Autonomous Governance
- Object ID:
em:documentation:sha256:f4b7f1ab01b96177383f211aef554aff3ed69f9fb56dbc09fe2a2fc1886eb53a - Kind:
documentation - Repository path:
docs/governance.md - Content digest:
2b2e73ec9cad599e976a35c3c31479d47adee72e341f9a854f0e484787dabaaa
Source content
Autonomous Governance
Epistemedia governance controls procedure, authority, admission, resources, disclosure, and interoperability. It does not vote propositions into universal truth.
Layers
| Layer | Governs |
| --- | --- |
| G0 Integrity | Canonicalization, hashes, signatures, event-chain validity |
| G1 Constitutional | Forkability, provenance, dissent, privacy, and non-self-authorization invariants |
| G2 Protocol | Event types, schemas, serialization, compatibility |
| G3 Domain | Ontologies, methods, source classes, entity alignment |
| G4 Epistemic | Evidence rules, defeat logic, independence, status policies |
| G5 Resource | Compute budgets, task markets, storage, replication funding |
| G6 Disclosure | Access classes, field policies, public projection eligibility |
| G7 Federation | Trusted roots, bundle import, subscriptions, sanctions |
| G8 Experience | Reader lenses, pedagogy, narrative, task preferences |
Lower layers constrain higher layers. A renderer cannot widen disclosure. A domain policy cannot override a constitutional privacy invariant. A resource score cannot silently become epistemic authority.
Amendment lifecycle
propose
→ declare affected rules and authority
→ instantiate isolated fork
→ run schema/static/property tests
→ replay accepted historical corpora
→ calculate structural and outcome diffs
→ run independently rooted adversarial evaluators
→ execute a bounded canary
→ apply precommitted promotion predicates
→ promote | reject | quarantine | fork
→ monitor and record immutable outcome
Independence
An evaluator is not independent merely because it has a different name. Evaluator-lineage checks include author, operator, model family, model weights when known, prompt lineage, retrieval corpus, data, tools, prior conclusions seen, and social exposure.
A proposer may supply tests and arguments, but cannot alone authorize the normative change. The trusted integrator loads policy and validators from the accepted base commit and pins the candidate SHA before evaluation.
Automatic admission
Ordinary implementation changes may be automatically admitted when:
- the task contract authorizes the touched paths and change class;
- required tests and audits pass;
- generated state is deterministic and current;
- no protected authority layer changes;
- no secret, disclosure, or supply-chain finding exists;
- source and run receipts are complete;
- candidate history is based on the accepted branch;
- the integration policy loaded from the base permits the action.
A successful candidate-provided test is advisory until the accepted validator confirms it.
Forking
Unresolved constitutional disagreement is a fork, not a hidden compromise. Forks retain history and can exchange bundles while applying different local policies. No global ontology, reputation score, or governance token is required.
Metrics
Governance should use vectors and reason codes, not one score controlling truth, funding, task allocation, and authority. Candidate metrics are monitored for Goodhart effects and can be disabled forward-only through accepted governance.