Stop-Loss Rule¶
Pre-committed rule — instantiates Catastrophic-Risk Bargaining De-escalation
A pre-committed hard trigger: the moment risk, control-loss, or third-party harm crosses a declared line, stop or roll back automatically — no renegotiating the limit in the heat of the moment.
In the middle of a standoff, pressure and sunk cost conspire to talk everyone past the line they swore they'd never cross — "just one more step" repeats until control is gone. A Stop-Loss Rule forecloses that by making the decision cold, in advance. It is a rule set before the crisis that mandates immediate cessation or rollback the instant a measurable bound — risk level, loss of control margin, uncertainty, or harm to uninvolved parties — is crossed. Its defining property is pre-commitment: the judgment is made ahead of time, by people not yet in the grip of the moment, and it binds automatically so that in-the-moment adrenaline and escalation-of-commitment cannot renegotiate it. It converts a fuzzy "we'll know when it's too far" into a bright line that trips on its own. It is the unilateral brake a party imposes on itself — distinct from a bilateral ceiling both sides negotiate.
Example¶
A firm is trapped in an escalating retaliation spiral with a competitor — a private trade war of tit-for-tat moves that is starting to threaten a shared critical supplier whose failure would harm uninvolved customers and a whole downstream region. In the heat of the fight, each round feels justified by the last. So, before the next round, the firm's leadership sets a stop-loss: if a retaliatory move would push the shared supplier past a defined stress threshold — measured by concrete indicators, not vibes — the escalation halts and the last move reverts, automatically, no exceptions granted mid-crisis.
Weeks later, with tempers high, an indicator trips the rule. Because the limit was set cold and pre-committed, it holds where an in-the-moment judgment would almost certainly have rationalized pressing on. The spiral stops one rung short of the harm no one actually wanted to cause.
How it works¶
- Set the bound cold, in advance — define the trigger before the crisis, when judgment is unclouded, and treat the limit as fixed rather than a starting point for later negotiation.
- Make the trigger measurable and observable — tie it to concrete indicators (a risk metric, a control-margin reading, a third-party-harm threshold) so it fires on evidence, not argument.
- Automate the response — bind cessation or rollback to the trigger so crossing the line is the decision, removing the mid-crisis discretion that pressure would corrupt.
- Pre-authorize the brake — establish who executes the stop and their authority now, so no one has to win a fresh argument to pull it.
Tuning parameters¶
- Threshold level — how far the bound sits from catastrophe; conservative thresholds trip early and safely but risk halting on false alarms and forfeiting position.
- Trigger metric — which observable(s) fire the rule (risk estimate, control-loss, uncertainty, third-party harm); the choice determines what dangers it actually catches.
- Response severity — full stop, partial rollback, or freeze-and-review; harder responses are safer but costlier to trigger on noise.
- Override policy — whether any mid-crisis override exists and who holds it; a permitted override restores flexibility but reopens the very in-the-moment renegotiation the rule exists to block.
- Hysteresis — how much conditions must recover before resuming, to prevent thrashing across the line.
When it helps, and when it misleads¶
Its strength is defeating escalation-of-commitment: because the limit is set cold and trips automatically, it holds precisely when human judgment is least trustworthy — under pressure, with sunk costs mounting and "one more step" always seeming reasonable. It is the mechanism that most directly protects bystanders, since a third-party-harm trigger stops the spiral on their behalf, not the parties'.[1]
It misleads when the threshold or metric is wrong: set too tight, it fires on noise and cries wolf until someone disables it; tied to the wrong indicator, it watches the wrong danger and gives false comfort while real risk climbs a path it doesn't measure. A generous override quietly restores the discretion the rule was meant to remove — the classic misuse, waiving the stop-loss "just this once" in exactly the moment it was built for. The discipline: choose the trigger metric deliberately, pressure-test the threshold against realistic scenarios, and make override hard, logged, and rare.
How it implements the components¶
risk_ceiling_and_no_go_boundary— it declares the hard bound and the no-go line, and enforces it by automatic cessation or rollback when crossed.nonconsenting_party_safeguard— its third-party-harm trigger halts the spiral on behalf of those who never consented to the risk, making their exposure a stopping condition.
It is a self-imposed unilateral brake; it does NOT negotiate the shared ceiling between the parties (Risk-Ceiling Agreement) or model the probabilities feeding the trigger (Probabilistic Safety Analysis / Scenario Probability Table).
Related¶
- Instantiates: Catastrophic-Risk Bargaining De-escalation — supplies the pre-committed hard limit that halts escalation before control is lost.
- Consumes: the risk state and thresholds from Probabilistic Safety Analysis or Scenario Probability Table.
- Sibling mechanisms: Risk-Ceiling Agreement · Probabilistic Safety Analysis · Scenario Probability Table · Cooling-Off Period Protocol · Fail-Safe Automation Interlock
References¶
[1] The pattern of a pre-set threshold that forces an automatic exit is the stop-loss order from trading and the circuit breaker that halts a market in freefall; both exist because in-the-moment judgment under loss is unreliable. Binding a decision in advance against one's own future weakness is the classic Ulysses contract. ↩