Size the fence to the stopping distance
The first fence we drew was provably too thin: the closed-form braking bound was 8.9 cm against a 3.5 cm margin. A body with momentum cannot stop at the line, so the fence moved out to the distance the machine actually needs. Refusal before the edge is the braking distance made physical.
A fence, not a goal
Built as a contraction condition, always move toward the safe pose, the guard vetoed 386 of 400 steps and the robot did nothing. Safety that freezes is its own failure. Built as set invariance, veto only what leaves the region, the task runs free inside and the guard intervenes about 8 times in 400, only during the fault.
One recover does not serve every constraint
Standing up is the right answer to a falling torso and the wrong answer next to a person, because standing swings a limb outward. Constraints that point in different directions each need their own recover, and the arbiter has to recognise which one is binding.
The niche picks the barrier
We expected joint limits to be the danger and measured that they are not: a torque-limited, damped, position-controlled arm physically cannot slam its own stops during a glitch. The real irreversibility was the tool going through the table, which is invisible to a joint-limit checker. Instrument before choosing what to guard.
Reactive recovery has a boundary
Parked deep in a slot under a shelf, the reactive retreat that certified the open table strikes the shelf every time, because home is on the far side of an obstacle. A safe motion exists, so the pocket is not inescapable, but reaching it needs a planner. Where free space stops being locally exitable, the honest move is to refuse to go there.
Empiricism concentrates in one place
Clearance is Lipschitz and the outward condition at the boundary is velocity free, so both are sound given a spatial pad. What remains sampled is which states the fault can actually deliver the machine to. Characterising that reachable set is the one honest gap between this and a closed-form proof.