Dark Decisions

The Orchestrator Framework

The Eight Gates

A gate is not a rule you remember. It is a check the system cannot skip, which is the only kind that survives a busy week.


Every team governing an AI product has rules. Most of those rules live in someone's head, or in a document nobody opens, which means they hold exactly as long as the person holding them is paying attention.

The eight gates are the same intentions rebuilt as mechanism. Four of them act at a point in the flow, catching a specific thing as it passes. Four govern everything and are always on. Together they are the difference between a system you hope is behaving and one you can show is behaving.

Audit a product against them and you will usually find two or three missing. The missing ones are rarely the ones you would have guessed.

The Eight Gates, split into two groups. Four in-line gates act at a point in the flow: Input Quality, Retrieval Verification, Verification Engine, and Confidence Signal System. Four system-wide gates govern everything and are always on: Permission Classification, Feedback Loop and Logging, Standing Rules Engine, and Escalation Pathway.
Figure 3. Four gates act at a point in the flow. Four are always on.

The four in-line gates

These sit in the path of a single request. Each one can stop it.

Gate one: what is allowed to enter?

The input quality gate decides what the system is willing to work with before any processing happens. It sets a floor: a minimum format, a minimum completeness, a minimum clarity. Anything below the floor is refused rather than attempted.

When it is missing, the system answers questions it should have declined. Nothing looks broken, because a confident answer to a bad question is indistinguishable from a confident answer to a good one.

Gate two: is the information it drew on actually right?

Retrieval verification checks the material the system pulled in before that material shapes an answer. Named sources, a relevance threshold, and an explicit rule for what happens when the search comes back empty.

When it is missing, the most common failure is not a fabrication. It is an answer built correctly on a document that was superseded two years ago.

Gate three: was the output checked before anyone saw it?

The verification engine tests what was produced against criteria defined in advance. The order matters more than it sounds: criteria written after you see the output are not criteria, they are opinions about that output.

When it is missing, verification quietly relocates to the reader, who is the person least equipped to do it and least aware they have been asked.

Gate four: does the reader know how much to trust this?

The confidence signal labels every output as verified, inferred, or flagged, and the label travels with it. The essential property is that nobody downstream can suppress it, including for a demo.

When it is missing, everything arrives wearing the same face. A verified answer and a plausible guess look identical, so the reader is forced to treat them identically, and they will choose to trust both.

The four system-wide gates

These are not in the path of any single request. They are always on, and they are what makes the system governable rather than merely functional.

Gate five: which actions may it never take alone?

Permission classification sorts every action into contained, boundary-crossing, or never autonomous, and names who approves the ones that need approval. The list is written before the system is capable enough to make the question uncomfortable.

When it is missing, the boundary does not hold a position. It moves, one reasonable exception at a time, and no single step ever looks like the one that crossed a line.

Gate six: how do you find out what is going wrong?

The feedback loop logs corrections in a structured form, so that patterns become visible over time rather than staying as a series of unrelated annoyances. What was produced, what it was changed to, where in the pipeline, and when.

When it is missing, the same fault is fixed repeatedly by different people who each believe it is the first time.

Gate seven: which rules fire without anyone remembering them?

Standing rules run before every task, automatically. This is the gate that distinguishes a governed system from a well-intentioned one, because a rule that depends on being recalled is a rule that works until the week you are busy.

When it is missing, your governance is only as reliable as your worst day, and nobody audits their worst day.

Gate eight: who decides when the system should not?

The escalation pathway routes anything beyond the system's authority to a named human, with the context needed to decide and a window in which to decide it. The recipient is a role, not a person, so the path survives someone leaving.

When it is missing, escalation still happens. It just happens informally, to whoever is nearest, with no record that it occurred.

Which are you missing?

The useful exercise is to take a product you already have in production and walk it against all eight. Most of the value is in the two you cannot answer for.

If you want a second opinion, write to darkdecisions@cerebrium.ca. Tell me what the product does and which gate you are least sure about, and I will tell you what usually breaks first. I read every message.