Langlotz.AI
Governance

Certified Trust Depreciates

· 905 words

Certified trust is capital. You invest once in a pattern, and every agent built on it afterwards draws on that investment instead of earning its approval from scratch. That is the argument I have been making, from the room that does not scale to the governed path a builder would choose, and it holds.

Which means it behaves like capital in every other respect too, including the one nobody puts on the slide. It depreciates. Patterns drift, and a certificate nobody renews is a snapshot decaying where no one is looking. That objection arrived against the case for shipping the road rather than guarding the gate, and it has not left me alone since.

The consequence is larger than a caveat.

The certificate stays constant. The asset does not.

Here is the quiet mismatch at the heart of pattern based governance. The certificate is a document, and documents hold still. The thing it certifies does not. The model gets retrained. The data shifts under it. An integration changes what the agent actually does in practice. A vendor ships an update that alters behavior nobody asked to change. Each of these moves the system a step away from the moment the certificate described.

The certificate does not lie. It keeps telling the truth from the day it was signed. That is precisely the problem, because the institution reads it in the present tense. On paper, the pattern is certified. In production, the pattern that earned the certificate may no longer be the pattern that is running. Book value and real value have quietly diverged, and nothing on the books shows it.

Accountability does not disappear. It moves.

The second point in that comment cuts deeper than the first. Shifting governance from individual agents to certified patterns does not remove the human from the hook. It moves them, from the person who approved the agent to the person who trusted the pattern. Someone is still accountable. The question is whether they know it.

Which is why every certified pattern needs a named owner, and the ownership has to sit with a role, not a person. Ownership that lives in one capable individual is how it quietly goes undocumented: they know the pattern, everyone trusts them, nothing is written down beneath them, and the day they change jobs the certificate is an orphan. Snapshots decay fastest exactly where nobody owns the looking.

Renewal runs on events, not anniversaries

The standard institutional reflex is the annual review, and for certified patterns it is close to worthless. A pattern does not drift on a schedule. It drifts when something happens: a retrain, a data source change, an integration update, a new version of the pattern itself. Review it every March and you will be early most years and catastrophically late in the one that matters.

The principle arrived in a comment on an earlier piece: approval is a state, not an event. Patterns inherit that completely. The certificate has to be wired to the events that can invalidate it, so that when one fires, the certificate visibly changes state from current to due for renewal, and someone with the authority to say stop is asked to say yes again, on evidence. Renewal that runs on the calendar is not a control. It is an anniversary ritual, performed on schedule and connected to nothing.

I watch a small version of this in my own fleet. Five weeks into the build, the components under my first agents have been updated more than once, and each update quietly moved the system away from what I had originally satisfied myself about. Nothing announced the change. Nothing ever does. That is the whole case for wiring.

Maintenance is not a failure of ownership

Here is why none of this weakens the capital argument, and why a board will understand it instantly. Every capital asset an institution owns depreciates, and every one of them carries a maintenance schedule. Nobody calls the maintenance plan for a vessel or a building an admission that buying it was a mistake. Maintenance is simply what owning an asset means.

Certified trust is the same asset class. The certification is the investment. The renewal discipline is the maintenance schedule. The named owner is the asset manager. Presented that way, the governance conversation stops being a plea for more control and becomes something a finance committee already knows how to fund: an asset worth protecting, with a maintenance line item attached. Governance functions rarely get to make that argument. This one is available.

The test you can run this quarter

Take any certified pattern, or approved model, or sanctioned agent architecture in your institution, and ask two questions. Who owns it, as a role that survives any individual leaving. And what event triggered its last renewal.

If the first answer is a name rather than a role, the ownership is one resignation away from undocumented. If the second answer is a date rather than an event, you do not have a control. You have a calendar.

The position I hold

Trust certified as a pattern is capital, and I stand by that. But capital depreciates, and the institutions that get this right will be the ones that treat the depreciation as part of the deal: a named owner for every certificate, renewal wired to the events that can kill it, and a maintenance budget that nobody has to fight for twice.

The certificate is not the trust. It is a claim about the trust, and claims age.

A comment started this one, so it ends with a question. If the depreciation schedule is wrong somewhere, I want to know where.