Current Governance and safeguards Updated: Translation: maintained translation

Institutional Immunity

— Helping Institutions Detect Misuse, Corruption, Rigidity, and Well-Intentioned Harm; Stop, Repair, and Learn

Nagi assumes that institutions can change for the worse.

Vital Commons, Resonant Democracy, social guarantees, public-interest AI, and even systems created to protect dignity can become new forms of domination. They may change through malice, but also through good intentions, optimization, emergency, expertise, habit, and time.

Institutional Immunity is the distributed social capacity to detect those changes, investigate them independently, protect people from severe and hard-to-reverse harm, provide remedy, and revise, reduce, divide, replace, or end the institution itself.

It is not a fourth principle above Non-Ownership, Resonance, and Breathing. It is the transversal function that keeps those principles from reversing into monopoly, conformity, and measurement of human worth.

1. Position inside Nagi

Institutional Immunity serves Nagi’s higher commitments: human dignity and kindness; opportunity to create; cultural and creative continuity; and an economy that remains a means rather than an end.

An institution is not justified merely because it uses Nagi’s language. If it no longer protects those commitments, it may need correction, contraction, loss of the Nagi name, transfer, or termination.

Institutional survival is never the highest value.

2. Four ways an institution can change for the worse

Malicious change

An actor may intentionally steal resources, suppress criticism, manipulate records, target a group, exploit emergency powers, or use infrastructure to demand obedience.

Well-intentioned change

People may remove human routes for convenience, collect more data “for safety,” force participation “for inclusion,” or prevent exit “to protect the community.” Harm does not become harmless because its stated purpose is good.

Structural change

Incentives, budgets, procurement, platform dependency, professional closure, technical architecture, or unequal access may produce domination even when no individual intended it.

Change through time

Temporary authority becomes customary. Exceptional data collection becomes normal. A role becomes hereditary. An audit body begins to protect its own budget and survival. Rules persist after the problem they addressed has changed.

3. A constitutional floor that review cannot weaken

Institutional Immunity does not permit every right to be suspended for investigation or efficiency.

The protected floor includes:

Review may improve the way these rights are protected. It does not convert them into rewards for cooperation.

4. Five layers of Institutional Immunity

4.1 Detection

People affected by a system, workers, local operators, civil society, journalists, auditors, researchers, and technical monitoring can each surface different forms of harm.

Detection channels must include anonymous and identified routes, accessible formats, local and human routes, and ways to report without using the institution being challenged.

4.2 Verification

A report is not automatically a verdict. Independent people with different methods examine evidence, uncertainty, affected groups, conflicts of interest, and alternative explanations.

The party operating the system does not control the only investigation. Minority findings and unresolved disagreement remain visible.

4.3 Protection and temporary pause

Where harm may be severe and hard to reverse, a narrowly scoped function can be paused before the entire investigation is complete.

The pause has a reason, scope, responsible authority, review time, expiration, and continuity plan. It restores essential supply and safety first. It does not become a hidden permanent ban.

4.4 Remedy

Institutional learning is not enough for people who were harmed.

Remedy may include restoring access, correction or deletion of records, compensation, health or legal support, reinstatement, relocation of decision authority, public acknowledgment, and protection from retaliation. The route to remedy remains available even when the institution disputes blame.

4.5 Learning and institutional change

Verified failures lead to changes in rules, architecture, staffing, budgets, contracts, data collection, authority, training, and public explanation.

If correction is insufficient, the institution can be divided, transferred, reduced, replaced, stripped of the Nagi name, or ended.

5. Do not create one supreme third-party authority

No single body should combine detection, investigation, emergency suspension, final adjudication, remedy, and rule revision.

Concentrating those powers would create a new sovereign center in the name of safety. Nagi instead uses overlapping authorities, independent routes, recorded disagreement, appeal across institutions, and the ability of affected people to seek support elsewhere.

6. Separate powers and responsibilities

At minimum, the system distinguishes:

Some roles may be held by the same organization at small scale, but conflicts of interest and escalation routes must remain explicit.

7. The right to report and protection from retaliation

People do not have to prove the entire case before asking for protection.

Reporting routes protect workers, residents, users, non-users, minorities, and people who have left. Retaliation through dismissal, loss of service, reputation systems, legal intimidation, immigration status, data exposure, or social exclusion is itself a serious institutional failure.

False or malicious reports can be investigated without making ordinary error, uncertainty, or unsuccessful reporting punishable.

8. Red teams and worst-case testing

Institutions are tested against their worst plausible users and conditions, not only their best operators.

Red teams examine capture by insiders, collusion, cyberattack, supply interruption, biased data, emergency misuse, coercive scoring, removal of human routes, exclusion of minorities, and the possibility that oversight becomes self-protective.

Affected communities help define the harms. Technical experts do not hold the only imagination of failure.

9. Auditing black boxes

An institution cannot answer every challenge with trade secrecy, national security, model complexity, or professional authority.

Public explanation may protect legitimate secrets and personal data while still revealing purpose, authority, inputs, decision boundaries, known limitations, incident rates, conflicts of interest, appeal routes, and independent findings.

Where a system cannot be inspected enough to protect life and rights, its authority must be limited accordingly.

10. Immunity costs are real operating costs

Redundancy, independent review, human routes, documentation, reserves, accessibility, secure reporting, remedy funds, manual capability, and time for dissent all cost money and labor.

An institution that works only after removing the cost of Institutional Immunity does not work.

Those costs are visible in budgets and procurement. They are not the first items removed in the name of efficiency.

11. Strength proportional to risk

Not every cultural group or small experiment requires the same machinery as a health system, energy grid, rights database, or system that allocates scarce resources.

The depth of audit, redundancy, pause authority, remedy funding, and independent review grows with potential harm, scale, irreversibility, data sensitivity, and difficulty of exit.

Low-risk activity still needs consent, explanation, and an exit. High-impact systems require full failure planning before deployment.

12. Audit the immunity system itself

Oversight bodies disclose their authority, terms, funding, methods, conflicts, decisions, errors, and dissenting views.

Their leaders and contractors rotate. Affected people can challenge them through routes they do not control. Their budgets and continued existence are periodically justified rather than presumed.

13. Prevent institutional autoimmune disease

A safety system can become harmful by treating dissent, novelty, minority culture, privacy, slowness, or non-participation as threats.

Institutional Immunity therefore targets verifiable harm and dangerous concentration, not difference itself. Protective action is narrow, proportionate, time-limited, and reviewable. It does not demand total transparency from private people while leaving powerful institutions opaque.

14. Asymmetry between public accountability and private life

The more power an institution has over life, rights, resources, or public decisions, the more it must explain.

The less power an individual has, the less they should be forced to expose in order to receive protection, report harm, or access basic life.

Transparency is a duty of power, not a demand that everyone surrender privacy.

15. Expiration and termination

Emergency authority, experimental programs, data collection, contracts, exceptions, and the immunity body itself carry review dates and end conditions.

Ending an institution includes continuity for essential services, preservation of evidence, protection for affected people and workers, data return or deletion, transfer of stewardship, and public explanation.

Termination is not always failure. Sometimes it is the successful refusal to let a structure outlive its purpose.

16. How success is judged

Institutional Immunity succeeds when:

Its purpose is not to produce a perfectly pure institution. It is to keep harm from becoming invisible, irreversible, or permanently owned by those who already hold power.

Closing

Nagi does not protect institutions from criticism. It protects people, life, culture, freedom, and the possibility of revision from institutions—including institutions created in Nagi’s name.

Detect without scoring people.
Verify without monopolizing truth.
Pause harm without making emergency permanent.
Repair people before preserving systems.
End what can no longer serve its purpose.

Governance and Safety
Transition and Crisis Design
Vital Commons