Charlot Lab · EFA · one energy, both roles

The controller is the certificate.

A single learned scalar energy over a saturated double integrator. The agent acts by descending it — and because that same energy provably contracts along the descent, the act of controlling is the stability guarantee. One object, two roles, no separate model to check.

energy V(x,v) — the bowl proven Lyapunov basin (certified R=1.35) agents descending to the goal
one energy · controller = argminu V(step) · certificate = ΔV+α‖s‖²<0, proven reached goal: 0 / 0 unification tax: zero
saturated torque |u|≤3 · greedy over 31 candidates · certified by affine Taylor+CROWN (959 boxes, audited)

The bowl is the energy V. Every agent picks, from 31 saturated torques, the one whose next state has lowest V — pure descent — and rolls to the goal. The gold ring is not drawn by hand: it is the region where a sound proof (2nd-order Taylor + per-box CROWN, the greedy controller handled as an OR over torques) guarantees V strictly decreases every step. Training a second energy only to certify buys no larger ring and still controls at 100% — so the two roles cost nothing to unify. Nano, in simulation; the honest scope is in the paper.