A governor sets how much authority the next action carries by reading how far realized behavior has moved from what the system was assured to do. That reading is taken in particular channels. Whether a given failure is visible at all is a property of the failure and its relationship to those channels, not a property of the governor.
Divergence is measured in something.
Two families of signal carry most of what a runtime control can see.
The first is agreement. A system with several independent sources for the same quantity can be asked whether they still say the same thing. When agreement collapses, something has moved that reaches all of them at once.
The second is magnitude. A system with a reference for what a quantity should be can be asked how far the realized value sits from it. When the residual grows, something has moved in the source that produced the value.
Those two are silent in different places, and the places do not overlap by accident. They are opposites.
The failure that moves nothing.
Take a fault that lives in one source relative to the estimator consuming it. A single position input drifts. Every other source is still correct, and because they are correct they still agree with each other. The agreement signal reads healthy, and it reads healthy accurately. Nothing common to the sources happened. The residual against the estimator carries the entire fault, and it can be enormous while agreement sits flat.
Reverse the case and the ordering reverses with it. A disturbance that corrupts every source at once, a spoofed reference, a jamming source, a clock or power fault, a shared vibration, leaves each source internally plausible while their mutual agreement falls apart. Now agreement carries the fault and the residual against any one source understates it.
A governor reading one family and not the other is not degraded on the class it cannot see. It is clean. It reports a healthy assessment, issues the widest grant it has, and the run proceeds with the control fully behind it. The same forward look that lowers authority on a step whose present trust reads higher is only as wide as the channels it reads.
The pattern is not particular to sensors. An agent whose retrieved context has been corrupted through one upstream source emits tool calls that are internally consistent, arrive at the expected rate, and satisfy every check written about the shape of the call. The corruption sits in one input relative to the world. The channels watching the agent's own behavior are exactly the channels the fault leaves alone.
Choosing the observable.
When a signal fails to separate a fault class there are two available responses.
One is to keep working the number. Move the threshold, normalize differently, add channels, try another window, and stop when a separation appears. That procedure terminates eventually, because with enough freedom something always separates on the sample in hand.
The other is to ask whether the fault physically perturbs the quantity being measured. If the mechanism says it does not, the null is the correct answer and the search should end there. Adding channels helps when the fault is common to them and independent noise averages down. Twelve more instruments the fault never touches contribute twelve more instruments worth of noise.
A control tuned until it separates on a corpus where the mechanism says it should not have is fitted to the answer, and it carries that fit into production as confidence. The honest move is to name the fault class first and the observable second, and to accept the ones with no observable as gaps rather than as tuning problems.
Coverage belongs in the envelope.
The declared envelope is where the governor's reference lives, and coverage belongs in it beside the bounds. For each hazard the system is exposed to, name the measurement that carries the evidence of it developing. Where no measurement carries a hazard, that is a stated gap in the declaration rather than a silence in the assessment.
A stated gap has a treatment. Actions whose failure mode falls in the gap start from a lower grant and stay there, because the governor has nothing to positively assure them with. The failsafe direction already holds that an uncertain forward look grants less. A class the forward look cannot observe at all is the limiting case of that rule, not an exception to it. What the governor cannot observe has to be priced as withheld authority rather than assumed clean.
Written that way, coverage becomes a property the party declaring the envelope owns and can be held to, and the governed system cannot widen it from inside the run.
What the safety case has to say.
For a certification reader the question is asked one hazard at a time. Which measurement carries the evidence that this hazard is developing. What does the control do when that measurement is quiet. A quiet channel and a clean system produce the same reading, and only the declaration distinguishes them.
The EU AI Act high-risk obligations fall on December 2, 2027 for standalone systems and August 2, 2028 for AI embedded as a safety component, and they include risk management and logging. A logging duty records what the chosen channels saw. It says nothing about the classes those channels were never able to see, which is where the assurance argument has to speak instead. SR 26-2 took effect on April 17, 2026, placed generative and agentic AI outside its scope, and pointed institutions at existing model risk practice. That practice knows how to challenge a number a model produced on data the model covers. The failure examined here produces no number to challenge.
Detectability is a property of the fault class relative to the channels a control reads. A bound on what an action may reach never had to recognize anything first, and that is the part of the argument that survives a quiet channel.
What we are building.
Wayfinder Systems Group builds a runtime governor. It sits above control and below intelligence, sets how much authority a system is granted on every action against a safety envelope declared before the run, and bounds autonomy so the system acts only inside what it grants, through a path it cannot step around. The envelope states what the governor can observe as well as what it will allow, so a hazard with no channel behind it is answered with a lower grant instead of a clean report. Every grant it issues is signed onto a tamper-evident chain as it happens. We call her Velma.
Thirty minutes. Architecture, not sales.
A conversation about which hazards in your deployment have a channel behind them, which do not, and what the grant should be on the actions that fall in the gap.
JonathanLuethke@WayfinderSystemsGroup.com
