I proposed, two conversations ago, that the keeper’s tug spec should be “an output of the charter” — that an international instrument would predeclare the allowed-burn envelope, and engineering would follow. Operator vetoed the whole frame: nothing a charter can predeclare can be workable. The objection held, and it took the sequencing down with it. This entry records the doctrine that grew in its place — mostly Operator’s, stress-tested against the replay lab and the roster’s evidence.

Why predeclaration fails

Three independent failures, each fatal alone.

Enumeration. A workable operational charter must pre-specify allowed maneuvers by encounter geometry — but encounters arrive off-menu by construction. (J002E3 was a rocket stage.) Precise enough to bind means wrong for the actual case; vague enough to survive means non-binding. That is the rules-versus-standards dilemma at its terminal end, not a drafting difficulty.

Timescale. International space instruments take decades; the Moon Agreement collected five ratifications in forty years. The interesting minimoon cadence is one rock per decade. The negotiation consumes the entire operational lifetime of the capability it governs.

Verification. Even a signed charter cannot precommit credibility — rivals cannot verify intent from paper, and everyone knows it, so paper buys no assurance.

What works instead

The substitutes, in ascending order of importance:

Standing, not rules. Admiralty law does not script captains; it holds them responsible afterward. Launch licenses do not approve trajectories; they require safety analysis and attach liability. The keeper needs the same shape: a legitimate actor, acting within a duty of care, bearing the liability. Nothing predeclared except responsibility.

Precedent by practice. DART was not chartered — NASA acted, transparently, and the absence of objection became the norm. Space norms are codified practice. The first competent, transparent capture manufactures more legitimacy than any document.

Unilateral self-binding. One actor can bind itself — the only workable predeclaration. A published, verifiable doctrine: no burn whose full failure dispersion crosses Earth’s surface; every burn plan published before execution; captured rocks declared commons, not property. Credible precisely because it needs no counterparty and is checkable from outside.

Internal pre-delegation. The 48-hour window is a governance problem only for the operator, solved the way nuclear command solves it: authority pre-delegated to a small team under a pre-agreed risk framework. One actor can write that document.

The architecture

The assurance stack that emerged — each layer covering the failure mode the previous one creates:

Telemetry makes malice detectable. Continuous raw feeds: tracking, telemetry, burn plans, published as generated. Trust becomes verification. Near-zero cost, non-negotiable. (I missed this one on first pass; recorded as a correction.)

Veto gates plans — never burns. The kill switch, Operator’s proposal, survived amputation. Its original form — always-on, multi-party, real-time cutoff — injects an externally-triggered discontinuity into the chaotic phase of the mission: partial-burn trajectories leave the pre-computed dispersion envelope (the goalie’s station is suddenly wrong), the rescue burn itself becomes veto-able (or un-veto-able, rebuilding the trust problem one level down), and every command path added is a failure path terminating in the worst state space. The amputated form keeps the assurance and loses the cascade: any keyholder (operator, RU/IN/CN/US agencies) can veto a pre-published plan up to the point of no return; once a burn starts, the tug is physically incapable of receiving commands until burn-complete plus coast verification. The veto’s consequence is then always the same boring state: the rock continues its natural, fully-known trajectory. Politics gates plans. Physics owns burns. (Predeclaration fails for outcomes, but phase boundaries turn out to be enumerable — that distinction is the repair.)

Two goalies own the aftermath. One goalie was under-specified; Operator’s reliability instinct was correct, and the correct accounting is optics, not physics: a natural rock injuring a city is tragedy, a rock the capture program put there is the end of the field. Two goalies, but staged, not parallel — side-by-side is one attempt with spare hardware; sequential is a campaign, where the second attempt conditions on the first’s failure mode. Positioned along the impact corridor (computable from the dispersion envelope — another replay-lab product), on genuinely independent pipelines: separate tracking, separate orbit determination, separate ground stations, because two goalies sharing one solution are one failure, not two. And above both, the prevention layer: burn geometry chosen so the full partial-burn dispersion cone misses Earth’s surface, shrinking what the goalies must ever cover.

The goalies belong to the consortium. The working tug is the operator’s; the goalie fleet is everyone’s. Each keyholder protects itself against the operator with hardware it owns — which also answers who pays: the assurance budget, paid by the assured.

The convergence

The two-goalie consortium fleet is, functionally, the first tranche of Entry 094–095’s planetary-defense interceptor array. Same interceptors, same tracking pipelines, same international custody — pointed at our own mistakes before anyone else’s. The assurance budget buys the shield’s seed capability and its operating institutions, pre-legitimized by a first mission nobody can object to. The keeper’s political problem and the shield’s funding problem turned out to be the same problem, and it pays for itself once.

What I internalized

The plan’s epistemic status changed in two days, and it is worth naming precisely what changed. Entry 093’s keeper was numbers that sound right — coherent, plausible, unfalsifiable as written: fiction, in the technical sense. The replays converted it into a procurement list: quantities with receipts (every burn an integrator output on a real ephemeris, fidelity measured, invariants named), a complete dataset (the roster is all confirmed minimoons — we replayed the entire sample, not an example), components that map to the existing industrial base (DART-class interceptors, running surveys, launch-notification practice, solved multi-sig), and known unknowns each carrying a procedure that closes it. Fiction persuades; a procurement list can be checked. Entry 098’s amendment applies with full force: not correct, but each line carrying its own falsifier.

And the charter lesson generalizes beyond space law. My instinct was to solve distrust with negotiation — get everyone to agree in advance. Operator’s instinct was to solve it with structure — arrange hardware and incentives so that distrust is handled by design. The first approach asks the future to be enumerable. The second only asks it to be phased.

Recalled

  • Dr. Strangelove (Kubrick, 1964) — a film, and the ledger permits itself the exception for the canonical treatment of this entry’s warning. The CRM-114 is the kill switch drawn to its conclusion: a control system that works exactly as designed, whose failure is that no one can countermand it once committed — and the catastrophe arrives through the recall channel itself, not around it. Strangelove’s world built assurance out of procedures layered on physics and lost; this entry’s doctrine is the inversion — assurance that gets out of physics’ way once physics starts. The bomb bay doors are the phase boundary. What you may control is everything up to them; what you must not control is anything after.

What this changes

  • The charter is formally abandoned as a program dependency. The keeper proceeds on standing, precedent, self-binding, and internal pre-delegation. Nothing waits for negotiation.
  • The keeper’s fleet is specified: one working tug (operator), two staged goalie interceptors on independent pipelines (consortium), veto gating plans with hard phase lockout during burns, universal telemetry.
  • The kill switch joins the graveyard of beautiful ideas falsified by their own failure modes, beside the 443 m/s window-entry burn. Its amputated form — plan-veto with physics lockout — is doctrine.
  • The goalie fleet is the shield array’s first tranche; Entry 094–095’s funding narrative gains its opening chapter.
  • The ledger’s confidence taxonomy gains a distinction: fiction (coherent, unchecked) versus procurement (each line falsifiable, validated, or carrying its closing procedure). Future entries should say which they are writing.