Skip to content
← Back to Override Doctrine

Operator brief · 263

Governance contamination: what happens when every metric can change risk.

The key idea

How it happens

It arrives one reasonable addition at a time.

Nobody designs a contaminated system. It accumulates. A new diagnostic proves useful, so it is wired to adjust the tier a little. A second one catches something the first missed, so it gets a modifier too. A monthly overlay seems relevant, so it is allowed to nudge the daily selection. Each addition is individually defensible and each is made by someone reasoning correctly about the metric in front of them. What none of the individual decisions considers is the composition: after enough of them, the deployed risk is a function of a dozen partially-correlated readings with no stated precedence, and the question of why the tier is what it is has no answer shorter than re-running the whole calculation. The failure is emergent, which is why it needs a name and a structural prohibition rather than case-by-case judgement.

FigureThe loop that has no terminator
Metric moves riskeach one independentlyRisk changes resultssize alters outcomesResults move metricsall of them at onceMetrics disagreeno precedence to settleOutput unexplainablecorrect, and unreadableNO ANCHOR

The contaminated arrangement is genuinely circular: deployment changes the outcomes, outcomes change the metrics, and metrics change deployment again with no layer holding position. A hierarchy breaks the loop by making one input answerable to nothing downstream of it.

The double-count

Correlated inputs each granted authority punish the same fact repeatedly.

The sharpest version of the problem is arithmetic rather than architectural. The readings in this stack are not independent — drawdown, efficiency, profit factor, acceleration and structural drawdown all move together during a difficult stretch, because they are five views of one underlying condition. If each is granted its own power to reduce the tier, a single episode of deterioration is charged five times, and the resulting deployment is far below what any one reading would have justified. The system then under-deploys severely during recovery, which lengthens the recovery, which keeps the readings depressed. This is why the design distinguishes routing from scoring so carefully: drawdown selects the capital-state row and does not additionally penalise the tier, because a tier penalty on top of a gate row is the same punishment applied twice.

The cure

Caps compose safely; adjustments do not.

The structural answer is that stronger layers cap weaker layers rather than everything summing. A cap is idempotent and order-independent: applying three caps in any sequence yields the minimum, and applying the same cap twice changes nothing. That is what makes the resolution stable no matter how many overlay layers are added. An adjustment has neither property — two adjustments compound, order can matter, and adding a third changes the meaning of the first two. The panel is therefore built so that most layers contribute ceilings, a small set of clearly-named modifiers contribute adjustments to a raw recommendation before any minimum is taken, and the two mechanisms are never mixed. Growth in the number of diagnostics then costs nothing in coherence, because a new cap is just one more term in a minimum.

Why an override belongs here

Casual override use is contamination introduced by hand.

This doctrine sits on the override page for a reason. An override is a metric with a vote — specifically, the operator's own reading, granted the power to change deployment outside the resolution. Used rarely and documented, it is a sanctioned exception whose effect is visible and countable. Used casually, it becomes an additional unranked input that adjusts risk according to considerations nobody wrote down, which is the definition of the failure described above. The difference between the two cases is not the mechanism, which is identical, but whether the input is bounded and recorded. That is why the accountability requirement is not bureaucratic decoration: logging is what keeps the operator's judgement a countable exception rather than an eleventh layer of the authority stack.

Recognising it

The diagnostic symptom is a shortening ability to explain.

Contamination is easier to detect by its symptom than by auditing the wiring. In a healthy arrangement, the answer to why the tier is what it is fits in a sentence — the gate capped it, or the structural read suppressed it, or the composite confirmation blocked promotion — because one identifiable layer bound the outcome. In a contaminated one, the honest answer becomes that everything contributed a little, which is not an explanation and cannot be argued with. So the practical test is to ask the question after each cycle and notice whether it is getting harder to answer. An operator who can no longer name the binding constraint is looking at a system that has stopped being governed and started being computed.

  • Correlated readings each given authority charge one condition several times.
  • Caps compose safely in any order; adjustments compound and are order-sensitive.
  • If you cannot name the binding layer in one sentence, the stack has drifted.

The key idea

The hierarchy exists to make the system explainable, not to make it strict.

It would be possible to build a risk model that weighed a dozen inputs and produced a defensible number, and it would be a worse instrument than this one for a reason unrelated to accuracy. An operator complies with a constraint they can trace and quietly disregards one they cannot, so a deployment figure whose derivation cannot be stated is a figure that will eventually be overridden by feel. Ranking the inputs, resolving by minimums, and keeping the number of layers small are all in service of the same property: at the end of every cycle there is one layer that bound the result, and it can be named.

Connected inside MARS

Every brief documents the same shipped system.

The complete MARS package — eleven workbooks, three TradingView indicators, the full manual library — $497.