Fail Closed
In the absence of established authority, the answer is no.
This is the elevator's pawls written as law, and it is the whole book compressed into one line. Every other article here can be argued over, phased in, scoped, and negotiated. This one is a single bit, and it is currently set wrong almost everywhere. Today, when a system cannot establish whether an action is permitted, it proceeds, because proceeding is what it was measured on and hesitation looks like failure on a dashboard. Reverse the bit. The cost of a wrong no is usually a delay and an annoyed user. The cost of a wrong yes is the rest of this book.
Usually, and the exception belongs here rather than in a footnote, because the sharpest critics of this article will arrive from medicine and emergency response, and on the narrow point they will be right. There are settings where a wrong no also injures and kills: the dispatch queue, the crash cart, the operator with ninety seconds to act. Fail closed does not mean those systems freeze while permission is located. It means something narrower and much harder to evade: in the absence of established authority, a system may not invent its own permission and proceed silently. Emergency authority is still authority. The paramedic who breaks your window is exercising a power that was named, bounded, trained for, and recorded long before the accident, and that is the design being asked for, not the exception to it. Emergency paths, continuity paths, and preauthorized overrides can and should exist. They are granted in advance by a party with a name, scoped to the condition that activates them, and they leave a record that can be examined afterward. What this article forbids is not acting under pressure. It is manufacturing permission out of momentum and calling the silence consent.