The Wealth Delta Tax: Constitutional Governance Intellectual Appendix
Wealth Delta Tax, constitutional governance, institutional failure, institutional capture, governance failure modes, anti-capture design, constitutional design, incentive compatibility, institutional decay, mechanism design, fiscal governance, taxpayer-state relations, governance robustness
Revision History
| Revision | Date | Details |
|---|---|---|
| 0.01 | 03 July 2026 | First Draft |
| 1.00 | 15 August 2026 | Published to website |
A. Failure-Mode Taxonomy
(GOV §2.1) derives its mechanism-shaped test from three named failure modes observed in real governance systems. This appendix develops each with real-world instances, so that the test’s underlying logic is auditable rather than asserted. The three modes are oracle failure, self-referential power, and resource-defines-truth degeneration.
A.1 Oracle Failure
A mechanism is oracle-dependent when its operation requires an external report of “what actually happened” that the mechanism itself cannot verify independently. Whoever controls that report controls the system without touching its formal structures directly.
The clearest live instance is the prediction market’s oracle problem. A prediction market works when an objective external event settles the contract: a price at close, a score at the final whistle, an election called. The market is well-designed; the oracle problem sits entirely outside it. Where no clean external settlement event exists — where “what actually happened” requires a determination by a party with an interest in the outcome — the well-designed market becomes the vehicle for whoever wins the oracle dispute. The mechanism is sound; the oracle is the gap.
Oracle failure has a subtle variant: the problem produced by after-the-fact narrative control. Even where an event is objective, the interpretation of what it means can drift from the event itself. Anti-evasion provisions often fall here: a definition narrow enough to catch the specific act it was written to target creates a routing map showing actors how to commit the same substantive act while falling outside the definition. The mechanism’s record shows compliance; the oracle of what actually happened substantively is never resolved in the mechanism’s favour.
A.2 Self-Referential Power
A mechanism suffers from self-referential power when the actor being scored holds enough influence over the outcome they are scored against that their score becomes partly a function of their own choices. The act of evaluation and the act being evaluated collapse, at least partially, into the same hands.
The clearest instances arise when forecasting-tournament logic is applied naively to governance. Forecasting-tournament calibration (of the kind associated with Tetlock’s work on superforecasting and the Brier scoring rule; see Tetlock & Gardner, 2015) is the closest validated real-world precedent for an automatic, proportional, no-judgment cost of the kind GOV’s mechanism-shaped test demands. It works under one critical structural condition: the forecaster being scored has no power over the outcome being forecast. A geopolitical analyst predicting an election does not decide the election. A weather forecaster does not make weather. The score is a clean external signal.
A governance actor does not share this property. A policy official whose tenure depends on forecasting targets defined partly by their own policy choices occupies both sides of the transaction simultaneously. Scoring it like a tournament reintroduces self-referential power precisely through the mechanism that appeared to avoid it — importing calibration scoring into governance design converts an externally-grounded system into an internally-grounded one. The only honest response is to identify the structural condition that makes forecasting tournaments work and ask whether the governance setting preserves it. In most cases it does not.
The self-referential power failure mode appears in a range of familiar institutional forms: the rating agency whose revenues depend on the goodwill of the entities it rates; the regulatory body whose senior staff are drawn from and return to the industry it regulates; the audit committee that appoints the partner who audits it. In each case the evaluating party and the evaluated party are insufficiently separated, and the score is correspondingly unreliable. These are not aberrations; they are the default state of long-lived institutions that develop ongoing relationships with the actors they are meant to assess.
A.3 Resource-Defines-Truth Degeneration
A mechanism degenerates into resource-defines-truth when removing all human discretion from an evaluation does not eliminate capture but instead redefines it as acquiring enough of whatever the mechanism counts. The mechanism’s objectivity is preserved; its meaning is hollowed out by the underlying resources that shape its inputs.
On-chain and DAO governance is the clearest live instance. Token-weighted voting removes human discretion entirely: the vote count is mechanically correct, the rules for counting are public, and there is nothing to bribe or manipulate within the counting process itself. But this precision merely relocates the problem. Token concentration is legitimate control by the mechanism’s own design. A party acquiring a majority of tokens has not captured the mechanism in any informal sense; they have simply operated within it. There is nothing left in the system to call capture once sufficient concentration has occurred, because the mechanism has identified resource-holding with legitimate authority as a matter of design rather than as a corruption of it.
The same degeneration pattern appears in any system that uses a cardinal, acquirable metric as its fundamental legitimacy source: one-share-one-vote corporate governance, vote-buying in nominally democratic contexts, and reputation systems that allow bulk positive ratings to be manufactured through coordination. The mechanism in each case is clean; the question is what is actually being measured by the thing that gets counted, and whether that thing is itself subject to manipulation by the actors the mechanism is meant to assess.
Making a mechanism non-discretionary does not by itself make it capture-resistant. A non-discretionary mechanism that counts something acquirable has transformed capture from a social process (persuading, corrupting, or intimidating the humans who run a system) into an economic process (acquiring enough of the relevant resource). Whether the economic process is easier or harder than the social one depends entirely on what the resource is and how it is distributed. Where the relevant resource is money and the actors being constrained are wealthy, the economic process is often substantially easier.
B. WDT Instrument Audit
The mechanism-shaped test in (GOV §2.1) derives five conditions that a proposed deterrent mechanism must satisfy. This appendix audits the WDT’s existing instruments against those five conditions, organised around which failure mode each instrument is designed against.
B.1 Instruments That Pass Cleanly
VAL’s Route C mechanism (self-declared, fungible assets with in-kind settlement) passes the mechanism-shaped test without qualification. There is no separate oracle needed to report what the true value was: the declared value is the equity stake, expressed twice. The taxpayer who declares a low value receives a proportionally smaller equity transfer from the must-transfer mechanism; the taxpayer who declares a high value receives proportionally more. Misdeclaration and self-injury are the same act, occurring simultaneously, at a cost proportional to the size of the misstatement. No panel, verifier, or after-the-fact assessment is required. The five conditions are met structurally.
CORP’s listed-company market-capitalisation delta levy also passes cleanly. A continuously traded public market capitalisation is about as close to an oracle-independent price signal as exists anywhere in the economy. The price is set by millions of transactions between parties with no shared interest in any particular valuation outcome. Moving the market-cap figure to evade the levy means destroying real, broadly held shareholder value in a way that is transparent, verifiable, and costly to the actor doing it. The test’s third condition (cost proportional to the size of the act) is satisfied structurally by the levy’s own base.
The delta-based self-correction mechanism operating across Routes A and B (professionally valued assets, fungible and non-fungible) passes the test for any asset whose market price is set exogenously. The declared value establishes the recognised basis; understatement defers rather than eliminates liability, and the deferred liability compounds with asset growth. No single actor sets a liquid market price for an exchange-traded security or a standard commercial property, so the self-correction mechanism does not carry oracle risk for these asset classes. It applies to the large majority of the WDT’s asset base.
B.2 Instruments with Qualified or Partial Status
VAL’s delta-based self-correction does not pass cleanly for Route D (self-declared, non-fungible assets with no market comparable). This is VAL’s own named “most vulnerable point.” Between a Route D asset’s entry declaration and the eventual realisation event (which may be decades later), the basis sits uncorrected. An understated entry basis on Route D defers rather than eliminates liability. The basis gap compounds against the taxpayer as the asset grows: the eventual delta at realisation is calculated against the understated floor, is larger than honest declaration would have produced, and hits a higher marginal rate bracket. The taxpayer’s lifetime envelope refund entitlement is also smaller than honest declaration would have generated, since it is proportional to taxes actually paid. The Route D auction mechanism is the deterrent response to egregious understatement at entry; its necessity argument rests on the inception basis vulnerability identified in VAL §14.4, not on understatement being advantageous across the holding period. The delta mechanism does not correct for this retrospectively, because there is nothing to correct against: the taxpayer’s declared value is the only price that exists for a non-fungible, non-market asset until it is realised or inherited.
(GOV §6.1) is the response built against this gap. The Route D auction mechanism replaces the need for any actor to assert what the correct value is. When the three-body Valuation Body consensus confirms an egregious outlier, the asset is auctioned at the taxpayer’s own declared price. The market supplies the price discovery. No oracle is required: the auction mechanism produces a verified market price through open competitive bidding among third parties, with the taxpayer entitled to bid alongside them, and the winning price becoming the new recognised basis. This substantially closes the oracle dependency Route D previously carried, though not completely: the confirmation step requires the three-body consensus, which is itself a procedural system that could in principle be gamed through the Valuation Bodies’ institutional drift. The drift risk is addressed through the visibility mechanisms in (GOV §6.1) rather than through an oracle-free mechanism in the VAL sense. The Route D gap is substantially closed; it is not eliminated.
CORP’s unidentified-ownership tranche rate does not pass the mechanism-shaped test and is acknowledged as the one point where the design cannot be made fully self-executing. It is a flat-rate deterrent (\(\tau_h\) applied to permanently unattributable beneficial ownership) rather than a proportional, self-executing cost. A sufficiently resourced actor can simply pay the flat rate as a line item, treating it as an acceptable cost of opacity, without the cost scaling against the size of what is being concealed. The forfeiture of symmetric loss-refund access (developed in (CORP.A §B.2) partially addresses this by imposing a qualitative exclusion from the cooperative architecture rather than purely a financial charge. But the mechanism remains rule-shaped rather than mechanism-shaped at the cost-proportionality level. It is retained on the comparative standard: the deterrent available at this point in the design is better than the alternative of no deterrent, and the flat charge with refund forfeiture is harder to arbitrage than a pure flat charge alone.
The Allocator requires separate treatment following the redesign in GOV v2.7. The prior framing treated the Allocator’s appointment and removal process as rule-shaped rather than mechanism-shaped, on the grounds that the cooling-off bar and independence criteria were the primary accountability instruments. The redesign removes that framing. The T1/T2 appointment and removal structure, with rebalancing costs falling on the proposing chamber if a T2 removal succeeds and no cost on any chamber if T2 fails, is closer to mechanism-shaped than the prior assessment acknowledged. Neither cost requires a panel to judge whether conduct was improper; both are structural consequences of the vote outcome. The capture-as-feature reframing changes what the instrument audit should be testing: not whether the Allocator is independent of the chambers (it is not, by design, and the inside connections are the mechanism through which the role functions) but whether the published reasoning makes synthesis quality legible to DR. The published recommendation is the mechanism doing its work. The Allocator remains the most capture-vulnerable body in the architecture; the assessment’s meaning has changed, not its verdict. Full revised operational specification is in (GOV.B §B.2).
C. The Rejected First Derivation
(GOV §3.1) describes briefly an earlier attempt at the lever-test derivation that started from the inherited government/capital/public frame and mostly confirmed that frame rather than testing it independently. This appendix preserves that attempt transaction by transaction, alongside the corrected derivation (GOV §3.2) actually relies on, so the comparison is auditable rather than asserted. The failure is part of the record, not a discarded draft.
C.1 The First Transaction: Delta Measurement and Tax Flow
The corrected derivation starts with the delta measurement, tax flow, and refund flow described in (WP §3.1) and (GOV §3.1). The party whose net worth is measured is required by the definition of the transaction; no other transaction on the list needs a second party of this kind, and no existing position in the inherited frame supplies this specific role without modification. The verdict is a new position: the Taxpayer.
The first attempt reached the same conclusion, labelling this position as “Capital” and importing it directly from the inherited three-estate frame. The conclusion is correct; the method is not. The first attempt never asked whether the mechanism’s transactions actually required a party in this specific form — it assumed so because the inherited frame already had one. The conclusion survived that assumption; the method would not survive any transaction where the inherited frame’s answer was wrong, which is exactly what the later transactions reveal.
C.2 The Second and Third Transactions: Valuation and Outlier Confirmation
VAL’s Routes A and B require the valuer to be a different party from the Taxpayer, so that the valuer bears independent risk for a mispriced valuation. No already-identified party can hold this risk without collapsing the independence VAL’s own design depends on: the tax authority cannot value assets on behalf of the person whose tax it is computing, and the Taxpayer cannot value their own assets without reintroducing the declaration-gaming VAL is designed against. The corrected verdict is a new position: the Valuer.
The first attempt never addressed valuation as a distinct function at all. It folded the valuation role silently into “Government” without asking whether valuation required independence from the state’s own fiscal interest. The difference between “independent of the Taxpayer” and “independent of the state’s interest in the outcome” is precisely the difference the competitive-tender professional valuation model in (VAL §10) is built on, and the first attempt had no way to see it because it never asked the question.
The confirmed-outlier auction trigger (WP §4.3; (GOV §6.1) requires an independent confirmation process and a body distinct from the one that raised the initial flag. It cannot be the Taxpayer, who is the party acted against. It cannot be the same body that produced the outlier flag, since allowing the flagging body to confirm its own flag makes the check circular (the same self-referential-power failure mode described in (GOV.A §A.2). The corrected verdict is a new position: the Adjudicator.
The first attempt noticed that the executive and the certifying function cannot sit in the same body, and split Government internally to address it. The insight is correct. It stopped there, however, rather than asking whether the certifying function was itself distinct from the valuation function. (GOV §6.1)’s analysis shows it was not: confirming whether a valuation is sound requires doing a valuation. The Adjudicator and the Valuer are functionally parallel positions, not a separation of executive from judicial oversight. The corrected derivation identifies both as distinct lever-positions; (GOV §6.1) explains why the settled architecture instantiates those two positions as three bodies with identical mandates rather than two with distinct ones.
C.3 The Fourth Transaction: Surplus Allocation
(WP §4.2) separates the mechanical refund trigger from the discretionary allocation function explicitly: the party who triggers refunds is not assumed to be the party who decides how the available-for-allocation balance is divided among general government revenue, labour relief, and reinvestment. That separation is a design choice in WP itself, and a derivation that imports “Government” as a single body misses it. The corrected verdict is a new position: the Allocator.
The first attempt folded the allocation function into the same internal Government split already applied to the certifying function, treating the resulting sub-body as a single undifferentiated remainder. It never tested whether this remainder contained two distinct functions requiring two distinct parties. The valuation/adjudication function and the allocation function share no structural property requiring them to be held by the same party; they were grouped together only because both fell outside the narrower executive role the first attempt had already split off. This is how the assumption of the inherited frame distorts the derivation: the frame has only one “not-Government-executive” slot, so anything not immediately identifiable as executive gets bundled into it.
C.4 Dividend Receipt and the Solvency-Ratio Check
Checking what the dividend recipients actually hold in the mechanism reveals only the receiving end of a transfer. They have no vote in the mechanism’s transactions, no valuation role, and no custody over anything upstream of the dividend itself. The corrected verdict is an endpoint only: Dividend Recipients are flagged as a position but not confirmed as a governing peer at the derivation stage. Their standing as a chamber is established separately in (GOV §5.1) through the anti-collusion guarantee, not through the lever test.
The first attempt concluded the opposite. It imported “Public” as a full chamber with an assumed vote, on exactly the same footing as Government and Capital, because the inherited three-estate frame already had a third position and required filling it. This is the first attempt’s core failure in its clearest form: it never asked what lever “Public” actually held against the mechanism’s own transactions. It assumed standing followed from inclusion in the inherited frame.
The solvency-ratio check (WP §4.1) is not a transaction performed by any party. It is a number — a computed ratio that feeds the Allocator’s constraint. The corrected verdict is that the solvency check is not a party at all. The first attempt’s three-estate frame had no category for a constraint that is not itself an actor; every element considered was assumed to map onto some party holding it. The distinction between a constraint and a party is invisible to a derivation that begins from a frame of actors rather than from a list of transactions.
C.5 Corporate Infrastructure and Rule-Change Proposals
(CORP §5) makes clear that the listed company in the corporate delta levy has no delta and no refund of its own. It remits a provisional levy, issues delta statements, and settles the gap between its provisional rate and each shareholder’s marginal rate, but the company itself is infrastructure around the individual transaction rather than an interested party to it. The corrected verdict is infrastructure, not a party. CORP’s scope extends beyond what the first attempt addressed, so this is a gap in scope rather than a failure of method, included here for completeness rather than as a criticism.
The capacity to propose a rule change is a property of whichever party is proposing, not evidence of a new party that needs to exist. The corrected verdict is that rule-change proposals produce no new position. In a derivation that begins from transactions rather than from actors, the question must be asked explicitly, and when it is, the answer is that the proposing capacity is always already held by one of the positions the derivation has already established.
C.6 What the Comparison Shows
The first attempt’s single result (recognising that the executive and the certifying function cannot sit in the same body) survives the corrected derivation as the distinction between the Allocator and the valuation/adjudication functions. What the first attempt got wrong was not that particular split but the method that produced it: testing the inherited frame for internal inconsistencies rather than building the frame from the mechanism’s transactions in the first place. A derivation that starts from a predetermined answer looks for problems that contradict that answer most obviously. It will not find the problems the answer itself creates, which are visible only if the starting point is the transactions rather than the frame.
A note on instantiation. The Valuer and the Adjudicator named as this derivation’s output are not the bodies that appear in (GOV §6.1)’s settled architecture. (GOV §6.1) replaces both with three independent Valuation Bodies operating under identical mandates. This appendix states the derivation’s positions as the lever test actually produced them, because that is what the derivation itself concluded. It is (GOV §6.1), not this appendix, that explains why the final architecture instantiates those two positions as three bodies rather than two.
D. Explored and Dropped Mechanisms
This appendix exists so that none of the mechanisms below get reproposed without the objection already recorded against them being addressed first. The objections are organised by the failure mode each proposed mechanism ultimately reproduces, because the underlying pattern matters more than the surface form of any individual proposal. None of these mechanisms are live in the architecture described in (GOV §3), (GOV §4), (GOV §5) and (GOV §6). None should be reproposed without addressing the specific objection recorded here.
D.1 Mechanisms That Reproduce the Resource-Defines-Truth Failure
Monetary fees on rule-changes were the simplest and most obviously flawed candidate. The fee prices the ability to propose structural change, acting as a friction cost. The failure is immediate: the wealthiest actor in the room can always afford it. What appears to be a deterrent becomes a toll a patient, well-resourced chamber simply pays, directly reintroducing the resource-defines-truth failure mode described in (GOV.A §A.3) as the very mechanism that was meant to avoid it.
Voluntary, self-formed groups as an alternative to fixed chambers were proposed on the grounds that the existing chamber design imposes participation structures actors find artificial. The objection is that group composition becomes a strategic choice available to the proposer: a chamber-equivalent could be assembled specifically to dilute the cost of a proposal, with nominal members recruited to share the burden. This is the same attribution-dilution failure CORP had to design against on the ownership side. CORP’s backstop is an unconditional levy that does not care who is hiding behind the structure; governance has no equivalent backstop if chamber membership is itself gameable by the proposer.
D.2 Mechanisms That Reproduce the Oracle Failure
Anti-evasion record requirements were proposed as a fix for procedural calcification — the tendency for informal influence to operate outside the formal amendment process without triggering the cost. The idea was to treat undocumented governance decisions as informal structural proposals attributed to whichever chamber benefited from them, subjecting them retroactively to the rebalancing cost. The failure runs on three compounding levels. First, it is a pure oracle failure: “lacks a formal record” as a trigger condition simply pushes targeted coordination into spaces the mechanism cannot see, including communication channels outside the system’s jurisdiction. Second, records are fabricable, which reinstates a judge as the mechanism’s de facto gatekeeper. Third, narrow anti-evasion definitions become routing maps: the more precisely the mechanism specifies what it is trying to catch, the more precisely it tells actors how to commit the same substantive act while remaining outside the definition. This is the same shape as the threshold-ratcheting rejection below, arriving one layer down.
A forecasting-error ledger scored against published public metrics was a more sophisticated attempt at the same goal. It would score each chamber’s governance decisions against an objective external metric (the solvency ratio, the delivered dividend) and impose a proportional cost when a chamber’s decisions predicted a better outcome than materialised. This is proportional and requires no panel, making it formally better than flat banishment. But the underlying metrics still need a methodology defined by someone, and that definition step inherits exactly the failure mode the mechanism was meant to avoid: not selective coverage or biased verdicts, but quiet methodological drift at the input-definition stage, upstream of any verdict ever being rendered. The metric looks objective; whoever defines the metric is not.
D.3 Mechanisms That Assume Away the Hardest Cases
Flat banishment from future participation for proposing a carried rule change was the earliest cost mechanism considered. It fails on four independent grounds. The cost is flat regardless of the act’s size, so it deters only the chamber whose desired change is smaller than the banishment cost: precisely the population least worth deterring. It is denominated in future system-participation, which a short-horizon actor does not value. It assumes the system survives the act, which is exactly what is in question for the most dangerous proposals; banishment from a captured system is not a meaningful cost. And it creates a sacrifice-play structure: a faction can field an expendable proposer, insulating the chamber’s surviving membership from the cost while achieving the outcome. Flat banishment rewards exactly the kind of faction discipline it was designed to prevent.
Mutually assured destructive capability, framed as a governance deterrent analogous to nuclear deterrence, collapsed on contact with the requirement that the mechanism be survivable. Once constrained to produce outcomes the institution could recover from (conditional vetoes, automatic procedural consequences, escalating review costs), it became indistinguishable from ordinary counterweight design, which was already available. The nuclear analogy is also structurally misleading for this architecture specifically: deterrence works when both parties have symmetric patience and symmetric stakes. The actors this architecture is trying to constrain do not share those properties across actor types. A long-horizon actor with patient capital and a short-horizon political agent playing within a single term have different discount rates that a single deterrent threat cannot reach simultaneously.
Automatic resignation from office upon a structural proposal passing catches only the least dangerous version of the failure mode it targets. The mechanism only costs an actor who values holding office above the policy outcome the proposal achieves. The more dangerous actor — one who treats office as a means rather than an end and is playing for the policy outcome alone — is not deterred at all. Worse, automatic resignation creates a clean sacrifice play: a faction backing a structural change can install an expendable proposer who does not mind losing the office, leaving the faction’s substantive membership intact on the other side of the transition.
Threshold-ratcheting after a failed structural proposal (an immune-system framing in which each rejected attack raises the threshold required for the next one) fails as a mechanism for the same reason as the anti-evasion record requirements. It requires classifying a proposal as an attack rather than good-faith parameter tuning, and that classification is exactly the discretionary judgment this paper’s standard exists to eliminate. A non-discretionary version might be constructed by keying the ratchet to a projected solvency impact rather than to judged intent, which would avoid the oracle problem at the classification step. Whether such a version can be specified without reintroducing discretion at the solvency-impact modelling stage is a question worth revisiting if a candidate specification can be found; it is not currently available.
D.4 The Veto Holder
The Veto Holder — a single long-tenure discretionary office whose occupant could block or delay structural proposals, raise visibility on compromised decisions, and provide institutional memory across the timescales that elected chambers cannot sustain — was developed further than any other dropped mechanism and warrants the most extended treatment here.
The office was introduced on hole-fitting grounds. Starting from the premise that it should exist, the design identified functions it could plausibly serve: deadlock resolution, elevated visibility on highly compromised proposals, epistemic diversity from an institutionally isolated perspective, and temporal friction from an actor whose institutional memory extended further back than any current chamber. Each function is real. The error was in the method: identifying functions a proposed office could plausibly serve, then treating that list as confirmation the office should exist, rather than first asking whether those functions were already met by existing mechanisms and whether this specific office would meet them reliably.
A gap analysis run from the opposite direction found three residuals. The first is the procedurally valid but substantively catastrophic decision: a proposal that clears the dual-threshold voting rule, attracts no seat-burning challenge from DR, and passes without triggering any enumerated-clause review, but is nonetheless a serious mistake. The second is simultaneous incapacitation of multiple bodies: the Administrator, the Valuation Bodies, and one or both proposing chambers compromised at the same time. The third is legitimacy erosion over multi-decade timescales, where the institution’s public standing decays slowly in ways no single decision tracks.
The Veto Holder does not cleanly address any of them. On the first residual: deadlock is structurally near-impossible by the architecture’s own design, and procedurally valid catastrophic decisions are precisely the category where a single individual’s discretionary judgment is most likely to be both wrong and irreversible. On the second: simultaneous incapacitation of multiple bodies is a scenario in which a single additional office is unlikely to remain uncompromised; the mechanism for simultaneous capture reaches a Veto Holder at least as readily as it reaches the bodies already in the design. On the third: legitimacy erosion over multi-decade timescales is the role-fidelity drift problem identified in (GOV.A §E.4), and temporal embeddedness is a vulnerability in that context as much as it is an asset. A Veto Holder who has been in office for thirty years embeds a set of thirty-year-old institutional assumptions as resistance; whether those assumptions were right when formed, and whether they guard against the failure modes the institution is currently facing, is something a single isolated individual cannot reliably judge.
Two further arguments were considered and found insufficient. The epistemic diversity argument — that a single institutionally isolated individual provides a perspective unavailable to any collective body that has developed a shared culture — is undercut by DR, which is explicitly designed as the architecture’s epistemic outsider. DR achieves institutional isolation through monthly lottery rotation and the deliberate absence of institutional culture; it provides that outsider perspective on a continuous, self-renewing basis rather than through a single long-tenure individual whose isolation is a product of long tenure and therefore not isolation in any structural sense. The political heat absorption argument — that a named, removable individual provides a target for backlash against unpopular but necessary interventions — identifies a real constitutional function, but does not establish that this architecture needs it. The rebalancing mechanism already provides an impersonal structural cost that makes no individual the target of backlash; the mechanism absorbs political heat by construction.
The office is dropped. Any future proposal to reintroduce it must address this gap analysis directly rather than restarting from the list of functions the office could plausibly perform. The list is not in dispute; the question is whether the office is the right mechanism for delivering them, given that the existing architecture already addresses most of them and the Veto Holder’s specific failure modes in the remaining cases are severe.
D.5 — Why a Lottery Specifically
The Veto Holder analysis establishes what DR needs to be: non-capturable because it is structurally independent of TP and FS, diffuse enough that coordinating it costs more than coordinating the two chambers it guards against, and rotating fast enough that no sustained relationship between its members and either proposing chamber can develop into reliable influence. What it does not establish is why a random lottery satisfies those requirements better than the alternatives.
Three properties are required of DR’s constitution method. First, membership must be independent of the two chambers it checks: DR cannot be composed of people appointed by TP or FS, selected from within an existing institution either chamber controls, or drawn from any pool that either chamber can influence before selection occurs. Second, the constituency must be diffuse enough that coordination costs exceed those of capturing TP and FS combined. Third, rotation must be fast enough that no sustained relationship between DR members and either proposing chamber develops into reliable influence.
Random selection by birth-month lottery satisfies all three directly. The alternatives do not. Appointment by an independent panel introduces a panel whose own independence must be guaranteed by some further mechanism, which either regresses or terminates in an assumption. Election by the broader public produces a constituency that TP and FS can both campaign within, reintroducing the political-influence channel the guarantee is designed to block. Self-selection by civil society volunteers produces a membership biased toward the professionally engaged, which at the wealth levels where WDT revenue concentrates means a membership that overlaps substantially with the advisory and institutional networks TP members already operate in. A lottery with no eligibility criteria beyond age produces a constituency whose independence is structural rather than promised: its members were not selected by anyone with a stake in what they decide, and their prior relationship to the WDT is identical — they have none.
The monthly birth-month stagger follows from the rotation requirement. A single annual draw replacing DR’s entire membership at once creates a moment of maximum vulnerability: the incoming cohort has no institutional memory, no established working norms, and no visibility into the label distribution patterns that inform seat-burn decisions. Staggered monthly entry ensures DR always contains members at different stages of their term, so new members enter an institution with a functioning culture rather than reconstituting one from scratch. The one-year term is the shortest period consistent with a member developing real rather than nominal familiarity with the mechanism’s outputs; shorter terms would make DR a formality.
E. Governance Decay: Four Sub-Forms
Governance decay is the gradual degradation of an institution’s capacity to perform its intended function, without any single discrete act causing it. It bypasses the mechanism’s formal amendment process: no structural clause is touched, no Tier 2 vote is triggered, and no rebalancing cost attaches. The institution continues to operate in its formal structure while its substantive capacity erodes beneath the surface.
Four sub-forms can be identified. Three are irreducible by mechanism design. One yields a mechanism-shaped response.
E.1 Definitional Drift
Words in a structural clause stay fixed on the page while their operational meaning migrates underneath them. This is the most irreducible sub-form, confirmed so by constitutional theory’s interpretation and construction problem, by the formal self-amendment literature, and by results in the broader study of self-governing rule systems (Ostrom, 1990; Elster, 2000).
The irreducibility is not uniform across all instances. Slow reinterpretation (a gradual shift in professional or institutional consensus with no single moment to point to) is undetectable in the moment by construction. The only honest response is the general corpus: the Public Valuation Register, the SWF’s actuarial record, the full published decision archive, preserved for whatever post-capture reconstruction effort eventually needs it. Fast reinterpretation (a sudden, motivated reading change tied to a specific proposal, ruling, or event) has a date and a proximate cause, and is therefore locatable after the fact without requiring any qualitative judgment about whether the reinterpretation was justified. This locatability depends entirely on the record itself being trustworthy. The Administrator’s publication mandate carries an explicit format-consistency requirement for exactly this reason: fixed cycle, fixed structure, no discretion to reformat, and any change to the format itself logged as a dated event.
The residue mechanism for definitional drift is the Public Valuation Register and the SWF’s actuarial record for the slow case, and the same archive plus the format-integrity guarantee for the fast case.
E.2 Procedural Calcification
The formal amendment process becomes progressively more expensive to use over time, while informal influence continues to operate freely outside it. A proposed fix (treating undocumented decisions as informal structural proposals subject to the same cost) fails on three compounding grounds: it is a pure oracle failure (GOV.A §A.1), since “lacks a formal record” as a trigger condition simply pushes targeted coordination into spaces the mechanism cannot see; the records it would rely on are themselves fabricable; and narrow anti-evasion definitions become routing maps for exactly the behaviour they were written to target. This sub-form collapses into definitional drift’s bucket for the same underlying structural reason.
The residue mechanism is the published vote record and three-way ratio described in (GOV §5.3): a complete history of what was formally proposed, voted on, and how each chamber voted, legible to any future reconstruction effort without requiring any retrospective judgment about intent.
E.3 Constituency Dissolution
A body’s formal membership rule stays fixed while what it actually draws from drifts underneath it. This is the one sub-form that is tractable by mechanism design, and the reason is structural: DR’s volunteer rate is a byproduct number rather than a fabricable record. It is generated by the underlying behaviour itself (lottery selectees actually choosing to serve or not) rather than reported by any party with an interest in shaping the figure. The constituency dissolution mechanism specified in (GOV §5.1) closes this sub-form mechanically: the monthly lottery draw count expands when the volunteer rate falls and decays back down asymmetrically once the rate recovers, with the decay window longer than the expansion trigger window.
This is the correct partition between tractable and irreducible: constituency dissolution is tractable because its diagnostic signal is a byproduct that cannot be strategically manipulated without changing the underlying behaviour itself. The other three sub-forms are irreducible because their diagnostic signals are either absent (slow definitional drift), fabricable (procedural calcification records), or structurally lagging (role-fidelity drift’s solvency ratio). The constituency dissolution mechanism does not reduce governance decay generally; it closes one specific sub-form that happens to have the structural property needed for a mechanism-shaped response.
E.4 Role-Fidelity Drift
A functional body’s actual conduct loosens away from its mandate without any term being redefined and without the formal amendment process ever being touched. For a single body, this is close to undetectable in real time. Real-world precedent (drift in the auditing profession, central bank mandate creep, regulatory capture within professional licensing) confirms that no ongoing mechanism-shaped deterrent exists against this sub-form. Detection is retrospective and depends on a tail event eventually surfacing it.
The three-body Valuation Body architecture described in (GOV §6.1) partially improves on this for the valuation function. Systematic divergence between the three Valuation Bodies (one consistently flagging outliers the other two do not corroborate, or one consistently producing estimates that diverge from the other two in a directional pattern) is visible in the aggregate published record without requiring any qualitative judgment about whether any single valuation was wrong. This is a visibility improvement, not a mechanism-shaped deterrent. Detection is possible; prevention within a live, ongoing institution is not.
The SWF Custodian is this sub-form’s highest-stakes instance: it directly controls the capital backing the refund liability, and drift toward less conservative holdings within its mandate could proceed for years without ever breaching the solvency floor, surfacing only in a downturn that finally tests it. (GOV §6.3)’s three structural requirements (pre-crisis public commitment to drawdown conditions, overlapping non-renewable tenure, and periodic stewardship statements) are this paper’s response to that specific instance, named there as the best available approximation to an irreducible problem rather than as a solution to it.
The three requirements are not independent safeguards but a single system, and the argument for each follows from the nature of the problem rather than from institutional convention. Pre-crisis public commitment to specific drawdown conditions converts the slow form of drift into the fast form: a Custodian that publishes its drawdown conditions annually in binding form cannot exercise those conditions differently in a crisis without the departure appearing as a dated, attributable event in the permanent record. Each loosening of stated conditions in successive annual statements is itself visible rather than absorbed silently into internal practice, and the cumulative record of statements is the raw material any future reconstruction effort needs. The pre-commitment requirement does not prevent drift; it makes drift locatable. Overlapping long non-renewable tenure removes the incentive to please any appointing party in anticipation of reappointment, while ensuring that no single appointment round reshapes the institution’s culture simultaneously. At any moment the Custodian’s leadership contains people at different distances from their appointment moment, making coordinated drift toward a shared preference harder to engineer than synchronised renewal would allow. Periodic stewardship statements on a fixed public cycle create a ratcheting reputational commitment: a Custodian that has publicly committed to a conservative investment disposition across several successive statements cannot silently reverse that position without a discontinuity appearing in the permanent record. The value of the ratchet compounds with time, which is why it works in combination with long tenure rather than independently of it. None of the three requirements is sufficient alone; pre-commitment without tenure produces a body that can loosen its stated conditions at each renewal; tenure without pre-commitment produces a well-insulated body with no public commitment to be held against; statements without either produce a record nobody is accountable for maintaining.
The residue mechanism for role-fidelity drift is the published decision archive alongside the three-body corroboration statistics and the Custodian’s stewardship statement record: a body whose conduct drifts either contradicts its own prior published statements or visibly redefines them, and either route is legible in the permanent record without requiring any oversight body to render a verdict in real time.
E.5 The Correct Partition and What Follows From It
The correct partition across all four sub-forms is: irreducible (definitional drift, procedural calcification, and role-fidelity drift) against tractable (constituency dissolution alone). The three irreducible sub-forms share a common structure: no diagnostic signal exists that is simultaneously timely, reliable, and outside the control of any actor with an interest in the outcome. Constituency dissolution is tractable precisely because its diagnostic signal (the volunteer rate) is all three.
The appropriate institutional response to the three irreducible sub-forms is residue rather than prevention: the systematic accumulation of durable assets (public registers, published records, actuarial histories) that survive a captured period and give a future legitimate effort the raw material it needs to reconstruct what happened and rebuild from it. This is not a consolation prize for design failure. It is the honest identification of what mechanism design can and cannot achieve, stated directly rather than papered over with mechanisms that appear to address these sub-forms but do not.
Naming them as irreducible prevents the design from generating false assurances of prevention, and gives the residue mechanisms their proper weight as the honest response to what cannot be prevented.