Capability deep-dive · cross-model gates
Your models agreed. What does that actually rule out?
A second model that confirms the first is worth something only if you can say what it read, how far apart the two answers were allowed to be, and how correlated their errors are. Without those three numbers, “two models checked it” is unfalsifiable.
The predicate is computed, not learned
Two or more heterogeneous models re-derive the answer, and a predicate over their structured outputs must pass before anything is released. It is arithmetic, not a judge model, so its inputs are inspectable and its outcome reproduces. It has three conjuncts, and dropping any one of them is how a gate becomes theatre.
conjunct 1
Categorical identity
Every categorical field of the structured output must be identical across the models. Not similar, not semantically close — identical.
conjunct 2
Numeric tolerance, per field
The spread between the highest and lowest value must sit inside a tolerance declared for that field and that decision class. Tightening the tolerance raises refusals; it does not lower escapes.
conjunct 3
Evidence overlap
The models’ cited evidence sets must overlap above a floor. Two models that reach the same answer while reading different documents do not pass — agreement on a conclusion is not agreement on a derivation.
Fail-closed release control is the fifth rung of the dispatch ladder and is designed, not built. The predicate, the verdict and the record are built.
What the gate does not catch
A COMPUTED AGREEMENT PREDICATE IS NOT A PROOF
The gate tests whether independent derivations converge. It does not test whether the converged answer is true. A wrong answer escapes whenever both models are wrong and wrong in the same direction — and model errors correlate for structural reasons: shared pre-training corpora, shared prompt framing, shared retrieved context. Two models from the same family will not clear a demanding correlation bound, which is why heterogeneity has to be measured rather than asserted, and why the number is printed on the certificate.
It does not decide the question
The gate decides what a claim is permitted to say. A passing predicate yields a gated warning that may propose an action. A failing one yields a contested warning where the disagreement is the content, and it may not propose anything. A class with no live validator yields an ungated observation, labelled as such. A dead input yields a refusal and no warning at all.
It never deletes the disagreement
A failed gate does not suppress the warning. Deletion is the failure mode a governance layer exists to prevent: it produces a system that looks calm because its disagreements are invisible. The contested class is how a disagreement stays visible, with both derivations openable side by side.
A gate is capped by its worst input, and can never raise a tier
Every feed datum has three clocks, not one: the time the observation describes, the time we received it, and the time a decision read it. The difference between the first and third governs truth; the other two assign blame correctly, which matters when an operational-resilience report has to say whether a degradation was ours.
Staleness composes downward and only downward. Adding an input can never improve a decision’s freshness, so a pipeline cannot launder a dead feed by averaging it with a live one; unknown provenance resolves to dead rather than to fresh; and a decision that consumed a stale input carries that fact permanently, because it is sealed with the thread. When a feed degrades, the achievable assurance tier drops and the certificate says so. It does not substitute a default.
cross-model validation core(shipped)no silent fallback on a missing upstream key(shipped)per-feed staleness thresholds derived from each feed’s own cadence(designed, not built)
A watcher may propose. It may not arm
A watcher that reads a hurricane advisory or a news stream can propose an effect — open an event room, review a moratorium, re-price an accumulation. The transition from proposed to armed requires a named human through a gated binding, and the armed state shows who armed it. Irreversibility overrides value: a signal that can trigger a spent effect gates against a third model regardless of how cheap it looked.
The second law is smaller and matters as much: a dead feed is a loud row, never a missing row. A watcher list that only ever shows healthy sources has told you nothing about what it does when a source dies.
Where the gate fails closed
REFUSED
GATE_DISAGREEMENT
Two heterogeneous models re-derived the answer and the agreement predicate evaluated false. Nothing was released.
The disagreement is not an error to retry away — it is the finding. Both derivations stay open and comparable, the per-field tolerance, the evidence overlap and the measured pair correlation are shown, and the warning is delivered in the contested class, which may not propose an action. The predicate, the verdict and the record are shipped. The rung that makes “released nothing” a platform-enforced property of every effect is designed and not built, and the certificate says which of the two applied.
The honest limit
WHAT THIS DOES NOT DO YET
- A computed agreement predicate is not a proof. It tests whether independent derivations converge, never whether the converged answer is true, and it cannot catch two models that are wrong in the same direction and agree on the same wrong answer.
- Most validator classes are not live. A warning class whose validator is not deployed cannot be gated at all; it is delivered as an explicitly ungated observation and may not propose an action.
- Drift-detection logic. The alert taxonomy and stores exist; the detection does not.
- Tiers 3–5 of the dispatch ladder. Tiers 1 and 2 run in production — so the release control that makes a failed gate release nothing is designed, not built.
- Every threshold: per-field tolerances, the evidence-overlap floor, the pair-correlation admissibility bound and per-feed staleness ladders are all [P: to be calibrated] against a tenant’s own decided cases.
What this connects to
The formal lane
Where a question is decidable, the answer can carry a checkable witness instead of a convergence. The gate is what covers everywhere it does not reach.
Deliberation rooms
What produces the conclusion the gate then re-derives — and the chair whose ruling the gate sits in front of.
Trust centre
The standing register of what is not built, with dates — including the rungs this page depends on.