Constable's conformance regime assembles the per-chapter test obligations into a single suite organized by property class, and pairs the testable obligations with the analyses the structural properties require.
Per-property suites. Constable runs the conformance tests each chapter specifies — ZTG-0a on Zero Trust Governance coverage/tamper/gap/metric tests, ZTG-0b on Zero Trust Governance reproduction/drift/isolation tests, ZTG-0c on Zero Trust Governance time tests, ZTG-0d on Zero Trust Governance identity tests, ZTG-0e on Zero Trust Governance atomicity/partition tests, ZTG-1 on Zero Trust Governance bypass/interception tests, ZTG-2 on Zero Trust Governance trigger/exit tests, ZTG-3 on Zero Trust Governance reachability/breach tests, ZTG-4 on Zero Trust Governance ordering/orphan/crash tests, ZTG-5 on Zero Trust Governance classification/banding/promotion tests, and §3 on Zero Trust Governance admissibility/verdict/provenance tests — and organizes them by the property class each falls into rather than by chapter alone.
Reachability analysis. For the structural properties, Constable maintains an effect-reachability argument over its architecture: the agent runtime holds no ambient effect capability, every outbound effect routes through a registered surface adaptor, and the gate is the only path from proposal to dispatch. This argument, not a test pass, is what discharges the no-bypass (ZTG-1 on Zero Trust Governance) and closure (ZTG-3 on Zero Trust Governance) obligations; a reachable effect path found without a registered surface raises an integrity violation and triggers Stasis.
Reproduction and convergence harness. Constable's replay harness (ZTG-0b on Zero Trust Governance) regenerates recorded determinations under pinned bundle and engine; the convergence regime runs independent assessment over the recorded substrate and compares, surfacing divergence as a conformance failure. Both operate without reaching the effect surface.
Injection and adversarial harness. Constable injects negative-space, fault, and tamper conditions — missing records, write-ahead crashes, altered log entries, partition between gates, suppressed evidence — and confirms the specified violation-handling and fail-closed responses.
Certification boundary. This seed describes an intended verification regime, not a completed conformance result. Implementation commentary, a deployment-specific conformance determination, and third-party certification are separate. No certification package or certification status is published by this document.