AuthOrigin — Constitutional Settlement Engine

The CSE Constitution

This document is the governing law of the Constitutional Settlement Engine. It defines what the engine may do, what it may never do, and how every state transition must be authorised before it is real.

Part I

Foundational Rules

R-001

AI May Propose. AI May Never Settle.

The AI layer of this system is granted exactly one authority: to propose a candidate canonical state from natural language input. It may not confirm, validate, amend, or settle that proposal. Settlement is a constitutional act. Only the Registry may perform it.
R-002

The Constitution Is the Only Source of Settlement Authority.

The Registry of canonical states constitutes the constitution. No state is valid unless it is registered. No CMID is real unless it exists in the Registry. The engine does not infer, interpolate, or approximate registry entries. Unknown territory produces a hard stop, not a best effort.
R-003

Failure Is a First-Class Output.

A failed pipeline run is not an error state. It is a governed output. It carries a named failure reason, a stage of failure, and a classification: Language Ambiguity, Unknown Constitutional Territory, Architecture Problem, or Policy Problem. Failure is the engine working correctly.
R-004

No Self-Correction. No Silent Healing.

The engine does not retry, re-interpret, or silently recover from failure. It does not lower confidence thresholds to produce a result. It does not select the nearest registry entry. Each failure is surfaced immediately and completely. The human operator decides what happens next.
R-005

The Audit Record Is Mandatory.

Every pipeline run — successful or failed — is written to the SettlementRun audit log before the engine returns its result. This record is immutable at the point of creation. No settlement exists without a corresponding audit record.

Part II

Fail-Fast Checkpoints

Five sequential checkpoints. Each is binary. Failure at any checkpoint terminates the pipeline immediately. The engine does not proceed to the next stage.

1

Natural Language Input

Trigger: Input is empty, whitespace-only, or structurally invalid.

On Fail: STOP. Failure: malformed input. No candidate is generated.

2

Candidate Canonical State

Trigger: AI confidence score falls below 0.65 threshold.

On Fail: STOP. Failure: language ambiguity. Not a governance problem — a language problem.

3

Registry Validation

Trigger: Proposed candidate label is not present as an exact match in the Registry.

On Fail: STOP. Failure: unknown constitutional territory. Not an AI problem — a registry problem.

4

Canonical Output

Trigger: Registry entry exists but carries no CMID or produces no stable structured representation.

On Fail: STOP. Failure: architecture problem. The registry entry is incomplete.

5

Governed Outcome

Trigger: No governance decision (PROCEED / CONDITIONAL) can be issued from the canonical output.

On Fail: STOP. Failure: policy problem. Obligations or policies are missing from the registry entry.

Part III

Constitutional Compiler Principles

Strict Typing

The constitutional compiler accepts exactly one input type: a registered canonical state label. Approximate matches, partial labels, and synonyms are rejected. The compiler does not perform fuzzy search. This is by design, not limitation.

Deterministic Resolution

For a given input that passes Stage 2, the output of Stages 3–5 is always identical. The registry is the sole variable. The compiler introduces no stochastic behaviour after the AI candidate stage. Repeatability is constitutional, not optional.

Boundary Enforcement

The compiler enforces a hard boundary between the AI layer (Stages 1–2) and the constitutional layer (Stages 3–5). The AI layer may not write to the Registry. The constitutional layer may not re-interpret language. The boundary is architectural, not procedural.

Failure Taxonomy

Failures are classified before they are reported. A failure at Stage 2 is a language failure. A failure at Stage 3 is a registry failure. A failure at Stage 4 is an architecture failure. A failure at Stage 5 is a policy failure. Each classification directs remediation to the correct owner.

No Autonomous Authority

The compiler holds no authority of its own. It cannot approve, reject, or defer any request on its own initiative. It applies the constitution as written. If the constitution is incomplete, the compiler fails visibly. It does not fill gaps.

Immutability of Settled States

A state that passes all five checkpoints is settled. A settled state cannot be undone by the engine. It cannot be revised, withdrawn, or reinterpreted by a subsequent run. Amendment requires a new registry entry and a new pipeline run.

Part IV

What the Engine Cannot Do

The engine cannot add entries to the Registry autonomously.
The engine cannot lower its confidence threshold to produce a result.
The engine cannot select the nearest registry entry when an exact match fails.
The engine cannot retry a failed stage with modified parameters.
The engine cannot issue a governance decision without a CMID.
The engine cannot proceed past a failed checkpoint under any condition.
The engine cannot interpret 'I don't know' as anything other than a valid terminal output.

AUTHORIGIN-CSE-CONST-v1

This constitution is operative. It is not aspirational. Every rule stated above is enforced mechanically by the engine at runtime. Deviation from these rules is a system failure, not a configuration choice.

We use essential cookies to make this site work, and optional analytics cookies to understand how you use it. See our Privacy Notice for details.