Why procedural governance fails
Every team that ships an AI agent reaches for the same first instinct: write a checklist. Add a review step. Require a sign-off field. Then the agent does something no one approved, and the post-mortem finds that every box was ticked.
Procedure assumes visibility
A checklist only works when the thing it checks for is visible at the moment of the check. Agent drift is not. The output that violates your intent looks, line by line, exactly like the output that honors it — right up until it doesn't. By the time a procedure would catch it, the decision has already shipped.
Authority is the control, not the checklist
The thing that actually stops a bad output is not a step in a list. It is a person with the authority to stop the line, and a system that will not proceed until they use it. We call it the owner's flip. Nothing publishes, dispatches, or executes until the owner turns the key.
What the dual-key gate taught us
Building it, we learned that governance you can prove beats governance you can describe. A procedure is a description. A gate is proof: the row cannot enter the published state without a recorded human decision. The status chip is not decoration — it is that record. If your governance lives in a document, it is advisory. If it lives in the write path, it is real.

Authentication Isn’t One Question
Part 1 — Three Security Questions That Looked Like One introduces the dis — Series title: Authentication Isn’t One Question Part 1 — Three Security Questions That Looked Like One introduces the discovery. Machine Auth asks who is calling? The Dual-Key Ceremony asks has th…
The silent drift problem
Agent behavior degrades quietly. Here's how to see it before your users do.
Stay Updated
Get notified when we publish new research or open licensing opportunities.
Owner-gated agent operations. Every action behind your flip.
See the platform →
0 comments