Part XIX, The Operating Model (How the System Runs)
Derived from Axioms 1 (sovereignty), 3 (ends from the people, means from the competent), 4 (every power checked), 7 (end-to-end verifiability), 9 (resilience), 10 (self-correction), and 11 (anti-capture). Parts 0-XVIII define what the system is and why; this Part defines how it runs, day to day, the live protocol that turns the principles of Part V, the citizen surface of Part II, the crisis machinery of Part VII, and the technology of Part VIII into a single, runnable process with no blanks. Its governing rule restates §V.6 as an operating invariant: AI detects and routes; humans and the people decide. Every fast or expert power has an always-live citizen backstop.
XIX.0 Why this Part exists
A constitution that stops at principle is not yet a system. The reader of Parts 0-XVIII knows who decides what, but not the exact path a question travels, the exact thresholds at which the people can act, or the exact line the machine may not cross. This Part fixes all three. It is deliberately concrete, percentages, timings, and named artefacts, because vagueness here is not elegance, it is attack surface (Axiom 11): an unstated threshold is one an adversary sets for you.
Nothing in this Part is new authority. It is the operating specification of authority already granted in earlier Parts. Where it states a number, that number is the model's recommended default (ratified at Referendum 2, §XV.2, and thereafter variable by the people, never by the bodies the number constrains).
XIX.1 The citizen's surface, three tiers by stakes, phone-first
The lived experience of the model is a single secure app (and a fully equivalent offline path, §II.7), but not every civic act carries the same risk, so they do not share the same channel. The honest engineering boundary of §VIII.3 (remote internet voting is unsolved for coercion-resistance and client-side malware) is respected by separating acts by stakes, so the convenience of the phone is spent only where it is safe to spend it.
| Tier | What it covers | Channel | Why it is safe here |
|---|---|---|---|
| 1, Continuous will (phone-first, frictionless) | Setting and ranking national priorities; signalling on budget envelopes; triggering a veto, recall, initiative, or the emergency brake (gathering verified signatures); responding to consultations; deliberating | Phone / wallet app, always open | These are signals and thresholds, not secret final ballots. Individual manipulation is absorbed by the aggregate, the cooling-off period (XIX.5), and the right of appeal. A compromised device can mis-signal one citizen; it cannot move a national threshold |
| 2, Binding deliberated decisions | Passing a triggered veto; confirming an expert; deciding a §V.4-escalated value question; a citizen-initiative vote | Phone offered, but never the sole channel: paper-backed, end-to-end-verifiable, receipt-free, risk-limiting-audited (§VIII.3, §XVIII D8) | The hardened channel gives coercion-resistance and software-independence the phone alone cannot |
| 3, Constitutional & electoral acts | Electing the Assembly; electing the Head of State; Charter amendment; removing an expert via recall | Hardened channel as Tier 2, plus the entrenchment process of §I and §XV | Highest value to an attacker; maximum assurance, slowest, most audited |
The invariant. Tier 1 is where "everyone pings from their phone" genuinely lives, the daily, continuous sovereignty of the people. Tiers 2 and 3 are rarer and run on the hardened rail. No act is ever moved down a tier for convenience (§VIII.3).
XIX.2 The end-to-end decision protocol
Every significant governing decision runs the §V.1 loop. This Part makes each stage operational and names what acts at it. The loop produces a public artefact at every step (Axiom 5, 7); the artefacts, chained, are the accountability.
0. INTAKE A question enters, from the mandate (Part III), an expert domain,
a citizen initiative (XIX.5), or a Review·Pause·Correct trigger (§V.7)
↓
1. CLASSIFY The Router (XIX.3) *recommends*: VALUE → the people · TECHNICAL → experts ·
AMBIGUOUS → escalate (the presumption, §V.4). A citizen panel (a walled
function of the Sortition Chamber) affirms it for material decisions before
it binds; reasoning is published; either side may appeal (XIX.8)
↓
2. EVIDENCE Open data, open models, stated uncertainty, red-team review (§V.2).
AI is decision-support here, never decider (§V.6, XIX.3)
↓
3. OPTIONS Real alternatives, each with costs, benefits, named winners/losers,
and assumptions (§V.3)
↓
4. DECISION VALUE questions → democratic decision (Assembly / Sortition Chamber /
referendum). TECHNICAL questions → the competent expert board, within
scope, with a named human owner and the §V.3 six-part published record
↓
5. IMPLEMENT With predicted outcomes recorded in advance and a falsification test
↓
6. MEASURE Actual vs predicted, on the public outcomes ledger (Part VI)
↓
7. PEOPLE'S The decision is live to the people's levers (XIX.5): veto, recall,
CHECK initiative. Irreversible decisions pause pending any triggered vote;
reversible ones proceed and unwind if overturned
↓
8. REVIEW·PAUSE· Confirm · adjust · pause · reverse (§V.7) → feeds back to INTAKE
CORRECT
The protocol is the same whether the question is a pothole-repair standard or a national energy strategy; only the tier (XIX.1), the deliberation depth, and the thresholds differ.
Proportionate to stakes (triage). Running the full eight-stage loop — public artefacts and red-team at every step — for every minor decision is infeasible at state scale, so a materiality/triage threshold (itself a Router-classified, appealable call, XIX.3) sets the loop depth: minor decisions run a light loop (named owner, recorded reasoning, published outcome), major ones the full loop, and the §V.8 fast/standard/crisis tracks are integrated here rather than left separate. Falsifiability is likewise tiered (§V.2): a genuine falsification test where the decision rests on an empirical prediction; explicit success-criteria plus a review trigger for value-laden or counterfactual-heavy decisions — so the requirement drives real evaluation rather than gameable pseudo-tests.
XIX.3 The AI layer, concretely, three roles, one bright line
The premise "given all technological advances" (§VIII, Part 0) is honoured by putting AI everywhere it adds speed and rigour, and nowhere it would hold power. Every governing AI is on the public algorithm register, is open-source, reproducibly built, bias-tested, and independently audited before and during use (§VIII.5, §VIII.8). There are exactly three governing roles, each bounded by the same invariant.
*1. The Router, recommends who decides — a citizen panel affirms it (never rules on what is decided). At stage 1 it answers one narrow question: is this a value choice (the people's), a technical choice (the experts'), or ambiguous?, applying the §V.4 value-flagging test. Honestly, only part of that test is a mechanical rule: the scale limb (§V.4.1) is a published deterministic threshold a citizen can apply by hand; the contestable* limbs (concentration, irreversibility, and above all "reasonable citizens could rationally disagree") are judgement, not rule — which is precisely why a human body, not the machine, makes the binding call. The Router is therefore rule-based where it can be and a flagging aid where it cannot, barred from being a learned/opaque model (§VIII.5) so its reasoning is inspectable, but the design does not pretend the whole classification is a citizen-applicable checklist.
- It recommends; a citizen panel affirms. Routing is a form of ruling, so it is never left to the machine. Affirmation is a screened, walled-off function of the Citizens' Sortition Chamber (§IX.2), not a new standing body: it draws a separate panel from a different stratum of the same verifiable lot (§VI.3a), with independently-set adversarial briefing and no briefer shared with the Router's author/deployer/evaluator — independent of both the Router and the Chamber's value-deciding function, without adding an institution (Axiom 14). Its method is blind re-classification (it decides without seeing the Router's answer), so there is no second duplicate panel.
- Throttled, so affirmation is neither a chokepoint nor a flood-DoS. Affirmation-before-binding applies only to a small top-materiality tier; for the rest the panel affirms by batch/sample with published exception-flagging, on a fixed affirm-or-lapse window whose default is proportionate to materiality (high → escalate on lapse; low → the recommendation stands, flagged) — plus an anti-flooding rate-limit, so the gate cannot be turned into a denial-of-service on delivery.
- *The materiality line is auditable upward. Because the checker sits above a materiality threshold that is itself a Router call, capture could hide by labelling a material question "immaterial." So near-threshold materiality calls default upward into affirmation*, and the triage-materiality determination is itself sampled and panel-auditable — mirroring "ambiguity defaults to escalation."
- The V-a/V-b call is affirmed too. The panel also checks the constitutional-magnitude determination (§V.4.2): a borderline "is this the people's binding word (V-b)?" defaults upward to the people, so a genuinely constitutional value question cannot be quietly downgraded to an overridable chamber ruling.
- A stakes-weighted escalation metric, anchored externally. The primary integrity metric is the escalation share within each materiality band (especially the top band), anchored to the blind panel's re-classification rate, so a wrong steady level (a Router "born captured," which a drift-only detector misses) trips review — not only a downward drift — and padding the count with trivia cannot mask it. A raw scalar floor is a secondary indicator only.
- Every classification is published with cited reasoning against a named clause; the Router's rules and version history are open and entrenched (a change is a logged governing act, never a silent retune); its rule/corpus author, deployer, and evaluator are institutionally separate (§VIII.5), so no single "man in the middle" can steer classifications invisibly.
2. The Threat-Matrix, detects crisis signals (never declares the crisis). A continuously-running, auditable detector that watches the §VII.3 evidentiary thresholds and flags a candidate emergency fast. It has zero authority: it cannot trigger any power. An independent human body, institutionally distinct from any body that would gain power from the emergency (declarer ≠ beneficiary, §VII.3), makes the actual declaration (XIX.7). AI detects; humans declare.
3. Decision-Support, strengthens evidence (never owns the decision). At stages 2-3 it does modelling, scenario-testing, anomaly detection, and plain-English translation of complexity (§V.6). A named human always owns the decision; "the algorithm decided" is never a defence; an automation-bias guard makes genuine human evaluation and recorded override mandatory (§V.6). No autonomous coercive power: no system may, of itself, deprive a citizen of liberty, money, status, or rights (§V.6, §XII).
The one line the machine may not cross: AI may detect, route, model, and explain. It may never decide a value, declare an emergency, or exercise authority over a citizen. That line is what keeps "use AI to govern well" from becoming "let the AI govern."
XIX.4 The people's levers, operational mechanics
The people are sovereign continuously, not only at elections (Axiom 1). Four standing levers, all triggered from Tier 1 and decided (where binding) on the Tier 2/3 rail, give effect to that sovereignty. Each runs the same safe sequence: verified trigger → mandatory deliberation + cooling-off → binding vote against a real national floor.
- The decision veto. Citizens may overturn a specific expert decision. Trigger: a verified, distributed petition reaching the XIX.6 threshold within the window. Then: the independent §II.5 brief is published and a cooling-off period runs (no binding vote inside an outrage spike, §II.4). Binds if: a majority of votes and the yes-side is at least a defined share of the whole electorate (XIX.6), so a veto is always a real slice of the country, never an activated minority on a low-turnout day (modelled on the 1979 "40% rule").
- A veto sets a constraint; it does not hand the majority the technical pen. When a decision is overturned, it returns to the expert board with the public's objection as a binding constraint (Court rights-screened, §I.3). The experts must produce a revised option that meets the objection and still clears the Charter and the evidence. The people can always say "not this"; they cannot vote the country onto a bridge that will not stand. This preserves §0.5 exactly: ends (including "this outcome is unacceptable") from the people; means from the competent.
- An independent decider rules whether the objection was met. The board does not judge whether its own revised option satisfies the public's objection — that would let it out-wait the people with a cosmetic change and then hide behind the anti-paralysis rate-limit. The Sortition Chamber (or the original petitioners' panel) rules on whether the revision is genuinely responsive; a revision ruled non-responsive is void and the named decision-owner faces §IV.5 accountability. And a challenge to a re-issued decision on the same matter is exempt from the re-veto rate-limit (§XIX.9), so the rule that stops vexatious re-litigation cannot double as the experts' shield against a legitimate second look.
- The expert recall. Citizens may remove an individual expert for serious failure or breach, between the for-cause routes of §IV.5. Higher trigger than a veto (you are removing a person, not reversing a call); same whole-electorate-share floor to pass; replacement runs the XIX.7 pipeline. This is the citizen-initiated complement to §IV.5 and §XVIII D4.
- The citizen initiative. Citizens may put a new question onto the agenda. Trigger: a higher, geographically distributed signature threshold (XIX.6), time-boxed. Then: Court rights pre-screen (no initiative may breach Class A rights or target a minority's qualified rights, §II.4) → deliberation → binding vote.
- The emergency brake. During a declared crisis (XIX.7) the routine levers pause, but this one never switches off: an expedited vote can end the emergency or recall the Crisis Defence Council at any moment. Crucially, a routine high phone-threshold would be unreachable in the very scenario the brake exists for — a captured Crisis Council controls the information brief, the app channel, and the tempo, while a real crisis degrades communications. So the brake is designed differently from the routine levers: it is not solely app-dependent but also fires on cross-institutional co-triggers (any two of the Constitutional Court, a Sortition-Chamber supermajority, and the Head of State's guardian-of-the-constitution alarm role, §XVIII D2); its threshold is *lower and decays further the longer a crisis runs (easier to end a dragging crisis, never harder); and if the Crisis Council controls the Public Information channel, brief-production transfers automatically to an independent body*. The backstop is deliberately decoupled from the infrastructure an adversary would control. It is the structural answer to "crisis-as-coup" (§VII.9): even a captured Crisis Council governs only for as long as the people allow, and the means to end it cannot be switched off with the lights.
XIX.5 The threshold schedule, the authoritative dials
All bars are a percentage of verified citizens (the §VIII.2 / §XVIII D8 identity stack is what makes them real and un-astroturfable). The governing principle (derived from §0.5 and §I.3.1): *the bar scales with how irreversible the act is and how much it overrides expertise — and, correcting an earlier flat schedule, the pass floor scales too, not only the trigger, so a reversible decision-veto passes at a lower whole-electorate share than an irreversible, person-removing recall or an emergency brake. Setting your own ends is the people's pure domain (low bar); overruling an expert's evidence-based means puts the burden on you (high bar). Electorate ≈ 52–55 million, computed from the model's actual* franchise (age 16+, automatic registration, tapered diaspora, §II.2, §XIII.7) — not the current 18+ register, whose ~48m would mis-key every threshold (§XIX.0's own warning) — and recomputed whenever the roll is reconciled (§VIII.2). Share floors are whole-electorate shares (defeating low-turnout capture), expressed as approval quorums (§II.4.5); the counts below are illustrative on a ~53m base.
| Act | Tier | Trigger (to start) | Deliberation | Pass (to bind) |
|---|---|---|---|---|
| Set / rank ends, priorities, budget envelopes | 1 | standing channel | continuous brief | informs the mandate; binding form is the election/referendum |
| Citizen initiative (new agenda item) | 1 → 2 | ~2%, distributed across ≥3 of the 4 nations and a minimum number of constituencies, time-boxed | Court rights-screen + §II.5 brief + cooling-off | majority of votes and yes ≥ 22% of the electorate |
| Decision veto (overturn a reversible expert decision) | 1 → 2 | ~1% within the window | §II.5 brief + cooling-off (no vote inside an outrage spike) | majority and yes ≥ 18% of the electorate; returns to experts as a binding constraint, responsiveness judged independently (XIX.4) |
| Representative recall (remove an elected member) | 1 → 3 | ~5% of the member's electorate | brief + cooling-off | majority and yes ≥ 25% of that electorate; by-election / countback per §III.6a |
| Expert recall (remove an appointed expert) | 1 → 3 | ~5% | brief + cooling-off | majority and yes ≥ 25% of the electorate; replacement via XIX.7 |
| Emergency brake (end a crisis / recall the Crisis Council) | 1 → 2, expedited, always live | ~10% rapid, or cross-institutional co-trigger (any two of Court / Sortition supermajority / Head-of-State alarm) | compressed brief; brief-production transfers to an independent body if the Crisis Council controls it | majority and a floor that *starts lower and decays further the longer the crisis runs — the bar to end* a dragging, suspicious crisis falls, never rises — expedited (XIX.4) |
| Assembly overrides a Sortition-Chamber value ruling | , | Assembly motion | published reasons | two-thirds supermajority of the Assembly (§IX.2); the people may then petition a referendum |
| Crisis powers | , | declared per XIX.7 | , | auto-sunset 30 days; Assembly two-thirds may renew up to a cumulative cap of ~180 days in any rolling 24 months; beyond it each renewal needs an escalating supermajority (⅔ → ¾), independent re-verification, and Sortition-Chamber concurrence; domestic-liberty powers beyond a further ~365-day ceiling need a confirmatory referendum (external-threat powers continue without one, §I.6.3a); inaction ends it (§VII.8) |
| Charter / constitutional change | 3 | high signature + Assembly supermajority | full deliberation + Court rights-screen | supermajority + referendum; core changes via the extraordinary route (§I.9.3), with double-majority across the four nations where the Union settlement is touched |
Two standing safeguards apply to every binding lever: irreversible decisions pause while a triggered vote runs (reversible ones proceed and unwind if overturned); and no lever may breach a Class A right or target a minority's qualified rights, the Court screens before any vote (§I.3, §II.4). Rate-limiting prevents the same decision being re-vetoed repeatedly to grind it down.
XIX.6 The expert appointment & removal pipeline
"Means from the competent" (§0.5) is only as good as the route by which the competent reach the job, the model's central capture vector (§IV). The operating pipeline marries merit with democratic legitimacy:
- Open competence criteria. For each of the ten domains (§XVIII D1), the criteria are published, measurable, and set in advance, appointment is hiring the best, not electing the loudest.
- Panel shortlist. A competence-bound, partly sortition-seeded appointments panel shortlists against those criteria. The panel is itself confirmable and removable by citizen jury, so no permanent gatekeeping class forms (closing the "who picks the pickers" recursion, §IV.4).
- Citizen-jury confirmation. A randomly-selected, demographically stratified citizen jury (sortition, §II.3) confirms the appointment, paid, professionally briefed from multiple sides, deliberating in a closed setting that is lobbying-resistant (Irish Citizens' Assembly lineage).
- Bounded tenure. Five-year staggered terms, maximum two (§XVIII D4), continuity without entrenchment (Axiom 8).
- Symmetric removal. For-cause removal via §IV.5, plus the citizen recall of XIX.4-XIX.5. Replacement re-enters at step 2.
Experts never expand their own remit (§IV.6); scope is granted by mandate and Charter, and acting outside it is void (§0.5).
XIX.7 Crisis operating procedure
Part VII is adopted in full; this section specifies only the operating seam with the live model, the two points Part VII left to the operating layer.
- Detect (machine). The Threat-Matrix (XIX.3) continuously watches the §VII.3 evidentiary thresholds and flags a candidate emergency fast. It authorises nothing.
- Declare (human, declarer ≠ beneficiary). An independent human body, distinct from any body that gains power from the emergency, verifies the flag against the published Threat Verification Matrix and declares, logging its reasoning to the transparency ledger (§VII.3), subject only to genuinely necessary, time-limited, independently-reviewed redaction.
- Act, bounded. The Crisis Defence Council acts strictly within pre-agreed doctrine and the Charter: Class A rights inviolable, no constitutional or electoral change, full logging, automatic 30-day sunset (§VII.4, §I.6).
- Citizen power during the crisis, pause, with the brake always live. The routine continuous levers (veto, recall, initiative) pause for the declared window, they are too slow and too gameable to run mid-crisis, and an adversary must not be able to jam the response by triggering them. But the emergency brake (XIX.4) stays live the entire time: the people can always, by the XIX.6 expedited threshold, end the emergency or recall the Council. Sovereignty is never fully switched off.
- End and account. Inaction ends the emergency (auto-sunset); only a two-thirds Assembly supermajority may renew (§VII.8). A mandatory, independent post-crisis inquiry with teeth examines proportionality and holds any overreach accountable; paused levers and rights restore automatically.
XIX.8 The boundary referee in operation
The integrity of the whole model rests on correctly, and incorruptibly, sorting value questions from technical ones (§0.5, §V.4). In operation:
- Default: the Router recommends a classification, fast and consistently, publishing cited reasoning; for a top-materiality tier a screened panel of the Sortition Chamber affirms it before it binds (silence → escalation), while the rest is affirmed by batch/sample on an affirm-or-lapse window, so the gate is neither a chokepoint nor floodable (§XIX.3).
- Bias: toward escalation — genuine ambiguity, near-threshold materiality, and borderline constitutional-magnitude all default upward (§V.4 presumption) — policed by a stakes-weighted escalation metric anchored to the blind re-classification rate, so a wrong level, not only a downward drift, auto-triggers a §V.7 review.
- Appeal: self-executing on a citizen petition, the Sortition Chamber, the Integrity bodies, or its materiality-affirmation panel; the Constitutional Court rules only on rights-legality, never on whether escalation was warranted (§V.4.3), so the boundary of democratic authority is not drawn by the least democratic institution.
- Audit: the Router is rule-based (not a learned model), open-source, and versioned; classifications are sampled and independently re-classified blind (§XIX.3); a pattern of mis-classification, or a drift in the escalation rate, is itself a §V.7 trigger.
This makes the subtlest capture route in the model, mislabelling a value as a fact to keep it from the people, fast to detect, cheap to appeal, affirmed by citizens before it binds, and impossible to do silently.
XIX.9 Failure modes and safeguards
| Failure mode | How it attacks | Safeguard in this Part |
|---|---|---|
| Phone-vote populism | 50%+1 of an activated minority overturns good-but-unpopular expertise on a low-turnout day | Whole-electorate approval-quorum pass floor that scales with irreversibility (18–25%, §XIX.5); mandatory deliberation + cooling-off; veto returns as a constraint, not the technical pen (XIX.4-XIX.5) |
| Client-side malware / coercion | Compromise the phone; coerce or buy votes at home | Tiering by stakes, binding/secret acts run on the paper-backed, receipt-free, software-independent rail; phone never the sole channel for Tier 2/3 (XIX.1, §VIII.3) |
| Router capture (mislabel values as facts) | Wall a value choice off from the people as "merely technical", or drift there on the unaudited tail | Non-learned classifier (rule-based where it can be); a screened Sortition-Chamber panel affirms material calls by blind re-classification (near-threshold + constitutional-magnitude default upward); stakes-weighted escalation metric vs the blind baseline; throttled affirm-or-lapse; author/deployer/evaluator separated (XIX.3, XIX.8) |
| Experts out-wait a veto | Return a cosmetic revision, then run the rate-limiter against the public | Independent decider (Sortition Chamber) rules if the objection was met; non-responsive revision void; re-issued decisions exempt from the rate-limit (XIX.4) |
| AI overreach | The machine accrues de-facto authority | One bright line, AI detects/routes/models/explains, never decides; named human owner; register + audit (XIX.3, §V.6) |
| Astroturfed trigger | Manufacture a fake grassroots petition | Verified identity per signature; geographic distribution requirement; thresholds as whole-electorate shares (XIX.5, §VIII.2) |
| Governance by constant veto | Permanent re-litigation paralyses the experts | Reversible decisions proceed pending vote; rate-limiting on re-vetoes; trigger and pass bars set to filter noise (XIX.4-XIX.5) |
| Crisis-as-coup | A captured Crisis Council suspends the people "for security", throttling the channel the brake runs on | Emergency brake always live and suppression-resistant (cross-institutional co-triggers, escalating-lower threshold, auto-transfer of the brief); hard cumulative emergency cap; declarer ≠ beneficiary; mandatory inquiry (XIX.4, XIX.7, §I.6.3a) |
| Crisis-response jamming | An adversary triggers routine levers to paralyse the emergency response | Routine levers pause during a declared crisis; only the high-threshold brake remains (XIX.7) |
| Low-turnout capture of a binding vote | Win a real vote on a tiny turnout | Whole-electorate approval-quorum floor on every binding lever (XIX.5) |
| *Router / Threat-Matrix simply wrong*** | Model error, adversarial-input gaming, or distribution drift misclassifies | Published error-rate metrics; mandatory revalidation cadence; low-confidence routes to a human fallback; blind sample re-classification; rule-based (not learned) classifier (XIX.3, §VIII.5) |
XIX.10 Effect on the score
This Part adds no new authority; it removes ambiguity, and ambiguity was itself a capture surface (Axiom 11). By fixing the thresholds, the AI bright line, and the crisis seam as concrete, published, appealable mechanisms, it strengthens the design honestly on capture-resistance (Criterion 5), accountability (4), and transparency & verifiability (6), the operating detail an adversary would otherwise exploit is now closed and on the record.
It does not, and must not be claimed to, move the score to 10. Consistent with §0.6.5 (a design that claims no weaknesses is lying) and §XVIII D10, the residual distance is the part no paper can earn:
- Outcome quality, provable only once the system runs and the outcomes ledger fills (§XVII.3.1);
- Simplicity, a complete governing system carries inherent complexity. This was the independent panel's sharpest finding (§XVII.2a), and it is answered as far as honesty allows: the whole-model map (§0.8) reduces the architecture to a holdable 1·5·4·4·3, the complexity ledger (
docs/COMPLEXITY.md) bounds the citizen's load to a counted sixteen concepts and justifies every institution item-by-item, and the tiered surface (XIX.1) keeps the daily ask smaller than today's. What remains — the intricacy the experts and auditors who run the system must carry — is inherent to governing a country and is not erased, only bounded and made navigable.
The model is now complete, decisive, and runnable: principles (0-XVII), the resolved settlement (XVIII), and the live operating protocol (XIX). The remaining points are earned by operating well, measured continuously and in public (§XVII.5), not by writing more pages.
Part XIX ends. With it the rulebook specifies not only what the system is and why, but exactly how it runs. Next, in the platform (/platform), these mechanisms become enforceable code: the Router, the threshold schedule, and the crisis seam wired into the symbolic core that already reproduces the rubric, the proportionality gate, and the STV+ count.