Skip to content

Separatrix Crossing Checklist

Governance protocol — instantiates Mixed-Stability Saddle Navigation

A pre-crossing governance gate that authorizes or aborts a high-stakes boundary crossing only after intent, rollback, and stakeholder understanding are all confirmed.

Some boundaries you cross on purpose — and those are exactly the ones where a moment's inattention is catastrophic. Separatrix Crossing Checklist is the deliberate go/no-go gate that stands before an intentional, high-stakes crossing of a basin boundary. It enforces the boundary as a hard set of veto questions — is the destination basin actually the one we intend, does a tested rollback exist, do the people involved understand the crossing and the abort call, are we inside the window where crossing is legitimate — and it resolves into a single explicit commit-or-abort trigger. Its defining property is that it authorizes only the attempt: it is a pre-crossing veto, not a live monitor and not a post-crossing verdict. Any unmet item blocks the crossing, which is precisely how it prevents both accidental and premature boundary shifts.

Example

A fire crew is planning a prescribed burn. Fire behavior sits at a saddle: a benign backing fire on one side, a runaway crown fire on the other, separated by a narrow band of wind, humidity, and fuel-moisture conditions. Before anyone drops a match, the burn boss runs the Separatrix Crossing Checklist. Intended destination: are we deliberately taking the fire into active spread, and is that the outcome we want here? Rollback: are the control lines cut, water and holding crews staged, and an escape route confirmed — a real hold, not a hoped-for one? Understanding: does every crew know the plan, the boundary conditions, and who can call the abort? Boundary/window: are the current readings inside the written prescription, with margin? Only if every item passes does the single "go" get spoken; any failure stands the ignition down. The result is that crossings into active fire happen only when they are intended, understood, and recoverable — and accidental escapes, the failure this gate exists to prevent, drop sharply.

How it works

  • Fix the veto questions to the boundary. Intent (destination basin named), rollback (a tested hold exists), boundary (irreversibility threshold explicit and current position confirmed inside the window), understanding (crews briefed, abort authority named).
  • Require evidence per item. Each answer must be shown, not asserted — especially "rollback exists."
  • Run it as a veto, not a vote. Any single unmet item blocks the crossing; there is no averaging away a failed rollback with a strong intent.
  • Resolve to one trigger. A single, pre-agreed commit ("go") that authorizes the crossing, or an abort that stands the attempt down.

Tuning parameters

  • Veto strictness — all-items-must-pass versus a weighted threshold. Maximum safety versus speed at the boundary.
  • Authorization level — who may pull the trigger (an independent reviewer versus the operator). Rigor versus latency.
  • Rollback standard — how firm "rollback exists" must be, from asserted to physically tested. The realism of the whole gate turns on this.
  • Window definition — how conservatively the irreversibility threshold and its margin are set; false alarms versus missed danger.
  • Re-arm cadence — a one-shot authorization versus a re-check if conditions drift between approval and commit.

When it helps, and when it misleads

Its strength is that it forces intent, rollback, and shared understanding into the open before an irreversible step, which is the only reliable defense against crossing a boundary by accident or too soon. It is grounded in hysteresis[1]: because the path back across a boundary is not the reverse of the path forward, "can we roll back?" cannot be assumed and must be a gated, evidenced question. Its central failure mode is checklist theater — items ticked ritually without real verification, so a fabricated "rollback exists" grants false assurance — or, at the other extreme, an over-strict gate that blocks beneficial crossings and produces paralysis at the edge. The classic misuse is running it as an after-the-fact rubber stamp to bless a crossing already underway. The guarding discipline is to demand evidence per item (a tested hold, not an asserted one), keep the list short and real so it stays honest, and pair it with a post-crossing check rather than treating authorization as confirmation.

How it implements the components

Separatrix Crossing Checklist fills the crossing-governance side of the archetype:

  • separatrix_boundary_guardrail — it enforces the boundary as a hard veto gate at crossing time; an unmet item blocks the crossing outright.
  • exit_or_commitment_trigger — its output is the single explicit commit-or-abort trigger the crossing hangs on.

It does not implement basin_destination_criterion — confirming the system actually arrived in the intended basin (rather than dipping through or drifting elsewhere) is the Basin Arrival Review, which runs afterward; the checklist only authorizes the attempt beforehand. Nor does it implement unstable_mode_monitor — continuous live tracking is the Unstable Mode Dashboard.

Editorial Notes

Form Classification

Form family: Decision, Gate & Allocation

Rationale: Separatrix Crossing Checklist operates by makes the case-specific cross-or-hold disposition from fixed veto questions at an irreversibility boundary. That concrete deployed or enacted form is Decision, Gate & Allocation under the frozen taxonomy.

Nearest alternative: Assessment, Review & Assurance — Although Assessment, Review & Assurance can support this mechanism, the frozen evidence makes its operative form the act that makes the case-specific cross-or-hold disposition from fixed veto questions at an irreversibility boundary; the alternative is therefore secondary rather than defining.

Review outcome: Adjudicated after independent review; high confidence.

Origin Attribution

Primary origin: Systems Thinking & Cybernetics

Origin pattern: Cross-disciplinary synthesis

Present-day reach: Multi-domain

Rationale: Treating a transition across a boundary between dynamic regimes as consequential derives from nonlinear systems and control thinking.

Related originating lineages:

  • Disaster Management & Risk Reduction — Escalation gates govern entry into emergency modes where ordinary recovery may no longer apply.
  • Engineering & Design — Go/no-go checklists verify rollback and readiness before hazardous state change.
  • Law & Governance — Authorization, informed understanding, and recorded intent make irreversible transitions procedurally legitimate.
  • Mathematics — A separatrix is formally the boundary dividing basins of attraction in phase space.

Review resolution: The blind reviewers agree that systems_cybernetics is the primary origin and differ only on reported ambiguity, alternate origin disagreement, origin mode disagreement. I preserve every independently explained alternate from both records rather than imposing a numeric cap. I retain cross_disciplinary_synthesis because the combined record shows material contributions from several lineages. The broader reach of multi_domain records portability separately from historical provenance, and encyclopedia_synthesis=true preserves the affirmative synthesis judgment where either reviewer identified one.

Attribution caveat: The boundary concept is mathematical; the checklist is an encyclopedia synthesis of governance and safety controls.

Encyclopedia synthesis: The exact catalogued form synthesizes established practice rather than reproducing a single standard historical label.

Review outcome: Reconciled after independent review; medium confidence.

Notes

The "rollback exists" item is the one most often faked and the one hysteresis makes load-bearing: if the crossing cannot in fact be undone, every other reassurance is beside the point. Weight verification there.

References

[1] Scheffer, Marten, et al. "Catastrophic Shifts in Ecosystems". Nature 413, 591–596 (2001). Shows that under hysteresis the threshold for returning to a prior state can differ from the threshold crossed on the way forward. registry