← The Rulebook Part XIX

Part XIX, The Operating Model (How the System Runs)

Derived from Axioms 1 (sovereignty), 3 (ends from the people, means from the competent), 4 (every power checked), 7 (end-to-end verifiability), 9 (resilience), 10 (self-correction), and 11 (anti-capture). Parts 0-XVIII define what the system is and why; this Part defines how it runs, day to day, the live protocol that turns the principles of Part V, the citizen surface of Part II, the crisis machinery of Part VII, and the technology of Part VIII into a single, runnable process with no blanks. Its governing rule restates §V.6 as an operating invariant: AI detects and routes; humans and the people decide. Every fast or expert power has an always-live citizen backstop.

XIX.0 Why this Part exists

A constitution that stops at principle is not yet a system. The reader of Parts 0-XVIII knows who decides what, but not the exact path a question travels, the exact thresholds at which the people can act, or the exact line the machine may not cross. This Part fixes all three. It is deliberately concrete, percentages, timings, and named artefacts, because vagueness here is not elegance, it is attack surface (Axiom 11): an unstated threshold is one an adversary sets for you.

Nothing in this Part is new authority. It is the operating specification of authority already granted in earlier Parts. Where it states a number, that number is the model's recommended default (ratified at Referendum 2, §XV.2, and thereafter variable by the people, never by the bodies the number constrains).


XIX.1 The citizen's surface, three tiers by stakes, phone-first

The lived experience of the model is a single secure app (and a fully equivalent offline path, §II.7), but not every civic act carries the same risk, so they do not share the same channel. The honest engineering boundary of §VIII.3 (remote internet voting is unsolved for coercion-resistance and client-side malware) is respected by separating acts by stakes, so the convenience of the phone is spent only where it is safe to spend it.

TierWhat it coversChannelWhy it is safe here
1, Continuous will (phone-first, frictionless)Setting and ranking national priorities; signalling on budget envelopes; triggering a veto, recall, initiative, or the emergency brake (gathering verified signatures); responding to consultations; deliberatingPhone / wallet app, always openThese are signals and thresholds, not secret final ballots. Individual manipulation is absorbed by the aggregate, the cooling-off period (XIX.5), and the right of appeal. A compromised device can mis-signal one citizen; it cannot move a national threshold
2, Binding deliberated decisionsPassing a triggered veto; confirming an expert; deciding a §V.4-escalated value question; a citizen-initiative votePhone offered, but never the sole channel: paper-backed, end-to-end-verifiable, receipt-free, risk-limiting-audited (§VIII.3, §XVIII D8)The hardened channel gives coercion-resistance and software-independence the phone alone cannot
3, Constitutional & electoral actsElecting the Assembly; electing the Head of State; Charter amendment; removing an expert via recallHardened channel as Tier 2, plus the entrenchment process of §I and §XVHighest value to an attacker; maximum assurance, slowest, most audited
The invariant. Tier 1 is where "everyone pings from their phone" genuinely lives, the daily, continuous sovereignty of the people. Tiers 2 and 3 are rarer and run on the hardened rail. No act is ever moved down a tier for convenience (§VIII.3).

XIX.2 The end-to-end decision protocol

Every significant governing decision runs the §V.1 loop. This Part makes each stage operational and names what acts at it. The loop produces a public artefact at every step (Axiom 5, 7); the artefacts, chained, are the accountability.

 0. INTAKE        A question enters, from the mandate (Part III), an expert domain,
                  a citizen initiative (XIX.5), or a Review·Pause·Correct trigger (§V.7)
        ↓
 1. CLASSIFY      The Router (XIX.3) *recommends*: VALUE → the people · TECHNICAL → experts ·
                  AMBIGUOUS → escalate (the presumption, §V.4). A citizen panel (a walled
                  function of the Sortition Chamber) affirms it for material decisions before
                  it binds; reasoning is published; either side may appeal (XIX.8)
        ↓
 2. EVIDENCE      Open data, open models, stated uncertainty, red-team review (§V.2).
                  AI is decision-support here, never decider (§V.6, XIX.3)
        ↓
 3. OPTIONS       Real alternatives, each with costs, benefits, named winners/losers,
                  and assumptions (§V.3)
        ↓
 4. DECISION      VALUE questions → democratic decision (Assembly / Sortition Chamber /
                  referendum). TECHNICAL questions → the competent expert board, within
                  scope, with a named human owner and the §V.3 six-part published record
        ↓
 5. IMPLEMENT     With predicted outcomes recorded in advance and a falsification test
        ↓
 6. MEASURE       Actual vs predicted, on the public outcomes ledger (Part VI)
        ↓
 7. PEOPLE'S      The decision is live to the people's levers (XIX.5): veto, recall,
    CHECK         initiative. Irreversible decisions pause pending any triggered vote;
                  reversible ones proceed and unwind if overturned
        ↓
 8. REVIEW·PAUSE· Confirm · adjust · pause · reverse (§V.7) → feeds back to INTAKE
    CORRECT

The protocol is the same whether the question is a pothole-repair standard or a national energy strategy; only the tier (XIX.1), the deliberation depth, and the thresholds differ.

Proportionate to stakes (triage). Running the full eight-stage loop — public artefacts and red-team at every step — for every minor decision is infeasible at state scale, so a materiality/triage threshold (itself a Router-classified, appealable call, XIX.3) sets the loop depth: minor decisions run a light loop (named owner, recorded reasoning, published outcome), major ones the full loop, and the §V.8 fast/standard/crisis tracks are integrated here rather than left separate. Falsifiability is likewise tiered (§V.2): a genuine falsification test where the decision rests on an empirical prediction; explicit success-criteria plus a review trigger for value-laden or counterfactual-heavy decisions — so the requirement drives real evaluation rather than gameable pseudo-tests.


XIX.3 The AI layer, concretely, three roles, one bright line

The premise "given all technological advances" (§VIII, Part 0) is honoured by putting AI everywhere it adds speed and rigour, and nowhere it would hold power. Every governing AI is on the public algorithm register, is open-source, reproducibly built, bias-tested, and independently audited before and during use (§VIII.5, §VIII.8). There are exactly three governing roles, each bounded by the same invariant.

*1. The Router, recommends who decides — a citizen panel affirms it (never rules on what is decided). At stage 1 it answers one narrow question: is this a value choice (the people's), a technical choice (the experts'), or ambiguous?, applying the §V.4 value-flagging test. Honestly, only part of that test is a mechanical rule: the scale limb (§V.4.1) is a published deterministic threshold a citizen can apply by hand; the contestable* limbs (concentration, irreversibility, and above all "reasonable citizens could rationally disagree") are judgement, not rule — which is precisely why a human body, not the machine, makes the binding call. The Router is therefore rule-based where it can be and a flagging aid where it cannot, barred from being a learned/opaque model (§VIII.5) so its reasoning is inspectable, but the design does not pretend the whole classification is a citizen-applicable checklist.

2. The Threat-Matrix, detects crisis signals (never declares the crisis). A continuously-running, auditable detector that watches the §VII.3 evidentiary thresholds and flags a candidate emergency fast. It has zero authority: it cannot trigger any power. An independent human body, institutionally distinct from any body that would gain power from the emergency (declarer ≠ beneficiary, §VII.3), makes the actual declaration (XIX.7). AI detects; humans declare.

3. Decision-Support, strengthens evidence (never owns the decision). At stages 2-3 it does modelling, scenario-testing, anomaly detection, and plain-English translation of complexity (§V.6). A named human always owns the decision; "the algorithm decided" is never a defence; an automation-bias guard makes genuine human evaluation and recorded override mandatory (§V.6). No autonomous coercive power: no system may, of itself, deprive a citizen of liberty, money, status, or rights (§V.6, §XII).

The one line the machine may not cross: AI may detect, route, model, and explain. It may never decide a value, declare an emergency, or exercise authority over a citizen. That line is what keeps "use AI to govern well" from becoming "let the AI govern."

XIX.4 The people's levers, operational mechanics

The people are sovereign continuously, not only at elections (Axiom 1). Four standing levers, all triggered from Tier 1 and decided (where binding) on the Tier 2/3 rail, give effect to that sovereignty. Each runs the same safe sequence: verified trigger → mandatory deliberation + cooling-off → binding vote against a real national floor.


XIX.5 The threshold schedule, the authoritative dials

All bars are a percentage of verified citizens (the §VIII.2 / §XVIII D8 identity stack is what makes them real and un-astroturfable). The governing principle (derived from §0.5 and §I.3.1): *the bar scales with how irreversible the act is and how much it overrides expertise — and, correcting an earlier flat schedule, the pass floor scales too, not only the trigger, so a reversible decision-veto passes at a lower whole-electorate share than an irreversible, person-removing recall or an emergency brake. Setting your own ends is the people's pure domain (low bar); overruling an expert's evidence-based means puts the burden on you (high bar). Electorate ≈ 52–55 million, computed from the model's actual* franchise (age 16+, automatic registration, tapered diaspora, §II.2, §XIII.7) — not the current 18+ register, whose ~48m would mis-key every threshold (§XIX.0's own warning) — and recomputed whenever the roll is reconciled (§VIII.2). Share floors are whole-electorate shares (defeating low-turnout capture), expressed as approval quorums (§II.4.5); the counts below are illustrative on a ~53m base.

ActTierTrigger (to start)DeliberationPass (to bind)
Set / rank ends, priorities, budget envelopes1standing channelcontinuous briefinforms the mandate; binding form is the election/referendum
Citizen initiative (new agenda item)1 → 2~2%, distributed across ≥3 of the 4 nations and a minimum number of constituencies, time-boxedCourt rights-screen + §II.5 brief + cooling-offmajority of votes and yes ≥ 22% of the electorate
Decision veto (overturn a reversible expert decision)1 → 2~1% within the window§II.5 brief + cooling-off (no vote inside an outrage spike)majority and yes ≥ 18% of the electorate; returns to experts as a binding constraint, responsiveness judged independently (XIX.4)
Representative recall (remove an elected member)1 → 3~5% of the member's electoratebrief + cooling-offmajority and yes ≥ 25% of that electorate; by-election / countback per §III.6a
Expert recall (remove an appointed expert)1 → 3~5%brief + cooling-offmajority and yes ≥ 25% of the electorate; replacement via XIX.7
Emergency brake (end a crisis / recall the Crisis Council)1 → 2, expedited, always live~10% rapid, or cross-institutional co-trigger (any two of Court / Sortition supermajority / Head-of-State alarm)compressed brief; brief-production transfers to an independent body if the Crisis Council controls itmajority and a floor that *starts lower and decays further the longer the crisis runs — the bar to end* a dragging, suspicious crisis falls, never rises — expedited (XIX.4)
Assembly overrides a Sortition-Chamber value ruling,Assembly motionpublished reasonstwo-thirds supermajority of the Assembly (§IX.2); the people may then petition a referendum
Crisis powers,declared per XIX.7,auto-sunset 30 days; Assembly two-thirds may renew up to a cumulative cap of ~180 days in any rolling 24 months; beyond it each renewal needs an escalating supermajority (⅔ → ¾), independent re-verification, and Sortition-Chamber concurrence; domestic-liberty powers beyond a further ~365-day ceiling need a confirmatory referendum (external-threat powers continue without one, §I.6.3a); inaction ends it (§VII.8)
Charter / constitutional change3high signature + Assembly supermajorityfull deliberation + Court rights-screensupermajority + referendum; core changes via the extraordinary route (§I.9.3), with double-majority across the four nations where the Union settlement is touched

Two standing safeguards apply to every binding lever: irreversible decisions pause while a triggered vote runs (reversible ones proceed and unwind if overturned); and no lever may breach a Class A right or target a minority's qualified rights, the Court screens before any vote (§I.3, §II.4). Rate-limiting prevents the same decision being re-vetoed repeatedly to grind it down.


XIX.6 The expert appointment & removal pipeline

"Means from the competent" (§0.5) is only as good as the route by which the competent reach the job, the model's central capture vector (§IV). The operating pipeline marries merit with democratic legitimacy:

  1. Open competence criteria. For each of the ten domains (§XVIII D1), the criteria are published, measurable, and set in advance, appointment is hiring the best, not electing the loudest.
  2. Panel shortlist. A competence-bound, partly sortition-seeded appointments panel shortlists against those criteria. The panel is itself confirmable and removable by citizen jury, so no permanent gatekeeping class forms (closing the "who picks the pickers" recursion, §IV.4).
  3. Citizen-jury confirmation. A randomly-selected, demographically stratified citizen jury (sortition, §II.3) confirms the appointment, paid, professionally briefed from multiple sides, deliberating in a closed setting that is lobbying-resistant (Irish Citizens' Assembly lineage).
  4. Bounded tenure. Five-year staggered terms, maximum two (§XVIII D4), continuity without entrenchment (Axiom 8).
  5. Symmetric removal. For-cause removal via §IV.5, plus the citizen recall of XIX.4-XIX.5. Replacement re-enters at step 2.

Experts never expand their own remit (§IV.6); scope is granted by mandate and Charter, and acting outside it is void (§0.5).


XIX.7 Crisis operating procedure

Part VII is adopted in full; this section specifies only the operating seam with the live model, the two points Part VII left to the operating layer.

  1. Detect (machine). The Threat-Matrix (XIX.3) continuously watches the §VII.3 evidentiary thresholds and flags a candidate emergency fast. It authorises nothing.
  2. Declare (human, declarer ≠ beneficiary). An independent human body, distinct from any body that gains power from the emergency, verifies the flag against the published Threat Verification Matrix and declares, logging its reasoning to the transparency ledger (§VII.3), subject only to genuinely necessary, time-limited, independently-reviewed redaction.
  3. Act, bounded. The Crisis Defence Council acts strictly within pre-agreed doctrine and the Charter: Class A rights inviolable, no constitutional or electoral change, full logging, automatic 30-day sunset (§VII.4, §I.6).
  4. Citizen power during the crisis, pause, with the brake always live. The routine continuous levers (veto, recall, initiative) pause for the declared window, they are too slow and too gameable to run mid-crisis, and an adversary must not be able to jam the response by triggering them. But the emergency brake (XIX.4) stays live the entire time: the people can always, by the XIX.6 expedited threshold, end the emergency or recall the Council. Sovereignty is never fully switched off.
  5. End and account. Inaction ends the emergency (auto-sunset); only a two-thirds Assembly supermajority may renew (§VII.8). A mandatory, independent post-crisis inquiry with teeth examines proportionality and holds any overreach accountable; paused levers and rights restore automatically.

XIX.8 The boundary referee in operation

The integrity of the whole model rests on correctly, and incorruptibly, sorting value questions from technical ones (§0.5, §V.4). In operation:

This makes the subtlest capture route in the model, mislabelling a value as a fact to keep it from the people, fast to detect, cheap to appeal, affirmed by citizens before it binds, and impossible to do silently.


XIX.9 Failure modes and safeguards

Failure modeHow it attacksSafeguard in this Part
Phone-vote populism50%+1 of an activated minority overturns good-but-unpopular expertise on a low-turnout dayWhole-electorate approval-quorum pass floor that scales with irreversibility (18–25%, §XIX.5); mandatory deliberation + cooling-off; veto returns as a constraint, not the technical pen (XIX.4-XIX.5)
Client-side malware / coercionCompromise the phone; coerce or buy votes at homeTiering by stakes, binding/secret acts run on the paper-backed, receipt-free, software-independent rail; phone never the sole channel for Tier 2/3 (XIX.1, §VIII.3)
Router capture (mislabel values as facts)Wall a value choice off from the people as "merely technical", or drift there on the unaudited tailNon-learned classifier (rule-based where it can be); a screened Sortition-Chamber panel affirms material calls by blind re-classification (near-threshold + constitutional-magnitude default upward); stakes-weighted escalation metric vs the blind baseline; throttled affirm-or-lapse; author/deployer/evaluator separated (XIX.3, XIX.8)
Experts out-wait a vetoReturn a cosmetic revision, then run the rate-limiter against the publicIndependent decider (Sortition Chamber) rules if the objection was met; non-responsive revision void; re-issued decisions exempt from the rate-limit (XIX.4)
AI overreachThe machine accrues de-facto authorityOne bright line, AI detects/routes/models/explains, never decides; named human owner; register + audit (XIX.3, §V.6)
Astroturfed triggerManufacture a fake grassroots petitionVerified identity per signature; geographic distribution requirement; thresholds as whole-electorate shares (XIX.5, §VIII.2)
Governance by constant vetoPermanent re-litigation paralyses the expertsReversible decisions proceed pending vote; rate-limiting on re-vetoes; trigger and pass bars set to filter noise (XIX.4-XIX.5)
Crisis-as-coupA captured Crisis Council suspends the people "for security", throttling the channel the brake runs onEmergency brake always live and suppression-resistant (cross-institutional co-triggers, escalating-lower threshold, auto-transfer of the brief); hard cumulative emergency cap; declarer ≠ beneficiary; mandatory inquiry (XIX.4, XIX.7, §I.6.3a)
Crisis-response jammingAn adversary triggers routine levers to paralyse the emergency responseRoutine levers pause during a declared crisis; only the high-threshold brake remains (XIX.7)
Low-turnout capture of a binding voteWin a real vote on a tiny turnoutWhole-electorate approval-quorum floor on every binding lever (XIX.5)
*Router / Threat-Matrix simply wrong***Model error, adversarial-input gaming, or distribution drift misclassifiesPublished error-rate metrics; mandatory revalidation cadence; low-confidence routes to a human fallback; blind sample re-classification; rule-based (not learned) classifier (XIX.3, §VIII.5)

XIX.10 Effect on the score

This Part adds no new authority; it removes ambiguity, and ambiguity was itself a capture surface (Axiom 11). By fixing the thresholds, the AI bright line, and the crisis seam as concrete, published, appealable mechanisms, it strengthens the design honestly on capture-resistance (Criterion 5), accountability (4), and transparency & verifiability (6), the operating detail an adversary would otherwise exploit is now closed and on the record.

It does not, and must not be claimed to, move the score to 10. Consistent with §0.6.5 (a design that claims no weaknesses is lying) and §XVIII D10, the residual distance is the part no paper can earn:

  1. Outcome quality, provable only once the system runs and the outcomes ledger fills (§XVII.3.1);
  2. Simplicity, a complete governing system carries inherent complexity. This was the independent panel's sharpest finding (§XVII.2a), and it is answered as far as honesty allows: the whole-model map (§0.8) reduces the architecture to a holdable 1·5·4·4·3, the complexity ledger (docs/COMPLEXITY.md) bounds the citizen's load to a counted sixteen concepts and justifies every institution item-by-item, and the tiered surface (XIX.1) keeps the daily ask smaller than today's. What remains — the intricacy the experts and auditors who run the system must carry — is inherent to governing a country and is not erased, only bounded and made navigable.

The model is now complete, decisive, and runnable: principles (0-XVII), the resolved settlement (XVIII), and the live operating protocol (XIX). The remaining points are earned by operating well, measured continuously and in public (§XVII.5), not by writing more pages.


Part XIX ends. With it the rulebook specifies not only what the system is and why, but exactly how it runs. Next, in the platform (/platform), these mechanisms become enforceable code: the Router, the threshold schedule, and the crisis seam wired into the symbolic core that already reproduces the rubric, the proportionality gate, and the STV+ count.