The Clipped-ReLU DEL Authorization Function
Status: PROPOSED CANON v1.0 (2026-08-11) — governance surface under CONSTITUTION.md
Article VI; this document becomes canon when the owner merges its review PR, and its
per-action-class parameterization remains [Roadmap] until built. Owner decision 11
(clipped-ReLU DEL as canon) is decided by that merge.
Sources: docs/product/SIGNAL_SHOPIFY_MASTER_v4.md §2.6, §3.2;
docs/product/SIGNAL_OVERVIEW_v5.md §2.6; CONSTITUTION.md II.1/III.6; OPERATING_SYSTEM.md
Art. 2.4/4; the shipped demo gate # MIZ OKI 3.5/mizoki_runtime/demo_signal.py
(documented read-only — demo behavior is NOT modified by this document; demo surfaces ship
only via the owner-approved site dispatch).
1. The function
For every action class c:
authority_c = min(cap_c, max(0, DEL_score − threshold_c))
- Flat zero below threshold — deterministic denial. No partial execution, no probabilistic leakage. Agents (however they negotiate) only propose; the deterministic policy service authorizes. A denial routes the proposal to a human with its reasoning path and a smaller alternative — never silently dropped.
- Margin-proportional authority above threshold. A barely-cleared score earns only the smallest reversible version of the action (the ACT-991 canon, §5).
- Saturation at
cap_c. The covenant cap bounds authority regardless of margin. - Adaptive guardrail envelopes are threshold shifts under volatility — the envelope
may move
threshold_cup (more conservative) in turbulent regimes; it never lowers a floor.
2. Threshold ownership — floors are not configurable downward
- The platform sets per-class floor thresholds. Merchants/customers may raise thresholds via covenant; they may never lower them below platform floors (master v4.0 finding N3 — High/safety). Safety is not merchant-configurable downward.
- The platform-wide floor that exists today: DEL ≥ 80.0 at the Decision Control Plane
(CONSTITUTION II.1; OPERATING_SYSTEM 2.4). Domains may raise their bar via
policy.yaml(per-domain 90s exist); none may set it below 80.0 —check_conformance()enforces the alignment. The clipped-ReLU parameterization inherits this: nothreshold_cmay sit below the DCP floor for its domain. - Media-domain bounds that exist today and bind every media action class: the $25,000
autonomous ceiling (above it →
approval-requiredto a named human), MDES bands with a hard operator gate on expansion, andexperiment-requiredfor media claims without incrementality evidence.
3. Mechanical demotion — never discretionary
- Per-class demotion on sustained near-zero margins: an action class whose authority hovers at zero is demoted automatically (master §2.6).
- Covenant proximity auto-drops an L5 class to L3 (master §3.2). Every demotion path is arithmetic against declared constraints; no human judgment is required to demote, only to re-promote.
- Autonomy levels are held per account × action class (L4 on budget while L2 on bids is normal); every level carries a one-tap kill switch, immutable journal, weekly plain-language digest.
4. The shipped gate, documented from source — [Validated] at miniature scale
# MIZ OKI 3.5/mizoki_runtime/demo_signal.py implements this function's shape at demo
scale, deterministically (seed-replayable; same seed → byte-identical run). Documented
values, read from the module on 2026-08-11:
ReLU gate (ReLUGate) — signal admission before planning:
score = max(0, uplift) × confidence × ln(1 + sample_size)
with three floors, each emitting a visible failure reason:
| Floor | Constant | Value |
|---|---|---|
| Uplift | GATE_UPLIFT_FLOOR |
0.05 (5%) |
| Confidence | GATE_CONFIDENCE_FLOOR |
0.70 |
| Sample | GATE_SAMPLE_FLOOR |
n = 15 |
Guardrail battery (GuardrailSet.evaluate) — validation of each planned action, checks
in source order:
budget_swing_cap— budget actions capped at ±20% (BUDGET_SWING_CAP_PCT)bid_swing_cap— bid actions capped at ±30% (BID_SWING_CAP_PCT)confidence_floor— decision confidence ≥ 0.70 (CONFIDENCE_FLOOR)sample_floor— supporting conversions ≥ 15 (SAMPLE_FLOOR)rollback_ready— rollback token minted before execution
Any failed check blocks the action before execution (blocked_by names the rule); each
scenario seeds one deliberate block so the veto is always visible; surviving actions rank
by expected_value × confidence; executions run dry_run with rollback tokens; a pure-veto
run holds ("No move earned execution this run — the desk held"). The margin-proportional
clip and per-class cap_c/threshold_c registry are not in the demo — the demo is the
gate + guardrails miniature, [Validated]; per-class parameterization is [Roadmap].
5. ACT-991 — the canonical example
The governed-decision class this function generalizes, proven end to end on live Cloud Run
(run 2ebf83c1, 24/24 steps — verified result 2026-07-27; the proposal itself is an
illustrative scenario): DEL score 84 against threshold 80 → margin 4 — a
barely-cleared score; the $45k proposal exceeded the $25k media autonomous ceiling →
routed approval-required to a named human; the authorization issued was signed, expiring,
single-use, bound to the exact proposed action (tampering → 422, second redeem → 409);
Stage-3 recommend-only recorded intent without executing. Under the clipped-ReLU reading:
small margin ⇒ smallest reversible authority; ceilings and gates bind regardless of score.
6. Intent-model promotion gates (F8.1) — canonical thresholds
The gates that decide whether an intent model may leave observe-only are canonical and identical everywhere (CONSTITUTION III.6; overview §2.6; capabilities doc Stage 2):
- Brier ≤ 0.20 · AUC ≥ 0.72 · stable lift across ≥ 2 purchase cycles, and promotion happens only via human approval.
- A model below the bar is advisory-only (observe-only) regardless of the merchant's autonomy level — merchant L-level never overrides a model gate.
- Brier degradation > 0.20 after promotion auto-demotes the model to observe-only, demotes the dependent action classes, and opens an incident.
- Live demonstration that the gate holds: the LII offline backtest recorded AUC 0.6884 (honest, leakage-gated) against the 0.72 line — a documented NO-GO; the production scoring path stays observe-only (open-work register item 17).
7. Build state — what exists vs. what this canonizes
| Element | State |
|---|---|
| DCP DEL ≥ 80.0 floor, eligibility states, $25k media ceiling, MDES bands, two-key rule | Deployed & live-verified (OPERATING_SYSTEM Art. 2.4/4; run 2ebf83c1) |
| Demo-scale ReLU gate + 5-guardrail battery | [Validated] (deterministic, test-pinned; AcquisitionShowcaseTestCase fails the build on drift) |
| Promotion gates as constitutional thresholds | Active law (CONSTITUTION III.6); enforcement on the BQML path is the hysteresis/shadow machinery of cells 33–36 |
Per-action-class threshold_c / cap_c registry, margin-proportional clip in the DCP |
[IN BUILD — not started]; lands with P2–P3 covenant work |
| Merchant covenant raise-only threshold mechanism | [IN BUILD — not started]; requires the covenant service (P3) |
| Auto-demotion wiring from Brier telemetry to merchant action classes | [IN BUILD — not started]; today's demotion path is platform-level observe-only reversion |
No claim in this document upgrades any capability's label; the platform ceiling remains built, pre-benchmark.