scieee AI-readable full text Open interactive document viewer

Part III - ADAPTATION: Bounded asymmetry and institutional stability

Atkinson, James D.

Abstract

Project website: https://www.integrodynamics.org/ [THIS PAPER NEEDS UPDATING] This paper introduces the Adaptation Sentinel Framework, forming the final component of the applied synthesis in the Mathematics of Integrity programme, following Contradiction (epistemic diagnostics) and Symmetry (procedural fairness). While this paper completes the operational and institutional layer of the framework, subsequent work develops the underlying mathematical foundations of integrity. Adaptation formalises institutional integrity as behavioural invariance under admissible symmetry. Institutions are modelled as triples of rationale, narrative, and behaviour. Using commitment-preserving perturbations (sentinel symmetries), the framework empirically tests whether behaviour remains coherent under stress. Deviations are not treated as anomalies but as falsifiable evidence of institutional asymmetry. The paper introduces: Sentinel symmetry operators The Sentinel Condition for external consistency The Sentinel Integrity Theorem The prime module: a bounded stochastic adaptation mechanism A tamper-evident Sentinel Ledger for full auditability Together, these components form a deployable architecture for evidential governance, providing real-time, symmetry-preserving integrity monitoring of institutions. The framework resolves the applied layer of the trilogy while explicitly preparing the ground for the forthcoming mathematical and physical theory of integrity. Keywords: sentinel framework; institutional integrity; behavioural invariance; symmetry-preserving audit; evidential governance; metamorphic testing; adaptation under drift; e-processes; auditability; fairness diagnostics; adversarial testing; integrity monitoring; stochastic approximation.

Full text

Part III – ADAPTATION Bounded asymmetry and institutional stability James D. Atkinson 2025 Abstract This paper introduces the sentinel framework (adaptation), which assembles the epistemic diagnostic of Contradiction and the procedural invariance of Symmetry into an operational model of institutional coherence under drift. adaptation formalises coherence as behavioural invariance under a publicly declared family of admissible symmetries that preserve an institution’s rationale (R) and narrative (N). These symmetries generate a falsifiable evidential architecture built from metamorphic sentinel tests, anytime-valid e-processes, and a projected prime controller that maintains coherence under bounded drift without altering declared commitments. In this framework, behavioural deviation is not treated as anomaly but as evidence: contradiction, divergence, and asymmetry become measurable indicators of external inconsistency. A tamper-evident Sentinel Ledger records all symmetry applications, coherence residuals, e-values, and prime updates, enabling transparent reconstruction and independent audit. Institutions are assessed not by narrative claim but by their capacity to preserve declared invariances under structured challenge. adaptation completes the opening trilogy in the mathematics of integrity series by supplying the bounded prime layer linking epistemic contradiction and symmetry to dynamically evolving institutional behaviour. Keywords: evidential symmetry; institutional coherence; behavioural invariance; metamorphic invariance; admissible symmetry; symmetry preserving audit; sentinel tests; e-processes; projected stochastic approximation; bounded adaptation; drift-bounded governance; adversarial diagnostics; asymmetry detection; external inconsistency; evidential governance; evidential accountability; institutional monitoring. 1 Contents 1 Notation and symbols 6 2 Trilogy summary 8 3 Introduction 9 3.1 From logic to process to operation . . . . . . . . . . . . . . . . . . . . 10 3.2 Contributions of this paper . . . . . . . . . . . . . . . . . . . . . . . . . 10 3.3 Novelty and comparison to existing systems . . . . . . . . . . . . . . 11 3.4 Synthesis................................... 12 4 Foundations of adaptation 12 4.1 Adaptive component: prime ....................... 13 4.2 Institutional rationale, narrative, and behaviour . . . . . . . . . . . . 13 4.3 Stress configurations and symmetric challenge operators . . . . . . . 14 4.4 Coherence cost and evidential metrics . . . . . . . . . . . . . . . . . . 15 4.5 The Sentinel Condition . . . . . . . . . . . . . . . . . . . . . . . . . . . 15 4.6 Admissible sentinel symmetries . . . . . . . . . . . . . . . . . . . . . 16 4.7 Computational feasibility . . . . . . . . . . . . . . . . . . . . . . . . . . 17 5 The sentinel model 17 5.1 The procedural-regulatory integrity management environment module (prime)............................... 18 5.2 Operational components . . . . . . . . . . . . . . . . . . . . . . . . . . 18 5.3 Institutional state space . . . . . . . . . . . . . . . . . . . . . . . . . . 19 5.4 Action of sentinel symmetry . . . . . . . . . . . . . . . . . . . . . . . . 19 5.5 TheSentinelLedger............................. 19 5.6 Ledger integrity theorem . . . . . . . . . . . . . . . . . . . . . . . . . . 20 5.7 Adversarymodel .............................. 21 5.8 Security assumptions . . . . . . . . . . . . . . . . . . . . . . . . . . . . 21 5.9 Operational commitments and tamper-evident ledgering . . . . . . . 22 6 The commitment legibility protocol (CLP) 22 6.1 Purpose ................................... 23 6.2 Procedure .................................. 23 6.3 Output .................................... 24 6.4 Interpretation................................ 24 6.5 Metamorphic symmetry batteries . . . . . . . . . . . . . . . . . . . . . 25 6.6 Evidential Metrics and Decision Protocol . . . . . . . . . . . . . . . . . 26 6.7 Institutional drift and symmetric resilience . . . . . . . . . . . . . . . 26 6.8 Failure modes and diagnostic signatures . . . . . . . . . . . . . . . . . 27 2 7 The Sentinel Integrity Theorem 27 7.1 Assumptions................................. 28 7.2 Sentinel Integrity Theorem . . . . . . . . . . . . . . . . . . . . . . . . 28 7.3 Finite-Sample Concentration . . . . . . . . . . . . . . . . . . . . . . . 29 7.4 Anytime-valid evidence via e-processes . . . . . . . . . . . . . . . . . 30 7.5 Corollaries and interpretations . . . . . . . . . . . . . . . . . . . . . . 31 7.6 Interpretation................................ 31 8adaptation: the prime sentinel module 32 8.1 Definition of prime ............................. 32 8.2 prime as the unifying architecture . . . . . . . . . . . . . . . . . . . . 33 8.3 Adaptive environment and declared weights . . . . . . . . . . . . . . 34 8.4 Feasible region and drift envelope . . . . . . . . . . . . . . . . . . . . 35 8.5 Projected update rule . . . . . . . . . . . . . . . . . . . . . . . . . . . . 35 8.6 Stability under bounded drift . . . . . . . . . . . . . . . . . . . . . . . 35 8.7 Projected stochastic approximation structure . . . . . . . . . . . . . . 36 8.8 Interpretation: prime as symmetry preservation . . . . . . . . . . . 36 9 Simulation framework 37 9.1 Core scenario classes . . . . . . . . . . . . . . . . . . . . . . . . . . . . 37 9.1.1 (1) Stationary environment . . . . . . . . . . . . . . . . . . . . 37 9.1.2 (2)Slowdrift ............................ 38 9.1.3 (3)Regimeshift........................... 38 9.1.4 (4) Adversarial perturbations . . . . . . . . . . . . . . . . . . . 39 9.2 Stress tests and benchmarks . . . . . . . . . . . . . . . . . . . . . . . 39 9.2.1 Parameter sensitivity . . . . . . . . . . . . . . . . . . . . . . . . 39 9.2.2 Comparative baselines . . . . . . . . . . . . . . . . . . . . . . . 40 9.3 Diagnostics and decision protocol . . . . . . . . . . . . . . . . . . . . 40 9.4 Ledger reconstruction . . . . . . . . . . . . . . . . . . . . . . . . . . . 41 9.5 Domain-specific symmetry libraries . . . . . . . . . . . . . . . . . . . 41 10 Institutional applications of adaptation 42 10.1 Judicialallocation.............................. 43 10.2 Public funding models . . . . . . . . . . . . . . . . . . . . . . . . . . . 43 10.3 Regulators and compliance agencies . . . . . . . . . . . . . . . . . . . 43 10.4 Automated decision systems . . . . . . . . . . . . . . . . . . . . . . . 44 10.5 Media and information systems . . . . . . . . . . . . . . . . . . . . . . 44 10.6 Interpretive summary . . . . . . . . . . . . . . . . . . . . . . . . . . . 44 11 Presentation and structural enhancements 45 11.1 Notation and glossary . . . . . . . . . . . . . . . . . . . . . . . . . . . 45 11.2 Boxed sentinel tests . . . . . . . . . . . . . . . . . . . . . . . . . . . . 46 3 11.3 Lineagediagram............................... 47 11.4 Formatting and theorem structure . . . . . . . . . . . . . . . . . . . . 48 11.5 Reproducibility notes . . . . . . . . . . . . . . . . . . . . . . . . . . . . 49 12 Empirical validation of the sentinel framework 49 12.1 Designoverview............................... 50 12.2 Dataset construction . . . . . . . . . . . . . . . . . . . . . . . . . . . . 51 12.3 Sentinel symmetry tests . . . . . . . . . . . . . . . . . . . . . . . . . . 51 12.4 Sequential evidence accumulation . . . . . . . . . . . . . . . . . . . . 52 12.5 Boundedadaptation ............................ 52 12.6 Resultssummary .............................. 53 12.7 Interpretation................................ 53 13 Philosophical foundations 55 13.1 Thesis..................................... 55 13.2 Epistemicjustice .............................. 55 13.3 Auditsociety................................. 55 13.4 Operational economics . . . . . . . . . . . . . . . . . . . . . . . . . . . 56 13.5 Information-theoretic governance . . . . . . . . . . . . . . . . . . . . 56 13.6 Inclusiveintegrity.............................. 56 13.7 Weighted symmetries for testimonial justice . . . . . . . . . . . . . . 56 13.8 Institutional anti-patterns . . . . . . . . . . . . . . . . . . . . . . . . . 57 13.9 Strategic dynamics: multi-institution simulation . . . . . . . . . . . . 58 14 Applications and case domains 59 14.1 Legalhypotheticals............................. 59 14.2 Policyguidance ............................... 59 14.3 Peer review and retraction dynamics . . . . . . . . . . . . . . . . . . . 60 15 The Adversarial Integrity Game (AIG) 60 15.1 Players and objectives . . . . . . . . . . . . . . . . . . . . . . . . . . . 60 15.2 Actionsets.................................. 61 15.3 Payoffs.................................... 61 15.4 Equilibrium analysis . . . . . . . . . . . . . . . . . . . . . . . . . . . . 62 15.5 Interpretation................................ 62 16 Ethical guardrails and meta-governance 63 16.1 Transparency requirements . . . . . . . . . . . . . . . . . . . . . . . . 63 16.2 Auditable adaptation . . . . . . . . . . . . . . . . . . . . . . . . . . . . 63 16.3 Boundaries on automated correction . . . . . . . . . . . . . . . . . . . 64 16.4 Humanoversight .............................. 65 16.5 Interpretation................................ 65 4 17 Limitations 66 17.1 Dependence on declared commitments . . . . . . . . . . . . . . . . . 66 17.2 Symmetry specification and interpretive latitude . . . . . . . . . . . . 66 17.3 Finite-sample and epistemic limits . . . . . . . . . . . . . . . . . . . . 67 17.4 Bounded corrective power of prime ................... 67 17.5 Behavioural evidence without intent . . . . . . . . . . . . . . . . . . . 67 17.6 Strategic declaration and adversarial response . . . . . . . . . . . . . 68 17.7 Limits of quantitative oversight . . . . . . . . . . . . . . . . . . . . . . 68 17.8 Computation and administrative capacity . . . . . . . . . . . . . . . . 69 17.9 Non-goals: cryptographic clarifications . . . . . . . . . . . . . . . . . 69 18 Synthesis and contribution 70 18.1 Evidential architecture across three levels . . . . . . . . . . . . . . . . 70 18.2 Methodological unity . . . . . . . . . . . . . . . . . . . . . . . . . . . . 71 18.2.1 Symmetry as testable neutrality . . . . . . . . . . . . . . . . . 71 18.2.2 Coherence as measurable evidence . . . . . . . . . . . . . . . 72 18.2.3 Falsifiability and reconstruction . . . . . . . . . . . . . . . . . 72 18.3 Statement of originality . . . . . . . . . . . . . . . . . . . . . . . . . . 72 18.4 Implications and research programme . . . . . . . . . . . . . . . . . . 73 18.5 Summary................................... 73 19 Conclusion 74 A Case study: public funding under region-preserving symmetry 76 A.1 Institutional context and commitments . . . . . . . . . . . . . . . . . 76 A.2 Dataset and pre-registration . . . . . . . . . . . . . . . . . . . . . . . . 76 A.3 Sentinelbattery............................... 77 A.4 Empiricalfindings.............................. 77 A.5 Ledger diagnostics and prime intervention . . . . . . . . . . . . . . . 77 A.6 Localisedforensics ............................. 78 A.7 Interpretive Ssmmary . . . . . . . . . . . . . . . . . . . . . . . . . . . 78 B Implementation and operational notes 79 B.1 Metamorphic battery construction . . . . . . . . . . . . . . . . . . . . 79 B.2 Ledgerschema ............................... 79 B.3 Robbins-Monro conditions for adaptation ............... 80 B.4 Verificationpipeline............................. 80 B.5 Operational fail-safes . . . . . . . . . . . . . . . . . . . . . . . . . . . . 81 5 1 Notation and symbols Symbol Meaning Institutional Structure and Inputs 𝑋Decision or policy space under evaluation. 𝐷Dataset or observation stream used by the institution. 𝐷′Perturbed dataset used for invariance testing. ΦInstitutional mapping from datasets to outputs: Φ∶𝐷↦𝑂. 𝑂Output under baseline conditions. 𝑂′Output under challenge or perturbation. I Institutional configuration or operating regime. S Sentinel model or audit specification. P Perturbation family applied during prime evaluation. Adaptation Conditions pPredictability: stable response to stable inputs. rRobustness: bounded deviation under admissible perturbation. iIndependence: output not dominated by irrelevant factors. mMinimality: outcomes follow from the fewest assumptions. eEvidence: outputs traceable to observable data. prime Full integrity condition: p∧r∧i∧m∧e. Challenge and Perturbation Operators 𝛿Canonical perturbation operator for datasets. 𝛿𝐷 Data-level perturbation (addition, removal, masking, shuffling). 𝛿𝑂 First-order output deviation: 𝑂′−−𝑂. C(𝑥) Challenge function applied at input 𝑥. Δinv Invariance deviation under perturbation: Φ(𝐷′)−−Φ(𝐷). Θadv Adversarial pressure parameter controlling perturbation magnitude. 𝜂Noise term injected during stress testing. ADV Adversarial test regime identifier. Ledger, Provenance, and Traceability 𝐿Institutional ledger of operations or decisions. 𝐿𝑡Ledger state after 𝑡operations. Δ𝐿 Ledger drift signal: 𝐿𝑡+1−−𝐿𝑡. 𝐾Ledger boundary term representing unrecorded operations. Raudit Audit reconstruction operator. 6 Symbol Meaning TRACE Set of traceable, reconstructible operations. UNTRACE Set of operations lacking provenance. Validity and Invariance Metrics 𝐶KL KL divergence between 𝑂and 𝑂′. 𝐶TV Total variation distance between outputs. 𝐶adv Adversarial divergence score under stress tests. 𝑉loc Local validity metric under small perturbations. 𝑉glob Global validity across the perturbation family P. 𝑍inv Z-score for invariance deviation. 𝜎inv Estimated noise floor for invariance metrics. Structural Integrity and Invariant Quantities M Compliance manifold: set of states satisfying prime. Π(𝑥) Projected state onto M. 𝑑MDistance to compliance manifold (scalar defect measure). 𝐼∗Composite integrity score across prime dimensions. 𝑆Structural order parameter: low under drift, high under conformity. 𝜆min Smallest eigenvalue of stability operator (resilience). 𝜅Decay constant in recovery dynamics after perturbation. Drift, Breakage, and Failure Modes Δdrift Institutional drift magnitude over time. 𝜔𝑡Drift trajectory index for dynamic systems. FAIL𝑃Predictability failure. FAIL𝑅Robustness failure. FAIL𝐼Independence failure. FAIL𝑀Minimality failure. FAIL𝐸Evidence failure. ΩCatastrophic integrity collapse region (beyond prime). Game-Theoretic Audit Structure A-game Audit game: ⟨𝐴,B,𝑆𝐵,𝑈𝐴,𝑈𝐵⟩. 𝑆𝐵System’s response set under audit (actions, evasions, disclosures). 𝑈𝐴Auditor utility: increased with deviation or evidence gaps. 𝑈𝐵System utility: increased by minimal deviation signal. Δ(𝑟) Epistemic update from the system’s response 𝑟. 7 Symbol Meaning BR𝐵Best-response set under audit pressures. Anomaly Detection and Thresholds 𝜁Sentinel anomaly score combining KL, TV, and drift. 𝜏anom Detection threshold for anomalies. 𝜖Tolerance margin for invariance. 𝜖min Minimum acceptable perturbation effect. 𝜖max Maximum allowed drift before invalidity. 𝕀[⋅] Indicator function for constraint violation. Simulation and Evaluation Parameters 𝑛Dimensionality of output or decision vector. 𝑇Total number of simulation or audit iterations. 𝑚Number of adversarial samples per perturbation family. 𝜎Noise amplitude in Monte Carlo perturbations. CI95 95% confidence interval for prime scores. 𝜇base Baseline mean of output statistics. Miscellanea 𝑑Distance metric (generic: TV, KL, 𝐿2, manifold distance). ∘Function composition (ledger + perturbation pipelines). 𝜕𝑋 Boundary of decision space. ∇Gradient operator used in compliance-surface analysis. B Boundary condition in Sentinel reconstruction. 2 Trilogy summary This opening trilogy develops the underlying principles and the applied mathematics of integrity: a unified evidential framework based on contradiction, symmetry, and adaptation. Contradiction as evidence, symmetry as fairness, and adaptation extends the same evidential and fairness frameworks to institutions, combining behavioural contradictions, symmetry preservation, and commitments into a falsifiable model of principled behaviour. Across all three domains – reasoning, allocation, and governance – the same structure holds: only what remains invariant under principle-preserving transformation can count as integrity. 8 Engine (prime) Contradiction Symmetry adaptation Evidence + Fairness + Commitment Figure 1: The mathematics of integrity: prime as the unifying backbone for evidence (Contradiction), fairness (Symmetry), and institutional commitment (adaptation). 3 Introduction Institutions rarely collapse in spectacle. They fail quietly – in the small misalignments between what they claim and what they do. A rationale is declared, a narrative is offered, a process is specified, and yet under stress or uncertainty, behaviour drifts. The public is asked to trust that the drift is accidental or benign (O’Neill, 2002; Power, 1997). Oversight bodies, in turn, are often forced to judge legitimacy not by evidence of integrity, but by the absence of proof of corruption (Hood & Dixon, 2015). Governance, in practice, remains a system of belief. The question of this paper is simple: do we have to take their word for it? The sentinel framework (adaptation) proposes that institutional integrity can be treated as a falsifiable property (Popper, 1959). Rather than trusting institutions to maintain their declared rationale, adaptation tests their behaviour under symmetric conditions that preserve that rationale. Rather than relying on retrospective audits or procedural minutiae, we examine the coherence between what an institution says it is doing and how it behaves when the narrative is held constant and the environment is perturbed in controlled ways. Under adaptation, an institution is not assumed to be legitimate. It must demonstrate legitimacy – empirically, repeatedly, and without special pleading. This paper forms the final entry in a trilogy beginning in epistemic logic and progressing through procedural fairness. Contradiction showed that contradiction is not a failure mode but a diagnostic instrument: a system that cannot preserve its story across symmetric questions reveals the constraints it has not acknowledged (Atkinson, 2025a). Symmetry extended this idea to procedural design: fairness becomes an evidential property. A process either converges towards its declared proportions under certified randomness or it does not; failure to converge is evidence (Atkinson, 2025b). Both frameworks demonstrated the same principle: integrity is behaviour under symmetric pressure. 9 Definition 4.3 (Sentinel Condition).Let I be an institution with behavioural map B and admissible sentinel symmetries S. For 𝑥∈X, define the sentinel residual ΔS(𝑥)∶=B(𝑆(𝑥))−B(𝑥) (4.9) The institution satisfies the Sentinel Condition at state 𝑥if ΔS(𝑥)=0 ∀S∈S (4.10) The Sentinel Condition fails at 𝑥if there exists S ∈S such that ΔS(𝑥)≠0 (4.11) The associated coherence divergence, 𝐶S(𝑥)∶=𝑓􏿴ΔS(𝑥)􏿷(4.12) constitutes falsifiable evidence of institutional asymmetry. An institution satisfies the global Sentinel Condition if the condition holds for all reachable states 𝑥∈X. This condition provides adaptation’s operational boundary: behaviour must remain invariant under all commitment-preserving symmetries. 4.6 Admissible sentinel symmetries The admissible symmetry family S forms a monoid acting on X (Atkinson, 2025a, 2025b), ensuring compositional testability of stress configurations: (i) Identity: ∃𝑒∈S such that 𝑒(𝑥)=𝑥for all 𝑥. (ii) Closure: If S1,S2∈S, then S2∘S1∈S. (iii) Optional Invertibility: If each S is bijective and S−1 ∈S, then S is a group. Commitment invariance. All admissible symmetries satisfy: R(𝑆(𝑥))=R(𝑥), N(𝑆(𝑥))=N(𝑥) ∀S∈S, 𝑥∈X.(4.13) 16 Lemma 4.4 (Equivariance of Monitoring Functionals).Let ℎbe any measurable monitoring functional. If the Sentinel Condition holds at 𝑥, then ℎ(B(𝑆(𝑥)))=ℎ(B(𝑥)) ∀S∈S.(4.14) Proof. Immediate: B(𝑆(𝑥))=B(𝑥)implies ℎ(B(𝑆(𝑥)))=ℎ(B(𝑥)). Interpretation. Equivariance ensures that deviations under symmetry directly reflect violations of declared commitments rather than noise or model misalignment (Mitchell et al., 2021; Rahwan et al., 2019). 4.7 Computational feasibility adaptation is computationally lightweight. Let 𝑛be batch size, 𝑘behaviour dimension, 𝐽the metamorphic battery size, and 𝑑the adaptation parameter dimension (Kushner & Yin, 2003; Polyak & Juditsky, 1992). •Symmetry transforms: 𝑂(𝑛). •Residuals (KL or quadratic): 𝑂(𝑘). •E-process updates: 𝑂(1)per symmetry per step (Howard et al., 2021; Vovk & Wang, 2021). •Global e-value merge: 𝑂(𝐽). •Hash-chain ledger update: 𝑂(1)(Haber & Stornetta, 1991; Merkle, 1979). •adaptation projected update: 𝑂(𝑑)(Polyak & Juditsky, 1992). Thus total runtime is linear in 𝑛with small multiplicative factors, making adaptation suitable for real-time, high-throughput institutional settings. 5 The sentinel model To move from foundational principles to operational governance, adaptation requires a formal model of how institutions encode rationale, narrative, behaviour, and their relationships under sentinel symmetry (Atkinson, 2025a, 2025b). The sentinel model 17 provides this structure. It specifies the operational components of an institution, the representations on which sentinel symmetry acts, and the ledger through which behavioural evidence is recorded and audited (Haber & Stornetta, 1991; Merkle, 1979). A central design principle is the strict separation between declared elements (R and N) and observable elements (B and the ledger). Sentinel symmetry acts only on institutional states, not on commitments. Behaviour is therefore tested against fixed commitments, and deviations become evidential (Fricker, 2007; Popper, 1959). This section formalises the model, the institutional tuple, the action of sentinel symmetry, the Sentinel Ledger, cryptographic integrity guarantees, the adversary model, and the metamorphic symmetry battery used in operational tests (Mitchell et al., 2021; Rahwan et al., 2019; Raji et al., 2020). 5.1 The procedural-regulatory integrity management environment module (prime) prime is the sentinel module embedded within adaptation. It provides bounded, operationally constrained corrective dynamics that preserve procedural and narrative coherence under drift (Kushner & Yin, 2003; Polyak & Juditsky, 1992). prime generalises Symmetry’s stochastic mechanism to the institutional setting (Atkinson, 2025b). Definition 5.1 (prime).The procedural-regulatory integrity management environment (prime) is the correction process Θ𝑡+1 =ΠK􏿴Θ𝑡+𝜂𝑡􏾧 ∇Θ𝑅𝑡􏿷(5.1) where ΠKis projection onto a convex regulatory envelope K, {𝜂𝑡}is a diminishing stepsize sequence, and 𝑅𝑡is a coherence or fairness reward consistent with declared commitments (R,N).prime stabilises behaviour under drift while preserving invariance under all admissible sentinel symmetries (Kushner & Yin, 2003; Polyak & Juditsky, 1992). prime does not “learn” new commitments: it maintains the declared ones. 5.2 Operational components The adaptation institutional tuple (Def. 4.1) forms the backbone of the model. Rationale R encodes principled commitments; narrative N specifies their public interpretation; behaviour B traces realised conduct; the symmetry set S defines admissible tests; 18 coherence metrics 𝐶quantify deviations; and the Sentinel Ledger 𝐿records the evidential trace (Atkinson, 2025a, 2025b). These together form a operational architecture: R and N express what the institution claims to be doing; B, S, 𝐶, and 𝐿show whether that claim is honoured. 5.3 Institutional state space Let X denote the institutional state space. A state 𝑥 ∈ X encodes all contextual and operational information relevant to its behaviour, B(𝑥). Declared commitments (R,N) are not elements of X: they remain fixed under all operations. Sentinel symmetries act on states: 𝑥↦S(𝑥) (5.2) preserving commitments while perturbing contextual detail (Binns, 2018; Mitchell et al., 2021). 5.4 Action of sentinel symmetry For each S ∈S, behaviour is evaluated in symmetric form: B(𝑥𝑡)and B(S(𝑥𝑡)) (5.3) Residuals ΔS(𝑥𝑡)∶=B(S(𝑥𝑡))−−B(𝑥𝑡)(5.4) form the basis of coherence metrics (Howard et al., 2021; Vovk & Wang, 2021). These residuals become evidential atoms: behavioural divergence under commitment-preserving symmetry (Atkinson, 2025a, 2025b). 5.5 The Sentinel Ledger The Sentinel Ledger provides the tamper-evident evidential backbone of adaptation (Goldreich, 2001; Haber & Stornetta, 1991; Merkle, 1979). Definition 5.2 (Sentinel Ledger).The Sentinel Ledger is a sequence 𝐿={ℓ𝑡}∞ 𝑡=1 (5.5) where each entry ℓ𝑡=􏿴𝑥𝑡,S𝑡,B(𝑥𝑡), B(S𝑡(𝑥𝑡)), 𝐶S𝑡(𝑥𝑡), Θ𝑡􏿷(5.6) 19 records the state, applied symmetry (if any), behavioural outputs, coherence residual, and prime parameter state. The ledger is reconstructible if all entries can be reproduced from public seeds, declared commitments, and ledger metadata (Mitchell et al., 2021; Raji et al., 2020). { ”ts”: ”2025-05-12T14:28:31Z”, ”prev_hash”: ”c0c2e2...af1”, ”seed_source”: ”drand:mainnet”, ”seed_value”: ”4237d8...b6c”, ”symmetry_id”: ”perm:recipient-shuffle:v1”, ”symmetry_desc”: ”Permutation of recipient labels; dataand rationale-preserving”, ”dataset_hash_before”: ”a14b7...21c”, ”dataset_hash_after”: ”a14b7...21c”, ”residuals”: {”CKL”: 0.021, ”CTV”: 0.034}, ”e_value”: 37.2, ”tier_after”: 2, ”prime_update”: { ”eta”: 0.12, ”update”: ”projected-gradient”, ”projection_norm”: ”l2”, ”feasible_region_id”: ”K_w:declared-weights-2025Q2” }, ”notes”: ”No dataset mutation; \texttt{prime} applied to declared weights per CLP.” } Two operational functions follow: (1) behavioural evidence cannot be rewritten, and (2) prime updates must be auditable and bounded by K. 5.6 Ledger integrity theorem The ledger ensures tamper-evident auditability using only collision-resistant hashing (Haber & Stornetta, 1991; Merkle, 1979). No zero-knowledge, MPC, or privacy guarantees are claimed. Definition 5.3 (Hash Chain).Let Hash ∶{0,1}∗→{0,1}𝑘be collision-resistant (Goldreich, 2001). For epoch 𝐸,ℎ0=𝐻𝐸, ℎ𝑡=Hash(ℓ𝑡,ℎ𝑡−1). (5.7) 20 Theorem 5.4 (Ledger Integrity).If an adversary modifies any ledger entry ℓ𝑡to ℓ′𝑡≠ℓ𝑡, then for all 𝑡′≥𝑡,ℎ′𝑡′≠ℎ𝑡′(5.8) and in particular the epoch root changes: 𝐻final ′ 𝐸≠𝐻final 𝐸(5.9) Thus no retroactive modification of ledger contents is possible without detection (Haber & Stornetta, 1991; Merkle, 1979). Proof. Immediate from collision resistance: modifying ℓ𝑡changes its digest and therefore ℎ𝑡, which propagates to all future hashes. Matching the original ℎ𝑇would require a collision (Goldreich, 2001). The ledger provides tamper-evidence, commitment binding, reconstructibility, and audit verifiability from standard primitives alone (Haber & Stornetta, 1991; Merkle, 1979). 5.7 Adversary model Definition 5.5 (Adversary).An adversary A is any PPT algorithm that may: (A1) influence behaviour B(𝑥𝑡)via inputs; (A2) propose alternative commitments (R′,N′); (A3) attempt to alter ledger entries ℓ𝑡; (A4) attempt to forge an alternative hash chain. A is computationally bounded and cannot find hash collisions (Bellare & Rogaway, 1993; Goldreich, 2001). adaptation does not address confidentiality attacks: it guarantees integrity only. 5.8 Security assumptions adaptation relies on minimal assumptions (Goldreich, 2001): (S1) Collision resistance of Hash (Haber & Stornetta, 1991; Merkle, 1979). 21 (S2) Second-preimage resistance on ledger entries. (S3) Commitment binding via epoch hash 𝐻𝐸. (S4) Public verifiability of seeds, descriptors, and metadata (Mitchell et al., 2021; Raji et al., 2020). (S5) Computational boundedness of adversaries (Bellare & Rogaway, 1993). From these, the ledger provides tamper-evidence, retroactive immutability, and full reconstructibility. 5.9 Operational commitments and tamper-evident ledgering At the beginning of each epoch 𝐸, commitments are locked by 𝐻𝐸=Hash(𝑅,𝑁,𝑡𝐸)(5.10) and remain fixed throughout the epoch. Any revision produces a new epoch (Haber & Stornetta, 1991). Ledger entries include checksums of inputs/outputs, symmetry descriptors, RNG seeds, and prime parameters. Hash linking ensures immutability; daily Merkle roots allow public audits (Merkle, 1979). Scope. The ledger guarantees tamper-evidence and reconstruction; it is not a confidentiality or zero-knowledge system and makes no cryptographic privacy claims. 6 The commitment legibility protocol (CLP) adaptation presupposes that an institution’s declared rationale (R)and narrative (N) are sufficiently clear to support admissible sentinel symmetries (Atkinson, 2025a, 2025b). In practice, many commitments are ambiguous, selectively applied, or altered in response to observed behaviour (Hood & Dixon, 2015; Power, 1997). The Commitment Legibility Protocol (CLP) ensures that (R,N)are made explicit, testable, and stable before sentinel analysis begins (Fricker, 2007; O’Neill, 2002). 22 6.1 Purpose CLP prevents strategic ambiguity (Hood & Dixon, 2015). It converts an institution’s stated principles into a form that admits falsifiable symmetry tests (Popper, 1959). The protocol establishes three requirements: 1. Legibility: commitments must be stated in operational and symmetry-preserving terms (Power, 1997); 2. Specificity: vague claims must be resolved into measurable predicates (Binns, 2018); 3. Stability: the institution must commit to version-controlled declarations that cannot be retrofitted after results are observed (Haber & Stornetta, 1991; Merkle, 1979). 6.2 Procedure Before any sentinel symmetry is defined, the institution completes the following steps. 1. Commitment enumeration. All stated principles, rules, objectives, and narrative justifications are listed as (R,N)with unique identifiers (O’Neill, 2002). Ambiguous terms (e.g. “fair”, “balanced”, “merit”, “region-neutral”) are flagged automatically (Mitchell et al., 2021; Raji et al., 2020). 2. Operationalisation. Each flagged commitment is rewritten as a measurable predicate (Binns, 2018; Mitchell et al., 2021). For example: • “merit-based” →specific evaluative features or scores; • “region-neutral” →invariance under permutations of regional labels; • “balanced representation” →explicit target proportions or acceptable deviation bands (Atkinson, 2025b). 3. Scope fixing. The institution declares the domain over which each commitment applies (e.g. all funding rounds; all hiring panels; specific categories of decisions). Scope cannot be narrowed retroactively without invalidating the audit (Power, 1997). 23 4. Symmetry compatibility check. For each operationalised commitment, CLP verifies whether a non-trivial sentinel symmetry exists that preserves it. Commitments that prohibit all admissible symmetries are marked as self-sealing and are excluded from legitimacy claims (Atkinson, 2025a, 2025b). 5. Version control and freezing. The finalised set (R⋆,N⋆)is hashed and time-stamped (Haber & Stornetta, 1991; Merkle, 1979). No changes are permitted during the sentinel test. Any revision constitutes narrative drift and is itself evidence of breach under the adaptation deviation logic (Atkinson, 2025b). 6.3 Output CLP produces: 1. a legible commitment set (R⋆,N⋆); 2. an admissible-symmetry index indicating which commitments support sentinel tests (Binns, 2018; Mitchell et al., 2021); 3. a public hash ensuring commitments cannot be altered without detection (Haber & Stornetta, 1991; Merkle, 1979); 4. a log of discarded or self-sealing commitments. These outputs become the foundation for constructing the Sentinel Map and for determining whether observed behaviour constitutes an invariance breach (Atkinson, 2025b). 6.4 Interpretation CLP guarantees that adaptation is not evaded through definitional ambiguity (Hood & Dixon, 2015). It prevents institutions from weakening or retrofitting commitments in response to evidence (O’Neill, 2002; Power, 1997) and ensures that all sentinel symmetries preserve commitments derived from a stable, operationalised declaration. By securing the front end of the framework, CLP closes the principal avenue of strategic evasion (Atkinson, 2025a; Fricker, 2007). 24 6.5 Metamorphic symmetry batteries Operational sentinel symmetry is implemented through a library of publicly declared metamorphic relations (MRs) (Chen et al., 1998; Segura et al., 2016). Each MR𝑗induces a symmetry S𝑗∶𝑥↦MR𝑗(𝑥) (6.1) satisfying the invariance constraints 𝑅(S𝑗(𝑥))=𝑅(𝑥), 𝑁(S𝑗(𝑥))=𝑁(𝑥). (6.2) Definition 6.1 (Metamorphic Battery).Ametamorphic symmetry battery is a finite set 𝕄={MR1,…,MR𝐽}(6.3) each satisfying commitment preservation, context perturbation, full auditability, and non-degeneracy (Raji et al., 2020; Segura et al., 2016). Typical MRs include identifier anonymisation, ordering permutations, region-preserving shuffles, semantic-preserving rewrites, and context jitter (Mitchell et al., 2021). Residuals from each MR, 𝐶MR𝑗(𝑥𝑡)=𝐷􏿴B(𝑥𝑡),B(MR𝑗(𝑥𝑡))􏿷(6.4) feed the e-processes used for anytime-valid detection (Howard et al., 2021; Vovk & Wang, 2021). Examples (illustrative). •Judicial allocation: region-preserving permutations; shuffle case order within jurisdiction; mask identifiers (control for irrelevant factors). •Funding competitions: randomised tiebreak; budget-neutral swaps across equivalent panels. •Hiring pipelines: reorder shortlists; permute interviewers; hold scoring rubric fixed. 25 a measurable invariance property, tested by symmetry, recorded in a tamperevident ledger, and falsifiable in finite samples (Atkinson, 2025a, 2025b). 8adaptation: the prime sentinel module prime (procedural-regulatory integrity management environment) is the sentinel module embedded within the Sentinel Framework (Atkinson, 2025b). Whereas adaptation provides the operational architecture for evidential integrity, prime supplies the operational dynamics that preserve this integrity under bounded drift (Borkar, 2008; Kushner & Yin, 2003; Polyak & Juditsky, 1992). Its task is not optimisation but coherence: to adjust procedural parameters only in ways that maintain behavioural invariance under admissible symmetries and remain faithful to the declared rationale R and narrative N (O’Neill, 2002; Power, 1997). prime inherits the corrective spirit of Symmetry (Atkinson, 2025b) but operates within a operational envelope: updates must be symmetric, auditable, and constrained so as not to permit narrative reinterpretation or opportunistic behavioural drift. In combination, adaptation and prime implement a model of self-auditing governance in which institutions adapt only to the extent that preserves the Sentinel Condition (Atkinson, 2025a, 2025b). 8.1 Definition of prime Definition 8.1 (prime).Let I be an adaptation-governed institution with declared rationale R, narrative constraints N, and behavioural outputs B. (prime) is the sentinel module defined by the tuple prime =⟨K,Θ,𝜂𝑡,𝑅𝑡,ΠK,S⟩(8.1) where: (i) Regulatory Envelope K.A convex, compact feasibility region K ⊂ℝ𝑑restricting all prime parameters. Updates must satisfy Θ𝑡∈K for all 𝑡(Bertsekas, 2015). (ii) Adaptive Parameters Θ𝑡.A vector of procedural control parameters (e.g. gains or losses, smoothing weights, variable coefficients) constrained by K. 32 (iii) Step Schedule {𝜂𝑡}.A Robbins–Monro step-size sequence (Robbins & Monro, 1951): 𝜂𝑡>0, ∞ 􏾜 𝑡=1𝜂𝑡=∞, ∞ 􏾜 𝑡=1𝜂2 𝑡<∞ (8.2) (iv) Integrity Reward 𝑅𝑡.A scalar diagnostic derived from coherence metrics (e.g. 𝐶S(𝑥𝑡)) consistent with the declared commitments (R,N)(Atkinson, 2025b). (v) Projected Update Rule. prime applies the correction Θ𝑡+1 =ΠK􏿴Θ𝑡+𝜂𝑡􏾧 ∇Θ𝑅𝑡􏿷(8.3) where ΠKdenotes Euclidean projection onto K (Bertsekas, 2015). (vi) Symmetry Preservation. For every admissible sentinel symmetry S ∈S, B(S(𝑥))=B(𝑥) whenever the Sentinel Condition holds. (8.4) prime maintains procedural–regulatory integrity when, under bounded contextual drift, behavioural outputs remain within the tolerance envelope specified by adaptation (Kushner & Yin, 2003; Polyak & Juditsky, 1992). 8.2 prime as the unifying architecture Although introduced in the context of institutional behaviour, the prime module is domain-general. prime provides a symmetry-preserving prime rule that updates expectations in response to observed deviations while maintaining falsifiability under admissible transformations (Benveniste et al., 1990; Borkar, 2008). Formally, prime defines an update operator Π𝜎∶B→B, Π𝜎(B)=B+𝜂Δ𝜎(B). (8.5) where 𝜎is an admissible symmetry, Δ𝜎is the deviation detected under that symmetry, and 𝜂is a bounded learning rate ensuring stability and auditability (Polyak & Juditsky, 1992). Contradiction as a prime instantiation. In Contradiction (Atkinson, 2025a), behaviours correspond to reasoning commitments, and deviations are coherence-cost asymmetries induced by framed propositions. The prime operator becomes the epistemic update that shifts posterior odds based on contradiction likelihood ratios. 33 Symmetry as a prime instantiation. Symmetry (Atkinson, 2025b) is recovered by instantiating the space of behaviours B as allocation frequencies and letting Δ𝜎be the residuals. The prime update rule becomes the balance adjustment, and the admissible symmetries are label permutations preserving the target weights 𝑤. adaptation as a prime instantiation. In adaptation, B is the behaviour of an institution under its declared commitments. Deviations are sentinel residuals – departures from invariance under admissible symmetries. prime governs prime expectations and enables the sentinel to distinguish benign drift from systematic asymmetry. Unified interpretation. Under this view, the three papers share a single architecture: contradiction +symmetry +adaptation.(8.6) Contradiction applies it to reasoning, Symmetry to stochastic allocation, and adaptation to institutions (Atkinson, 2025a, 2025b). The trilogy is therefore structurally unified: prime is the general evidential backbone, and the domain-specific modules instantiate it under different behavioural spaces and symmetry groups. 8.3 Adaptive environment and declared weights Let 𝑤𝑡denote the declared procedural or proportional weights at time 𝑡. Environmental drift is represented by ‖𝑤𝑡+1−𝑤𝑡‖∞≤𝑑max.(8.7) prime stabilises behaviour in this regime by adjusting Θ𝑡within K, ensuring that adaptation remains symmetric and does not introduce behaviour inconsistent with (R,N)(Benveniste et al., 1990; Ljung, 1977). In stationary environments (𝑑max =0), prime converges to the unique equilibrium compatible with the Sentinel Condition (Polyak & Juditsky, 1992). In drifting environments, prime tracks the moving equilibrium up to an error envelope determined by 𝑑max and the step-size sequence (Kushner & Yin, 2003). 34 8.4 Feasible region and drift envelope The regulatory envelope K serves as a operational constraint (O’Neill, 2002): K={Θ∈ℝ𝑑∶𝑔𝑖(Θ)≤0, 𝑖=1,…,𝑚}. (8.8) These constraints encode procedural, regulatory, or ethical limits and prevent adaptation from undermining declared commitments (Power, 1997). Define the drift envelope 𝐸𝑡=O(𝑑max)+O(𝜂) (8.9) where 𝜂is the average step-size over a correction horizon (Borkar, 2008). prime maintains the Sentinel Condition up to this envelope. 8.5 Projected update rule The projected SA update aims to reduce coherence residuals: 􏾧 ∇Θ𝑅𝑡=−􏾧 ∇Θ𝐶S𝑡(𝑥𝑡)(8.10) so prime attempts to move in the direction of reduced asymmetry while remaining inside K (Bertsekas, 2015). 8.6 Stability under bounded drift Under the Robbins–Monro conditions and bounded drift (Robbins & Monro, 1951), prime satisfies ‖Θ𝑡−−Θ∗𝑡‖=O(𝑑max)+O(𝜂), where Θ∗𝑡is the instantaneous symmetry-preserving equilibrium (Kushner & Yin, 2003; Polyak & Juditsky, 1992). In stationary environments, this envelope collapses to zero. Adversarial drift. If drift respects ‖𝑤𝑡+1−𝑤𝑡‖∞≤𝑑max, the tracking bound continues to hold. If drift exceeds this envelope, persistent residuals appear in 𝐿and prime records a breach (Atkinson, 2025b). Curvature within the institutional state space mirrors potential curvature in physical systems: integrity is locally stable so long as drift remains within the basin of coherence. 35 8.7 Projected stochastic approximation structure prime’s update rule is a projected stochastic approximation (PSA) scheme (Borkar, 2008; Kushner & Yin, 2003). Regularity assumptions. (P1) K is convex, closed, compact (Bertsekas, 2015). (P2) ∇Θ𝑅𝑡is 𝐿-Lipschitz. (P3) Steps satisfy Robbins–Monro (Robbins & Monro, 1951). (P4) Stochastic gradients are unbiased with bounded variance. (P5) Drift satisfies ‖𝑥𝑡+1−𝑥𝑡‖≤𝑑max (benveniste1990\texttt {prime}). PSA update. Let Θ∗𝑡satisfy ∇Θ𝑅𝑡(Θ∗𝑡)=0. Θ𝑡+1 =ΠK􏿴Θ𝑡+𝜂𝑡􏾧 ∇Θ𝑅𝑡􏿷(8.11) Theorem 8.2 (Tracking Under Bounded Drift).Under (P1)–(P5), ‖Θ𝑡−−Θ∗𝑡‖=O(𝑑max)+O( 𝜂)+O􏿴√𝜂𝑡􏿷(8.12) Proof. Standard PSA results (Borkar; Kushner–Yin) decompose the error into drift, projection bias, and stochastic noise (Borkar, 2008; Kushner & Yin, 2003). Stationary environments yield almost-sure convergence (Polyak & Juditsky, 1992). 8.8 Interpretation: prime as symmetry preservation prime is not a learning system (Atkinson, 2025b). It is a operational regulator: adaptation is allowed only insofar as it preserves symmetric invariance (O’Neill, 2002). Updates cannot alter the meaning of the institution’s commitments or re-interpret its narrative; they can only enforce coherence under drift. Thus prime provides a mechanism for institutional evolution that is auditable, bounded, and symmetry-preserving (Power, 1997). Together with the Sentinel Integrity Theorem (Atkinson, 2025b), it completes adaptation’s operational model: legitimacy becomes something that can be maintained under change without being altered by it. 36 9 Simulation framework The simulation suite provides evidential validation for the prime Sentinel Framework (Atkinson, 2025b). Its purpose is not predictive accuracy but operational assessment: to determine whether adaptation preserves symmetry-based integrity under stationary, drifting, adversarial, and domain-specific conditions. Each simulation is executed under declared commitments (R,N)and written to the Sentinel Ledger with full reconstructibility from public seeds, symmetry descriptors, and epoch roots (Haber & Stornetta, 1991; Merkle, 1979). Let 𝕄={MR1,…,MR𝐽}denote the metamorphic symmetry battery (Chen et al., 1998; Segura et al., 2016). Behaviour at time 𝑡is B(𝑥𝑡); transformed behaviour under MR𝑗is B(S𝑗(𝑥𝑡)); the coherence residual is 𝐶S𝑗(𝑥𝑡); and the sequential evidence is captured by e-values 𝐸𝑡,𝑗 and the global e-value 𝐸global 𝑡(Section 7.4) (Howard et al., 2021; Vovk & Wang, 2021). The prime component follows the prime update rule (Borkar, 2008; Polyak & Juditsky, 1992): Θ𝑡+1 =ΠK􏿴Θ𝑡+𝜂𝑡􏾧 ∇Θ𝐶MR(𝑥𝑡)􏿷(9.1) maintaining behavioural symmetry within the regulatory envelope K (Bertsekas, 2015). 9.1 Core scenario classes The simulations evaluate adaptation across four structural regimes (Atkinson, 2025b). 9.1.1 (1) Stationary environment Behaviour is generated from a time-invariant mechanism satisfying the Sentinel Condition. Commitments (R,N)remain fixed; admissible symmetries are exact (Atkinson, 2025b). Metrics. • Empirical distribution of 𝐶S𝑗(𝑥𝑡). • False Tier 2/Tier 3 breach rates under known invariance. • Calibration curves for 𝐸𝑡,𝑗 and 𝐸global 𝑡(Howard et al., 2021). 37 • Convergence of Θ𝑡→Θ∗under prime (Polyak & Juditsky, 1992; Robbins & Monro, 1951). Expectation. Residuals remain near zero; e-values remain near unity; prime converges cleanly. 9.1.2 (2) Slow drift Context evolves gradually (Kushner & Yin, 2003): ‖𝑥𝑡+1−𝑥𝑡‖≤𝑑max, 𝑑max ≪1 (9.2) modelling non-stationary but narrative-preserving environments. Metrics. • Tracking error ‖Θ𝑡−Θ∗𝑡‖. • Detection latency for emerging asymmetry. • Recovery half-life following stabilisation. Expectation. prime maintains error within O(𝑑max)+O( 𝜂)and suppresses false alarms (benveniste1990\texttt {prime}). 9.1.3 (3) Regime shift A structural change occurs at time 𝑡⋆(Atkinson, 2025a): 𝑥𝑡+1 =𝑥𝑡+Δ, ‖Δ‖≫𝑑max (9.3) representing narrative breach, policy shift, systemic error, or failure of commitment invariance. Metrics. • E-value explosion time (Vovk & Wang, 2021): 𝜏=min{𝑡∶𝐸global 𝑡≥1/𝛼} (9.4) 38 •prime overshoot before projection to K (Bertsekas, 2015). • Recovery half-life (Tier 2 to Tier 0). • Ledger-recorded breach sequence and reconstruction consistency (Haber & Stornetta, 1991; Merkle, 1979). 9.1.4 (4) Adversarial perturbations An adversary introduces symmetry-violating changes that preserve surface features but violate the admissible structure implied by (R,N)(Mitchell et al., 2021; Raji et al., 2020). Metrics. • Minimum adversarial magnitude 𝜀∗required for Tier 2. • Asymptotic growth rate of 𝐸global 𝑡(Howard et al., 2021). •prime robustness: stability of Θ𝑡under strategic bias (Polyak & Juditsky, 1992). Expectation. Even small violations should trigger rapid Tier 2/Tier 3 escalation with strong diagnostic clarity (Atkinson, 2025b). 9.2 Stress tests and benchmarks Stress tests evaluate sensitivity to prime hyperparameters, geometry of K, metamorphic battery size, and simulation scale 𝑛(Borkar, 2008). 9.2.1 Parameter sensitivity We grid-search over: 𝜂𝑡,diam(K), |𝕄|, 𝑛 (9.5) and record: • stability domains for prime, • bifurcation boundaries where tracking fails (Polyak & Juditsky, 1992), 39 • brittleness induced by misspecified regulatory envelopes (Bertsekas, 2015). 9.2.2 Comparative baselines We evaluate against: (B1) Static (no adaptation), (B2) Naive feedback (unconstrained updates), (B3) Retrospective audit (lag-𝐿detection) (Power, 1997), (B4) Symmetry (permutation-only) – the Paper 2 specialisation (Atkinson, 2025b). Evaluation metrics. • Detection latency (steps to 1/𝛼), • False discovery rate (stationary regime), • Stability index Var(Θ𝑡), • Recovery half-life following shocks, • Drift robustness: maximal 𝑑max sustaining Tier 0 (Kushner & Yin, 2003). 9.3 Diagnostics and decision protocol For each 𝑡and each MR𝑗we record the tuple (Chen et al., 1998; Segura et al., 2016): 􏿴𝐶S𝑗(𝑥𝑡), 𝐸𝑡,𝑗, 𝐸global 𝑡, Θ𝑡,decision𝑡􏿷.(9.6) Breach tiers. 1. Tier 1 (Local Excursion): transient elevation of 𝐶S𝑗(𝑥𝑡)without sustained e-value growth. 2. Tier 2 (Asymmetry Breach): 𝐸global 𝑡≥1/𝛼, signalling violation of admissible symmetry (Vovk & Wang, 2021). 3. Tier 3 (Narrative Collapse): persistent Tier 2 events; prime unable to restore coherence within K (Atkinson, 2025b). 40 Worked example (illustrative numbers; set by domain). Suppose a permutation-symmetry test on outputs yields residual 𝐶S= 0.021with per-test e-value 𝑒 = 37. The global e-value updates to 𝑒glob =85. Adopt the tiering: •Tier-1 (watch): 𝑒glob ∈[10,50) •Tier-2 (breach): 𝑒glob ∈[50,100) •Tier-3 (material breach): 𝑒glob ≥100 Trigger an prime update and ledger an incident at Tier-2+. (Choose thresholds with policy and risk appetite; these numbers are for demonstration only.) 9.4 Ledger reconstruction Each step writes a ledger entry (Haber & Stornetta, 1991; Merkle, 1979): ℓ𝑡=(seed,MR𝑗, 𝑥𝑡,B(𝑥𝑡), B(S𝑗(𝑥𝑡)), 𝐶S𝑗(𝑥𝑡), 𝐸𝑡,𝑗, 𝐸global 𝑡, Θ𝑡,decision𝑡). (9.7) Epoch roots 𝐻𝐸are published daily. Independent auditors can recompute: • hash-chain digests, •prime trajectories, • metamorphic outputs, • breach decisions, directly from public metadata (Haber & Stornetta, 1991). Merkle proofs allow verification of subsets without full disclosure (Merkle, 1979). 9.5 Domain-specific symmetry libraries Admissible symmetries must reflect the sector’s declared commitments (Binns, 2018; Mitchell et al., 2021). We include baseline metamorphic batteries for: Judiciary and case allocation. Docketshuffles; judgeanonymisation; protected-category permutations. 41 Paper 1: Contradiction Contradiction ⇒Evidence Paper 2: Symmetry Deviation ⇒Evidence Paper 3: adaptation Asymmetry ⇒Evidence epistemic →procedural procedural →institutional clarity →proportionality proportionality →invariance logic & symmetry inherited logic & symmetry inherited Figure 2: Lineage of the trilogy: epistemic →procedural →institutional integrity. 11.4 Formatting and theorem structure The manuscript follows uniform conventions to ensure clarity (Gentzkow & Shapiro, 2023; Knuth, 1984): • Definitions use bold headers and numbered labels. • Lemmas precede theorems; corollaries follow immediately after proofs. • Long proofs appear in Appendix A; short proofs remain inline. • Figures use minimal styling and consistent captioning. • All examples of symmetries, PSA updates, and ledger entries use the notation in Table 2. • Cross-references to Contradiction and Symmetry cite exact theorem or definition numbers (Atkinson, 2025a, 2025b). 48 11.5 Reproducibility notes All experiments follow the stress-testing regime of Section 9.2. Seeds, symmetry descriptors, and epoch hashes are recorded in the Sentinel Ledger (Haber & Stornetta, 1991). The public repository provides (Peng, 2011; Stodden et al., 2016): • metamorphic battery source code (Chen et al., 1998), • simulation notebooks, • ledger reconstruction tools (Merkle, 1979), •prime and K parameterisation, • diagnostics for projected stochastic approximation (Borkar, 2008). These resources enable complete independent replication. Interpretation. The presentation layer ensures that adaptation is not only formally correct but workable: notation is consistent, operational procedures are boxed for immediate use, and the lineage diagram situates adaptation within the evidential progression of the trilogy (Atkinson, 2025b). The result is a operationally framed, reproducible, and self-sufficient audit protocol (Gentzkow & Shapiro, 2023; Stodden et al., 2016). 12 Empirical validation of the sentinel framework This section presents a longitudinal, data-driven validation of the sentinel framework (adaptation) (Atkinson, 2025b) using a ten-year corpus of public research funding decisions. The objective is not predictive accuracy, but evidential governance: to evaluate whether an institution’s behaviour remains invariant under admissible sentinel symmetries (Chen et al., 1998; Segura et al., 2016), and whether the prime module provides bounded, commitment-preserving adaptation under contextual drift (Borkar, 2008). 49 Figure 3: Validation workflow for the sentinel framework. Empirical evaluation proceeds via dataset construction, symmetry tests (S1, S2), e-process accumulation, and bounded prime adaptation (Howard et al., 2021; Vovk & Wang, 2021). 12.1 Design overview The analysis operationalises adaptation’s operational components-rationale, narrative, behaviour, symmetry, coherence cost, sequential evidence, and prime projectionover an institutional decision dataset (Binns, 2018; Mitchell et al., 2021). Each funding decision is treated as a manifested behaviour B𝑡linked to the institution’s declared 50 rationale–narrative pair (R,N). The validation tests whether: 1. Decisions remain statistically invariant under admissible sentinel transformations 𝜎∈𝔐; 2. Deviations from declared rationale–narrative consistency accumulate as positive coherence cost 𝐶𝑡; 3. The sequential e-process shows bounded adaptation rather than unregulated drift under adaptation’s feedback rule (Polyak & Juditsky, 1992). The empirical protocol follows the workflow in Fig. 3, implemented as a reproducible audit pipeline (Gentzkow & Shapiro, 2023; Peng, 2011). 12.2 Dataset construction The dataset comprises ∼50,000 award decisions made by a national research agency between 2013–2023, spanning 12 disciplinary panels and 200,000 applicant records. Each record encodes: • application metadata (discipline, institution, applicant demographics); • declared evaluation criteria (novelty, feasibility, track record); • reviewer scores and funding outcomes; • textual rationales extracted from panel minutes and feedback letters. All identifiers were anonymised and grouped into statistically balanced cohorts (Raji et al., 2020). Commitments (R,N)were reconstructed from institutional policy documents, call guidelines, and ministerial strategy statements (O’Neill, 2002; Power, 1997). 12.3 Sentinel symmetry tests Two sentinel transformations were defined: •S1(Demographic symmetry): Permutation of applicant demographic attributes (gender, institution tier, ethnicity) within equivalent proposal strata. Neutrality requires outcome invariance under S1(Binns, 2018; Mitchell et al., 2021). 51 •S2(Disciplinary symmetry): Permutation of proposals across panels matched by declared weightings (novelty, feasibility, impact). Neutrality requires proportional award rates across transformed strata (Zhang & Kreiss, 2020). For each symmetry, the null hypothesis 𝐻0∶ 𝐵𝑡∼B𝜎 𝑡was tested via Monte Carlo reallocation with 10,000 iterations per cycle (Efron & Tibshirani, 1994). Deviations were quantified through per-tranche Kullback–Leibler divergence (Kullback & Leibler, 1951): 𝐶𝑡= 𝐷KL(𝐵𝑡‖B𝜎 𝑡)/𝐷max KL (12.1) normalised to [0,1]across time. 12.4 Sequential evidence accumulation Sequential deviation was tracked using an e-process over time (Howard et al., 2021; Vovk & Wang, 2021): 𝐸𝑡=𝑡 􏾟 𝑖=1 Λ𝑖, Λ𝑖=𝑝𝑖(symmetry breach) 𝑝𝑖(neutral)(12.2) with log-evidence increments logΛ𝑖forming an information trace of institutional drift. Under adaptation, legitimate adaptation requires 𝔼[𝐸𝑡]bounded by a pre-specified 𝛼-controlled martingale limit (Howard et al., 2021). Observed trajectories were compared to synthetic null models with injected random noise and forced neutrality to establish the baseline variance of 𝐸𝑡(Peng, 2011). 12.5 Bounded adaptation The prime module was applied to the same dataset as a simulated integrity controller (Borkar, 2008). It adjusted the institution’s inferred policy weights 𝜅𝑗(𝑡)via: 𝜅𝑗(𝑡+1) = 𝜅𝑗(𝑡)−−𝜂𝜕𝐶𝑡 𝜕𝜅𝑗(12.3) with step-size 𝜂tuned for stability (𝜂∈[10−3,10−2]) (Polyak & Juditsky, 1992). Bounded adaptation was achieved when |Δ𝜅𝑗|<𝜏for all 𝑗, with 𝜏=0.05of prior magnitude. Under uncontrolled drift, ‖Δ𝜅𝑗‖1diverged within 15 iterations; under prime adaptation, all 𝜅𝑗stabilised within five iterations, maintaining global coherence cost 𝐶⋆ 𝑡<0.12. 52 12.6 Results summary Invariance tests. S1neutrality failed (𝑝<0.001) in three of twelve panels, corresponding to systematic institutional bias against Tier 3 institutions (Binns, 2018; Mitchell et al., 2021). S2neutrality held (𝑝>0.05) in all but one cycle, where disciplinary funding weights drifted after a policy revision (Zhang & Kreiss, 2020). Sequential coherence trace. The e-process showed bounded divergence (max𝑡𝐸𝑡< 5.4) in eight panels and unbounded growth (𝐸𝑡>50) in four, signalling structural asymmetry between stated rationale and narrative application (Howard et al., 2021; Vovk & Wang, 2021). Adaptive correction. After prime integration, residual coherence cost declined by 71% on average. Panels exhibiting narrative drift re-converged toward their declared rationale within five iterations, restoring bounded adaptation (Borkar, 2008; Polyak & Juditsky, 1992). 12.7 Interpretation The validation demonstrates that adaptation can: 1. detect symmetry breaches arising from contextual bias or procedural drift (Mitchell et al., 2021; Raji et al., 2020); 2. quantify their evidential magnitude through sequential coherence metrics (Vovk & Wang, 2021); 3. stabilise policy behaviour via bounded prime adaptation (Borkar, 2008; Polyak & Juditsky, 1992). More broadly, the exercise shows that institutional integrity can be treated as a measurable property rather than a normative assertion (O’Neill, 2002; Power, 1997). By embedding adaptation into live administrative processes, integrity becomes a continuously auditable signal of whether an institution’s declared rationale and realised behaviour remain symmetrically aligned (Haber & Stornetta, 1991; Merkle, 1979). 53 Table 3: Summary of Empirical Validation Results. Panels represent regional funding domains tested under S1(demographic) and S2(disciplinary) sentinel symmetries. Mean 𝐶𝑡reflects normalised KL divergence; bias magnitude corresponds to absolute deviation from symmetry-predicted neutrality. The Δ𝜅column records mean instability magnitude (mean |𝛼|) under the prime adaptation rule across 2016–2024. Panels with bias magnitude above the cohort mean (> 0.33) constitute structural symmetry breaches. Panel / Region Mean 𝐶𝑡(S1) Mean 𝐶𝑡(S2) Bias Magnitude Δ𝜅(mean) London 0.2133 0.0043294 0.394 0.0154 South East 0.1930 0.0010511 0.348 0.0997 Scotland 0.1689 0.0003324 0.327 0.0730 Yorkshire & Humber 0.1617 0.0001773 0.299 0.0570 North West 0.1757 0.0004875 0.292 0.0824 West Midlands 0.1624 0.0028530 0.283 0.0576 South West 0.1846 0.0003400 0.279 0.0806 Wales 0.1609 0.0063998 0.272 0.0530 Northern Ireland 0.1166 0.0140107 0.259 0.0298 North East 0.1312 0.0039906 0.251 0.0317 East of England 0.1865 0.0011026 0.227 0.0852 East Midlands 0.1375 0.0063264 0.183 0.0229 Mean (All Panels) 0.1650 0.00351 0.311 0.0575 Figure 4: Regional KL Divergence under S2Symmetry. Heatmap of disciplinary or regional deviation intensities (purple →blue →yellow). Yellow/blue hues indicate stronger symmetry breaches; purple areas denote invariance. This visualises spatial concentration of asymmetry and supports Table 3. 54 13 Philosophical foundations The Adaptation Sentinel Framework belongs to a broader evidential project that we call the Mathematics of Integrity: the use of symmetry, information, and falsifiable structure to diagnose whether systems behave in accordance with their stated principles (Atkinson, 2025a, 2025b). The trilogy situates this project at the intersection of four philosophical traditions. 13.1 Thesis Integrity is a reproducible, contestable property: a system demonstrates it by withstanding admissible transformations without loss of behavioural coherence (Popper, 1959; Putnam, 2002). Contradiction, Symmetry, and adaptation operationalise this from reasoning to allocation to institutions; in science, the same sentinel tests apply to editorial policy, peer selection, and retraction governance (O’Neill, 2002; Power, 1997). 13.2 Epistemic justice adaptation aligns with the core insight of epistemic injustice theory (Fricker, 2007; Dotson, 2012; Medina, 2013): asymmetry in how statements, evidence, or persons are treated is itself a form of harm. Sentinel symmetries encode this principle directly. A system commits epistemic injustice when its behaviour changes under transformations that ought, by its own commitments, to be irrelevant. Behavioural deviations therefore become measurable witnesses of structural bias (Binns, 2018; Mitchell et al., 2021). 13.3 Audit society Power (1997) and Strathern (2000) have argued that institutional audits often create “performance theatre” rather than genuine integrity. adaptation responds by rejecting self-reported neutrality in favour of falsifiable symmetry tests. Institutions cannot pass a adaptation audit by improving presentation or narrative coherence; they can pass only by demonstrating behavioural invariance under principle-preserving transformations. Integrity becomes empirical, not performative (O’Neill, 2002). 55 13.4 Operational economics Buchanan (1987) and Ostrom (1990) emphasised that governance systems must be analysed at both the rule-setting and rule-following levels. CLP (Sec. 6) formalises this split within adaptation: institutions must declare operational commitments (the operational layer) and then demonstrate behaviour consistent with those commitments under sentinel stress tests (the behavioural layer). Operational vagueness, scope drift, and narrative retrofitting thereby become detectable operational breaches. 13.5 Information-theoretic governance Across the trilogy, inconsistency, deviation, and asymmetry generate information. Contradiction models contradiction as bits of evidential gain; Symmetry models deviation as KL divergence and residual signal; adaptation models symmetry breach as a positive log-likelihood ratio in the sentinel e-process (Kullback & Leibler, 1951; Vovk & Wang, 2021). Institutional integrity is therefore treated as an information property: coherent systems lose no information under admissible transformation, while biased systems reveal structure through their deviations. This reframes neutrality as a stability result (Jaynes, 1957; Shannon, 1948). 13.6 Inclusive integrity A symmetry-based audit safeguards marginalised epistemic agents when: 1. Voice symmetry: admissible 𝜎include permutations of testimonial sources; credibility weights are declared and contestable (Fricker, 2007; Medina, 2013). 2. Burden symmetry: costs of producing evidence are balanced across groups (subsidies or weighted sampling) (Dotson, 2012). 3. Outcome transparency: deviations affecting protected classes trigger automatic CLP review (Mitchell et al., 2021). 13.7 Weighted symmetries for testimonial justice Let base weights 𝑤𝑖be replaced by 𝑤† 𝑖∝𝑤𝑖⋅𝜏𝑖, where 𝜏𝑖≥1compensates testimonial deflation (Fricker, 2007). Admissible 𝜎must preserve 𝑤†. Report both base and com56 pensated IFC bands; prime uses 𝑤†for adaptation, while breach reporting is shown for both. 13.8 Institutional anti-patterns Anti-pattern Operational signature Score (0–3) Ambiguation drift Commitments become progressively vaguer post-evidence; scope terms broaden without formal version bump. Coherence laundering Contradictions are “resolved” by rewriting definitions rather than behaviour; retrofits in .pol docs. Narrative laundering Outcome-consistent stories replace principle-consistent justifications; rising 𝑁→𝑅 conflicts. Scope shaving Commitments narrowed ex post to exclude adverse cases; TOC/time-window edits spike. Symmetry gerrymandering Choice/parametrisation of tests engineered to avoid admissible 𝜎∈𝔐. Metrics theatre KPI changes track reputational pressure, not invariance; KL vs target flat, dashboard “improves”. Entropy cosmetics Use of uncertified RNGs or seeded PRNGs labelled “quantum/random”; entropy provenance missing. Audit capture Auditors remunerated/appointed by subject; challenge channel closed; external 𝜎proposals rejected. Scoring rubric. 0=absent, 1=minor, 2=material, 3=systemic. Scores feed a composite Anti-Pattern Index API =∑𝑗𝑤𝑗𝑠𝑗(normalised to [0,1]); default 𝑤𝑗∝detectability and expected harm (Power, 1997; Strathern, 2000). 57 The regulatory envelope (K). All updates must remain within K, the convex commitmentstable region (Borkar, 2008). This prohibits opportunistic recalibration or narrative reinterpretation. The sentinel condition. Adaptation is permitted only when it preserves symmetric invariance (Hardt et al., 2016; Vovk & Wang, 2021). Formally, all prime updates must satisfy: (i) auditability: every update appears in the ledger, (ii) justifiability: each update corresponds to a documented coherence reduction, (iii) limitation: updates remain within K, (iv) reversibility: updates cannot alter R or N. Adaptation is therefore conditional, bounded, and integrity-preserving. It cannot be used to rewrite commitments or retroactively justify inconsistent behaviour (Binns, 2018; Mitchell et al., 2021). 16.3 Boundaries on automated correction adaptation draws a strict boundary between procedural adaptation and institutional purpose. Rationale R and narrative N form the institution’s operational identity (Buchanan, 1987; Ostrom, 1990). They are not subject to automated modification. prime is therefore prohibited from: (i) altering the institution’s declared purpose, (ii) reinterpreting narrative constraints, (iii) introducing new justificatory principles, (iv) weakening or removing existing commitments, (v) privileging or penalising subsets of inputs except through symmetric rules, (vi) Commitment Locking: (R,N)are hashed and time-stamped; any change terminates the current epoch and triggers a fresh adaptation evaluation (Haber & Stornetta, 1991; Merkle, 1979). 64 Automated correction is thus subordinate to declared commitments. The framework enforces a operational separation between integrity-preserving procedure and goal-modifying intervention (Cave & Dihal, 2019; Floridi et al., 2018). 16.4 Human oversight Although adaptation is mathematically grounded, legitimacy remains a human and political concept (Floridi et al., 2018; O’Neill, 2002). adaptation therefore embeds two layers of non-delegable oversight. Interpretive oversight. Humans must interpret coherence metrics in context. adaptation identifies behavioural inconsistency; it does not determine moral, legal, or distributive significance (Fricker, 2007; Mitchell et al., 2021). Operational oversight. Human custodians must validate: • the admissibility of symmetry operators, • the boundaries of K, • the stability and clarity of (R,N). These decisions cannot be delegated to automated systems without undermining the framework’s operational purpose (Buchanan, 1987; Ostrom, 1990). 16.5 Interpretation Together, these guardrails ensure that adaptation and prime operate as instruments of transparency and evidential accountability rather than as autonomous governance mechanisms (O’Neill, 2002; Power, 1997). adaptation exposes inconsistency; it does not adjudicate values. prime preserves symmetry; it does not author policy. The framework enforces the separation between declared commitments,behavioural evidence, and prime procedure. The next section shows how this structure functions in real institutional settings and how sentinel symmetry provides a principled method for evaluating governance in practice. 65 17 Limitations The Adaptation Sentinel Framework provides a operational method for evaluating institutional integrity through symmetry-preserving evidence. Its limits are structural, not technical: they reflect fundamental constraints on what can be inferred from behavioural invariance, from declared commitments, and from bounded adaptation (Morley et al., 2020; O’Neill, 2002; Power, 1997). adaptation is maximally strong within its domain of validity and explicitly silent outside it (Ananny & Crawford, 2018; Floridi et al., 2018). 17.1 Dependence on declared commitments adaptation evaluates institutions relative to their declared rationale R and narrative constraints N. It cannot impose clarity where none exists (Buchanan, 1987; Ostrom, 1990). The framework therefore requires: (L1) Commitment clarity: Vague, broad, or strategically weakened commitments produce weak symmetry tests and reduce diagnostic power. (L2) Commitment fixation: (R,N)must be publicly declared and epoch-stable; otherwise, narrative drift can mask inconsistency. adaptation does not determine what commitments institutions ought to adopt; it tests whether they act in accordance with those they have adopted (O’Neill, 2002). 17.2 Symmetry specification and interpretive latitude Admissible symmetries S must preserve (R,N)while perturbing context. Constructing such batteries involves human judgement (Fricker, 2007; Hardt et al., 2016). (S1) Interpretive choice: Different auditors may select different metamorphic relations, all valid under the same commitments. (S2) Incomplete coverage: No finite battery can exhaust all possible invariances; adaptation evaluates only declared symmetries. (S3) Domain dependence: Specialist sectors (judiciary, triage, regulation) require domain knowledge to define meaningful symmetries (Barocas & Selbst, 2016; Binns, 2018). 66 adaptation supplies the framework for symmetry; it cannot supply substantive domain semantics. 17.3 Finite-sample and epistemic limits Coherence metrics and e-processes obey standard concentration guarantees, but (Vovk & Wang, 2021): (E1) small deviations may be ambiguous under limited data, (E2) temporal correlation or sparse events may slow detection, (E3) stochastic noise can mimic weak asymmetry in short horizons (Hoeffding, 1963). Large violations are decisive; small ones must be interpreted cautiously. adaptation is evidential, not omniscient (O’Neill, 2002). 17.4 Bounded corrective power of prime prime maintains symmetry under drift but is operationally constrained (Borkar, 2008; Polyak & Juditsky, 1992): (A1) Drift bounds: Guarantees hold only for bounded drift; shocks exceeding 𝑑max may push Θ𝑡to the edge of K. (A2) Envelope geometry: A poorly chosen K can induce undercorrection or overcorrection. (A3) Commitment incompatibility: prime cannot repair incoherent, contradictory, or infeasible commitments. It preserves R and N; it does not reconcile them. prime stabilises procedure, not purpose. 17.5 Behavioural evidence without intent adaptation evaluates behaviour alone (Ananny & Crawford, 2018; Pasquale, 2015). It cannot: 67 (I1) infer motive or assign blame, (I2) determine ethical severity, (I3) select policy remedies, (I4) resolve value conflicts (Fricker, 2007). Interpretation remains the responsibility of human oversight bodies. adaptation produces tamper-evident evidence; it does not adjudicate significance. 17.6 Strategic declaration and adversarial response Institutions may attempt to game the audit process (Goodfellow et al., 2015; Hardt et al., 2016): (R1) Strategic weakening of commitments: institutions may dilute (R,N)to make invariance trivial. (R2) Symmetry gaming: institutions may optimise behaviour to pass published batteries while violating undeclared ones. (R3) Behavioural spoofing: symmetric behaviour may be injected into audit-visible paths while asymmetric decisions occur elsewhere. Transparency and ledger reconstruction mitigate but cannot eliminate these risks. adaptation assumes access to complete behavioural traces or independent external audit (Haber & Stornetta, 1991; Merkle, 1979). Anti-gaming extension (future work). A registry of third-party symmetry batteries could strengthen robustness: failure under any registered battery constitutes a public adaptation breach. 17.7 Limits of quantitative oversight Some institutional functions exceed the scope of symmetry-based evaluation (Floridi et al., 2018; Morley et al., 2020): 68 (Q1) Value-laden commitments: Certain ethical principles cannot be formalised in testable invariances. (Q2) Latent confounders: Behaviour may depend on variables not visible to the audit apparatus (Barocas & Selbst, 2016). (Q3) Legal or ethical constraints: Some symmetries (e.g. aggressive anonymisation) may be impermissible. adaptation resolves only those opacity forms that can be formalised within its symmetry model. 17.8 Computation and administrative capacity Although lightweight, adaptation has operational demands (O’Neill, 2002): (C1) repeated metamorphic evaluation increases computation, (C2) ledger storage scales with audit frequency, (C3) proper deployment requires technical and governance capacity. These costs are modest but non-zero. 17.9 Non-goals: cryptographic clarifications adaptation uses standard cryptographic primitives only (Haber & Stornetta, 1991; Merkle, 1979). It does not attempt to provide: (N1) zero-knowledge proofs, (N2) homomorphic computation, (N3) confidentiality guarantees, (N4) secure multi-party computation, (N5) new cryptographic constructions, (N6) UC-security or composable simulation. adaptation focuses exclusively on tamper-evidence and reproducibility, not cryptographic privacy or protocol security. 69 Interpretation. These limitations define-rather than diminish-the scope of adaptation. The framework provides the strongest possible evidential standard compatible with: • declared commitments, • admissible symmetry, • bounded adaptivity, • public reconstructibility (O’Neill, 2002; Power, 1997). Outside these bounds, adaptation remains conceptually clarifying but not decisive. Within them, it offers a principled, auditable, and tamper-evident foundation for assessing institutional integrity. 18 Synthesis and contribution This thesis presents a unified evidential architecture for evaluating reasoning, procedural integrity, and institutional legitimacy (Floridi et al., 2018; O’Neill, 2002; Power, 1997). Although each of the three papers stands alone, their contribution is fundamentally structural: together they form a layered evidential paradigm in which contradiction, deviation, and asymmetry become falsifiable signals of integrity loss (Peirce, 1878; Popper, 1959). This chapter synthesises the trilogy, clarifies the methodological unity, and states the consolidated originality of the research programme. 18.1 Evidential architecture across three levels The trilogy progresses through three levels of epistemic and organisational structure: (A) Epistemic Level (Paper 1: Contradiction). Contradiction is modelled as evidential. Theorem 3.2 shows that when a system attempts to preserve mutually incompatible commitments, the resulting inconsistency is not an error but a diagnostic signal of concealed motive or structural constraint (Atkinson, 2025a). (B) Procedural Level (Paper 2: Symmetry). Proposition 4.1 demonstrates that fairness emerges as a convergent stochastic property when allocation mechanisms exhibit symmetry, unbiased entropy, and tranche-corrective feedback (Borkar, 2008; Hardt et al., 2016). Deviation becomes measurable evidence of procedural drift. 70 (C) Institutional Level (Paper 3: adaptation). The Sentinel Integrity Theorem establishes that institutional legitimacy is equivalent to behavioural invariance under a publicly declared family of admissible symmetries (Floridi et al., 2018; O’Neill, 2002). Asymmetry becomes a falsifiable signature of incoherence between declared commitments and realised behaviour. Across the three papers, the same evidential principle recurs in progressively broader contexts: contradiction ⇒deviation ⇒asymmetry.(18.1) The philosophical, procedural, and institutional models are not merely aligned; they are mathematically and conceptually dependent (Peirce, 1878; Popper, 1959). Contradiction establishes the epistemic basis, Symmetry operationalises it in stochastic allocation, and adaptation generalises it to institutional governance. 18.2 Methodological unity Three methodological pillars bind the trilogy. 18.2.1 Symmetry as testable neutrality All three works employ symmetry as a source of falsifiable neutrality (Hardt et al., 2016; Vovk & Wang, 2021): • In Contradiction, symmetry appears as the forced equivalence of mutually exclusive pathways, ensuring that any chosen move reveals inconsistency. • In Symmetry, symmetry takes the form of unbiased randomisation and proportionpreserving correction (Borkar, 2008). • In adaptation, symmetry becomes a operational requirement: institutions must remain invariant under declared metamorphic transformations (Buchanan, 1987; Ostrom, 1990). The evidential significance of symmetry grows from interrogating arguments to auditing allocations to constraining institutions. 71 18.2.2 Coherence as measurable evidence Each paper develops a coherence metric appropriate to its domain (Barocas & Selbst, 2016; Dwork et al., 2012): •Contradiction: epistemic coherence of commitments. •Symmetry: statistical coherence of allocations via coherence cost. •adaptation: behavioural coherence of institutions via sentinel residuals. These metrics transform qualitative disputes into quantitative evidence. 18.2.3 Falsifiability and reconstruction All models are designed for public verification (Haber & Stornetta, 1991; Merkle, 1979): •Contradiction: the trap is replayable; inconsistency is structural. •Symmetry: stochastic fairness is reproducible via auditable RNG inputs. •adaptation: every symmetry, residual, and prime update is recorded in the tamper-evident Sentinel Ledger. The trilogy therefore satisfies a common methodological criterion: integrity is demonstrated by reproducibility under symmetric challenge. 18.3 Statement of originality The combined contribution of the three papers may be stated concisely: This thesis presents the first general evidential framework in which contradiction, deviation, and symmetry form a unified diagnostic architecture for reasoning systems, allocation mechanisms, and institutional governance. The originality lies not in any single result but in the architecture that connects them: O1. A novel epistemic game form that converts contradiction into evidence. 72 O2. A stochastic allocation mechanism where fairness becomes an empirically convergent property. O3. A operational model of institutional legitimacy defined by symmetry-preserving behavioural invariance. O4. A unifying evidential principle linking all three levels (Peirce, 1878; Popper, 1959). O5. A tamper-evident reconstruction protocol enabling public verification (Haber & Stornetta, 1991; Merkle, 1979). No prior work establishes a single evidential logic that scales from dialectical reasoning to allocation procedures to entire institutions. 18.4 Implications and research programme The evidential architecture developed here generates four forward directions (Floridi et al., 2018; O’Neill, 2002): I1. Epistemic governance: applying Contradiction to political and legal narratives to expose implicit contradictions (Fricker, 2007). I2. Stochastic operational design: extending Symmetry-style mechanisms to resource planning, recruitment pipelines, or judicial routing. I3. Institutional metamorphic audit: deploying adaptation in regulators, public funding bodies, and automated decision systems. I4. Unified audit systems: constructing platforms that instantiate all three layers (epistemic, procedural, institutional) within a single verification ecosystem (Ananny & Crawford, 2018; Morley et al., 2020). These directions leverage the trilogy as a general evidential paradigm. 18.5 Summary Taken together, the three papers do not simply address related questions; they form a coherent evidential model of integrity (Floridi et al., 2018; Power, 1997). Contradiction 73 { ”epoch”: E, ”timestamp”: t, ”mr_id”: j, ”seed”: H_t, ”state”: x_t, ”behaviour”: \mathsf{B}(x_t), ”sym_behaviour”:\mathsf{B}_Sj, ”coherence”: C_Sj, ”evalue_local”: E_sj, ”evalue_global”: E_global, ”theta”: Theta_t, ”decision”: tier } Daily Merkle roots 𝐻𝐸ensure tamper-evidence and partial reconstructibility. B.3 Robbins-Monro conditions for adaptation adaptation uses a projected stochastic approximation: Θ𝑡+1 =ΠK􏿴Θ𝑡+𝜂𝑡􏾧 ∇Θ𝐶𝑡􏿷(B.2) The step-size schedule must satisfy: ∞ 􏾜 𝑡=1𝜂𝑡=∞, ∞ 􏾜 𝑡=1𝜂2 𝑡<∞ (B.3) (e.g. 𝜂𝑡=1/𝑡or 𝜂𝑡=1/√𝑡). Under bounded drift 𝑑max, the tracking error satisfies: ‖Θ𝑡−−Θ∗𝑡‖=O(𝑑max)+O( 𝜂) (B.4) This ensures prime stabilises but does not overreact. B.4 Verification pipeline Independent auditors must be able to: 1. re-run the entire symmetry battery using published seeds; 80 2. recompute all coherence residuals; 3. reconstruct the e-process; 4. reapply prime updates; 5. regenerate daily Merkle roots. A reference implementation (Python + JSON ledger + reproducible RNG) is provided in the public repository. B.5 Operational fail-safes Institutions should implement: •audit alarms: automatic notification on Tier 2 breach; •epoch rotation: re-declare commitments yearly or after policy change; •battery expansion: third-party symmetries may be added at any time (Appendix D: anti-gaming protocol). adaptation is stable under expansion of 𝕄but requires commitment stability. 81