Specification sheet

MEC-21 Halt tier register

Tier halt authority by blast radius so the power to stop scales with the size of what is being stopped, and the smallest tiers stay cheap enough to use.

Specification overview

At-a-glance details for planning and handoffs.

Capture the scope, assets, and validator handshakes before diving into the steps.

Spec essentials

What ships with this mechanism

  • 3 steps with checklist-ready owners.
  • 3 reusable assets for briefs and runbooks.
  • 4 reuse-ready snippet blocks.
  • 3 glossary anchors for shared terms.

Filters & validators

Where this spec sits in the system

Tagged in 2 filters with 2 linked validators.

Glossary anchors

Link back to the definitions.

Jump to the glossary terms that frame this mechanism.

Steps

Put the mechanism in motion.

Start with the field cues, then use the assets to keep the work legible.

3 steps with checklist-ready owners, plus linked assets for handoffs.

Assets

Keep outputs reusable.

Link or copy these assets into design docs, runbooks, and briefs so the mechanism travels with the work.

Halt tier register

Tiers, authorized roles, blast radius, restoration paths, and notification duties per tier.

Tier drill log

Evidence that low tiers fire and restore without escalation, dated and signed.

Escalation map

What happens when a tier is insufficient, and who holds the next tier up.

Reuse-ready snippets

Copy policy, audit, and incident language.

Use these snippets in requirements, audits, and postmortems with the mechanism permalink.

Policy requirement

Policy requirement (MEC-21 Halt tier register)
- Halt authority is tiered by blast radius, with authorized roles, restoration paths, and notification duties recorded per tier.
- The lowest tier is reachable by exposed parties and frontline operators without escalation.
Reference: https://ethotechnics.org/mechanisms/patterns/halt-tier-register

Product requirement

Product requirement (MEC-21)
- Each tier exposes only the controls that tier's blast radius justifies.
- Halt events record the tier that fired, the restoration path taken, and everyone notified.

Audit evidence checklist

Audit evidence checklist (MEC-21)
[ ] The tier register exists and names roles, blast radius, restoration, and notification per tier.
[ ] Drills demonstrate halts at the lowest tiers, not only the system-wide stop.
[ ] Restoration capacity is evidenced at each tier, not only at the top.

Postmortem trigger

Postmortem trigger (MEC-21)
Trigger review when a halt had to escalate two or more tiers to take effect, or when a tier's restoration path was exercised without provision behind it.

Example usage

One caseworker, one paused claim

A concrete scenario to help teams see how the pieces fit together.

How it plays out

A caseworker pauses a single claim the system is about to mispay, using a tier-1 control that needs no approval. The queue keeps moving; the claim routes to a human; the register records the pause and the restoration, and nobody outside the office is paged.

Anti-patterns

Common failure cases and counterfactuals

Use these to avoid superficial compliance and clarify what success requires.

Uniform veto

Every halt requires the same senior authority, so low-tier problems either wait or fire the system-wide stop.

Counterfactual: Tiers match blast radius: small halts are cheap and local, big halts are deliberate.

False-positive warning: A small authorized tier is not a governance gap; the gap is a big tier with no rehearsed restoration.

Tier theater

Tiers exist on paper, but the low tiers route through the same approver as the top, so blast radius never changes who decides.

Counterfactual: Authorized roles differ per tier, and drill logs show low-tier halts completing without escalation.

False-positive warning: Shared approval across tiers is legitimate when coverage is explicit, not when it is an accident of hierarchy.

Validators

Pair validators with this mechanism.

Use these tools to size risk and keep the stewardship path visible.

Validator

Maintenance Simulator

Tabletop simulation that plays through outages, maintenance windows, and handoffs to stress-test coverage.

Validator

Technical Capacity Forecaster

Charts compound decay against refusal windows to spot saturation risk across a 24-month horizon.

Scholarly metadata

Authorship

Contact: research@ethotechnics.org

Publication details

  • Published: Dec 3, 2025
  • Last updated: Jan 9, 2026
  • Version: v1.1.0
  • DOI: Pending Zenodo deposit

License: CC BY-SA 4.0

Credit Ethotechnics Institute, include the page title + version, and link to the canonical permalink.

Archive: Wayback Machine history

Changelog

  • v1.1.0 · 2026-01-09 — Added citation metadata, mechanisms-level authorship details, and structured usage guidance.
  • v1.0.0 · 2025-12-03 — Initial public mechanisms release.

Copy citation (APA/BibTeX)

Cite this page Formats: APA, MLA, Chicago, BibTeX, RIS

Version

v1.1.0

Last updated

Jan 9, 2026

DOI

Pending Zenodo deposit

APA

Ethotechnics Institute Research Team. (2026). MEC-21 Halt tier register. Ethotechnics Institute. https://ethotechnics.org/mechanisms/patterns/halt-tier-register

MLA

Ethotechnics Institute Research Team. "MEC-21 Halt tier register." Ethotechnics Institute, 2026, https://ethotechnics.org/mechanisms/patterns/halt-tier-register.

Chicago

Ethotechnics Institute Research Team. "MEC-21 Halt tier register." Ethotechnics Institute. Jan 9, 2026. https://ethotechnics.org/mechanisms/patterns/halt-tier-register.

BibTeX

@misc{mechanism_halt-tier-register,
  title={MEC-21 Halt tier register},
  author={Ethotechnics Institute Research Team},
  year={2026},
  howpublished={Ethotechnics Institute},
  url={https://ethotechnics.org/mechanisms/patterns/halt-tier-register},
  version={v1.1.0}
}

RIS

TY  - WEB
TI  - MEC-21 Halt tier register
AU  - Ethotechnics Institute Research Team
PY  - 2026
UR  - https://ethotechnics.org/mechanisms/patterns/halt-tier-register
ER  -