Building Systems That Matter — Volume II: The Governed System (EDDA & AISDR)
A case-study volume. Where Volume I argued the eight laws and proved each against fragments of real systems, Volume II takes one architecture — EDDA, a governance framework for intelligent systems, and AISDR, its security profile — and follows it end to end, showing the eight laws operating together.
Source material: RESOURCES/whatisaisdr.md and the EDDA framework material. Built on CLAUDE.md; see ROADMAP.md and PROOF_POINTS.md.
Status: drafted end to end (M5). In editorial review.
The distinction this volume insists on: EDDA is the general framework; AISDR is one profile of it (EDDA applied to AI-assisted security). They are never collapsed.
Projected Canonical Units
refarch-eddacase-aisdr
This volume is projection prose. Canonical claims live in canon/; the volume supplies teaching order, examples, and synthesis.
Front matter
- Introduction
Chapters
| # | Chapter | Focus |
|---|---|---|
| 1 | The Problem: Ungoverned Intelligence | Why AI-assisted decisions need governance; the seven questions |
| 2 | EDDA: The General Framework | Governance domains; the eight laws of governed AI; framework vs. profile |
| 3 | Identity, Policy, and the Control Plane | The single door; fail-closed gate; action rights; the decision registry |
| 4 | Evidence and Grounding | The governed corpus; provenance; freshness; evidence bundles (Law V) |
| 5 | Reasoning That May Not Act | The AI that proposes, never disposes; confidence; calibration; eval gates |
| 6 | Actions, Agents, and the Prompt | Connector firewall; tier enforcement; tool integrity; prompt security |
| 7 | The Governed Request Lifecycle | One decision, followed end to end through every domain |
| 8 | The Eight Laws, Together | Synthesis: all eight laws simultaneously true in one system |
Reference material
Promoted from the former legacy tree during Phase 4 (see reference/README.md):
JSON schemas, OpenAPI control-plane definitions, reference architecture, conformance specs.
governance-lifecycle, risk-approval-flow, federation, runtime-topology, service-map, EDDA pillars, governed-request sequence).
reference/edda-framework/— the formal EDDA framework: RFCs, ADRs,diagrams/— EDDA / AI-governance diagrams (control-fabric, evidence-chain,
Related
- Volume I — The Laws
- Series glossary — the single authoritative source for terms
- Appendix A — Proof-Point Systems (EDDA §A.2, AISDR §A.3)
