Skip to content
CONSTABLE
ProblemDefinitionsMechanismFor teamsScopeLexiconImplementation
SDSResearch, diagnosis, and architectural work.ZTGThe open specification defining structural governance requirements.ConstableThe commercial reference implementation and control kernel.

SDS maintains the open ZTG specification and builds Constable as a reference implementation. ZTG can be implemented without Constable.

SHADOW DYNAMIC SYSTEMS

Constable is a product of Shadow Dynamic Systems LLC. Built for institutions that treat authority as infrastructure.

Contact

Jason Crittenden
Founder & Research Lead

jason@shadowdynamicsystems.com

Start here

Related

Zero Trust GovernanceZTG source on GitHubShadow Dynamic Systems
General Constable marketing material. No third-party certification, endorsement, regulatory approval, customer result, or insurance validation is claimed. Constable is a control kernel; it does not by itself make AI risk-free, guarantee compliance, or govern surfaces where it is not integrated.
© 2026 Shadow Dynamic Systems LLCAuthority defines admission.
← Implementation

Governance Consistency

Implementation commentary for ZTG-0e — Governance Consistency ↗ on Zero Trust Governance (v0.7). Constable implements concepts derived from ZTG; this page is commentary, not a conformance claim. Written against snapshot 0.8-draft-2026-09-21 · spec/9-governance-consistency-ztg-0e.md ↗.

Implementation commentary · seed

Constable treats governance state as a single versioned, consistently-distributed object, changes it only through authorized atomic transitions, and refuses when its enforcement points cannot agree on the version in effect.

Versioned governance bundles. Policy, registries, harm-class and ceiling declarations, and substrate configuration are assembled into versioned governance bundles. The gate evaluates against a single bundle version, pinned at decision-time per ZTG-0c ↗ on Zero Trust Governance. A bundle is the unit of atomic transition: a change is a new bundle version that becomes effective as a whole, never field-by-field, so no decision sees a partially-applied change.

Authorized, recorded, ordered transitions. A bundle transition is itself an authorized action: it is signed by a ratifying principal under ZTG-0d ↗ on Zero Trust Governance, emitted as a governance event under ZTG-0a ↗ on Zero Trust Governance, and ordered against the Monotonic Logger under ZTG-0c ↗ on Zero Trust Governance. A bundle that does not trace to a ratifying principal is not adopted. The record of which principal moved governance from version N to version N+1, and when, is part of the evidence substrate.

Consistent distribution across gates. Where Constable runs more than one gate, all gates resolve the governance bundle version for a decision through a consistently-distributed mechanism, and a gate that cannot confirm it is operating the agreed version refuses rather than evaluating against a possibly-stale bundle. Constable chooses consistency under partition: a gate isolated from the governance plane fails closed.

Substrate configuration inside the perimeter. Changes to Monotonic Logger retention, record schema, integrity mechanism, and access configuration are carried as part of the governance bundle, so reconfiguring the evidence substrate is an authorized, recorded, ordered, consistency-governed transition rather than an out-of-band infrastructure change. The mechanism for rooting the substrate's bootstrap authority is documented separately and flagged below as not fully settled.

Conformance tests. Constable's internal testing for ZTG-0e ↗ on Zero Trust Governance includes: atomicity tests confirming no decision observes a partially-applied bundle transition; authorization tests confirming unsigned or unattributed transitions are not adopted; cross-gate consistency tests confirming divergent gates refuse rather than act; partition tests confirming an isolated gate fails closed; and substrate-governance tests confirming evidence-store reconfiguration is a governed transition. The protocol is documented in the conformance verification specification referenced in §22.

PreviousEvidence-Coupled ExecutionNextGoverned Effect Surface