Skip to content
CONSTABLE
ProblemDefinitionsMechanismFor teamsScopeLexiconImplementation
SDSResearch, diagnosis, and architectural work.ZTGThe open specification defining structural governance requirements.ConstableThe commercial reference implementation and control kernel.

SDS maintains the open ZTG specification and builds Constable as a reference implementation. ZTG can be implemented without Constable.

SHADOW DYNAMIC SYSTEMS

Constable is a product of Shadow Dynamic Systems LLC. Built for institutions that treat authority as infrastructure.

Contact

Jason Crittenden
Founder & Research Lead

jason@shadowdynamicsystems.com

Start here

Related

Zero Trust GovernanceZTG source on GitHubShadow Dynamic Systems
General Constable marketing material. No third-party certification, endorsement, regulatory approval, customer result, or insurance validation is claimed. Constable is a control kernel; it does not by itself make AI risk-free, guarantee compliance, or govern surfaces where it is not integrated.
© 2026 Shadow Dynamic Systems LLCAuthority defines admission.
← Implementation

Governed Effect Surface

Implementation commentary for ZTG-3 — Governed Effect Surface ↗ on Zero Trust Governance (v0.7). Constable implements concepts derived from ZTG; this page is commentary, not a conformance claim. Written against snapshot 0.8-draft-2026-09-21 · spec/12-governed-effect-surface-ztg-3.md ↗.

Implementation commentary · seed

Constable implements ZTG-3 ↗ on Zero Trust Governance as an effect-surface registry plus a dispatch architecture in which the registered surfaces are the only reachable path from the agent to the world.

No ambient effect authority. Constable's agent runtime holds no general-purpose capability to act on external systems. Every outbound effect is dispatched through a registered surface adaptor; there is no reachable code path by which the agent can produce an external effect except by routing a proposal through the gate to a registered surface. Effect capability is held by the surface mechanism, not ambiently by the agent.

Surface registry. Surfaces and sub-surfaces are registered with their declared harm-class default, compositional multiplier, and reversal_strategy. Sub-surface declarations are validated to tighten, never relax, their parent's defaults. The registry is carried in the ZTG-0e ↗ on Zero Trust Governance governance bundle, so registration and declaration changes are signed by a ratifying principal, recorded, ordered, and applied atomically; the gate evaluates against the registry version pinned at decision-time.

Routing and provenance. When the gate authorizes an action, Constable routes it to the matching registered surface and records SURFACE_ROUTE_SELECTED, binding the surface's harm class, multiplier, and reversal strategy into the action's provenance alongside the ZTG-5 ↗ on Zero Trust Governance fields. Reversal strategy is recorded as provenance only; the gate selection follows harm class and computed assessment per ZTG-5 ↗ on Zero Trust Governance and is never discounted by the presence of a reversal strategy.

Closure verification. Constable treats the absence of reachable unregistered effect paths as a verifiable architectural property and tests for it (below). A reachable effect path discovered without a corresponding registered surface is raised as an integrity violation and triggers Stasis (ZTG-2 ↗ on Zero Trust Governance) rather than being auto-registered.

Conformance tests. Constable's internal testing for ZTG-3 ↗ on Zero Trust Governance includes: reachability analysis confirming no agent-reachable effect path bypasses a registered surface; ambient-authority tests confirming the agent holds no general-purpose effect capability; declaration tests confirming sub-surfaces tighten and never relax defaults; provenance tests confirming reversal strategy is recorded but never relaxes gate or harm class; routing tests confirming every effect records its surface selection; registry-governance tests confirming registration changes are ZTG-0e ↗ on Zero Trust Governance transitions; and breach tests confirming a reachable unregistered channel triggers Stasis. The protocol is documented in the conformance verification specification referenced in §22.

PreviousGovernance ConsistencyNextGraded Conformance