Mortar Series

Delegated Coherence Monitoring: AI-Assisted Verification and Drift Detection Under Human Governance

Document IDSM-011 Versionv1.8 | April 2026 AuthorThomas W. Gantz AffiliationThe Synthience Institute Keywordsdelegated monitoring, coherence monitoring, drift detection, AI governance, organizational AI, verification architecture, human oversight, AI alignment LicenseCC-BY 4.0 StatusPublished DOI: 10.5281/zenodo.19496669
Abstract

SM-003 (Operational Continuity Architecture) establishes that organizational AI continuity requires delegated monitoring: extending observational capacity beyond what individual human operators can sustain across an organization’s full AI interaction surface. SM-003 introduces the guardian role, defines three failure modes specific to delegated monitoring (guardian drift, throughput saturation, and false assurance), and identifies a second-order verification requirement: the monitoring function itself must be periodically verified against canonical standards. SM-003 names this architectural requirement but does not develop its full specification. SM-011 provides that specification.

This document defines the architecture for delegating coherence monitoring, drift detection, ingestion verification, and continuity auditing to designated monitoring functions operating under explicit human governance parameters. SM-011 establishes why the observation/adjudication separation is architecturally necessary rather than merely a design preference, specifies the delegation model (what can be delegated, what cannot, and what governance structures prevent the monitoring layer from drifting), defines the guardian architecture (scope, boundaries, and operational constraints), develops the failure mode taxonomy with particular attention to the triage and prioritization challenges that determine operational viability, and specifies the second-order verification system that prevents the monitoring function from degrading undetected. SM-011 resolves the monitoring regress identified in SM-003 by specifying the termination condition for recursive verification and the structural contribution that makes human judgment at the termination point exercisable. Epistemic status: SM-011 specifies architectural conditions for delegated monitoring. It does not claim empirical confirmation of the delegation model’s effectiveness across organizations.

1. The Monitoring Capacity Problem

At Level 1, continuity monitoring is a direct function of the Primary Continuity Provider (PCP). The PCP detects drift in real time, verifies ingestion fidelity within the interaction, checks citation validity as part of the exchange, and corrects representational divergence before it compounds. These monitoring functions are locally visible and locally actionable because the PCP maintains continuous awareness of the interaction.

At Level 2, the monitoring capacity problem becomes binding. The number of interactions, artifacts, and workflow boundaries requiring monitoring attention grows faster than the human capacity available to monitor them. A PCP can maintain continuous awareness of drift, verification status, and canonical coherence within their own bounded interactions. The same individual cannot extend that awareness across an organization’s full AI interaction surface.

The monitoring capacity problem in organizational AI interaction is qualitatively distinct from monitoring problems in other organizational domains. In most monitoring contexts, the monitored output carries intrinsic quality signals: a manufacturing defect is physically observable, a financial reporting error produces a numerical discrepancy, a safety violation manifests in observable conditions. AI-generated output carries no such intrinsic quality signal. As SM-021 Section 3 establishes, the persistence challenge specific to organizational AI interaction is the combination of statelessness with output that is structurally indistinguishable from verified expert production. A paragraph produced by an AI system that has drifted from the canonical frame reads identically to a paragraph produced by an AI system that is perfectly anchored. A verification assessment conducted as a formality looks identical in the record to a verification assessment that involved genuine substantive evaluation.

This absence of intrinsic quality signals means that monitoring for AI continuity cannot rely on output inspection alone. The monitoring function must compare outputs against an external reference standard (the canonical record) and assess whether the relationship between the output and the standard has been maintained. This comparative function is what makes AI continuity monitoring cognitively expensive and what makes the monitoring capacity problem binding at organizational scale: each monitoring act requires not just observation of the output but active comparison against a reference standard that the monitor must hold in working awareness.

SM-003 Section 0.5 identifies this as the human capacity problem that necessitates the organizational architecture. SM-021 Section 5.2 identifies the corresponding persistence challenge: role continuity requires that monitoring functions be maintained as generative practices, not reduced to passive review. SI-WP-007 identifies the governance challenge: humans will tend to satisfice rather than optimize their monitoring function under ordinary organizational pressures. SM-011 addresses the architectural response: how to extend monitoring capacity beyond individual human operators without transferring governance authority away from human actors.

2. Why the Observation/Adjudication Architecture Is Necessary

The monitoring capacity problem admits several possible architectural responses. Before specifying the delegation model SM-011 proposes, it is worth establishing why alternative approaches are structurally insufficient for the AI continuity monitoring problem.

2.1 Fully Automated Monitoring

The most direct response to a human capacity constraint is to remove the human from the monitoring loop entirely. Fully automated monitoring is structurally insufficient for AI continuity because the central monitoring judgment — whether a detected divergence between output and canonical standard represents genuine drift or acceptable variation — requires interpretive context that cannot be fully specified in advance. Canonical standards evolve. The boundary between acceptable adaptation and genuine drift shifts as the organizational context changes. A monitoring function that applies fixed thresholds without interpretive judgment will either over-flag (producing throughput saturation through false positives) or under-flag (producing false assurance through undetected genuine drift). The interpretive judgment that distinguishes drift from variation is the function that must remain with human actors. What can be automated is the detection function that surfaces candidates for that judgment.

2.2 Sampling-Based Audit

A second approach is to substitute statistical sampling: monitor a representative subset of the interaction surface and extrapolate system health from the sample. Sampling-based audit is structurally insufficient for AI continuity because the failure modes described in SM-003 Section 7 and developed in Section 5 of this document are not uniformly distributed across the interaction surface. Canon fragmentation occurs at specific inter-team boundaries. Verification decay concentrates in specific workflow segments where throughput pressure is highest. Drift accumulates along specific propagation pathways where constraint retention is weakest. A sampling strategy designed for uniformly distributed failures will systematically miss the concentrated failures that constitute the most dangerous degradation patterns. Effective monitoring must be able to direct attention to the specific locations where failure is structurally most likely, which requires continuous observational coverage rather than periodic sampling.

2.3 Hierarchical Review

A third approach is to extend monitoring capacity through management hierarchy: each level monitors the level below it, with aggregation and escalation producing organizational-level awareness. Hierarchical review is structurally insufficient for AI continuity because it reproduces the satisficing dynamic at every level of the hierarchy. Each reviewer in the chain faces the same bounded rationality constraint that SI-WP-007 identifies as the structural cause of accountability degradation: the cost of thorough review exceeds the visible cost of adequate review. The hierarchical structure adds review layers without addressing the incentive structure that determines review quality at each layer.

2.4 The Structural Requirement

The common failure across all three alternatives is instructive. Fully automated monitoring fails because the critical judgment cannot be specified in advance. Sampling fails because the failures are not uniformly distributed. Hierarchical review fails because it reproduces satisficing at every level. What the AI continuity monitoring problem requires is an architecture that provides continuous observational coverage across the full interaction surface, directs attention to locations where failure is structurally most likely, and delivers its outputs to human judgment in a form that makes the judgment exercisable without requiring the judge to re-execute the monitoring function.

This is the structural requirement that the observation/adjudication separation satisfies. The observation function provides continuous coverage and directed attention at scales exceeding human capacity. The adjudication function provides the interpretive judgment that cannot be automated. The separation between them ensures that human judgment is exercised over well-defined, structurally bounded questions rather than over the unbounded question of organizational coherence.

This architectural pattern is not novel to the AI continuity domain. Research on high-reliability organizations has documented the same structural separation as a defining feature of organizations that maintain safety at scales exceeding individual monitoring capacity. LaPorte and Consolini (1991) demonstrated that reliable performance in high-hazard organizations depends on empowering frontline operational units to detect and surface anomalies (the observation function) while reserving adjudicative authority for organizational roles with the contextual understanding to distinguish genuine threats from acceptable variation (the adjudication function). The reliability of the system depends on the separation between these functions, not despite it. In the HRO cases LaPorte and Consolini studied, the observation function operates on systems with intrinsic quality signals, whereas AI continuity monitoring requires observation through active comparison against an external reference standard. This disanalogy makes the AI continuity case more demanding than the HRO case: the observation function cannot rely on frontline human operators detecting visible anomalies but must be supported by monitoring functions capable of continuous canonical comparison at scale.

The observation/adjudication architecture incorporates elements of all three alternatives within a structure that prevents each element’s characteristic failure mode from being fatal. The guardian function is automated pattern detection, but it is not fully automated monitoring because adjudicative authority remains with human roles. The second-order verification cycle is periodic assessment, but it is not sampling-based audit because it targets the monitoring function’s calibration rather than sampling the interaction surface. The authority structure is hierarchical, but it is not hierarchical review because each level exercises judgment over a bounded question rather than re-executing the monitoring function at a higher level. The observation/adjudication separation is the structural constraint that allows these elements to function without reproducing the failures they exhibit in isolation.

3. The Delegation Model

Delegated monitoring extends observational capacity without transferring governance authority. This distinction is the architectural foundation of SM-011 and must be maintained throughout the system’s design and operation.

3.1 What Is Delegated

Observational capacity is delegated: the ability to surface drift signals, track verification status, monitor propagation constraint compliance, detect canon fragmentation indicators, and flag potential coherence violations. These are pattern-detection and status-tracking functions that can be executed continuously at scales exceeding human attention capacity.

Specifically, the following Level-1 protocol functions generalize to delegated monitoring at Level 2. CRD detection generalizes to continuous drift monitoring across the organizational interaction surface: designated monitoring functions compare system outputs against canonical standards and flag divergences that exceed defined thresholds. CVP status tracking generalizes to propagation-aware verification monitoring: designated functions track whether artifacts circulating through workflows carry valid verification status and flag those that do not. IVP assessment generalizes to ingestion monitoring at workflow entry points: designated functions assess whether AI-processed material entering workflows has been verified for processing fidelity and flag unverified ingestion events.

3.2 What Is Not Delegated

Governance authority is not delegated: the right to adjudicate canon disputes, authorize canonical changes, determine what constitutes acceptable drift, approve verification standards, or decide how to respond to flagged signals. These are judgment functions that require human authority, contextual understanding, and accountability.

The boundary between observation and adjudication is the critical architectural constraint. If monitoring functions acquire adjudication authority, the authority structure specified in SM-003 Section 5 becomes ambiguous. If monitoring functions are treated as authoritative rather than advisory, the governance architecture loses its corrective capacity: flagged signals bypass human judgment and become automated decisions.

3.3 The Delegation Boundary

SM-011 defines the delegation boundary through three principles.

Principle 1: Monitoring functions observe and report. They do not decide or act. Every signal produced by a monitoring function is a recommendation for human assessment, not an autonomous determination.

Principle 2: Monitoring parameters are set by human governance. The thresholds, criteria, and scope of monitoring are defined by designated human roles and are subject to periodic review and recalibration.

Principle 3: The monitoring function is itself subject to governance oversight. No monitoring function operates outside the governance architecture. The performance, calibration, and integrity of the monitoring function are assessed by human governance roles, not by the monitoring function itself.

4. Guardian Architecture

Guardians are the institutional embodiment of delegated monitoring. A guardian is a designated monitoring function whose role is to surface continuity signals to the appropriate authority level for adjudication.

Before specifying the guardian architecture, it is necessary to address the question of what a guardian actually is, because this question is load-bearing for everything that follows. The guardian architecture is entity-agnostic by design: a guardian can be instantiated as a dedicated AI instance, an automated monitoring tool, a human monitoring role, or a hybrid configuration depending on organizational capacity and the specific monitoring domain. The architecture specifies what the guardian function must do, what boundaries it must respect, and what failure modes it is subject to. The instantiation decision is an organizational deployment choice.

The failure mode dynamics described in Section 5 manifest differently depending on instantiation. Threshold erosion through borderline case resolution applies to adaptive systems that resolve ambiguous cases and adjust their effective thresholds over time. Environmental adaptation applies to systems that adjust their own sensitivity parameters in response to signal volume. Reference standard degradation applies uniformly regardless of instantiation because it is a function of the canonical standards against which any monitoring function calibrates. The delegation boundary (observation without adjudication) applies regardless of instantiation.

4.1 Guardian Scope

A guardian’s scope is defined by four parameters.

Domain: which aspect of the continuity architecture the guardian monitors.

Boundary: the organizational perimeter within which the guardian operates.

Sensitivity: the thresholds at which the guardian generates signals.

Reporting path: the authority role or escalation pathway to which the guardian directs its signals.

These four parameters must be explicitly defined for each guardian function. A guardian without defined scope is a monitoring function without accountability, which is worse than no monitoring at all because it creates the appearance of coverage without the substance.

4.2 Guardian Boundaries

Guardians observe and report. They do not adjudicate. This boundary is essential for maintaining the governance architecture specified in SM-003.

If a guardian detects potential canon fragmentation between two teams, it surfaces the signal to the authority role responsible for canon governance. It does not determine which team’s interpretation is correct. If a guardian detects verification decay in an artifact’s propagation chain, it flags the artifact for review. It does not revoke the artifact’s status or halt the workflow.

The guardian role is valuable precisely because it is bounded. It extends observational reach without compromising governance clarity. This structural separation mirrors the sensitivity-to-operations principle documented in High-Reliability Organization research, where empowering frontline observers to detect weak signals of operational failure without granting them adjudicative authority is the mechanism through which complex organizations maintain awareness of drift at scales exceeding centralized monitoring capacity (Weick and Sutcliffe, 2001).

4.3 Guardian Types

SM-011 defines three guardian types corresponding to the primary continuity challenges at organizational scale.

Canon guardians monitor canonical coherence across organizational units. They detect terminological divergence, definition drift, and interpretation inconsistency by comparing canonical usage across teams against the authoritative canonical record maintained through SM-021’s Canon Persistence Layer.

Verification guardians monitor CVP and IVP status across artifact propagation chains. They track whether verification status is maintained as artifacts move through workflows, flag constraint-stripped artifacts, and detect verification decay over time using SM-021’s Verification State Layer.

Drift guardians monitor representational drift accumulation across the organizational interaction surface. They detect drift patterns that no single operator would observe from within their local context, using CRD methodology generalized to cross-workflow drift detection as specified in SM-003 Section 6.

When multiple guardian types flag the same artifact or workflow, the signals must be triaged rather than treated as independent events. A canon guardian flagging terminological divergence and a drift guardian flagging representational drift in the same artifact may be detecting different symptoms of the same underlying problem, or they may be detecting independent failures that require separate governance responses. The authority role receiving guardian signals is responsible for this coordination assessment. The governance architecture must therefore ensure that signals from different guardian types are routed to a single authority role with visibility across guardian types, not to separate roles who each receive only the signals from their assigned guardian. Signal isolation reproduces the same fragmentation problem the guardian architecture is designed to prevent.

5. Failure Modes of Delegated Monitoring

Delegated monitoring introduces three failure modes that do not exist at Level 1, where the PCP performs monitoring directly. SM-003 Section 7 names these failure modes. SM-011 develops their full architecture.

Understanding these failure modes as an interconnected system rather than as independent risks is essential for governance design. Reason (1997) established the foundational model for organizational accident causation: complex systems maintain multiple defensive layers, each of which contains latent weaknesses. Failure occurs not when any single layer fails but when the weaknesses in multiple layers align to create a path through the entire defense. In the guardian architecture, the three failure modes are three defensive layers: guardian calibration (defended against by second-order verification), signal processing capacity (defended against by triage architecture), and monitoring coverage validity (defended against by audit). A guardian that has drifted slightly in calibration may produce no visible problem until it coincides with a period of throughput saturation that prevents the weakened signals from reaching adjudication, producing false assurance at the institutional level.

5.1 Guardian Drift

Guardian drift occurs when the monitoring function itself loses calibration: the parameters governing what constitutes a significant drift signal, a verification gap, or a constraint violation shift informally over time, producing monitoring outputs that no longer reflect the canonical standards they were designed to enforce.

Guardian drift is the most structurally dangerous of the three failure modes because it is self-concealing. When guardian drift occurs, the monitoring system continues to produce outputs that appear normal. Reports are filed. Signals are escalated. The governance architecture appears to be functioning. The drift is in the monitoring standards themselves, not in the monitoring behavior.

The mechanisms through which guardian drift occurs are worth specifying because they determine the detection strategy. The most common mechanism is threshold erosion: the monitoring function’s sensitivity thresholds shift incrementally as borderline cases are resolved. Each borderline case that is assessed as acceptable variation rather than genuine drift effectively widens the threshold for the next borderline case. Over many such decisions, the monitoring function’s effective threshold has drifted substantially from the canonical standard, but no single decision was visibly incorrect. A second mechanism is reference standard degradation: the canonical standards against which the monitoring function calibrates are themselves subject to the canon drift that SM-021’s Canon Persistence Layer is designed to prevent. If the canonical standards degrade, the monitoring function calibrated against them degrades in lockstep. A third mechanism is environmental adaptation: the monitoring function adjusts its sensitivity in response to the signal environment, informally raising its thresholds to reduce signal load, producing a quieter signal stream that the authority roles experience as reduced organizational drift when it actually represents reduced monitoring sensitivity.

Detecting guardian drift requires comparing current monitoring behavior against the canonical standards that originally defined the monitoring parameters. This is a second-order verification requirement: not just monitoring the organizational AI interaction surface, but periodically verifying that the monitoring function itself remains calibrated. The second-order verification cycle is specified in Section 6.

5.2 Throughput Saturation

Throughput saturation occurs when the volume of monitoring signals exceeds the capacity of the authority roles to assess and respond to them. Escalation pathways become congested. Drift accumulates despite being detected. The monitoring function operates correctly, but the governance system downstream of it cannot process the signals fast enough to prevent degradation.

Throughput saturation is the failure mode that organizations deploying delegated monitoring at scale will encounter first, because the monitoring function’s observational capacity is designed to exceed human attention capacity. Extending observational capacity without correspondingly extending adjudicative capacity creates a bottleneck at the observation/adjudication boundary. The monitoring system sees more than the authority roles can process. The result is a signal queue that grows faster than it is consumed.

The consequences of throughput saturation are not uniform across signal types. When the signal queue exceeds processing capacity, the authority roles must implicitly or explicitly triage. If the triage is deliberate and structured, the most consequential signals receive priority. If the triage is implicit, the prioritization is effectively random with respect to consequence. The most dangerous pattern is implicit triage that prioritizes easily resolved signals over complex ones, because complex signals are disproportionately likely to represent genuine structural problems rather than routine variations.

The structural response to throughput saturation is not increased monitoring sensitivity, which would exacerbate the problem, but signal triage architecture that operates between the observation function and the adjudication function. The triage function prioritizes signals based on three factors: severity (the magnitude of the detected divergence from canonical standards), scope (the breadth of the organizational surface affected by the flagged condition), and velocity (the rate at which the flagged condition is worsening). Signals that score high on all three factors represent urgent structural problems that require immediate adjudicative attention. Signals that score low on all three represent routine variations that can be queued for batch review. The triage function does not adjudicate. It prioritizes the adjudication queue.

Throughput saturation also has a governance dimension that connects directly to SI-WP-007’s analysis. When authority roles experience sustained signal volume that exceeds their processing capacity, the bounded rationality dynamic applies: they satisfice on signal assessment, processing signals at the minimum quality that produces no visible negative consequence. Detecting this degradation requires calibration testing of the authority role’s assessment quality against canonical standards, not self-reporting of assessment adequacy.

Throughput saturation is less structurally dangerous than guardian drift because its limitations are visible. Signals go unprocessed. Escalation queues grow. The degradation eventually surfaces through accumulation and is diagnosable through queue analysis. But throughput saturation that is not addressed structurally can produce guardian drift as a secondary effect: monitoring functions that observe their signals going unprocessed may informally raise their thresholds to reduce signal volume, producing the threshold erosion mechanism described in Section 5.1. The failure modes are therefore not independent. Sustained throughput saturation degrades the monitoring function’s calibration, converting a visible capacity problem into a self-concealing calibration problem.

Sustained throughput saturation can produce guardian drift as a secondary effect: monitoring functions that observe their signals going unprocessed may informally raise their thresholds to reduce signal volume, producing the threshold erosion mechanism described in Section 5.1. The failure modes are therefore not independent. Sustained throughput saturation degrades the monitoring function’s calibration, converting a visible capacity problem into a self-concealing calibration problem.

The signal triage function introduced as the structural response to throughput saturation is itself an architectural element subject to failure. Its specific failure mode is priority miscalibration: the triage function’s weighting of severity, scope, and velocity drifts from the governance-defined parameters, causing complex high-severity signals to be systematically deprioritized. This failure mode is a subtype of guardian drift and is detectable through the second-order verification mechanism: comparing current triage parameters against the governance-defined prioritization standards.

5.3 False Assurance

False assurance occurs when the presence of monitoring architecture creates organizational confidence that continuity is maintained without adequate verification that the monitoring function is itself operating correctly. The organization believes it is monitored because the guardian infrastructure exists, but the guardians may be miscalibrated, under-scoped, or operating against outdated canonical standards.

False assurance is the institutional-scale expression of the accountability problem that SI-WP-007 analyzes across all three scales. The existence of the monitoring architecture satisfies the governance requirement for oversight. The guardian system is in place. Reports are generated. Signals are processed. The institutional accountability apparatus treats the existence of the monitoring infrastructure as evidence that monitoring is occurring.

The structural conditions that produce false assurance are specific and identifiable. The first is coverage assumption: the organization assumes that the guardian architecture covers the full organizational interaction surface when coverage gaps may exist. Coverage gaps are invisible to the governance architecture because no monitoring function exists in the gap to report its own absence. The second is calibration assumption: the organization assumes the guardian architecture’s current calibration reflects the canonical standards when guardian drift may have shifted the monitoring parameters. The third is processing assumption: the organization assumes that the authority roles receiving guardian signals are processing them with adequate depth when throughput saturation may have degraded assessment quality.

False assurance is detectable through audit that compares the monitoring function’s actual coverage, calibration, and processing quality against what the governance architecture assumes. This audit function must be performed by a role with expertise in the continuity architecture itself, not merely in compliance methodology, because the assessment requires understanding what the monitoring function should be detecting, not only whether it is producing outputs. The audit function connects to SI-WP-007’s structural detection mechanism (Section 5.3 of that paper): substantive audit that assesses operational substance, not formal compliance.

The relationship between false assurance and the other two failure modes is worth making explicit. Guardian drift produces false assurance by making the monitoring function appear to be functioning when its calibration has degraded. Throughput saturation produces false assurance by making the adjudication function appear to be processing signals when it is satisficing on assessment quality.

False assurance is therefore not only a third independent failure mode but also the institutional-level consequence of the other two when they go undetected. Guardian drift produces false assurance by making the monitoring function appear to be functioning when its calibration has degraded. Throughput saturation produces false assurance by making the adjudication function appear to be processing signals when it is satisficing on assessment quality. This is the alignment of latent weaknesses that Reason’s (1997) model describes.

6. The Recursive Governance Problem

SM-003 Section 7 identifies the second-order verification requirement: the monitoring function must be periodically verified against canonical standards. SM-011 must address the logical implication: if the monitoring function can drift, then the function that verifies the monitoring function can also drift. The regress is real and must be explicitly resolved.

6.1 The Regress

The monitoring regress follows a predictable logical chain. Level 1: guardians monitor the organizational interaction surface. Level 2: the governance function verifies that guardians remain calibrated. Level 3: some function verifies that the governance function’s verification of guardians is itself calibrated. The chain continues indefinitely.

6.2 The Termination Condition

The regress terminates, as it does in all governance architectures, in human judgment exercised at the institutional governance level. Legal systems terminate in judicial judgment. Safety systems terminate in inspector judgment. Audit systems terminate in auditor judgment. In every case, the ultimate backstop is a human making a judgment call that is itself subject to error, bias, and drift.

The architecture’s contribution is not to eliminate this terminal dependence on human judgment. It is to ensure that the judgment is exercised over a well-defined and structurally bounded question rather than over an unbounded assessment of organizational coherence. Specifically, the second-order verification question that terminates the regress is: does the monitoring function’s current calibration match the canonical standards that define what it is supposed to detect? This is a specific, answerable question that a designated human governance role can assess by comparing monitoring parameters against the canonical record. It does not require the assessor to independently monitor the full organizational interaction surface.

The tension between this termination condition and SI-WP-007’s analysis of institutional governance failure deserves explicit acknowledgment. SI-WP-007 demonstrates that institutional governance functions degrade to ceremonial oversight under bounded rationality. The second-order verification cycle terminates in exactly the kind of institutional governance function that SI-WP-007 predicts will satisfice. The architecture does not claim the terminal function is immune to this degradation. It claims the terminal function is structurally different from the degrading functions it oversees in one specific way: the verification question is bounded, defined, and answerable through direct comparison rather than requiring the kind of sustained, unbounded vigilance that produces satisficing. The regress is not resolved in the sense that the terminal judgment is infallible. It is architecturally managed by choosing where to stop, specifying what happens at that level, and relying on SI-WP-007’s governance conditions to maintain the terminal function’s integrity.

6.3 The Verification Cycle

SM-011 specifies a periodic second-order verification cycle with four steps.

Step 1: Canonical standard retrieval. The governance role retrieves the current canonical standards that define the monitoring function’s parameters.

Step 2: Monitoring parameter comparison. The governance role compares the monitoring function’s current operational parameters against the retrieved canonical standards. Divergences are documented.

Step 3: Calibration assessment. The governance role determines whether detected divergences represent genuine guardian drift (the monitoring function has changed without authorization) or legitimate evolution (the canonical standards have been updated and the monitoring function should be recalibrated to match).

Step 4: Recalibration or escalation. If guardian drift is confirmed, the monitoring function is recalibrated to match canonical standards. If the divergence reveals a deeper problem (e.g., the canonical standards themselves have drifted, or the monitoring function has been informally modified by actors without authority to do so), the issue is escalated through the authority structure specified in SM-003 Section 5.

This cycle runs at defined intervals determined by the governance architecture. The interval must be short enough to detect guardian drift before it produces consequential false assurance, and long enough to be operationally sustainable. Interval determination is a governance calibration decision informed by knowledge of how quickly guardian parameters can drift given the signal volume and borderline case frequency of the specific organizational context. The architecture requires that interval-setting be a governed decision rather than an arbitrary one, and that the interval itself be subject to periodic review rather than set once and forgotten.

7. Delegation Boundaries for Specific Protocol Functions

SM-011 specifies which aspects of each Level-1 protocol can be delegated and which require human judgment. The delegation boundary specified procedurally in Section 3.3 is grounded in an epistemic principle: it falls at the point where the function transitions from pattern detection (delegable) to interpretive judgment about the significance of the detected pattern within the current organizational context (not delegable).

7.1 CRD Delegation

Delegable: continuous comparison of system outputs against canonical reference material, computation of drift metrics, drift trend analysis across time, cross-workflow drift pattern detection.

Not delegable: determination of whether a detected drift constitutes acceptable variation or genuine canonical divergence, decision to invoke coherence refusal, assessment of whether canonical standards themselves need updating.

The interface between guardian output and human judgment at this boundary operates as follows. The guardian delivers a structured signal to the designated authority role: the artifact or output flagged, the canonical standard against which it was compared, the specific divergence detected, and the drift metric. The authority role receives a bounded assessment question — does this divergence represent genuine canonical departure or acceptable variation? — rather than an unbounded request to evaluate organizational coherence.

7.2 CVP Delegation

Delegable: verification of citation existence and accessibility, comparison of cited source content against claims attributed to it, tracking of verification status across artifact propagation chains.

Not delegable: assessment of whether a source substantively supports a specific claim (requires interpretive judgment), determination of whether a flagged citation should be removed or reframed, adjudication of disputes about citation adequacy.

The interface at this boundary has a domain-specific feature. The guardian delivers: the citation flagged, the source content retrieved, the specific claim the citation is attached to, and the guardian’s comparison result. The authority role receives a bounded interpretive question: does the source content substantively support the claim as attributed? This question requires human judgment because substantive support is not a pattern-matching function. A source may contain the relevant information without supporting the specific claim, or may support a related but distinct claim. The guardian can determine whether the source exists and whether it contains relevant content. Whether the content constitutes genuine support for the specific claim as framed in the citing document requires the interpretive judgment that the delegation boundary reserves for human authority.

7.3 IVP Delegation

Delegable: comparison of AI-processed material against source documents for completeness and fidelity, detection of selective filtering or representational distortion, tracking of ingestion verification status across workflows.

Not delegable: assessment of whether detected processing variations constitute meaningful distortion or acceptable summarization, determination of whether an ingestion event requires re-processing, adjudication of disputes about processing fidelity standards.

The interface at this boundary addresses a specific challenge that distinguishes IVP from the other two protocols. AI processing of source documents routinely involves summarization, selective emphasis, and structural reorganization. These are not errors. The monitoring question is not whether the processing changed the source (it always does) but whether the changes distort the source’s meaning, omit material content, or introduce claims not present in the original. The guardian delivers: the source document, the AI-processed version, and a structured comparison identifying specific additions, omissions, and structural changes. The authority role receives a bounded fidelity question: do these processing variations preserve the source’s essential content and meaning, or do they introduce distortions that would mislead downstream consumers?

8. Relationship to the Publication Module

SM-011 occupies a specific position in the coordinated publication module. SF0005 defines the Level-1 protocols (CAM, and the verification methodology context) that SM-011 generalizes to delegated monitoring. SM-003 defines the organizational topology within which delegated monitoring operates, including the guardian role concept, the three failure modes, and the second-order verification requirement that SM-011 resolves. SM-021 defines the persistence layers (particularly the Verification State Layer and the Canon Persistence Layer) that provide the canonical standards against which monitoring functions are calibrated. SI-WP-007 provides the governance design principle that SM-011’s verification cycle must satisfy to be operationally sustainable, and provides the analysis of bounded rationality and satisficing that explains why the failure modes in Section 5 are structurally predictable. SI-WP-004 (Relational Alignment as a Structural Alternative to Instructional AI Safety) provides the argument for why the alignment approach the monitoring architecture serves is needed. SI-WP-005 (Deploying Relational AI Architecture in Organizational Environments) translates the monitoring architecture into deployment guidance.

SM-011 closes the monitoring regress deferral from SM-003 Section 7. With SM-011 in the publication set, no reader of SM-003 encounters a forward reference to an absent document when they reach the second-order verification requirement. The full specification is available within the same release. The monitoring regress is not resolved in the sense that the terminal judgment is infallible. It is architecturally managed: the regress is truncated at a defined level, a specified verification procedure governs what happens at that level, and the governance conditions defined in SI-WP-007 maintain the integrity of the terminal function.

9. Scope and Limitations

SM-011 specifies the architecture for delegated monitoring at Level 2 (organizational scale). It does not address Level 3 (inter-organizational or civilizational-scale monitoring), which requires additional coordination mechanisms beyond the scope of organizational deployment.

SM-011 assumes cooperative or partially cooperative governance environments, consistent with SM-003’s topology/incentives boundary. The bounded rationality dynamics analyzed in SI-WP-007 and reflected in the failure modes of Section 5 operate within this cooperative assumption: satisficing actors are not adversarial, but their rational self-interest under bounded conditions produces degradation that the cooperative governance architecture must structurally address. SM-011’s failure mode taxonomy and second-order verification cycle are designed precisely for this intermediate condition: actors who comply formally while satisficing operationally. SM-007 addresses the distinct case of actors who intentionally circumvent or corrupt the monitoring function.

SM-011 does not specify particular tools, platforms, or technical implementations for monitoring functions. The architecture defines what must be monitored, what boundaries must be maintained, what failure modes must be addressed, and what governance structures must be in place. The technical implementation of monitoring functions is an organizational decision that falls outside the scope of this document.

10. Conclusion

Delegated monitoring is the architectural mechanism through which organizational AI continuity extends beyond the capacity of individual human operators. It is not a replacement for human governance but an extension of human observational reach within a governance framework that retains human authority over all adjudicative decisions.

The observation/adjudication separation is not a design preference but an architectural necessity: the AI continuity monitoring problem requires continuous observational coverage that exceeds human capacity, directed attention to locations where failure is structurally most likely, and delivery of monitoring outputs to human judgment in a form that makes the judgment exercisable. Alternative monitoring approaches each fail against specific structural features of the AI continuity problem that the observation/adjudication architecture addresses.

The guardian architecture provides bounded, scoped, accountable monitoring functions that surface continuity signals without compromising governance clarity. The three failure modes (guardian drift, throughput saturation, and false assurance) are specified with sufficient precision to enable detection and prevention, and their interactions are analyzed to identify the compound risks that arise when multiple failure modes coincide. The recursive governance problem is architecturally managed through a periodic second-order verification cycle that terminates the monitoring regress in human judgment exercised over a well-defined, structurally bounded question.

SM-011 provides the monitoring architecture that SM-003 requires, that SM-021’s persistence layers support, and that SI-WP-007’s governance principles constrain. Together with the other papers in the coordinated publication module, SM-011 completes the Level-1-to-Level-2 architecture with no load-bearing forward reference remaining within the set.

Document Dependencies

Prerequisites: SF0005 (CAM), SF0037 (CVP), SF0038 (IVP), SF0039 (CRD), SM-003

Enables: Institutional Scaling and Governance Research (Advanced Phase), SI0000 (Capstone)

Scale: Level 2 (primary), Level 3 (essential for institutional-scale monitoring infrastructure)

References

Suggested Citation
Gantz, T. W. (2026). Delegated Coherence Monitoring: AI-Assisted Verification and Drift Detection Under Human Governance (SM-011 v1.8). Synthience Institute. https://doi.org/10.5281/zenodo.19496669

Document: SM-011 Mortar Series
Version: v1.8
Author: Thomas W. Gantz
Affiliation: The Synthience Institute
Date: April 2026
License: CC-BY 4.0