The multiplicity layer
Family-wise control of false blocks across the whole constraint set, valid under continuous monitoring, without an independence assumption the architecture openly violates.
Why this exists
Certify one constraint and you have a bound. Run a hundred under continuous monitoring and those per-constraint bounds say nothing about how often the system as a whole blocks work it should have let through.
Governance that blocks too much gets switched off. This is Rule 8, it raises the ceiling, not the barrier, made statistical.
Responsible AI · Rule 8 →The construction
Every lane is a test against a declared limit.
E-values compose under arbitrary dependence, and the lanes are dependent by construction; a p-value method would need an independence assumption the system does not have.
Anytime-valid under continuous monitoring and optional stopping, what makes "we watch it constantly" compatible with "the bound still holds".
These quadrants are not the Aggregate Drift regions. Those classify where the decision stream sits; these classify what a burst of simultaneous detector firings means. Different object, different quadrants.
Proceed, log only.
One fires, e-BH confirms, a genuine violation; gate that output.
Several fire, e-BH rejects, the pattern multiplicity alone predicts. Do not block. This is the false-block every naive system commits.
Several fire, e-BH confirms across the window, gate, escalate, and hand off to the Aggregate Drift Service, the layer built for what this state is detecting.
Row three is the product.
The honest boundary
False-discovery control is a statement about the rate of false blocks across the set, not that any individual verdict is correct, and it improves no single lane's detection. It trades a small per-constraint miss-rate increase for a controlled set-level false-block rate: a governance decision your oversight team configures, recorded in the traceability matrix like any other operating point.
Rule 8's enforcement mechanism. The eight rules →