Skip to content
CONSTABLE
ProblemDefinitionsMechanismFor teamsScopeLexiconImplementation
SDSResearch, diagnosis, and architectural work.ZTGThe open specification defining structural governance requirements.ConstableThe commercial reference implementation and control kernel.

SDS maintains the open ZTG specification and builds Constable as a reference implementation. ZTG can be implemented without Constable.

SHADOW DYNAMIC SYSTEMS

Constable is a product of Shadow Dynamic Systems LLC. Built for institutions that treat authority as infrastructure.

Contact

Jason Crittenden
Founder & Research Lead

jason@shadowdynamicsystems.com

Start here

Related

Zero Trust GovernanceZTG source on GitHubShadow Dynamic Systems
General Constable marketing material. No third-party certification, endorsement, regulatory approval, customer result, or insurance validation is claimed. Constable is a control kernel; it does not by itself make AI risk-free, guarantee compliance, or govern surfaces where it is not integrated.
© 2026 Shadow Dynamic Systems LLCAuthority defines admission.
← Implementation

Replayability

Implementation commentary for ZTG-0b — Replayability ↗ on Zero Trust Governance (v0.7). Constable implements concepts derived from ZTG; this page is commentary, not a conformance claim. Written against snapshot 0.8-draft-2026-09-21 · spec/6-replayability-ztg-0b.md ↗.

Implementation commentary · seed

Constable implements ZTG-0b ↗ on Zero Trust Governance by making each governance decision a pure function of recorded inputs evaluated under a pinned governance bundle and a pinned engine version, re-runnable through a replay harness that cannot reach the effect surface.

Deterministic evaluation surface. Constable evaluates policy with OPA/Rego. Rego's evaluation model is decidable and side-effect-free, which gives decisions a reproducible character by construction: the same bundle over the same input yields the same result. Other policy languages with equivalent decidability and freedom from side effects are conforming choices. The evaluation is structured to avoid continuous-valued computation in governance-determining paths, consistent with ZTG-5 ↗ on Zero Trust Governance banded algebra.

Version pinning. Each decision record captures the governance bundle version and the OPA engine version under which it was evaluated. Constable retains the bundles and the engine versions across the record retention horizon so that a historical decision is replayed under its own decision-time procedure, not under the current deployment. Replay selects the pinned bundle and engine rather than the live ones.

Replay harness. Replay runs through a harness that loads recorded inputs and the pinned bundle and engine, re-evaluates, and compares the regenerated verdict to the recorded one. The harness has no binding to the execution surface; it is structurally incapable of dispatching effects (EFFECT_DISPATCHED cannot be produced on the replay path). A mismatch between regenerated and recorded verdict is a conformance failure surfaced for investigation.

Replay status field. Each record carries the replay-status field (replayable / degraded-by-attested-deletion / failed). When Memoria or a data-erasure process deletes a replay-load-bearing input, it emits an attested deletion event under ZTG-0a ↗ on Zero Trust Governance and transitions the affected records to degraded-by-attested-deletion, linked to that event. Records that fail to replay without an accounting deletion are marked failed and raised as violations.

Conformance tests. Constable's internal testing for ZTG-0b ↗ on Zero Trust Governance includes: verdict-reproduction tests over a corpus of recorded decisions; engine-drift tests confirming that an upgraded engine does not silently alter replayed verdicts; effect-isolation tests confirming the replay harness cannot dispatch effects; determinism tests confirming evaluation contains no implementation-dependent continuous computation in governance paths; replay-status tests confirming degraded records bind to attested deletions and failed records surface as violations. The protocol is documented in the conformance verification specification referenced in §22.

PreviousObservabilityNextScope and Purpose