendment.
Constraints that cannot be revised based on evidence are brittle. The learning process ensures that constraint evolution is governed — observed ineffectiveness produces amendment proposals, not silent abandonment.
CO-CO-ACV: Constraint activation shall follow a declared process: creation, review, approval, and activation as distinct lifecycle stages.
A constraint that becomes active upon creation has no review gate. The activation lifecycle ensures that constraints are examined before they bind.
CO-CO-ITP: Constraint ambiguity shall be resolved by ascending the authority chain to the constraint's author or to the nearest authority with jurisdiction over the ambiguous scope.
When a constraint's application is unclear, interpretation follows a deterministic path. The interpretation rules prevent actors from resolving constraint ambiguity in their own favor.
CO-CO-EIF: Constraints that reference environment-observable conditions shall declare the observation mechanism and the confidence threshold for determining that the condition obtains.
A constraint conditioned on external state ("if market conditions warrant...") is unenforceable without a declared observation mechanism. The environment-interface binding makes externally-conditioned constraints testable.
CO-CO-CYC: The constraint register shall undergo periodic review at a declared cadence, with effectiveness assessed, obsolete constraints retired, and gap analysis performed.
A constraint register that is never reviewed accumulates obsolete prohibitions and misses emerging risks. The review cycle is the mechanism that keeps the constraint architecture current.
§5.4.5 Time (TI)
Primary primitives: cycle, decision. Time is the dimension that gives governance its temporal structure — when things happen, how long they persist, and what triggers transitions.
CO-TI-INT: Every governance cycle shall trace to an intent that justifies its cadence — the governance purpose that the cycle serves.
A cycle without justifying intent is ritual. The intent linkage ensures that every review cycle, reporting period, and lifecycle stage answers: what governance objective does this temporal structure serve?
CO-TI-EVD: Every decision shall carry temporal evidence establishing when it was made relative to available information, with timeliness auditable.
A decision made after relevant information was available but not considered is a governance finding. Temporal evidence is as important as substantive evidence. (Preserved from CO-TI-EO.)
CO-TI-AUT: Authority to set cycle cadence shall be a strategic governance surface distinct from content authority.
Temporal authority — who can change when things happen — is distinct from content authority — who can change what things mean. The cadence of governance reviews shapes the system's temporal resolution. (Preserved from CO-TI-AM.)
CO-TI-WRK: Temporally governed work shall carry explicit start conditions, duration constraints, and completion criteria with each transition auditable.
Work without temporal governance can persist indefinitely, consuming resources without accountability. Temporal work constraints make duration and completion structurally visible.
CO-TI-CST: Temporal constraints shall propagate through lifecycles such that terminated directives cannot bind after termination and period-of-performance constraints specify active windows.
A finding re-opened at cycle review re-activates its constraints on the responsible entity. Period-of-performance constraints specify when constraints are active and when they expire. (Preserved from CO-TI-CP.)
CO-TI-DEC: Every cycle transition — start of review, disposition of finding at cycle-end, extension, and termination — shall be a governed decision boundary.
The temporal grain of decision boundaries determines governance responsiveness. Too coarse and problems fester; too fine and decision fatigue overwhelms. (Preserved from CO-TI-DB — thick cell.)
CO-TI-ACT: Accountability resolution shall establish temporal causation: whether the entity had needed information before failure and whether corrective action was timely.
Temporal accountability prevents the governance failure where "we didn't know" is accepted when the information was available but the review cycle hadn't occurred yet. (Preserved from CO-TI-AR.)
CO-TI-CMT: Temporal commitments — review deadlines, response windows, carry-forward obligations — shall be explicit and enforceable, with missed deadlines producing governance findings.
A temporal commitment without enforcement is a suggestion. Missed deadlines must be visible as governance findings, not silently absorbed.
CO-TI-CAP: The governance system's temporal capacity — the number of cycles, reviews, and dispositions it can process per period — shall be assessed against its governance workload.
A system with more governance obligations than temporal capacity to process them will accumulate unreviewed findings. Temporal capacity assessment prevents governance backlog from becoming invisible.
CO-TI-IDN: Every governance period, cycle instance, and lifecycle stage shall carry a unique identifier enabling temporal cross-reference and historical audit.
Without temporal identifiers, references to "last quarter's review" or "the prior reporting period" are ambiguous. Temporal identifiers make governance history navigable.
CO-TI-ENT: Every governance cycle shall name the entity or entities responsible for initiating, conducting, and closing the cycle.
A cycle without named responsibility is a calendar entry, not a governance mechanism. The entity binding ensures that temporal governance has accountable subjects.
CO-TI-CTX: Temporal governance requirements shall be context-qualified — different governance contexts may warrant different cycle cadences and lifecycle definitions.
A research program and an operational system may have different governance rhythms. Context-qualification ensures that temporal governance is fit for the domain it governs.
CO-TI-NSP: Temporal constructs (periods, cycles, stages) shall be defined in the namespace with stable identifiers, enabling cross-system temporal alignment.
Namespace registration for temporal constructs ensures that terms like "FY2024" and "the pilot period" resolve to specific, non-overlapping time ranges rather than informal convention.
CO-TI-ORI: The governance system shall declare its temporal orientation — whether it is forward-looking (planning), concurrent (monitoring), or retrospective (auditing) — at each governance surface.
Different governance activities have different temporal orientations. Conflating planning-oriented and audit-oriented temporal structures produces governance that is neither forward-looking nor retrospective.
CO-TI-LRN: Governance cycle parameters (cadence, duration, scope) shall be revisable based on accumulated evidence about governance effectiveness at prior cadences.
A governance cycle that cannot learn from its own history repeats mistakes structurally. The learning pathway ensures that temporal governance adapts to evidence about its own effectiveness.
CO-TI-ACV: Governance cycle activation shall require satisfaction of preconditions — at minimum, availability of required evidence from the prior period and assignment of responsible entities.
A governance cycle that begins without the evidence it needs to examine is ceremonial. Activation preconditions ensure that cycle execution is substantive.
CO-TI-ITP: Temporal ambiguity — disputes about when a decision was made, whether a deadline was met, or which period an event falls in — shall be resolved through declared interpretation rules referencing the temporal identifier registry.
Temporal disputes must resolve by reference to the registered temporal structure, not by narrative reconstruction of what happened when.
CO-TI-EIF: The governance system's temporal awareness shall be bounded by its environment-interface — the system can only govern temporal relationships for events within its observation surface.
A governance system cannot hold actors accountable for timing relative to information the system itself cannot observe. The environment-interface bounds temporal governance to the system's perception.
CO-TI-CYC: The governance cycle shall be self-governing: the cadence, scope, and effectiveness of the cycle itself shall be reviewed at a declared meta-cycle cadence.
A cycle that governs everything except itself is structurally incomplete. The meta-cycle ensures that temporal governance is reflexively examined. (Thick cell — primary primitive.)
§5.4.6 Observation (OB)
Primary primitives: orientation, environment-interface, context, interpretation. Observation is how the governed system perceives the world — what it can see, how it interprets what it sees, and what conditions shape its perception.
CO-OB-INT: Every observation capability shall trace to an intent — the governance purpose that justifies what the system observes and at what resolution.
Observation without intent is surveillance. The intent linkage ensures that every sensor, monitor, and audit procedure answers: what governance objective does this observation serve?
CO-OB-EVD: Observations shall preserve capture-time immutability: what was observed and the conditions of observation shall be retained as-is.
Capture-time immutability means what was observed and under what conditions must be preserved, not retroactively adjusted. Retroactive adjustment corrupts the evidentiary record. (Preserved from CO-OB-EO.)
CO-OB-AUT: Interpretive authority shall be a distinct governance surface separated from observation authority and action authority.
An AI system may observe and flag, but the interpretation of what the observation means for governance action may require human authority. Interpretive, observation, and action authority are three distinct surfaces. (Preserved from CO-OB-AM.)
CO-OB-WRK: Observation activities shall be governed work — scoped, scheduled, authorized, and evidenced — not ambient background processes exempt from governance oversight.
Observation work that escapes governance is invisible governance. Treating observation as governed work ensures that the system's perception surface is auditable.
CO-OB-CST: Observation constraints shall propagate through the interface specification such that no downstream record can claim evidence about a domain not covered by the perception surface.
Coverage gaps propagate: an interface limitation at the observation layer becomes an evidence limitation at the finding layer becomes an accountability limitation at the resolution layer. (Preserved from CO-OB-CP.)
CO-OB-DEC: Every interpretation of an ambiguous signal shall be a governed decision where the assigned meaning and alternative interpretations are documented.
Making interpretation visible as a decision surface prevents the governance failure where "we observed X" silently includes "and we interpreted X to mean Y" without documenting Y as a choice. (Preserved from CO-OB-DB.)
CO-OB-ACT: Disputed observations shall be resolved by examining orientation, interface, context, and interpretation as independent factors.
Decomposing observation into its four structural components makes disputes resolvable rather than subjective. (Preserved from CO-OB-AR.)
CO-OB-CMT: The observation system shall carry explicit commitments regarding observation frequency, coverage scope, and reporting obligations.
Observation commitments define what the system promises to watch and how often. Without commitments, observation is discretionary and coverage gaps are invisible.
CO-OB-CAP: The observation system's capacity — resolution, coverage, and throughput — shall be assessed against governance demands and documented with capacity gaps as findings.
An observation system that cannot keep pace with its governance obligations produces stale or incomplete evidence. Capacity assessment ensures observation is fit for purpose.
CO-OB-IDN: Every observation event shall carry a unique identifier enabling traceability from raw observation through interpretation to governance action.
Without observation identifiers, the chain from "what we saw" to "what we did about it" is unauditable. Identifiers make observation-to-action traceability possible.
CO-OB-ENT: Every observation shall be attributable to an observing entity whose capacity, authority, and potential biases are registered.
Observations from unattributed sources are ungovernable. The entity binding ensures that the observer's standing is known when evaluating the observation's weight.
CO-OB-CTX: Every observation shall carry context metadata — the conditions under which the observation was made — that qualifies the observation's applicability and reliability.
Context is a primary structural surface for observation. An observation made under normal conditions and the same observation made under duress carry different governance weight. Context metadata makes this difference structural. (Thick cell — primary primitive.)
CO-OB-NSP: Observations shall be classified within the governed namespace such that observed phenomena resolve to governed terms and unclassifiable observations are flagged as vocabulary gaps.
Observations that cannot be expressed in the governed vocabulary are either vocabulary gaps or scope boundaries. Namespace classification ensures that observation findings map to the term structure.
CO-OB-ORI: The observation system shall declare its epistemic orientation — the assumptions, models, and frameworks that shape what it looks for and how it interprets what it finds.
Orientation is a primary structural surface for observation. An observation system's orientation determines what counts as signal versus noise. Undeclared orientation makes the observation system's biases invisible and unauditable. (Thick cell — primary primitive.)
CO-OB-LRN: The observation system shall evolve through a declared learning process: observation effectiveness review, coverage gap identification, and governed recalibration.
An observation system that cannot learn from its own performance is static. The learning pathway ensures that observation capabilities adapt to evidence about what the system is missing.
CO-OB-ACV: Observation mechanisms shall activate only when declared preconditions are met — at minimum, calibration verification, authority grant, and scope confirmation.
Observation mechanisms that activate without precondition checks may produce unreliable evidence. Activation conditions ensure that observations meet minimum quality standards before entering governance.
CO-OB-ITP: Interpretation of observations shall follow declared rules specifying how raw signals map to governed meanings, with interpretation disputes resolvable by examining the rules themselves.
Interpretation is a primary structural surface for observation. Without declared interpretation rules, two actors observing the same signal can reach different governance conclusions with no mechanism for resolution. (Thick cell — primary primitive.)
CO-OB-EIF: The observation system shall declare its environment-interface specification — the boundary between what it can observe and what lies outside its perception surface.
The environment-interface is a primary structural surface for observation. What the system cannot observe cannot produce evidence, cannot produce findings, and cannot produce accountability. The interface specification makes these blind spots explicit and auditable. (Thick cell — primary primitive.)
CO-OB-CYC: Observation activities shall operate within a declared cycle — observation windows, reporting periods, and review cadences — with out-of-cycle observations requiring justified exceptions.
Observation without temporal structure produces ungoverned data streams. The cycle binding ensures that observation is temporally organized and its outputs enter governance at predictable intervals.
§5.4.7 Relations (RE)
Primary structural surface: cross-cutting via object properties. Relations are the connections between governed objects — hierarchies, class memberships, cross-references — that determine how everything else propagates.
CO-RE-INT: Every relation shall trace to an intent that justifies its existence — the governance purpose served by connecting these two objects.
Relations that exist without justifying intent are structural clutter. The intent linkage ensures that every edge in the governance graph answers: what governance objective does this connection serve?
CO-RE-EVD: Every relation shall be auditable: cross-references shall resolve, parent references shall form a valid chain to the apex, and class memberships shall satisfy applicability scope.
Broken relations (references that do not resolve, chains that do not terminate) are governance findings. (Preserved from CO-RE-EO.)
CO-RE-AUT: Authority shall flow through the relation structure — hierarchical and class-membership — such that traversable authority chains are determined by the relation graph.
The relation structure determines which authority chains are traversable. An off-chain authority route (delegation outside the established relation graph) is a structural violation. (Preserved from CO-RE-AM.)
CO-RE-WRK: Relation maintenance — creation, modification, retirement, and integrity verification — shall be governed work, not a side effect of other operations.
Relations that change as a side effect of content edits are ungoverned structural mutations. Treating relation maintenance as explicit work ensures that the governance graph evolves deliberately.
CO-RE-CST: Relations shall serve as the channels through which all six constraint-propagation patterns operate.
Tighten-only inheritance flows through hierarchical relations; lateral inheritance flows through class membership; halt-and-escalate routes through authority relations. Without well-defined relations, constraint propagation has no channels. (Preserved from CO-RE-CP.)
CO-RE-DEC: Creation or modification of any relation — parent reference, class membership, cross-reference — shall be a governed decision that alters the governance graph.
Restructuring relations is a high-stakes governance act because it changes the paths through which everything else flows. (Preserved from CO-RE-DB.)
CO-RE-ACT: The quality of accountability resolution shall be proportional to the quality of the relation graph, with broken relations constituting findings.
A system with well-maintained relations can trace responsibility precisely; a system with broken or missing relations traces responsibility imprecisely or not at all. (Preserved from CO-RE-AR.)
CO-RE-CMT: The relation architecture shall carry stability commitments specifying which structural relationships are frozen and which are subject to governed change.
Stability commitments for relations protect downstream consumers. A relation marked as frozen can be relied upon without monitoring for change; a mutable relation must be watched.
CO-RE-CAP: The relation graph's capacity — depth of hierarchy, breadth of cross-reference, and navigability under load — shall be assessed against governance demands.
A relation graph that is too shallow to express the governance hierarchy or too tangled to navigate under time pressure is a structural bottleneck. Capacity assessment ensures the relation architecture scales with governance complexity.
CO-RE-IDN: Every relation shall carry a stable identifier enabling relation-level audit trails, modification history, and cross-reference from governance findings.
Without relation identifiers, a finding that says "the authority chain was broken" cannot point to which specific relation was broken. Identifiers make relation-level governance precise.
CO-RE-ENT: Every relation shall connect registered entities or governed objects — no relation endpoint shall be unregistered.
A relation with an unregistered endpoint is a dangling reference. The entity binding ensures that every edge in the governance graph connects known, governed nodes.
CO-RE-CTX: Relations shall declare the contexts in which they are active — a relation that applies in one governance context but not another must declare both states.
Context-sensitivity in relations means that the governance graph can vary by context. Undeclared context-sensitivity produces governance that is structurally different from what participants believe it to be.
CO-RE-NSP: Relations shall be scoped within the namespace hierarchy such that cross-namespace relations are explicitly declared and their resolution rules are specified.
Relations that silently cross namespace boundaries create hidden dependencies. Namespace-scoping ensures that cross-boundary relations are visible and governed.
CO-RE-ORI: The relation architecture shall declare its orientation — whether relations represent structural hierarchy, temporal sequence, causal dependency, or associative reference — at the class level.
Different relation types serve different governance purposes. Conflating hierarchical authority relations with associative reference relations produces governance that cannot distinguish binding from informational connections.
CO-RE-LRN: The relation architecture shall evolve through a declared learning process: graph integrity review, navigation efficiency assessment, and governed restructuring.
A relation architecture that cannot learn from its own usage patterns is static. The learning pathway ensures that the governance graph adapts to evidence about structural effectiveness.
CO-RE-ACV: New relations shall activate only after structural validation — at minimum, endpoint verification, constraint compatibility check, and authority confirmation.
A relation that activates before its endpoints are verified may connect to nonexistent or inappropriate nodes. Activation conditions prevent the governance graph from admitting structurally invalid edges.
CO-RE-ITP: Ambiguous relations — edges whose type, direction, or scope is unclear — shall be resolved through declared interpretation rules referencing the relation type system.
Ambiguous relations are governance uncertainty. The interpretation rules for relations must reference the declared type system so that disputes about what a relation means have a deterministic resolution path.
CO-RE-EIF: The relation graph shall declare which relations connect internal system nodes and which span the environment-interface boundary, with boundary-spanning relations carrying additional governance requirements.
Relations that cross the system-environment boundary carry higher governance risk because one endpoint may be outside the system's control. Declaring boundary-spanning relations ensures that cross-boundary governance is explicit.
CO-RE-CYC: The relation graph shall undergo periodic integrity review at a declared cadence, with broken references repaired, orphaned nodes identified, and structural health assessed.
A relation graph that is never reviewed degrades as content evolves. The review cycle ensures that the governance graph's structural integrity is maintained over time.
§5.4.8 Transition Logic (TL)
Primary primitives: work, activation. Transition Logic is how governed objects change state — the rules that determine when and how things move from one state to another.
CO-TL-INT: Every state transition shall trace to an intent — the governance purpose that the transition serves or advances.
A state transition without intent linkage is motion without direction. The intent binding ensures that every transition in the lifecycle of governed work answers: what objective does this change serve?
CO-TL-EVD: Every work specification shall name the evidence it will produce, at what granularity, and with what verification surface.
Work that executes without producing its specified evidence is a governance finding. The pre-execution evidence commitment constrains the work before it begins. (Preserved from CO-TL-EO.)
CO-TL-AUT: Authority to define work, set activation conditions, and modify transition rules shall be three distinct governance surfaces separated from operational authority.
Operational authority (who can do the work) is distinct from governance authority (who can change the rules of the work). This prevents the governance failure where the people doing the work also set the rules for evaluating it. (Preserved from CO-TL-AM.)
CO-TL-WRK: Work specifications shall be structurally complete: named inputs, named outputs, success criteria, constraint set, authority binding, and evidence commitment.
Work is the primary structural surface for transition logic. A work specification missing any of these elements is structurally incomplete — it may execute but cannot be governed. (Thick cell — primary primitive.)
CO-TL-CST: Work shall inherit its effective constraint set from the parent objective, class memberships, and local declarations.
Constraints propagate into the work specification: an output constrained at the objective level must be constrained in the work specification that produces it. (Preserved from CO-TL-CP.)
CO-TL-DEC: Every activation and every state transition in the lifecycle of governed work shall be a governed decision boundary.
Every activation is a decision (the work could have been deferred, redirected, or declined). Every state transition is a decision (the work was evaluated and advanced, held, or returned). (Preserved from CO-TL-DB.)
CO-TL-ACT: Accountability for work failure shall follow the delegation chain from executor through authorizing authority to the served objective, with transition rules establishing where in the lifecycle failure occurred.
The transition rules determine where in the work's lifecycle the failure occurred, which in turn determines which authority bears responsibility. (Preserved from CO-TL-AR.)
CO-TL-CMT: Work specifications shall carry explicit completion commitments — what "done" means — that are testable before the work's output enters the governance system.
A work specification without a completion commitment can persist indefinitely in "in progress" state. The completion commitment makes done structurally verifiable.
CO-TL-CAP: Work assignments shall be validated against the executing entity's capacity before activation, with capacity insufficiency producing a governance finding rather than silent degradation.
Work assigned to an entity without sufficient capacity is set up to fail. Capacity validation at assignment time prevents the governance failure where overloaded entities produce substandard outputs.
CO-TL-IDN: Every work instance, state transition, and lifecycle stage shall carry a unique identifier enabling work-level audit trails and cross-reference.
Without work identifiers, governance findings cannot reference specific work instances, and lifecycle tracking across periods is impossible.
CO-TL-ENT: Every work instance shall be bound to a registered entity (executor) and traceable to an authorizing entity, with both bindings auditable.
Work without entity bindings is orphaned — nobody is accountable for its execution and nobody authorized its initiation. The dual entity binding (executor + authorizer) is the structural foundation of work governance.
CO-TL-CTX: Work specifications shall declare the context in which they operate — the governance domain, temporal period, and environmental conditions that scope the work.
Context-qualification ensures that work specifications are not silently reapplied in contexts they were not designed for.
CO-TL-NSP: Work-related terms (statuses, transition names, output types) shall be defined in the namespace with stable identifiers, ensuring consistent usage across work instances.
Without namespace registration, the same status label can mean different things in different work contexts, making cross-instance analysis unreliable.
CO-TL-ORI: Work specifications shall declare whether the work is investigative (seeking evidence), constructive (producing output), corrective (addressing findings), or evaluative (assessing other work).
Work orientation determines how the work's output is treated in governance. Conflating investigative and constructive work obscures the distinction between evidence-gathering and action-taking.
CO-TL-LRN: Transition logic shall evolve through a declared learning process: lifecycle effectiveness review, bottleneck identification, and governed rule amendment.
Transition rules that cannot be revised based on evidence about their effectiveness produce fossilized processes. The learning pathway ensures that workflow evolves deliberately.
CO-TL-ACV: Work activation shall require satisfaction of declared preconditions — at minimum, authority grant, constraint set inheritance, and evidence commitment registration.
Activation is a primary structural surface for transition logic. Work that activates before its preconditions are met enters the governance system in an indeterminate state. Activation conditions are the gate that ensures work is governable from its first moment. (Thick cell — primary primitive.)
CO-TL-ITP: Disputes about work completion, state transitions, or lifecycle stage shall be resolved through declared interpretation rules referencing the work specification and transition rule definitions.
Work disputes must resolve by reference to the declared specification, not by narrative claims about what was intended. The interpretation rules make work governance deterministic.
CO-TL-EIF: Work that interacts with the system's environment — producing external outputs, consuming external inputs, or modifying external state — shall declare its environment-interface requirements explicitly.
Work that silently reaches outside the system's boundary is ungoverned at the boundary. The environment-interface declaration makes cross-boundary work visible and subject to additional governance controls.
CO-TL-CYC: Work lifecycles shall operate within declared temporal cycles, with work that persists beyond its expected cycle producing a carry-forward finding.
Work without temporal bounds can persist indefinitely. The cycle binding ensures that aging work is visible and that carry-forward decisions are governed.
§5.4.9 Memory (ME)
Primary primitives: evidence, learning. Memory is what the governed system retains — the evidence it preserves, the lessons it crystallizes, and the governance history it carries forward.
CO-ME-INT: The memory system shall trace to an explicit intent: the governance purpose of retaining evidence, crystallizing learning, and preserving institutional knowledge.
Memory without intent is hoarding. The intent linkage ensures that retention, crystallization, and decay decisions answer: what governance objective does this preservation serve?
CO-ME-EVD: The evidence-retention discipline shall be reflexively evidenced: the system shall retain evidence that its own evidence-retention discipline is functioning.
Memory houses the evidence obligations discipline itself. The evidence obligation specific to Memory is reflexive: the system proves that its proof-keeping works. (Preserved from CO-ME-EO — thick cell.)
CO-ME-AUT: Authority over retention policy, retention duration, and evidence sufficiency shall be a distinct governance surface separated from observation and operational authority.
Learning authority — who can determine that accumulated evidence warrants changing the system's behavior — is distinct from observation authority and operational authority. (Preserved from CO-ME-AM.)
CO-ME-WRK: Memory operations — evidence capture, triage, crystallization, and decay — shall be governed work with traceable work specifications and evidence commitments.
Memory operations that escape governance are invisible structural changes. Treating memory operations as governed work ensures that what the system remembers and forgets is auditable.
CO-ME-CST: Retention constraints shall propagate such that no downstream record specifies shorter retention than the apex requires, and learning constraints propagate through class-membership review obligations.
If the apex requires three years of evidence retention, no downstream record can specify shorter. If a class requires findings to be reviewed each annual cycle, every member inherits the review obligation. (Preserved from CO-ME-CP.)
CO-ME-DEC: Every learning-lifecycle transition — capture, triage, crystallize, or decay — shall be a governed decision, with decay decisions documented because crystallization was the alternative.
The decision to decay (release a gap signal as noise) must be documented because the alternative (crystallization into a system change) was available and was rejected. (Preserved from CO-ME-DB.)
CO-ME-ACT: Accountability for memory failure — evidence not retained, findings that did not trigger learning, corrective actions lost — shall follow the authority chain responsible for the memory system.
This is a self-referential finding: the governance system's memory of its own governance has failed. Resolution requires examining why the memory system failed to retain, learn, or track. (Preserved from CO-ME-AR.)
CO-ME-CMT: The memory system shall carry explicit retention commitments specifying minimum retention periods, evidence quality thresholds, and conditions under which decay is permissible.
Without retention commitments, the distinction between governed retention and accidental persistence disappears. Commitments make the system's memory contract auditable.
CO-ME-CAP: The memory system's capacity — storage, retrieval speed, and evidence integrity maintenance — shall be assessed against governance demands, with capacity shortfalls producing findings.
A memory system that cannot retain what governance requires is structurally deficient. Capacity assessment ensures that memory infrastructure matches governance needs.
CO-ME-IDN: Every retained evidence artifact shall carry a unique identifier enabling retrieval, cross-reference, and lifecycle tracking across governance periods.
Without evidence identifiers, the memory system becomes a repository that cannot be navigated. Identifiers make evidence retrieval deterministic and evidence lifecycle tracking possible.
CO-ME-ENT: Every evidence artifact shall be attributable to a capturing entity whose observation authority and capacity are registered.
Evidence from unattributed sources has unknown provenance. The entity binding ensures that evidence quality can be assessed by examining the capturing entity's standing.
CO-ME-CTX: Every retained evidence artifact shall carry context metadata — the conditions of capture, the governance period, and the observation circumstances — that qualifies its applicability.
Evidence without context is ambiguous. Context metadata ensures that evidence from one period is not misapplied to another and that capture conditions are known when evaluating evidence weight.
CO-ME-NSP: Evidence artifacts shall be classified within the governed namespace such that evidence types, retention categories, and learning outcomes resolve to governed terms.
Namespace classification for evidence ensures that retention policies can be applied by category and that evidence types are consistently defined across governance periods.
CO-ME-ORI: The memory system shall declare its epistemic orientation toward retained evidence — whether evidence is treated as immutable historical record, as input to learning, or as both.
Orientation in memory determines how retained evidence is used. A system that treats all retained evidence as immutable record cannot learn from it; a system that treats all retained evidence as learning input may modify its historical record.
CO-ME-LRN: The memory system shall implement a declared learning process: pattern detection across retained evidence, proposal of systemic changes, and governed crystallization of learning into system modifications.
Learning is a primary structural surface for memory. Without a declared learning process, evidence accumulates without producing insight, and the system's governance improves only accidentally. (Thick cell — primary primitive.)
CO-ME-ACV: Learning crystallization — the transition from accumulated evidence to system modification — shall activate only when declared thresholds are met, preventing premature generalization from insufficient evidence.
Premature crystallization produces overfit governance — rules derived from too few examples. Activation thresholds ensure that learning produces robust generalizations.
CO-ME-ITP: Disputes about evidence quality, retention sufficiency, or learning validity shall be resolved through declared interpretation rules referencing the evidence taxonomy and retention commitments.
Memory disputes must resolve by reference to the declared evidence standards, not by subjective judgment about what counts as sufficient evidence.
CO-ME-EIF: The memory system shall declare its environment-interface — what evidence the system can retain about its own state versus what evidence it can retain about the external environment.
Evidence about the system's own state and evidence about the external environment may have different retention requirements, quality standards, and interpretation rules. The interface declaration makes this distinction structural.
CO-ME-CYC: The memory system shall operate within a declared review cycle — evidence review, retention assessment, learning review, and decay disposition — with cycle-level evidence produced about the memory system's health.
A memory system without a review cycle accumulates without curation. The cycle binding ensures that the memory system is periodically examined for fitness, completeness, and relevance.
§5.4.10 Uncertainty (UN)
Primary structural surface: cross-cutting via truth-type system. Uncertainty is what the model does not know, represented structurally through truth-type classification and epistemic propagation.
CO-UN-INT: The uncertainty management architecture shall trace to an explicit intent: the governance purpose of making the system's unknowns visible, classifiable, and actionable.
Uncertainty management without intent is anxiety. The intent linkage ensures that truth-type classification, investigative queries, and epistemic propagation answer: what governance objective does uncertainty awareness serve?
CO-UN-EVD: Every claim's truth type shall be documented and auditable as meta-evidence — evidence about the quality of the system's other evidence.
Truth-type evidence is meta-evidence. The evidence obligation is not "we classified our claims" but "for every claim, the truth type is recorded, the basis traceable, and the derivation chain preserves epistemic status at each step." (Preserved from CO-UN-EO.)
CO-UN-AUT: Authority to assign truth types shall be a distinct governance surface separated from content authority.
You may have the authority to state something without having the authority to declare it verified. Truth-type authority is distinct from content authority. The constituting authority holds the highest truth-type authority. (Preserved from CO-UN-AM.)
CO-UN-WRK: Investigation of uncertainty — the work of resolving opaque or declared claims toward authoritative status — shall be governed work with explicit scope, authority, and evidence commitments.
Investigation work that escapes governance produces unauditable epistemic transitions. Treating investigation as governed work ensures that truth-type promotions are traceable to authorized, scoped inquiry.
CO-UN-CST: Truth types shall constrain derivation such that authoritative findings cannot issue from opaque inputs without declaring the derivation chain and epistemic limitations.
If input A is opaque and conclusion B is derived from A, then B's truth type cannot exceed derived-from-opaque. This propagation is structural, not advisory. (Preserved from CO-UN-CP.)
CO-UN-DEC: Assignment of truth types, resolution of investigative queries, and promotion of claims along the opaque-declared-authoritative chain shall each be governed decision surfaces.
Promoting a claim from opaque to declared (based on investigation) or from declared to authoritative (based on verification) is a governed decision with alternatives and audit trail. (Preserved from CO-UN-DB.)
CO-UN-ACT: Accountability for epistemic failure shall examine the truth-type chain to establish whether the decision-maker knew the reliability limits of the claims on which they relied.
Uncertainty-aware accountability does not ask "did you know the right answer?" — it asks "did you know how much you didn't know, and did you act accordingly?" (Preserved from CO-UN-AR.)
CO-UN-CMT: The governance system shall carry explicit commitments regarding epistemic standards — what truth-type thresholds are required for different classes of governance decisions.
Without epistemic commitments, all truth types are treated equally and the distinction between "we verified this" and "someone said this" disappears at the decision point.
CO-UN-CAP: The governance system's capacity to assess, classify, and track uncertainty shall be assessed against its epistemic demands, with capacity shortfalls producing findings.
A system with more epistemic demands than capacity to classify them will produce decisions based on unclassified claims. Epistemic capacity assessment prevents truth-type governance from being overwhelmed.
CO-UN-IDN: Every investigative query shall carry a unique identifier enabling lifecycle tracking from creation through investigation to resolution or retirement.
Without query identifiers, the system's inventory of acknowledged uncertainties is unnavigable. Identifiers make uncertainty management auditable across governance periods.
CO-UN-ENT: Every truth-type assignment shall be attributable to a registered entity whose epistemic authority is documented.
Truth-type assignments from unattributed sources have no epistemic standing. The entity binding ensures that the authority behind a truth-type classification is known and auditable.
CO-UN-CTX: Truth-type classifications shall be context-qualified — a claim may be authoritative in one context and declared or opaque in another.
Context-sensitivity in uncertainty management reflects the reality that epistemic status varies across domains. A claim verified by one methodology may be merely declared under a stricter standard.
CO-UN-NSP: Epistemic constructs (truth types, query statuses, derivation chain labels) shall be defined in the namespace with stable identifiers, ensuring consistent usage across governance domains.
Namespace registration for epistemic constructs ensures that "authoritative" means the same thing everywhere in the governance system and that truth-type labels are not informally redefined.
CO-UN-ORI: The uncertainty management architecture shall declare its epistemic orientation — the philosophical stance (e.g., closed-world, open-world, or hybrid) that governs how absence of evidence is interpreted.
Orientation in uncertainty management determines whether silence is treated as evidence of absence (closed-world) or as genuine unknowing (open-world). Undeclared orientation makes the system's treatment of unknowns implicit and unauditable.
CO-UN-LRN: The uncertainty management architecture shall evolve through a declared learning process: review of truth-type classification effectiveness, query resolution patterns, and epistemic propagation accuracy.
An uncertainty system that cannot learn from its own classification history repeats epistemic mistakes. The learning pathway ensures that truth-type governance adapts to evidence about its own effectiveness.
CO-UN-ACV: Truth-type promotion — the transition from opaque to declared, or from declared to authoritative — shall activate only when declared evidentiary thresholds are met.
Premature truth-type promotion undermines the entire epistemic architecture. Activation thresholds ensure that claims earn their truth-type status through governed evidence accumulation.
CO-UN-ITP: Epistemic disputes — disagreements about truth-type classifications, derivation chain validity, or investigation adequacy — shall be resolved through declared interpretation rules referencing the epistemic taxonomy and evidentiary standards.
Epistemic disputes must resolve by reference to the declared standards, not by authority claims about who "really knows." The interpretation rules make epistemic governance deterministic.
CO-UN-EIF: The uncertainty management architecture shall declare which uncertainties arise from internal system limitations and which arise from environment-interface limitations, with different governance treatments for each.
Internal uncertainty (the system's own knowledge gaps) and external uncertainty (limits of observation) require different responses. Internal uncertainty may be resolvable through investigation; external uncertainty may be permanently bounded by the interface specification.
CO-UN-CYC: The uncertainty register — the system's inventory of acknowledged unknowns, open queries, and epistemic gaps — shall undergo periodic review at a declared cadence, with stale queries dispositioned and emergent uncertainties captured.
An uncertainty register that is never reviewed accumulates stale queries and misses emerging unknowns. The review cycle ensures that the system's epistemic self-awareness remains current.
§5.5 Primitive Navigation via Governance Disciplines
With nineteen primitives, a full "control objectives by primitive" section would produce nineteen subsections totaling one hundred ninety COs read a second time — redundant with §5.4. Instead, the five governance disciplines (§3.1-§3.5) serve as the navigational grouping for primitive reads.
Each governance discipline groups a subset of the nineteen primitives. To read a discipline's coverage map across all ten ingredients, consult the COSO overlay table in §3.6 for the discipline's constituent primitives, then read those rows in the summary table (§5.1). The thematic patterns that the old five-column matrix surfaced — authority separation, named decision surfaces, tighten-only propagation, named evidence artifacts, structural accountability chains — remain visible through this overlay but now operate at the full resolution of nineteen primitives rather than the compressed resolution of five.