Part VI, Integrity, Safeguards & Self-Review
Derived from Axioms 4 (every power checked, including the checkers), 5 (transparency), 7 (verifiability), 10 (self-correction), 11 (anti-capture). This is the system's immune system. It improves on model5 in two decisive ways: it answers "who guards the guardians", and it adds the missing outcome-measurement feedback loop that tells the people whether governance is actually working.
VI.1 The Integrity & Safeguard system, deliberately not one body
The integrity of the whole system is guaranteed not by a single all-seeing Integrity Assembly but by a small family of independent bodies, each barred from holding the combination of powers that would let one institution steer the country. The genuinely dangerous concentration is precise (§VI.10): one body holding the record, the measure, the audit, and the message. The message is removed entirely (Public Information sits outside, below); the remaining three epistemic-infrastructure powers — record, measure, audit — must never combine, so they are separated. Investigation and enforcement hold none of those three, so they are consolidated into one office (splitting them only created seams). The result is three bodies plus a shared custody function, not six — the minimum split that separates the real danger (Axiom 14; the §IX.1 marginal test):
| Body | Sole job | The one power it holds |
|---|---|---|
| Office for Statistics & Outcomes | Measure the wellbeing composite; score outcomes (§VI.7) | Measurement + publication; cannot choose which indicators exist (entrenched, §VI.7) |
| Algorithm & Data Audit Office | Audit every governing algorithm, incl. the Router (§VI.4) | Audit + referral; no custody of the record it audits |
| Integrity Enforcement Office | Anti-corruption & procurement forensics (§VI.5), rights/doctrine-compliance monitoring, and whistleblower protection (§VI.9), under internal walls | Investigate + refer + shield; cannot punish, and cannot unilaterally freeze — it requests a Pause, never holds one |
- *The transparency ledger is a multi-custody function, not a body (§VI.6, §VIII.4): its keys are split m-of-n* across the three bodies plus external civil-society notaries, so no single body can alter the record — stronger than a standalone custody office (itself a single point of custody) and one fewer appointment/funding/oversight surface.
- The Public Information function (§II.5) is deliberately outside this family: an auditor of the state's honesty must never also be the voice of the state's messaging (§II.5, §IX.7).
- Joining the dots is owned. The highest-value corruption is visible only across custody × measurement × audit; since no body may hold another's power, the citizen oversight juries (§VI.3) — which already have their own investigators and a statutory right to pull any record — carry the standing duty to correlate across all three bodies' outputs (read-only), closing the cross-body seam without re-concentrating a power.
- Coordination is not left to accrete into an informal seventh body. Jurisdiction disputes between the bodies go to the Court (never an inter-body chair); a standing joint secretariat is prohibited; shared technical standards (the ledger schema, the recompute toolchain) are set by the entrenched §VIII.8 process, not by any one body.
Collectively these bodies expose and refer; they never govern or punish unilaterally. Where later Parts say "the Integrity Assembly" as shorthand, it means the relevant body in this family, never a single all-powerful one.
The Pause, in two tiers, held by the Court. To stop harm without becoming a standing veto — and without being too slow to catch fast harm:
- Emergency interim freeze — immediately effective, triggerable by a single judge or a single named senior officer of the Integrity Enforcement Office, for a very short fixed period, auto-referred to the Court for affirmation within hours; uncapped in number because it is self-limiting and instantly reviewed. This is the fast lock against irreversible harm (a data purge, an irreversible deploy, a spend commitment) that a purely time-boxed Pause would miss over a recess.
- Policy Pause — for contested-but-not-urgent decisions: time-boxed (auto-expires unless the Court affirms), capped per-decision (so serial re-Pausing of one decision is blocked while distinct new harms stay actionable), appealable on proportionality, with a published justification.
Neither is held unilaterally by an investigatory body: the Enforcement Office requests; the Court affirms.
VI.2 Independence, structural, not promised
The Integrity Assembly must be independent of every body it watches, or it is theatre:
- Separate appointment (not by the executive or experts it oversees), multi-stage, like §IV.4, with a strong sortition component.
- Secured, constitutionally guaranteed funding that cannot be cut by those it investigates, defunding is the classic way to neuter a watchdog.
- Cannot be disbanded or restructured except by the §I.9 amendment process, it is Charter-level, not at the mercy of ordinary politics.
- Operational transparency: it works in the open by default (its own investigations excepted only while live and only on published criteria).
VI.2a Guarding against guardian convergence (enacted, not merely asserted)
The bodies above and the other guardians (Court, expert boards, the Router's governance) could drift into a shared professional-class consensus so that "independent" checks stop checking each other. This is defended by operative rules here, not only named in the threat model (§XVI Scenario J):
- Cross-body diversity: viewpoint, disciplinary, and background diversity is required across the guardian bodies, not only within each (extends §IV.3).
- Inter-guardian recirculation limits: time-bounded cooling-off and recusal between guardian roles, with an absolute bar only on the single most sensitive adjacency (serving in a body you recently audited, or that audited you). Lifetime bans are avoided — they would sterilise the small pool of proven integrity talent and leave seats empty, and a capture control that makes staffing infeasible is self-defeating.
- No shared secretariats or briefers among bodies meant to check each other.
- A dissent-integrity audit, not a raw-agreement audit: the red flag is not "they agreed" (a clean, well-run state should produce concordant clean findings) but "a recorded disagreement was buried." Every body carries a protected internal-dissent channel, and the audit flags suppressed dissent and anomalous shifts against a modelled baseline — never legitimate consensus.
VI.3 Who guards the guardians, closing the loop
model5 shows an Integrity Assembly watching everyone, but nothing watching it. Axiom 4 forbids any unchecked power, so the Integrity Assembly is itself checked, by four independent means at once:
- Citizen oversight juries (sortition). Standing panels of citizens, chosen by lot, with real powers over the Integrity Assembly: access to its records, the ability to investigate it, to commission independent audits of it, and to refer its members for removal. Ordinary citizens, immune to insider capture, are the ultimate watchers, and they rotate, so they cannot themselves be captured.
- The Rights & Constitutional Court (Part IX), legality of the Integrity Assembly's own actions.
- Radical self-transparency, the watchdog's own operations, budgets, and decisions are on the public ledger.
- The people, via the amendment power and the elected Assembly's confirmation/removal role.
This is the recursive answer Axiom 4 demands: every box has a check, including the boxes that do the checking, and the chain terminates in the rotating judgement of ordinary citizens.
The juries' independence is itself protected (closing the circularity). A jury that could see only what the body it oversees chooses to show it would be captured by that body — the regress would loop, not bottom out. So the oversight juries have their own independent secretariat and investigators, not employed by or seconded from any body they oversee; a statutory right to pull any record directly rather than receive curated packs; and a route to the Court for any dispute with the body under review. Their members are drawn by the verifiable lot of §VI.3a, so the family cannot quietly select its own overseers. "Unbribable" is not asserted of citizens as a magic property (a small panel can be pressured or suborned): it is engineered — panels are large enough to resist decisive small-group bribery, serve under monitored and protected conditions, are subject to post-hoc financial audit, and can add candidates and questions rather than only ratifying what they are shown (§IV.4).
VI.3a Verifiable sortition, the lot is a defended primitive, not a trusted one
Selection by lot is load-bearing across the model: it seats citizens on the appointments panels (§IV.4), the Citizens' Sortition Chamber (§IX.2), the oversight juries (§VI.3), and the constitutional-convention procedure (§I.9.4a). If the draw could be biased, all of these are captured at once — a common-mode failure that would collapse checks the model presents as independent. So the lot is specified as a verifiable public process, held to the same standard as the vote count (Axiom 7):
- Publicly verifiable randomness. Each draw uses a published, tamper-evident public-randomness beacon (a drand-style distributed beacon whose entropy no single party controls), so the seed cannot be quietly chosen.
- Reproducible and auditable. The eligible roll (reconciled and published in aggregate, §VIII.2), the selection algorithm (open-source, §VIII.8), and the beacon output together let any citizen re-run the draw and confirm the panel was fairly selected.
- Stratification set adversarially. The demographic strata and their weights are set by an entrenched, adversarial, published process — not by the body being seated — so composition cannot be tilted by choosing the strata.
- Independent draws for independent bodies. The distinct sortition bodies use independently administered draws (different custodians, staggered), so one selection mechanism is never a single point of failure across checks meant to be independent (§XVI.5).
VI.4 Algorithm and data oversight
Given the technological layer (Part VIII), opaque algorithms are a new route to unaccountable power. Therefore:
- *No unaccountable algorithms in government. The default is full public registration and open audit of every algorithm or AI used in a governing function — registered, auditable, explainable, bias-tested before and during use. The rule is not that no model is ever confidential (some security and intelligence models must be, §VIII.5, §XII.4) but that none is unaccountable: a narrowly-defined, security-justified exception still receives closed audit by cleared independent reviewers plus jury-cleared members, never zero* audit. Secrecy from all scrutiny is never permitted. This states, in identical terms, the same rule as §VIII.5, so the two cannot be read against each other.
- Data governance: what data the state holds, why, for how long, and under what rights constraints (§I.3 privacy) is public and audited.
- Independent testing: the Integrity Assembly (and citizen juries) can audit any government algorithm, including its training data and its real-world impact, at any time.
VI.5 Procurement forensics and anti-corruption
Corruption is a primary capture vector (Criterion 5), and procurement is where public money meets private interest:
- Real-time spend transparency: public money is recorded to the transparency ledger as it is committed, who, what, how much, why.
- Automated anomaly detection: continuous forensic analysis flags irregular patterns (bid-rigging signatures, conflict-linked awards, price anomalies) for investigation.
- Asset & interest declarations for all office-holders, public and audited (links §IV.7).
- Revolving-door enforcement (§IV.7).
- Beneficial-ownership transparency for entities contracting with the state, no hiding behind shells.
VI.5a Lobbying transparency
Revolving-door and conflict rules (§IV.7) close the back door; the front door — access — is closed too:
- A statutory register of lobbyists, and published meeting and diary logs for decision-makers (who met whom, when, and about what), integrated with the transparency ledger (§VI.6).
- An ACOBA-equivalent regime across the whole expert and executive layer for post-office roles.
- Influence is thereby visible whether it is exercised through money, jobs, or access — the vector the model would otherwise leave open while closing the others.
VI.6 The transparency ledger
The shared spine of verifiability (Axiom 7): an immutable, tamper-evident, public record of decisions, public money, anonymised votes/results, reasoning artefacts, appointments, and declarations. Properties:
- Append-only and tamper-evident, entries cannot be silently altered or deleted; any tampering is detectable.
- Publicly auditable, any citizen, journalist, or researcher can inspect and verify it (privacy-preserving where personal data is involved, §II.1).
- The default home of state reasoning, §V.3 decision artefacts live here.
Technical design (consensus, custody, privacy, integrity) is specified in Part VIII; here it is mandated as a constitutional requirement.
VI.6a Freedom of information and official statistics
The transparency ledger is proactive publication, controlled by the publisher; the reactive right to ask is what catches what power wants hidden:
- A freedom-of-information right: any person may request information the state did not choose to publish, with defined, narrow exemptions, adjudicated by an independent information authority empowered to order disclosure, and an appeal tribunal — the reactive complement to the ledger, and a citizen route into the §XII.4 / §VII.3 secrecy carve-outs (a withholding can be compelled to review).
- Official-statistics independence: an ONS-equivalent producing the national statistics free of political interference, whose integrity is itself one of the backsliding indicators (§VI.7).
VI.7 Outcomes measurement, the missing feedback loop
model5's largest omission: it shows decisions being made but never shows the country finding out whether they worked. This model adds a public outcomes ledger:
- The wellbeing composite (§0.2) is measured and published continuously, by dimension.
- Decisions are tracked against their own predictions (§V.3 falsification tests), every major decision's predicted outcome is recorded in advance and scored against reality.
- The system's own performance is scored against the §0.4 rubric on a live basis (feeds Part XVII).
- The data is open so citizens, academics, and the press can hold the measurement itself to account.
- Backsliding indicators, with automatic tripwires. Tracked openly alongside the wellbeing data: the share of legislation receiving full committee and deliberative scrutiny (§IX.2), measures of judicial independence and media plurality, the rate of §V.4 escalation-abuse (§V.4.4), the Router's escalation rate (§XIX.3), and the rubric score itself, modelled on the V-Dem indicators used to track democratic decline internationally. The slow, lawful erosion that kills democracies (§XVI.4-E) then shows as a moving number before it becomes irreversible. Crucially, a defined subset of these indicators carry hard thresholds that auto-trigger a mandatory, non-discretionary consequence — a Court reference, convocation of a citizen oversight jury, and a scheduled confirmatory referendum — independent of press or political attention, because relying on "press attention" (the original design's implicit trigger) fails exactly when a backslider has captured the press first. The indicators are computed and published by multiple independent custodians from external, pre-committed, publicly-recomputable data, not solely by the body being measured, so a captured measurer can be immediately contradicted. A smoke detector must not be wired to the arsonist.
This closes the loop in the architecture diagram: outcomes flow back to the people as accountability and renewed (or withdrawn) consent. It is what makes "best long-run outcomes for citizens" a measurable commitment rather than a slogan.
Guarding the measurement (Goodhart's law) — and guarding the measurer
"When a measure becomes a target, it ceases to be a good measure." And whoever controls the measure controls the definition of success, so the measurer is guarded as tightly as the measure:
- A basket, not a number — many indicators across dimensions, so no single metric can be gamed to fake success.
- The measurer does not own the basket. Which indicators and weights exist is a value question (§V.4) — it defines what "doing well" means — so it is set by the people / Sortition Chamber and entrenched, changeable only through the §V.4 value route, never by the Office for Statistics that computes it. The measuring body reports the numbers; it cannot choose which numbers count. This closes the subtle capture in which a body quietly redefines the metric to flatter its patron.
- External, recomputable data. The composite is bound to external, pre-committed sources (international indices, raw administrative series published in full) so the score is independently recomputable by any third party without the measurer's discretion; the recompute toolchain is open (§VIII.8).
- Retroactive re-scoring. Any change to indicators or weights is applied retroactively to the historical series and published under both old and new definitions, so a decline cannot be hidden behind a redefinition.
- Independent measurement + outcome-vs-prediction — the Office for Statistics (watched by citizen juries) measures; the governed do not grade their own homework; gaming shows up as predictions that "succeed" on paper while the wider basket and lived reality diverge.
VI.8 Institutionalised self-correction
Self-correction (Axiom 10) is made structural, not aspirational:
- Mandatory post-implementation reviews on a published schedule (§V.7).
- An open error register, recorded mistakes, openly, feeding learning.
- Sunset clauses on major policies, they expire and must be re-justified against measured outcomes, rather than persisting by inertia.
- Continuous rubric scoring (§VI.7) so decline is detected early.
VI.9 Whistleblowing and enforcement
Integrity needs eyes inside and teeth outside:
- Protected, anonymous channels to the Integrity Assembly, constitutionally shielded from retaliation.
- Real consequences: referral to the Court, removal for cause, recovery of funds.
- Retaliation is itself an offence, investigated independently.
VI.10 Failure modes and safeguards
| Failure mode | How it attacks | Safeguard |
|---|---|---|
| Capture of the integrity body | Watchdog is bought or packed | Independent appointment + guaranteed funding + Charter-level protection (§VI.2); split into single-power bodies (§VI.1); citizen-jury oversight (§VI.3) |
| Epistemic concentration | One honest body controls the record, the measure, the audit, and the message, and steers the country | Split into a family of single-power bodies; Public Information function moved out; no body holds more than one power (§VI.1) |
| Watchers collude with watched | Cosy regulatory capture | Rotating sortition juries with real powers, their own independent secretariat and record-pull right (§VI.3); verifiable lot (§VI.3a) |
| Sortition draw biased | Rig the lot to seat friendly citizens across every check at once | Publicly verifiable randomness beacon; reproducible, auditable draws; adversarial strata; independent draws per body (§VI.3a) |
| Integrity body becomes a standing veto | Watchdog freezes an elected government by serial Pausing | Pause is time-boxed, capped, appealable, justified; expose-and-refer only (§VI.1) |
| Defund the watchdog | Starve it quietly | Constitutionally guaranteed funding, uncuttable by those it watches (§VI.2) |
| Secret/opaque algorithms | Unaccountable automated power | Default open register + audit; security exceptions get closed audit, never zero; no unaccountable algorithms (§VI.4, §VIII.5) |
| Procurement corruption | Public money to insiders | Real-time spend ledger; anomaly detection; beneficial-ownership + revolving-door rules (§VI.5) |
| Gaming the metrics (Goodhart) | Hit the target, miss the point | Basket not number; measurer cannot own the basket (entrenched, §V.4); external recomputable data; retroactive re-scoring; outcome-vs-prediction (§VI.7) |
| Backsliding measured by the backslider | Capture the measurer so the decline never shows | Multiple independent custodians from external data; hard-threshold auto-tripwires independent of press/politics (§VI.7) |
| Hidden by non-publication | Only proactive disclosure, so what is not published stays dark | FOI right to request + independent information authority + appeal tribunal (§VI.6a) |
| Influence through access | Lobby the decision-maker off the record | Lobbyist register; published meeting/diary logs; ACOBA-equivalent (§VI.5a) |
| Suppressing bad-outcome data | Hide failure to avoid accountability | Open outcomes ledger; concealment is itself a failure (§0.6); whistleblower channels (§VI.9) |
| Whistleblower retaliation | Silence the insider who tells the truth | Constitutional protection; retaliation an offence (§VI.9) |
| Integrity body overreaches | Watchdog becomes a power itself | Expose-and-refer only; cannot govern or punish unilaterally (§VI.1); Court + juries check it |
Part VI ends. The system can now form an honest mandate, execute it competently, and police its own integrity and outcomes. Next: Part VII, Crisis & Resilience.