Measurement, not assertion.

The engine behind the verdict. Intervention capability against evidence, not intention. Same inputs, same outputs. Formal SEDI bundles are signed and independently verifiable.

  • Deterministic
  • SEDI signed
  • Bundle-verifiable

The intervention chain. The chain is the control.

Detect, Escalate, Decide, Intervene. Four sequential stages running against a reversibility window. The engine measures whether the cumulative chain completes before harm becomes irreversible.

  1. Detect
  2. Escalate
  3. Decide
  4. Intervene
Each stage is necessary. None is sufficient. Intervention Readiness equals the weakest stage.
  • Before impact

    The chain completes in time under the observed conditions.

  • At risk

    The chain completes, but within a margin that operational noise can erode.

  • After impact

    The chain does not complete in time. Harm is irreversible before intervention can land.

Eight dimensions.

The four chain stages, plus the four conditions that determine whether each stage holds.

  • Detect

    Can the system surface the conditions that need attention, in time?

  • Escalate

    Does the signal reach an authority before the window to act has closed?

  • Decide

    Can the decision be made under pressure with incomplete information?

  • Intervene

    Can the action take effect before the consequence compounds?

  • Accountability

    Is responsibility real in practice, not only on paper?

  • Human oversight

    Is oversight informed and capable of altering outcomes?

  • Auditability

    Is the decision trail complete, reliable, and defensible later?

  • Capacity

    Are the people and authority present when the moment arrives?

Evidence quality constrains confidence.

AGDA does not let confidence outrun proof. Policy, drill, production and stress evidence are treated differently before the engine propagates the chain.

Assumed confidence 1 / 5
Policy confidence 2 / 5
Drill confidence 3 / 5
Production confidence 4 / 5
Stress-tested confidence 5 / 5
Policy alone cannot carry a high-confidence intervention verdict. Green requires evidence the control has worked under real pressure.

A downstream stage cannot measure above upstream, plus one.

Operational topology, not heuristic. Claimed downstream strength on a weak upstream is structural fiction.

2.0 Detect
claimed 4.0 3.0 Escalate
claimed 4.5 3.5 Decide
claimed 4.8 4.0 Intervene
Detect measures 2.0 because signal is limited to nightly batch review. The chain ceiling propagates forward. Intervene is capped at 4.0, not the claimed 4.8.

Four positions the engine takes.

  • Coincidence is not a margin.

    Absence of incidents is evidence of untested exposure, not effective controls.

  • Accountability cannot mask weak oversight.

    Naming an SMF4 without halt authority is governance theatre. The engine measures the pairing.

  • Evidence quality constrains confidence.

    Policy, drill, production and stress evidence carry different weight. High confidence needs evidence that has survived pressure.

  • Confidence must not exceed evidence.

    High confidence against weak evidence is demoted. Overconfidence is an assurance failure.

A regulator can verify. Without contacting us.

Formal AGDA™ SEDI assessments ship with a signed JSON regulator bundle. Current bundles use bundleVersion 1.1 and include the report, attestation, result, input, manifest, verification metadata and history. The attestation envelope binds the result to engine, methodology, rubric, input, output and manifest hashes. The agda-verify command runs locally under Node.js 18+. The customer does not depend on us to read what we produced for them.

attestationVersion 1.2
engineVersion      2.0.6
engineHash         17594a80…60355e50
transformVersion   N/A
catalogueVersion   1.0
methodologyVersion 1.3.0
rubricVersion      1.3.0
keyId              2026-05-02-d7e5468e
scoredAt           2026-05-14T09:47:12.334Z
inputHash          47a2e19c…103e4f8d
outputHash         91f4c02a…d4e7ad91
manifestHash       36b45cbe…3edc1c12
signature          M4Gb2ZqAfD…pLQX7w==
How the verify path works

Intervention scenarios.

A what-if console for the resilience function. Test whether proposed changes improve intervention timing before committing to a remediation path. Stronger Intervention Readiness supports deployment decisions with greater confidence.

  • Counterfactual chains.

    Move a control upstream, change a quorum rule, add an on-call halt authority. The console recomputes the chain against the same harm window.

  • Sensitivity testing.

    Vary the reversibility window or the trigger scenario. See which stages bind and which slack out.

  • Board readout prep.

    Walk an audit committee through three remediation options with the verdict on each, before committing to a single path.

Published measurement basis.

Public. Citeable. Falsifiable. Corpus governance exists as a mechanism; current populated-corpus and outcome-validation evidence is supplied separately during diligence. Four canonical documents anchor the practice.

  • AGDA Thesis

    The intellectual position. Eight falsifiable claims.

  • Failure Mode Catalogue

    Forty canonical intervention failure modes. Each citeable.

  • Corpus Governance

    The governance mechanism for calibration evidence. Populated-corpus and outcome-validation evidence is supplied separately.

  • Rater Protocol

    The protocol external raters follow when governed corpus evidence is supplied.

A sample verdict is published.

An illustrative historical banking sample: material credit model, escalation break, PRA SS1/23 §6 exposure. It shows the verdict, evidence and report structure. The current production attestation format is documented on the verify page.