---
title: "The Layer Walk"
subtitle: "A protocol for using The Stack on a real failure"
author: Elias Kunnas
description: "A short operational protocol for using The Stack on a concrete failing system. Assemble the evidence bundle, scan the twelve domains, identify the case-specific binding relation, diagnose the failed conversion, and specify its actuator core — owner, authority, capacity, feedback."
canonical: https://kunnas.com/articles/layer-walk
url: https://kunnas.com/articles/layer-walk.md
date_published: 2026-05-17
date_modified: 2026-07-12
corpus_frame_url: https://kunnas.com/articles/how-to-read-this.md
---
## How to read this corpus

The corpus applies one lens to many domains: what mechanisms produce the outcome? It shares four methodological commitments and one explicit directional commitment. Each linked page argues for its part; the links are derivations and disputes, not evidence inherited by every page. The directional commitment does not by itself settle system boundary, distribution, sacrifice, or institutional authority.

1. **Mechanisms are what act.** Incentive gradients, selection pressures, feedback loops, and capital stocks produce the distribution of outcomes. Intentions, labels, official categories, and stated values are evidence about mechanisms, or are themselves coordination mechanisms. They are not causal substitutes. — [Mechanism Realism](https://kunnas.com/articles/mechanism-realism.md) · [Only Selection](https://kunnas.com/articles/only-selection.md)
2. **The reference telos is sustained flourishing.** The broadest achievable adaptive safety margin over deep time — not the continuity of any incumbent state, coalition, institution, or doctrine. A mechanism's own stated goal can still serve as a local proof obligation — showing that its incentives defeat even the purpose it claims is a bounded finding — but meeting that goal establishes nothing about the margin. — [Flourishing Is Maximum Safety Margin](https://kunnas.com/articles/flourishing-is-maximum-safety-margin.md)
3. **Law, rights, legitimacy, democracy, markets, and sovereignty are mechanisms under evaluation.** They are constraints, carriers, or proxies inside the analysis. None is a terminal value or a boundary of what is real. Treating one as terminal ends the mechanism search before it starts. Evaluation carries current function, replacement cost, path dependence, uncertainty, capture risk, reversibility, and who bears model error into the ledger. — [The Stack](https://kunnas.com/articles/the-stack.md) · [Mechanism Space](https://kunnas.com/articles/mechanism-space.md)
4. **Optimization is a system function.** A civilization has to build, exercise, and revise metamechanisms that search mechanism-space, discard dominated options, install, observe effects, and repair under uncertainty. Not running that loop leaves margin unrealized, and that is itself the failure. No single component — analyst, model, or institution — is presumed to contain a global optimum; the capacity is a property of the system. — [From Telos to Policy](https://kunnas.com/articles/from-telos-to-policy.md) · [The Three-Layer Architecture](https://kunnas.com/articles/three-layer-architecture.md)
5. **Uncertainty is preserved, not spent.** Partial orders, binding constraints, unknowns, and residuals stay explicit. An unmeasured effect is not a favorable default. — [The Compression Paradox](https://kunnas.com/articles/compression-paradox.md) · [Cargo Cult Epistemology](https://kunnas.com/articles/cargo-cult-epistemology.md)

*Each essay bears its own evidence. Links carry definitions, derivations, applications, and disputes; they do not transfer proof. Criticism is answered on its substance.*

Canonical: <https://kunnas.com/articles/how-to-read-this.md>

---

# The Layer Walk

*A protocol for using The Stack on a real failure*

Elias Kunnas

## Thesis {#thesis}

The Layer Walk is the short operating manual for [The Stack](the-stack.md): how to take a bounded telic system — or a policy or program analysed as a mechanism inside one — scan the twelve domains, construct the case-specific dependency relation, diagnose the failed telos-relevant conversion, and specify its actuator core: *owner, authority, capacity, feedback*. Those four fields are not the whole repair contract. They are the minimum receiver-side core that must later pass viability, legitimacy, native-surface, wrong-repair, and movement tests. It is not the same artifact as a [Mechanism Analysis](mechanism-analysis.md) (the pre-enactment legislative document) or [the production discipline behind one](how-mechanism-analyses-are-made.md). It is the general-purpose diagnostic procedure for a bounded failing system.

---

## I. What this page is {#i-what-this-page-is}

The framework's operational front matter now has five pages. [The Stack](the-stack.md) is the corpus map — the twelve failure domains and the essays at each. [Capital Stocks](capital-stocks.md) is the operational reference for the Stock ledger / accounting domain. [The Mechanism Analysis](mechanism-analysis.md) defines the pre-enactment legislative artifact. [How Mechanism Analyses Are Made](how-mechanism-analyses-are-made.md) defines the production discipline behind that artifact. This page is the fifth: the short procedure for diagnosing a failing system using the Stack and producing a diagnostic record plus an actuator core.

The output is a diagnostic record plus an actuator core, not a recommendation memo or a complete repair contract. The protocol's eight steps are: bound the case; state the failure; scan the domains; identify the binding relation; diagnose the failed conversion; specify the actuator core; apply the viability test; tag confidence.

The scan order matters for coverage, but layer number is an address, not causal precedence. The case-specific geometry determines what is upstream, downstream, jointly binding, or incomparable. The artifact is only as strong as its weakest supported step.

---

## II. Inputs — the evidence bundle {#ii-inputs-the-evidence-bundle}

Before the domain scan, assemble the evidence bundle. The bundle is the first artifact the protocol produces and the first thing a reviewer should ask to see.

- **System boundary:** What is inside the system being analysed; what is outside.
- **Time horizon:** Over what period the failure is observable and over what period the repair should produce visible movement.
- **Actors:** The named decision-makers, beneficiaries, cost-bearers, and intermediaries with material influence.
- **Observable failure:** The concrete failure-as-symptom, stated in one or two sentences as a measurable gap between stated purpose and produced outcome.
- **Capital stocks affected:** Which stocks from the [Capital Stocks](capital-stocks.md) reference are being built, depleted, or held flat.
- **Counter-explanations:** The strongest alternative diagnoses already in circulation, named explicitly. The protocol's diagnosis has to outperform them.
- **Sources:** Empirical evidence with provenance. Unsourced claims are flagged as such.
- **Success criterion:** What it would look like for the repair to have worked, stated in advance.

---

## III. The domain scan {#iii-the-domain-scan}

For each of the twelve domains in [The Stack](the-stack.md), ask the diagnostic question for the case in the evidence bundle and write a short answer. Thin or unsupported answers are not evidence of health; mark them `UNKNOWN` until the evidence bundle supports a conclusion.

| \# | Domain | Diagnostic question | Failure signal |
|----|----|----|----|
| 0 | Telos | What is this system actually selecting for? | Stated purpose and revealed purpose diverge under stress |
| 1 | Mechanism | How does it produce its outcome? | Intent treated as cause; legal text assumed to produce behaviour |
| 2 | Response | What does the next actor find cheapest? | Gaming, exit, substitution, withdrawal dominate compliance |
| 3 | Standing / carrier | Which telos-relevant claims, harms, benefits, anomalies, or consequences have a procedural voice? | One side has standing; the other absorbs cost silently |
| 4 | Measurement | What signal is treated as reality? | Metric optimised; underlying reality drifts |
| 5 | Stock ledger / accounting | Which stocks are drawn down, and which effects remain UNKNOWN rather than zero? | Hidden depletion masked by visible flow or unsupported effects booked as zero |
| 6 | Decision-frame compilation | Does the decision frame exist? | Pieces scattered; assembled public-usable frame missing |
| 7 | Frame computation / uptake | Does the system compute with the frame? | Frame refused, captured, sloganised, or moralised away |
| 8 | Decision | Who is forced to choose? | Diagnosis exists; no one is required to act |
| 9 | Operational execution | Can the receiver implement? | Repair exceeds the institution's bandwidth |
| 10 | Feedback | Does reality update the rule? | Evaluation observes but does not correct |
| 11 | Reproduction | Does the generator-chain continue? | Output survives; the generator dies |

---

## IV. Finding the binding relation {#iv-finding-the-binding-relation}

Most real failures involve more than one domain. Because layer number is an address rather than a causal rank, the binding relation must be derived from the case instead of inferred from numerical adjacency. A binding domain is one whose repair would unblock the claimed outcome under the case-specific dependency graph; a joint-binding set is the smallest set that must change together.

- **Dependency test.** Draw the implicated domains and the causal or enabling edges among them. Ask which failure blocks which conversion in this case; do not infer direction from layer numbers.
- **Minimal cut-set test.** Identify the smallest single domain or joint set whose successful repair breaks every live path preserving the original failure.
- **Repair-leverage test.** Prefer the smallest specific intervention that produces the largest supported cascading repair, but do not treat leverage as proof of causal primacy.
- **Counterfactual sufficiency test.** Imagine the proposed repair lands and works as designed. Does the original failure persist? If yes, the repair targets a contributing domain, not a sufficient binding relation.

When no single domain is a unique cut set, name the joint-binding set explicitly. Standing/carrier–Decision and Decision-frame compilation–Frame computation/uptake are common examples, but the relation must come from the case rather than the layer numbers.

**Triage heuristic.** In this corpus's applied cases, the binding failure often sits at Standing / carrier (3), Decision (8), or a Standing/carrier–Decision interaction — the architecture is wrong about who can challenge it or about who is forced to decide. Scanning all twelve domains is the rigorous protocol; checking Standing/carrier and Decision first is the rapid-triage version when time is short.

---

## V. Diagnosing the failed conversion {#v-diagnosing-the-failed-conversion}

At the binding relation, the diagnosis is incomplete until it names the exact telos-relevant conversion that failed. The master heuristic remains interpretively elastic — almost any failure can be loosely described as an unowned channel — so the template below records the conversion as source facts. It does not choose a future owner, authority, capacity, or binding instrument; those are actuator decisions in [§VI](#vi-the-actuator-core). Fill every slot or mark it `UNKNOWN`. An unsupported slot cannot be silently completed by the repair design.

| Slot | What it specifies |
|----|----|
| Telos-relevant object or signal | The concrete claim, harm, benefit, anomaly, event, or state change that must be converted. |
| Source state | Where the object currently exists and in what form: tacit knowledge, measurement, record, complaint, model, decision, or consequence. |
| Required conversion | The institutional state it must become for the reference telos: admissible record, decision input, binding duty, implementation change, correction, or re-entry. |
| Current route | The path it currently travels — through which actors, artifacts, systems, and intermediaries. |
| Current receiver | Who in the present architecture is structurally positioned to receive or process it. |
| Ignore or distortion point | Where it may be dropped, reframed, delayed, weakened, or converted into a non-binding substitute. |
| Cost-bearer or silent class | The actor or class — often silent, future, statistical, or diffuse — whose interest is absorbed by the failed conversion. |
| Missing return or re-entry | What consequence, correction, reopening, or learning path fails to return after the object is processed. |

---

## VI. The actuator core {#vi-the-actuator-core}

The four-part structure below is the actuator core, not a complete repair specification. It states who could own the failed conversion and with what authority, capacity, and binding feedback. A complete repair must also name the repair object and native surface, legitimacy or mandate, the strongest legitimate weaker alternative, repair harm or retired load, the wrong-repair warning, the movement test, and the re-entry path. [Constructive Diagnosis](constructive-diagnosis.md) and [When Ownership Is the Wrong Repair](when-ownership-is-the-wrong-repair.md) supply those adjacent constraints.

| Part | What it answers |
|----|----|
| **Owner** | Who would own the failed conversion under the proposed actuator? Named actor or institution, not a function. |
| **Authority** | What legal, statutory, or constitutional authority lets the owner act? Advisory authority is rarely sufficient. |
| **Capacity** | What resources, skills, and operational infrastructure let the owner execute? If the receiver lacks capacity, the repair's first deliverable is capacity, not action. |
| **Feedback** | What binding consequence, response duty, or re-entry obligation ensures correction? Specify the level (reputational / procedural / budgetary / statutory / constitutional) and why that level is sufficient. |

Before advancing the actuator core as a repair, apply the **viability test**: does the receiving institution have the capacity to implement the change without producing worse distortion than the original failure? If no, the capacity-build step is the repair's first deliverable, not an afterthought.

Finally, tag each claim with its **confidence type**: *mechanism logic* (deductive from causal architecture — highest confidence); *structural inference* (architecture as currently observed — depends on evidence bundle); *behavioural prediction* (how actors respond — lower confidence because behaviour depends on factors outside the mechanism); *speculative cascade* (second- and third-order effects — useful for scenario planning, not specification). Magnitude claims should never be presented with mechanism-logic confidence unless anchored to a quantified source.

The success criterion from the evidence bundle becomes the **movement test**: define in advance what observable change in outcomes would count as the repair having worked, and the time horizon over which it should be observable.

Three checks tighten the actuator proposal before the repair ships.

- **Object walk**: name the *native object* the institution processed (permit, certificate, platform, consultation, drive-time, complaint) against the *real object* the telos required (the cumulative ecosystem, actual safety, deployable capability, the computation, real access, the pattern); a procedurally-valid frame can still be the wrong object.
- **Motion**: the failed conversion is an ingress (reality → correction), a surface (surplus → telos), or an egress (consequence → accountability) failure — [The Stack](the-stack.md) [§IV](the-stack.md#iv-the-ownership-heuristic-underneath); the motion decides which carrier the repair must own.
- **Binding grade and wrong-repair warning**: state the binding force the repair compiles to (decorative / advisory / reputational / procedural / consequential — [Feedback Authority](feedback-authority.md)) and the attractive wrong repair the institution would reach for instead. A correct diagnosis routed to the wrong actuator becomes capture, theatre, dashboarding, exhaustion, or cancer; [When Ownership Is the Wrong Repair](when-ownership-is-the-wrong-repair.md) gives the repair-compilation test in full, including the case where a weak actuator is the strongest one legitimately available.

---

## VII. Worked miniature — housing-supply collapse {#vii-worked-miniature-housing-supply-collapse}

*Compressed for length. The intent is to illustrate the walk, not to validate the protocol.*

**Evidence bundle.** System: state-and-local housing-supply governance in California, 2000–present. Observable failure: permits well below population-implied need; gap compounding over two decades. Capital stocks affected: demographic, social, fiscal, human (out-migration). Counter-explanations to outperform: developer rationality alone, NIMBY moralism, construction labour shortage.

**Strong domain signals.** Standing / carrier (3): incumbent homeowners have full procedural standing; future residents have none. Stock ledger / accounting (5): local councils book wins on the visible ledger; demographic and fiscal depletion unbooked. Decision (8): state delegated implementation with no override; councils evaded by zoning required housing onto unbuildable parcels.

**Binding relation.** Joint Standing / carrier (3) + Decision (8). The standing/carrier asymmetry (homeowners have standing; future residents do not) makes the decision-domain evasion structurally available. Either repair alone under-performs.

**Failed conversion.** The decision-relevant interest of would-be residents exists outside the local-council decision record and is not converted into procedural standing or a binding state-level override trigger.

**Actuator core.** *Owner*: state housing agency. *Authority*: statutory provision stripping or weakening local zoning veto on demonstrated non-compliance — California's Builder's Remedy is the live form this repair has taken. *Capacity*: agency staffing and legal infrastructure to certify non-compliance and defend it in court — earlier programs (RHNA without enforcement) lacked exactly this. *Feedback*: statutory level; non-compliance produces concrete legal exposure. The statutory level appears to be the current live test of sufficient binding force; lower binding force had already proved insufficient over prior planning cycles.

**What the protocol does not solve by itself.** The local carrier asymmetry is backed by political-power asymmetry: homeowners vote in local elections; future residents, displaced workers, renters, and would-be household-formers have weaker or no local voice. A local process repair cannot overcome that by clever design alone. The repair requires a higher-tier owner — state, statutory, or constitutional — that can give the silent class procedural standing or override the captured local channel. Mechanism design does not substitute for political power; it specifies where political power must be reallocated, and what owner, authority, capacity, and feedback would make that reallocation real.

---

## Synthesis {#synthesis}

**The argument in three sentences.** The Layer Walk turns a bounded failing system into a diagnostic record plus an actuator core by scanning [the Stack](the-stack.md), deriving the case-specific binding relation, and recording the failed conversion before choosing owner, authority, capacity, and feedback. The four actuator fields are a minimum receiver-side core, not the whole repair contract; an unsupported diagnosis remains `UNKNOWN` rather than being completed by the proposed intervention. The page is short by design — it tells you how to run the procedure, not what the domains contain (Stack), what stocks to count (Capital Stocks), what a legislative mechanism analysis looks like (Mechanism Analysis), or how the production discipline works (How Mechanism Analyses Are Made).

---

**Related references:**

- [The Stack](the-stack.md) — the twelve domains (layer addresses) and the essays at each
- [Capital Stocks](capital-stocks.md) — operational reference for the Stock ledger / accounting domain
- [The Mechanism Analysis](mechanism-analysis.md) — the pre-enactment legislative artifact
- [How Mechanism Analyses Are Made](how-mechanism-analyses-are-made.md) — the production discipline behind that artifact
- [Essays index](index.md) — the full corpus

## Sources and Notes

**Status.** The Layer Walk is an operational procedure, not yet a discipline (no shared epistemic community, no codified empirical methodology, no third-party replication). The page presents the procedure honestly — what it claims and what it acknowledges as unfinished — without claiming the field-formation work that would have to happen for it to be cited as a discipline.

**Adjacent traditions.** The procedure overlaps substantially with realist evaluation (Pawson and Tilley: *context + mechanism = outcome*), public choice theory (Buchanan, Tullock, Olson) on the Standing / carrier domain, institutional economics (North, Williamson, Ostrom) on the underlying treatment of rules and incentives, the safety-engineering Swiss-cheese model (Reason, Leveson) on layered failure, and implementation science on the Operational execution and Feedback domains. The Layer Walk does not claim to have invented these treatments; the contribution is the specific domain scan + failed-conversion diagnosis + actuator-core organisation.

**Methodological caveat on the housing miniature.** The [§VII](#vii-worked-miniature-housing-supply-collapse) miniature is a demonstration of use, not a validation. The diagnosis is constructed after the fact and against a case where the eventual repair had multiple advocates. The procedure's status as a useful frame depends on its evidence base growing through additional applications, particularly to cases the analyst had not previously studied.

**Housing miniature.** The California housing example draws on California housing-element law, RHNA compliance debates, and Builder's Remedy enforcement under the Housing Accountability Act. Useful public references include California HCD materials on housing elements and RHNA, ABAG / UC Davis primers on Builder's Remedy, and public reporting on California's continuing housing underproduction and permitting shortfall.

**Known gaps.** The protocol is strongest at Mechanism, Response, Standing / carrier, Stock ledger / accounting, Decision-frame compilation, and Reproduction. It is weaker at Operational execution and Feedback authority, and at the freshly-separated Measurement and Frame computation / uptake domains. Future essays will fill those gaps.
