LEVERS

A Complete Theoretical Formulation (v5)

I. Primitives

D1. System. A set of agents and processes that produces outcomes over time. A system is managed when at least one agent (the manager, individual or collective) can intentionally alter its configuration. The manager may be inside the system, including a person managing themselves.

D2. Configuration variable. Any alterable property of a system that conditions its outcomes.

D3. Lever. A class of configuration variables satisfying three axioms:

  • A1 (Irreducibility). Its effects cannot be expressed as a combination of settings of the other levers.
  • A2 (Universality). It is present in every managed system, at every scale, from an individual to a civilization.
  • A3 (Actionability). A manager can, at least in principle, change its setting.

D4. Setting. The current value of a lever. A setting is misset when, conditional on the settings of the levers above it, an available alternative setting would yield strictly better attainable outcomes. A lever is unpulled when its setting is the default that no one has deliberately chosen. (Misset and unpulled are distinct pathologies; unpulled is the more common.)

D5. Pull. An intentional change to a setting. Pull depth is the degree to which the change rearranges the system's recurring operation — how much of what agents actually do, encounter, and are consequenced by in an ordinary cycle is altered, and for how long. A pull that changes documents but not days is shallow, whatever its subject.

D6. Constraint. A configuration variable fixed from outside the manager's authority. Any lever can appear to a given manager as a constraint. A constraint is not a lever for that manager: it cannot be pulled, only responded to, and the response occurs at whichever levers remain actionable.

D7. Validity domain. Every setting is correct only within a range of scale, environment, and time. A pull should declare its validity domain at pull time: the conditions under which the setting holds, and the observables whose movement signals that the domain has been exited. A setting outside its validity domain is misset regardless of the care with which it was originally chosen — missetting requires no error. Correctness is a perishable state.

II. The Seven Levers

The complete, ordered set of levers for any managed system:

L1. Purpose. The system's operative priority ordering over outcomes under scarcity — what wins when goods conflict. Purpose is revealed by resolution of conflicts, not by declaration; a stated purpose that loses conflicts is not the purpose.

L2. Model. The set of beliefs on which the system acts: how its domain works, what causes what, and what the system itself is (identity, at personal scale; culture and doctrine, at collective scale). The model generates the option set — actions unthinkable under a model are unavailable regardless of every other setting.

L3. Boundary. The definition of the system's extent: what it attempts, what it contains, whom it includes, and — equally constitutive — what it excludes. Boundary has two modes: chosen (a lever) and imposed (a constraint; see D6, C3).

L4. Structure. The arrangement of consequence and sequence: decision rights, incentives, error-correction mechanisms, defaults, environments, and the order in which things are done. Structure is the system's answer to "who may decide what, and what happens to whom when." For an individual, structure is environment and schedule.

L5. Information. The mapping from system state to decision-relevant signal, with three properties: selection (what is sensed and measured), fidelity (how honestly the signal reflects the state), and tempo (the latency of the loop from state to signal to action). Tempo is a property of this lever, not of L4.

L6. People. The capability and will of agents in role. The lever decomposes into selection (who enters, who stays, who exits) and development (what those inside become), with selection carrying at least equal weight. Exhortation is not a setting of this lever.

L7. Resources. The stock of fungible inputs: money, time, materiel, headcount, and attention. Attention is a resource whose allocation is set by L4 and whose routing is a function of L5.

III. The Ordering Relation

For levers Lᵢ and Lⱼ with i < j, Lᵢ dominates Lⱼ, meaning both:

  • Downward cascade. A change in the setting of Lᵢ generically changes the correct setting of Lⱼ. The lower lever's optimum is defined only conditional on the settings above it.
  • Upward non-compensability. No setting of Lⱼ restores the outcomes forgone by a misset Lᵢ. Lower pulls under a higher missetting can at most stabilize (see Law 4).

The ordering therefore ranks repair priority and diagnostic precedence — not marginal importance, not effect size, and not the location of the binding constraint (see Law 1).

IV. The Laws

Law 1 — Dominance (with the binding-constraint clause). No lever compensates for a misset lever above it, and repairing any lever below the highest misset lever treats symptoms. However: when every lever above is correctly set, the binding constraint on outcomes may sit at any level, including L7, and pulling it there is then the correct and sufficient move. The hierarchy tells you where to look first and what to fix first; it does not tell you where the shortage is.

Law 2 — Keystone. (Held at lower confidence than the other laws; see §VIII.) Pulls differ in cascade coefficient: the degree to which executing them mechanically forces other levers toward correct settings. Among feasible pulls of comparable depth, prefer the one with the highest cascade coefficient — one move that resets the board over seven moves that each reset a square.

Law 3 — Descent bias. Managers under stress systematically pull levers below the highest misset lever, because low pulls are cheap, legible, immediately available, and require no admission that something above — usually something the manager chose — is wrong. In the absence of stress the same pathology appears as neglect: the default state of ordinary systems is unpulled middle levers. Corollary: the prevalence of low-lever activity in a system is evidence about its managers' self-model, not about where its problems are. ◇ Over time, descent bias has a recognizable signature: escalating effort at low levers — longer hours, more spend, harder grinding — to postpone updating a high lever whose validity domain has been exited; the escalation itself is often the earliest legible symptom of the silent expiry above.

Corollary 3a — Elevation bias. The framework induces in its users the mirror of the bias it corrects: diagnosing high causes for low problems — inventing purpose crises for systems that need staff, delaying obvious fixes, and condescending to the people inside them. Descent bias is refusing to look up; elevation bias is refusing to stop while ascending. The guard for both directions is the same termination rule: stop at the highest verified misset lever (see P1's verification clause), and where nothing is misset, accept that the answer is a binding constraint, however unglamorous.

Law 4 — Stabilization inequality. Pulls below a misset lever can bound losses over a finite horizon; they cannot restore the outcome frontier, and the horizon is finite whether or not its end is visible. Stabilization is a legitimate use of low levers if and only if the time purchased is spent repairing the missetting above. Stabilization treated as cure converts a crisis into a chronic condition.

Law 5 — Goodhart coupling. L5 and L4 are not independent. A signal attached to consequences without aligned incentives degrades its own fidelity, at a rate increasing in the pressure applied. Therefore information pulls and incentive pulls are a single compound move: measure-and-align, never measure alone. Symmetrically, fidelity is manufactured structurally — a system obtains honest signals exactly to the degree that its structure makes honesty safe and distortion unrewarding. ◇ Integrated over time, Law 5 is a lifecycle: under sustained pressure a metric passes from signal to target to gamed to dead (a special case of Law 8's adaptation mechanism), so metric rotation and refresh are maintenance obligations, not design failures (see P5).

Law 6 — Imitability gradient. In adversarial settings, the durability of an advantage under observation increases with the height of the lever that produces it. Low-lever advantages (resource positions, information edges) are legible and copyable: observation suffices for reproduction, so they decay once seen. High-lever advantages (models, cultures, doctrines) survive full publication, because their observable content underdetermines their reproduction — reproducing them requires the imitator to reset its own upper levers, i.e., to become something else. Corollary 6a: optimal secrecy allocation concentrates on low and middle levers; secrecy spent on high levers is largely wasted. Corollary 6b: in live conflict, where both sides pull continuously, outcomes track relative model-update tempo — the speed at which each side's L2 incorporates what its L5 delivers. This is the point at which Laws 5 and 6 meet.

Law 7 — Pull depth. Effect magnitude is a joint function of lever height and pull depth. Height sets the ceiling — what could change; depth determines how much of the ceiling is realized. Consequently a deep pull of a low lever routinely outperforms a shallow pull of a high one, and lever height never excuses shallow pulling. Corollary 7a (Embedding): a pull at any height persists only if adjacent levers are reset to hold it — a structural artifact without the model behind it is ritual and inert; a model change without supporting structure decays. Pulls embed or evaporate. ◇ Embedding purchased today is hysteresis owed tomorrow (see Law 9).

Law 8 — Drift. All settings decay toward misset with time, through five mechanisms:

  • Scale invalidation. Growth or shrinkage exits the setting's validity domain; hub structures saturate, osmotic transmission fails past the size where everyone knows everyone.
  • Environmental drift. External or internal constraints move slowly beneath the perception threshold (C3-extended in slow motion); markets shift, bodies age, technologies mature.
  • Sedimentation. Structures, boundaries, and commitments accrete monotonically — each individually justified — until the aggregate is misset though every component passes inspection. Sedimentation is the pathology P1's one-setting-at-a-time audit cannot see; it requires layer audit (C7, P5).
  • Goodhart decay. Metrics die with use (Law 5's lifecycle form).
  • Reflexive adaptation. The system and its environment learn the pull: repeated identical pulls select for resistance to themselves — populations evolve around the pesticide, cities induce demand into the new lanes, people game the incentive. Pull potency is a depleting asset under repetition; rotate mechanisms or vary depth.

Consequently, correctness is a maintained state, never an achieved one, and maintenance means re-derivation, not repetition.

Law 9 — Hysteresis and latency. Two temporal asymmetries compound at high levers:

  • Hysteresis. Resistance to re-pulling a setting rises with lever height, embedding depth, and the setting's record of past success — the durability Law 6 celebrates adversarially is symmetric, and defends the setting against its own owner. Success is the strongest fixative: every year a model works, it re-verifies itself and grows harder to abandon.
  • Symptom latency. The delay between a missetting and its legible symptoms rises with lever height. Resource missettings announce themselves immediately; purpose and model missettings can run symptomless for years while lagging observables continue to "verify" them.

Jointly: high levers rot silently and resist repair. Therefore high levers are checked on clocks, not alarms — scheduled re-derivation at a cadence set by the lever's height and its environment's drift rate (P5) — and some fraction of verification must be forward-looking and off-model, probing what the current model says won't work, lest the verification clause itself institutionalize the success trap.

V. Derived Concepts

C1. Binding constraint. The lever whose current setting most limits outcomes given that all levers above it are correctly set. Diagnosis locates the highest missetting; the binding constraint is where effort goes once nothing above it is wrong.

C2. Anti-descent device. A pre-commitment that blocks pulls of a low lever until specified higher levers verifiably meet their conditions. Anti-descent devices are installable at every scale, externally (imposed by an authority) or reflexively (imposed by the manager on their own future self), and are the structural remedy for Law 3.

C3. Imposed-boundary response. An imposed boundary is a constraint; the system's lever response to it occurs at L2 — the constraint redirects the model's search rather than being pulled itself. Redirection is not compensation: the constraint's cost remains. C3 (extended). When an external constraint changes and the system's model does not update to track it, the model is thereby misset. The constraint is never the repair site; failing to metabolize it always is. A system may therefore be fully "internally correct" against a world that no longer exists — and that is an L2 diagnosis, not an exemption.

C4. Boundary–demand coupling. A chosen boundary drawn against strong, unchanged demand does not eliminate the excluded activity; it relocates the activity into an adversarial structure outside the boundary. Effective exclusion of the demanded requires a companion pull at L2 (change the demand's model) or L4 (price the path).

C5. Coupled pairs. The levers are ordered but not independent. The load-bearing couplings: L5–L4 (Law 5), L2–L4 (Corollary 7a), L3–L2 (C3, C4), L6-selection–L2 (culture is maintained by who is admitted and removed).

C6. Adjacency rule. Classification of a real situation into levers is sometimes ambiguous. When the competing classifications are adjacent levers, the repairs they imply generally converge, and repair may proceed without resolving the label. When the competing classifications span non-adjacent levers, the implied repairs diverge, and the classification must be resolved — by the verification clause of P1 — before acting.

C7. Anti-sediment device. The temporal sibling of C2, directed at Law 8's sedimentation mechanism: settings carry their reasons and an expiry at creation (sunset clauses); commitments lapse unless renewed rather than persist unless killed; and periodic layer audits evaluate accumulations as wholes, with the burden of re-justification on each setting's continuation, not on its removal. Where a setting's original reason is lost, subtraction is preceded by model archaeology — recover why it exists before deciding its fate — so that pruning does not reactivate the disaster the setting was built against.

C8. Graduation. For systems whose purpose includes the managed becoming self-managing — children, mentees, teams under development, recipients of aid — correct management is a staged transfer of levers downward to the managed: structure loosens as their internal structure forms, decision rights migrate as their model matures, and the manager's role shifts from director to advisor to absent. The success criterion includes the manager's obsolescence, and holding levers past the managed's readiness is a missetting, not a safety margin.

C9. Completion and dissolution. Purposes can complete or expire. A completed purpose held past completion is misset, and activity that preserves the institution in the purpose's absence is descent bias at the highest lever. The fork is honest re-derivation of a new purpose from scratch, or dissolution with honor — boundary → ∅ is a legitimate design outcome, and a framework that cannot recommend an ending is biased toward institutional immortality.

VI. Operating Procedures

P1. Diagnosis (bottom-up in symptoms, top-down in causes). Symptoms surface at low levers. Beginning at the lever where the symptom presents, ask of each lever in ascending order — ◇ first: has this setting's declared validity domain been exited (D7)? — then: is this lever's setting correct conditional on the settings above it? ◇ The domain check is often cheaper and earlier than the conditional-correctness test, and catches the missettings that arise without error.

Verification clause. A candidate missetting is admitted only with a named, in-advance observable that would confirm it — a measurement, record, or test specifiable before any repair begins. No observable, no diagnosis; the ascent continues past unverifiable candidates. This clause is what separates diagnosis from storytelling, and it is the operative guard against both Corollary 3a and motivated stopping.

Continue upward past every lever whose setting is merely downstream-correct, and stop at the highest verified misset lever. That is the repair site. Everything fixed below it is stabilization (Law 4) and must be labeled as such, with an intended expiry. If no lever is misset, identify the binding constraint (C1) and pull there — without embarrassment (Corollary 3a).

P2. Design (strictly top-down). Set L1 through L7 in order, at each step deriving the lever's setting from those already fixed, choosing the deepest feasible pull (Law 7), preferring keystone pulls (Law 2), compounding measurement with incentive alignment (Law 5), and installing anti-descent devices (C2) before the pressure to descend arrives. A design begun mid-hierarchy inherits the unexamined defaults of every lever above its starting point.

P3. Adversarial extension. Map both sides' settings. Direct attack at the opponent's low levers (counterable, degradable); build one's own advantage at high levers (durable under observation, Law 6); allocate secrecy per Corollary 6a; and above all maximize relative model-update tempo (Corollary 6b), which functions as the adversarial master variable.

P4. Self-application. The manager is a managed system. The framework applies reflexively: a manager's own descent bias, elevation bias, model rigidity, and attention allocation are settings of their personal L1–L7, and P1 — verification clause included — runs on them unchanged.

P5. Maintenance (the temporal procedure). Time is a standing adversary (Law 8) with an accomplice inside the walls (Law 9). The countermeasures, in order of leverage:

  1. Declare domains at pull time. Every pull states its validity domain and the observables that signal exit (D7) — the verification clause, extended into the future.
  2. Check clocks, not just alarms. Schedule re-derivation of each lever at a cadence rising with its height and its environment's drift rate; purpose and model reviews happen on the calendar precisely because no symptom will summon them in time (Law 9). Include forward-looking, off-model probes in every high-lever review.
  3. Design for the next epoch when it is visible. Known threshold ahead — a scheduled scale crossing, an announced constraint change — means re-derivation happens before the crossing, not after the breakage.
  4. Rotate pulls in adaptive systems. Where the system learns the pull (Law 8's fifth mechanism), vary mechanism and depth; retire and replace metrics on a lifecycle (Law 5); never assume constant potency under repetition.
  5. Subtract on schedule. Run layer audits and enforce sunset defaults (C7); accretion is the default motion of structure and boundary, so pruning must be a standing appointment, not a response.
  6. Run successions as model transfers. A handoff of role is a project of extraction, codification, apprenticeship overlap, and staged authority migration — with the personnel action at the end, not the beginning (C8's transmission form). Purpose and model persist across people only by active re-transmission; every untended handoff is a generation of drift.
  7. Know the ending. Check purposes for completion; when complete, choose re-derivation or dissolution deliberately (C9). Anticipate graduation where it applies (C8) and schedule the handoffs.

VII. Compressions

  • The one-sentence form: most management failure is pulling a lever below the broken one.
  • The diagnostic form: find the highest verified misset lever; fix that; call everything below it stabilization.
  • The design form: top-down, deep, keystone, coupled, pre-committed.
  • The adversarial form: attack low, build high, update fast.
  • The humility form: where nothing is misset, the answer is a shortage — fix the shortage.
  • ◇ The temporal form: every correct setting is expiring; maintenance is re-derivation, not repetition — and the higher the lever, the quieter the rot.

VIII. Scope, Confidence, and Falsifiability ◇ (updated)

Scope. The framework applies to any system meeting D1 — possessing a manager with alterable configuration — and claims validity as description (the levers exist and are complete), diagnosis (P1 locates repair sites correctly), and now dynamics (Laws 8–9 describe how settings decay and resist repair over time).

Epistemic status by layer:

  • Description and diagnosis: supported by three rounds of case induction and replicated-evidence validation, including convergent derivation by an independent research program.
  • Procedures: tabletop-tested across 40 simulated situations (20 static, 20 evolutionary); mechanically applicable; failure modes discovered and guarded (3a, C6, and the temporal silences repaired in v5). Tabletop testing was author-designed and author-graded and therefore establishes coherence, not efficacy.
  • Temporal laws (8–9): each of Law 8's five mechanisms rests on independently replicated empirical literatures (scale thresholds, induced demand, resistance evolution, metric gaming, drift); their unification into a single decay law, and Law 9's latency-hysteresis pairing, are this framework's synthesis, validated so far only by simulation.
  • Prescription: formally untested. Whether practitioners using the framework outperform those without it awaits an externally graded trial — now requiring a longitudinal arm.

Confidence gradient. Laws 1, 3 (with 3a), 5, 6, and 7 rest on replicated, multi-method evidence; Law 4 on consistent but thinner evidence; Laws 8–9 on replicated component evidence with synthetic unification; Law 2 on convergent narrative only. Law 2 should be held loosely and applied with stated uncertainty.

Falsifiability. The framework is refuted, in whole or part, by any of:

  1. A demonstrated case of durable upward compensation — a misset upper lever fully offset from below beyond any stabilization horizon (refutes Law 1).
  2. An eighth configuration class satisfying A1–A3 (refutes completeness).
  3. A reduction of any of the seven to combinations of the others (refutes irreducibility).
  4. High-lever advantages decaying under observation at rates comparable to low-lever advantages (refutes Law 6).
  5. Shallow high-lever pulls systematically outperforming deep low-lever pulls (refutes Law 7).
  6. P1 systematically terminating at levers whose repair does not improve outcomes (refutes the ordering itself).
  7. Framework-trained practitioners systematically over-diagnosing high-lever causes relative to verified ground truth despite the verification clause (would refute the adequacy of the 3a guard, requiring procedural redesign).
  8. ◇ Settings observed to remain correct indefinitely absent maintenance, across changing scale and environment (refutes Law 8).
  9. ◇ Symptom latency observed flat or decreasing with lever height, or re-pull resistance uncorrelated with embedding and past success (refutes Law 9).
  10. ◇ Repeated identical pulls retaining full potency in systems capable of adaptation (refutes Law 8's reflexivity mechanism).

A framework of this generality risks unfalsifiable elasticity — every outcome explainable after the fact. The falsification conditions above, the verification clause in P1, the domain declarations of D7, and the standing requirement that any diagnosis name in advance the lever whose repair will move outcomes are the guard. Where the framework cannot make that forward-looking commitment, it should be silent.