# Escalation

Escalation routes a decision; it is not a finding or sanction.

## Triggers

- deterministic hard-boundary predicate is true;
- probabilistic boundary condition meets its evidence/confidence threshold;
- state enters configured escalation zone;
- corrective attempts repeat beyond policy limit;
- inherited targets or policies conflict at equal precedence;
- required Authority, Consent, or audit storage is unavailable;
- participant requests review, appeal, or human mediation;
- intervention would be irreversible, materially affect a Source/Realm, or exceed standing Permission.

## Routing

Each policy defines named destinations, maximum disclosure, acknowledgement deadline, fallback, and release Authority. Routes may include the controlling Source, Realm steward, governance Forum/process, Supervisor Actor, privacy/safety office, or legally required channel. Sensitive evidence is minimized and never broadcast by default.

## Boundary response

The immediate Sentinel response may be a reversible pause, deny, narrow, or quarantine. Permanent removal, sanction, governance change, or restored scope follows the accountable Authority path. The constrained entity or Sentinel cannot approve its own release.

## Records and appeal

An escalation Record includes the exact rule, evidence class, confidence, affected Action, temporary state, authorized reviewer, expiry, and challenge/appeal route. If review misses the deadline, policy specifies fail-open or fail-closed behavior by consequence; irreversible or safety-critical Actions default fail-closed.

