# Governed AI Development: The Glossary


*This glossary speaks the practice register. The GAD Formal Specification defines the exact technical floor for every term that carries a conformance meaning; where the two differ, the specification governs formal claims.*
**Brandon King · Atlas North Institute · July 2026**

The vocabulary of the discipline, defined once, tool-agnostically. A term used here names a concept, not a product feature. Where a reference implementation exists, it implements these definitions; it does not own them.

---

## The work and its contract

**Frozen plan.** The contract for a unit of governed work: a dependency graph of tasks, validated and hash-stamped before any agent executes. Once frozen, the plan is a fact independent of anyone's memory, and every later claim about the work is measured against it. Changing a frozen plan is not an edit; it is a succession.

**Node.** One task within a frozen plan: an obligation with a description, a scope fence, and at least one done-test. A node with no done-test is not governable and is rejected at the door.

**Done-test.** The machine-checkable definition of done for a node, stated as observables: a command exits zero, a route returns a status, a file exists with specific content. "It should work better" is not a done-test. If the observable cannot be stated, the work is not ready to be contracted.

**Succession.** The governed way a frozen plan changes: a new plan version supersedes the old under human authority, with the change recorded. Succession preserves the contract's integrity; erosion (quietly weakening checks until they pass) destroys it. The discipline permits the first and exists to prevent the second. The Formal Specification also governs its own amendments through a distinct, signed specification-succession procedure; the two successions share a name and nothing further, and neither substitutes for the other.

**Scope fence.** The permitted execution surface declared for a node; in the current software profile, the surface is expressed primarily as file paths. The engine observes the touched surface and evaluates it against the declared boundary after the session reaches quiescence; an implementation may additionally enforce the boundary preventively during execution, but the protocol claim is observation and evaluation, not universal prevention. Three things bear the name and must not be conflated: the declared permitted scope, the engine-observed touched surface, and the post-session scope evaluation that compares them. Fences convert "the agent could touch anything" into "the agent could touch these four files." Work found outside the fence is a scope violation, and committing it to make the flag disappear is laundering, not remediation.

## Verification and its honesty

**Verification over attestation.** The discipline's second principle, operationalized: completion claims are evaluated outside the executor. An executor's own report may be preserved and credited only as attested evidence where the plan's evidence floor permits it; it does not become independent verification merely because the engine recorded it.

**Evidence class.** The stated strength of a verification result. Three classes, in descending order: **engine_observed** (in practice speech, server-verified: qualifying engine capture of a direct observable; the property is epistemic, not topological), **proxy** (the engine ran the check, but the pass signal comes from a worker-authored artifact such as a test suite, credited only with its fired negative probe), and **attested** (the worker's own report, accepted only where the plan's required evidence floor permits it, and labeled as such). These three names are the registry's, copied exactly. Strength is computed on two axes, capture and signal, and a verdict's class is the minimum of the two: qualified capture comes through authenticated engine observation or successful policy-required independent replay, and neither axis can launder weakness in the other. Reference tooling may print composite capture labels (such as server_observed_proxy) on its console; the registry's three class names govern. A node's class is the weakest of its checks. Records that do not state their evidence class are records that overclaim by omission.

**Negative probe.** A planted-failure demonstration required when evidence from a worker-authored check must receive proxy completion credit: the companion check that proves the check was capable of rejecting known-bad work. A test suite that passes is evidence only if it would have failed on broken work; the negative probe demonstrates that. No worker-authored proxy check is trusted without one, and a probe counts as fired only when it actually spawned, exited nonzero, and produced output. A probe that "fired" without running is the always-green test wearing a disguise.

**Always-green test.** A test that passes unconditionally: it asserts nothing, or asserts something that cannot be false. The characteristic failure mode of machine-generated test suites, and the reason negative probes exist. An always-green test is worse than no test, because it manufactures confidence.

**Fail closed.** The disposition of a governed system when a check cannot run: the work stops. An unavailable check is a failed check, never a skipped one. The alternative, failing open, is how missing checks silently become permission.

## Authority and its record

**Approval gate.** A stop built into the contract at a point of consequence: irreversible actions, high-risk changes, production-touching work. The run halts until a named human approves, and the approval enters the record as a typed, signed entry, ordered before the consequence it authorizes; under the Formal Specification, a gate ratifies verified findings, and the evaluator checks the order, not the sentiment. Refusal, halt, and succession are legitimate gate outcomes; the system does not merely wait until yes. A gate is not review after the fact; it is a door the machine cannot open alone.

**Gate authority.** The named human whose approval opens a gate, and the role that owns the blast radius of what follows. Anonymity is incompatible with the role: an unnamed approval is a rubber stamp, and a named one is testimony.

**Plan author.** The role that turns intent into adequate contracts: decomposing obligations into nodes, stating done-tests as observables, drawing fences, and marking consequence points. The quality of everything downstream is set here.

**Verifier steward.** The role that owns check adequacy: matching each obligation to the strongest available evidence class, requiring negative probes on proxies, and hunting always-green tests. Where the plan author writes the contract, the verifier steward ensures the contract can actually be enforced.

**Circuit breaker.** The bounded-failure mechanism of governed execution: repeated verification failures trip the breaker and halt the run for human intervention. Runaway behavior converges to a human decision, and the trip itself is recorded.

## The session and its verdicts

**Session.** The supervised unit of execution: the engine commissions a set of nodes, one executor works them, and the session closes with a recorded exit and a recorded result. The session, not the individual task, is what the engine watches; per-node attribution of a multi-node session's changes is derived afterward, at proxy strength, never observed directly.

**Witness.** The specification's name for the chained record: the append-only, hash-linked log in which every protocol transition appends exactly one entry at its moment. If it is not in the witness, it did not enter the record.

**Derived candidacy.** How nodes become eligible for verification after a session closes: the engine derives candidates from evidence bound to the session's recorded result. A node the evidence cannot support is not a candidate and enters governed failure resolution instead; insufficient evidence is a routed outcome, never a silent disappearance.

**Between-sessions verification.** The choreography of verdicts: verification runs after a session's result is recorded and before any new session touches the node. The worker never records its own verdicts, and a verdict written mid-session is illegal on its face.

**Evaluator.** The separately executable program that judges an exported record using the bundle, the named policy, the evaluator implementation and version, public verification material, and any policy-required replay inputs, with no access to the producing system. Whether a given evaluation also counts as independent is a question the trust policy answers, not the architecture.

**Validity and defensibility.** Two computations, deliberately separate. Validity: the record satisfies the nine record conditions. Defensibility: the policy-mandated anchors, evaluator attestation, evaluator independence, replay conditions, and precedence commitments additionally hold. A valid record is not automatically defensible, and a document that collapses the two is overclaiming.

**Evidence envelope.** The versioned packaging of a sealed core bundle with its anchors and later evaluation attestations. The sealed core is inert; the envelope is how lawful additions attach without touching it.

## The record and its proof

**Chained record.** The append-only log of a governed run in which every entry is cryptographically linked to its predecessor. Any removal, insertion, or alteration breaks the existing linkage unless downstream commitments are recomputed; bound signatures, checkpoints, and external anchors make such replacement detectable under their applicable trust assumptions. A mutable log is a liability; a chained one is an exhibit.

**Time anchor.** An external timestamp (such as an RFC 3161 token from a timestamp authority) binding a particular byte commitment to an independently issued time. It establishes that the anchored bytes existed no later than that time and makes later alteration incompatible with the original anchored identity. It does not establish when the underlying events occurred, validate internal timestamps, prove authorship, or prove the truth of the contents, and an honest record says so.

**Core bundle.** The immutable, canonicalized heart of a governed run's proof: the frozen contract, the witness, the governed artifacts, and the verification material, packaged deterministically so a retained copy can be compared byte-for-byte against a delivered one. Built to be verified by parties who do not have, and do not trust, the tooling that produced it. Once sealed, the core is inert: its witness cannot be extended or rewritten, and later evidence attaches through a new envelope snapshot, never by modifying the core. The older practice term for the whole package, evidence bundle, names the core plus its envelope informally.

**Field record.** The human-readable rendering of a run's evidence: what was contracted, what was done, what was verified at which evidence class, who approved what, and what the record does not prove. A field record that omits the last item is not a field record.

**Honest boundaries.** The discipline's sixth principle as a property of artifacts: every record states what it proves and what it does not. Overclaiming records collapse under adversarial review; records with stated limits survive it. The practice of writing "this check proves presence, not sufficiency" is not modesty. It is what makes the rest of the document believable.

## The four computed answers

**Valid record.** Whether the exported core satisfies the specification's nine conditions. A computation, not a compliment.

**Outcome.** How the run ended, from a five-value set: completed, superseded, halted, incomplete, or invalid. A halted run can be a perfectly valid record; a crashed run is a run whose record says so.

**Contract satisfied.** Whether every active obligation reached its required evidence strength and every required approval was lawfully ordered.

**Defensible.** Whether the record meets a named trust policy's requirements: anchors verifying, the evaluator's attestation verifying, the evaluator independent under that policy, and precedence commitments honored. Validity without defensibility is common and honest; the reverse is impossible.

## The three conformance levels

**Bundle conformance.** A claim about one specifically identified exported core bundle under the named specification, schemas, registries, evaluator version, and verification inputs. The only level a passing record establishes, and it establishes only that scoped result; the bundle and its historical verdict remain permanently identifiable.

**Constructor conformance.** A claim about whether producing machinery implements the required construction procedures and bindings. Assessed by inspection against the published procedures, never inferred from any number of passing records.

**Operational conformance.** A claim about the environment around the machinery: controls, key custody, deployment, and ongoing operation. Assessed by operational audit.

No level implies another. Trial 0's signed scope statement exists to refuse exactly that inference.

## The two ledgers

**Governed work.** Work executed under a frozen plan with declared scope, engine-side verification, applicable gates where the plan designates consequential actions, and an integrity-linked witness. The full discipline; a plan with no consequential actions carries no gates and is no less governed for it.

**Recorded work.** Work executed without a contract but with an honest practice record: the instruction given, the transcript, the change produced, the identity of the executor. Legitimate, useful, and never to be confused with governed work, nor with formal GAD-1: a practice record documents honestly without conforming, while a GAD-1 record carries the mandatory execution triplet and integrity requirements. Label which one you hold.

**The two-ledgers doctrine.** Label everything; govern what matters; never confuse the ledgers. A recorded-but-ungoverned build honestly labeled is within the discipline. An ungoverned build presented as governed is the discipline's definition of dishonesty.

## The ladder

**GAD-0, Ungoverned.** Agents run; nothing is recorded. Where roughly everyone is today.

**GAD-1, Recorded.** Practice goal: AI execution is attributable and inspectable rather than ephemeral, with instruction, transcript, delta, and executor identity kept where available. Formal floor: every executor invocation produces the mandatory dispatch, executor-exit, and execution-result triplet in the integrity-linked witness. The practice material is valuable; only the triplet is conformance material.

**GAD-2, Verified.** Completion claims are checked engine-side at the specification's evidence-strength floors; done is defined observably, and worker-authored proxies carry their negative probes.

**GAD-3, Governed.** Frozen contracts, scope fences, chained records, and, where the plan names points of consequence, gates; formally, the exported record satisfies all nine validity conditions, and another party can recompute that verdict cold. A plan with no gated nodes satisfies the gate condition vacuously, and the record says so; gates are mandatory where the frozen plan requires them, not everywhere.

**GAD-4, Defensible.** Under a named trust policy: the record is valid, required anchors verify, the evaluator's attestation verifies, the evaluator is independent under that policy, and pre-dispatch commitment verifies wherever bounded precedence is claimed. You gain a deterministically canonicalized core and versioned evidence envelopes built to survive the tooling that produced them and the adversarial reader who receives them.

The ladder grades defensibility, not autonomy. Other maturity models measure how much the machine may do; this one measures how well you could prove what it did.

---

*Definitions are versioned with the discipline. For the practice register, this glossary is the naming authority, and implementations conform to it rather than the reverse. For every term that carries a conformance meaning, the GAD Formal Specification (v1.3, sealed at succession-7) is the naming authority, and this glossary conforms to it. The header said so; the footer now agrees.*
