Response controls
Govern impact containment after harm has begun: isolation, rollback, recovery, and revocation.
The framework
The book’s operating model combines three control levels with six structural primitives that shape authority, sequence, and adoption.
Three control levels
Govern impact containment after harm has begun: isolation, rollback, recovery, and revocation.
Govern behavior correction. Unsafe behavior appears, then is detected, blocked, reverted, or remediated.
Govern decision space. Unsafe trajectories are unreachable by design.
Chapter 8 · Encoding structural constraints
Represents workflow state and valid next moves so the control plane can distinguish legitimate progression from an unsafe jump.
Mints bounded authority only inside valid workflow context, with explicit purpose, scope, and terminal state.
Expose intent-level moves instead of raw control-plane power.
Ensures actions are valid only from the right workflow state and in the right order.
Ensures authority ends when the mission, incident, deployment, export, or agent task ends.
Packages the primitives into the default workflow teams actually use under pressure.
The build sequence
Start with a high-impact workflow where authority is created, speed is necessary, pressure is real, and failure has meaningful blast radius. Name the states, identify one unsafe transition that must become unreachable, then build bounded authority, curated actions, progression rules, and collapse into a paved road.
The paved road becomes the control - not because it reminds people what to do, but because it changes what normal work can express.
Stay on the trajectory
Book updates, new essays, and practical resources on trajectory governance - sent occasionally.