The Finality Kernel
The part that does the computing. Give it what the work had to prove, the typed evidence, who has authority, the current state, and the exact action being asked about. It returns three things: a Finality Account (the full case file), a Finality Verdict (the answer), and a reliance license (who may act on it, for what, and until when).
Division of labor
Governance supplies the rules. The kernel computes.
The kernel does not invent requirements, choose a route, approve itself, or perform the outside action. The four stages below are the pipeline around it; only the last is the kernel’s. Around it, Governed Multi-Route Selection (GMRS) governs route eligibility, Constrained Policy Reinforcement Learning (CP-RL) may rank eligible routes, and the Mechanistic Conflation Engine (MCE) may propose controls for independent approval. The verifier, the Four-Corners Test™, the trust boundary and Continuous Finality provide independent checking, reconstructability and current validity.
Admit
Authority is checked, the list of requirements is fixed, and what the decision applies to is declared. A list shortened by the caller is refused, not passed.
Route
GMRS selects an eligible route within the work’s risk level and budget. With no eligible route, the correct output is a hold that names what was missing.
Execute
Execution produces typed evidence as a by-product, not as an afterthought assembled later.
Compute
The Account assembles; the Verdict is the lowest grade across the required list; a claim license bounds what may be said and a reliance license names who may act.


Conservative composition
One failed obligation blocks the whole result.


The verdict is the lowest grade across every required obligation. One blocked obligation blocks the whole result, no matter how strong the rest is. An obligation that does not apply is left out.
Adding a requirement can never improve the aggregate
Improving the evidence for an existing one can. The direction of travel is fixed.
Strength on one axis may not compensate weakness on another
A deliberate design rule.
Ceilings hold
No volume of lower-class evidence aggregates upward into a stronger class, or into authority.
The ceiling rule has a plain reading: a thousand log lines do not become an attestation, a thousand attestations do not become an independent observation, and no volume of any evidence class becomes authority. Composition may weaken an answer, never launder one upward: the quiet rule that makes bad news wins safe to automate.
Degradation
Degrade selectively. Keep the rest running.
When evidence ages, an observer fails or a provider degrades, the composition forces no choice between ignoring it and halting everything. The failing obligation becomes UNKNOWN and is named. Where a compensating obligation was declared in advance, is independent of what failed, and is itself discharged, the verdict recomputes to DEGRADED, reliance narrows to the exact decisions affected, and work whose roster is undamaged proceeds. Where there is no such compensating obligation, the verdict stays at the lower grade.
Selective degradation, targeted quarantine and computed recovery are Continuous Finality in day-to-day operation: resilience built into the rules, not an add-on.
People authorize. They do not edit the verdict
Humans set policy, hold exception authority, supply domain judgment, resolve contested decisions and escalate. A human approval does not become the verdict either. It enters as one more piece of evidence, and the verdict is computed again.
Verification cannot mutate state
Verification runs as a separate role that provably cannot change anything, and when producer and verifier disagree, the result is a stop, not a pass.
An exception is an object, not an override
Held, typed, explained, with the missing obligation named, converting the missing obligation from an argument into a finding.
No surface may grade its own work
A connector that produces evidence about outputs its own author generated is a self-report dressed up as evidence, and is either separated or capped accordingly.
A precise claim
Exactly what the kernel establishes.
That the computation, decision, action, claim and reliance process was governed to an exactly declared profile and remained valid at the moment of reliance. That is a claim you can hand to an auditor, a regulator or a counterparty, and they can recompute it.
The kernel treats what it cannot see honestly. Anything that could not be observed stays a recorded unknown. Not-observed is never converted into did-not-occur.
Not observed≠Did not occur
A check that could not run≠A check that passed
Next steps
The kernel computes. The other objects declare, discharge, bind and keep current.
It computes. The roster declares, the evidence discharges, the licenses bind, and Continuous Finality keeps the answer current.