Skip to content
← Back to System Architecture

Operator brief · 48

Diagnose, permit, deploy — three authorities that never merge.

The key idea

The three roles

Structural truth, governance overlay, deployment interpretation.

The division is clean and was stated explicitly during the build sessions. The Structural Diagnostic Engine diagnoses structural condition — it reports what the system's deeper metrics say, and reporting is the whole of its job. The calculated diagnostics generate overlays and vetoes — converting structural readings into graded permission: supportive, caution, suppression, hard veto. The Throttle Control Panel converts those vetoes into deployment behavior — turning permission into a tier, a pool percent, and a per-trade risk. Diagnose, permit, deploy. Each module owns exactly one verb.

The critical prohibition

The deployment interpreter must never become the source of structural truth.

This is the doctrine's sharpest edge, and it was chosen deliberately over the more convenient alternative. The Throttle Panel could compute its own structural view — it has the inputs — and if it did, the module with the strongest incentive to deploy would also be the module deciding whether deployment is justified. Every governance system that has ever failed has failed at exactly that merge. Keeping the panel as an interpreter means it can only ever answer 'given these structural verdicts, what deployment do they authorize?' — and when the verdicts are suppressive, it has no mechanism for arguing with them. Its lack of authority over structural truth is the source of its trustworthiness about deployment.

FigureThree authorities, one direction of flow
verdicts flow down, never upSDEdiagnose structural condition — report onlyCalculated diagnosticsgenerate overlays: support, caution, suppress, vetoThrottle panelconvert vetoes into deployment behaviorCycle deploymentthe only layer that touches capital

Each layer consumes the previous layer's verdict and cannot revise it. The deployment layer is the only one that touches capital — and the only one with no say in whether deployment is justified.

Graded, not binary

The permission layer speaks in degrees, which is what makes separation survivable.

Separation would be brittle if permission were a switch — a single veto flag would either halt the system or be routinely ignored. Instead the overlay layer is graded: confirmation, caution with aggressive promotion avoided, suppression restricting deployment posture, hard veto blocking expansion, and multiple hard vetoes triggering survival-first operation. Because permission arrives in degrees, the deployment layer always has a legitimate action available, and never faces the choice between obeying an absolute stop and overriding it. Graded suppression plus layered governance is what lets strict separation coexist with continuous operation.

  • Caution and suppression restrict posture without halting the system — the ordinary states, not exceptions.
  • A hard veto blocks expansion specifically, which is a narrower and more enforceable claim than 'stop trading.'
  • Multiple hard vetoes escalate to survival-first — the graded ladder's own terminal state.

The audit consequence

Separation is what makes the final decision explainable.

Because each layer's contribution is distinct, the resolved tier can be traced backward through its sources: the gate was Growth so capital authority was open, daily EV was green so the tactical condition was healthy, the weekly structural read was constructive, Category 6 gave conditional confirmation, calculated diagnostics applied normal cap logic — therefore T4 Mid. The engine's own governance table exists to publish exactly that chain. A merged architecture couldn't produce it: when one module both diagnoses and deploys, the output has no decomposition, and the operator is left either trusting a black box or overriding it emotionally when it feels wrong. Traceability is not a reporting feature here. It is what separation buys.

The key idea

Authority you can't concentrate is authority that can't be captured.

Splitting diagnosis, permission, and deployment across modules that structurally cannot perform each other's roles means no single point in the system can quietly optimize for deployment. The structural layer has no capital ambitions; the permission layer has no execution surface; the deployment layer has no epistemic authority. What survives that arrangement is a decision no individual component could have manufactured on its own — which, when capital is on the line and the operator is tired, is precisely the property worth engineering for.

Connected inside MARS

Every brief documents the same shipped system.

The complete MARS package — eleven workbooks, three TradingView indicators, the full manual library — $497.