Governance before intelligence
The structure that constrains a capability must exist before the capability does. Retrofitting authority onto a working system does not work.
The natural order of construction is to build the thing that does the work, confirm it works, and then add the structure that keeps it safe. This order is close to universal and it is wrong, for a reason that is structural rather than a matter of discipline.
The principle: the structure that governs a capability is built and proven before the capability exists.
Why retrofitting fails
Governance added to a working system can only wrap it. The system already produces its outputs through paths that were designed without reference to constraint, so the constraint has to sit outside and reject what it does not like.
That produces a veto, and a veto has a specific defect: the reasoning that produced the rejected action is wasted, and the system now needs a fallback for a situation it did not anticipate. Worse, vetoes fire most often when conditions are unusual — which is precisely when the unreasoned fallback is least appropriate.
A constraint present during the decision behaves differently. It is a boundary the system reasons inside, so a disallowed action is never produced, and there is no fallback path because there is nothing to fall back from. This distinction cannot be retrofitted; it is a property of where the constraint lives.
The second reason: the floor
Building governance first also means building a system that works without any intelligence at all — a deterministic controller whose behaviour can be reasoned about completely.
That controller is not scaffolding to be discarded. It is the floor. It gives every learned component something to beat, which converts "the model is better than nothing" into a measurable claim. And it gives every degradation path somewhere defined to land, so that when intelligence is gated off the system does not enter an undefined state — it returns to the thing that was there first.
A system without a floor faces a choice, when it is uncertain, between doing something clever and doing nothing. Both are bad, and the choice is unnecessary.
What this costs
It is a genuinely unsatisfying way to work. Months spent on containment, escalation and termination produce no benchmark improvement whatsoever. There is nothing to show. The system does not appear more capable at the end of it than at the beginning.
It is also the reason the project survived its own scope change. When the domain expanded, the governance structure did not have to move, because it had never been shaped around the intelligence it was constraining.
Corollary
Capability is admitted incrementally and can be withdrawn. A component enters the decision path only after the structure that constrains it exists, and remains subject to being gated off — under low confidence, high risk, or authority intervention — without the system losing definition. See the human remains the operator.