A vehicle controller logged its own performance at 100 percent nominal. A governor watching the same 1.94 million timesteps of NVIDIA PhysicalAI telemetry flagged one moment in five where that self-report could not be cited as evidence.
The governor never asked the controller how it was doing. That is the design, not an accident of it.
The two slots.
The doer/checker architecture splits an autonomous system into two parts. The doer is the capable component, hard to validate because it learned its behavior. The checker is the conventional component that holds the safe operating envelope at runtime. The framing comes from Philip Koopman's work on autonomous-system safety, and it is the cleanest statement of the problem. Let the capable but hard-to-validate component do the work, and place a component you can actually argue about between it and the world.
A runtime governor is a checker. It sits beside the model that acts, scores each action, and sets the authority that action carries before it executes.
Hard veto, or continuous authority.
There are two ways to build the checker, and they sit at opposite ends.
At one end the checker is a hard veto. The doer is untrusted. The checker holds a fixed envelope and blocks anything outside it. The whole integrity argument lives in the checker, which is conventional and can be taken to the highest assurance level on its own.
At the other end the checker's authority is continuous. It does not only block. It scales how much the action is permitted to do as measured trust moves. The moment the checker grants partial authority instead of a binary stop, the doer's integrity is back inside the safety case. A slightly trusted doer and a slightly trusted checker add up to a safe system only if you can argue, at high rigor, that they do not fail together. In automotive terms that is ASIL B(D): two B-level elements carrying a D-level decomposition.
The common mode.
On ASIL B(D), common-mode failure is the limit to safety. Two elements that each look adequate are worth nothing together if one cause takes both down at once. So freedom from common-mode failure stops being a footnote. It becomes an ASIL D requirement, at full rigor, on both elements.
Decomposition does not make that requirement go away. It relocates it. The independence claim, the argument that the doer and the checker cannot fail for the same reason, now carries the entire D-level weight. The two B-level elements are the easy part. The freedom-from-common-mode argument is the safety case.
What closes by construction.
One common mode closes at the design level, and comes off the list you re-argue per deployment.
A checker that reads the doer's self-report shares a failure with it. If the doer is confidently wrong, and the checker's trust is a function of the doer's confidence, both move together, and the checker raises authority at exactly the wrong moment. So the checker's trust must not read the doer's self-report at all.
The governor computes trust from expected-versus-observed divergence. It compares what an action implies against what the world returns. The doer's own confidence is not an input. A controller reporting 100 percent nominal cannot raise its own authority, because its report is not in the calculation. That is why the governor disagreed with the controller one moment in five. The two cannot fail on shared confidence, because there is no shared confidence to fail on. That mode is structural. It does not get re-argued on the next deployment.
What stays owed.
The rest of the freedom-from-common-mode argument is still a D-level argument, and it is owed in full. Shared sensors. Shared power. A single environmental cause that corrupts both the action and the measurement of the world it is checked against. The independence of the divergence measurement itself. None of that is closed by the architecture. The architecture buys one narrow structural win and leaves the rest of the safety case where it was.
This is the honest scope. A single common mode is off the table by design. Everything else is per deployment, and it is the highest-integrity part of the work.
The record.
The governor signs a per-decision record. Among other fields it holds the moment-by-moment divergence between what the doer claimed and what the world returned. That is runtime evidence of when the doer and the checker disagreed, and by how much.
Whether that evidence carries weight toward a freedom-from-common-mode argument, or whether independence has to close entirely at design time and the runtime record is only ever a forensic artifact, is an open question. It is the right question to be putting to the people who write the safety-case standards.
What we are building.
Wayfinder Systems Group builds the checker that sits in the decision path. It scores each action against versioned rules, sets the authority the action carries, holds the action for a person when the rules require it, and signs every decision onto a tamper-evident chain. It does not retrain the model or redesign the autonomy stack. It sits above control and below intelligence. Patents held in The Wayfinder Trust. We call her Velma.
Thirty minutes. Architecture, not sales.
A conversation about where a checker's authority should be continuous, where it has to be a hard veto, and which common modes close at design time versus per deployment.
JonathanLuethke@WayfinderSystemsGroup.comVocabulary note: the doer/checker architecture and the safe-operating-envelope monitor come from Philip Koopman's published work on autonomous-system safety and UL 4600. The ASIL decomposition language is ISO 26262.

