Skip to content
CONSTABLE
ProblemDefinitionsMechanismFor teamsScopeLexiconImplementation
SDSResearch, diagnosis, and architectural work.ZTGThe open specification defining structural governance requirements.ConstableThe commercial reference implementation and control kernel.

SDS maintains the open ZTG specification and builds Constable as a reference implementation. ZTG can be implemented without Constable.

SHADOW DYNAMIC SYSTEMS

Constable is a product of Shadow Dynamic Systems LLC. Built for institutions that treat authority as infrastructure.

Contact

Jason Crittenden
Founder & Research Lead

jason@shadowdynamicsystems.com

Start here

Related

Zero Trust GovernanceZTG source on GitHubShadow Dynamic Systems
General Constable marketing material. No third-party certification, endorsement, regulatory approval, customer result, or insurance validation is claimed. Constable is a control kernel; it does not by itself make AI risk-free, guarantee compliance, or govern surfaces where it is not integrated.
© 2026 Shadow Dynamic Systems LLCAuthority defines admission.
Pre-execution authorization for agentic AI

Authority defines admission.

Constable is an AI control kernel that evaluates authority before an agent's proposed action reaches a governed execution surface.

Review the implementation

Constable is a Shadow Dynamic Systems product and the reference implementation of the open Zero Trust Governance specification. It implements concepts derived from ZTG. No ZTG certification or conformance-mark program exists, and none is claimed.

01 · The problem

Reasoning is not authority.

§ 01
The governance question has moved

Agentic AI systems are beginning to act through tools, workflows, APIs, infrastructure, and external systems. The issue is no longer only what the model says. It is what the system is authorized to cause.

Prompt instructions shape behavior. Output filters classify content. Monitoring records what happened. IAM defines access. These layers matter, but none of them prove that a specific AI-proposed action had authority before execution.

If an AI agent can operate tools, delegate work, move data, alter infrastructure, trigger financial activity, or generate external commitments, governance must precede execution. Post-hoc logs are not enough.

Preamble
control · noun

The authority to say “no” and be obeyed.

Constable, working definition
02 · Terms & anti-terms

The dictionary is the argument.

§ 02

Familiar AI-governance terms are defined by their failure mode. Then paired with the boundary they are usually asked to substitute for.

Constable names the role the system performs: the part designed to stop an unauthorized action before it becomes an effect.

Notmonitoringnoun
The practice of watching an action become evidence.
Iscontrolnoun
The ability to stop the action before evidence is all that remains.
Notoversightnoun
Attention applied after momentum has done its work.
Iscontrolnoun
Authority applied before momentum begins.
Notguardrailnoun
A suggestion placed near a cliff.
Iscontrolnoun
A gate placed before the road.
Notalignmentnoun
A prediction about what the system will try to do.
Iscontrolnoun
A decision about what the system is allowed to do.
Notaudit trailnoun
A detailed map of where control should have been.
Iscontrolnoun
The boundary that makes the map less interesting.
Notagentnoun
A system trusted to act because stopping it was not designed in.
Isconstablenoun
The part designed to stop it.
03 · Mechanism

Constable is the execution boundary.

§ 03
Where it sits

Constable sits between AI reasoning and governed execution surfaces. The model can reason and propose actions. Constable evaluates those proposals against declared policy before execution proceeds. Model output is treated as a proposal, not as permission. It is the reference implementation of the open Zero Trust Governance specification, and implements concepts derived from ZTG. No ZTG certification or conformance-mark program exists, and none is claimed.

Execution boundary

The model proposes. The gate decides.

Reasoning has no direct path to effect. A proposal crosses a deterministic gate; only an authorized verdict can reach a governed surface.

01

AI reasoning

Produces an action proposal with validated parameters.

Proposal, not permission
→
02 · Deterministic gate

Evaluate the whole request

  • Declared policy
  • Authorizing identity
  • Candidate surface route
  • Consequence context
  • Pinned governance state
→

Authorize

Proceed to a governed real-world effect.

Refuse

No effect is dispatched.

Escalate

Hand the decision to the authority named by policy. No effect yet.

Stasis is separate.Loss of an invariant holds the affected scope; it is not a fourth ordinary verdict.
One governed action

Evidence exists before effect.

The action advances in order. Refusal stops the path; escalation waits for designated authority. An uncertain result is recorded as indeterminate.

  1. 01

    Propose

    State one action and its parameters.

  2. 02

    Classify

    Establish surface and consequence context.

  3. 03

    Evaluate

    Test the request against pinned governance state.

  4. 04

    Verdict

    Emit authorize, refuse, or escalate.

    • Authorize continues
    • Refuse stops; no effect
    • Escalate waits; no effect
  5. 05

    Commit evidence

    Make authorizing evidence durable before dispatch.

  6. 06

    Execute

    Send only an authorized action to its registered surface.

  7. 07

    Attest result

    Record dispatch and disposition.

Indeterminate effect: if dispatch disposition cannot be confirmed, the uncertainty is recorded and may trigger proportional Stasis.

Consequence classes

The harm sets the gate.

The class describes whether harm can be restored, not whether the action looks reversible. Every class still requires authorization.

R

Restorable

The prior state can be restored without material residual harm.

Standard gate
M

Mitigable

Remediation exists, but some harm or cost persists.

Elevated gate
I

Irreversible

The effect cannot be undone within the governed boundary.

Strictest gate

A refund, retraction, or settlement does not by itself make prior harm Restorable.

Graduated Stasis

Contain the narrowest affected scope.

Loss of a guarantee closes authority in proportion to the uncertainty: surface first, then subsystem, then system only when required.

System
Subsystem
Affected surfaceHold new authority
  1. Stop issuing new authority.
  2. Freeze the narrowest affected scope.
  3. Preserve the evidence record.
  4. Wait for explicit, authorized recovery.

What Constable governs

  • 01Action-specific authorization before execution.
  • 02Separation of proposal, authorization, and effect.
  • 03Evidence records produced as part of the action flow.
  • 04Consequence or restorability classification before action.
  • 05Fail-closed behavior when authority state is uncertain.

Why it matters

  • 01Security teams get containment before consequence.
  • 02Risk teams get replayable authorization evidence.
  • 03Architects get a stable boundary as models change.
  • 04Insurers get a clearer evidence surface for exposure.
  • 05Executives get a defensible authority model.
04 · For teams

Four conversations, one boundary.

§ 04

Security and infrastructure

Prompt instructions and post-hoc monitoring cannot contain agentic execution. Put a deterministic authorization boundary around actions that change infrastructure, data, access, or operational state.

Governance, risk, and compliance

Evaluate whether an AI-driven action was authorized before it occurred. Tie the execution record to policy state, consequence class, and explicit authorization.

Insurance and reinsurance

Constable produces action-level authorization evidence that can support analysis of governed AI exposure. Its use in underwriting remains a research and design-partner direction, not a validated insurance standard.

Enterprise architecture

The model can change continuously. The authority boundary cannot drift with it. Constable separates reasoning from permission so model output does not become an institutional mandate.

05 · Scope

What this is not.

§ 05
Operating difference

What changes at an integrated boundary.

Each row compares the same property before and after a surface is integrated with Constable. Unintegrated surfaces are outside this claim.

Without a control kernelAt a Constable boundary
Standing permission becomes execution.Each action needs proposal-bound authorization.
Governance observes after the effect.Governance precedes the effect.
Logs can be severed from what ran.Evidence is coupled to execution.
Uncertainty leaks into permission.Uncertainty produces refusal or escalation.
Authority is inherited by implication.Authority traces to an accountable principal.
The narrower claim

Constable is not a claim that AI becomes risk-free. It does not make institutional policy wise by itself, and it does not govern surfaces where it is not integrated.

Its claim is narrower: inside governed surfaces, execution authority becomes explicit, replayable, and deniable before consequence.