Skip to content

Containment & Isolation

← Back to Mechanisms by Solution Family

Solutions that keep faults, hazards, conflicts, contamination, or overload from spreading by separating regions, flows, or responsibilities.

144 mechanisms across 15 solution archetypes in this solution family. A mechanism inherits the primary family of the archetype it instantiates; family is about the move the solution makes, not the domain where it originated.

Bulkhead Isolation

Partition shared resources or failure domains into bounded compartments so local failure stays contained instead of spreading through coupling.

0 mechanisms · View full solution archetype

No mechanism currently instantiates this archetype as its primary archetype.

Conditional Independence Boundary Mapping

Reduce a complex dependency field to the smallest validated statistical interface that is sufficient for reasoning about a target.

11 mechanisms · View full solution archetype

  • Bayesian Network Markov Blanket Extraction — Reads a target's minimal screening interface straight off a graphical model — its parents, its children, and its children's other parents — so the boundary is derived from structure rather than guessed.
  • Blanket Drift Monitor — Watches a live boundary over time and fires an update rule the moment an outside variable starts leaking target-relevant information the blanket used to screen off.
  • Blanket Variable Quality Audit — Audits an established blanket for governance quality — that it collects no more than the minimal sufficient interface, and that the same interface holds across subgroups.
  • Conditional-Independence Test Suite — Empirically stress-tests a candidate boundary with a battery of conditional-independence tests — dropping variables that add nothing and flagging outside variables the blanket fails to screen.
  • D-Separation Walkthrough — Walks the paths of a dependency graph to decide, by the d-separation rules, which variables a candidate boundary screens off — and which colliders would open a path if conditioned on.
  • Expert Dependency Review — A facilitated session where domain experts define the target and hand-draw the dependency structure — supplying edges, directions, and hidden variables the data alone can't reveal.
  • Feature Ablation and Holdout Validation — Validates a candidate blanket empirically by dropping its variables one at a time and checking, on held-out data, whether the target gets harder to predict — sufficiency and minimality proven out-of-sample rather than by graph structure.
  • Hidden-Variable Sensitivity Analysis — Asks how strong an unobserved variable would have to be to break the blanket's screening-off claim — quantifying the boundary's robustness to the confounders you cannot measure.
  • Intervention or Active-Sensing Probe — Deliberately manipulates a variable, or actively acquires a targeted measurement, to settle a boundary question that passive data leaves ambiguous — buying causal direction and confounder-breaking that observation alone cannot.
  • Minimal Interface Dashboard — A standing operational view that surfaces only the validated blanket variables and wires each to the decision it informs — turning the minimal sufficient interface into the one screen people actually watch and act on.
  • Structure-Learning Screen — Runs an automated structure-learning pass over the whole variable field to propose a dependency graph and a candidate Markov blanket — a fast first draft of the boundary, not a validated one.

Distributed Authority Checks and Balances

Prevent any one authority from becoming final over its own consequential actions by distributing power, information, review, and correction across independently capable and mutually constrained bodies.

6 mechanisms · View full solution archetype

  • Deadlock Breaker with Sunset — Activates a bounded temporary tie-breaker or continuity rule when authorities deadlock, then forces mandatory review, retrospective repair, and automatic expiry back to ordinary governance.
  • Dual-Key or Concurrence Rule — Requires two holders of distinct authority to concur before a defined high-risk action can execute, so no single actor can complete it alone.
  • Independent Appointment, Budget, and Tenure Test — Tests whether a reviewed actor can select, starve, dismiss, or cut off the reviewer meant to check it — the appointment, budget, tenure, and information levers that quietly make oversight dependent.
  • Mutual Oversight Effectiveness Audit — Compares each check's formal mandate against what actually happens — real access, capacity, timeliness, remedy completion, outcomes, and retaliation — to reveal which checks constrain and which only appear to.
  • Power Concentration and Conflict Scan — Scores combinations of powers that let one actor authorize, conceal, review, or remedy its own action, ranking the concentration risks worth breaking up.
  • Reasoned Veto and Override Docket — Records each veto's grounds, evidence, deadline, the response, the override threshold, and the final decision and outcome, so objection and override are legible and bounded.

Entry-Boundary Friction Calibration

Calibrate the cost of crossing a membership boundary so the population inside reflects intended qualification, not unequal ability to pay entry costs.

10 mechanisms · View full solution archetype

  • Administrative Burden Audit — Walks an existing entry process step by step from the applicant's side, itemizing every cost it imposes and flagging which ones do no protective work.
  • Assisted Onboarding Navigation — Pairs each entrant with a guide who walks them through the process end to end, absorbing the cognitive and informational cost of figuring out what to do next.
  • Barrier Impact Statement — Forecasts, before a proposed entry requirement is adopted, whom it will keep out, whether it tracks the real qualification, and whether incumbents escape the same cost.
  • Document Substitution Matrix — A published table that lists, for each fact an applicant must prove, the alternative documents accepted as equivalent evidence — so lacking one specific form is not a dead end.
  • Entry Funnel Abandonment Analysis — Measures where and among whom entrants stall or quit along the crossing path, reading observed step-by-step behavior rather than the process's official design.
  • Exception and Appeal Review — A case-by-case review channel where an applicant the standard process rejected can contest the outcome, so a rigid rule does not permanently exclude a qualified person.
  • Fee Waiver or Subsidy Rule — A published rule that waives or subsidizes the monetary cost of entry for applicants a hardship test identifies, so price alone does not decide who can cross.
  • Provisional or Staged Access — Grants a limited, revocable form of membership up front and expands it as the entrant demonstrates qualification, so full proof is earned inside rather than paid at the gate.
  • Remote or Asynchronous Entry Path — Adds a non-co-located or non-synchronous route through the same entry requirements, so crossing no longer demands being in a particular place at a particular time.
  • Single-Window Intake — Collapses multiple separate offices, forms, and visits into one intake point that gathers what's needed once and routes it internally, so the entrant faces a single door instead of a maze.

Interface Fouling Control

Keep a working interface functional by preventing opportunistic occupants from accumulating faster than detection, shedding, or removal can clear them.

9 mechanisms · View full solution archetype

  • Antifouling Coating or Surface Treatment — A passive surface property — material, chemistry, or texture — that lowers the odds opportunistic occupants can attach and stabilize at the interface.
  • Backflush, Purge, or Wash Cycle — Periodically reverses or pulses flow through the interface to dislodge and flush deposits before they consolidate into a hard-to-remove layer.
  • Chemical or Biological Fouling Treatment — Doses a reactive agent — biocide, dispersant, or acid — to kill, loosen, or dissolve the occupants themselves, within an ecological side-effect budget.
  • Condition-Based Cleaning Trigger — Launches cleaning when a fouling-load signal crosses a functional threshold, so service happens exactly when the interface needs it — not by the calendar.
  • Design for Cleaning Access — Builds reachability into the interface up front — ports, removable panels, service clearances — so removal stays possible over the whole lifecycle.
  • Flow-Shear or Self-Cleaning Geometry — Shapes flow and geometry so shear keeps the interface swept clean, denying opportunistic occupants a place to settle.
  • Sacrificial Liner, Screen, or Filter — Puts a cheap, replaceable surface in front of the real interface so fouling lands where removal is trivial — swap the surrogate, spare the asset.
  • Scheduled Cleaning or Scraping Protocol — Cleans or scrapes the interface on a fixed, forecast-set cadence, trading precision for the predictability of a standing routine.
  • Visual or Sensor Fouling Inspection — Reads the fouling state of the interface — by eye or sensor — and confirms whether a clean actually restored function.

Layered Barrier Defense Architecture

Protect a critical asset by layering independent barriers, monitors, delays, and recovery backstops so loss requires multiple correlated failures rather than one breach.

12 mechanisms · View full solution archetype

  • Backup Restore Drill — Proves the last-resort recovery layer actually works by restoring from it under realistic conditions — turning an assumed backstop into a tested one.
  • Canary or Tripwire Asset — A deliberately planted decoy that only an intruder would touch, so that any interaction with it is a high-confidence sign the outer layers have already been crossed.
  • Common-Mode Failure Probe — Deliberately fails a shared dependency to see how many 'independent' layers drop together — testing the independence the whole defense is betting on.
  • Compensating Control Register — A living ledger of every place a required barrier is missing or weakened, the stand-in control put in its place, and the residual risk knowingly accepted — so gaps are owned, not forgotten.
  • Intrusion or Anomaly Alerting — Watches the protected system's live signals for the signature or the statistical shadow of a breach, and turns a detection into a timed, routed response before loss completes.
  • Layer Health Dashboard — A single at-a-glance view of whether each defensive layer is actually up, degraded, or down right now — so a silently failed barrier is seen before it's needed, not after.
  • Layered Control Matrix — Lays every control against every threat pathway in a grid so open pathways, single points of coverage, and merely-redundant layers become visible at a glance.
  • Multi-Factor Access Challenge — Guards a single access point by demanding several credentials of deliberately different kinds, so defeating one does not open the door.
  • Network Segmentation Policy — Divides a network into isolated zones with only named, controlled crossings, so a breach in one segment cannot spread to the crown jewels.
  • Physical Security Zoning — Arranges physical space into concentric graded zones so reaching the asset means passing successively harder, differently-guarded boundaries under lengthening exposure.
  • Safety Interlock Chain — Wires several independent safety conditions to the hazard's energy source so that if any one is unmet, the system forces itself into a safe state without waiting for a human.
  • Tabletop Breach Walkthrough — Gathers the real role-holders to talk through an escalating breach step by step, surfacing the seams between layers that only appear when the defense is exercised as a whole.

Leakage Path Containment and Recapture

Prevent constrained resources, information, risks, contaminants, funds, or obligations from escaping through unintended paths by making leakage paths visible, bounded, sealed, and recoverable.

12 mechanisms · View full solution archetype

  • Anomaly or Shrinkage Alert — Watches a loss signal against a threshold and fires the instant measured leakage deviates from expected, routing the alarm to whoever owns the path.
  • Canary Token or Tracer Dye — Embeds a distinctive, trackable marker in the protected quantity so that any escape reveals itself — and reveals which path it took and where it surfaced.
  • Controlled Release Valve — Gives a quantity under pressure a single sanctioned, rate-limited outlet — so the excess escapes through a channel you designed and can recover from, instead of finding its own unintended path.
  • Exception Log Review — Periodically re-opens the standing log of granted exceptions and overrides to the containment rules, so bypasses that quietly became permanent leaks are re-decided, re-owned, or revoked.
  • Leakage Budget Dashboard — Tracks cumulative loss against an explicitly allowed residual budget and shows the open repair backlog — turning 'are we leaking too much?' into a running balance with a limit.
  • Leakage Path Walkthrough — Walks the actual boundary of a container end to end, with the people who operate it, to name every path a constrained quantity can escape through — before any of them starts losing.
  • Mass-Balance Audit — Reconciles what entered, what legitimately left, and what remains across a bounded control volume, attributing the unexplained gap to leakage.
  • Post-Seal Displacement Check — After a leak is sealed, verifies that total loss actually fell rather than merely relocating to the next-easiest path.
  • Recapture or Recall Protocol — A standing procedure for retrieving or neutralizing a quantity that has already escaped, by tracing where it went and pulling it back through assigned owners.
  • Red-Team Exfiltration Probe — A sanctioned adversary actively tries to smuggle the constrained quantity past the controls, discovering exploitable leak paths by attacking rather than surveying.
  • Seal-and-Retune Patch — Closes an identified leak path and re-tunes the surrounding controls so the fix holds and residual loss lands within budget, working the repair off a prioritized backlog.
  • Side-Channel Scan — Systematically sweeps for covert, unintended paths through which the quantity bleeds out indirectly — the routes the boundary model never listed.

Migration-Resistant Hazard Control

Reduce the pressure that generates a hazard and measure outcomes across every plausible destination so local blocking cannot pass as genuine risk reduction.

14 mechanisms · View full solution archetype

  • Adaptive Circumvention Red Team — Plays the motivated adversary against a control to find how it will be evaded and which under-defended destination the blocked pressure will be pushed toward.
  • Before–After–Elsewhere Evaluation — Measures the target outcome before and after at the intervention site and — the defining addition — at the places the hazard could have moved to, so a local win cannot pass as reduction until 'elsewhere' clears too.
  • Boundary Expansion Review — Deliberately widens the evaluation boundary until it contains the whole system that generates and receives the hazard, so a control cannot score a win by pushing the hazard just past where anyone is counting.
  • Causal Loop Diagram — Draws the pressure behind a hazard, the feedback loops that regenerate it, and the delays between them, so a control can be aimed at the loop rather than the symptom it displaces.
  • Cross-Boundary Hazard Ledger — A standing double-entry record that follows the hazard across every boundary, so a reduction booked in one place must reconcile against system totals or stand exposed as a mere transfer.
  • Cross-Jurisdiction Incident Review — A recurring convening where separately-accountable jurisdictions pool their incident data, so a hazard that slips across the seam between them gets caught, owned, and made good instead of falling into the gap no one answers for.
  • Fault Tree Analysis — Decomposes a single system-level harm downward through logical gates until the transfer path — and the exact boundary where risk crosses out of the controlled unit — becomes explicit.
  • Hazard Analysis — Enumerates the hazards a control leaves behind — including the ones it displaces — and holds each residual against an explicit tolerance rather than against whatever the current design happens to achieve.
  • Intervention Displacement Stress Test — A pre-deployment probe that grants the control its local success and asks the harder question — where would the blocked pressure go, who would absorb it, and how long until it surfaces — before you commit.
  • Mass Balance — Applies conservation bookkeeping across a declared boundary so a hazard that 'disappears' from one channel must reappear as an outflow somewhere — and the unaccounted gap localises the leak.
  • Migration Sentinel Network — A distributed set of watch-points placed at a hazard's likely destinations, giving early warning when a suppressed hazard reappears somewhere new rather than having genuinely gone away.
  • Pressure-Absorption Redesign Workshop — A facilitated redesign session that, once a control is caught merely rerouting a hazard, reworks the system to give the residual pressure a safe place to go instead of a taller wall to push against.
  • Source-Reduction or Safe-Dissipation Plan — A plan that attacks the pressure generating a hazard at its source — lowering the demand, load, or incentive that drives it — so there is less hazard to migrate at all, held to a stated tolerance for any residual that remains.
  • Whole-System Impact Map — Lays a control's full field of consequences — direct, indirect, delayed, and cross-boundary — on one artifact, so a local win can be netted against the system-wide effect that hides the displaced burden.

Purity-Pollution Boundary Governance

Make clean/contaminating status, transfer paths, containment rules, and restoration paths explicit so purity logic can protect without becoming arbitrary exclusion.

11 mechanisms · View full solution archetype

  • Allergen Segregation Plan — Keeps declared allergens from cross-contacting other products in a shared facility by separating ingredients, equipment, and runs, and holding any residual transfer below a reaction threshold.
  • Aseptic Field Protocol — Establishes a protected sterile field defined by a strict clean/contaminated binary, and governs it with an 'only sterile may touch sterile' contact rule.
  • Chain-of-Custody Log — Maintains an unbroken, timestamped record of every hand and transfer an item passes through, so any later claim about its status can be audited back to origin.
  • Pollution Pricing or Liability Rule — Makes a polluting transfer accountable by attaching a price or liability to it, sized to the harm, so the cost falls on the polluter instead of being externalized downstream.
  • Quarantine Label and Hold — Physically sets suspect or unverified items aside in a bounded holding zone until their status is resolved, with an explicit rule for what it takes to release them back.
  • Red/Green Status Tagging — Makes a decided clean, restricted, or contaminated status visible at a glance through a simple standardized marker anyone can read without expertise or lookup.
  • Ritual Ablution or Cleansing Act — Restores impure or restricted status to clean through a culturally recognized cleansing act whose power rests on legitimacy, not physical change.
  • Stigma Escalation Review — Checks whether a purity response has hardened into identity-marking, scapegoating, or disproportionate harm — and forces it back within bounds.
  • Symbolic Reintegration Ritual — Publicly and ceremonially re-accepts a restored person or object so no residual informal exclusion survives the cleansing.
  • Tainted Data Quarantine — Isolates data of compromised provenance — and everything derived from it — from the trusted corpus until it is cleansed, rejected, or relabeled.
  • Validated Clean-Down Protocol — Restores equipment, space, or material to verified-clean status through a specified procedure tested against an acceptance limit and signed off.

Reachability-Guided Resource Reclamation

Reclaim resources only after proving they are unreachable from every declared live root and protecting in-flight or externally retained dependencies.

10 mechanisms · View full solution archetype

  • Concurrent Collection Barrier — Intercepts reference writes while the collector runs so the mutator can keep working without corrupting the in-progress reachability view.
  • Cycle Detection Pass — Finds groups of resources that keep each other alive by mutual reference yet are collectively unreachable — the cycles a reference count can never free.
  • Dry-Run Reclamation Report — Computes exactly what would be reclaimed and reports it for review without deleting anything, so the delete-list can be approved before it runs.
  • Generational Collection — Partitions resources by age and collects the short-lived young generation often and cheaply, scanning the long-lived old generation only rarely.
  • Lease Expiry Sweep — Grants each resource a time-limited lease that its holder must renew, and reclaims whatever lease lapses — treating renewal as a liveness signal.
  • Reachability Graph Visualization — Renders the reference graph and its retention paths so a human can see what is keeping a resource alive and why it will not be reclaimed.
  • Reference Counting — Tallies the inbound references to each resource and reclaims it the instant the count falls to zero — no global scan required.
  • Tombstone-Then-Delete — Marks a resource logically deleted and keeps the marker through a grace window so in-flight readers and replicas converge, then physically removes it.
  • Tracing Mark-Sweep Cycle — Traces every resource reachable from the declared roots, marks it live, then sweeps away everything the trace never touched.
  • Weak Reference Registry — Registers references that point to a resource without keeping it alive, so the collector may reclaim the target and clear the weak references afterward.

Rupture Containment

Limit damage after a break by containing fracture propagation and stabilizing adjacent structures.

10 mechanisms · View full solution archetype

  • Blast or Fire Containment — A safety mechanism that contains explosive, thermal, chemical, or fire damage within a defined boundary and protects adjacent structures.
  • Bulkhead Isolation — A compartmentalization mechanism that prevents failure, flooding, fire, contamination, or overload in one compartment from spreading to others.
  • Conflict Containment Agreement — A negotiated boundary that prevents a rupture in one relationship, faction, or issue from expanding into broader retaliation, polarization, or institutional breakdown.
  • Crack Arrester — A structural feature that stops or slows fracture propagation by interrupting the path along which a crack can travel.
  • Critical Dependency Disconnect — A controlled disconnection or pause of a dependency path that would otherwise transmit overload, contamination, compromise, or conflict into adjacent systems.
  • Financial Ring Fence — A legal, accounting, or organizational mechanism that separates liabilities, assets, losses, or obligations so one rupture does not destabilize the wider system.
  • Incident Containment Zone — An operational boundary that defines the affected scope, restricts propagation routes, assigns containment owners, and stabilizes adjacent operations during an incident.
  • Quarantine or Firebreak — A boundary mechanism that separates affected from unaffected regions to slow biological, informational, cyber, ecological, or social spread.
  • Service Fault Isolation — A software, infrastructure, or operational mechanism that isolates a failing service, dependency, queue, shard, or region so the fault does not cascade.
  • Trust Stabilization Message — A communication mechanism that acknowledges the rupture, states containment boundaries, reduces rumor-driven propagation, and preserves enough confidence for stabilization.

Sanctuary-Aware Source Control

Do not mistake repeated sink suppression for elimination: find the low-contestation source, close the reach gap, act on source and sinks together, block reseeding, and confirm regeneration stays below replacement.

10 mechanisms · View full solution archetype

  • Below-Replacement Confirmation Test — Confirms the target's reproduction has fallen below replacement — telling durable decline apart from a suppression that will rebound the moment pressure lifts.
  • Containment Barrier — A standing barrier that denies the target passage into protected or vulnerable zones — buying time and shrinking spread without reducing the source itself.
  • Coordinated Access Protocol — A standing agreement that lets one controller act on a source sitting inside another authority's domain, sequencing who may act where so source and sinks can be hit together.
  • Cross-Boundary After-Action Review — A structured retrospective over a campaign that spanned several authorities, deciding what to restore, when to exit, and how to respond if the source rebounds.
  • Protected-Zone Exception Review — A governance review that adjudicates requests to act inside a protected sanctuary — guarding legitimate refuges from wrongful action while denying the source a place to hide behind 'protected' status.
  • Rebound and Reseeding Stress Test — Before declaring victory, deliberately imagines the surviving source rebounding and reseeding the cleared zones — to see whether the barrier holds and to harden the contingency plan for when it doesn't.
  • Sanctuary Reachability Audit — Checks, source by source, whether the controller can actually reach and lawfully act there — and separates a genuine refuge that must be spared from a blind spot the target is exploiting as cover.
  • Sentinel Surveillance Dashboard — Turns a network of early-warning sentinel sites into one live picture of recurrence, so the first sign of reseeding shows up against the replacement line long before the target re-establishes.
  • Source–Sink Network Mapping — Maps the target as a network of sources and sinks so the low-contestation node that keeps reseeding the rest can be found and named — not just the biggest visible infestation.
  • Synchronized Campaign Calendar — Schedules source and sink interventions to land together and inside the target's vulnerable window, so no actor clears early and leaves a gap the surviving source can reseed.

Sandboxing

Create a bounded environment where actions, experiments, or failures can occur without directly affecting the wider system.

8 mechanisms · View full solution archetype

  • Lab Containment Space — Holds hazardous material behind physical barriers and interlocks so work can proceed without uncontrolled release.
  • Regulatory Sandbox — Grants a novel product a time-boxed license to operate under caps, supervision, and reporting before general approval.
  • Safe Play Space — A facilitated space governed by consent and norms where people can practice or err without real-world reputational cost.
  • Software Execution Sandbox — Confines untrusted code to a least-authority runtime so it can execute while the host and its data stay out of reach.
  • Staging Environment — Runs a release against a production-like replica before promotion, so integration failures surface off the live system.
  • Synthetic Data Testbed — Swaps sensitive live data for a generated stand-in so pipelines and models can be exercised without exposing real records.
  • Test Market — Launches a product into a bounded slice of the real market to gather demand evidence before a full rollout.
  • Training Simulator — Lets people rehearse high-stakes action in a synthetic world where instructors inject scenarios and mistakes stay fictional.

Sequestration Containment

Remove a harmful, volatile, scarce, or sensitive target from active circulation and hold it in governed containment until safe disposal, preservation, or controlled release is justified.

8 mechanisms · View full solution archetype

  • Carbon Sequestration Storage — A method for removing carbon from active atmospheric circulation and holding it in a more stable storage form.
  • Data Quarantine — A workflow that isolates suspicious, contaminated, embargoed, or sensitive data from ordinary production use.
  • Escrowed Asset Holding — A custody arrangement that places an asset under a neutral or governed holder until release conditions are met.
  • Evidence Locker — A restricted physical or digital custody artifact for preserving evidence outside ordinary access.
  • Hazardous Material Containment — A physical and procedural system for holding hazardous substances away from exposure pathways.
  • Isolation Vault — A protected physical, digital, or institutional vault used to prevent unauthorized access, movement, or alteration.
  • Quarantine Storage — A temporary isolation protocol for items that may be contaminated, unsafe, compromised, or unverified.
  • Restricted Reserve Account — A governed account or stock that keeps a resource outside routine circulation and ties release to authorization or criteria.

Source–Sink Viability Management

Manage asymmetric support networks by protecting sources, diagnosing sink dependency, and deciding when to sustain, restore, transform, or exit sinks.

13 mechanisms · View full solution archetype

  • Connectivity or Corridor Plan — Designs and protects the actual pathways along which a source's surplus can reach a sink, and deliberately keeps more than one route open, so rescue can happen without leaving the sink hostage to a single link.
  • Cross-Subsidy Budget — Makes the transfer from source to sink an explicit line item — how much surplus each source can spare after protecting itself, where it goes, and whether the resulting subsidy is fair — so support is a decision, not a leak.
  • Dispersal or Transfer Tracer — Tags and follows the individuals or units that actually move between patches, turning assumed support flows into a measured map of who really feeds whom and what each patch's true net balance is.
  • Metapopulation Model — Runs a network of coupled patches forward from their per-patch birth–death and dispersal rates to forecast whether the whole persists — and which patches are true sources versus occupied-but-doomed sinks.
  • Minimum Support Schedule — Sets the smallest reliable support a sink needs to stay just above its viability threshold, delivered on a fixed cadence and adjusted by rule as conditions change — sparing the source without letting the sink slip under.
  • Rescue-Effect Audit — Periodically tests whether a sink's apparent health is genuine local recovery or merely a rescue effect — persistence borrowed from a source — by asking what it would do if the support were removed.
  • Restoration Priority Matrix — Ranks dependent sinks by how recoverable they are against how much they are worth keeping, sorting each into restore, convert, sustain, or exit — so scarce surplus goes where it can actually change a unit's fate.
  • Role Reclassification Review — A standing review that watches for role-change triggers and, on a set cadence, formally re-labels any unit whose source or sink status has shifted — so the classification the whole system trusts never silently goes stale.
  • Sink Dependency Dashboard — Tracks each sink's dependency in real time — how much support it draws, how close it sits to its viability threshold, and which flows it relies on — so hidden fragility and lock-in surface before an interruption exposes them.
  • Source Depletion Dashboard — Continuously watches each source's health — how much exportable surplus is left, whether its viability guardrails are being breached, and how it holds up under stress — so stewardship never quietly slides into extraction.
  • Source–Sink Patch Map — Lays out every unit as a labelled patch — source, sink, neutral, or contested — coloured by measured net balance, so the asymmetric structure of who is quietly carrying whom becomes visible at a glance.
  • Support Flow Agreement — Turns an informal support flow into an explicit compact — stating why the support exists, until when it is promised, and on what fair terms — so a subsidy is a governed decision rather than an accreted habit.
  • Support Taper Plan — A staged glide-path for reducing or ending support, paced to the sink's response and bounded by a do-no-harm guardrail, so withdrawal is a controlled landing rather than a cliff.