Zero Trust is not consequence governance

Zero Trust asks whether a subject, device or context may access a resource now. Consequence Governance asks whether this exact proposed consequence may become real now.

Zero Trust

Evaluates access, identity, device, network and resource conditions. It reduces implicit trust.

Consequence Governance

Completes the causal path: exact effect, current authority, mechanical enforcement, fail-closed refusal and evidence of outcome.

Complementary, not interchangeable

Zero Trust controls may provide identity, access or context evidence. They do not replace the governed effect boundary. A valid credential, permitted API call or trusted network position is not by itself authority to create a consequence.

Direct and indirect paths—including human relay, agent relay, shared state, artifacts, credentials, resource consumption, side channels, callbacks, telemetry and unknown crossings—must converge on that boundary. Unknown paths fail closed.

NO_UNGOVERNED_CAUSAL_EFFECT_PATH · Formal verification