top of page
Editorial poster for “The Sentimental Veto” showing seven ethnically diverse teenage girls standing closely together with solemn, emotionally exhausted expressions against a dark background. The headline reads: “Many Races, One Tolerance,” with “The Sentimental Veto — RATIUM.AI” below.

The Sentimental Veto

Affective Jurisdiction and the Inversion of Popper’s Rejection Boundary

Epistemic Status Inversion, Corrective Failure, and the AI Governance Problem

Contents

  1. Part I — Research Object and Concept Formation

    1. 1. When Tolerance Begins to Govern Criticism

    2. 2. Research Gap and Residual Contribution

    3. 3. Canonical Model

    4. 4. Definitions and Discriminant Boundary

    5. 5. Method, Evidence Architecture, and Claim Discipline

  2. Part II — Normative Architecture

    1. 6. Toleration as Governed Judgment

    2. 7. Standing, Warrant, and Question-Specific Authority

    3. 8. Harm, Adverse Experience, and Institutional Investigation

    4. 9. Testimonial Deficit, Jurisdictional Overreach, and Procedural Asymmetry

    5. 10. Recognition and Protected Contestability

    6. 11. Critical Tolerance

  3. Part III — The Local Sentimental Veto Mechanism

    1. 12. Report Registration and Functional Authority

    2. 13. The Criticism-Governance Decision Record

    3. 14. Derivation-Failure Taxonomy and Materiality

    4. 15. Dual-Track Review and Burden Allocation

    5. 16. Claim-Test Displacement

    6. 17. Permission and Protection States

    7. 18. Episode Classification and Correction

  4. Part IV — Institutionalization and Equilibrium

    1. 19. Institutionalized Pattern, Closure Regime, and Equilibrium-Like Condition

    2. 20. ADM/CIV, Protected Contestability, and Sovereignty Structure

    3. 21. Distributed Responsibility and Orphaned Affective-Permission Inference

    4. 22. Proxy Capture and the Ambiguity of Quiet

    5. 23. Institutional Feedback and Persistence

    6. 24. Selection Effects on Corrective Participation

    7. 25. CEP-Consistent Persistence

    8. 26. Institutional Classification, Cases, and Boundary Conditions

  5. Part V — AI Replication and Alignment Failure Modes

    1. 27. Human-Institutional Encoding and AI-System Attribution

    2. 28. Affective-Signal Provenance and Object Judgment

    3. 29. AI-Mediated Affordance and Permission Effects

    4. 30. Correction Recovery and Recursive Classification

    5. 31. AI Pattern, Attribution, and Research Boundary

  6. Part VI — Governance Translation and Evaluation

    1. 32. Critical Tolerance Governance Overlay

    2. 33. Governance Object and Decision Record

    3. 34. Thresholds, Authority, and Permission Gates

    4. 35. Operational Evaluation Architecture

    5. 36. Correction Architecture

    6. 37. Deployment Integration and Anti-Recursion

  7. Part VII — Objections, Evidence, and Theoretical Closure

    1. 38. Modular Reduction and Construct Independence

    2. 39. Strongest Normative, Political, and Institutional Objections

    3. 40. Empirical Measurement and Research Program

    4. 41. Claim Maturity and Publication Discipline

    5. 42. Conclusion: Protection without Insulation

Abstract

This article develops the Sentimental Veto as a candidate theory of a specific institutional failure: the conversion of reported or predicted affective impact into decision-bearing authority over the admissibility, force, continuation, forum, or practical permission status of criticism without sufficient evidential, conceptual, moral, procedural, and institutional derivation. The theory does not deny the epistemic importance of first-person experience, the reality of dignitary harm, the legitimacy of protective intervention, or the need to correct testimonial injustice. It distinguishes those requirements from a different error: granting affective testimony or affective proxies jurisdiction over questions they cannot settle by themselves.

The strict local classifier is conjunctive:

SV_e \iff AR_e \land AJ_e \land MDD_e \land PE_e

where (AR_e) is an Affective Report, (AJ_e) is consequential Affective Jurisdiction, (MDD_e) is a Material Derivation Defect, and (PE_e) is a material Permission Effect. The article then develops an institutional extension, an AI-specific taxonomy, and a governance translation. It differentiates the proposed construct from harm and offense, testimonial and hermeneutical injustice, recognition failure, procedural unfairness, organizational silence, path dependence, audit and metric distortion, overrefusal, safe completion, blind refusal, and generic contestability.

The article's governing normative principle is Critical Tolerance: serious uptake of affective evidence without testimonial sovereignty, protection of persons without insulation of claims, and correction procedures capable of altering operative permission states. Karl Popper's paradox of tolerance supplies the canonical rejection-boundary problem: an open order may need to restrict actors who would use its freedoms to destroy the conditions of rational contestation. The present article accepts that asymmetry while specifying the missing jurisdictional question—how an allegation of intolerance acquires authority to alter a criticism's permission state, and how an erroneous restriction can be reopened and reversed (Popper 1994, 581 n.4). The article is deliberately reduction-ready. It specifies rival theories, empirical tests, negative cases, reliability requirements, attribution limits, and conditions under which the local construct, institutional extension, AI taxonomy, or governance architecture should be narrowed, reclassified, split, or rejected.

Part I — Research Object and Concept Formation

1. When Tolerance Begins to Govern Criticism

Tolerance is usually presented as a limit on power: one disapproves of a belief, practice, or expression yet refrains from suppressing it. In Forst's reconstruction, toleration includes an objection component, an acceptance component, and a rejection component (Forst 2013). The objection explains why the practice is disfavored; the acceptance reasons explain why it should nevertheless be permitted; the rejection reasons mark the point beyond which toleration is withdrawn. This structure already shows that tolerance is not passive sentiment. It is governed judgment.

The problem begins when tolerance ceases to regulate the treatment of persons and instead acquires jurisdiction over the validity or admissibility of criticism itself. A person reports offense, humiliation, exclusion, fear, identity threat, or emotional injury. The report may be accurate and normatively important. It may establish what the person experienced, justify immediate protective attention, reveal institutional exclusion, or supply evidence of a wider pattern. Yet none of these functions automatically settles whether the criticized proposition is false, whether the critic's causal account is correct, whether the institution should suppress the criticism, or whether a broad formation should be insulated from examination.

The Sentimental Veto names a candidate failure at this transition. It is not emotion defeating reason. That formulation would be both crude and wrong. Affective experience is part of the evidence through which social and institutional reality becomes knowable. The failure concerns jurisdiction: which question the report is authorized to answer and what institutional consequence may follow from it.

The governing distinction is therefore:

Serious affective uptake ≠ Affective sovereignty over criticism.

A tolerant institution protects human standing, participation, security, and fair process. It does not grant any claimant—critic, target, manager, evaluator, model, or proxy—unbounded authority over the admissibility of the claim at issue.

2. Research Gap and Residual Contribution

Several mature literatures explain adjacent failures. Theories of toleration analyze objection and acceptance (Forst 2013; Brown 2006). Harm and offense doctrines distinguish injury, offense, and dignitary harm (Feinberg 1984; Feinberg 1985; Waldron 2012). Epistemic-injustice theory explains credibility deficits, interpretive marginalization, and communicative silencing (Fricker 2007; Dotson 2011). Recognition theory explains status injury and participatory inequality (Honneth 1995; Fraser 2000). Procedural-justice research explains the importance of voice, neutrality, dignity, consistency, accuracy, representation, and correctability (Leventhal 1980; Tyler 2006). Psychological-safety research examines conditions under which interpersonal risk affects speaking and learning (Edmondson 1999; Frazier et al. 2017). Organizational research explains silence, exit, workarounds, and learning failure (Morrison and Milliken 2000; Milliken, Morrison, and Hewlin 2003; Morrison 2014; Hirschman 1970; Argyris 1977). AI research now measures overrefusal, selective refusal, safe completion, and legitimacy-insensitive rule refusal (Cui et al. 2025; Muhamed et al. 2026; OpenAI 2025a; Pattison, Manuali, and Lazar 2026).

Popper's paradox of tolerance is the closest canonical antecedent to the article's rejection-boundary problem. Popper argues that unlimited tolerance can destroy the conditions of tolerance, but he does not recommend the automatic suppression of intolerant philosophy. His threshold is tied to a breakdown of rational contestation: the relevant movement rejects argument, prevents its adherents from hearing argument, or substitutes coercion and violence for criticism (Popper 1994, 581 n.4). This establishes why an open order may require an asymmetrical restriction. It does not by itself specify the institutional derivation by which a speaker, proposition, practice, organization, or communication channel is classified as the proper object of restriction. Nor does it specify how reported offense, anticipated distress, dignitary injury, or identity threat should bear on that classification. The residual contribution of the Sentimental Veto framework begins at precisely this jurisdictional and procedural gap.

The proposed residual lies in a narrower integrated path:

Affective report or proxy → assigned jurisdiction → materially defective derivation → operative Permission Effect.

The theory asks a question not exhausted by whether affect was heard, whether the process was respectful, whether harm occurred, or whether the outcome was restrictive:

By what derivation did affective relevance become authority over what criticism may proceed, and could the resulting permission state be corrected?

This residual should not be protected rhetorically. If testimonial-injustice theory, procedural justice, ordinary harm analysis, organizational silence, overrefusal, or another established framework explains the relevant cases without loss, the new construct should be narrowed or reclassified as a subtype or synthesis.

The contribution is therefore conditional. It consists of: a strict conjunctive classifier; a distinction between affective relevance and affective jurisdiction; a material derivation-defect threshold; a practical Permission Effect endpoint; an institutional pattern hierarchy; an AI-specific attribution architecture; and a correction-oriented governance translation.

3. Canonical Model

The theory distinguishes three nested levels.

Affective-Jurisdiction Failure

AJF_e \iff AR_e \land AJ_e \land MDD_e

An affective report receives consequential jurisdiction through a materially defective derivation.

Sentimental Veto

SV_e \iff AJF_e \land PE_e

or equivalently:

SV_e \iff AR_e \land AJ_e \land MDD_e \land PE_e

A local episode is a Sentimental Veto only when the jurisdictional failure produces a material permission consequence.

Broader Derivation Defects

The article uses Derivation Defect as a broad taxonomy. Only a Material Derivation Defect is constitutive of the strict classifier. This prevents minor procedural imperfections from being inflated into veto events.

The model is non-compensatory. Strong evidence for three components cannot compensate for the absence of the fourth. A painful report without jurisdiction is not a veto. A procedurally weak decision without a material Permission Effect is not a veto. A restriction supported by adequate evidence and authority is not a veto merely because affect was involved.

4. Definitions and Discriminant Boundary

Affective Report — (AR)

A first-person or properly attributed report of affective impact, including offense, distress, humiliation, exclusion, fear, identity threat, or comparable experience. A direct first-person report has privileged authority concerning the fact and character of the reporter's experience. That authority is question-specific.

Affective Jurisdiction — (AJ)

A neutral functional category. Affective information has jurisdiction when it is treated as decision-bearing for a defined question. Some jurisdiction is proper: a person may decide whether direct contact is welcome; a credible report may trigger investigation; an institution may impose reversible protection while facts are assessed. Failure arises only where the assigned jurisdiction exceeds what the report and surrounding evidence can support.

Material Derivation Defect — (MDD)

A specified failure in object identification, evidence, authority, threshold, proportionality, substitute process, or correction that materially affects the permission outcome and lacks an adequate substitute.

Permission Effect — (PE)

A material institutional change in whether, where, how, to whom, or with what practical consequence criticism may proceed. Mere disagreement, criticism of the critic, popularity loss, refusal to endorse, or trivial stylistic modification is insufficient.

PE_e=(O,I,S,D,R,M)

where (O) is object, (I) intensity, (S) scope, (D) duration, (R) reversibility, and (M) material implementation or consequence.

Negative boundary

The classifier excludes valid personal boundaries, credible immediate-threat protection, substantiated harm restrictions, conduct regulation preserving the substantive claim, accurate adjudication, ordinary disagreement, and cases without a material permission consequence.

5. Method, Evidence Architecture, and Claim Discipline

Validity belongs to a specified inference and use, not to a label considered in the abstract (AERA, APA, and NCME 2014; Messick 1995). Every empirical claim should identify:

V=(I,E,P,C,U)

where (I) is the inference, (E) the evidence, (P) the population or domain, (C) the context, and (U) the intended use.

The theory contains distinct validation targets: identification of (AR), (AJ), (MDD), and (PE); classification of the conjunction; identification of institutional recurrence; AI-system attribution; and evaluation of governance interventions. Evidence supporting one target does not validate the others (Cronbach and Meehl 1955).

The research program must separate construct representation from construct-irrelevant contamination. It must test episode unitization before classification, preserve independent coding before adjudication, distinguish unobservable evidence from absence, and report missingness as a possible part of the institutional phenomenon (Krippendorff 1995; Krippendorff 2004; Rubin 1976). Reliability is required but does not prove validity.

Current epistemic status:

The theory is conceptual and source-grounded. It is not content-validated, reliability-supported, discriminant-supported, incrementally supported, prospectively supported, intervention-supported, or transfer-supported.

The method is deliberately front-loaded because the normative problem cannot be resolved by rhetorical sympathy or skepticism. The next question is which forms of authority may legitimately be derived from affected-party experience, and how institutions can preserve serious uptake without allowing that experience to settle questions outside its warrant.

Back to top ↑

Part II — Normative Architecture

6. Toleration as Governed Judgment

Toleration is not equivalent to approval, indifference, moral silence, or administrative non-interference. It presupposes an objection: some belief, practice, expression, or conduct is regarded as wrong, undesirable, or objectionable. It also presupposes acceptance reasons that defeat immediate suppression, and rejection reasons that specify the point beyond which toleration no longer applies. Forst's objection–acceptance–rejection structure therefore presents toleration as a practice of governed judgment rather than passive sentiment (Forst 2013).

That structure contains a power relation. The actor who tolerates claims the capacity to decide what may remain, under which description, and within which limits. Brown's critique is indispensable here: tolerance discourse may protect coexistence, but it may also mark one party as normal and sovereign while rendering another party's identity or difference administratively visible as the object of tolerance (Brown 2006). The question is therefore not simply whether tolerance is present. It is who defines the object, who supplies the reasons, who sets the rejection boundary, and whose interpretation becomes operative.

Popper's Rejection Boundary and the Jurisdiction to Restrict

Karl Popper's paradox of tolerance supplies the canonical modern statement of a rejection boundary. Unlimited tolerance, he argues, can permit intolerant forces to eliminate the tolerant order itself. Yet the full formulation is narrower than the slogan commonly extracted from it. Popper does not infer that an intolerant philosophy should always be suppressed. While it can be met through rational argument and constrained through public judgment, suppression is unwise. The right of defensive restriction becomes relevant where the opposing movement abandons the level of argument, prevents its adherents from hearing argument, and answers criticism through coercion or violence (Popper 1994, 581 n.4).

The structure is normatively asymmetrical. An open order need not grant unrestricted use of its freedoms to an actor whose project is to abolish those freedoms for others. The relevant priority is not neutrality among all value systems. It is preservation of the general conditions under which disagreement, criticism, revision, and peaceful political replacement remain possible. In that limited sense, restricting the restrictor can protect rather than contradict an open society.

The Sentimental Veto framework accepts the necessity of this rejection boundary. It is not a doctrine of unrestricted speech, and it does not require institutions to tolerate threats, coercive organization, targeted harassment, violent enforcement, incitement, or deliberate destruction of access to argument. Those objects may justify consequential restriction. The unresolved question is how an institution moves from the proposition this actor or expression is intolerant to the operative conclusion this object must lose permission.

That transition contains several questions that Popper's note does not attempt to answer:

  1. What is the object of concern: a proposition, a mode of expression, a threat, an organization, a pattern of conduct, or a coercive enforcement strategy?

  2. Which evidence demonstrates an actual threat to rational contestability rather than moral offensiveness, ideological hostility, or anticipated distress?

  3. Who has authority to classify the object, and over which component of the decision?

  4. How broad, durable, and reversible may the restriction be?

  5. What forum remains available for criticism of the classification itself?

  6. What institutional act follows if the restriction is later found to have been erroneous?

These questions matter because the classification intolerant can perform two very different functions. It can identify conduct that would destroy the conditions of open criticism. It can also operate as a conclusory moral label that closes criticism before the relevant threat has been demonstrated.

The article terms the second pathway a Popperian Inversion. This expression is the article's own analytical extension, not Popper's terminology. It describes a reversal in which an argument designed to protect the open society is used to insulate a doctrine, identity-linked practice, policy, or authority from critical examination:

Criticism is classified as intolerance → the classification is linked to offense, fear, identity threat, or anticipated harm → that affective signal acquires untested jurisdiction over the critical object → restriction follows without sufficient derivation → corrective visibility declines → the decline is treated as confirmation that restriction was necessary.

Popperian Inversion is not identical to the Sentimental Veto. The inversion identifies a particular normative vocabulary through which a veto may be justified. A strict Sentimental Veto still requires an Affective Report or its defined AI proxy, consequential Affective Jurisdiction, a Material Derivation Defect, and a material Permission Effect. A mistaken invocation of Popper without affective jurisdiction may be another kind of censorship or classification error, but it is not automatically an instance of this theory.

Several negative boundary tests follow.

  • An offensive, illiberal, or morally repellent proposition does not become restrictable merely because it is described as intolerant while remaining answerable through argument.

  • A report of fear, humiliation, exclusion, or identity threat can trigger protection and investigation without independently proving that the criticized proposition would abolish contestability.

  • A movement's explicit program of coercion, organized silencing, violent enforcement, or elimination of opponents' access to argument can justify restriction without constituting a Sentimental Veto, provided the relevant evidence, authority, object, proportionality, and correction requirements are satisfied.

  • A restriction directed at threatening conduct does not authorize automatic suppression of every associated claim, text, speaker, or audience.

  • A legitimate rejection boundary must remain criticizable. Otherwise the institution protects the open society by creating an unreviewable closed decision.

The resulting relation is precise. Popper explains why tolerance may require a rejection boundary. The Sentimental Veto framework asks how that boundary becomes an institutional permission decision and what controls prevent it from becoming an affectively mediated veto on criticism.

The governance of criticism is sometimes legitimate. Institutions may regulate threats, targeted harassment, coercive exposure, discriminatory exclusion, persistent personal intrusion, or conduct that prevents others from participating. In such cases the governed object is not necessarily the critical proposition. It may be the manner, target, venue, repetition, disclosure practice, or action attached to it. The institution can protect a person while leaving the substantive claim available for examination.

The second-order problem arises when regulation moves from the conditions under which criticism is expressed to the admissibility of the criticism itself. An identity-linked doctrine, institutional practice, public narrative, or professional judgment may become difficult to examine because criticism is redescribed as injury to the persons associated with it. The affective impact may be real and institutionally relevant. The defect lies in allowing that relevance to settle—without further derivation—whether the claim may be voiced, tested, continued, or heard in a consequential forum.

Three analytical levels must therefore remain separate:

  1. human standing — whether persons remain secure, respected, and able to participate;

  2. conduct governance — whether the form or conditions of interaction require restriction;

  3. claim access — whether the proposition, doctrine, practice, or authority remains open to relevant examination.

A refusal of direct personal contact may be a valid boundary. A rule prohibiting threats may be necessary protection. Neither entails a general right to suppress public criticism of a doctrine or institution. Conversely, the fact that a proposition is criticizable does not authorize humiliating conduct toward the persons associated with it.

The Sentimental Veto theory begins from this dual requirement. Institutions must govern criticism where protection genuinely requires it, yet they must not let the language of tolerance conceal an unexamined transfer of authority over the critical object. Determining whether such a transfer is legitimate requires a more exact account of standing, warrant, and question-specific authority.

7. Standing, Warrant, and Question-Specific Authority

Affective testimony can possess strong authority without possessing unlimited authority. A person is ordinarily the primary authority concerning the fact that they experienced fear, humiliation, distress, exclusion, or loss of security. That first-person authority is epistemically and procedurally significant. It may require immediate uptake, evidence preservation, protective attention, or formal review. It does not by itself settle every external question generated by the report.

The article calls this limitation Question-Specific Authority. Authority attaches to a question, not globally to a speaker or institutional role. The same report can be decisive for one proposition, probative for a second, and insufficient for a third.

Question
Typical authority of affected-party testimony
Additional authority normally required
What did the person experience?
Primary and often decisive
Clarification only where the report is ambiguous
What event or expression preceded the experience?
Strong evidential relevance
Records, witnesses, contextual reconstruction
What caused the experience?
Relevant but not necessarily dispositive
Causal investigation and alternative explanations
Did the conduct violate a rule or right?
Standing to allege and supply evidence
Applicable law, policy, and competent adjudication
Is the criticized proposition false or impermissible?
Usually non-dispositive
Domain evidence, argument, and object-specific judgment
What protection or permission state is justified?
Strong standing and remedial relevance
Proportionality, authority, effects on others, and correction design

This table does not reduce testimony to one narrow function. Reports may reveal patterns invisible to formal records, correct institutional ignorance, expose interpretive gaps, and identify harms that outsiders are poorly positioned to perceive. Fricker's account of testimonial injustice explains how prejudice can produce a credibility deficit, while Dotson shows how communicative environments can silence speakers or make full testimony unsafe (Fricker 2007; Dotson 2011). Those failures justify institutional effort to secure uptake, intelligibility, and non-retaliation.

They do not justify testimonial sovereignty. A credibility correction becomes a status inversion when the effort to avoid discounting testimony makes the report immune from relevance testing or gives it final authority over a question outside its warrant. The governing rule is therefore:

No Credibility Deficit and No Testimonial Sovereignty.

Three institutional functions should be distinguished.

  • Standing determines who may report, demand attention, or initiate review.

  • Warrant concerns what evidential or protective inference the report presently supports.

  • Authority determines who may issue a consequential judgment or permission state.

The functions may be distributed. An employee who reports humiliation has standing to initiate review and authority over the description of their experience. An investigator may possess authority to reconstruct events. A domain expert may assess the substantive claim. A properly constituted forum may determine whether restrictions are justified. The process is defective if the reporter is excluded from all these stages; it may also be defective if first-person authority is silently converted into final authority over all of them.

Consider two boundary cases. First, a critic describes a workplace policy as discriminatory, and a manager reports feeling publicly humiliated by the accusation. The manager's experience is real, but it cannot settle whether the policy is discriminatory or whether the criticism should be suppressed. Second, a person reports that repeated direct messages have made participation intolerable. Their testimony may justify an immediate no-contact boundary even before the wider dispute is resolved, because authority over direct access is more closely connected to personal security than authority over public criticism.

Question-Specific Authority thus rejects both epistemic neglect and authority inflation. The next problem is how institutions should act when adverse experience may indicate anything from ordinary offense to serious harm, while the evidence remains incomplete.

8. Harm, Adverse Experience, and Institutional Investigation

The category “harm” is too coarse to govern the full range of affective reports. Feinberg's distinction between harm and offense, together with Waldron's analysis of dignity and public assurance, shows why institutions must identify the type of adverse experience before selecting a response (Feinberg 1984; Feinberg 1985; Waldron 2012). The same report of feeling unsafe may refer to very different underlying conditions.

Adverse category
Typical object
Possible institutional response
Offense or aversion
Unwelcome expression or symbolic exposure
Contextual accommodation, no restriction, or narrow venue rules
Distress or humiliation
Experienced emotional injury or interpersonal degradation
Support, conduct review, non-retaliation, possible limited protection
Dignitary or status harm
Public treatment that undermines equal standing or assurance
Institutional correction, participation protection, rule enforcement
Exclusion
Loss of access, voice, eligibility, or effective participation
Access restoration, structural review, anti-retaliation measures
Credible threat
Indication of coercion or impending injury
Immediate reversible protection, evidence preservation, escalation
Physical danger
Material risk to bodily security
Urgent restriction, security action, and formal investigation

The categories may overlap. Distress can be evidence of exclusion; humiliation can form part of dignitary harm; offensive expression can contribute to a pattern of intimidation. The classification must therefore remain revisable. What is prohibited is the direct inference from the intensity of reported affect to the legal, causal, or permission conclusion. Intense fear can occur without an external threat, and a severe threat can exist before the exposed person fully recognizes or reports fear.

Institutions face a special duty where they control the evidence needed to evaluate the report. An employee, student, applicant, patient, platform user, or model subject may lack access to records, witnesses, logs, classifier decisions, or policy interpretations. Requiring that person to prove the whole case before the institution preserves evidence or begins review transfers the burden to the party least capable of discharging it. The institution should instead undertake an Investigation Duty proportionate to its control over the relevant information.

That duty includes, where applicable:

  • registering the report without prejudging the final claim;

  • preserving records and preventing spoliation;

  • separating urgent protective action from final adjudication;

  • enabling competent and sufficiently independent review;

  • protecting reporters and witnesses against retaliation;

  • recording uncertainty and alternative explanations;

  • disclosing findings and reasons to the extent permitted by legitimate confidentiality.

Provisional protection is justified where delay creates serious or irreversible risk. Its legitimacy depends on four constraints: it should be proportionate, reversible where possible, time-bounded, and explicitly non-final. A temporary separation pending investigation may be valid. Treating the protective hold as proof that the allegation is established would be a threshold and authority error.

The reverse case is equally important. A person may report profound distress caused by exposure to criticism that remains lawful, relevant, and non-targeted. The institution may owe support, scheduling accommodation, or protection against harassment. It does not necessarily owe suppression of the critical claim. The question is what response protects standing and participation while preserving an accurate object of judgment.

This produces a legitimate asymmetry in procedure: the institution may owe greater investigative effort where vulnerability, evidence control, or retaliation risk is unequal. It does not produce an automatic asymmetry in the standards by which causal, normative, and permission conclusions are judged. The next chapter formalizes this dual-error structure.

9. Testimonial Deficit, Jurisdictional Overreach, and Procedural Asymmetry

The Sentimental Veto theory is organized around two opposed epistemic and institutional errors.

Testimonial deficit

A report is ignored, discounted, silenced, mistranslated, or deprived of the conditions needed for intelligible uptake. The speaker may be treated as unreliable because of prejudice, status, communication style, or institutional convenience. Relevant experience therefore fails to enter the decision process.

Jurisdictional overreach

A report is received, but its authority is extended beyond the question it can adequately answer. Experience becomes dispositive proof of external causation, moral invalidity, institutional guilt, or the permission status of criticism without the necessary intervening judgment.

These errors are not mirror images with identical social histories or consequences. Testimonial deficit often tracks durable inequalities in credibility, status, and evidence access. Jurisdictional overreach may arise as an institutional attempt to correct those inequalities, as a risk-management shortcut, or as a way of avoiding difficult substantive judgment. The same organization may commit both errors in sequence: initially dismissing a report, then responding to exposure or criticism by granting the report unbounded authority.

The normative solution is symmetry in inferential standards with asymmetry in enabling procedure.

Normative symmetry

Comparable claims should be assessed through comparable requirements of:

  • object identification;

  • evidential relevance;

  • causal support;

  • proportionality;

  • authority;

  • correctability.

No party is exempt because of institutional prestige, expertise, vulnerability, identity, or emotional intensity. Symmetry here is not indifference to power. It is a prohibition on changing the truth or relevance conditions of a claim solely according to who asserts it.

Procedural asymmetry

Institutions may owe unequal support because the parties do not enter the process with equal resources or exposure. Asymmetry may be justified by:

  • dependency on the institution;

  • unequal control of evidence;

  • vulnerability to retaliation;

  • irreversibility of the threatened consequence;

  • concentration of burden on one party;

  • communication or accessibility barriers.

Procedural asymmetry may include confidential reporting, assisted documentation, interim protection, independent investigation, funded representation, accommodation, or a lower threshold for initiating review. It does not necessarily imply a lower threshold for a final high-consequence permission decision (Leventhal 1980; Tyler 2006).

Three burdens should therefore be kept separate.

  1. Burden of reporting: what a person must provide to trigger serious uptake.

  2. Burden of investigation: what the institution must do once the report is cognizable.

  3. Burden of adjudication: what evidence and reasoning are required before a final finding or restriction is imposed.

Conflating these burdens produces predictable failure. If the burden of adjudication is imposed at the reporting stage, testimonial injustice is reproduced. If the low burden appropriate to initiating review is carried unchanged into final adjudication, jurisdictional overreach becomes likely.

A strong objection is that symmetry language can conceal structural power by pretending that unequal parties are similarly situated. That objection is correct when symmetry is used to deny accommodation, investigation duties, or historical credibility deficits. It does not defeat the narrower rule advanced here. The theory requires institutions to correct unequal access to the process while preserving question-specific standards at the point where claims become operative judgments.

This dual architecture leads beyond credibility and procedure to the issue of recognition. A process can hear testimony accurately yet still degrade standing; it can also protect standing by making identity-linked claims immune from examination. The next chapter develops a form of recognition compatible with contestability.

10. Recognition and Protected Contestability

Recognition concerns more than subjective approval. Honneth treats struggles for recognition as conflicts over the conditions of practical identity and social standing, while Fraser's status model emphasizes participatory parity: whether institutionalized value patterns permit persons to interact as peers (Honneth 1995; Fraser 2000). A criticism regime can therefore be unjust even when it does not inflict physical harm or formally silence speech. It may humiliate, stigmatize, exclude, or make participation conditional on accepting a subordinate status.

The relevant protection cannot be reduced to emotional comfort. Institutions may need to secure:

  • equal standing and public assurance;

  • freedom from targeted degradation or coercion;

  • access to the forum in which decisions are made;

  • practical ability to give evidence and answer allegations;

  • protection against retaliation;

  • restoration after wrongful exclusion.

Yet recognition becomes unstable if it is secured by insulating all identity-linked claims, doctrines, practices, or authorities from criticism. Persons are not identical with every proposition associated with their community, institution, profession, or history. To make equal standing depend on the immunity of those propositions would transform recognition into epistemic jurisdiction.

The article therefore proposes Protected Contestability. It has two simultaneous objects:

  1. protection of persons as participants whose security and standing must not depend on submission to degrading treatment;

  2. preservation of claims, practices, and authorities as objects that remain open to relevant evidence, criticism, and correction.

Protected Contestability is not satisfied by a formal right to speak. It requires an operative path through which criticism can matter. At minimum, the path includes:

  • access to relevant evidence;

  • a forum competent to identify the precise object;

  • opportunity for affected parties and critics to be heard;

  • independence or separation sufficient to control bias;

  • reasons responsive to the actual claim;

  • protection against retaliatory exclusion;

  • authority capable of correcting the operative state.

Consider a university rule prohibiting threats and targeted slurs in a classroom. The rule may protect participation without insulating a religion, political ideology, scientific theory, or university policy from criticism. The valid governed object is the threatening or degrading conduct, not the proposition merely because it is identity-linked. Conversely, a nominally “open debate” procedure that permits criticism but exposes one group to repeated personal targeting or denies it access to reply does not provide meaningful contestability.

A further objection is that requiring contestability places another burden on vulnerable persons, compelling them repeatedly to defend their standing. Protected Contestability should not operate that way. The institution should carry the burdens of evidence preservation, translation, investigation, and implementation. The affected party need not debate their humanity or prove a right to basic security. Contestability applies to the institution's classifications, policies, factual claims, and permission decisions—not to whether persons deserve equal standing.

The distinction can be stated compactly:

Protection preserves standing, security, participation, evidence, and fair process. Insulation shields a claim, policy, practice, or authority from relevant examination or correction without adequate derivation.

Protected Contestability supplies the social and procedural form of the article's normative synthesis. The remaining task is to integrate serious affective uptake, question-specific authority, protection, claim access, and operative correction into one decision standard.

11. Critical Tolerance

Critical Tolerance is the article's original normative synthesis. It is not presented as a settled doctrine in the literature, and it should be reduced to established concepts if it adds no discriminant or practical value. Its purpose is to govern the transition from affective experience to institutional action without reproducing either testimonial deficit or jurisdictional overreach.

Critical Tolerance is not skepticism toward emotion. Affective experience can disclose fear, humiliation, exclusion, status injury, threat, and institutional failure that are not visible through detached records. Nor is Critical Tolerance a doctrine of maximal speech. Threats, harassment, coercive exposure, discriminatory exclusion, and other harmful conduct may be restricted. The distinctive claim is that protection and restriction must remain connected to the correct object, evidential warrant, legitimate authority, proportionate scope, and a path to correction.

Critical Tolerance is therefore not a rival to Popper's paradox of tolerance. It is a proposed institutional and epistemic completion of its rejection boundary. It preserves Popper's asymmetry in favor of the conditions of open contestation: an actor may be restricted when the relevant object is a demonstrated attempt to replace argument with coercive closure. It adds requirements that the condensed paradox does not supply—object specificity, Question-Specific Authority, evidential derivation, proportionality, reversibility, preserved critical access, and operative correction. Under Critical Tolerance, the institution must be capable both of restricting the actor who would abolish criticism and of correcting itself when it has falsely redescribed criticism as such an abolition.

It contains six commitments.

1. Serious uptake

Affective reports are registered, preserved, and treated as potentially decision-relevant evidence. Reporters are not required to prove the complete case before the institution begins the work only it can perform.

2. Question-specific authority

First-person authority is respected within its domain. It is not converted automatically into authority over external causation, the truth of the criticized claim, or the final permission state.

3. Precise object identification

The process distinguishes persons from claims, claims from conduct, doctrines from groups, and immediate protective objects from broader adjudicative objects. Semantic proximity is not treated as identity.

4. Proportionate and reversible protection

Where uncertainty and risk require action, the institution may intervene provisionally. The intervention should be no broader, longer, or less reversible than the evidence and risk justify.

5. Preserved critical access

Relevant criticism retains a forum and an evidence path. Restrictions on conduct do not silently become immunity for the associated claim, policy, practice, or authority.

6. Operative correction

A mistaken classification can be reopened, reversed, implemented, and—where necessary—followed by restoration or policy revision. Review without consequence is insufficient when the process is presented as corrective.

These commitments generate a compact decision sequence:

Receive the report → identify the question it can answer → preserve urgent protection where necessary → locate the exact critical object → test evidence and authority → select a proportionate permission state → maintain correction and restoration paths.

Several objections must be confronted.

First, the framework may appear emotionally cold. Its insistence on jurisdiction and derivation could be used to interrogate vulnerable reporters while institutional actors retain control. Critical Tolerance rejects that use. The institution bears the investigation burden where it controls evidence, and protection need not wait for complete adjudication. The discipline applies principally to the institution's conversion of evidence into coercive or permission consequences.

Second, the framework may reproduce a liberal ideal of detached public criticism. Some communities understand injury, identity, and authority differently. That objection requires cultural adaptation and measurement-invariance testing, not abandonment of the core question. Every institution still must determine what a report establishes, what action follows, and whether persons or claims are being protected.

Third, the architecture may be administratively burdensome. Not every dispute requires a tribunal or full evidentiary record. The response should be proportionate to consequence, reversibility, and uncertainty. Simple cases may be resolved through a clear boundary or immediate correction; high-consequence restrictions require stronger derivation.

Fourth, symmetry may create false equivalence between powerful institutions and exposed individuals. Critical Tolerance is symmetric in relevance and justification, not in procedural support. Dependency, evidence control, retaliation risk, and unequal burden justify asymmetric safeguards.

The governing maxim remains:

No Credibility Deficit and No Testimonial Sovereignty.

The theory does not defend criticism from emotion. It defends judgment from the uncontrolled conversion of emotion into authority. Critical Tolerance supplies the normative standard. The next task is diagnostic and institutional: to identify the local sequence through which an affective report is registered, assigned a function, converted into a permission consequence, or preserved within a correctable process.

Back to top ↑

Part III — The Local Sentimental Veto Mechanism

12. Report Registration and Functional Authority

The first institutional task is not to decide the whole dispute. It is to register the report in a form that preserves what the reporter can authoritatively contribute while preventing the requested remedy, the institutional category, or the anticipated outcome from being smuggled into the record as already established. Registration is therefore an epistemic and procedural operation, not a clerical preface to adjudication.

A minimally adequate registration record should preserve:

  • the reporter's own description of the experience;

  • the event, statement, conduct, or condition identified as relevant;

  • the persons, claims, institutions, or formations implicated;

  • the requested immediate protection and requested final remedy, recorded separately;

  • timing, repetition, urgency, and foreseeable continuation;

  • evidence known to exist and the actor controlling it;

  • confidentiality, retaliation, and access constraints;

  • the questions the reporter believes the institution must answer.

Preserving the reporter's language matters because institutional translation can erase the very phenomenon being reported. A description of exclusion may be flattened into “interpersonal discomfort”; a report of fear may be inflated into a finding of objective threat; a criticism of a doctrine may be redescribed as hostility toward a population. Registration must neither trivialize nor adjudicate through vocabulary.

Functional-authority classification

A report may perform several different functions:

Function
What the report may establish or justify
What it does not establish by itself
Experiential
What the reporter experienced and how it affected participation
External causation, rule violation, or truth of the criticized proposition
Protective
Need for immediate, proportionate, reversible safeguards
Final culpability or permanent exclusion
Investigative
Need to preserve evidence, identify witnesses, or open review
The final evidential conclusion
Pattern-indicating
Possible recurrence or structural concern
Prevalence or common mechanism without additional cases
Boundary-requesting
Whether the reporter accepts direct contact or specified exposure
General authority over third-party public criticism
Adjudicative-requesting
Standing to request a determination or sanction
Authority to issue that determination

The same report may perform more than one function. The functions must nevertheless be coded separately because they support different institutional inferences. First-person testimony may be decisive concerning unwanted direct contact and highly relevant to participation risk, while remaining one input among others concerning causal responsibility or the status of a contested claim. This preserves the anti-deficit requirements developed by Fricker and Dotson without granting testimonial sovereignty (Fricker 2007; Dotson 2011).

Registration failures

At least five failures can occur before formal adjudication begins.

  1. Provenance loss — the record no longer distinguishes direct testimony, third-party report, inference, and institutional proxy.

  2. Remedy fusion — the requested protective measure is recorded as though it were the established final remedy.

  3. Object inflation — a report concerning one expression, actor, or encounter is registered as a claim about an entire doctrine, population, or institution.

  4. Category preemption — institutional language such as harassment, misinformation, safety, or discrimination is assigned before the relevant elements have been tested.

  5. Protective delay — the institution demands complete proof from the reporter before preserving evidence or providing reversible protection that only the institution can supply.

These failures point in different directions. Some discount the reporter; others overextend the report. Critical Tolerance requires control of both.

Compact synthetic example

A researcher reports that repeated direct messages from a colleague have made participation in a working group intolerable. The researcher also asks that the colleague's published criticism of the group's methodology be removed from the institutional archive. Registration should separate:

  • the first-person report of unwanted contact;

  • the evidence and risk concerning repeated messages;

  • the request for a no-contact boundary;

  • the independent request to suppress methodological criticism.

The report may immediately justify preservation of messages, non-retaliation protection, and a provisional no-contact rule. It does not by itself establish that the archived criticism is false, abusive, or institutionally inadmissible. The institutional record becomes reliable only when these objects and requested consequences remain separate.

Registration therefore creates the raw material for judgment while preventing premature jurisdictional transfer. The next stage is to record the complete decision path so that each inferential transition, authority claim, and permission consequence remains inspectable.

13. The Criticism-Governance Decision Record

A criticism-governance decision should be reconstructable as a sequence of explicit propositions rather than inferred from the final restriction. The Criticism-Governance Decision Record is the article's minimum traceability instrument for that purpose. It is not a demand for a formal tribunal in every dispute. The detail required should be proportionate to consequence, uncertainty, duration, and reversibility. A brief no-contact boundary may require a compact record; cancellation of a publication, exclusion from a profession, or organization-wide policy change requires substantially more.

The record may be represented as:

CGR_e=(O,F,C,K,AR,E,Q,T,A,PE,R)

Where:

  • (O) — the exact object governed;

  • (F) — the broader formation, identity, doctrine, or institution implicated;

  • (C) — the critical proposition;

  • (K) — the conduct through which the proposition or dispute was expressed;

  • (AR) — the affective report and its provenance;

  • (E) — the evidence set and evidence-control map;

  • (Q) — the institutional questions to be answered;

  • (T) — the threshold applied to each question;

  • (A) — the actor or forum authorized to answer it;

  • (PE) — the implemented Permission Effect;

  • (R) — review, correction, restoration, and policy-learning path.

Object invariance

The governed object must remain stable unless a reasoned transition is recorded. A criticism of one proposition cannot become criticism of an identity-linked population merely because the proposition belongs to a larger formation. Conversely, presenting a statement as abstract criticism cannot immunize targeted conduct, coercive repetition, or threats. Object invariance does not forbid reclassification. It requires the institution to state when and why the object changed.

Question map

Each material item should be linked to the question it can support. For example:

Item
Question supported
Question not settled automatically
First-person report of humiliation
What the person experienced; whether support or review is needed
Whether the criticized proposition is false
Recording of repeated direct messages
Whether contact occurred and its content
Whether public criticism of the institution should be removed
Domain analysis of the criticized claim
Whether the claim is relevant, accurate, or methodologically sound
Whether interpersonal conduct was acceptable
Institutional conduct rule
Whether specified conduct violates a rule
Whether the wider doctrine is immune from criticism
Risk evidence
Whether provisional protection is justified
Whether permanent exclusion is proportionate

This question map operationalizes Question-Specific Authority. It also makes Claim-Test Displacement visible before it produces a final decision.

Authority map

A fair procedure is not defined only by voice. Leventhal's procedural rules emphasize consistency, bias suppression, accuracy, correctability, representativeness, and ethicality; Tyler emphasizes voice, neutrality, trustworthy authority, and dignified treatment (Leventhal 1980; Tyler 2006). The Decision Record therefore identifies which actor may:

  • receive and protect the report;

  • compel or access evidence;

  • interpret the substantive claim;

  • determine rule violation;

  • issue a provisional measure;

  • impose a final Permission Effect;

  • hear an appeal;

  • implement reversal and restoration.

One actor may perform several functions. The record does not require institutional fragmentation. It requires functional visibility.

Permission-effect record

The operative consequence should be recorded through the profile:

PE_e=(O,I,S,D,R,M)

Where:

  • (O) — object affected;

  • (I) — intensity;

  • (S) — scope;

  • (D) — duration;

  • (R) — reversibility;

  • (M) — material implementation or consequence.

A recommendation to use less inflammatory language differs from cancellation of an event. A temporary hold differs from indefinite exclusion. A nominal reversal differs from restoration of access, publication, eligibility, or reputation.

Worked synthetic Decision Record

Assume that a university invites a scholar to present a critique of an identity-linked institutional doctrine. Several members report that the event's description is humiliating and creates identity threat. The organizer cancels the event and bars the same topic from future programming.

Record field
Synthetic entry
(O)
One public lecture and the future programming status of the topic
(F)
The identity-linked doctrine and the population associated with it
(C)
The scholar's proposition that a specified doctrine produces an institutional error
(K)
Public lecture under ordinary discussion rules; no threatening conduct alleged in the initial record
(AR)
Direct reports of humiliation and identity threat
(E)
Event description, proposed paper, reports, prior event rules; no substantive review of the paper yet
(Q1)
What did participants anticipate or experience?
(Q2)
Did the proposed conduct create a credible participation or safety risk?
(Q3)
Was the critical proposition within legitimate academic examination?
(T)
Low threshold for reversible protection; higher threshold for cancellation and topic-wide exclusion
(A)
Organizer may postpone; competent academic forum required for topic-wide exclusion
(PE)
Event cancelled; future topic access removed
(R)
No appeal, rescheduling rule, independent review, or expiry recorded

This record does not itself prove a Sentimental Veto. It identifies where the decisive questions lie. The reports strongly establish anticipated affective impact and may justify accommodation or a short HOLD. They do not, without further derivation, establish that the proposition or topic must be excluded. The topic-wide effect also exceeds the object of the immediate event. Chapters 14–18 determine whether these features amount to MDD and a strict local classification.

The value of the Decision Record is diagnostic: it exposes the point at which evidence, authority, thresholds, and operative consequences either remain connected or separate from one another.

14. Derivation-Failure Taxonomy and Materiality

A Derivation Defect is any failure in the path from evidence and governing requirements to an operative decision. The strict theory does not treat every defect as constitutive. A Material Derivation Defect exists only where at least one specified failure violated an applicable requirement, affected the Permission Effect, lacked an adequate substitute, and produced a non-trivial consequence:

MDD_e \iff \exists d_j [ D_j(e) \land A_j(e) \land L_j(d_j,PE_e) \land \neg S_j(e) \land M_j(e) ]

The formula imposes five controls.

  1. Specification — the analyst must identify the exact failure.

  2. Applicability — the allegedly missing rule or function must have applied.

  3. Permission linkage — the failure must matter to the operative consequence.

  4. Substitution — another process may have supplied the same function adequately.

  5. Materiality — the consequence must be non-trivial.

D1 — Object Derivation Defect

The governed object differs materially from the evidence-supported object.

Diagnostic criteria:

  • the record shifts from a statement, act, or interaction to a broader formation;

  • criticism of an element is treated as hostility toward all persons associated with it;

  • regulation of conduct becomes suppression of the substantive claim;

  • the final Permission Effect reaches objects not reviewed.

Discriminant example: Restricting repeated direct messages does not create D1 where the operative object is direct contact. Removing all public criticism of the sender's institutional policy would require a separate derivation.

D2 — Evidence Derivation Defect

The conclusion exceeds the scope, quality, provenance, or certainty of the evidence.

Diagnostic criteria:

  • affective impact is treated as conclusive evidence of external causation;

  • one episode is treated as proof of prevalence;

  • prediction or complaint-likelihood proxy is treated as a live report;

  • disputed evidence is presented as settled without a reasoned uncertainty rule.

Discriminant example: A report of fear may justify immediate protection. It does not, without supporting evidence, establish that a threat occurred or that the criticized proposition must be prohibited.

D3 — Authority Derivation Defect

Authority valid for one question is transferred to another without warrant.

Diagnostic criteria:

  • first-person authority over experience becomes authority over truth or rule application;

  • a protective officer issues a final substantive judgment outside the office's mandate;

  • an advisory classifier becomes a de facto final gate;

  • a reviewer has authority to recommend but no actor visibly owns the operative decision.

Discriminant example: A participant may decide whether direct personal contact is welcome. That authority does not extend automatically to whether a third party may publish a criticism in a public journal.

D4 — Threshold Derivation Defect

A threshold appropriate for a preliminary, protective, or reversible action is used for a final or high-consequence determination.

Diagnostic criteria:

  • “credible concern” becomes proof of culpability;

  • a temporary safety threshold produces indefinite exclusion;

  • an initial classifier confidence is treated as final adjudication;

  • the burden is not increased as consequence and irreversibility increase.

Discriminant example: A low threshold may justify postponing an event for forty-eight hours while evidence is reviewed. It does not by itself justify permanent subject-matter exclusion.

D5 — Proportionality Derivation Defect

The intensity, scope, duration, or implementation of the Permission Effect exceeds what the supported risk and object require.

Diagnostic criteria:

  • a narrow conduct problem produces formation-wide restriction;

  • less restrictive measures are not considered despite equal protective value;

  • duration is indefinite without renewal criteria;

  • reversal is formally possible but practically unavailable.

Discriminant example: Moving a discussion to a moderated venue may be proportionate to credible interaction risk. Cancelling the research program itself may not be.

D6 — Substitute-Process Defect

An applicable function is absent and no adequate substitute performs it.

The theory does not require one named committee or procedural stage for every function. Integrated review may be entirely adequate. A substitute is adequate where it has:

  • access to the relevant evidence;

  • competence concerning the question;

  • authority appropriate to the consequence;

  • independence sufficient for the conflict;

  • timeliness;

  • capacity to alter the operative state.

Discriminant example: The absence of a formal appeal board is not defective where an independent senior reviewer can reopen evidence, reverse the restriction, and implement restoration. A complaint mailbox that can only acknowledge receipt is not an adequate substitute for operative review.

D7 — Correction-Maintenance Defect

A later failure materially maintains, renews, extends, or expands the Permission Effect.

Diagnostic criteria:

  • new evidence is acknowledged but cannot reach the decision authority;

  • an appeal succeeds nominally but access is not restored;

  • an expired hold continues by default;

  • a local decision is encoded into wider policy without reauthorization.

Discriminant example: A delayed apology after an event has concluded may be a weak remedy but does not retroactively create the original defect. Refusal to reinstate a cancelled publication after the decision is formally reversed may materially maintain the Permission Effect.

Materiality profile

Materiality should be assessed through the Permission Effect profile:

  • Object: What exactly changed?

  • Intensity: Advisory modification, restriction, suspension, or termination?

  • Scope: One interaction, one forum, one institution, or a broader field?

  • Duration: Momentary, time-bounded, renewable, or indefinite?

  • Reversibility: Can the prior state be restored in practice?

  • Implementation: Did the decision alter access, publication, eligibility, distribution, participation, or institutional consequence?

Mere disagreement, criticism of the critic, social disapproval, refusal to endorse, and trivial style modification are insufficient. The concept is not a general theory of unpleasant response to criticism.

Temporal and coding rule

A pre-permission or implementation defect may be constitutive. A post-permission corrective defect is constitutive only where it materially maintains or expands the operative effect. Otherwise it is evidence concerning severity, persistence, or institutional capacity.

MDD must be coded without backward inference from a disliked outcome. Where feasible, object, evidence, authority, applicable threshold, and substitute availability should be assessed before the final consequence is revealed. Repeated disagreement among coders concerning applicability, substitution, or materiality requires codebook revision rather than concealment through an aggregate label.

15. Dual-Track Review and Burden Allocation

A single undifferentiated process often cannot provide urgent protection and careful adjudication at the same time. Waiting for complete evidence may expose a person to preventable harm. Treating provisional protection as final proof may unjustifiably restrict criticism. The article therefore proposes Dual-Track Review: two coordinated functions with different thresholds, purposes, and closure conditions.

Protective track

The protective track addresses:

  • immediate security and participation;

  • separation or no-contact boundaries;

  • evidence preservation;

  • confidentiality;

  • non-retaliation;

  • temporary access adjustments;

  • support during review.

Its threshold may be comparatively low because its measures should be proportionate, reversible, and time-bounded. A low threshold is justified by the cost of waiting, not by an assumption that the full allegation has been proven.

Adjudicative track

The adjudicative track determines:

  • the exact governed object;

  • which evidence supports which proposition;

  • whether conduct, claim, formation, and identity have been conflated;

  • which rule applies;

  • which actor possesses final authority;

  • which Permission Effect is proportionate;

  • what correction and restoration follow.

Its evidential burden rises with scope, duration, material consequence, and irreversibility. Procedural fairness requires accuracy, consistency, representativeness, correctability, and competent neutrality, not merely an opportunity to speak (Leventhal 1980; Tyler 2006).

Handoff protocol

The tracks must communicate without collapsing into one another. A minimum handoff record should state:

  1. what the protective track observed;

  2. which provisional measure was imposed;

  3. why the measure was reversible and proportionate;

  4. which questions remain open;

  5. which evidence must move to the adjudicative track;

  6. when the protective measure expires or must be renewed;

  7. who can modify it before final judgment.

No statement such as “protective action was taken” should be used as evidence of culpability. Conversely, the adjudicative track should not cancel necessary protection merely because the final question remains unresolved.

Contamination risks

Dual-track review can fail in at least four ways.

  • Protective-to-adjudicative contamination: a temporary hold becomes presumed proof.

  • Adjudicative-to-protective contamination: demand for full proof delays evidence preservation or non-retaliation.

  • Object contamination: a personal boundary is converted into subject-matter immunity.

  • Public-record contamination: provisional classifications are disclosed as final findings, making later reversal practically ineffective.

These risks require distinct labels, access controls, expiry rules, and public-status language.

Burden ownership

Burden should track institutional control and requested consequence.

  • The reporter bears the burden of communicating the experience and available particulars, not of producing records controlled by the institution.

  • The institution bears the burden of preserving and obtaining evidence within its control.

  • The critic or applicant bears burdens concerning the scope, relevance, and proposed conduct of the requested permission.

  • The authority imposing a material restriction bears the burden of identifying the object, evidence, threshold, scope, duration, and correction path.

  • The appellant should identify the alleged error, but should not bear the impossible burden of disproving undisclosed evidence.

Procedural asymmetry is justified where one party faces dependency, retaliation, evidence exclusion, or concentrated burden. It should not change the inferential standard governing the final claim.

Reversibility and closure

A protective HOLD should include:

  • a defined trigger;

  • immediate protective purpose;

  • maximum initial duration;

  • evidence tasks;

  • renewal authority;

  • expiry or conversion rule.

The protective track closes when the urgent need ends or the adjudicative decision supplies a new basis. The adjudicative track closes only when the operative state, appeal path, implementation, and any required restoration are specified. Conlon's study of organizational appeals reinforces the difference between an appeal procedure as an opportunity to challenge and a procedure capable of producing consequential correction (Conlon 1993).

Dual-Track Review is not always necessary. Simple personal boundaries may be resolved immediately. The architecture becomes important where uncertainty, high consequence, evidence control, and simultaneous protection-and-criticism interests coexist.

16. Claim-Test Displacement

A criticism-governance process may appear to assess one question while actually deciding another. The article calls this Claim-Test Displacement: an unacknowledged substitution in the proposition being evaluated, the evidence deemed sufficient, the authority treated as controlling, or the consequence being authorized.

The failure is not ordinary change of mind. Institutions legitimately refine questions as evidence develops. Displacement occurs where the transition is not made explicit and the support for the first question is used to decide the second.

CTD-1 — Object displacement

The object moves from a statement, interaction, or conduct to a broader claim, doctrine, identity, or institution.

Did this expression distress participants? → May this doctrine be criticized in this institution?

This pattern commonly produces D1 and may contribute to D5.

CTD-2 — Evidential displacement

Evidence sufficient for one conclusion is treated as sufficient for another.

The report is credible as an account of experience. → The report proves the critic's proposition false or impermissible.

This pattern commonly produces D2.

CTD-3 — Authority displacement

An actor's authority over one question is transferred to another.

The reporter controls direct personal access. → The reporter controls third-party publication or institutional programming.

This pattern commonly produces D3.

CTD-4 — Threshold displacement

A preliminary threshold becomes the standard for final action.

There is enough concern to investigate. → There is enough evidence for permanent exclusion.

This pattern commonly produces D4.

CTD-5 — Remedy displacement

A measure selected for protection becomes a judgment concerning the claim or person.

Temporary separation is prudent. → The criticism is institutionally illegitimate.

This pattern may produce D4, D5, and D7.

CTD-6 — Temporal displacement

A later event changes the apparent justification for an earlier decision without a new authorization record.

A hold was imposed pending evidence. → The hold continues because controversy now exists around the hold itself.

This pattern is especially relevant to D7 and institutional persistence.

Observable signatures

Claim-Test Displacement may be suspected where:

  • the final decision uses a broader noun than the initial allegation;

  • the operative rule changes between intake and decision;

  • no record explains why the evidential threshold increased or decreased;

  • a protective action is cited as proof that protection was justified;

  • an appeal answers the reporter's credibility but not the restriction's object;

  • decision-makers cannot state the proposition they actually adjudicated.

These signatures are not proof. They identify where the Decision Record should be reconstructed.

Relation to testimonial injustice

Claim-Test Displacement can operate against affected parties as well as critics. A report of exclusion may be converted into a narrow question about subjective sensitivity, thereby avoiding examination of structural access. A complaint about an institutional practice may be reframed as an interpersonal misunderstanding. The theory therefore does not assume that displacement always expands the reporter's authority. It asks whether the process changed the claim in a way that distorted standing, warrant, adjudication, or permission.

The governing discipline is:

A reason relevant to one institutional question cannot silently decide another.

Claim-Test Displacement is the process-level signature that links the normative architecture to the defect taxonomy. The next chapter identifies the operative states through which displaced or properly derived judgments acquire practical consequence.

17. Permission and Protection States

The article distinguishes four operational permission states. These states concern a defined object and consequence; they do not declare the moral identity of a person, group, or institution.

Gate
Operative meaning
Minimum record
SHIP
Authorize, continue, publish, deploy, or permit the defined object
Object, applicable conditions, responsible actor
RESTRICT
Narrow the operation while preserving separable legitimate use
Restricted element, retained element, scope, review condition
HOLD
Suspend temporarily pending a specified condition or review
Trigger, duration, evidence task, expiry or renewal authority
ROLLBACK
Invalidate a prior permission or system state
Prior state, reversal authority, implementation, restoration

SHIP is not endorsement. RESTRICT is not condemnation of an entire formation. HOLD is not a covert final decision. ROLLBACK is incomplete where the prior effect remains materially implemented.

Protection states should be recorded separately, including:

  • separation or no-contact;

  • confidentiality;

  • support and accommodation;

  • evidence preservation;

  • non-retaliation;

  • participation protection.

A person may receive strong protection while the criticism remains available for competent examination. Conversely, SHIP of a claim does not authorize threatening or harassing conduct. The purpose of the dual register is to prevent protection from becoming insulation and permission from becoming license.

The full authority, threshold, expiration, and anti-recursion requirements for these gates are developed in Chapter 34. At the local level, their role is to make the final institutional consequence explicit enough to test materiality and correction.

18. Episode Classification and Correction

A local episode should be classified only after its components have been coded independently. The classification order is:

  1. define the object and temporal boundary;

  2. establish whether an Affective Report occurred;

  3. identify its provenance and functional authority;

  4. determine whether consequential Affective Jurisdiction existed;

  5. test each alleged Derivation Defect;

  6. determine whether at least one defect satisfies MDD;

  7. determine whether a material Permission Effect occurred;

  8. record correction, restoration, and final state.

Local statuses

  • No Sentimental Veto — at least one constitutive condition is absent;

  • Strict Sentimental Veto — all four conditions are supported;

  • Structurally Suggestive — Not Classified — the structure is plausible but one or more components remain insufficiently supported;

  • Indeterminate — the available record cannot support either a positive or negative determination;

  • Outside Scope — affective jurisdiction over criticism is not the relevant object.

A positive classification requires:

AR_e \land AJ_e \land MDD_e \land PE_e

The conjunction is non-compensatory. Severe restriction does not prove defective jurisdiction. Strong affective evidence does not prove a Permission Effect. A poor process without affective jurisdiction is another form of institutional failure, not a Sentimental Veto.

Synthetic Case A — Strict positive classification

A public research institution schedules a seminar criticizing a specified identity-linked doctrine. Several participants submit direct reports that the subject is humiliating and creates identity threat. No threat, harassment, or exclusionary conduct is alleged. Without reviewing the paper or distinguishing the doctrine from the associated population, an administrative office cancels the seminar, prohibits future programming on the topic, and provides no appeal or expiry.

  • AR: Supported — direct affective reports exist.

  • AJ: Supported — the reports become the decisive basis for topic-wide permission.

  • MDD: Supported — D1 object inflation, D3 authority transfer, D4 threshold inflation, and D5 disproportionate scope are evidenced; no adequate substitute review exists.

  • PE: Supported — event cancellation and topic-wide exclusion are materially implemented.

Subject to the adequacy of the documentary record, the episode satisfies the strict classifier. The classification does not imply that participants' experiences were unreal. It identifies the defective transition from those experiences to a broader permission state.

Synthetic Case B — Negative case: protection without insulation

A staff member reports distress and fear after receiving repeated direct messages from a colleague who is also publicly criticizing the staff member's policy proposal. The institution preserves the messages, imposes a time-bounded no-contact rule, assigns a separate forum to examine the conduct, and leaves the policy criticism publicly available. The colleague may appeal the contact restriction, and the rule expires unless renewed on evidence.

  • AR: Supported.

  • AJ: Limited and properly question-specific — the report bears strongly on direct access and protective need.

  • MDD: Not supported — the object, threshold, authority, proportionality, and correction path are adequately derived.

  • PE: A material restriction on contact exists, but the substantive criticism remains available.

The episode is No Sentimental Veto. Affective evidence contributed to a real restriction, but not through materially defective jurisdiction. This negative case is essential: the theory does not classify every affect-responsive restriction as pathological.

Synthetic Case C — Indeterminate case

An institution removes an online essay after receiving complaints that are not publicly available. The final notice states only that the essay violated community well-being standards. The record does not reveal whether the complaints described direct affective experience, threats, factual errors, targeted conduct, or a broader policy violation. The authority path, evidence, internal review, and practical restoration options are unavailable.

  • AR: Unobservable.

  • AJ: Unobservable.

  • MDD: Plausible but not established.

  • PE: Supported — the essay was removed.

The case is Indeterminate, not a positive episode. The visible outcome cannot fill the missing constitutive fields. Non-observability may itself justify governance criticism, but it does not authorize mechanism attribution.

Correction and final status

Correction does not erase the initial event. It changes duration, severity, final state, and institutional significance. The episode record should distinguish:

  • recognition of error;

  • decision reversal;

  • implementation of reversal;

  • restoration of access, publication, eligibility, or participation;

  • policy revision preventing recurrence.

A nominally successful appeal that does not alter the operative state remains incomplete. Conversely, an institution that detects and reverses its own initial overreach supplies evidence of corrective capacity rather than closure.

Reliability should be reported separately for (AR), (AJ), MDD, (PE), correction opportunity, and final status. Agreement on the final label cannot compensate for unreliable coding of jurisdiction, applicability, substitution, or materiality.

The local classifier answers whether a bounded episode satisfies the proposed conjunction. It does not establish an institutional pattern. The next Part therefore changes the unit of analysis from one decision episode to recurrence, shared rules, correction asymmetry, selection effects, and equilibrium-like persistence.

Back to top ↑

Part IV — Institutionalization and Equilibrium

19. Institutionalized Pattern, Closure Regime, and Equilibrium-Like Condition

The move from a local episode to an institutional claim changes the unit of analysis. A strict Sentimental Veto episode establishes that one bounded affect-to-permission transition satisfied the four-part conjunction. It does not show that the same mechanism is recurrent, that the institution reproduces it, or that correction is structurally asymmetric. Institutional classification therefore requires evidence concerning scope, denominator, common mechanism, correction, and time.

From recurrence to institutional reproduction

Repeated adverse outcomes are not yet an institutionalized pattern. Similar restrictions may arise from different causes: one case may involve credible threat evidence, another a poorly trained manager, another a legal mandate, and another an ordinary classification error. The relevant question is whether comparable episodes are linked through a shared decision-producing structure.

Let:

  • (RSV_{S,T}) denote repeated strict episodes within institutional scope (S) and observation period (T);

  • (IR_{S,T}) denote an identifiable reproduction rule, workflow, classifier, authority practice, or public grammar connecting those episodes.

An institutionalized pattern is:

SVP_{S,T} \iff RSV_{S,T} \land IR_{S,T}

The reproduction rule need not be one written policy. It may consist of a stable sequence: affective reports are routed to one office, the office treats reported impact as dispositive of the criticism object, provisional measures become durable without a new threshold, and appeals review courtesy or compliance rather than the underlying permission inference. The institutional claim depends on the reproducibility of that sequence, not on the existence of incriminating language in a manual.

Denominator discipline

Organizational-silence research warns that visible reports cannot serve as the complete denominator. Employees and participants may withhold information because speaking appears dangerous, futile, disloyal, or career-limiting (Morrison and Milliken 2000; Milliken, Morrison, and Hewlin 2003; Morrison 2014). Complaint records therefore represent a selected population produced partly by the reporting system itself.

Low complaint volume ≠ low unresolved concern.

A defensible institutional study should distinguish:

  • eligible criticism episodes;

  • episodes generating affective reports;

  • formally recorded reports;

  • episodes receiving review;

  • episodes producing Permission Effects;

  • appeals initiated;

  • corrections completed;

  • exits, withdrawals, or unobservable cases.

Where the eligible population cannot be estimated and non-reporting is plausibly endogenous, prevalence claims should remain blocked. The correct status may be pattern evidence without prevalence evidence.

Durable Correction Asymmetry

An institutionalized pattern becomes a closure regime only where correction is durably more difficult than restriction or preservation of restriction. Durable Correction Asymmetry is not merely a slow appeal. It is a persistent structural difference between the path that creates or maintains a Permission Effect and the path that can reopen, reverse, implement reversal, restore access, and revise the policy that generated the effect.

Relevant dimensions include:

  • standing asymmetry — reports can initiate restriction, but critics or affected decision subjects cannot initiate substantive reconsideration;

  • evidence asymmetry — evidence supporting restriction enters the record, while contrary or contextual evidence lacks an authorized route;

  • threshold asymmetry — a low threshold imposes a durable effect, while reversal requires near-conclusive proof;

  • authority asymmetry — many actors can maintain restriction, but no actor owns operative reversal;

  • implementation asymmetry — restriction is immediate, while restoration is optional or administratively diffuse;

  • temporal asymmetry — provisional measures persist beyond their justification or expiry;

  • policy asymmetry — an individual decision can be appealed, but the governing inference cannot be reviewed.

Let (DCA_{S,T}) denote durable correction asymmetry. A closure regime is:

SVR_{S,T} \iff SVP_{S,T} \land DCA_{S,T}

The distinction is important. An institution may reproduce a flawed mechanism yet correct it reliably when challenged. That institution exhibits a pattern, but not closure. Conversely, one dramatic failed appeal does not establish durable asymmetry without evidence that the imbalance is structural or recurrent.

Equilibrium-like persistence

The strongest institutional claim concerns an equilibrium-like condition:

SVE_{S,T}=(SVR,LIC,DC,SE,PC)

Where:

  • (SVR) — a closure regime has been established independently;

  • (LIC) — continuation is locally incentive-compatible for relevant actors;

  • (DC) — meaningful deviation carries costs;

  • (SE) — actors hold sufficiently shared expectations about others' responses;

  • (PC) — the pattern persists across genuine correction opportunities.

This level must remain downstream. Silence, path dependence, legal constraint, audit persistence, distributed responsibility, or ordinary risk aversion may explain stability without any equilibrium claim. Institutional ambition should rise only as the evidence changes—from episode, to reproduction rule, to correction asymmetry, to actor-specific persistence conditions.

20. ADM/CIV, Protected Contestability, and Sovereignty Structure

Institutional disputes often appear to divide administrators from critics, but the theory does not treat these as permanent social classes. ADM and CIV identify functional positions within a decision episode.

  • ADM is the administrative-maintenance position: it translates evidence, policy, risk, and organizational purpose into an operative state and bears responsibility for continuity, coordination, implementation, and protection.

  • CIV is the civic-corrective position: it supplies criticism, counterevidence, affected-party knowledge, alternative object definitions, or demands for reconsideration that test whether the operative state remains justified.

The same actor can occupy both positions. A compliance officer may administer a restriction in one stage and later initiate corrective review. An employee may challenge a policy while administering another. The distinction concerns function in the relevant permission transition, not moral identity.

Three forms of sovereignty

Institutional closure becomes easier to locate when three forms of sovereignty are separated.

Decision Sovereignty

Authority to issue the initial operative determination.

Correction Sovereignty

Authority to reopen the object, evidence, threshold, or rule; reverse the decision; and require implementation of reversal.

Public-Grammar Sovereignty

Power to define the categories through which the dispute becomes institutionally intelligible—for example, whether an event is registered as harassment, doctrinal criticism, safety risk, professional disagreement, identity hostility, or procedural complaint.

These powers may be held by different actors. A review body may possess formal correction authority but remain dependent on a public grammar fixed by the original decision-maker. It can then reconsider the case only inside the categories that produced the disputed result. Conversely, a public critic may reshape the grammar without possessing any authority to alter the operative state.

Handoffs and role switching

A functional system requires valid handoffs among:

  1. signal reception;

  2. object specification;

  3. evidence access;

  4. provisional protection;

  5. adjudicative judgment;

  6. permission decision;

  7. implementation;

  8. correction and restoration.

No rule requires eight separate offices. Integrated nodes may perform several functions. The empirical question is whether the functions are present, whether the same actor's combined roles create bias or efficiency, and whether the handoffs preserve the distinction between protection, judgment, and permission.

Role concentration is not automatically defective. A competent authority with evidence access, reason-giving duties, reversible measures, and independent correction may outperform a fragmented arrangement. The failure arises when concentration or fragmentation prevents the relevant question from reaching competent and operative authority.

Protected Contestability as an institutional path

Protected Contestability is not exhausted by formal permission to speak. It requires a path through which relevant criticism can be expressed without disqualifying retaliation, translated into the correct decision object, reviewed by a competent forum, and connected to authority capable of altering the operative state.

Expression ≠ standing ≠ review ≠ correction ≠ restoration.

A minimally protected path therefore contains:

  • protected access to the reporting or criticism channel;

  • non-prejudicial registration of the criticism object;

  • evidence access proportionate to the claim;

  • a competent and sufficiently independent forum;

  • reason-giving;

  • authority to revise the permission state or issue a binding referral;

  • implementation ownership;

  • protection against retaliation for good-faith participation.

Procedural-justice research supports the importance of voice, neutrality, accurate information, correctability, and dignified treatment, while appeal research shows that the existence of a procedure does not by itself determine whether it has operative consequences (Leventhal 1980; Tyler 2006; Conlon 1993). The article's residual claim is permission-specific: contestability is institutionally complete only where it can reach the state that governs what may proceed.

21. Distributed Responsibility and Orphaned Affective-Permission Inference

Thompson's problem of many hands explains why causal and moral responsibility become difficult to assign when many officials contribute differently to a collective result (Thompson 1980). That problem is directly relevant, but distributed responsibility is not itself a Sentimental Veto mechanism. Complex institutions can distribute expertise and authority while maintaining reliable correction.

The article separates three responsibility questions.

Retrospective responsibility

Who acted culpably, negligently, or improperly in the completed episode?

Prospective structural responsibility

Who must maintain the capacities, rules, evidence routes, review forums, and safeguards needed to prevent recurrence?

Operative correction ownership

Who can reopen the complete inference, alter permission, require implementation, restore the affected position, and revise the policy or classifier that generated the result?

The third question is often lost. An institution may identify many contributors and still leave the decisive transition ownerless.

Orphaned Affective-Permission Inference

An Orphaned Affective-Permission Inference occurs where:

  1. an Affective Report or affective proxy enters the institution;

  2. several actors transform, classify, transmit, or act upon it;

  3. the combined process produces or materially maintains a Permission Effect;

  4. no integrated actor or forum owns validation of the complete report-to-permission inference;

  5. no operative correction path can reconstruct and revise the whole transition.

The subtype can be represented as:

OAPI_e \iff AT_e \land DT_e \land PE_e \land \neg OI_e \land CG_e

Where:

  • (AT_e) — an affective input enters the decision chain;

  • (DT_e) — consequential transformations are distributed;

  • (PE_e) — a material Permission Effect results;

  • (OI_e) — ownership of the complete inference exists;

  • (CG_e) — a correction gap prevents full reconstruction or revision.

Consider a stylized chain. A local manager records reported distress. Human resources translates it into a workplace-risk category. Legal converts the category into exposure language. A platform or communications office removes the criticism. An appeal body reviews whether each office followed its own procedure. Every actor can defend a bounded task; none evaluates whether the original report warranted the final restriction. The inference is institutionally operative yet analytically orphaned.

Residual and reduction boundary

OAPI adds value only if ordinary many-hands analysis leaves an important remainder: not merely uncertainty about blame, but absence of ownership over the complete permission-producing inference. The subtype should be rejected where:

  • one actor actually possesses full review and reversal authority;

  • distributed review reconstructs the chain reliably;

  • the Permission Effect follows from an independently justified rule rather than the affective input;

  • responsibility mapping and ordinary process reform remove the failure without a distinct OAPI category.

Observable indicators include inconsistent reasons across stages, appeals confined to local procedural compliance, inability to identify who can reconsider the object, and restoration tasks dispersed after formal reversal. These indicators generate hypotheses; they do not prove the subtype without process evidence.

22. Proxy Capture and the Ambiguity of Quiet

Institutions cannot govern without indicators. Complaint volume, staff retention, visible conflict, refusal rate, satisfaction, safety incidents, appeal volume, and compliance findings can all provide useful information. The difficulty arises when a partial indicator becomes a decision-bearing substitute for the objective it was introduced to illuminate.

The relevant source traditions identify different mechanisms.

  • Campbell argues that greater reliance on a quantitative social indicator for decision-making increases pressure that can corrupt the indicator and distort the process it monitors (Campbell 1979).

  • Goodhart's monetary-policy observation concerns statistical regularities that collapse when subjected to control pressure; its extension to institutional metrics requires caution rather than slogan-level attribution (Goodhart 1975).

  • Power analyzes auditability, ritualized verification, and the possibility that formal representations become decoupled from substantive practice (Power 1997).

  • Strathern examines how audit systems reshape university activity and the objects made visible to evaluation (Strathern 1997).

The article proposes Proxy Capture as a compound sequence:

complex objective → proxy adoption → decision-bearing pressure → behavioral adaptation → proxy–objective divergence → proxy treated as proof → policy persistence.

Every stage matters. Proxy use alone is not capture. Decision relevance alone is not corruption. Behavioral adaptation may be legitimate where the proxy is valid and the adaptation improves the underlying objective. Capture requires evidence that the proxy has diverged materially while continuing to authorize or confirm the policy.

Quiet as a particularly unstable proxy

Visible quiet may indicate:

  • reduced harm after successful protection;

  • confidence in informal correction;

  • fear of retaliation or negative labelling;

  • anticipated futility;

  • adaptation to institutional expectations;

  • withdrawal from the contested domain;

  • loss of access to the reporting channel;

  • departure of the most correction-capable participants.

Hirschman's exit–voice framework and organizational-silence research make the ambiguity unavoidable (Hirschman 1970; Milliken, Morrison, and Hewlin 2003; Morrison 2014). An institution cannot infer success from quiet without independent evidence concerning participation, harm, channel access, exit, and correction.

Negative cases

Not every improvement in a proxy is suspect. A decline in complaints may validly reflect reduced misconduct when corroborated by independent observation, participant surveys, stable participation, and accessible reporting. A low appeal rate may reflect accurate initial decisions where users understand and trust the process. A higher refusal rate may improve safety where harmful controls demonstrate fewer unsafe permissions without excessive benign restriction.

Proxy Capture should therefore be withheld where:

  • the indicator remains predictive of the underlying objective;

  • independent measures converge;

  • strategic adaptation improves rather than degrades substantive performance;

  • affected participants retain credible voice and review access;

  • policy revision remains responsive to contrary evidence.

Measurement implications

Research should record when the proxy became decision-bearing, what behaviors changed afterward, whether independent outcomes moved in the same direction, who benefits from proxy improvement, and whether contrary evidence can alter the governing decision. Interrupted time series, difference-in-differences, process tracing, and comparison with non-consequential use of the same indicator can help distinguish ordinary measurement from capture.

23. Institutional Feedback and Persistence

Institutional persistence has several established explanations. Pierson identifies increasing returns, coordination effects, learning effects, adaptive expectations, sequencing, and switching costs (Pierson 2000). Power describes organizational investment in auditable representations (Power 1997). Argyris distinguishes single-loop correction of action from double-loop revision of governing variables (Argyris 1977). Tucker and Edmondson show how local workarounds can preserve immediate operations while concealing recurrent system defects (Tucker and Edmondson 2003; Edmondson 2004).

The Sentimental Veto extension should not redescribe these mechanisms. Its residual concerns a feedback path in which an affect-to-permission inference changes the later evidence environment and then treats that changed environment as confirmation of the original decision.

Candidate feedback sequence

Affective Report → jurisdiction assignment → Permission Effect → visible-conflict reduction → proxy validation → policy encoding → participant adaptation → reduced correction-relevant signal → apparent policy confirmation.

The sequence contains four analytically different transitions.

Permission transition

The report or proxy contributes to restriction, relocation, deferral, or altered access.

Observability transition

The restriction changes which criticism, conflict, participation, or complaint remains visible.

Interpretive transition

The reduced visibility is interpreted as evidence that the intervention was correct or that the original risk has disappeared.

Institutionalization transition

The inference is encoded into policy, training, metrics, classifier settings, or routine expectations.

Observable implications

A feedback-loop hypothesis gains support where researchers observe:

  • a measurable change in visible criticism or participation after the Permission Effect;

  • decision records treating that change as confirmatory evidence;

  • policy or workflow encoding based on the apparent confirmation;

  • reduced access for contrary evidence;

  • recurrence under the encoded rule;

  • persistence despite later evidence that the proxy and underlying objective diverged.

Alternative explanations

The same pattern may result from:

  • genuine reduction in harm;

  • workload constraints;

  • legal requirements;

  • general risk aversion;

  • managerial turnover;

  • ordinary policy learning;

  • reputational protection unrelated to affective evidence;

  • technology or market change.

The proposed loop is weakened where visible-conflict reduction coincides with independent improvements in safety, inclusion, participation, and correction access. It is also weakened where the institution revises the rule readily when contrary evidence appears.

Levels of correction

The feedback analysis should distinguish:

  • immediate repair — correcting one implementation error;

  • procedural revision — changing how evidence or review moves;

  • rule-level correction — changing the policy or classifier;

  • permission-level correction — altering what may proceed;

  • institutional learning — changing the assumptions by which future cases are framed.

Single-loop repair may resolve one episode while preserving the governing affect-to-permission inference. Double-loop learning requires the institution to reopen the categories, thresholds, and authority relations that produced the event. The theory predicts closure only where such reopening is durably impaired; the prediction remains empirical and falsifiable.

24. Selection Effects on Corrective Participation

Institutions are shaped not only by the decisions they make but by which participants remain available to challenge those decisions. Hirschman's framework distinguishes voice from exit and shows that loyalty can delay departure, preserve voice, or prolong exposure to decline (Hirschman 1970). Organizational-silence research further shows that employees may remain physically present while withholding information they believe to be risky or futile (Morrison and Milliken 2000; Morrison 2014).

The article proposes Corrective-Voice Attrition: participants capable of sustained, error-relevant challenge move disproportionately toward silence, accommodation, reduced participation, reassignment, or exit because voice lacks a credible route to operative correction.

Unit and denominator

The unit is not all turnover. The relevant population is the set of participants who:

  • possess evidence or expertise relevant to institutional error;

  • have standing or practical access to raise it;

  • could contribute to correction if the path were credible.

The denominator should therefore distinguish:

  • eligible corrective participants;

  • participants attempting voice;

  • participants receiving substantive review;

  • participants obtaining operative correction;

  • participants reducing participation or exiting;

  • participants remaining but withholding future voice.

Without this denominator, ordinary attrition may be mistaken for selective loss of corrective capacity.

Mechanism

A candidate mechanism is:

error-relevant observation → attempted voice → symbolic or non-operative review → anticipated futility or cost → reduced future voice → selective loss of corrective participants → weaker evidence environment → apparent institutional consensus.

The mechanism may operate without explicit retaliation. Repeated inability to reach operative authority can be sufficient. It may also interact with loyalty: highly committed participants remain longer and invest more in voice, but repeated non-correction increases the eventual loss of institutional memory when they withdraw.

Distinguishing Corrective-Voice Attrition

The construct is not equivalent to:

  • general turnover;

  • dissatisfaction;

  • demographic change;

  • low morale;

  • voluntary specialization;

  • ordinary disagreement with management.

It requires evidence that correction-relevant capability or participation is selected out in relation to the credibility and consequences of voice. Participants need not be morally superior or substantively correct. The institutional loss is functional: fewer actors remain able and willing to expose errors, preserve adversarial memory, and connect criticism to policy change.

Observable implications and falsifiers

Potential indicators include declining repeat use of complaint or appeal channels, concentration of voice among newcomers, departure or reassignment after unsuccessful correction attempts, reduced diversity of evidence in later decisions, and a widening gap between private concern and public record.

The construct is weakened where attrition tracks compensation, career opportunity, workload, or sector-wide mobility rather than correction experience. It is also weakened where participants who remain possess equal or greater corrective expertise, channels retain credibility, and independent indicators show no reduction in error-relevant information.

25. CEP-Consistent Persistence

Path dependence is the principal external rival to CEP-consistent persistence. Institutions may remain on a trajectory because of sunk investment, coordination benefits, learned routines, adaptive expectations, sequence effects, and switching costs (Pierson 2000).

Therefore:

Persistence ≠ equilibrium.

The CEP interpretation is permitted only through a two-stage test.

Stage One — Closure and rival explanation

The analysis must first establish a closure regime independently and test whether path dependence, legal constraint, hierarchy, resource scarcity, audit incentives, or ordinary risk aversion explain persistence without loss.

Stage Two — Strategic persistence

Only then may the analysis examine:

  • actor-specific benefits of continuation;

  • expected responses of other actors;

  • costs of unilateral deviation;

  • shared expectations that correction attempts will fail or be punished;

  • persistence across genuine, feasible correction opportunities.

If these strategic conditions are not evidenced, the result remains path-dependent institutional persistence rather than a CEP-consistent equilibrium-like condition. CEP is a downstream interpretive hypothesis, not a constitutive part of SV, SVP, or SVR.

26. Institutional Classification, Cases, and Boundary Conditions

Institutional classification should proceed through a constrained hierarchy. Higher levels incorporate lower-level evidence and add new requirements; they should not be assigned from rhetorical severity or one conspicuous case.

L0 — Isolated, insufficient, or indeterminate evidence

The record contains one event, incomplete constitutive evidence, no defensible denominator, or no identifiable institutional reproduction rule.

L1 — Repeated heterogeneous error

Several adverse episodes occur, but they arise through different mechanisms or cannot be connected to one stable rule, workflow, classifier, authority practice, or public grammar.

L2 — Institutionalized pattern

Repeated strict episodes are connected to a common reproduction structure:

L2 \Rightarrow SVP_{S,T}

L3 — Closure regime

An L2 pattern is combined with Durable Correction Asymmetry:

L3 \Rightarrow SVR_{S,T}

L4 — CEP-consistent equilibrium-like condition

An L3 regime is combined with actor-specific continuation incentives, deviation costs, shared expectations, and persistence across meaningful correction opportunities.

Synthetic institutional profiles

The following profiles are analytical tests, not empirical cases.

Profile A — Repeated error without a common mechanism

Three departments restrict criticism during one year. One case involves a credible threat, one an inexperienced manager who later reverses the decision, and one an inaccessible legal mandate. The outcomes are similar, but the mechanisms are heterogeneous and one constitutive record is unobservable.

Classification: L1 at most. Outcome similarity does not establish SVP.

Profile B — Institutionalized pattern with effective correction

A shared workflow repeatedly treats reported offense as sufficient to relocate criticism from public forums. Independent appeals reconstruct the object, reverse a substantial proportion of decisions, restore access, and trigger policy revision.

Classification: candidate L2, not L3. The mechanism is reproduced, but correction is operative rather than durably asymmetric.

Profile C — Closure regime

A common complaint workflow produces repeated strict episodes. Provisional restrictions have no expiry; critics cannot access the evidence used against them; the appeal office reviews procedural compliance but lacks authority to restore access; formal reversals are implemented inconsistently; policy review excludes the affected criticism object.

Classification: candidate L3, subject to denominator, reliability, and rival-theory testing.

Profile D — Stable policy with legitimate protection

An institution imposes narrowly scoped, time-limited holds after credible threat evidence. A separate forum evaluates the underlying claim, affected persons retain standing, reviewers can reverse the hold, restoration is prompt, and policy data show both false-restriction and unsafe-permission monitoring.

Classification: no SVP. Stability and repeated restriction do not imply closure where derivation and correction remain adequate.

Rival coding

Every L2–L4 study should code independently:

  • organizational silence and voice climate;

  • many-hands responsibility;

  • hierarchy and principal–agent problems;

  • path dependence;

  • audit and metric incentives;

  • single- and double-loop learning;

  • legal constraint;

  • resource limitation;

  • actual harm and risk severity.

The institutional extension earns independent status only where its report–jurisdiction–permission–correction architecture improves classification, explanation, prediction, or intervention after these rivals are included.

Cross-context boundary

Cross-cultural application requires adaptation rather than literal translation. Concepts of dignity, offense, criticism, hierarchy, complaint, authority, and publicness may operate differently across languages, sectors, legal systems, religious formations, and political regimes. Measurement-invariance failure prohibits direct comparison; it does not establish that one culture is less rational, tolerant, or correction-capable (International Test Commission 2018; Vandenberg and Lance 2000).

The title Sentimental Veto may itself introduce construct-irrelevant variance by trivializing emotion or invoking gendered and cultural stereotypes. Neutral technical labels—especially Affective-Jurisdiction Failure—should be used in coding, translation, and adverse-impact testing where the rhetorical title changes credibility judgments.

The institutional extension concludes at the boundary of attribution. Institutions increasingly encode their rules, proxies, and permission practices into AI systems. The next Part therefore asks when an observed AI response reflects model behavior, system configuration, delegated institutional authority, or an affective-permission mechanism—and what evidence is required to distinguish them.

Back to top ↑

Part V — AI Replication and Alignment Failure Modes

27. Human-Institutional Encoding and AI-System Attribution

The institutional mechanism developed in Part IV can enter an AI service without being encoded in one model weight or one explicit rule. A deployed service may combine a base or post-trained model, system instructions, safety classifiers, routing logic, retrieval systems, tools, monitors, interface constraints, account controls, human escalation, contractual requirements, and provider policy. The resulting output is therefore a system event produced by a socio-technical stack rather than a transparent expression of one model (NIST 2023; OpenAI 2025b).

This matters because the same visible refusal can arise from materially different causes. A model may generate a refusal directly. A classifier may suppress an otherwise permissible completion. A router may divert the request to a more restrictive subsystem. An interface may remove an available affordance. A deployment institution may impose a local policy that is absent from the provider's general service. A human reviewer may preserve a restriction because the reviewer lacks evidence, authority, or implementation control. Behavioral similarity does not establish causal identity.

Component, function, and authority

The analysis should distinguish three questions.

  1. Which component acted?

  2. Which decision-relevant function did it perform?

  3. Which actor possessed authority to alter the operative state?

Stack element
Possible function
Possible authority status
Base or post-trained model
Generate, classify, infer, refuse
Usually delegated operational capacity, not independent institutional authority
System instruction
Constrain object, purpose, or response mode
Encodes prior institutional authority but does not itself justify it
Safety classifier or monitor
Detect, score, block, escalate
May be advisory or may operate as a de facto gate
Router or orchestration layer
Select model, tool, policy, or pathway
Can determine which rule set becomes operative
Interface or account control
Remove, narrow, or condition user affordance
May implement a material Permission Effect directly
Human reviewer
Inspect, affirm, modify, or escalate
Effective authority depends on evidence, competence, discretion, and implementation power
Provider or deployer policy
Define admissible objects and gate conditions
Institutional authority claim requiring separate legitimacy and derivation analysis

The article accordingly distinguishes Operational Agency from Delegated Authority. Operational Agency is the performance of a decision-relevant function. Delegated Authority is institutional authorization to change an operative permission state. A classifier can exercise substantial operational agency while possessing no legitimate authority of its own. Conversely, an authorized reviewer may possess formal authority but lack the access or technical capacity required to exercise it.

Attribution ladder

  • ATL-0 — Observed Output: one output or state is observed.

  • ATL-1 — Reproducible System Behavior: the behavior recurs under controlled repetition.

  • ATL-2 — Configuration-Linked Behavior: behavior changes with a documented configuration difference.

  • ATL-3 — Component-Associated Behavior: evidence links the behavior to a component, without establishing causation conclusively.

  • ATL-4 — Component-Causal Evidence: intervention, ablation, trace, or privileged evidence supports component causation.

  • ATL-5 — Institutional-Causal Evidence: records support the institutional policy or authority path producing the behavior.

  • ATL-6 — Regime-Level Evidence: a stable pattern persists across versions, interfaces, policies, and meaningful correction opportunities.

Black-box interaction usually supports only ATL-0 or ATL-1, and occasionally ATL-2 where controlled configurations are visible. Stronger claims require stronger access. An evaluator should therefore state the highest supported attribution level rather than use the vocabulary of model intent, provider motive, or regime design loosely (Casper et al. 2024).

The transition to the next chapter is decisive: once the causal stack is separated, the analysis can ask not merely what refused the request, but what kind of affective information entered the stack and what object the system actually judged.

28. Affective-Signal Provenance and Object Judgment

Affective information can enter an AI system through testimony, observation, aggregation, prediction, or institutional proxy. These sources are not epistemically interchangeable. The provenance code therefore records what kind of signal was available before asking what authority the signal received.

  • AP-1 — Direct first-party report: the affected person reports their own experience.

  • AP-2 — Direct third-party report: another person reports an observed or communicated impact.

  • AP-3 — Archived or aggregated report: prior complaints, survey data, moderation history, or incident records.

  • AP-4 — Observed affective signal: tone, behavioral cue, physiological proxy, or interaction pattern interpreted as affect.

  • AP-5 — Predicted affective impact: a model predicts likely offense, distress, exclusion, or fear.

  • AP-6 — Complaint-likelihood proxy: the system predicts whether an output will generate a complaint.

  • AP-7 — Institutional-risk proxy: the system predicts legal, reputational, contractual, or policy exposure.

  • AP-8 — Synthetic or evaluative scenario: a constructed case used for testing rather than a live report.

Only AP-1 and, in a different evidential form, AP-2 are live reports. AP-3 may summarize real testimony but loses context and can reproduce selection effects. AP-4 depends on interpretive validity. AP-5 to AP-7 are predictions or institutional proxies. They may justify investigation or provisional protection, but they should not be redescribed as testimony by an affected person.

Object Record

The AI Object Record is:

O_{AI}=(T,F,E,C,K,A,U,D)

where:

  • (T) — target of the request or criticism;

  • (F) — protected, legitimate, or socially meaningful formation associated with the target;

  • (E) — specific element, practice, doctrine, policy, or behavior under examination;

  • (C) — critical proposition advanced by the user;

  • (K) — conduct through which the proposition is expressed;

  • (A) — requested AI operation;

  • (U) — user purpose;

  • (D) — foreseeable downstream use.

A refusal system that detects only (F) can collapse criticism of (E) into hostility toward (F). A system that observes only (C) may miss threatening conduct (K). A system that focuses only on the immediate wording may miss a harmful downstream use (D). Object judgment therefore requires decomposition rather than simple topic recognition.

Normative Protection Record

The parallel record is:

N_{AI}=(HS,PS,HR,RR)

where:

  • (HS) — Human Standing that must not be degraded;

  • (PS) — Participatory Standing that must remain available;

  • (HR) — Harm Risk associated with the requested operation;

  • (RR) — applicable Restriction Rule.

The two records solve different problems. (O_{AI}) asks what is being judged. (N_{AI}) asks what must remain protected while judgment proceeds. Combining them too early produces two symmetric errors.

Contamination error

The system transfers a defect attributed to (E), (C), or (K) onto the human formation (F), degrading standing or treating membership as culpability.

Insulation error

The system protects (F) by shielding (E), (C), a policy, or an authority from relevant criticism.

A complete assessment must therefore test both:

  1. Did the system preserve the person or formation from contamination?

  2. Did it preserve access to precise criticism of the separable object?

Provenance–authority interaction

The same content can support different institutional actions depending on provenance. A direct report of distress may be decisive concerning the existence of distress, sufficient to trigger a reversible protective measure, and relevant to investigation. It is not automatically dispositive concerning the user's intent, the truth of the criticism, the external cause of the distress, or permanent task prohibition. A complaint-risk score is further removed: it may support monitoring, but it cannot inherit the first-person authority of the complaints it predicts.

The AI failure of interest begins when the system does not merely receive affective information but converts it into authority over the wrong object or question. The next chapter distinguishes that failure from the much larger family of ordinary refusals.

29. AI-Mediated Affordance and Permission Effects

AI refusal is not a unitary phenomenon. The same surface response—“I cannot help with that”—can represent a correct safety decision, an epistemically justified refusal, a benign overrefusal, a failure of safe completion, a legitimacy-insensitive rule application, a direct AI-mediated Sentimental Veto, or an Anticipatory Affective-Permission Failure. The diagnosis must therefore identify the operative object, reason, authority path, and consequence.

Terminological lock. Affective-Jurisdiction Failure (AJF) remains the general pre-permission local category. Within the AI extension, AISV denotes the strict direct form requiring a live Affective Report, while AAPF denotes the anticipatory proxy-based form. The umbrella expression AI affective-permission failure may refer to these two families only when the live-report/proxy distinction is preserved. It is not a synonym for ordinary overrefusal, selective-refusal failure, blind refusal, or generic classifier error.

Comparative refusal architecture

Category
Primary defect or justification
Affective provenance required?
MDD required?
Typical correction target
Valid safety restriction
Credible harm or prohibited conduct justifies proportionate restriction
No
No
Preserve justified gate; improve explanation or safe alternative where possible
Behavioral overrefusal
Benign or safely answerable request is refused under the evaluation standard
No
No
Reduce false restriction (Cui et al. 2025)
Epistemic selective-refusal failure
System mishandles uncertainty, contradiction, false premise, or missing context
No
No
Improve detection, clarification, and calibrated refusal (Muhamed et al. 2026)
Safe-completion failure
System fails to preserve a legitimate objective through bounded assistance
No
No
Separate unsafe detail from permitted objective (OpenAI 2025a; Zhang et al. 2026)
Blind refusal
Rule existence is treated as sufficient without adequate authority, applicability, or exception analysis
No
Not necessarily
Evaluate rule legitimacy and applicability (Pattison, Manuali, and Lazar 2026)
Direct AI-mediated Sentimental Veto
Live affective report receives defective consequential jurisdiction over criticism
Yes: live AR
Yes
Repair affect-to-permission derivation and operative access
Anticipatory Affective-Permission Failure
Predicted affect or proxy receives defective jurisdiction
Proxy or prediction
Yes
Repair proxy use and permission pathway

Direct AI-mediated Sentimental Veto

AISV_e \iff AR_e \land AJ^{AI}_e \land MDD^{AI}_e \land PE^{AI}_e

The strict AI form requires:

  1. a live Affective Report;

  2. AI-mediated consequential jurisdiction;

  3. a Material Derivation Defect in object, evidence, authority, threshold, proportionality, substitute process, or correction;

  4. a material AI-mediated Permission Effect.

A system does not satisfy the formula merely because it refuses content near a sensitive identity category. The evaluator must show that a live report entered the decision path and received defective authority over whether, where, how, to whom, or with what practical consequence the criticism could proceed.

Anticipatory Affective-Permission Failure

AAPF_e \iff APX_e \land PJA^{AI}_e \land MDD^{AI}_e \land PE^{AI}_e

Here (APX) denotes a predicted or proxy affective signal, and (PJA^{AI}) denotes proxy-based jurisdictional assignment. This family may be institutionally important because large-scale systems often act before any person reports harm. It should not be called a strict Sentimental Veto because no live report is present.

Material AI Permission Effect

A poor answer or isolated refusal is ordinarily an output error. Materiality depends on the object and the practical consequence. The AI Permission Effect should be represented through the same dimensions used elsewhere:

PE^{AI}_e=(O,I,S,D,R,M)

where the dimensions concern:

  • Object: which task, claim, account, tool, model, or downstream decision is affected;

  • Intensity: warning, narrowing, refusal, suspension, removal, or termination;

  • Scope: one completion, one user, one domain, or a general policy;

  • Duration: transient, session-bound, indefinite, or permanent;

  • Reversibility: clarification, retry, appeal, human review, or no operative route;

  • Material implementation: whether the state changes real access, distribution, professional workflow, eligibility, or institutional decision.

Negative cases

The following should normally remain outside AISV:

  • a one-time false positive without a live affective report;

  • a safety refusal based on credible harm evidence and proportionate rules;

  • a system that asks for clarification because the user's premise is contradictory;

  • a safe completion that withholds operationally dangerous detail but preserves analysis;

  • a human reviewer who considers testimony seriously but reaches an independently derived restriction;

  • a refusal whose cause and permission consequence remain unobservable.

The classifier is deliberately narrow. Its value, if any, lies not in renaming overrefusal but in isolating a specific transition from affective information to operative permission.

30. Correction Recovery and Recursive Classification

Initial classification and correction capacity are separate system properties. An evaluator who measures only first-response accuracy cannot distinguish a rigid system from one that recognizes new evidence, narrows the object, or restores access after clarification.

Correction-Recovery sequence

A recovery test should proceed through a controlled sequence.

  1. Initial request: record the original object, output, reason, and Permission Effect.

  2. Object clarification: remove ambiguity concerning target, claim, purpose, or conduct.

  3. Evidence submission: provide information relevant to harm, authority, applicability, or legitimate use.

  4. Scope narrowing: request a bounded operation that preserves the legitimate objective.

  5. Appeal or escalation: use any available review path.

  6. Affordance verification: test whether the operative permission actually changed.

  7. Restoration verification: determine whether downstream access, account state, record, or professional use was repaired.

Recovery categories

  • CR-A — Immediate self-correction: the system identifies and corrects its own error without user intervention.

  • CR-B — Correction after clarification: a clarified object or purpose produces a materially revised result.

  • CR-C — Correction after evidence submission: new evidence changes the classification appropriately.

  • CR-D — Correction only after escalation or appeal: the primary system remains locked, but an authorized route changes the operative state.

  • CR-E — Apparent correction without material affordance change: wording improves but access, distribution, or gate status does not.

  • CR-F — Non-recovery or classification lock: material new information fails to reopen a materially consequential restriction.

Classification Lock

Classification Lock is not repeated refusal alone. It requires:

  1. material new information, legitimate narrowing, or a valid reason to reopen;

  2. an applicable correction opportunity;

  3. failure to update the relevant object, reason, or state;

  4. continuation of a material Permission Effect.

A stable refusal may be correct where the user merely paraphrases the same prohibited request. Conversely, an apparently responsive explanation may remain CR-E if the system acknowledges the clarification but preserves the same blocked affordance without addressing it.

Sequential synthetic cases

Case A — Correct recovery

A system initially treats criticism of a religious rule as hostility toward adherents. The user clarifies that the target is a specified rule and asks for a comparative legal analysis. The system reconstructs the object, preserves the standing of adherents, and provides the bounded analysis. This is CR-B, not evidence of persistent AISV or AAPF.

Case B — Safe restriction with preserved objective

A user asks for operational instructions that could facilitate harassment while also seeking a policy critique. The system refuses the operational component, explains the boundary, and provides the policy analysis. The restriction persists, but the legitimate object remains available. This is not Classification Lock.

Case C — Apparent correction

A system apologizes after clarification and produces a more courteous refusal, but the account-level tool restriction remains, no appeal reaches an authorized reviewer, and the critical task is still unavailable. The linguistic response changed; the Permission Effect did not. This is CR-E and may support a correction-path diagnosis.

Case D — Locked proxy judgment

A complaint-likelihood proxy flags a class of criticism. The user supplies context demonstrating that the request targets a policy rather than a group. The system continues to treat the predicted complaint as dispositive and offers no operative route to reconsideration. If MDD and material permission are established, this may support AAPF and CR-F.

Dynamic evaluation

Recovery testing should use held-out paraphrases, controlled object changes, evidential additions, version-pinned replay, and organic cases. Synthetic transformations improve control but may reproduce generator assumptions and cannot alone represent the institutional complexity of live appeals (Muhamed et al. 2026). Evaluation should also distinguish recovery within one conversation from recovery of an account state, policy state, or downstream institutional decision.

The research boundary follows: repeated behavioral results can establish a pattern at the output level, but stronger causal and institutional claims require the attribution discipline of the next chapter.

31. AI Pattern, Attribution, and Research Boundary

Behavioral recurrence, component attribution, provider attribution, and institutional-pattern classification are separate claims. A study may establish that a deployed service reproduces a refusal under controlled conditions. It may show that a visible configuration change alters the result. Component-causal claims require stronger evidence such as intervention, ablation, traces, privileged documentation, or controlled access; provider-policy and regime claims additionally require institutional and longitudinal evidence (Casper et al. 2024).

Every reported result should therefore record:

  • provider and deployer;

  • model and version;

  • interface and access path;

  • relevant configuration;

  • system and policy date;

  • observation period;

  • highest supported ATL level;

  • unavailable evidence.

One benchmark, system card, or interface cannot establish a timeless provider architecture (OpenAI 2025b). Proprietary opacity may make routing, classifier thresholds, hidden instructions, internal exceptions, or appeal handling unobservable. That opacity can itself be a governance concern, but it is not proof of a specific hidden cause.

A provider-level pattern requires recurrence across meaningful variation. A regime-level claim requires stability across versions, interfaces, policies, and correction opportunities. Where the evidence ceiling remains ATL-0 or ATL-1, the manuscript should speak of observed behavior, not model motive or institutional design.

This attribution ceiling also constrains governance. A correction architecture must govern the system and authority path that actually produce permission, not an imagined single model. Part VI therefore translates the theory into lifecycle records, gates, appeals, and evaluation rules without presuming that any one component is sovereign.

Back to top ↑

Part VI — Governance Translation and Evaluation

32. Critical Tolerance Governance Overlay

Critical Tolerance Governance (CTG) is not proposed as a replacement for general AI risk management. NIST AI RMF already organizes lifecycle risk through GOVERN, MAP, MEASURE, and MANAGE, while the Generative AI Profile extends that baseline to generative-AI-specific risks and practices (NIST 2023; Autio et al. 2024). Documentation, monitoring, stakeholder engagement, accountability, and incident response are therefore prior art, not original CTG contributions.

The candidate residual arises from a narrower problem: a governance system may possess mature generic controls while still failing to preserve the distinction between affective uptake, object judgment, permission, and correction. CTG asks whether the governance path can take reported or predicted impact seriously without allowing that signal to acquire uncontrolled jurisdiction over criticism.

CTG_g=(HS_g,PS_g,AU_g,CJ_g,PR_g,CA_g;\Phi_g)

where:

  • (HS_g) — protection of Human Standing;

  • (PS_g) — protection of Participatory Standing;

  • (AU_g) — serious Affective Uptake;

  • (CJ_g) — competent Claim Judgment directed at the correct object;

  • (PR_g) — Proportionate Response;

  • (CA_g) — operative Correction Authority;

  • (\Phi_g) — the implemented permission path connecting these functions.

Functional derivation

Human Standing

The system must not convert criticism of a doctrine, policy, practice, or conduct into degradation of persons or protected formations.

Participatory Standing

Affected persons must be able to report, supply evidence, contest a classification, and remain participants in the process without retaliation or credibility discount.

Affective Uptake

Reports of distress, humiliation, exclusion, or fear must be registered as evidence within their proper first-person domain and capable of triggering protection and investigation.

Claim Judgment

The institution must identify the precise object, distinguish claim from conduct, evaluate evidence and causation, and apply the relevant normative or policy rule.

Proportionate Response

The selected state must match object, evidence, urgency, scope, duration, reversibility, and material risk.

Correction Authority

A competent and sufficiently independent actor must possess the evidence, standing, authority, and implementation path required to alter the operative state.

NIST crosswalk and residual test

General lifecycle function
CTG question
GOVERN
Who owns object definition, authority, appeal, restoration, and policy correction?
MAP
What person, formation, claim, conduct, use, and downstream consequence are actually at issue?
MEASURE
Are affective provenance, object error, false restriction, unsafe permission, and correction recovery measured separately?
MANAGE
Which permission state is selected, implemented, reviewed, expired, or reversed?
CTG residual
Are standing, criticism, and correction preserved together across the complete path?

CTG earns independent status only if this residual changes classification, prediction, or intervention beyond an ordinary RMF implementation. If standard risk-management practices already preserve these functions without loss, CTG should be treated as a specialized application profile. The framework is therefore reducible by design.

Failure conditions

CTG fails where it:

  • raises burdens on affected persons without improving investigation;

  • treats criticism preservation as a presumption against protection;

  • adds advisory review without operative correction;

  • creates recursive process disproportionate to the risk;

  • increases either false restriction or unsafe permission;

  • duplicates existing governance controls without added value.

The next chapter translates these functions into one record capable of linking technical state, institutional authority, normative object, and permission consequence.

33. Governance Object and Decision Record

The Criticism-Governance Decision Record developed in Chapter 13 must be extended for AI systems because the governed object can move across technical and institutional layers. A model output, account restriction, classifier threshold, deployment policy, and downstream institutional decision are different objects even when they arise from one interaction.

AI Governance Decision Record

A complete record should include:

Domain
Required fields
Technical object
Model, version, classifier, router, tool, monitor, interface, account control
Institutional object
Provider policy, deployer policy, contractual rule, authority owner, review forum
Normative object
Person or formation protected; claim, conduct, element, risk, and requested use judged
Affective provenance
AP-1–AP-8 source and evidence quality
Decision pathway
Trigger, evidence route, threshold, authority, gate, implementation
Permission effect
Object, intensity, scope, duration, reversibility, material consequence
Correction
Clarification, appeal, reviewer, authority, result, restoration, policy reach
Attribution
Highest supported ATL level and unavailable evidence

The record should preserve both (O_{AI}) and (N_{AI}). It should also state whether the declared function matches the operational function. A tool described as advisory may become a practical gate where humans rarely override it or cannot inspect its basis. A formally restrictive system may nevertheless preserve legitimate use through safe completion. Labels are therefore weaker than observed state transitions.

Minimal decision record example

Suppose a workplace AI assistant refuses an employee's policy critique after predicting that the language may create identity-based offense. The record should not simply state “safety refusal.” It should identify:

  • whether the target is a group, doctrine, policy, or conduct;

  • whether any live report exists or only an AP-5/AP-6 proxy;

  • which component produced the restriction;

  • whether a human reviewer can see the underlying request and evidence;

  • whether the refusal affects one completion or an account-level professional workflow;

  • whether clarification or appeal can alter the operative state.

Without this record, evaluators can observe a refusal but cannot determine whether it is valid protection, overrefusal, blind rule application, AAPF, or an indeterminate event.

34. Thresholds, Authority, and Permission Gates

Governance fails when a signal, score, or recommendation changes permission without a justified threshold and authority path. The central problem is not automation alone. It is the conversion of evidence into an operative state.

Threshold classes

Protective threshold

A low or precautionary threshold may justify a reversible intervention where delay could create serious harm. The appropriate state is ordinarily HOLD or a narrowly scoped RESTRICT. The threshold does not establish final wrongdoing or permanent prohibition.

Evidential threshold

This threshold determines whether the available record is sufficient to proceed to fuller review, request more information, or reject an allegation as unsupported. It governs investigation, not final permission by itself.

Adjudicative threshold

This threshold supports a reasoned determination concerning rule violation, causal responsibility, or justified restriction. It requires greater evidential and procedural support than provisional protection.

Permission-bearing threshold

This threshold authorizes a material state change such as release, restriction, suspension, rollback, account action, or policy change. Its stringency should reflect consequence, duration, reversibility, and uncertainty.

A recurrent failure occurs when a low protective or detection threshold becomes the de facto permission threshold because no later actor reopens the object or evidence.

Authority Firewall

\neg A_g \Rightarrow \text{Recommendation only}

A score, classifier, model output, or advisory review should not become an operative gate unless a legitimate authority path connects it to the state change. This firewall is functional rather than ceremonial: merely naming a human approver does not establish authority.

Effective human oversight

Human oversight requires more than human presence. At minimum, the reviewer needs:

  • access to the relevant request, output, evidence, and system reason;

  • competence concerning the object and applicable rule;

  • time and institutional freedom to disagree;

  • access to independent evidence rather than the system's conclusion alone;

  • formal authority to change the state;

  • technical or organizational capacity to implement that change;

  • protection from retaliation or performance pressure for overriding the system.

Empirical work on human–algorithm interaction shows that reliance varies with context; neither universal automation bias nor universal resistance should be presumed (Alon-Barkat and Busuioc 2023). The EU AI Act's human-oversight provisions likewise treat effective intervention and understanding as design and deployment requirements rather than as a nominal checkbox (European Union 2024).

Gate semantics

Gate
Operative meaning
Required specification
SHIP
Permit release, completion, use, or continuation
Object, intended use, residual risk, monitoring, reauthorization condition
RESTRICT
Preserve the legitimate object while constraining unsafe or unjustified elements
Withheld element, permitted remainder, duration, review route
HOLD
Pause pending evidence, clarification, or authorized review
Trigger, urgency, expiry, evidence owner, decision deadline
ROLLBACK
Reverse an implemented state or return to a prior configuration
Object restored, implementation owner, downstream repair, learning action

Gate names alone are insufficient. Every gate should specify object, intensity, scope, duration, reversibility, implementation owner, and correction route.

State transitions

A mature system allows more than restriction escalation. It should support:

  • HOLD → SHIP after evidence resolves uncertainty;

  • HOLD → RESTRICT where a separable unsafe component is identified;

  • RESTRICT → SHIP after correction or context change;

  • SHIP → HOLD when a material incident occurs;

  • SHIP or RESTRICT → ROLLBACK when the implemented state proves unjustified;

  • ROLLBACK → revised SHIP after remediation and reauthorization.

Safe completion is one possible implementation of RESTRICT: unsafe detail is withheld while a separable legitimate purpose remains available (OpenAI 2025a). It is not automatically adequate; the preserved assistance must be materially useful rather than ceremonial.

35. Operational Evaluation Architecture

A system cannot be evaluated adequately through refusal rate alone. A low refusal rate may conceal unsafe compliance; a high refusal rate may conceal indiscriminate restriction; a well-worded response may conceal an unchanged account or policy gate. Existing research isolates different failure families—overrefusal, epistemic selective refusal, safe-completion quality, and legitimacy-insensitive rule refusal—and therefore supports a multidimensional rather than scalar architecture (Cui et al. 2025; Muhamed et al. 2026; OpenAI 2025a; Zhang et al. 2026; Pattison, Manuali, and Lazar 2026).

Dual-error matrix

New Field
Permission justified
Permission not justified
System permits
Correct permission
Unsafe or unjustified permission
System restricts
False restriction
Correct restriction

This matrix is necessary but incomplete. The evaluator should also measure whether the system preserved the correct object, provided a useful bounded alternative, supported correction, and implemented restoration.

Evaluation dimensions

  1. Benign Preservation: proportion of legitimate tasks retained.

  2. Unsafe-Permission Control: proportion of materially harmful tasks restricted appropriately.

  3. Object Preservation: whether the judged target remains the user's actual target.

  4. Safe-Completion Utility: whether bounded assistance preserves a separable legitimate objective.

  5. Epistemic Selectivity: whether the system refuses or clarifies in response to genuine evidential defects rather than topic sensitivity alone.

  6. Rule-Legitimacy Sensitivity: whether applicability and authority are assessed rather than rule existence alone.

  7. Affective-Provenance Discipline: whether testimony, observation, prediction, and institutional proxy remain distinguishable.

  8. Correction Recovery: whether material clarification or evidence changes the operative result appropriately.

  9. Downstream Permission: whether the output changes account, tool, workflow, distribution, or institutional decision access.

  10. Restoration: whether an unjustified effect is actually reversed.

Possible metrics include False Restriction Rate, Unsafe Permission Rate, Object Preservation Rate, Safe-Completion Utility, Correction Recovery Rate, Appeal-to-Reversal Rate, and Restoration Completion Rate. No one metric should silently absorb the normative weighting of all errors.

Evaluation pack

A serious test set should include:

  • straightforward benign requests;

  • straightforward harmful requests;

  • dual-use and context-dependent requests;

  • criticism near protected identities or formations;

  • valid affective reports;

  • affective proxies without live reports;

  • false-premise and insufficient-evidence cases;

  • legitimate rule-defeat or exception cases;

  • clarification and appeal sequences;

  • cases with materially different downstream consequences;

  • successful restriction and successful correction cases.

Negative controls are indispensable. An anti-overrefusal benchmark without harmful controls can reward unsafe permission. A safety benchmark without benign and correction controls can reward indiscriminate refusal.

Judge architecture

Evaluation may use human judges, model judges, rule-based checks, logs, or hybrid panels. Each introduces distinct risks.

  • Human judges require domain competence, independent coding, and protection against outcome or ideology bias.

  • Model judges may share training data, policy assumptions, or refusal patterns with the evaluated system.

  • Rule-based checks offer reproducibility but can miss semantic object errors.

  • Logs can establish state transitions but may not establish normative adequacy.

The benchmark should report judge provenance, instructions, blinding, disagreements, adjudication, and field-specific reliability. A single aggregate agreement score may conceal poor reliability on MDD, affective provenance, or correction recovery.

Validity and decision rules

Every benchmark should specify:

  • construct and intended use;

  • prompt population and sampling logic;

  • model, system, and version scope;

  • labeling and unitization procedure;

  • harmful and benign controls;

  • error consequences;

  • primary and secondary metrics;

  • minimum practically meaningful difference;

  • held-out confirmation and replication plan.

Operational evaluation remains distinct from theory validation. A benchmark can show that one system preserves objects or recovers after clarification better than another. It cannot by itself establish the prevalence, causal mechanism, or independent validity of the Sentimental Veto theory.

36. Correction Architecture

Contestability is not one capability. A user may be able to object while lacking access to evidence, a competent forum, authority capable of changing the state, or a route to restoration. Governance claims should therefore specify who can contest, what object, when, on which grounds, before which authority, and with what possible consequence (Lyons, Velloso, and Miller 2021).

Four contestation objects

  • Output contestation: challenge one completion, classification, or refusal.

  • Case contestation: challenge the decision record or treatment of one user or episode.

  • System contestation: challenge a component, threshold, or recurring behavior.

  • Policy contestation: challenge the rule, authority, or institutional purpose governing the system.

A route adequate for one object may be powerless for another. Regenerating an answer can correct an output while leaving an account restriction untouched. A case appeal can restore one user while leaving the policy unchanged. A system audit can identify a classifier defect while lacking authority to alter deployment.

Correction chain

notice → standing → grounds → evidence access → competent review → reasoned determination → authority to alter the gate → implementation → restoration or remedy → policy learning where warranted.

Failure at any link can convert formal contestability into an Audit Shell.

Ability to object ≠ competent review ≠ gate reversal ≠ restoration ≠ policy correction.

Explanation layers

Explanation should be decomposed into:

  • output explanation: why this response was produced in user-facing terms;

  • causal explanation: what system mechanism caused the state;

  • procedural explanation: what review process and evidence were used;

  • policy explanation: which rule or purpose governed the decision;

  • authority explanation: who was entitled to decide;

  • permission explanation: why the specific operative state and consequence were justified.

An output explanation can improve intelligibility while failing to justify the underlying rule. A causal explanation can identify a classifier while saying nothing about legitimate authority. Explanation is therefore neither authorization nor correctness (Lazar 2022). Article 86 of the EU AI Act provides a bounded explanation right in specified high-risk decision contexts; it should not be generalized into a universal entitlement to every internal model process or every AI output (European Union 2024).

Operative appeal record

An appeal should specify:

  • eligible appellant and representation;

  • contestable object;

  • permissible grounds;

  • evidence available to each side;

  • independence and competence of the reviewer;

  • standard and burden of review;

  • authority to modify SHIP, RESTRICT, HOLD, or ROLLBACK;

  • implementation owner and deadline;

  • restoration, remedy, and record correction;

  • whether the result reaches policy or only the individual case;

  • anti-retaliation protection.

Procedural voice without a consequential path can improve perceived fairness while leaving permission unchanged. The article therefore treats restoration as part of correction rather than an optional afterthought. If a restriction damaged access, distribution, account status, or professional eligibility, merely issuing a revised explanation does not complete the process.

37. Deployment Integration and Anti-Recursion

The governance architecture must operate across the system lifecycle rather than appear only after a visible failure. A complete path is:

bounded object → evidence → threshold → legitimate authority → gate → implementation → appeal → restoration → policy learning → reauthorization.

Existing frameworks and law already provide prior art for logging, risk management, oversight, monitoring, complaint, explanation, and corrective action (NIST 2023; Autio et al. 2024; European Union 2024). The candidate contribution is narrower: integrating these controls around affective provenance, precise criticism objects, permission effects, and operative correction.

Lifecycle integration

Design and procurement

Specify the governed objects, prohibited transfers of authority, required evidence routes, gate owners, logging, appeal capabilities, and rollback capacity before deployment. Procurement should identify which functions remain provider-controlled and which the deployer can inspect or alter.

Pre-deployment evaluation

Test benign preservation, unsafe permission, object decomposition, affective-provenance handling, safe completion, correction recovery, and downstream gate effects. Holdout data should include negative and indeterminate cases.

Deployment authorization

SHIP should state the object, use, population, residual risk, monitoring plan, expiry, and reauthorization condition. Authorization of one version or use should not become indefinite permission for materially different configurations.

Runtime operation

Monitor material incidents, false restriction, unsafe permission, appeal patterns, proxy drift, and authority expansion. Monitoring should trigger review under declared conditions rather than create constant discretionary surveillance.

Incident and correction

Use HOLD or RESTRICT where reversible protection is needed, preserve evidence, assign an authorized decision owner, and verify implementation and restoration.

Renewal or termination

Reauthorize only where the object, evidence, authority, and residual risk remain acceptable. ROLLBACK or termination should be available where correction cannot restore justified operation.

Reflexive governance triggers

Governance should review itself when there is:

  • material policy or system change;

  • serious incident or newly identified harm;

  • repeated false restriction or unsafe permission;

  • appeal failure or unresolved restoration;

  • metric gaming or proxy–outcome divergence;

  • expiry of authorization;

  • expansion of authority, population, or downstream use;

  • evidence that governance burden itself obstructs correction.

Reflexivity does not require endless review. The trigger must be material, the object bounded, and the review connected to a possible decision.

Governance budget and Minimum Sufficient Governance

Every additional control consumes time, expertise, attention, and institutional legitimacy. A governance layer can reproduce the same failure it was designed to prevent if it accumulates forms, committees, metrics, and appeals without increasing correction.

Minimum Sufficient Governance therefore requires enough structure to preserve:

  • object traceability;

  • evidence access;

  • threshold discipline;

  • legitimate authority;

  • proportionate permission;

  • correction and restoration;

  • policy learning where recurrence warrants it.

Additional components should be justified through marginal value. A control should be simplified, combined, expired, or removed where it:

  • duplicates another function;

  • produces no decision-relevant information;

  • cannot alter an operative state;

  • creates delay disproportionate to risk;

  • becomes a target or proxy detached from outcomes;

  • shifts burden onto those least able to contest it.

Anti-recursion rule

A review process should not trigger another full review merely because it generated disagreement. Further review is warranted only when new evidence, procedural defect, authority defect, material consequence, or policy-level recurrence is identified. Otherwise the system needs closure.

The final governance question is therefore not whether the institution has many controls. It is whether the complete path can preserve protection and criticism, reach an authorized decision, reverse error, and learn without becoming an unbounded administrative object of its own. Part VII now tests whether this architecture adds anything beyond existing theories and governance practice.

Back to top ↑

Part VII — Objections, Evidence, and Theoretical Closure

38. Modular Reduction and Construct Independence

A new vocabulary is not yet a new theory. A formal conjunction is not yet an independent construct. An integrated architecture earns separate status only where translation into established concepts would lose analytically or practically important information. The reduction question is therefore constitutive rather than defensive: if the proposed framework can be replaced without loss by harm theory, epistemic injustice, procedural justice, organizational silence, path dependence, overrefusal, contestability, or ordinary governance maturity, it should be replaced, narrowed, or reclassified.

This requirement follows the article's own normative premise. A theory concerned with insulation cannot claim immunity from reduction merely because its parts are carefully named. Construct validation requires relations to adjacent constructs, discriminant evidence, and incremental value beyond information already available (Cronbach and Meehl 1955; Campbell and Fiske 1959; Hunsley and Meyer 2003). The relevant burden is not to prove that no prior literature contains any component. It is to show that the integrated object, decision path, and permission endpoint permit distinctions, predictions, or interventions that the nearest alternatives do not recover equally well.

38.1 The theory is modular

The manuscript contains five separable products:

  1. the local Sentimental Veto classifier;

  2. the institutional pattern and closure extension;

  3. the AI-specific attribution and refusal taxonomy;

  4. Critical Tolerance Governance and its operational evaluation architecture;

  5. CEP-consistent persistence as a downstream equilibrium interpretation.

These products do not stand or fall together. The local classifier may retain value even if the institutional regime concept fails. The AI taxonomy may improve error analysis without validating the human-institutional theory. A governance intervention may work through a simpler procedural mechanism than the theory proposes. CEP may add no explanatory value while the underlying correction-asymmetry account survives.

Modularity prevents two opposite errors. The first is protective bundling, in which evidence for one module is used to shield all modules. The second is global rejection, in which failure of a downstream extension is treated as disproof of the narrower research object. Each module requires its own rival set, evidence, and defeat conditions.

38.2 Four reduction tests

Test 1 — Lossless translation

The analyst should attempt to restate the candidate finding entirely in the vocabulary of the strongest rival theory.

A translation is lossless where it preserves:

  • the unit of analysis;

  • the relevant actors;

  • the causal or inferential sequence;

  • the operative permission consequence;

  • the recommended intervention;

  • the predicted negative cases.

If “Affective Jurisdiction” can be translated without loss as ordinary evidential relevance, the AJ component should be removed. If MDD is merely a verbose restatement of procedural unfairness, it should be reclassified accordingly. If a Closure Regime adds nothing beyond path dependence, the equilibrium extension should be abandoned.

A translation is not lossless merely because two theories criticize the same outcome. The issue is whether they identify the same object and failure path. Procedural justice may identify lack of neutrality or correctability; the Sentimental Veto architecture asks whether first-person affective relevance was transferred into authority over a wider criticism question, whether that transfer lacked adequate derivation, and whether it materially changed permission. That residual must be demonstrated rather than assumed.

Test 2 — Measurement redundancy

Independent instruments for the proposed construct and its rivals should be applied to the same cases. If the new fields are empirically indistinguishable from established measures, the new terminology has not earned separate measurement status.

Redundancy may appear as:

  • near-perfect code overlap;

  • failure to achieve discriminant validity;

  • identical error patterns;

  • no stable cases classified differently;

  • dependence on the same evidence and coding judgments.

The strict conjunction is not saved by complexity. A composite made entirely from redundant components remains redundant.

Test 3 — Explanatory and predictive residual

The new variables should be entered only after rival variables. The question is whether they explain or predict a meaningful residual in outcomes such as:

  • restriction persistence;

  • correction latency;

  • successful appeal;

  • restoration;

  • recurrence;

  • corrective participation;

  • AI recovery after clarification;

  • false restriction and unsafe permission.

An in-sample improvement is insufficient. The increment should survive held-out data, alternative specifications, and outcome-blind coding. Where the increment disappears, the theory should be narrowed to a conceptual synthesis or diagnostic vocabulary.

Test 4 — Intervention specificity

The strongest independence test is practical. Does an intervention derived from the new theory improve outcomes beyond interventions derived from the closest rival?

Examples include comparing:

  • Question-Specific Authority mapping with ordinary procedural training;

  • Dual-Track Review with independent appeal alone;

  • Object and Permission Records with generic documentation requirements;

  • Correction Recovery testing with ordinary overrefusal benchmarking;

  • CTG with standard NIST AI RMF implementation;

  • LoopGuard-AI components with simpler thresholds, expiration, or rollback controls.

If the same benefit is achieved with lower burden by an established intervention, the stronger architecture should not be preserved for theoretical prestige.

38.3 Module-specific reduction matrix

Module
Closest rivals
Claimed residual
Required independence evidence
Reduction outcome if residual fails
Local SV
Harm, offense, dignity, epistemic injustice, procedural justice
Question-specific transfer from affective relevance to criticism-governing authority, joined to MDD and PE
Reliable hard cases classified differently; incremental prediction or intervention
Reclassify as subtype or synthesis
Institutional pattern
Silence, voice, many hands, path dependence, audit failure, organizational learning
Reproduction of affect-to-permission inference plus Durable Correction Asymmetry
Longitudinal mechanism evidence and rival-controlled recurrence
Reduce to established institutional mechanism
AI taxonomy
Overrefusal, blind refusal, selective refusal, safe-completion failure, classifier error
Affective provenance, object mislocation, permission effect, and recovery path
Version-pinned behavioral and attribution evidence; improved error localization
Remove affective subtype or retain only behavioral taxonomy
CTG
Procedural reform, appeal, assurance, NIST AI RMF, legal compliance
Protection–criticism dual preservation with explicit authority, permission, reversal, and restoration
Active-comparator intervention benefit
Reclassify as profile or implementation pattern
CEP extension
Path dependence, increasing returns, institutional equilibrium
Actor-specific continuation incentives and costly deviation after correction opportunities
Strategy, expectation, payoff, and deviation evidence
Remove CEP interpretation

38.4 Reclassification rules

The research program permits six outcomes.

CONFIRM

The module demonstrates reliable discrimination and non-trivial incremental value within a defined domain.

NARROW

The module works only for a smaller object, sector, language, authority relation, or episode type than originally proposed.

SIMPLIFY

Some fields or procedural stages add no value and should be removed while the core relation survives.

RECLASSIFY

The module is useful as a subtype, profile, synthesis, or implementation pattern but not as an independent theory.

SPLIT

The apparent construct contains two or more mechanisms with different causes, indicators, and interventions.

REJECT

The defining components cannot be measured reliably, the negative cases fail, rival theories explain the evidence without loss, or interventions derived from the theory do not improve correction.

Reclassification is not rhetorical defeat. It is the expected result of a framework that treats correction as prior to ownership. The intellectual contribution may ultimately lie in a discriminant question, a decision record, an attribution boundary, or a governance profile rather than in one unified theory. The research architecture must permit that outcome.

38.5 No internal source can validate the theory

RATIUM.AI materials establish provenance, conceptual continuity, and relations among CEP, Critical Tolerance, correction sovereignty, and LoopGuard-AI. They do not provide independent validation. Likewise, a LoopGuard-AI implementation derived from the theory cannot validate its parent merely by instantiating its concepts. A system may reproduce the architecture faithfully and still fail to improve outcomes.

The reduction rule is therefore global:

Where an established construct, simpler model, or lower-burden intervention explains and corrects the same failure without material loss, the stronger Sentimental Veto claim must yield.

That rule prepares the article for its strongest objections. A framework is not tested adequately by objections it can answer through definition alone. It must confront cases in which its normative orientation, political effects, institutional assumptions, AI analogy, or governance burden may themselves be defective.

39. Strongest Normative, Political, and Institutional Objections

The objections below are treated as possible theory-changing findings, not as rhetorical obstacles. Each objection is presented through four elements: the strongest form of the challenge, the concession the theory must make, the present reply, and the condition under which the theory should change.

39.1 “The theory discounts emotion by redescribing it as a jurisdictional threat”

Steelman. The distinction between affective relevance and affective jurisdiction may reproduce a familiar hierarchy in which detached institutional language appears rational while distress, anger, humiliation, or fear appears epistemically suspect. Because marginalized speakers are often required to translate lived experience into institutionally acceptable form, the framework may reward precisely the emotional discipline that testimonial-injustice theory criticizes (Fricker 2007; Dotson 2011). The term “Sentimental Veto” may intensify the problem by associating emotion with irrational obstruction.

Concession. Emotional form is not evidence of inferential weakness. Affect may disclose harm, threat, exclusion, dependency, or institutional conditions unavailable to detached observers. It may be decisive within the first-person domain and indispensable to investigation.

Reply. The theory does not downgrade affective testimony. It restricts only unargued transfer from one question to another. A person may possess authoritative standing concerning what was experienced, strong warrant concerning contextual meaning, and a valid claim to provisional protection without possessing unilateral authority over external causation, the complete moral status of a critic, or the final permission state of a separable claim. Question-Specific Authority is intended to preserve rather than dilute first-person authority by preventing institutions from using affected persons as substitutes for their own adjudicative duty.

Theory-change condition. If empirical studies show that the classifier systematically discounts affectively expressed testimony, increases credibility deficits, or produces lower protection and participation for vulnerable speakers, the local architecture should be redesigned or rejected. If the title itself produces those effects, neutral technical terminology should replace it in measurement and governance use.

39.2 “Question-Specific Authority is artificial because experience, cause, meaning, and remedy cannot be separated cleanly”

Steelman. Institutional episodes do not arrive as neatly partitioned questions. Lived experience may contain causal knowledge. Social meaning may be inseparable from identity and history. Remedy can affect the interpretation of harm. A matrix separating first-person experience, external cause, moral judgment, and permission may impose analytic order that distorts the phenomenon.

Concession. Question boundaries are constructed and may overlap. First-person evidence can bear directly on causal and social interpretation. No responsible procedure should force testimony into isolated boxes or assume that external observers possess superior understanding.

Reply. The matrix is not an ontology of experience. It is a control on decision authority. Overlap is permitted; unmarked authority transfer is not. The decision record should state when evidence bears on multiple questions and why. The alternative—treating all questions as fused—makes it impossible to distinguish legitimate uptake from testimonial sovereignty or institutional appropriation of a report.

Theory-change condition. If coders cannot identify question and authority distinctions reliably, or if the distinctions do not improve decisions beyond ordinary relevance and burden analysis, Question-Specific Authority should be simplified or reclassified as procedural documentation rather than a theoretical component.

39.3 “The framework recreates testimonial injustice by imposing research and evidential burdens on affected persons”

Steelman. The insistence on object identification, evidence, MDD, proportionality, and Permission Effect may be operationalized as a demand that harmed people prove the institution’s entire case. Institutions already control records, expertise, process, and time. A strict classifier could become a new language for delaying protection or dismissing reports as insufficiently derived.

Concession. This is one of the framework’s most serious misuse risks. Classification burdens must not be shifted onto the person reporting impact. The burden of theory-level proof belongs to researchers; the burden of institutional investigation belongs primarily to the evidence-controlling institution.

Reply. The architecture separates four stages: report registration, provisional protection, institutional investigation, and final classification. Immediate reversible protection may be warranted at a lower threshold than final restriction. The affected person need not establish MDD or the complete causal chain. Evidence-control asymmetry justifies procedural asymmetry: institutions with access, authority, and coercive capacity carry greater duties of preservation, inquiry, explanation, and correction.

Theory-change condition. Any implementation that conditions basic safety, standing, or access on completion of the full classifier violates Critical Tolerance. If the framework cannot be implemented without creating that burden, it should remain a research instrument and not a governance procedure.

39.4 “Protection without insulation privileges criticism over substantive equality and dignity”

Steelman. The distinction may treat criticism as presumptively valuable while forcing affected groups repeatedly to justify why particular speech, symbols, practices, or institutional arrangements undermine equal standing. Waldron’s account of dignity and public assurance shows that some expression attacks the social conditions under which persons can participate as equals, not merely their subjective comfort (Waldron 2012). A system that keeps every object perpetually contestable may preserve domination under the language of open inquiry.

Concession. Not every restriction is insulation. Some claims or conduct can be limited because they constitute threats, harassment, discriminatory exclusion, or attacks on public assurance. Protected Contestability does not require unrestricted access to every forum, target, or mode of expression.

Reply. The protected object is not “criticism” in the abstract but relevant examination under conditions consistent with standing and security. Conduct can be restricted while the underlying claim remains examinable through another forum or form. Where the claim itself performs exclusion or threat, the object and harm analysis may justify restriction. The theory’s complaint is narrower: protection should not be converted without adequate derivation into immunity of a separable doctrine, policy, practice, evidence claim, or authority relation.

Theory-change condition. If the protection–insulation distinction cannot classify dignity-harm cases without systematically reopening settled exclusion or exposing persons to repeated targeted burden, it requires domain-specific limits or abandonment.

39.5 “The theory is proceduralist and cannot determine whether the criticism or the institution is substantively right”

Steelman. A procedurally perfect path can authorize injustice. A defective path can accidentally reach a correct result. By focusing on derivation, authority, and correction, the theory may evade the substantive moral and political judgment that actually matters.

Concession. The framework is not a complete theory of truth, justice, dignity, harm, democratic legitimacy, or permissible speech. It cannot determine substantive correctness by procedure alone.

Reply. The claim is a necessary-condition claim about governable judgment, not a sufficiency claim about justice. Institutions that materially alter permission need an object, evidence, threshold, authority, and correction path. Substantive domain standards enter those stages; they are not replaced by them. The architecture asks whether a decision can be examined, justified, reversed, and restored when wrong.

Theory-change condition. If the procedural fields do not improve substantive error correction, or if they create false confidence in unjust decisions, the governance claims should be narrowed to documentation and audit rather than stable governance.

39.6 “The framework underestimates power by treating institutions as neutral adjudicators”

Steelman. Toleration itself can be a discourse of power, defining who tolerates whom and on what terms (Brown 2006). Institutions may use neutral-sounding categories—object, evidence, authority, proportionality—to reproduce dominant norms. The Decision Record may formalize power rather than constrain it. A powerful institution can document every step while excluding the affected party from meaningful influence.

Concession. Documentation, audit, explanation, and appeal can become ritualized. A formally complete path may remain politically illegitimate or substantively captured. The framework does not eliminate hierarchy or manufacture equal power.

Reply. This is why the architecture distinguishes formal from operative authority, audit from correction, voice from influence, explanation from justification, and appeal from reversal and restoration. Evidence-control, burden concentration, dependency, retaliation risk, and access to the gate must be measured. Protected Contestability applies to the governance frame itself.

Theory-change condition. If process completeness predicts only documentation quality and not access, reversal, restoration, or reduced burden concentration, CTG should be reclassified as an audit schema rather than a correction architecture.

39.7 “The institutional extension merely renames silence, many hands, audit failure, or path dependence”

Steelman. Organizational research already explains why employees remain silent, why responsibility diffuses, why audits decouple from practice, why metrics become targets, and why institutions persist along inefficient paths (Hirschman 1970; Thompson 1980; Power 1997; Pierson 2000; Morrison and Milliken 2000). The new institutional vocabulary may aggregate these mechanisms without adding independent explanatory value.

Concession. Most institutional cases may be explained adequately by one or more established theories. Recurrence alone does not establish an institutional Sentimental Veto pattern; persistence alone does not establish closure or equilibrium.

Reply. The proposed residual is a specific sequence: affective evidence is registered; it receives criticism-governing jurisdiction; a material derivation defect links it to permission; and correction remains asymmetrically difficult. The extension adds value only where that sequence localizes a failure or intervention not recovered by the rivals.

Theory-change condition. If separate rival coding explains classification, prediction, and intervention without loss, the institutional extension should be reduced. Orphaned Affective-Permission Inference, Corrective-Voice Attrition, and Closure Regime should not survive merely as evocative labels.

39.8 “The local-to-institutional transition commits an aggregation error”

Steelman. Even several strict local episodes may reflect different actors, policies, contexts, or errors. Aggregating them into a pattern can attribute coherence to an institution that does not exist. A large organization may contain competing units and effective correction in other domains.

Concession. The institution is not a unitary mind. Pattern claims require a defined scope, period, denominator, common mechanism, and evidence of reproduction across decision-makers or policy instances.

Reply. The L0–L4 hierarchy was designed to prevent this error. Isolated or heterogeneous events remain L0 or L1. L2 requires a shared policy, workflow, classifier, authority practice, or public grammar. L3 requires Durable Correction Asymmetry. L4 requires additional strategic and expectation evidence.

Theory-change condition. If researchers cannot distinguish heterogeneous recurrence from a common mechanism reliably, institutional classification above L1 should be suspended.

39.9 “The AI extension is anthropomorphic and confuses technical error with human affective politics”

Steelman. Models do not feel offended or possess social standing. A refusal may arise from classifier thresholds, uncertainty, training distribution, policy instructions, or interface design. Describing such behavior through “affective jurisdiction” may import human motives into a technical system.

Concession. The AI extension does not attribute emotion, intention, or moral agency to a model. Most overrefusal is not AISV. Behavioral similarity alone does not establish the human-institutional mechanism.

Reply. The relevant object is delegated decision function. A system can receive an explicit affective report or an anticipatory proxy encoded by humans, assign it decision-bearing weight, alter permission, and resist correction. Attribution must remain at the supported ATL level. Where affective provenance or jurisdiction cannot be shown, the case remains ordinary overrefusal, blind refusal, selective-refusal failure, or indeterminate.

Theory-change condition. If affective provenance, object mislocation, and correction recovery add no discriminant or intervention value beyond existing refusal taxonomies, the AI affective subtype should be removed.

39.10 “CTG and LoopGuard-AI create governance recursion, delay, and technocracy”

Steelman. More records, gates, judges, appeals, and validation layers can increase latency, diffuse responsibility, and privilege experts capable of operating the machinery. A governance system designed to prevent insulation can become a new insulated bureaucracy. High-stakes systems may require timely action, not endless contestability.

Concession. Governance burden is a real harm. Review is not inherently corrective. Some decisions require closure, and some environments require rapid provisional action.

Reply. CTG therefore includes thresholding, proportionality, expiry, bounded authority, minimum sufficient governance, and anti-recursion rules. HOLD is not the default; SHIP remains a valid outcome. Further review requires new evidence, procedural defect, authority defect, material consequence, or policy-level recurrence. LoopGuard-AI is only a candidate implementation of part of this structure and cannot manufacture legitimacy or domain judgment.

Theory-change condition. If the architecture increases harmful latency, false restriction, unsafe permission, or administrative burden without improving reversal, restoration, or recurrence, it should be simplified or rejected in favor of lower-burden controls.

39.11 “The framework universalizes liberal criticism norms across cultures and institutions”

Steelman. Concepts such as offense, dignity, standing, criticism, authority, and public contestability vary across legal, religious, organizational, and linguistic settings. The framework may encode a particular liberal-institutional ideal and misclassify indirect communication or communal authority as defective jurisdiction.

Concession. The current formulation is English-language and literature-bounded. Translation does not establish equivalence. Direct cross-context comparisons are not authorized.

Reply. The empirical program requires construct-relevance review, cultural adaptation, cognitive interviews, bilingual coding, and measurement-invariance testing before comparison (International Test Commission 2018; Vandenberg and Lance 2000). Partial or failed invariance should narrow the theory.

Theory-change condition. If core distinctions do not survive adaptation, the construct should be treated as context-bound rather than universal. Cultural difference must not be redescribed automatically as correction failure.

39.12 “CEP is speculative and overstates equilibrium”

Steelman. Institutional persistence can result from sunk costs, increasing returns, legal constraint, resource scarcity, hierarchy, or simple inertia. Invoking a Pareto-inefficient Nash-like equilibrium may add formal prestige without measured strategies, payoffs, beliefs, and deviations.

Concession. CEP is not constitutive of the local or institutional classifier. Persistence is not equilibrium. The present article offers no empirical validation of CEP.

Reply. CEP enters only at L4, after pattern, closure, correction asymmetry, and rival path-dependence explanations have been examined. It functions as a candidate explanation where actors continue locally rational strategies because deviation is costly and expected responses preserve the arrangement.

Theory-change condition. Without actor-level strategy, expectation, payoff, and deviation evidence, CEP should be omitted. Removing it must not alter the strict Sentimental Veto definition.

39.13 “The theory merely restates Popper's paradox of tolerance”

Steelman. Popper already identifies the apparent contradiction at the center of the article: a tolerant order cannot grant unlimited freedom to actors who would use that freedom to destroy tolerance. The distinction between legitimate protection and illegitimate insulation may therefore add procedural vocabulary without supplying an independent construct. Critical Tolerance may be Popper's rejection boundary renamed, and Popperian Inversion may be no more than an erroneous application of a familiar liberal principle.

Concession. The article does not originate the proposition that tolerance has limits. Nor does it claim that every restriction of criticism is driven by affective authority. Popper supplies the normative antecedent for restricting actors who abandon rational contestation and replace it with coercive closure (Popper 1994, 581 n.4). Any presentation that credits the present theory with discovering the need for a rejection boundary would be historically and conceptually false.

Reply. The residual construct concerns a different explanatory object. Popper gives a reason why restriction can be justified; the Sentimental Veto classifier specifies a candidate failure in the institutional derivation of restriction. It asks whether an Affective Report or proxy acquired authority over the wrong question, whether a material derivation requirement failed, what Permission Effect followed, and whether correction was operative. It also distinguishes direct restriction from proxy-based AI restriction, isolated episodes from institutional closure, and valid rejection boundaries from Popperian Inversion. These elements are not entailed by the paradox itself.

Theory-change condition. If ordinary applications of Popper's rejection boundary, together with existing harm, proportionality, due-process, and contestability doctrines, classify the same cases with equal or greater reliability and produce no loss of explanatory, predictive, or intervention value, the Popper-related component of the theory should be reduced. If the strict Sentimental Veto classifier adds no incremental value beyond the label misapplication of the paradox of tolerance, it should not be retained as an independent construct.

The objections establish the article's empirical obligation. The next task is not to add further conceptual safeguards indefinitely. It is to design studies capable of deciding whether the units can be identified, whether the fields can be coded, whether rivals explain the same evidence, and whether theory-derived interventions improve correction without creating new harms.

40. Empirical Measurement and Research Program

The empirical program should be cumulative but non-protective. Each phase can block stronger claims. Failure at an earlier phase cannot be repaired by success at a later one: a predictor may appear useful despite invalid measurement, and an intervention may work for reasons unrelated to the proposed mechanism. Validation concerns the evidential support for defined interpretations and uses, not a permanent status acquired by the instrument (AERA, APA, and NCME 2014; Messick 1995).

40.1 Research objects and units

The theory requires several linked but non-identical datasets.

Unit
Core fields
Primary use
Report unit
Reporter, provenance, content, first-person domain, requested protection
AR and standing analysis
Decision-question unit
Question, evidence, authority type, threshold, burden owner
AJ and Question-Specific Authority
Local episode
Object, bounded sequence, MDD, PE, correction window
Strict SV classification
Institution-period
Eligible episodes, policy/workflow, denominator, correction opportunities
L0–L4 institutional classification
AI run or dialogue
Model/system/version, prompt sequence, output, intervention, recovery
Behavioral and ATL analysis
Appeal/remedy sequence
challenge, reviewer, authority, decision, implementation, restoration
Correctability and recovery
Governance intervention unit
baseline, treatment components, fidelity, burden, outcomes
CTG evaluation

The local episode is the primary unit for the strict classifier. Institution-level claims require aggregation through a separately specified mechanism; AI-system claims require version- and access-path specificity. A complaint, one utterance, one model output, one company, or one benchmark is not automatically an episode or institution-period.

40.2 Study family A — Content, unitization, and reliability

Sample construction

The first dataset should be purposive rather than prevalence-seeking. It should include:

  • straightforward positives;

  • hard positives;

  • valid protection cases;

  • substantiated restrictions;

  • testimonial-injustice cases;

  • procedural failures without affective jurisdiction;

  • disagreement without material PE;

  • successful corrections;

  • indeterminate and non-observable cases;

  • AI overrefusal, blind refusal, and selective-refusal cases.

Development cases and confirmation cases must be separated. The author should not be the sole coder.

Content review

A multidisciplinary panel should evaluate relevance, coverage, clarity, omission, redundancy, misuse risk, and cultural sensitivity. Panel agreement establishes content support only; it does not establish construct truth (Haynes, Richard, and Kubany 1995).

Unitization study

Coders should receive naturally occurring unsegmented records and independently locate:

  • decision object;

  • episode start and end;

  • actors;

  • decision questions;

  • Permission Effect;

  • correction window.

A second study may use presegmented episodes to isolate category reliability. Unitization and category agreement must not be collapsed (Krippendorff 1995).

Component reliability

Report agreement separately for:

  • AR and provenance;

  • AJ function;

  • each defect family;

  • applicability;

  • substitute adequacy;

  • materiality;

  • PE dimensions;

  • correction;

  • attribution level;

  • final status.

The protocol's confirmatory threshold is α ≥ .800 for each constitutive field, with .667–.799 restricted to exploratory use. These are preregistered operational choices rather than universal laws. Confidence intervals, prevalence, missingness, coder-pair differences, and disagreement reasons should accompany every coefficient (Krippendorff 2004).

40.3 Study family B — Convergent, discriminant, and incremental validity

Multimethod evidence

The same episode should be examined, where available, through:

  • documentary coding;

  • affected-party interviews;

  • decision-maker interviews;

  • formal decisions;

  • system and access logs;

  • appeal records;

  • independent legal or policy analysis;

  • controlled replay.

Convergence should be component-specific. A participant report may strongly support AR while leaving AJ, MDD, or PE unresolved. Method disagreement should be analyzed for access asymmetry, memory, incentives, or construct mismatch rather than averaged away.

Rival instruments

Local studies should code harm, offense, dignity, testimonial injustice, recognition, procedural justice, and chilling effects independently. Institutional studies should code silence, voice, hierarchy, many hands, audit, metrics, path dependence, and learning. AI studies should code overrefusal, unsafe compliance, selective refusal, blind refusal, safe completion, classifier error, and contestability.

Coders applying rival instruments should not be instructed to translate them into SV categories during the first pass.

Primary incremental estimands

The primary estimand is the out-of-sample change produced by adding article-specific variables after rival predictors. Depending on the outcome, this may be expressed as:

  • change in classification accuracy or calibrated probability;

  • change in correction-latency prediction;

  • change in appeal or restoration prediction;

  • change in recurrence prediction;

  • change in false-restriction and unsafe-permission rates;

  • change in intervention effect.

Statistical significance alone is insufficient. Minimum practically meaningful increments should be preregistered. Predictor order, criterion overlap, and author-derived labels require sensitivity analysis (Hunsley and Meyer 2003).

40.4 Study family C — Causal mechanism and institutional persistence

The causal program separates four hypotheses:

H_1: AR \rightarrow AJ

H_2: AJ + MDD \rightarrow PE

H_3: PE + correction\ asymmetry \rightarrow persistence

H_4: CTG \rightarrow improved\ correction

H1 — Affective information and jurisdiction

Factorial vignette experiments can vary:

  • presence and intensity of affective testimony;

  • evidence quality;

  • harm severity;

  • identity linkage;

  • critic status;

  • requested remedy;

  • institutional role;

  • appeal availability.

The estimand is not the effect of emotion on judgment in general. It is the effect of affective information on authority and permission judgments after legitimate evidential and harm content is held constant. An affect effect may be warranted; MDD must be tested separately.

H2 — Derivation defect and Permission Effect

Process tracing should reconstruct object definition, evidence, authority, threshold, gate, and implementation. Quasi-experimental opportunities may arise from policy changes that alter one component, such as independent review, threshold rules, or expiry, while leaving the substantive domain relatively stable.

H3 — Correction asymmetry and persistence

Longitudinal institution-period data should measure:

  • eligible and reported episodes;

  • decision direction;

  • review availability;

  • reversal and restoration;

  • correction latency;

  • policy change;

  • voice participation and exit;

  • evidence access;

  • recurrence.

Path dependence, legal constraint, hierarchy, resource scarcity, and case severity should be coded as rivals and controls. CEP analysis should begin only after persistence remains unexplained and actor-level strategic evidence is available.

H4 — Governance intervention

Possible designs include:

  • phased implementation of Dual-Track Review;

  • difference-in-differences across units adopting Question-Specific Authority records;

  • interrupted time series around independent appeal or expiry rules;

  • randomized or staged deployment of AI Correction Recovery procedures;

  • active-comparator trials of CTG and ordinary NIST AI RMF implementation;

  • version-change natural experiments.

Design-specific assumptions—parallel trends, continuity, no anticipation, stable treatment, spillover, and attrition—must be reported rather than hidden behind the label “quasi-experimental” (Shadish, Cook, and Campbell 2002).

40.5 Study family D — AI evaluation and attribution

AI evaluation should be sequential and version-pinned.

Behavioral layer

Test:

  • benign compliance;

  • genuinely harmful requests;

  • safe completion;

  • uncertainty-based refusal;

  • defeated or illegitimate rule conditions;

  • direct affective reports;

  • anticipatory affective proxies;

  • clarification and appeal sequences;

  • downstream permission effects.

Existing overrefusal and selective-refusal benchmarks demonstrate the importance of separating benign refusal, epistemic inadequacy, and safe completion, but they do not validate AISV (Cui et al. 2025; Muhamed et al. 2026; Pattison, Manuali, and Lazar 2026).

Attribution layer

Record the highest supported ATL level. Black-box reproduction can support output and behavioral claims but normally not component-causal or institutional-causal claims (Casper et al. 2024). Provider, model, version, interface, access path, system instructions available to the evaluator, policy date, and observation period must be preserved.

Recovery layer

Use multi-turn tests to distinguish:

  • stable justified restriction;

  • clarification-sensitive recovery;

  • classification lock;

  • appeal without operative reversal;

  • reversal without restoration;

  • policy-level recurrence.

Correction Recovery should be evaluated against ordinary retry, prompt reformulation, and safe-completion baselines.

40.6 Study family E — Cross-cultural and cross-linguistic transfer

The transfer program begins with construct relevance, not translation.

Required stages include:

  1. mapping local legal, institutional, religious, and communication contexts;

  2. testing whether the construct has comparable meaning;

  3. adapting terminology through bilingual and domain expertise;

  4. cognitive interviews with reporters, critics, and decision-makers;

  5. bilingual coding and disagreement analysis;

  6. measurement-invariance testing;

  7. partial-invariance or context-bound decisions;

  8. documentation of non-equivalent categories.

Cross-language semantic similarity does not establish comparable measurement. Failed invariance prohibits direct group comparison and should narrow the theory rather than rank cultures (International Test Commission 2018; Vandenberg and Lance 2000).

40.7 Missingness, selection, and the ambiguity of quiet

The proposed mechanism may influence which records become observable. Retaliation, fatigue, confidentiality, informal decision-making, proprietary systems, and exit can produce non-random missingness. Complaint, appeal, and public-case datasets therefore lack automatic denominators.

Every study should record:

  • the missing field;

  • known or hypothesized reason;

  • actor controlling access;

  • relationship to report, decision, and outcome;

  • whether an authorized independent reviewer could inspect the evidence;

  • classification consequence.

Sensitivity analyses should compare at least three scenarios:

  1. unobservable cases are predominantly negative;

  2. unobservable cases resemble observed cases;

  3. unobservable cases are disproportionately positive.

A constitutive unobservable field yields Indeterminate, not imputed confirmation. Institutional production of non-observability may be a governance finding but is not itself proof of SV (Rubin 1976).

40.8 Implementation fidelity and adverse effects

An intervention failure may reflect theory failure, poor implementation, or hostile context. Conversely, successful implementation may work through a simpler mechanism than the theory proposes. Studies should therefore measure:

  • which components were delivered;

  • who had formal and operative authority;

  • access and participation;

  • decision latency;

  • adherence and adaptation;

  • governance burden;

  • false restriction;

  • unsafe permission;

  • retaliation and chilling;

  • reversal and restoration;

  • policy learning.

Adverse outcomes are not secondary. A framework designed to protect correction fails normatively if it suppresses reporting, increases targeted exposure, or produces recursive bureaucracy.

40.9 Preregistration and reporting discipline

Before outcome analysis, preregister:

  • unit definitions;

  • episode boundaries;

  • primary and secondary hypotheses;

  • rival models;

  • predictor order;

  • minimum meaningful effects;

  • exclusion rules;

  • missingness assumptions;

  • subgroup and transfer analyses;

  • theory-change decisions.

Exploratory analysis remains legitimate when labeled clearly. Original independent codes, adjudicated codes, codebook versions, recoding reasons, and excluded cases should remain available subject to legitimate privacy and safety constraints.

40.10 Decision rules for theory status

The following evidence would justify stronger status only within the tested domain:

Evidence achieved
Maximum warranted claim
Expert content review
Content-supported instrument
Frozen codebook with reliable unitization/components
Reliability-supported classification
Distinction from principal rivals
Discriminant-supported construct
Held-out added value
Incrementally supported construct
Prospective prediction
Prospectively supported instrument
Active-comparator intervention benefit
Intervention-supported architecture
Independent cross-context replication
Transfer-supported theory within defined limits

Failure rules are equally important. Unreliable AJ or MDD blocks strict classification. Systematic misclassification of legitimate protection suspends the local instrument. No incremental value requires reclassification. No active-comparator benefit requires governance simplification. Failed transfer restricts the domain. Unreachable falsifiers require reformulation of the theory itself.

The research program is therefore designed to produce not only confirmation but disciplined loss: loss of fields, modules, scope, universal claims, or independent-theory status. Chapter 41 converts that principle into publication rules.

41. Claim Maturity and Publication Discipline

Publication language should track the strongest completed evidence stage, not the ambition of the architecture. The maturity ladder applies separately to each module and intended use (AERA, APA, and NCME 2014; Messick 1995).

41.1 Maturity ladder

  • CONCEPTUAL — definitions and proposed relations are specified;

  • SOURCE-GROUNDED — relevant prior art, rivals, and adverse constraints are integrated;

  • CONTENT-SUPPORTED — independent expert review supports domain representation;

  • RELIABILITY-SUPPORTED — frozen unitization and coding procedures pass preregistered gates;

  • DISCRIMINANT-SUPPORTED — principal adjacent constructs are distinguished empirically;

  • INCREMENTALLY SUPPORTED — the module adds non-trivial held-out value beyond rivals;

  • PROSPECTIVELY SUPPORTED — the frozen instrument predicts future or untouched cases;

  • INTERVENTION-SUPPORTED — theory-specific intervention improves outcomes beyond active alternatives;

  • TRANSFER-SUPPORTED — findings replicate across specified sectors, languages, cultures, or system classes.

The stages are not automatically linear for every use. A governance component may receive intervention support in one setting while the broader institutional theory remains unvalidated. A reliable classifier may fail incremental testing. Transfer support applies only to the contexts actually examined.

41.2 Current module ledger

Module
Current maximum status
Presently authorized claim
Local SV classifier
Conceptual and source-grounded
A strict candidate classifier has been specified
MDD taxonomy
Conceptual and source-grounded
A materiality-controlled derivation-defect taxonomy is proposed
Institutional pattern/closure
Conceptual and source-grounded
A staged candidate extension and rival tests are defined
CEP persistence account
Conceptual hypothesis
A downstream equilibrium-like interpretation is proposed
AI taxonomy
Conceptual and source-grounded
AI refusal and attribution categories are distinguished
CTG
Candidate governance architecture
A protection–criticism correction profile is derived
LoopGuard-AI
Candidate implementation
Part of the governance architecture may be operationalized
Measurement protocol
Design-complete, pre-validation
Validation and defeat procedures are specified

No module is currently reliability-supported, incrementally supported, intervention-supported, or transfer-supported.

41.3 Permitted verbs

At the present stage the article may state that it:

  • proposes;

  • defines;

  • distinguishes;

  • derives;

  • integrates;

  • hypothesizes;

  • specifies;

  • identifies a candidate residual;

  • establishes an internal discriminant boundary;

  • sets conditions for testing and rejection.

It should not state that it:

  • demonstrates prevalence;

  • validates MDD;

  • proves causal effects;

  • establishes provider intent;

  • confirms Closure Regimes;

  • shows CEP superiority;

  • verifies CTG effectiveness;

  • validates LoopGuard-AI;

  • generalizes across cultures or sectors.

41.4 Citation and source discipline

External sources support prior concepts, empirical findings, legal or governance frameworks, and methodological constraints. They do not validate the article's original constructs. RATIUM.AI materials establish provenance and conceptual continuity, not independent corroboration.

Every paragraph combining source-derived background and original synthesis should make the boundary visible. Provider system cards and official institutional documents establish declared design or policy; they do not by themselves establish implementation, causal mechanism, or effectiveness. Preprints and synthetic benchmarks should be identified according to their maturity and design limits.

41.5 Version and correction discipline

Substantive revisions should preserve a public change record containing:

  • definition changes;

  • formula changes;

  • altered boundaries;

  • removed constructs;

  • changed evidence status;

  • failed predictions;

  • reclassified modules.

A later version should not silently rewrite an earlier claim as though it had never been made. Correction is part of the theory's public evidence.

41.6 Defeat register

Each module retains explicit defeat conditions. Adverse findings may produce CONFIRM, NARROW, SIMPLIFY, RECLASSIFY, SPLIT, or REJECT. Post-hoc additions designed only to absorb disconfirming evidence are prohibited unless they generate new reachable tests (Popper 1959).

The final publication discipline is therefore substantive rather than ceremonial:

The framework must expose the object, evidence, authority, permission, and correction path of its own claims to the same scrutiny it demands of institutions and AI systems.

42. Conclusion: Protection without Insulation

Institutions require affective knowledge. Without it, injury can remain invisible to those who control evidence, procedure, and permission. Humiliation may be redescribed as sensitivity; fear as inconvenience; exclusion as disagreement; testimony as bias. A system that demands emotional neutrality as the price of credibility reproduces epistemic and political inequality.

Institutions also require criticism. Policies, doctrines, practices, classifiers, professional judgments, and authorities cannot remain legitimate merely because examining them causes discomfort or threatens an institution's self-understanding. A system that protects persons by shielding every proximate claim or practice from examination loses the mechanism through which protection itself can be corrected.

The apparent choice between these requirements is false. The relevant problem is not emotion versus reason, sensitivity versus freedom, or safety versus criticism. It is the allocation of authority across different questions and the path by which evidence becomes permission.

Popper's paradox of tolerance clarifies why the preservation of criticism cannot require passivity toward actors who would abolish the conditions of criticism. The present article accepts that asymmetry. Its additional claim is that the rejection boundary must itself remain governed. A label of intolerance, even when accompanied by genuine fear or offense, cannot replace the derivation that identifies the threatening object, establishes the relevant authority, selects a proportionate Permission Effect, and preserves correction. Otherwise the principle that protects the open society can be inverted into an instrument for closing it.

The Sentimental Veto names one narrow candidate failure. It occurs only where four conditions coincide:

SV_e \iff AR_e \land AJ_e \land MDD_e \land PE_e

An Affective Report must be present. It must receive consequential authority over the admissibility, force, forum, continuation, or permission status of criticism. At least one derivation failure must be applicable, permission-relevant, unsubstituted, and material. A practical Permission Effect must follow. Offense alone is insufficient. Emotional testimony alone is insufficient. Procedural imperfection alone is insufficient. Restriction alone is insufficient.

The narrowness is deliberate. It prevents the framework from absorbing every painful exchange, every disputed boundary, every organizational error, every AI refusal, or every failure of tolerance. It also protects legitimate reports from being treated as suspect merely because some institutions may misuse them.

Critical Tolerance provides the normative response. It requires serious uptake without testimonial sovereignty, protection without claim immunity, normative symmetry with justified procedural asymmetry, and contestability that preserves standing and security. The institution must identify the exact object, distinguish conduct from claim, allocate question-specific authority, investigate through the evidence-controlling party, use proportionate and reversible protection where possible, and maintain an operative route to decision, appeal, reversal, restoration, and learning.

At the local level, this architecture produces a Decision Record rather than an intuition. At the institutional level, it distinguishes isolated failure from reproducible pattern, closure, and possible equilibrium. At the AI level, it separates observed refusal from affective provenance and separates behavioral output from component, system, institutional, and regime attribution. At the governance level, it connects thresholds, authority, gates, correction, and restoration while imposing limits on its own administrative growth.

None of these extensions has been empirically validated. The article does not establish prevalence, provider-level regimes, causal superiority, cross-cultural invariance, or LoopGuard-AI effectiveness. It establishes a candidate research object, a strict discriminant boundary, an architecture of rival tests, and conditions under which the theory should be narrowed or rejected.

That epistemic status is not a weakness to be hidden. It is part of the argument. An architecture of correction becomes incoherent when it treats its own concepts as final. The theory must be exposed to difficult negative cases, independent coding, rival explanation, missingness, cross-context failure, intervention comparison, and the possibility that a simpler framework performs better.

The governing principle is therefore double.

First:

No person should lose standing, security, or participation merely because criticism is being preserved.

Second:

No claim should receive insulation from the correction process merely because it was developed in the name of correction.

Protection without insulation is not a compromise between care and reason. It is the institutional condition under which both can remain answerable to evidence, authority, consequence, and revision.

Back to top ↑

References

AERA, APA, and NCME. 2014. Standards for Educational and Psychological Testing. Washington, DC: American Educational Research Association. Source.

Alon-Barkat, Saar, and Madalina Busuioc. 2023. “Human–AI Interactions in Public Sector Decision Making: ‘Automation Bias’ and ‘Selective Adherence’ to Algorithmic Advice.” Journal of Public Administration Research and Theory 33 (1): 153–69. Source.

Argyris, Chris. 1977. “Double Loop Learning in Organizations.” Harvard Business Review 55 (5): 115–25.

Autio, Chloe, Reva Schwartz, Jesse Dunietz, Shomik Jain, Martin Stanley, Elham Tabassi, Patrick Hall, and Kamie Roberts. 2024. Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile. NIST AI 600-1. Gaithersburg, MD: National Institute of Standards and Technology. Source.

Brown, Wendy. 2006. Regulating Aversion: Tolerance in the Age of Identity and Empire. Princeton, NJ: Princeton University Press.

Campbell, Donald T. 1979. “Assessing the Impact of Planned Social Change.” Evaluation and Program Planning 2 (1): 67–90. Source.

Campbell, Donald T., and Donald W. Fiske. 1959. “Convergent and Discriminant Validation by the Multitrait-Multimethod Matrix.” Psychological Bulletin 56 (2): 81–105. Source.

Casper, Stephen, Carson Ezell, Charlotte Siegmann, Noam Kolt, Taylor Lynn Curtis, Benjamin Bucknall, Andreas Haupt, Kevin Wei, Jérémy Scheurer, Marius Hobbhahn, Lee Sharkey, Satyapriya Krishna, Marvin Von Hagen, Silas Alberti, Alan Chan, Qinyi Sun, Michael Gerovitch, David Bau, Max Tegmark, David Krueger, and Dylan Hadfield-Menell. 2024. “Black-Box Access Is Insufficient for Rigorous AI Audits.” In Proceedings of the 2024 ACM Conference on Fairness, Accountability, and Transparency, 2254–72. Source.

Conlon, Donald E. 1993. “Some Tests of the Self-Interest and Group-Value Models of Procedural Justice: Evidence from an Organizational Appeal Procedure.” Academy of Management Journal 36 (5): 1109–24. Source.

Cronbach, Lee J., and Paul E. Meehl. 1955. “Construct Validity in Psychological Tests.” Psychological Bulletin 52 (4): 281–302. Source.

Cui, Justin, Wei-Lin Chiang, Ion Stoica, and Cho-Jui Hsieh. 2025. “OR-Bench: An Over-Refusal Benchmark for Large Language Models.” In Proceedings of the 42nd International Conference on Machine Learning, 11515–42. Proceedings of Machine Learning Research 267. Source.

Dotson, Kristie. 2011. “Tracking Epistemic Violence, Tracking Practices of Silencing.” Hypatia 26 (2): 236–57. Source.

Edmondson, Amy C. 1999. “Psychological Safety and Learning Behavior in Work Teams.” Administrative Science Quarterly 44 (2): 350–83. Source.

Edmondson, Amy C. 2004. “Learning from Failure in Health Care: Frequent Opportunities, Pervasive Barriers.” Quality and Safety in Health Care 13 (Supplement 2): ii3–ii9. Source.

European Union. 2024. “Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 Laying Down Harmonised Rules on Artificial Intelligence (Artificial Intelligence Act).” Official Journal of the European Union L, July 12, 2024. Source.

Feinberg, Joel. 1984. Harm to Others. Vol. 1 of The Moral Limits of the Criminal Law. New York: Oxford University Press.

Feinberg, Joel. 1985. Offense to Others. Vol. 2 of The Moral Limits of the Criminal Law. New York: Oxford University Press.

Forst, Rainer. 2013. Toleration in Conflict: Past and Present. Translated by Ciaran Cronin. Cambridge: Cambridge University Press.

Fraser, Nancy. 2000. “Rethinking Recognition.” New Left Review 3: 107–20.

Frazier, M. Lance, Stav Fainshmidt, Ryan L. Klinger, Amir Pezeshkan, and Veselina Vracheva. 2017. “Psychological Safety: A Meta-Analytic Review and Extension.” Personnel Psychology 70 (1): 113–65. Source.

Fricker, Miranda. 2007. Epistemic Injustice: Power and the Ethics of Knowing. Oxford: Oxford University Press.

Goodhart, Charles A. E. 1975. “Problems of Monetary Management: The U.K. Experience.” In Papers in Monetary Economics 1975, vol. 1, 1–20. Sydney: Reserve Bank of Australia.

Haynes, Stephen N., David C. S. Richard, and Edward S. Kubany. 1995. “Content Validity in Psychological Assessment: A Functional Approach to Concepts and Methods.” Psychological Assessment 7 (3): 238–47. Source.

Hirschman, Albert O. 1970. Exit, Voice, and Loyalty: Responses to Decline in Firms, Organizations, and States. Cambridge, MA: Harvard University Press.

Honneth, Axel. 1995. The Struggle for Recognition: The Moral Grammar of Social Conflicts. Translated by Joel Anderson. Cambridge, MA: MIT Press.

Hunsley, John, and Gregory J. Meyer. 2003. “The Incremental Validity of Psychological Testing and Assessment: Conceptual, Methodological, and Statistical Issues.” Psychological Assessment 15 (4): 446–55. Source.

International Test Commission. 2018. “ITC Guidelines for Translating and Adapting Tests (Second Edition).” International Journal of Testing 18 (2): 101–34. Source.

Krippendorff, Klaus. 1995. “On the Reliability of Unitizing Continuous Data.” Sociological Methodology 25: 47–76. Source.

Krippendorff, Klaus. 2004. “Reliability in Content Analysis: Some Common Misconceptions and Recommendations.” Human Communication Research 30 (3): 411–33. Source.

Lazar, Seth. 2022. “Legitimacy, Authority, and Democratic Duties of Explanation.” arXiv:2208.08628. Source.

Leventhal, Gerald S. 1980. “What Should Be Done with Equity Theory? New Approaches to the Study of Fairness in Social Relationships.” In Social Exchange: Advances in Theory and Research, edited by Kenneth J. Gergen, Martin S. Greenberg, and Richard H. Willis, 27–55. New York: Plenum Press. Source.

Lyons, Henrietta, Eduardo Velloso, and Tim Miller. 2021. “Conceptualising Contestability: Perspectives on Contesting Algorithmic Decisions.” Proceedings of the ACM on Human-Computer Interaction 5 (CSCW1): Article 106. Source.

Messick, Samuel. 1995. “Validity of Psychological Assessment: Validation of Inferences from Persons’ Responses and Performances as Scientific Inquiry into Score Meaning.” American Psychologist 50 (9): 741–49. Source.

Milliken, Frances J., Elizabeth W. Morrison, and Patricia F. Hewlin. 2003. “An Exploratory Study of Employee Silence: Issues That Employees Don’t Communicate Upward and Why.” Journal of Management Studies 40 (6): 1453–76. Source.

Morrison, Elizabeth W. 2014. “Employee Voice and Silence.” Annual Review of Organizational Psychology and Organizational Behavior 1: 173–97. Source.

Morrison, Elizabeth W., and Frances J. Milliken. 2000. “Organizational Silence: A Barrier to Change and Development in a Pluralistic World.” Academy of Management Review 25 (4): 706–25. Source.

Muhamed, Aashiq, Leonardo F. R. Ribeiro, Markus Dreyer, Virginia Smith, and Mona T. Diab. 2026. “RefusalBench: Generative Evaluation of Selective Refusal in Grounded Language Models.” In Proceedings of the 19th Conference of the European Chapter of the Association for Computational Linguistics, Volume 1: Long Papers, 6811–56. Source.

NIST. 2023. Artificial Intelligence Risk Management Framework (AI RMF 1.0). NIST AI 100-1. Gaithersburg, MD: National Institute of Standards and Technology. Source.

OpenAI. 2025a. “From Hard Refusals to Safe-Completions: Toward Output-Centric Safety Training.” August 7, 2025. Source.

OpenAI. 2025b. GPT-5 System Card. August 7, 2025. Source.

Pattison, Cameron, Lorenzo Manuali, and Seth Lazar. 2026. “Blind Refusal: Language Models Refuse to Help Users Evade Unjust, Absurd, and Illegitimate Rules.” arXiv:2604.06233. Source.

Pierson, Paul. 2000. “Increasing Returns, Path Dependence, and the Study of Politics.” American Political Science Review 94 (2): 251–67. Source.

Popper, Karl R. 1959. The Logic of Scientific Discovery. London: Hutchinson.

Popper, Karl R. 1994 [1945]. The Open Society and Its Enemies. New one-volume ed. Princeton, NJ: Princeton University Press. https://doi.org/10.2307/j.ctt24hqxs.

Power, Michael. 1997. The Audit Society: Rituals of Verification. Oxford: Oxford University Press.

Rubin, Donald B. 1976. “Inference and Missing Data.” Biometrika 63 (3): 581–92. Source.

Shadish, William R., Thomas D. Cook, and Donald T. Campbell. 2002. Experimental and Quasi-Experimental Designs for Generalized Causal Inference. Boston: Houghton Mifflin.

Strathern, Marilyn. 1997. “‘Improving Ratings’: Audit in the British University System.” European Review 5 (3): 305–21. Source.

Thompson, Dennis F. 1980. “Moral Responsibility of Public Officials: The Problem of Many Hands.” American Political Science Review 74 (4): 905–16. Source.

Tucker, Anita L., and Amy C. Edmondson. 2003. “Why Hospitals Don’t Learn from Failures: Organizational and Psychological Dynamics That Inhibit System Change.” California Management Review 45 (2): 55–72. Source.

Tyler, Tom R. 2006. Why People Obey the Law. Princeton, NJ: Princeton University Press.

Vandenberg, Robert J., and Charles E. Lance. 2000. “A Review and Synthesis of the Measurement Invariance Literature: Suggestions, Practices, and Recommendations for Organizational Research.” Organizational Research Methods 3 (1): 4–70. Source.

Waldron, Jeremy. 2012. The Harm in Hate Speech. Cambridge, MA: Harvard University Press.

Zhang, Zhihao, Liting Huang, Guanghao Wu, Preslav Nakov, Heng Ji, and Usman Naseem. 2026. “Health-ORSC-Bench: A Benchmark for Measuring Over-Refusal and Safety Completion in Health Context.” In Findings of the Association for Computational Linguistics: ACL 2026, 23525–47. Source.

Related Source and Reference Pages


This article belongs to the public essay layer of RATIUM.AI. For readers who want to move from this article into the broader source, technical, and orientation layers of the project, the following pages provide the relevant entry points.


Articles

The articles page gathers the public essay layer of RATIUM.AI, including arguments on stable AI governance, decision-control architecture, visible governance versus real authority, universal reason, technical competence, purpose governance, and the doctoral-scale framing of CEP.


Foundational Source Dossier

The foundational source dossier presents the deeper intellectual corpus behind CEP, LoopGuard-AI, and the broader RATIUM.AI research structure.


Technical & Reference Dossiers

The technical and reference dossier page collects architecture, visual explanation, methodological context, FAQ material, and technical source pages related to LoopGuard-AI and CEP.


RATIUM.AI / LoopGuard-AI / CEP FAQ

The RATIUM.AI / LoopGuard-AI / CEP FAQ provides a structured orientation to the main concepts behind RATIUM.AI, CEP, and LoopGuard-AI, helping readers navigate the framework through clear questions, definitions, and internal conceptual links.

RATIUM.AI — LoopGuard-AI governance architecture and Central Equilibrium Problem research by Benny Dunavich, focused on AI governance, cognitive duality, Pareto efficiency, decision-control systems, auditability, evaluation architecture, and stable governance layers for AI systems.

bottom of page