Authoring, owning and overriding are three different people. The engineer writes the rule, the product owner sets the tier, the steward grants the override — and no one of them can do all three (ADR-13).
Two machines are in the cast on purpose. The orchestrator's pre-run gate check is the highest-volume interaction in the system, and the sweeper is the reason a lost event is not a pass.
The auditor's goal — 'get the answer from a log nobody could have edited' — is why the override audit log is Object-Locked rather than merely append-only (ADR-14).
Assumptions
One data product owner per domain, 42 domains. Stewardship is a named delegation, not a job title.
Auditors read twice a year, over a 25-month verdict window and a 7-year override log.
Risks
The steward role is the soft spot: if override authority is granted widely to keep pipelines moving, every other control in this set becomes advisory.
Nobody in this cast owns 'datasets with no assertions'. That gap is why coverage is rendered as a distinct state rather than left implicit (ADR-05).