Closed-Loop Control
Observables feed back into mandatory revision — binds stay committed while consequences update policy, delegation, and supersession
Every consequential commit declares what signal it watches, who monitors it, and what actuators fire when assumptions fail — feedback closes the loop through recorded revision, not silent rewrite or politics.
Closed-loop control applies cybernetic feedback to committed decisions and platform binds: the organisation acts on a hypothesis at bind, instruments the world for the observables that hypothesis requires, and updates through declared actuators — falsification triggers, contest resolution, supersession, delegation policy revision, escalation threshold changes — when evidence diverges. The original bind stays visible; correction travels forward as L0 facts.
Introduction in decision terms: Decision Principles and the Record — assumption tables with monitors and triggers. At platform scale: One Authority Per Invariant — At Scale — platform domains instrument error rates, contest outcomes, drift, and calibration decay, then act.
The pattern
At bind, declare the loop:
The loop is closed when actuator firing is mandatory and recorded, not optional negotiation. Debate closed at bind (Decision Making Principle 7); observation continues; revision routes through mechanism.
In software systems
Metric alerts wired to ticket creation and spend gates. Model drift monitoring that triggers delegation review. ADR assumption tables with automated checks. Override and contest metrics feeding threshold recalibration. Event-sourced supersession chains when triggers fire — not UPDATE policy SET ….
What good looks like: the system can answer what observation would change our mind and what happens when it crosses — without a meeting.
In human organisations
Quarterly assumption reviews with pre-declared triggers in the (A)DR. Strategy commits paired with market observables and mandatory review dates. Post-bind contestability as formal feedback channel. Platform/compliance domains with published SLAs and signal-driven policy revision when error rates or contest overturn rates shift.
What good looks like: revision depersonalises — the trigger fired, not you attacked me.
In socio-technical systems
Hybrid AI+human binds close the loop: automated commits within recorded delegation policy; human contest and override as sensors; calibration studies and threshold L0 updates as actuators. Centralised cross-cutting authority stays learnable only when consequences update bind policy — not when the platform emits L0 forever without feedback.
Goodhart, Campbell, and second-order risk
Closing the loop creates control pressure on whatever you declared as sensor and comparator. Goodhart’s Law and Campbell’s Law predict the same mechanism: once a measure is wired to mandatory actuators and incentives, it stops behaving like a reliable measure of the assumption. Metric substitution is the dark pattern form — the dashboard improves while the aim rots.
That does not argue for open-loop instead. Open-loop confidence until catastrophe is worse at the first order. The risk is false legitimacy: a green comparator on a gamed proxy reads as the record proves we were right — confident deck with wiring diagrams.
Mitigations — meta-loop control:
- Label observables as proxies with honest tier and known distortion risk
- Use multiple independent signals — outcome-linked, not activity-linked only (MOE vs MOP discipline)
- Meta-sensors: contest overturn rate, override rate, incidents despite green metric, manual recency sampling
- Actuators that can supersede the metric definition, not only the decision
- Never reward “trigger did not fire” as performance success
A2 — working stance T12: No formula guarantees non-gameability under incentive pressure. Closed-loop plus meta-loop is humility with machinery, not a magic wand.
Why this solves the anti-patterns
Open-loop confidence until catastrophe
Missing feedback structure at bind — sensors and actuators wired here replace open-loop omission.
Decisions as one-way streets
Forward-only commits without designed return path. Closed-loop control is the return path — triggers, contest, supersession.
Commitment-as-immunity and unprincipled bind epilogue
Feedback externalised in the record depersonalises late correction; without the loop, repair routes through identity and politics.
Related patterns
- Decision Making Principle 4 — hypothesis schema at bind
- Experiment architecture — pre-committed design, separate observation streams
- Refutation propagation — dependents receive correction events
Corpus stance
Adopt — same architecture for software platforms, organisational strategy, and (A)DR discipline: closed-loop control, not open-loop confidence until catastrophe.