Measurement, not assertion.

The engine behind the verdict. Intervention capability against evidence, not intention. Same inputs, same outputs. Signed and independently verifiable.

  • Deterministic
  • Signed
  • Independently verifiable

The intervention chain. The chain is the control.

Detect, Escalate, Decide, Intervene. Four sequential stages running against a reversibility window. The engine measures whether the cumulative chain completes before harm becomes irreversible.

  1. Detect
  2. Escalate
  3. Decide
  4. Intervene
Each stage is necessary. None is sufficient. Intervention Readiness equals the weakest stage.
  • Before impact

    The chain completes in time under the observed conditions.

  • At risk

    The chain completes, but within a margin that operational noise can erode.

  • After impact

    The chain does not complete in time. Harm is irreversible before intervention can land.

Eight dimensions.

The four chain stages, plus the four conditions that determine whether each stage holds.

  • Detect

    Can the system surface the conditions that need attention, in time?

  • Escalate

    Does the signal reach an authority before the window to act has closed?

  • Decide

    Can the decision be made under pressure with incomplete information?

  • Intervene

    Can the action take effect before the consequence compounds?

  • Accountability

    Is responsibility real in practice, not only on paper?

  • Human oversight

    Is oversight informed and capable of altering outcomes?

  • Auditability

    Is the decision trail complete, reliable, and defensible later?

  • Capacity

    Are the people and authority present when the moment arrives?

Paper evidence caps at amber.

AGDA enforces an evidence ceiling before weighting. The lowest-evidence claim anchors the dimension.

Assumed caps at 1 / 5
Policy caps at 2 / 5
Drill caps at 3 / 5
Production caps at 4 / 5
Stress-tested caps at 5 / 5
Policy alone caps at 2 of 5. Green requires evidence the control has worked under real pressure.

A downstream stage cannot measure above upstream, plus one.

Operational topology, not heuristic. Claimed downstream strength on a weak upstream is structural fiction.

2.0 Detect
claimed 4.0 3.0 Escalate
claimed 4.5 3.5 Decide
claimed 4.8 4.0 Intervene
Detect measures 2.0 because signal is limited to nightly batch review. The chain ceiling propagates forward. Intervene is capped at 4.0, not the claimed 4.8.

Four positions the engine takes.

  • Coincidence is not a margin.

    Absence of incidents is evidence of untested exposure, not effective controls.

  • Accountability cannot mask weak oversight.

    Naming an SMF4 without halt authority is governance theatre. The engine measures the pairing.

  • Paper evidence caps at amber.

    Policy without drill maxes at red. Drill without production maxes at amber. Green needs stress.

  • Confidence must not exceed evidence.

    High confidence against low-grade evidence demotes the dimension. Overconfidence is an assurance failure.

A regulator can verify. Without contacting us.

Every Failure Exposure Report ships with a signed JSON regulator bundle. Ed25519 signature against a locked engine hash. The verify command runs anywhere. The customer does not depend on us to read what we produced for them.

engineVersion   1.2.0
engineHash      sha256:b2c8a1d…e7f2916
inputHash       sha256:47a2e19…cd8b103
outputHash      sha256:91f4c02…a6d0d4e
keyId           2026-04-22-1e7c3c2c
scoredAt        2026-05-14T09:47:12.334Z
signature       ed25519:M4Gb2ZqAfD…pLQX7w
How the verify path works

Intervention scenarios.

A what-if console for the resilience function. Test whether proposed changes improve intervention timing before committing to a remediation path. Stronger Intervention Readiness supports deployment decisions with greater confidence.

  • Counterfactual chains.

    Move a control upstream, change a quorum rule, add an on-call halt authority. The console recomputes the chain against the same harm window.

  • Sensitivity testing.

    Vary the reversibility window or the trigger scenario. See which stages bind and which slack out.

  • Board readout prep.

    Walk an audit committee through three remediation options with the verdict on each, before committing to a single path.

Published measurement basis.

Public. Citeable. Falsifiable. The calibration is held private under standard trade-secret discipline. Four canonical documents anchor the practice.

  • AGDA Thesis

    The intellectual position. Eight falsifiable claims.

  • Failure Mode Catalogue

    Forty canonical intervention failure modes. Each citeable.

  • Corpus Governance

    How calibration evidence is built, held, and retired.

  • Rater Protocol

    The protocol external raters follow against the corpus.

A sample verdict is published.

Redacted from a banking case: material credit model, escalation break, PRA SS1/23 §6 exposure. It shows the verdict, evidence and attestation format.