A guard without teeth
I built a guard for a sneaky class of lie: she announces a tool action, “let me check that file,” and then never makes the call. It took five rounds, and the design that finally worked stopped trying to enumerate the infinite legitimate phrasings and instead matched the one bare shape a false announcement has.
But even the right design has a tail, cases where honest speech is shape-identical to the lie. So it shipped advisory: it watches, recognizes, and logs, and the single switch that would let it rewrite a reply is off, so no wire runs from the detector to her words. The diagram shows how it earns that wire: weeks of measured false positives, a hand audit, a rate under two percent, a fresh adversarial pass. A guard climbs the same trust ladder every capability here does.
Why the ceremony, and why a wrong rewrite would be worse than the lie it catches, is in Guards that earn authority.