The system that holds
Working Papers ·
written 19 September 2026 · open
Download the original (.docx)
Dr. Toye Oyelese, MBBS, CCFP, FCFP
Clinical Associate Professor, Department of Family Practice
University of British Columbia
The framework is mine and the clinical observations are forty years old. Some of what follows was worked out in the last week and did not exist before it. I have set those parts apart where they occur, because how long a thing has been standing should change how much weight you give it. I changed my mind three times while writing. I have left the changes in.
Almost none of this is proven. It is what makes the most sense to me.
Physiology is function. Homeostasis is function that is being held against something, at a cost.
That second one is what I mean. The mind is not sitting still when it is well. It is holding something down, all day, and paying for it.
Which changes the question. Not what does a working mind do, but what is doing the holding, what does the holding cost, and what happens when the bill comes in higher than the account.
Everything here rests on one premise. Uncertainty is not a problem to be solved. It is the medium. Uncertainty is constant change in every unit of change — take any unit you like, however fine, and that unit is changing too. There is no still frame anywhere. What I do not know will always exceed what I know. I call that the Null Hypothesis.
Four pieces of the framework follow from it and this paper uses all four. The Sphere of Ordered Experience maps how experience gets ordered. The Inner House says the mind is plural — seven Residents, each with a question, all present from birth. The Navigation Loop is what the house does: Sense, Interpret, Act, Reflect, Update, Orient. The Binary Outcome Framework is a discipline against lying to yourself under uncertainty, not a way of picking the best option.
Enough of each is given here to follow the argument. The full account of any of them is elsewhere: The Null Hypothesis, The Sphere of Ordered Experience, The Inner House, The Navigation Loop, and — for the Binary Outcome Framework — The Brake Not the Calculator. The developmental account is in Beyond Erikson.
This paper asks one thing of all of it. What is the difference between a mind that is working and a mind that is not?
I tried three obvious ones first. All three fail, and getting rid of them is most of the job.
It is not that the alarm is too loud. Nesse worked this out. If a false alarm is cheap and a missed threat kills you, the best system is one that goes off constantly. Not a broken system. The best one. Haselton and Buss say the same thing more generally: where the costs of being wrong have been lopsided for long enough, what gets built is a biased detector, not a fair one. So an alarm going off when nothing is wrong is the machine working.
It is not that vigilance has taken over. Cacioppo's model treats positive and negative as two separate channels rather than two ends of one dial, and it expects them to run at the same time. You can be mildly open to the world and watchful in the same moment. That is ordinary.
And it is not that the question never got answered. This one my own premise forbids. If everything is changing in every unit of change, then am I safe is a question about ground that moves while you are standing on it. Nothing settles it. If never settling were the illness, everyone has it, permanently.
Three gone. Each one was something I would have reached for.
Trust asks: am I safe.
I think its resting position is I am not safe, and that it spends its time hunting for reasons to feel safe. Left alone it is screaming. It has to be calmed down by the others.
Watch the word negative there, because I nearly used it myself. I am not safe is not negative. It is the correct setting for something whose job is keeping you alive. The smoke detector already showed us that. Call it negative and within a paragraph you are treating the alarm as the thing to get rid of.
There is a simpler argument underneath. Anything that asks a question does not already have the answer. If Trust sat at I am safe, there would be nothing to ask.
This does not spread evenly across the seven, and the questions split by shape. Am I safe, do I choose this, and can I be truly seen can each hold a position waiting for a verdict. What can I try, what must be done, who am I, what am I building — these can be answered or not answered, but there is nothing for a negative to stick to. Only a closed question can have a stance. That is grammar, not preference.
And the closed three do not behave alike. Only Trust makes a claim. Autonomy sits nearer I am not sure I chose this. Intimacy sits nearer I do not think I can be truly seen. Those are doubts. A doubt is settled by supplying the missing comparison, which is cheap. A claim has to be argued with, which is not.
Two cuts run through the house and they do not line up. I have wasted time treating them as one cut, so here they are side by side.
| Resident | Question | Register | Shape |
|---|---|---|---|
| Trust | Am I safe? | pre-verbal, pre-logic | closed — a claim |
| Autonomy | Do I choose this? | trans-verbal | closed — a doubt |
| Initiative | What can I try? | verbal (early) | open |
| Industry | What must be done? | verbal | open |
| Identity | Who am I? | verbal | open |
| Intimacy | Can I be truly seen? | verbal | closed — a doubt |
| Generativity | What am I building beyond myself? | verbal | open |
Intimacy is the only closed question in the verbal register. It is the only one you can speak to that also has something of its own at stake. That turns out to matter.
Trust is the only one that is completely pre-verbal. Words do nothing to it.
Autonomy is trans-verbal, and it is the only one. The signal arrives and is understood as signal. The meaning is not reliably built. It is a period of intense comparative reality analysis — the child is checking what was said against what actually happened. Trans-verbal is a word I made up while writing this and I am keeping it. I mean trans as in across, not as in passing through.
The other five are verbal. Initiative is early but it is fully verbal. Meaning gets built.
That last correction matters more than it looks. Initiative is verbal and its question is open, so words answer it — you can tell someone it is all right to try, and it lands. Autonomy is trans-verbal and its question is a doubt about authorship, which only the person can settle. Permission can be given in words. Authorship cannot.
I did not see this one coming. The registers do not change. I had already written that Trust stays pre-verbal for life and that what develops is the account of it. But my whole framework says nothing is acquired at any stage — and a Resident changing register would be the biggest acquisition in it. So if it is permanent for Trust it is permanent for all of them. Autonomy is trans-verbal at fifty. Not only at two.
There is a second thing about Trust I have never written down, although it has been sitting in my own material for years. Trust is pre-logic.
And it is not a second property. It follows from the first. Reasoning needs something to reason in. Propositions, relations between them, and steps from one to the next all require a symbolic medium, and the medium is language. Take the words away and there is nothing left for an argument to be built out of.
So Trust being pre-verbal is the whole of it, and pre-logic falls out. It runs no inference. It weighs no probability. It holds no counterfactual. Not because those were separately withheld from it, but because it has nothing to do any of them with.
Which is why what can we do about that does nothing when it is offered to Trust. It is a problem-solving move, and problem-solving is logic. So is what is the worst that could happen. So is how likely is that, really. Every one of them is addressed to something that cannot receive it.
I have been saying the principle for years without naming it. You cannot fix a Basement feeling with your thinking brain. No amount of reasoning makes you stop being scared. You need a hug and a night-light. That is pre-logic, and I never called it that.
It also explains why showing works when arguing does not. A demonstration is not an inference. Being seen and not dropped is not an argument that you are safe. It is a present fact about the room, and a present fact is the only thing Trust reads.
This turns the registers into something more useful than a description. If reasoning needs language, then what each Resident can do is set by what language reaches it. No words at all, and there is only a present state to read — Trust. Signal without reliable meaning, and there is comparison: hold what was said against what was arranged and see whether they match — Autonomy. Full meaning, and inference becomes available — the other five. State, comparison, inference. The register is not a fact about the Resident alongside its operation. The register is why it has that operation.
One objection I should meet, because it is the obvious one. Infants who cannot speak will look longer at something physically impossible, which looks like holding an expectation and noticing it broken. Is that not reasoning without words? I do not think so. Noticing a mismatch is a comparison, and a comparison is not an inference. It is the middle tier, not the top one. But it is the test: show me genuine inference in something with no language and this falls over.
I do not like where that goes, and I think it is right.
You cannot tell an adult that they have a choice. They hear you. They understand the words. The part that decides whether it is true does not build meaning out of words — it compares what you said against what is actually arranged, and it believes the arrangement.
Which explains something that has puzzled me for years. Clever, articulate people, told plainly that they have options, and nothing moves. They are not being stubborn and they have not misunderstood. The sentence landed somewhere that does not do sentences.
It predicts something I have watched many times. A person agrees to something out loud, signs it, means it — and still feels they had no say. The agreement went to the parts that take words. Autonomy went and looked at the arrangement, found no choice in it, and was not interested in the signature.
At the trans-verbal stages, words are doing a second job they later stop doing. Checking a signal against what happens is Interpret being calibrated. So a word that does not match what happens does not just mislead once. It damages the mapping between words and reality. That is a structural reason for being careful what you say to a three-year-old, rather than a moral one.
I left this vague for years. The other Residents was all I had. It turns out I had already named the mechanisms and not noticed what I had named.
The Structural Anchor is the world staying where you left it: your home, your routine. The Behavioural Anchor is your body — sleep, food, movement, the things it does regardless of what your mind is doing. The Emotional Anchor is the one person whose presence tells Trust you are not alone. The Identity Anchor is the sentence that holds your story together: I am someone who…
That is from the Navigational Console, the first thing I ever built. Read it again and it is not a list of comforts. It is a list of reassurers.
| Anchor | What it is | Needs a Resident online? |
|---|---|---|
| Structural | the world staying where you left it | no |
| Behavioural | your body — sleep, food, movement | no |
| Emotional | Intimacy — one person's presence | yes |
| Identity | Identity — I am someone who… | yes |
This answers something I could never account for. Reassurance is effortful and it collapses under load — when someone is exhausted the Residents that do it have gone offline. But the top two rows do not need a Resident. The body reassures Trust directly, in the only language Trust has. Breathing. Food. Sleep. Feet on the floor. A hand on something solid. That is not the small thing you offer when the real interventions are unavailable. It is the only thing still working at the moment it is most needed.
It also explains why reassurance fails, and there are three separate reasons, which I want kept apart.
Wrong register. Words do not reach Trust.
Wrong effect. The reassurance literature is blunt about this: relief is brief, and seeking it stops the feared thing being disconfirmed. In obsessive-compulsive disorder the reassurance itself gets read as proof — if I need this much reassurance, something must really be wrong.
Wrong authority. You are safe is a claim about the world, and nobody is the authority on the world.
Which is why I see you can land where you are safe cannot. It is not aimed at Trust at all. It is aimed at Intimacy, in words, which Intimacy takes. And it is a statement about me, not about the world — and I am the authority on me. It can be checked in the room.
This is the most useful rule in the paper. A closed-question Resident cannot reassure anything until its own question has been answered. Ask it to while its own doubt is open and you have one alarmed part trying to calm another. I see you answers Intimacy's own question first. That is what frees it to work on Trust. So the order matters: answer the reassurer, then reassure.
Every Resident is answered by doing. Not by deciding. Not by being told.
So Industry is the key, because Industry is the one asking what must be done. It is the part that turns any other Resident's question into a task.
But they do not all take the same amount of doing.
| Resident | What answers it | How much |
|---|---|---|
| Initiative | having tried | one attempt |
| Autonomy | a task pointed at what you actually want | one, but it must carry direction |
| Identity | I am someone who… | a pattern — many, over time |
| Intimacy | being seen and not dropped | repeated; once is an event |
| Generativity | something that outlasts you | never finished in your lifetime |
You cannot decide who you are. That is why the Identity Anchor is a sentence about what you have done and not a description of yourself.
Industry cannot work from nothing. What must be done needs a heading and a position. Direction gives the heading. But if nothing has been done there is no position, and the question has nowhere to bite. That is not Industry failing. There is genuinely nothing to calculate from.
That is what the Next True Step is for, and it is why a tiny step works when a big one does not. The step is not there to make progress. It is there to make a position. Do one thing and now there is a here. Heading plus here gives you the next move, and Industry is working again.
A big step would wake Trust. Trust would take the house. Then there is no Industry to restart.
The step is a spark, not a replacement.
Which is why there are three parts and not one. The Next True Step strikes the spark — small enough not to wake Trust, real enough to make a position, pointed enough that Autonomy can see it is theirs. The Containment Window puts a fence round it, so the promise stays reversible and the frightened parts can be told it is only ten minutes. The Review Moment reads the new position; without it you have moved and still do not know where you are standing.
Then Industry picks the next step, and it runs by itself.
I will not pretend that is not tidy. And that is why there are exactly three is the shape of an argument I distrust in other people. What I will say is that each part breaks something different when you take it out.
Put together: Trust runs all the time at a resting position of alarm, asking a question the world guarantees it cannot answer. The others reassure it, through four anchors — two of them Residents, two of them the body and the world. The reassurance costs. Industry turns the house's questions into tasks, which is the only way any of them get answered, and needs a heading and a position to do it. The Loop supplies the position, one turn at a time.
That is a mind being held, not a mind at rest. It is doing work to stay where it is.
Medicine almost never draws this line sharply. What does the work is compensation. A failing heart doing several abnormal things that keep the blood moving is compensated, and the patient is out shopping. Decompensation is when those things run out. The abnormal finding was never the disease.
This is what the paper is for. Reassurance is compensation. The alarm is not the illness. The failure of the reassurance is. Which means pathology is not a state of Trust at all. It is a state of the house that holds Trust.
That handles the case that breaks a simpler answer. Someone with severe obsessive-compulsive disorder who holds down a job and raises children is navigating. On a pure can-they-function test they are not ill, which is obviously wrong. A cardiologist would not be confused for a second. They are compensated, expensively, and burning reserve. The reserve is the thing to worry about, not the symptom count.
It also gives the line a shape. My own console already uses it: red when the load is greater than the capacity. Not can you move — at what cost, against what you have. That makes it a ratio, not a threshold, which fits a framework that threw out two-pole scales everywhere else.
And it separates two things that look identical across a desk.
Stalled is Industry with no position to calculate from. The Next True Step is exactly right and it will work.
Spent is capacity gone. Striking sparks into an empty tank does nothing, and each failed attempt adds load.
Stuck and spent walk in looking the same. One needs a step. The other needs the step not to be asked for yet.
Anxiety is what sent me looking, so it is the fair test.
On this account: Trust is activated and leading, running its question against ground that will not hold still, with the reassurance absent or not enough. That is all. It is not a malfunction of Trust. Trust is working.
Unreassured Trust doubles the load. So capacity can read normal while the capacity actually available is halved. That is why anxiety is exhausting on a day when nothing happened.
This may be why it lasts. Reassurance is effortful and collapses under load, and the parts that do it go offline when someone is tired, hungry, unwell or overwhelmed. So the alarm raises the load, the load takes the reassurers offline, and fewer reassurers means more alarm. It feeds itself. That would explain how one bad afternoon becomes eight months without needing a separate mechanism for persistence — and why taking load off anywhere at all, even something unrelated, helps far more than it looks like it should.
Whatever they tell you it is about was written afterwards by the Archivist and is not the cause. Which is why the reasons shift, and why some people cannot give one at all. I have always taken that as a sign they were not looking hard enough. I think now it is a sign the account had not been written yet.
And the alarm has no tense. There are no still frames in uncertainty, and before and after need fixed points to sit between. Material gets ordered into the field, Trust reads the field, and the alarm is now. Next Tuesday is a label the Archivist adds. My framework was already tenseless everywhere else and I had not noticed: Direction is a pull you have now, not a goal ahead; irreversibility is a property of an act, not a prediction; Ground Status is a reading taken now; and I had already written that the Loop's six operations are not segments of time that happen one after another, that they are all running all the time, and that one of them is leading.
I asked for the research that would kill this, and it belongs here rather than in a footnote. Anything else is advertising.
The strongest thing against me is anatomical. The bed nucleus of the stria terminalis keeps responding to threat that is uncertain in time, while the amygdala fires briefly at threat that is here now. The split is replicated and it sits at the centre of anxiety research. If the future were only a label, a dedicated structure for sustained anticipation takes some explaining.
I notice that those studies vary unpredictability, not distance in time — which would make it an uncertainty detector rather than a future detector, and that would suit me very well. Which is exactly why I should not be allowed to say it without committing to a test first. So: does that structure respond to a threat that is certain but far away? If it does, time is real to the system, and the strong version of what I have written here fails.
Seligman and his colleagues argue in Homo Prospectus that the mind is drawn by the future rather than pushed by the past, and that looking ahead is the whole point of us. That is a flat contradiction of what I have said. I note that their machinery is the same constructive simulation that supports my side, and that the two may be one mechanism described from opposite ends. I note it. I do not claim it settles anything.
Attachment rates sit against the resting-position claim. The biggest meta-analysis — 285 studies, more than twenty thousand pairs — puts secure attachment at 51.6 per cent, the largest single group. If mistrust were the baseline, a majority landing secure is awkward. I weigh it less than the other two, because that measure classifies a relationship rather than the resting state of an alarm, but I am not dismissing it.
The general factor of psychopathology goes after the structure rather than the resting state. If one dimension fits the data better than separate ones, then Residents with structurally different illnesses is a harder position to hold.
Two corrections on my own side, which I would rather print than quietly drop. I took Cacioppo's positivity offset — that positivity wins when almost nothing is coming in — as a refutation of my own claim. It is not, because his model treats the two as separate channels that can run together, and I had assumed a single dial. And I leaned briefly on Schachter and Singer's misattribution of arousal, which has failed replication in its strong form.
What came through every attempt to knock it down was the structural work, not the interpretive work. There is no instantaneous now — the present is a built window of two or three seconds. Remembering and imagining are one process running on one network. Neither of those depends on a contested construct. I take that as a lesson about where to look, not as a win.
Whether this is circular. If the test is can they navigate, and illness is cannot navigate, that says nothing unless load and capacity can be measured apart from it. My console measures them by asking the person. Good enough for an instrument. Probably not good enough for a claim about illness.
Where suffering goes. Someone can be compensated, inside their capacity, and in agony. A functional test says that is not pathology. Forty years says otherwise. I cannot reconcile them.
Whether the quiet one exists. This predicts an illness that does not look like one — low alarm, enough capacity, and a position that no evidence ever shifts. It would not present as distress. I do not know whether I have been seeing that person for years or whether the prediction is simply wrong.
Whether reassurers can be recruited on purpose or only arranged for. If recruited, there is a technique. If only arranged for, the work is environmental and a lot of talking is beside the point.
Whether anything at all reaches Autonomy in words. Nobody else can answer do I choose this, and the register is wrong on top of that. If that is right, Autonomy is reached by arrangement alone — and a great deal of consent practice is addressed to the wrong part of the person.
And whether compensation is one thing or two. Reassurance failing and Industry stalling are different failures in different places. I have kept them apart all through this paper, because running two mechanisms together is the mistake I make most. Whether they really are two, I cannot yet show.
Three things this paper does not attempt. What the reassurance looks like at each stage, now that the registers turn out to be fixed. How gating and rotational leadership relate, which are two mechanisms and not one. And whether decompensation has kinds, or only degrees.
Nesse RM, The smoke detector principle, Annals of the New York Academy of Sciences 2001; Evolution, Medicine and Public Health 2019.
Haselton MG and Buss DM, Error management theory, Journal of Personality and Social Psychology 2000.
Freeston MH and Komes J, Revisiting uncertainty as a felt sense of unsafety: the somatic error theory of intolerance of uncertainty, Journal of Behavior Therapy and Experimental Psychiatry 2022.
Cacioppo JT and Berntson GG on the evaluative space model; Ito TA and Cacioppo JT on individual differences in the positivity offset and negativity bias.
Mikulincer M, Dolev T and Shaver PR on attachment-related strategies during thought suppression.
Higgins ET, Promotion and prevention: regulatory focus as a motivational principle, 1998.
Berlyne DE on curiosity and the exploratory drive.
Halldorsson B and Salkovskis PM and colleagues on reassurance seeking in obsessive-compulsive disorder and health anxiety.
Schacter DL and Addis DR, On the constructive episodic simulation of past and future events, Behavioral and Brain Sciences 2007.
Pöppel E on the specious present; James W, The Principles of Psychology, 1890.
Avery SN and colleagues on phasic and sustained responses in the amygdala and bed nucleus of the stria terminalis.
Seligman MEP, Railton P, Baumeister RF and Sripada C, Homo Prospectus, 2016.
Peters J and Büchel C, Episodic future thinking reduces reward delay discounting, Neuron 2010.
Caspi A and colleagues on the general factor of psychopathology.
Meta-analytic distribution of attachment classifications, 285 studies.