The Stack

The failure domains of persistent telic systems — and a map to the corpus

Elias Kunnas

Corpus frame

The corpus applies one lens to many domains: what mechanisms produce the outcome? It shares four methodological commitments and one explicit directional commitment. Each linked page argues for its part; the links are derivations and disputes, not evidence inherited by every page. The directional commitment does not by itself settle system boundary, distribution, sacrifice, or institutional authority.

  1. Mechanisms are what act. Incentive gradients, selection pressures, feedback loops, and capital stocks produce the distribution of outcomes. Intentions, labels, official categories, and stated values are evidence about mechanisms, or are themselves coordination mechanisms. They are not causal substitutes. — Mechanism Realism · Only Selection
  2. The reference telos is sustained flourishing. The broadest achievable adaptive safety margin over deep time — not the continuity of any incumbent state, coalition, institution, or doctrine. A mechanism's own stated goal can still serve as a local proof obligation — showing that its incentives defeat even the purpose it claims is a bounded finding — but meeting that goal establishes nothing about the margin. — Flourishing Is Maximum Safety Margin
  3. Law, rights, legitimacy, democracy, markets, and sovereignty are mechanisms under evaluation. They are constraints, carriers, or proxies inside the analysis. None is a terminal value or a boundary of what is real. Treating one as terminal ends the mechanism search before it starts. Evaluation carries current function, replacement cost, path dependence, uncertainty, capture risk, reversibility, and who bears model error into the ledger. — The Stack · Mechanism Space
  4. Optimization is a system function. A civilization has to build, exercise, and revise metamechanisms that search mechanism-space, discard dominated options, install, observe effects, and repair under uncertainty. Not running that loop leaves margin unrealized, and that is itself the failure. No single component — analyst, model, or institution — is presumed to contain a global optimum; the capacity is a property of the system. — From Telos to Policy · The Three-Layer Architecture
  5. Uncertainty is preserved, not spent. Partial orders, binding constraints, unknowns, and residuals stay explicit. An unmeasured effect is not a favorable default. — The Compression Paradox · Cargo Cult Epistemology

Each essay bears its own evidence. Links carry definitions, derivations, applications, and disputes; they do not transfer proof. Criticism is answered on its substance.

Where each commitment is derived

An institutionalised telic system — a persistent, goal-directed system that maintains itself by converting information into action, correction and reproduction — and any policy or program analysed as a mechanism inside one can be walked through the Stack once it meets the six preconditions in §0, of which a declared boundary and a named reference telos are the two the walk cannot start without. A policy document by itself need not be a complete telic system; it may be one mechanism within a larger one. Such systems fail in a small number of recognisable ways, and this page sorts those failures into twelve domains. Each domain asks one question; each question has a healthy answer-shape and a failure-shape.

This page is the navigation surface for the rest of the corpus: what each domain is, the canonical failure in that domain, and the essays that cover it. The page is not an argument that the world has exactly twelve layers. It is a navigation surface: when a failure appears, the Stack asks which domain is implicated and points to the essays that treat it. Treat the partition as a working hypothesis — useful enough to organise the work, not the periodic table of social science.


0. Scope and reference telos

The Stack is telos-relative. It does not define failure by itself. A Stack walk must name the system boundary and the reference telos before naming the failed domain. The same event may be success relative to one local system and failure relative to another: a village coalition can succeed at coalition preservation while failing relative to legal-civic legitimacy; a bureaucracy can succeed at defensibility while failing relative to action; a democracy can succeed at voter satisfaction while failing relative to deep-time flourishing.

In local use, the reference telos is often the institution's legitimate mandate. In framework use, the reference telos is deep-time flourishing and survival margin. When these diverge, Layer 0 is not background; it is the first object of audit.

The Stack applies where a persistent goal-directed system has channels through which relevant reality must become action, correction, or reproduction. The preconditions are: (1) a declared system boundary, (2) a reference telos, (3) reality entering through identifiable channels, (4) a conversion path from signal to action, (5) persistent carriers — roles, files, queues, ledgers, memory, feedback loops, reproduction pipelines — and (6) localisable failure across distinguishable substrates. Without all six, the Stack is metaphor rather than diagnostic. It applies strongly to institutions and institutionalised systems; it applies to other substrates (AI systems, markets, cultures, minds, organisms) only by translation into substrate-native hardening devices.

Carrier is used in three distinct senses on this page and they are not interchangeable, so it is worth fixing them here. A state carrier is a file, queue, register or ledger: it holds a record and does nothing on its own. A claim carrier (Layer 3) is a party or procedure with standing: it acts, pushing a harm into a decision system that would otherwise not see it. A capacity carrier (Layer 11) is people and practices: it reproduces, and what it holds is a competence rather than a record or a claim.

What the three share is only the diagnostic question, which is why one word survives: remove it, and does the thing it held remain available to the system? Passive storage, active advocate and reproducing competence take three different repairs, and reading one for another is a live way to misdiagnose a case.

The compressed first-pass form of failure relative to telos T is therefore: T-relevant reality entered through a channel the system does not own, so the reality could not become T-preserving adaptation. Read that as the ingress case — the one the line was written for, and the reason it is worth memorising — not as the definition of failure. §IV adds the two other places the same conversion question arises (unowned surplus, unowned consequence) and states plainly why even the triad is a heuristic rather than a genus. The "T-relevant" qualifier is not optional in any of the three forms; it is the variable that decides which channels count as load-bearing.

Three nested failure types follow from this. Telos-misalignment failure: the system executes well, but its telos itself fails the meta-telos (the village game running correctly while depleting substrates that deep-time flourishing depends on). Execution failure: the system's telos is acceptable, but it fails in one of the eleven non-telos domains (the welfare agency that cannot process claims because the queue is invisible). Multi-system collision failure: multiple systems each succeed locally but jointly produce higher-order failure because no one owns the translation between them (the court closing the case while the town reopens it).

The third category requires a distinct primitive: something that converts standing and closure across system boundaries — whose finding another system is obliged to import, who owns protecting the person that carried it, and what counts as closed in one system when the other has reopened it. The Stack does not supply that primitive and no essay in this corpus yet does; it is named here so the gap is visible rather than absorbed into the twelve domains, and the worked example below is what it looks like when it is missing.

Failure also includes preventable loss of attainable improvement, not only breakdown against an existing specification. A system may perform its current task correctly while failing to search for, recognise, or implement better feasible arrangements. The same comparison applies to its own search-and-correction architecture. That is not a thirteenth layer; it is an evaluation condition across the existing domains. From Telos to Policy states the search obligation.

Worked example, telos-relative diagnosis. The case below is a composite of a recurring pattern rather than a documented incident; it is here to show the diagnostic move, and carries no evidentiary weight of its own. A small town: an authority figure is convicted in court; the community responds by slandering the victim and continuing to grant social standing to the convicted man. The legal system and the town substrate are each running their own stack. The legal system succeeds at universal-rule closure: standing was granted, evidence was processed, the verdict was rendered, the sentence was imposed.

The town succeeds at coalition preservation: the in-group authority figure was defended, the outside intrusion was named as such, the defector (the complainant) was sanctioned. Neither system necessarily fails by its own lights.

The failure relative to deep-time flourishing is the unowned conversion between them — no role in the town substrate owns importing the verdict, protecting the complainant's continued membership-standing, or sanctioning post-verdict retaliation. The same structure is worth testing against workplace HR vs staff culture, regulator vs industry, audit vs department culture, international tribunal vs national public, university discipline vs peer group, and whistleblower vindication vs industry blacklisting — each of which pairs a system that can render a verdict with one that controls whether the verdict costs the loser anything. None is worked here, and the pairs differ in whether the second system has a formal existence at all, which is likely where the analogy breaks.

The diagnostic move is to walk both stacks and ask which channel of conversion between them is unowned.


I. The twelve domains (layer addresses)

  1. Telos: What is the system for? Canonical failure: no owner of the purpose; drift; capture by proxy objective.
  2. Mechanism: How does it actually produce its outcome? Canonical failure: intent replaces causal model; words assumed to control behaviour.
  3. Response: What does the system make rational, cheap, or unavoidable for the next actor? Canonical failure: pressure routes through the cheapest channel — gaming, exit, substitution.
  4. Standing / carrier: Which telos-relevant claims, harms, benefits, anomalies, or consequences get a voice in the decision system? Canonical failure: one side has a carrier; the other side is silent and absorbs the cost.
  5. Measurement: What signal is treated as reality? Canonical failure: proxy becomes target; map detaches from territory; Goodhart dynamics.
  6. Stock ledger / accounting: Which stocks does the policy actually draw down? Canonical failure: hidden depletion masked by visible flow; unsupported or unmeasured effects silently treated as zero.
  7. Decision-frame compilation: Does the public-usable decision frame exist? Canonical failure: pieces exist scattered; the assembled artifact nobody compiles.
  8. Frame computation / uptake: Does the system actually compute with the frame? Canonical failure: parameterised reasoning is refused, captured, or masked as values.
  9. Decision: Who must choose, repair, or override — and how is evasion prevented? Canonical failure: diagnosis exists; no one is forced to act on it.
  10. Operational execution: Does the institution have the capacity to implement the repair? Canonical failure: smart fix demands competence the receiver lacks; result worse than the disease.
  11. Feedback: Does observed failure feed back into mechanism correction? Canonical failure: decorative evaluation; advisory reports that bind nothing.
  12. Reproduction: Does the system reproduce the capacity that made its outputs possible? Canonical failure: output survives; the generator-chain dies.

Layer number is an address, not a causal precedence rank. The twelve domains provide a scan order and a shared vocabulary. The case's actual dependency geometry — sequential, parallel-bonded, selector, allocation, substrate, or topology, each defined in §III under Where the chain is the wrong diagnosis — determines what is upstream, downstream, jointly binding, or incomparable.

A given problem rarely sits in one domain alone. The diagnostic move is to construct that case-specific dependency relation and ask which failed domain, or smallest joint set of domains, blocks the claimed outcome. A policy that has the right mechanism (1) and the right stock accounting (5) but no decision-side enforcement (8) may be blocked at Decision; a policy whose decision-side is healthy but whose operational execution (9) has been hollowed out may be blocked there. The vocabulary lets the post-mortem be specific without treating numerical adjacency as causation.


II. The domains, with corpus pointers

0. Telos — what is the system for?

The question. What is the system actually selecting for, explicitly or implicitly? An institution without an owned, articulated purpose is being optimised by selection pressures it does not see.

Healthy primitive. Explicit reference telos, viability constraints, named trade-off authority, and a public rule for incomparable choices; no hidden scalar objective is implied.

Failure family. No owner of the purpose; drift; capture by proxy objective; comfort-and-preservation as terminal value; multi-objective incoherence.

In this corpus.

1. Mechanism — how does it actually work?

The question. What rule, incentive, constraint, or architecture is supposed to produce the outcome? "We will pass a law about X" is not a mechanism; "the law changes the cost of Y, which causes actor A to substitute toward Z" is.

Healthy primitive. Explicit mechanism claim with named actor, changed constraint, expected response, target output, time horizon.

Failure family. Intent treated as causal force; legal text assumed to compile into operational behaviour; moralisation replaces computation.

In this corpus.

2. Response — what do agents do next?

The question. Once the rule changes, what does the next actor find rational, cheap, safe, or unavoidable? Policy lands inside an existing strategic landscape and triggers a response. The response is a property of the actor and the architecture, not of the legislator's intent.

Healthy primitive. Mapped response channels; predicted dominant response; counterfactual against status quo.

Failure family. Pressure routes through the cheapest channel — compliance gaming, formal substitution, withdrawal, exit, lobbying, reclassification, passive non-uptake.

In this corpus.

3. Standing / carrier — what can carry telos-relevant reality into the decision system?

The question. Which telos-relevant claims, harms, benefits, anomalies, or consequences become visible because they have someone or something to carry them into the institution that could act, and which remain invisible because no carrier or standing exists?

Healthy primitive. Standing for the silent class; explicit bearer of diffuse cost; statistical victim given a procedural voice.

Failure family. One side has a carrier (legally, organisationally, narratively); the other is silent. The silent side absorbs the cost. The carrier-equipped side writes the rules.

In this corpus.

4. Measurement — what signal is treated as reality?

The question. What does the system observe, and what does it treat as evidence of success or failure? Measurement is never neutral: once a measure is attached to reward, punishment, or legitimacy, the actors inside the system optimise the measure, not the underlying reality it was meant to track. Measurement and ledger failures are distinct and often chained: where a ledger entry is computed from a proxy, corrupting the proxy corrupts the entry, so the measurement defect has to be repaired first. That is a dependency in the case, not a consequence of 4 coming before 5 — and it does not run the other way round only.

A ledger can fail on quantities that were measured correctly and then omitted, mispriced, or booked to the wrong account.

Healthy primitive. Measurements that remain coupled to the underlying reality; proxy treated explicitly as proxy; audit path from metric back to territory; periodic recalibration when the relationship between proxy and reality drifts.

Failure family. Goodharting; proxy-target divergence; cargo-cult epistemology; metric-compliance replacing reality contact; map detaching from territory.

In this corpus.

5. Stock ledger / accounting — what gets counted as cost?

The question. Which capital stocks does this intervention draw down to fund the visible benefit, and are those stocks on a ledger anyone consults? Most of what a civilisation runs on is booked at zero by default; that booking decides what looks like a gain.

Healthy primitive. Explicit accounting posture for every identified load-bearing stock: measured value where supported and UNKNOWN where unsupported or unmeasured; stock, flow, and recovery horizon kept distinct. Possible but unidentified stocks remain a visible scope residual rather than an implied zero.

Failure family. Hidden depletion masked by visible flow; unsupported or unmeasured effects silently treated as zero; balance-sheet theft at civilisational scale.

In this corpus.

6. Decision-frame compilation — does the right decision-frame exist?

The question. Have the relevant academic substrate, statistical evidence, and policy considerations been assembled into a public-usable decision frame that a generalist can actually pick up and use? Three distinct objects often get confused: academic synthesis, institutional compilation outputs, and the publicly-pickable decision-frame artifact. The third one is the one that is frequently missing. Decision-frame compilation is the supply-side question; whether the frame is actually used once it exists is the Frame computation / uptake domain below.

Healthy primitive. Parameterised public frame with named variables, causal structure, an update rule, and a policy-evaluation test.

Failure family. The pieces exist; the assembled frame does not.

Repair-side analogue. Compilation has a repair-side analogue. A diagnosis may compile correctly into a public decision frame and still fail to compile into a native institutional artifact. The first question is content compilation: does the frame exist? The second is actuator compilation: does the frame land as the right kind of object — statute, reasons, guidance, record, register, contract clause, budget line, dashboard, audit trigger, parliamentary motion, or public essay — at the right binding strength? A correct frame routed to the wrong surface becomes an over-prescription, a decorative report, or an administrative impossibility. Content compilation supplies the diagnosis. Actuator compilation selects the repair vehicle. See §V Repair routing for the operational protocol.

In this corpus.

7. Frame computation / uptake — does the system actually use the frame?

The question. Once a decision frame exists, does the system actually compute with it — or does it convert the frame into slogans, factional ammunition, or moral cover? Compilation and computation are separable problems: a perfectly compiled frame can land in a discourse architecture that refuses to compute with it. The two failures call for different repairs.

Healthy primitive. Parameterised reasoning made procedurally consequential; disagreement attached to named variables; values separated from empirical claims; institutional teeth that make ignoring the frame expensive.

Failure family. Computation refused; empirical claim hidden as value disagreement; frame captured by faction; frame sloganised; public debate remains slogan-shaped despite the compiled artifact existing.

In this corpus.

8. Decision — who must choose, repair, or override?

The question. Once the mechanism failure is visible and the frame exists, who is forced to decide, and how is invisible evasion prevented? Diagnosis without a forced decision is decorative.

Healthy primitive. Repair-or-override loop with named owner; political override permitted but visible; no quiet decay.

Failure family. No one is forced to act; the warning is filed; the system continues. Or the decision is delegated until no owner remains.

In this corpus.

9. Operational execution — does the system actually implement the repair?

The question. Once a decision is made, does the receiving institution have the capacity, authority, and feedback loop to execute the repair without producing worse distortion than the original problem?

Healthy primitive. Implementation ledger with owner, trigger, and a movement test that distinguishes activity from result.

Failure family. Critique absorbed without repair; reform-form without transformation; smart mechanism failing because implementation capacity is missing.

In this corpus.

10. Feedback — does reality update the system?

The question. After the policy is enacted, does observed failure feed back into mechanism correction — or only into narrative? Most evaluation produces reports; very little produces correction.

Healthy primitive. Feedback is not complete when information returns. Feedback is complete only when returned information changes the system’s action set, opens a decision forum, or forces a reasoned refusal to act. Operationally: each observation channel must trace to artifact → owner → deadline → forum → response menu → public output → no-action explanation → named next carrier where action lies outside the instrument. A channel that stops at “monitor and reassess” is an alarm, not a feedback loop.

Failure family. Decorative evaluation; advisory reports that bind nothing; audits that observe but do not alter the mechanism; soft-control verbs (monitor, evaluate, develop, agree, recommend, increase transparency) that name the next institutional event implicitly when no such event is structurally required.

In this corpus.

11. Reproduction — does the generator-chain continue?

The question. Does the system reproduce the capacity that made its outputs possible — the apprenticeship, the lineage, the standards, the tacit knowledge? Output can continue for years after the generator is dead. The persistence is misleading: the corpse is still standing.

Healthy primitive. Live generator-chain; apprenticeship and intergenerational transmission; explicit standards; spore strategies for hostile environments.

Failure family. Output without generator; chain breakage; institutional shell surviving the competence that filled it; AI substituting for the practitioner-chain that would have produced the next generation of practitioners.

In this corpus.


III. Two navigational cuts: layer and gate

The Stack names the where of failure: telos, mechanism, response, standing / carrier, measurement, stock accounting, decision-frame compilation, frame computation / uptake, decision, operational execution, feedback, reproduction. A second cut names the where in passage: the route by which institutional intelligence becomes binding action. The two cuts form a coordinate system. The layer asks which functional domain is broken. The gate asks where, in the passage from "someone knows" to "the institution acts," the object stopped moving.

This second cut covers one geometry, not the whole corpus. The corpus also contains parallel-bonded faults, selector matrices, allocation channels, substrate stacks, and topology / feedback structures (see end of this section). The chain is the dominant grammar — the recurring sequential conversion that the most load-bearing recent essays instantiate — but it is not the master architecture.

The passage:

The diagnostic rule: identify the earliest dependency gate whose failure blocks passage of the relevant object. Downstream repair cannot substitute for the missing upstream dependency. More dashboards do not fix non-admission. More consultation does not fix powerless intelligence. More reports do not fix a missing execution ledger. If the upstream gate cannot be repaired directly, downstream work can still be preparatory, compensatory, or pressure-building — but it should be named as such, not treated as a cure.

The layer and the gate together locate a failure more precisely than either alone. “Layer 7 computation failure” says the institution refuses to compute with a frame that could bind it. “Production gate” says the bound was never created; “admission gate” says it existed but never became a procedural object. “Layer 4 measurement failure” says the system’s signal has detached from reality. “Anchoring gate” says that detachment blocks later binding, execution, and learning. The layer locates the substrate. The gate locates the stopped passage.

Binding has strength, not only status. The gate table asks a yes/no question — is anyone with authority constrained — and passing it is genuinely binary. What is not binary is how much. An admitted object can constrain an institution weakly, moderately, or heavily. Each substrate has a ladder of instruments. In law, roughly: reasons, then guidance, then agency duty, then statutory public duty, then parliamentary reporting, then constitutional duty. In software: warning, log, alert, failed test, deployment block, rollback trigger. In organisations: note, memo, policy, budget condition, audit finding, dismissal trigger.

Read these as rough bands, not as orderings that hold case by case — a statutory duty owed to an identifiable person outbinds a reporting obligation that is politically rather than legally enforced, and a paging alert outbinds a non-blocking test. What is robust is the direction: moving up a ladder increases ignore-cost, and it also increases administrative friction, jurisdictional exposure, and maintenance burden.

A repair can therefore fail in two opposite ways: under-binding, where the object creates no real response duty, and over-binding, where the object is routed through a heavier instrument than the institution, genre, or problem can carry. The Stack diagnosis names the missing conversion; the repair must still choose the lightest instrument that actually converts. The two specialisations of binding strength — Powerless Intelligence and Feedback Authority — treat the receiver-side and consequence-side of the same gradient.

Where the chain is the wrong diagnosis

The chain applies to sequential intelligence-translation. Several recurring corpus structures are not sequential, and the first-failed-gate rule misleads when applied to them:

The chain’s debugging register transfers well to sequential administrative passage. It transfers badly to live political contestation, recursive causality, simultaneous failure, and legitimacy contestation. Bad Equilibria Are Not One Thing explicitly says its five gates “are diagnostic axes, not mutually exclusive boxes and not a causal sequence.” Forcing those essays into the chain distorts their analysis.

This subsection is a map legend, not a master theory. The Stack gives the layer coordinate. The passage gates give a second coordinate for the intelligence-to-action corridor. Other geometries point to other coordinate systems. Reading a corpus essay correctly starts by asking which geometry it occupies — sequential, parallel-bonded, selector, allocation, substrate, topology — and then applying the diagnostic move appropriate to that geometry.

Chain plus distortion in practice

Real cases are rarely pure instances of one geometry. A case often has a dominant sequential passage while secondary geometries operate around the failed gate. A chain-only diagnosis can be locally correct and still under-repair the case: it identifies the blocked gate without scanning for what stabilizes the failure, where pressure routes when blocked, which bonded layers restabilize the failure, which reform vectors are attempted, which substrates are missing, or whether the gate is itself a routing topology.

The two-step diagnostic that fits most real cases is: locate the dominant passage failure (the earliest blocking dependency), then scan the failed gate for distortions.

A repair plan that fixes the dominant gate without addressing the distortions usually fails: the next case in the same domain reproduces the same failure through the same bonded layers, allocation channels, or substrate gaps. The mechanism test the corpus uses in practice now reads as two paired moves — gate repair plus distortion repair.

Reverse consequence: when the gate works correctly

A separate complement to the chain operates when the gate is not failing at all. Structural Residue covers cases where a gate works under its own rule but leaves a consequence causally live. This is the worked egress case for §IV Motion 3: the gate may be healthy but the consequence-exit channel is unowned, so the consequence routes outward without binding back as accountability.

The usual case is refusal: a claim is correctly excluded, and the consequence routes outward through other actors, scales, time horizons, or institutional channels. A second case is acceptance-by-design: a relief valve, exception, appeal, discretion clause, or safety mechanism correctly accepts the hard case but sheds processing load, litigation, delay, or discretion burden downstream. The gate is not broken in either case. The unowned object is the consequence of the gate working.

Repair therefore does not mean closing the gate; it means naming the downstream load, owner, capacity, and feedback path. The chain follows admissible signal forward through gates; structural residue follows the live consequence outward through carriers. A case can call for both diagnostics: a chain failure plus distortions plus persistent residue from earlier correctly-functioning gates that have been routing or shedding for years.


IV. The ownership heuristic underneath

One sentence keeps surfacing across the twelve domains and is worth preserving as the master ownership heuristic:

A system fails, relative to telos T, where T-relevant reality enters through a channel the system does not own.

Ingress without ownership creates blindness. Surface without ownership creates parasitism. Egress without ownership creates externalization.

Higher-resolution candidate. “Ownership” is the Stack’s compressed first-pass question, not a complete theory of conversion. A named owner is neither necessary nor sufficient: distributed protocols can convert without one, while a named office can lack grounding, legitimate authority, capacity, calibration, correction, or continuity. The current candidate under hostile-case testing is: a persistent telic system fails, relative to a declared and separately evaluated reference telos T, where a load-bearing T-relevant conversion cannot reliably produce T-preserving adaptation.

The corresponding contract asks whether the conversion is grounded; authorized through an accountable carrier or control topology; actuated with sufficient and proportionate force; verified, contestable, and re-entered on failure; and maintained and composable under load and across time. Capture, endogenous overload, and symbolic substitution remain cross-contract distortions. This candidate does not yet replace the ownership line or the ingress / surface / egress triad.

That first sentence names the original ownership heuristic; the second states the full triad. The same conversion question recurs in three motions, and the rest of this section takes them in order. They remain especially productive for governance, but not every conversion defect is necessarily an ownership defect; the Stack’s twelve domains are the substrates on which either the ownership triad or another contract obligation can fail.

Motion 1 — Ingress. Reality arrives: a harm occurs, a cost lands, an anomaly shows up, a signal is generated somewhere the system could in principle detect. Something has to own the channel it arrives through, or the arrival never becomes information the system holds. The diagnostic question for ingress failure: which T-relevant reality is entering, and through what unowned channel? Failure of the first motion produces blindness. This is the motion the master heuristic above states, so its essay family is §II itself — every layer's corpus list is a list of ingress failures at that layer. The Asymmetric Carrier Problem, The Attenuation Layer and The Information Gradient come closest to treating the motion as such.

Later paragraphs call it channel failure when the emphasis is on the conduit rather than the direction; the two words name the same motion.

Motion 2 — Surface. Telic systems contain surplus: money, discretion, legitimacy, trust, attention, debt capacity, exception space, optionality. Surplus not owned by a telos-preserving constraint becomes a feeding surface. Actors attach to the surface, build justifications, harden them into offices, budgets, contracts, and metrics, and reproduce past correction. The diagnostic question for surface failure: which T-relevant surplus is unowned, and which carrier prevents capture? Failure of the second motion produces parasitism.

Full Accounting, Telocracy, and The Dominant-Player Constraint develop the surplus-side ownership question; the cross-layer overload and capture conditions below are specific failure modes of this motion at aggregate and rule-setting scales. Surface parasitism is the earlier ecological form and capture is what it hardens into: feeding actors reproduce, gain institutional position, acquire capture levers, and then use those levers to keep the surface open.

Motion 3 — Egress. A decision is made, an action taken, a cost incurred. The consequence must return through an owned channel to bind some actor — the decision-maker, an oversight body, a successor administration, a payer of record.

If it exits through an unowned channel, it leaves the decision system entirely: future taxpayers, displaced workers, depleted trust, unbuilt alternatives, deteriorated demographic or institutional capital, and knowledge that drains into informal carriers because no formal compiler exists. The diagnostic question for egress failure: which T-relevant consequence is exiting, and what carrier should hold the return path? Failure of the third motion produces drift: the system continues making decisions whose consequences arrive on parties too diffuse, delayed, or fragmented to constitute a decision-grade counterparty.

Structural Residue (a gate works correctly but the consequence routes outward), The Asymmetric Carrier Problem (silent payer absorbs cost), The Tyranny of the Present (consequences land on future cohorts), and the cost-displacement family in Full Accounting treat this motion at substrate-specific resolution.

The three motions are not independent. Channel failure produces blindness — the system does not feel that surplus is being eaten. Surface failure produces feeding — actors organize around the unowned surplus. Egress failure produces drift — the costs of the feeding leave the decision system without binding back. The three compose into a self-preserving loop: blindness permits feeding; feeding externalizes costs; externalized costs do not return; non-return preserves the blindness. This is the mature predatory form, and §V lists four other attractors a real case can land on instead — including ones with no organised feeders at all.

The corpus essays at each layer give the substrate-specific repair vocabulary; the three motions give the geometry that holds them together.

The twelve domains are twelve addresses at which a T-relevant conversion can fail. Ownership is the most recurrent governance question, which is why the existing layer-specific shorthand remains useful: Unowned purpose produces telos gaps. Unowned mechanism produces intent-substitution and moralised causal disputes. Unowned actor response produces the four-channel pressure routing. Unowned harm produces silent-side absorption. Unowned measurement produces cargo-cult epistemology and the severed map. Unowned cost produces false-zero accounting. Unowned decision frame produces non-compilation. Unowned computation produces the Calculemus slogan war. Unowned decision produces powerless intelligence. Unowned repair produces institutional containment. Unowned feedback produces theatrical accountability. Unowned generator-chain produces sterile generativity.

The first diagnostic question for any failure is: which load-bearing T-relevant conversion is failing, and what evidence makes that defect part of the case’s minimal causal cut set? The ownership heuristic then asks: which channel, surface, or consequence lacks an accountable carrier or control topology, and under what legitimate authority could that relation be repaired? The "T-relevant" qualifier is non-optional: change the telos and the verdict on the same events can change.

Premise-correction ownership. One further cross-cutting condition, listed separately from the four below because it is about what the other four are applied to rather than a fifth way for a channel to fail. A system can own its procedures, metrics, and implementation channels while leaving premise correction unowned. When adverse reality returns, the error is absorbed somewhere, and the load-bearing premise stays insulated by being absorbed anywhere else.

The diagnostic tell is the absorption question: when reality pushes back, which of six categories receives the error — the premise itself; the auxiliary apparatus built around it; execution (it would have worked if done properly); the reporter's standing (they were not entitled to raise it); the admissibility of the evidence (it does not count, or falls outside our domain); or the world (noise, bad luck, exceptional conditions)? Only the first is premise correction. The other five are all ways of not doing it.

The discriminator is the direction of risk — a healthy system absorbs an anomaly by increasing its future contact-risk (the patch exposes the premise to a new way of being wrong); a premise-insulating system absorbs it by decreasing premise-risk while preserving status. The most self-serving route is rejecting the reporter as unauthorized rather than the evidence as false — a Feedback Authority admissibility failure, but one that fires against the system's model rather than against its conduct. Premise and conduct are not Stack domains: the distinction is in what the inadmissibility protects, and it cuts across Layers 4, 7 and 10 rather than adding a thirteenth address.

Four conditions cut across all twelve layers rather than living at one.

Cross-layer overload. Accumulated binding mass can exceed the system’s action capacity, so each owned channel itself becomes a maintenance burden the institution can no longer carry. Cancer Failures names this cross-layer pathology — the layers are individually owned but their aggregate weight is unowned — and pairs against the conversion-failure family the rest of the stack diagnoses.

Cross-layer under-binding. Each owned channel either generates conversion capacity or fails to. Steering Power (Capacity × Coupling × Salience) names the macro-amplitude form; Powerless Intelligence (Authority × Resource × Answerability) names the receiver-side specialization; Feedback Authority grades the consequence the institution bears once conversion path exists; The Refusal to Compute names the active strategy to suppress conversion by refusing to produce or admit the bound that would activate obligation. The two constructs above share a multiplicative, any-zero-kills-the-product structure, and the corpus has found it wherever a conversion needs several independent things to be simultaneously true.

Whether it is the general form at every layer, or the form that two well-worked cases happened to take, is open — the test is a layer where the factors substitute for one another rather than gating each other. Cross-cutting precondition: this is the inverse failure family to Cancer (under-binding per channel; Cancer is over-binding aggregate).

Cross-layer capture. One actor can choose the rules, evidence, forum, timing, closure condition, and enforcement substrate of a contest that affects others. The Dominant-Player Constraint names governance as the architecture that prevents this concentration of upstream control. Most governance-arc primitives block specific capture levers; the cross-layer condition is that any owned channel can be captured if no primitive blocks the relevant lever, and no primitive maps to exactly one lever — each blocks several, and several are needed to block any one. A primitive-by-primitive audit therefore tends to understate what remains open, by a margin that depends on the case.

Cross-layer symbolic substitution. A system can populate any layer with an artifact that represents ownership without carrying the causal role that ownership would require. A declared right may lack an enforcement carrier; a transparency mandate may lack a publication surface; a procedure may lack a consequence; a monitoring duty may lack a response path; a constitutional protection may lack a re-entry channel into decision.

The artifact appears in the institution’s official compilation, but the institution’s action set is unchanged or changed only at a weaker level than the artifact implies. This is not simply overload, under-binding, or capture — it is a prior type question that can precede or co-occur with all three: a symbolic substitute can mask under-binding, help capture, or accumulate into overload.

Symbolic artifacts are not causally inert: they coordinate, legitimate, signal, and create focal points. The failure occurs when those symbolic effects are treated as if they were enforcement, correction, measurement, allocation, or execution — that is, when the artifact carries less or different causal force than the role it is invoked to perform.

The connection to Feedback Authority is direct: the substitution pattern is the channel-installation version of selling one binding-force profile (procedural, consequential) while installing a lower one (decorative, advisory). The diagnostic test: what action set changes, who must act differently, what record or trigger is created, what consequence follows if nothing happens? If the answer is only that the institution has named, affirmed, announced, or represented a channel, the channel is symbolic rather than owned.

Mechanism Space develops the underlying geometry (semantic space vs mechanism space); Laws Are the Wrong Abstraction §VII gives the rights-specific application (“a right without a mechanism is a wish”); The Halting Problem of Law §II gives the legal-text-as-code application (syntactic vs semantic). The substitution diagnostic is what unifies them across layers.

Two sibling child-families specialize the parent diagnostic by what is being substituted. The Causal Talisman (and the broader Talisman cluster) names the substitution of legitimacy-bearing weight for analysis — a morally protected cause-name or category discharges analytical pressure without any formal institutional artifact required. Nominal Execution names the substitution of form/status-bearing availability for execution — a formal artifact (right, statute, certification, procedure, model) is invoked as if it had carried the institutional fact it names. The two surface at different points: weight-substitution can operate without any formal token; form-substitution requires the token and credits its presence.


V. Using the map

The page is built to be a working object, not an essay to be read once. Four intended uses:

Triage. For any concrete failure — a policy that obviously isn't working, an institution that obviously isn't delivering, an organisation's capability that is obviously eroding — walk the twelve layers in order. Where is the binding failure? Multiple layers usually contribute, but one is usually load-bearing for the current state. Naming the layer is the first move; the corpus essays at that layer are the second.

In every layer walk, run the symbolic-substitution check before the under-binding diagnosis: distinguish the owned channel from its symbolic substitute, ask what action set changes, who must act differently, what record or trigger is created, what consequence follows if nothing happens. If the answer is only that the institution has named, affirmed, announced, or represented a channel, the repair has not yet reached mechanism level — and a subsequent under-binding diagnosis will mistake an absent channel for a weak one.

The loop named in §IVblindness permits feeding; feeding externalizes costs; externalized costs do not return; non-return preserves the blindness — is the mature predatory attractor, but it is not the only attractor a real case lands on. Four conversion-failure attractors and one wrong-repair attractor recur, and they take different repair routes. Naming the attractor is the second triage move after naming the layer.

The wrong-repair row is the discipline against the corpus’s own favourite move: install an owner. Ownership is the repair when ingress, surface, or egress is unowned. It is the wrong repair when the binding mass is already the failure, when the proposed owner is captured by the surface it must judge, when the trigger becomes its own bureaucracy, or when the trace becomes theatre without re-entry. Each repair-route cell above is correct only when the layer diagnosis has cleared the wrong-repair test as well. When Ownership Is the Wrong Repair gives the full family — capture, theatre, dashboarding, exhaustion, cancer — the repair-compilation test, and the case where a weak actuator is the strongest one legitimately available.

Cross-referencing. When two essays in the corpus seem to overlap but are not the same thing, the layer assignment usually clarifies why. Non-Compilation at the Compilation layer (6) and Calculemus at the Computation/adoption layer (7) treat the supply side and demand side of the same problem, but at different layers — Compilation asks whether the frame exists; Computation asks whether the system uses it. Cargo Cult Epistemology at the Measurement layer (4) and Full Accounting at the Ledger layer (5) also treat related but distinct failures: measurement asks what signal counts as evidence; ledger asks what stock counts as cost. The layer assignments make the distinctions visible.

Gap-finding. Where a layer has fewer essays than its weight in the failure stack would predict, the gap is informative. Measurement (4) was freshly separated from Compilation in earlier versions of the stack; the dedicated Layer 4 anchor is The Measurement Anchor, which gathers the Goodhart family explicitly.

Computation/adoption (7) has its operational anchor in The Refusal to Compute, which supplies the four-gate test (relation, bound, obligation, unbounded substitute) that distinguishes refusal from honest non-computation and operationalizes Calculemus’s broader argument. Reproduction (11) has strong coverage on chain breakage and weaker coverage on chain formation; a How Generator-Chains Form essay is the non-trivial missing half. The stack is a working map; the gaps are part of what the map is for.

Repair routing. A Stack diagnosis is not yet a repair. After the failed layer and gate are named, the repair must be compiled into a native institutional artifact. Three questions control the compilation. First: what object is needed — telemetry, reason-giving, evaluation, intervention, escalation, capability, or public argument? Second: which authority owns that object — the target instrument, a related carrier, a different institution, or no institution yet? Third: what binding strength is native to that surface — explanation, guidance, agency duty, public statistic, statutory duty, parliamentary trigger, or constitutional rule?

The recurring error is to discover the right risk and prescribe the wrong actuator. A Measurement failure does not automatically require a statutory report. A Feedback failure does not automatically require parliamentary review. A Capability failure does not become solvable because a contract asks suppliers for more paperwork. More binding is not always more repair. The repair is correct only when the object, owner, surface, and strength match the failure. Risk discovery is not actuator selection.

Pitfall under repair routing: observability over-binding. The most common wrong repair after a Measurement, Feedback, or Learning diagnosis is to add a dashboard, report, audit, ledger, or statutory review duty at the heaviest available level. The diagnosis may be correct and the repair still wrong. Observability is administratively respectable, so it expands beyond its native attachment point.

The test is: what must be observed, by whom, at what granularity, for what decision, and with what consequence? If the answer is operational telemetry, a public statistic or decision field may be enough. If the answer is policy evaluation, reasons or a follow-up section may be the native surface. If the answer is intervention, a report without a decision duty is only theatre. More visibility is not repair unless it lands on the decision that needs the visibility.

The cross-cutting positive synthesis is What Bureaucracy Is: the runtime of traceable discretion, decomposed into five recurring functions (admit, authorize, assign, remember, contest-or-close) that the Stack’s layers and the corridor essays specialize. The Stack reads failure-relative; What Bureaucracy Is reads function-relative.

Two further cross-stack disciplines sit alongside the Stack rather than inside it. Hardening Devices is the substrate-export discipline: the Stack’s failure types are substrate-general, but the carriers that implement repair — records and files in institutions, weights and eval artifacts in AI, identity commitments and habits in minds, rituals and taboos in cultures, contracts and audited accounts in markets — are substrate-specific. A claim that a Stack-layer failure-type generalizes across substrates must pass the substrate-translation discipline before it ships.

Inside the Closure Machine is the practitioner-true counterpart: the abstract Stack architecture is right, but the unit of analysis inside an actual ministry is not the decision but the durable position, and the governance-arc primitives are relocated and constrained when read through the pre-clearance machinery that produces durable positions. Both essays are reading disciplines on the Stack rather than additional layers in it.

The stack is not exhaustive of the corpus. Several essays are foundational (the physics and architecture beneath the stack) — The Four Axiomatic Dilemmas, The Physics of Intelligence, The Physics of Moloch, The Thermodynamics of Power, Telic Systems (the corrective-architecture class the stack applies to; the five-property diagnostic decides what counts), The Sovereignty Ladder (the nine-rung taxonomy of telic systems, prion to civilisation), and The Three-Layer Architecture (the reactive/constitutional/strategic layering that recurs across scales).

Others are domain-applied (AI alignment, Finnish-specific institutional analysis, the alignment-via-physics treatments). Others are about the craft of writing the essays themselves (Essay Engineering, Optimal Prose, How I Work). Those are listed on the main essays index rather than here, because the stack is a failure-mode taxonomy for goal-directed systems and they sit alongside it rather than inside it.


The argument in three sentences. Institutional failures sort, in this corpus's experience, into roughly a dozen recurring kinds, and within each kind the failures look much alike across very different domains; other substrates need the translation §V describes before the claim carries.

The vocabulary of the stack lets a post-mortem be specific — this failed at the measurement layer, not the ledger layer; this failed at the computation layer, not the compilation layer — instead of devolving into "the system is broken" or "the people are corrupt." The corpus organises by layer because the layer is where the diagnosis lands; where the repair goes is a second question, answered by §V Repair routing, and confusing the two is the error that section exists to prevent.


Related references:

Sources and Notes

Status of the partition. The twelve-layer scheme is a working taxonomy, converged on through internal dialectical work over the corpus. An earlier version of this page used a ten-layer scheme; the current revision splits Measurement out of Compilation and splits Computation/adoption out of Compilation to preserve distinctions the corpus has deliberately made (Non-Compilation vs. Calculemus; Goodhart-family failures vs. Full-Accounting failures). The partition is not claimed to be the periodic table of social science.

Other partitions exist — Hirschman's exit-voice-loyalty, Ostrom's design principles for the commons, Tilly's repertoires, the political-economy literature's principal-agent stack, the safety-engineering Swiss-cheese model — and each cuts the same territory differently. The defence of this partition is pragmatic: it organises the corpus, it produces non-empty rows at every layer, and it makes the cross-layer interactions legible. A better partition that did the same work would be welcome.

The master ownership heuristic and current candidate. "A system fails, relative to telos T, where T-relevant reality enters through a channel the system does not own" remains the most compressed ownership form the corpus has converged on. An earlier version omitted the "relative to telos T" qualifier; the qualifier is non-optional because the Stack is telos-relative. The line is now explicitly treated as a first-pass heuristic rather than the complete genus of system failure.

The higher-resolution candidate under hostile-case testing is: "A persistent telic system fails, relative to a declared and separately evaluated reference telos T, where a load-bearing T-relevant conversion cannot reliably produce T-preserving adaptation." Ownership is one obligation in that contract; no replacement is ratified by this page. Where existing essays cite "the structural law," they continue to point to the ownership line unless and until a corpus-wide revision says otherwise.

Scope discipline (strong / by translation / weak / invalid). The Stack applies strongly to institutions and institutionalised systems (ministries, agencies, courts, public consultations, welfare systems, permitting regimes, universities, professional discipline systems, legislative mechanisms, infrastructure decision systems). It applies by translation to software systems, AI systems, markets, cultures, minds, and organisms — but only after substrate-native hardening devices are substituted for institutional ones (records become traces or evals; feedback authority becomes deployment-gate or rollback-trigger; reproduction becomes model lineage or transmission ritual).

It applies weakly to isolated actions, reflexes, one-shot decisions with no future state, purely physical processes, simple tools, and systems with no memory or correction loop. It is invalid when: (a) no telos is declared, (b) the local telos is treated as morally final, (c) a regularity that holds only for a particular institutional arrangement is treated as one that holds for any telic system, or (d) a sequential-chain diagnosis is forced onto a parallel-bonded, selector-matrix, allocation-routing, or topology/feedback structure that requires a different geometry.

Three failure types. The Stack must distinguish: telos-misalignment failure (the system executes well but its telos itself fails the meta-telos — the village game running correctly while depleting substrates that deep-time flourishing depends on), execution failure (the system has an acceptable telos but fails at one of the eleven lower layers — the ordinary Stack use), and multi-system collision failure (multiple systems each succeed locally but jointly produce higher-order failure because no one owns the translation between them — the court closing the case while the town reopens it). The third category requires a distinct cross-system primitive, not the Stack alone.

Adjacent maps. Full Accounting and the Capital Stocks reference page work the ledger layer (5) at higher resolution. The Layer Walk is the operational sibling to this page: the procedure for taking a real failure and walking it through the layers this page lists. The Mechanism Analysis defines the pre-enactment legislative artifact; How Mechanism Analyses Are Made defines the production discipline behind it. (All five listed under Related, above.) The full essay list on the articles index is organised by topic cluster rather than by layer, and remains the canonical entry point for readers who do not yet have a specific failure in mind.

Known under-treatments and open writing slots. Measurement (4) and Computation/adoption (7) were the freshly-separated layers; both have dedicated anchors — The Measurement Anchor at Layer 4 and The Refusal to Compute at Layer 7. Feedback (10) is filled by Feedback Authority. Reproduction (11) has solid coverage on chain breakage but weaker coverage on chain formation — a How Generator-Chains Form essay is the non-trivial missing half.

The actuator-compilation discipline (the second operation after diagnosis: compiling the diagnosis into a native repair artifact with the right owner, surface, and binding strength) is currently distributed across §V Repair routing, the binding-strength gradient at the Binding gate, the Structural Residue acceptance-by-design expansion, and the Layer 6 Compilation repair-side analogue paragraph; the companion essay When Ownership Is the Wrong Repair consolidates it, with the repair-compilation test and the legitimate-ceiling distinction. (These four are also listed under Related, above.) These gaps are flagged here so readers can know what is missing rather than assuming silence is consent.