Pre-Governance in Production: A Single-Operator Case Study of Constraint-First Governance at the Deployment Decision Surface
Abstract
v1.1 (2026-08-22) withdraws this study's expiry findings. The status recorded as EXPIRED in the governance trace denotes a consumed approval, not an unadjudicated timeout: it is written when an escalation is approved, to spend a one-time approval. The timeout path writes a different status and there are no such records in the deployment. Withdrawn accordingly: the "60% expiring unadjudicated" and "42% expiry rate" figures, the load-shedding-by-silence reading of §5.4, the citation attached to it, and the claim to have observed an unowned non-decision cost. The check-side analysis is unaffected — 2,130 pre-action checks, 24 constraint activations, zero overrides — as is the saturation result, which is an arrival-rate finding (198 escalations in ~5 weeks falling to 2.1/week after codification) and never depended on outcome status. Cites dataset v2 (10.5281/zenodo.22051720).Recent work on runtime governance for AI agents has converged on a shared thesis: constraining an agent's decision surface before action is structurally superior to auditing behaviour afterwards (Bandara, Gore, Gunaratna, et al., 2026; Kaptein, Khan, & Podstavnychy, 2026; Lavi, 2026; Uchibeke, 2026). This academic literature is formal, architectural, or testbed-based; it contains no published, longitudinal, single-operator production study. This paper contributes one.From September 2025, a single human operator built and operated nine repositories (eight with production surface area) comprising 802 API endpoints and 319 database models using AI coding agents, governed by a pre-action authorization gate at the deployment decision surface. Check-level instrumentation ran 22 March–24 June 2026 and recorded 2,130 pre-action authorization checks against 44 active constraints, producing 24 constraint activations (22 pre-action, 2 post-action) and zero uses of the formal override mechanism. A separately logged escalation channel (from 15 February — 224 escalations over its wider window, 26 within the check window) shows a natural before/after: in the pre-gate period, approval-first governance saturated (198 escalations in ~5 weeks, 109 of them deploy approvals); after constraint codification, that same push-approval demand shifted to deterministic checks (2,090 of 2,121 auto-allowed), deploy escalations fell to 17, and adjudication demand fell ~90% coincident with codification while action volume rose — consistent with the governance-coordination-cost thesis, though causal attribution is not possible at N = 1 where the regime and the operator's behaviour changed together. v1.1 withdraws this study's expiry findings: the status recorded as EXPIRED denotes a consumed approval, not an unadjudicated timeout (see the Correction). Two further findings: (i) enforcement strength is a property of interlock placement, not verdict — the deployment gate (a client-side hook, no server-side protection) bound compliant clients only, and a tool-call surface with no interlock detected but did not prevent an agent publishing to an external channel; (ii) the noisiest constraint was tolerated unamended for the full window while amendment machinery was exercised elsewhere, consistent with attention as the binding resource. We state the observability boundary and single-operator limits explicitly, and publish the measurement protocol for replication. Data availability. The sanitized, reconciled event trace underlying this study is deposited separately: https://doi.org/10.5281/zenodo.21200204 (2,150 events, 224 escalations, 51 constraints).
// Source
Authors: Roshan Ghadamian
Institutions: California Institute for Regenerative Medicine, Regenerative Medicine Institute