# Manual-Only Governance

> A defect in which architecture rules or security policies exist only in documents or in reviewers' memory, with no executable check, so they drift from what the system does.

Record: `architecture:manual-only-governance`
Kind: anti-pattern
Layer: [Enforcement Core](https://banes-lab.com/records/layer/enforcement-core.md)
Severity: discouraged
Scope: correctness_verification, security_governance
Aliases: Document-Only Policy
Canonical: https://banes-lab.com/ontology#architecture-manual-only-governance

Listed in [Architecture principles](https://banes-lab.com/api/records/architecture.md), after [Boundary Leakage](https://banes-lab.com/records/architecture/boundary-leakage.md) and before [Opaque Runtime Behavior](https://banes-lab.com/records/architecture/opaque-runtime-behavior.md).

## Repair

- Refactored by: create_fitness_function, add_static_check, add_policy_as_code, add_architecture_test, track_rule_metrics
- Detected by: rule_exists_only_in_docs, no_CI_gate, reviewer_specific_enforcement, repeated_same_violation, missing_fitness_function
- Violated by: Encode architecture rules in documents, meetings, or reviewer memory without executable checks, metrics, or automated enforcement.
- Measured by: stated rules without an executable check, repeat violations of one rule
- Enforced by: a rule-coverage check that requires every stated rule to name its executable gate

## Contracts

- [Quality Governance Loop](https://banes-lab.com/records/algorithms/quality-governance-loop.md)

## Severity

- [discouraged](https://banes-lab.com/records/vocabulary/severity-discouraged.md)

## Category

- [Anti-patterns](https://banes-lab.com/records/architecture-category/anti-patterns.md)

## Force

- [Correctness verification](https://banes-lab.com/records/force/correctness-verification.md)
- [Security governance](https://banes-lab.com/records/force/security-governance.md)

## Negated by

- [Policy as Code](https://banes-lab.com/records/architecture/policy-as-code.md)

## Linked from

- [Who does what](https://banes-lab.com/disciplined-methodology/start/who-does-what.md)
- [The stance](https://banes-lab.com/disciplined-methodology/start/the-stance.md)
- [Where a rule lives](https://banes-lab.com/disciplined-methodology/start/from-chat-to-tree.md)
- [A system is a graph](https://banes-lab.com/software-architecture/model/a-system-is-a-graph.md)
- [Seven controls, seven classes](https://banes-lab.com/software-architecture/decay/seven-controls-seven-classes.md)
- [Anti-patterns](https://banes-lab.com/ontology/principles/architecture-category-anti-patterns.md)
- [Security / Privacy / Compliance / Governance](https://banes-lab.com/ontology/principles/architecture-category-security-privacy-compliance-governance.md)
- [Quality engine](https://banes-lab.com/ontology/algorithms/algorithms-domain-quality-engine.md)
- [Failure shapes](https://banes-lab.com/ontology/reasoning/the-failure-shapes.md)
- [Severity levels](https://banes-lab.com/ontology/schema/the-vocabulary-severity.md)
- [The forces](https://banes-lab.com/ontology/schema/the-forces.md)
