The Enforcement Ladder: Six Levels, A Measured Assurance, And A Catch Above The Hook Is An Incident
Summary
One policy, the number and size of files committed, walked up every place it could be enforced: nothing; a line in a prompt; a skill or a system prompt; a git hook in the agent's own clone; a check at the destination; and out-of-band verification after the fact. The reading places the six levels on the corpus's three tiers and finds a fourth the tier test had not named: detection. The memo's sharpest claims: assurance per level is measured on ordinary usage rather than asserted; the first four levels are client side, limited and a great signal in the same breath, because a breach seen at the destination means something is seriously wrong, a different policy, a different buffer, and possibly the loss of the licence to operate. Then the practical half: start with a published skill, a script and examples; look for a standard; find a name; and tie it to the grant and the mandate with a default-deny list. Built the same day: a revised policy naming the levels, a level on every ledger event, a reconciliation job that replays git against the ledger, a destination check in report mode, and a room card.
Key concepts
- Doctrine 13 — the reading, as doctrine
- The three-tier control test — what the six levels refine
- Decision points — the levels mapped to hooks, CI and the reconciliation job
- The room — catches by level, the sixth card
- Change control — GM-D104 to GM-D108
Key ideas
- The levels of enforcement are the tier test refined, and level five is a tier the test had not named: it does not prevent, it finds out.
- A skill outranks a prompt not because either enforces anything, but because compliance with it is more reliable, and that is a number.
- Assurance per level is measured from the ledger's catch rate on ordinary work, never asserted.
- A catch above the hook is an incident, not a volume event: no draw, a different policy, escalation, a candidate for suspension.
- A commit that carries no claim is the detection. Reconciliation against git turns a setting into a detector.
- Start with a skill, then a hook, then a destination check, then reconciliation; each step needs nothing above it.
- The object stays policy; the ladder is the levels of enforcement; the product name is the project lead's.
On this site
Adds insurance doctrine 13 and, in packs/insurance-ecosystem: policy revision r2 with the levels and files_per_commit, a level on every event, tools/reconcile.py, a policy-report CI workflow in report mode, the room's sixth card, and amendments to documents 01 to 08 with IE-D17 onward.