Applications

Moral circuit breakers

Build stop, slow, and escalate controls the same way safety-critical systems build emergency stops: explicit authority, instrumented thresholds, and auditable restart rules.

Trigger conditions

  • Decision error rates exceed agreed risk thresholds.
  • Users report harmful outcomes with no clear recourse path.
  • On-call responders cannot explain system behavior with confidence.

Role assignment

  • Operator can activate a slow mode immediately.
  • Incident lead can pause the workflow pending review.
  • Executive owner signs restart decisions and publishes rationale.

Interface controls

  • Single-click pause and traffic throttle controls.
  • Escalation routing to named human reviewers by risk tier.
  • Public decision state visible in the incident and repair log.

Fail-safe behavior

  • High-risk actions default to deny when telemetry confidence degrades.
  • Queue routing diverts cases to human adjudication while paused.
  • Rollback packet captures evidence and opens a remediation timer.