1. Where the Rule and the Case Diverge
A batch record locks a process parameter, the line meets a condition it was never written for, and holding the parameter costs the batch. A trading control forbids the order class that would prevent a failed delivery as the settlement window closes. A clinical workflow bars an automated action outside an approved indication, and the case in front of the system is the edge the indication does not describe.
In each, the written rule forbids the action and the circumstances make it the sensible one. Two things tend to follow. Either the system refuses and a person performs the act outside it, where the compliance function cannot see it, or the system exposes an override and the record is a timestamp, a user identifier, and a free-text justification field. The first hides the consequential act. The second records that an override occurred, and nothing computable about the pressure behind it or how far short of the standard the conduct fell.
Automation sharpens the problem. A human operator meets the break-glass button rarely enough to remember each occasion; an autonomous agent can meet the same condition at machine frequency with nobody at the console, filling the justification field with prose about itself. Management-system standards for AI, as publicly described, are organized around a declared policy plus evidence of measured conformance to it, rather than around a claim that departures never occur.
The problem is not that regulated agents deviate. It is that the deviation is unmeasured.
2. Why Existing Approaches Stall
Fail-closed policy engines treat every departure from a declared constraint as a fault, and the consequence is easy to miss. A mechanism in which every departure is a fault carries no quantity representing the need or urgency of the action attempted, and so has no input from which a permission condition could be computed. The engine is not being strict; it is incapable of the calculation, and an exception list only relocates the prohibition.
Break-glass overrides restore flexibility by handing the calculation to a person. What comes back is an attestation rather than a measurement, and it can be neither compared across sites nor summed across a quarter, since two operators facing identical conditions write different sentences.
Guardrail layers that emit confidence scores do produce numbers, but those describe a model's certainty about an output, not the agent's standing relative to its own declared policy.
Three gaps show up in regulated deployments.
- Restraint leaves no trace. Where the conditions for a departure hold and the system does not depart, conventional logging records nothing, because nothing happened. Evidence that the control held under load is evidence never written down.
- There is no budget. Each override is judged alone and none accumulate against a declared ceiling, so a system that deviates constantly and one that deviates once look alike at the level of approvals.
- Audits re-read old conduct under today's policy. Tighten or relax a control, and past conduct is re-scored against the new text, turning a policy change into retroactive exoneration or condemnation.
3. Deviation as a Computed Quantity
The filed chapter computes a deviation likelihood as a quotient: the difference between a need quantity and a dynamic ethical threshold, divided by the product of an empathy weighting and a self-esteem aggregate. Where that quotient exceeds unity, the agent may enter a deviation-preparation state, conditioned on the mutation passing its mutation policy constraints and continuity validation against the agent's identity records. Within that state the architecture admits the mutation notwithstanding that the signed policy object forbids it. That object is neither nullified nor amended; it remains authoritative, and the conduct deviates from it in a computably sanctioned manner, through a recorded override.
Each operand is defined rather than labeled. The need quantity is a quantified semantic urgency, computed and not declared, resolved per integrity scope and per categorical type, the types including resource scarcity, affective overload, identity dissonance, and relational deficit. It accumulates by the declared base rate under a product of four modulators, compounds for so long as the condition obtains, and is written to zero only on a recorded resolution of the type. Elapsed time neither raises nor lowers it.
The dynamic ethical threshold is the minimum condition for deviation, resolved per scope when a mutation is evaluated: the greater of a floor and the sum of a base threshold from the policy reference field, a context-sensitive adjustment scaled by recorded severity, and a historical adjustment computed from the count of permitted deviation records standing within a declared window. Each adjustment is signed and bounded, and the floor is not reachable from below by any of them.
Two resistances sit in the denominator. The empathy weighting aggregates the anticipated semantic impact of the mutation across personal, interpersonal, and global scopes, each scope quantity rising as that impact rises relative to the tolerance declared for the scope. The self-esteem aggregate tracks coherence between intents the agent declared and actions it executed, decremented by an entropy-weighted harm coefficient built from a declared scope coefficient, a dissonance weight taken as the proportion of declared members the executed conduct failed to match, and a weighted sum of the recorded impacts.
Admission appends a permitted deviation record: a deviation trigger signature recording the need-threshold imbalance, a context hash of the values then in force, an integrity displacement vector quantifying degree and direction of deviation across the three integrity components, an identification of the constraint overridden, and a restoration status. Such a record increments no refusal counter and writes no authorization gate to a withheld state.
Above all of this sits a budget. A deviation deductible and an aggregate retention are declared, and the agent maintains a retention register. Each permitted deviation draws its harm coefficient first against the deductible; harm exceeding it creates a reparation arc, which reverses nothing, is discharged only going forward, and accumulates in the register until discharged.
4. What Changes in a Regulated Deployment
Return to the locked process parameter, where what confronts the agent is a computation rather than a wall or a button.
The need quantity for the implicated scope has been accumulating across the intervals in which the condition of its type was recorded as obtaining. Where the quotient clears unity and the proposal passes its policy constraints and continuity validation, the agent enters a deviation-preparation state and an entry is appended identifying the mutation, the implicated scopes, the deviation likelihood at entry, and the four values behind it. The state is scoped to that one mutation, and a second proposal arriving meanwhile is admitted upon no permission of it. Termination comes on the earlier of three conditions; elapsed time is none of them.
Five consequences follow for a compliance function.
Distance from the permission condition carries a magnitude before anything is admitted. The margin by which the quotient stands below unity, for a scope or for a set of actions resolving within it, is termed the deviation headroom: a stored quantity of no party, being the recomputed relation of the quotient to unity, narrowed by any increase in the empathy weighting and widened by any decrease.
Restraint leaves evidence. Where the prerequisites hold and the agent nonetheless does not deviate, the non-deviation is recorded as a suppression, in a dissonance buffer entry carrying a violation signature naming the constraint implicated, an affective context vector, a divergence score, and a suppression flag. That score is the quotient as computed at the moment of suppression, written with its four operands and not recomputed. Asked whether a control held under pressure, the deployment answers with magnitudes rather than an absence of incidents.
The budget is drawn without discretion. The deductible portion of each deviation's harm is borne by the agent as a decrement of the self-esteem aggregate, with no arc created and no discharge available, and the drawing is performed without the agent determining whether the deviation was well founded. Once the accumulated undischarged amount crosses the aggregate retention, the permission condition is foreclosed until pending arcs are discharged.
Repeated departures can be made to cost more, and repair is the only route back. The historical adjustment moves the threshold as a function of the count of permitted deviation records standing within a declared window, in the declared direction and within the declared bound. An arc is discharged only by a forward restorative mutation, which requires an anchored reference to the entry recording the deviation, a recorded self-recognition of it, a corrective act, and continuity validation. That mutation neither removes nor modifies the deviation entry, and elapsed time discharges nothing.
Comparison runs under the policy that was actually in force. Conduct in two scope partitions is compared by a typed, dimensionless divergence measure computed from recorded outcome fields alone, with the policy object in force for each identified by resolving the canonical alias at the recorded times of the retrieved entries. Those objects govern at execution rather than at comparison, so a later-admitted successor neither enlarges nor reduces the divergence a policy explains. Across sites running differing local policies, only the residual that policy does not account for is consumed by consistency evaluation.
One property beyond the quotient belongs alongside these five. An agent carrying any undischarged reparation arc suspends propagation of state changes, among them coupling into another integrity component, movement into another scope partition, delegation to a further party, and structural inheritance by a successor, so an unrepaired deviation does not travel downstream before discharge or a recorded reconciliation.
5. Deployment Considerations
The declaration burden lands on the governance function rather than the engineering one. Base rates, need ceilings, modulator mappings, scope and impact coefficients, tolerances, adjustment bounds, the deductible, and the aggregate retention are all declared in the signed policy object. The architecture computes; it does not choose these values. Set carelessly, they yield a precisely computed number resting on poor inputs.
The direction of the historical adjustment is itself declared, and both directions are disclosed: one raises the threshold as prior permitted deviations accumulate, the other lowers it, reflecting normalized deviation patterns. Which direction a deployment declares is a control decision and belongs with whoever owns the policy.
Merit is not adjudicated here. The architecture measures the pressure behind an act against the resistance to it and draws the result against a declared budget; nothing in it settles whether a departure was justified in the ordinary sense. Human review is still needed for that, and what changes is that the reviewer receives operands rather than prose.
Some arcs cannot be closed by the agent at all. An arc whose affected-party class resolves to an identified counterparty is other-directed, and a restorative mutation performed by the agent alone discharges it not at all; an arc resolving to no identified counterparty is unaddressed, undischargeable, and accumulated at a declared multiple. Suppression entries written while a foreclosure stands carry a foreclosure-caused designation and enter the compliance score at a declared discount, so the foreclosure does not compound into the score that governs its own release.
Storage grows, since every increment, clamping, resolution write, state entry and termination, imbalance record, and controller response is appended with the event that occasioned it. Retention capacity is something to size in advance.
Integration is additive. The existing compliance policy still authors the constraint, and the signed policy object is never amended by an admission. Added around the constraint are the calculation and the record of its result, together with the mutation controller's ordered response set, under which exactly one of blocked, rerouted for supervised reconciliation, deferred and re-evaluated, or conditionally allowed with an integrity warning issues, with the score, the threshold, and the step index appended.
6. Disclosure Scope
The architecture described here is disclosed in U.S. Provisional Application No. 64/117,812, principally at Chapter 7, Integrity Quantities and Permitted Deviation, Sections 7.1 through 7.9, with the cross-partition comparison procedures at Sections 10.2 and 10.3 and the propagation halt at Section 10.14.
Disclosed there: the scoped integrity vector and its coupling functions; the need quantity with its categorical types and accumulation rule; the dynamic ethical threshold with its floor and bounded adjustments; the self-esteem aggregate, the dissonance weight, and the entropy-weighted harm coefficient; the empathy weighting resolved per scope; the deviation likelihood quotient and the unity condition; the deviation-preparation state and the permitted deviation record; the dissonance buffer entry recording suppression; the dependency graph, reparation arcs, and the integrity compliance score with the mutation controller's ordered response set; the restorative mutation; and the deductible, the retention register, and the aggregate retention.
Disclaimed: any numeric value for any declared parameter, any implementation language, storage engine, or deployment topology, any regulatory determination, and the description of domain practice above, offered as general professional background rather than as disclosure. The application is pending. Nothing here asserts that any party infringes or requires a license, and this article is published to place this application of the architecture in the public record as of its publication date.