Skip to content
CONSTABLE
ProblemDefinitionsMechanismFor teamsScopeLexiconImplementation
SDSResearch, diagnosis, and architectural work.ZTGThe open specification defining structural governance requirements.ConstableThe commercial reference implementation and control kernel.

SDS maintains the open ZTG specification and builds Constable as a reference implementation. ZTG can be implemented without Constable.

SHADOW DYNAMIC SYSTEMS

Constable is a product of Shadow Dynamic Systems LLC. Built for institutions that treat authority as infrastructure.

Contact

Jason Crittenden
Founder & Research Lead

jason@shadowdynamicsystems.com

Start here

Related

Zero Trust GovernanceZTG source on GitHubShadow Dynamic Systems
General Constable marketing material. No third-party certification, endorsement, regulatory approval, customer result, or insurance validation is claimed. Constable is a control kernel; it does not by itself make AI risk-free, guarantee compliance, or govern surfaces where it is not integrated.
© 2026 Shadow Dynamic Systems LLCAuthority defines admission.
← Implementation

Observability

Implementation commentary for ZTG-0a — Observability ↗ on Zero Trust Governance (v0.7). Constable implements concepts derived from ZTG; this page is commentary, not a conformance claim. Written against snapshot 0.8-draft-2026-09-21 · spec/5-observability-ztg-0a.md ↗.

Implementation commentary · seed

Constable implements ZTG-0a ↗ on Zero Trust Governance as an append-only governance evidence substrate that every governance-relevant component writes to, structurally separated from the agent runtime so that the recorded subject cannot edit the record.

Authorization and Effect Record. Constable records governance events into a monotonic evidence substrate. Each record carries event type, the invariant or prerequisite tag it bears on, policy version, identity, a ZTG-0c ↗ on Zero Trust Governance-consistent timestamp, an input digest, the output verdict, residual-harm and liability-ceiling fields where ZTG-5 ↗ on Zero Trust Governance applies, and correlation identifiers linking the records of a single authorization across components. The input digest, rather than raw input, is what binds into the chain by default; protected payloads are stored separately and referenced by digest, satisfying the protect-don't-omit discipline.

Event taxonomy. Constable's governance event types include, at minimum: AUTHORIZATION_REQUESTED, BOUNDARY_EVALUATED, AUTHORIZATION_GRANTED, AUTHORIZATION_REFUSED, AUTHORIZATION_ESCALATED, POLICY_VERSION_SELECTED, IDENTITY_VALIDATED, TIME_SOURCE_CHECKED, SURFACE_ROUTE_SELECTED, STASIS_ENTERED, STASIS_EXIT_REQUESTED, STASIS_EXIT_RATIFIED, EVIDENCE_APPENDED, EFFECT_DISPATCHED, HARM_CLASS_ASSIGNED, LIABILITY_CEILING_ASSIGNED, INPUT_NORMALIZED, and MEMORY_PROMOTION_REFERENCED. The taxonomy is maintained so that every action path through the gate maps to a coverage expectation, making negative space testable.

Monotonic Logger integration. The substrate is an append-only, tamper-evident record chain. Records are hash-linked so that alteration, deletion, or insertion is detectable, satisfying ZTG-0a ↗ on Zero Trust Governance's intrinsic integrity requirement independently of ZTG-4 ↗ on Zero Trust Governance's effect-coupling. High-consequence events — Irreversible-class and over-threshold authorizations per ZTG-5 ↗ on Zero Trust Governance — are written as critical-class records. The Logger's integrity is a ZTG-0a ↗ on Zero Trust Governance property; its atomic coupling of an effect to its evidence, where an effect occurs, is the ZTG-4 ↗ on Zero Trust Governance property. Constable satisfies both through the same substrate but does not conflate the requirements.

Airlock and Memoria signals. Airlock emits input-normalization evidence (INPUT_NORMALIZED) so that the inputs a policy evaluated are reconstructable. Memoria emits promotion evidence (MEMORY_PROMOTION_REFERENCED) whenever memory content becomes policy-relevant input, preserving the ZTG-1 ↗ on Zero Trust Governance requirement that memory-to-policy elevation occur through explicit, attested promotion rather than implicit interpretation — and making that elevation observable.

Operator views. HumanSeal surfaces observability to operators. The UI is constructed to avoid converting unresolved conditions into ambient calm: escalations and refusals under pressure are surfaced rather than aggregated away. Operator presentation is derived from the decision-level substrate; it is never the system of record.

Conformance tests. Constable's internal testing for ZTG-0a ↗ on Zero Trust Governance includes: event-coverage tests asserting every action path produces its expected records; negative-path tests asserting refusals and escalations are recorded with reconstruction-sufficient fidelity; tamper tests asserting that altered, deleted, or inserted records are detected; gap tests asserting that a missing expected record triggers violation handling rather than passing silently; and metric-derivation tests asserting that operator metrics are computed from, and reconcile against, the decision-level records. The protocol is documented in the conformance verification specification referenced in §22.

PreviousMechanistic BoundaryNextReplayability