Governance / Doctrine

Governance Doctrine

Architecture, not preference.

FERZ Governance Doctrine is the set of canonical architectural positions that distinguish authority from authorization and runtime authorization from monitoring, observability, and non-verdict-based interruption. Each position is a structural claim, not a preference. Together they specify what AI governance is and what it is not: authorization is evaluated before execution, produces an independently verifiable verdict, and is categorically separate from logging, intervention, and post-hoc review.

The Concepts section defines the vocabulary FERZ uses for runtime authorization. This section asserts the architectural positions FERZ takes about that vocabulary. Concepts answer “what is this?” Doctrine answers “what follows from how this is built?”

This is not an observability framework, an identity and access management overlay, or a policy engine. It is a category of its own: runtime authorization architecture for AI actions, producing pre-execution verdicts that can be independently verified. The doctrine pages exist to distinguish that category from adjacent ones without forcing readers to reconstruct the argument each time.

The doctrine is established across the FERZ corpus, with foundational arguments in On the Impossibility of Observability-Based Authorization (Meyman, 2026) and supporting analyses in the related papers cited in References below. The wording on each doctrine page is canonical. It is not paraphrased across FERZ materials and should not be paraphrased when citing.

The four positions

The combined canonical form

FERZ Governance Doctrine
Governance that can be bypassed is not governance.Observability and monitoring are not authorization.A halt is not a verdict.
Canonical wording. FERZ corpus.

This is the FERZ Governance Doctrine in its compressed form. It appears verbatim in the corpus and in FERZ external materials. The four doctrine pages above expand each clause into its full argument, counter-positions, and architectural implications.

Why these positions matter

The AI governance market currently uses one word for several categorically different things. “Governance” is attached to content filtering, logging, human review queues, model fine-tuning, and policy documentation, among other practices. Each of these has a place in a complete AI stack. None of them, alone or in combination, constitutes runtime authorization.

The doctrine pages exist so that buyers, regulators, and engineers can distinguish authorization architecture from adjacent categories without having to reconstruct the argument each time. They are written for citation. The canonical wording is fixed; the surrounding argument can be excerpted; the structural claim can be quoted verbatim in regulatory submissions, academic work, and procurement documentation.

Frequently asked questions

What is the difference between FERZ Concepts and FERZ Doctrine?

Concepts define the vocabulary used in runtime authorization architecture, such as ex-ante authorization, Proof-Carrying Decisions, and ABSTAIN. Doctrine asserts the structural positions FERZ takes about that vocabulary, such as observability is not authorization. Concepts answer "what is this?"; doctrine answers "what follows from how this is built?"

Are these doctrines opinions or structural claims?

Structural claims. The enforcement positions are grounded in the FERZ corpus's impossibility result showing that observability-based architectures cannot produce ex-ante authorization artifacts. The definitional position is grounded in the paper Authority versus Authorization: A Definitional Framework for AI Governance, which distinguishes authority, delegation, policy, authorization, and enforcement as separate architectural concepts.

How is this different from audit logs and governance dashboards?

Audit logs are narratives of what happened. Authorization proof is replayable evidence that an action was authorized before it occurred. A system that produces only logs has not performed authorization, regardless of how complete those logs are. The distinction is developed in the FERZ Governance Taxonomy.

Can FERZ doctrine wording be cited verbatim?

Yes. The doctrine is published in canonical form precisely so that buyers, regulators, and engineers can cite it without paraphrase. The compressed three-clause form, the individual position statements, and the underlying corpus papers are all designed for direct citation.

References

Meyman, E. (2026). On the Impossibility of Observability-Based Authorization. Zenodo. https://doi.org/10.5281/zenodo.19647542
Meyman, E. (2026). Observability Is Not Enforcement. Zenodo. https://doi.org/10.5281/zenodo.18663864
Meyman, E. (2026). From Monitoring to Authorization. Zenodo. https://doi.org/10.5281/zenodo.18743974
Meyman, E. (2026). The Override Asymmetry: Why ABSTAIN-Plus-Human-Override Is Not Guardrails-Plus-Human-in-the-Loop. Zenodo. https://doi.org/10.5281/zenodo.19772248
Meyman, E. (2026). A Taxonomy of AI Governance Approaches: Distinguishing Visibility, Alignment, and Authorization. Zenodo. https://doi.org/10.5281/zenodo.18275969
Meyman, E. (2026). Authority versus Authorization: A Definitional Framework for AI Governance. Zenodo. https://doi.org/10.5281/zenodo.21341907
For the underlying vocabulary, see Governance Concepts. For architectural contrasts with adjacent categories such as IAM, policy engines, observability platforms, and runtime application security, see Comparisons. For the corpus papers from which the doctrine is derived, see FERZ Research.
Cite this page

FERZ, Inc. (2026). Governance Doctrine. https://ferz.ai/governance/doctrine

BibTeX
@misc{ferz2026doctrine,
  author = {{FERZ, Inc.}},
  title  = {Governance Doctrine},
  year   = {2026},
  url    = {https://ferz.ai/governance/doctrine},
  note   = {FERZ Knowledge Base}
}