Applied

Four ways out, and what each costs

An impossibility theorem lists conditions and says no rule has them all. That leaves exactly as many escapes as there are conditions, each of them a real institution — a dictator, a two-stage procedure, a supermajority, a restricted agenda — and each escape's price can be counted rather than argued about.

Worth reading first: No rule escapes the doctrinal paradox · Deciding the premises or the conclusion.

The rung below this one exhausts every rule that treats the judges alike and every proposition alike, and finds that none of them is both decisive and coherent. That is a complete answer to the question it was asked and no answer at all to the question a body actually faces, which is what to do on Tuesday.

An impossibility theorem is a list of conditions with the word and between them. Denying the conjunction is exactly as strong as saying that at least one has to go, and the theorem says nothing about which. So a theorem with four conditions has four escapes, and the interesting work is entirely in what each one costs.

Each escape below is a rule somebody uses. Each is run here over every profile of the agenda, and each condition it keeps or breaks is a search result rather than a claim.

Five rules, and the one condition each of them gives up. A table with one row per aggregation rule and one column per condition, marking which conditions each rule satisfies when run over every profile of the agenda.
Fig. 1 Five rules, with all 64 profiles of three judges run through each and every column decided by that sweep. Plain majority fails consistency, which is the impossibility. The other four are consistent and each gives up exactly one of the remaining conditions — anonymity, systematicity, completeness, or being defined on every profile.

The agenda, and what a rule is

The setting is the smallest one in which the paradox occurs. There are two premises and a conclusion that is their conjunction: each judge accepts or rejects each premise, and must accept the conclusion exactly when they accept both premises. So a judge has four possible positions, and a body of three judges has 64 profiles.

A rule takes a profile and returns the body’s collective verdict on the three propositions. It is consistent when its verdict on the conjunction agrees with its verdicts on the premises. It is complete when it takes a view on all three.

The conditions the theorem uses are two more:

Anonymity — permuting the judges never changes the output. Nobody’s vote counts more than anybody else’s.

Systematicity — the verdict on a proposition depends only on which judges accept it, and in the same way for every proposition. This is the strongest of the four and the one whose content is easiest to miss: it forbids the body from treating the conclusion differently from the premises, even though the conclusion is a different kind of thing.

16 rules, and none that survives. A table of every systematic anonymous aggregation rule for 3 judges: one row per rule, showing the verdict it gives at each count of yes-votes, whether it decides every proposition, and whether it is consistent. No row has both.
Fig. 2 The theorem being escaped. Every rule that treats the judges alike and every proposition alike is a verdict for each possible count of yes-votes, so there are 16 of them at three judges. Some take a view on every proposition and its negation; some never contradict themselves; and none does both.

Give up anonymity: a dictator

The crudest escape is to let one judge decide everything. The collective verdict is that judge’s verdict, on all three propositions.

This is consistent — trivially, because the judge is consistent. It is complete, systematic and defined on every profile. It fails anonymity and nothing else, which is what makes it a genuine escape rather than a joke: the theorem is exactly strong enough to force a dictator once the other three conditions are insisted on.

That is worth stating carefully, because it is the same shape as Arrow’s theorem and the resemblance is not an accident. In both cases the conditions are so nearly sufficient to pin down a rule that the only survivor is the one nobody wants. An impossibility theorem whose only escape is a dictatorship is really a characterisation theorem in disguise, and reading it that way is more informative than reading it as a prohibition.

The price is obvious and is worth naming precisely anyway. A dictatorship is not bad because it is unfair in some general sense; it is bad because the body’s verdict carries no information about anybody but one member, so convening the others is pointless. Every other escape below preserves the property that the collective output depends on more than one judge.

Give up systematicity: decide the premises first

The rung below sets out the two procedures a real court chooses between, and the premise-based one is an escape from this theorem.

Take the majority verdict on each premise, then derive the conclusion. The result is consistent by construction — the conclusion is computed from the premises rather than voted on — and it is complete, anonymous and defined everywhere.

What it gives up is systematicity, and precisely: the conclusion’s verdict does not depend on which judges accept the conclusion. A judge who accepts both premises and is therefore committed to the conclusion has their conclusion-vote ignored, because the rule never looks at it.

Where the two procedures part company. A table of 3 judges' verdicts on two premises and the conclusion each is committed to, with the two majorities at the foot disagreeing about the conclusion.
Fig. 3 The profiles on which the two procedures part company, counted over every consistent assignment of positions to judges. The disagreement is not a curiosity of one famous case; a definite fraction of profiles produce it, and the fraction is counted here rather than asserted.

The cost is a collective judgement nobody holds. On the classic profile, a majority accepts each premise while a majority rejects the conclusion, and the premise-based rule announces the conclusion anyway — a verdict that every member of the body would have voted against. Whether that is a defect depends on whether the body’s product is its reasoning or its decision, which is the whole subject of the rung below and is not settled by any theorem.

Give up completeness: raise the bar

The third escape keeps every judge equal and every proposition alike, and buys consistency by allowing the body to say nothing.

A quota rule accepts a proposition when at least qq judges accept it and rejects it when at least qq reject it. When neither, it takes no view. Majority is the quota at just over half; unanimity is the quota at all of them; and everything in between is a supermajority.

Consistency against decisiveness, over every quota from 1 to 5. A pair of bars for each quota rule, one counting the profiles on which the rule is inconsistent and the other the profiles on which it declines to decide.
Fig. 4 Every quota from 1 to 5, run over all 1024 profiles of five judges. The contradictions run out at a quota of 4 and the silences climb to 900 — so consistency is bought with decisiveness, and the exchange rate is measured here rather than asserted.

The sweep says something a statement of the theorem does not. The two counts do not trade smoothly: the inconsistencies are 180, 300 and 150 as the quota climbs to three, and then at a quota of four they are 0 — and the silences jump from none to 900 of the 1024 profiles in the same step. The escape is not a dial. It is a cliff, and a body adopting it is not choosing a point on a curve but accepting near-total silence in exchange for coherence.

That is why supermajority requirements in real institutions are nearly always attached to a default. A constitutional amendment needs two thirds and fails otherwise; a jury must be unanimous and the alternative is a mistrial. In both cases the rule is silent on most profiles and the institution supplies an answer from outside the rule — which is honest, and is the thing the theorem cannot see, because the default is not a function of the judges’ votes at all.

Give up universal domain: restrict what may be asked

The fourth escape changes neither the rule nor the conditions. It changes which profiles the body is permitted to face.

A profile is unidimensionally aligned when the judges can be arranged in some left-to-right order such that, for every proposition on the agenda, the ones accepting it sit at one end — a block at the left or a block at the right, never a group in the middle with dissenters on both sides.

On such a profile, plain majority is consistent, and the reason is short. A block at one end containing more than half the judges must contain the middle one. So the majority verdict on every proposition is the middle judge’s own verdict, and that judge is a person with a coherent position. The collective is a member.

634 of 1024 profiles line up, and majority is safe on all of them. Three bars splitting every profile of the agenda into the aligned ones, the ones on which majority happens to be consistent without being aligned, and the ones where it fails.
Fig. 5 All 1024 profiles of five judges, sorted by two questions. 634 are aligned and majority is consistent on every one of them; a further 240 are not aligned and majority happens to be consistent anyway; the remaining 150 are where the paradox lives. Alignment is sufficient and not necessary, which the search establishes and the statement of the theorem does not.

The gap between 634 and 874 is the interesting number in that figure. Alignment is a sufficient condition, comfortably stronger than what majority consistency actually needs, and nobody has a usable description of the exact boundary. A body relying on domain restriction is therefore relying on a condition it can check and that is stricter than the one it needs — which is the normal situation with domain restrictions and is worth knowing before trusting one.

Reading the cliff

The quota sweep has a shape that no statement of the theorem predicts, and it is worth reading rather than skipping.

The inconsistencies do not fall steadily as the quota rises. Over five judges they go 180, then 300, then 150, and only then to zero. A quota of two is worse than a quota of one, which sounds impossible until one asks what each rule does.

At a quota of one, a proposition is accepted the moment any judge accepts it — and rejected the moment any judge rejects it, so on most profiles the rule contradicts itself immediately by accepting and rejecting the same thing. The figure counts a profile as inconsistent when the verdict on the conjunction disagrees with the verdicts on the premises, and at a low quota the rule accepts nearly everything, which agrees with the conjunction more often than a middling quota does. At a quota of two the rule accepts the premises easily and the conjunction less easily, and the mismatch between those two thresholds is what the middle of the sweep is measuring.

The maximum in the middle is the whole mechanism of the paradox, seen as a graph. The doctrinal paradox is a gap between how hard it is to carry each premise and how hard it is to carry both, and that gap is widest when the threshold is high enough to bite on the conjunction and low enough not to bite on the premises. Push the threshold to the top and both become equally hard — unanimity on the premises is unanimity on the conjunction — and the gap closes.

That reading also says why the closure is abrupt rather than gradual. The gap vanishes only when the threshold reaches the point where carrying a premise and carrying the conjunction are the same requirement, and there is exactly one such point.

A fifth move, and what it says about the list

The four escapes are four because the theorem names four conditions. Add a condition nobody wrote down and a fifth escape appears, which is worth doing once to see how the accounting works.

Pick a judge at random and take that judge’s verdicts. The result is consistent and complete; it treats every proposition alike; and it is anonymous in the only sense a randomised rule can be, since permuting the judges leaves the distribution of outputs unchanged. It escapes the theorem, and it escapes by violating a condition the theorem never states: that the rule be a function of the profile at all.

Determinism is assumed silently in the framing — a rule is a map from profiles to verdicts — so randomisation does not appear in the list of escapes because it was excluded before the list began. That is the general situation with any impossibility result, and it is the reason to read the definitions as carefully as the conditions.

Whether the random dictator is an acceptable institution is a separate question and mostly it is not: a body whose verdict is one member’s, chosen by lot, gives up the same information the deterministic dictatorship does, and adds the objection that it would have decided differently yesterday. It is used in practice all the same, in sortition and in the random selection of a panel, and the strategic case for it is that a rule nobody can predict is a rule nobody can game.

What the escapes have in common

Read the table again with five judges rather than three and nothing moves except the counts.

Five rules, and the one condition each of them gives up. A table with one row per aggregation rule and one column per condition, marking which conditions each rule satisfies when run over every profile of the agenda.
Fig. 6 The same five rules over all 1024 profiles of five judges. Every verdict in the table is unchanged: the dictatorship still fails anonymity alone, the premise-based rule still fails systematicity alone, unanimity still fails completeness alone, and the aligned rule is still the one that is not defined everywhere. The impossibility does not weaken with the size of the body, and neither does any escape from it.

Each escape removes a different kind of thing, and it is worth separating them, because the four are not four points on one scale.

Dropping anonymity changes who the rule listens to. Dropping systematicity changes what counts as one question — the premise-based procedure treats the conclusion as derived rather than voted on, which is a claim about the agenda’s structure. Dropping completeness changes what an output is, admitting silence as an answer. And dropping universal domain changes what the body is allowed to face, which is not a property of the rule at all.

Only the first three are choices a rule-maker can make. The fourth is a bet about the world: it says that the profiles which break the rule will not arise, and nothing inside the theory supports that. When a body is genuinely divided along one dimension the bet is good, and when a new question cuts across the existing division it fails without warning — which is exactly when a body most needs its procedure to work.

Why there are four and not five

A reader who has met several impossibility theorems will notice that the escape list is always the condition list, and that this is a piece of logic rather than a discovery about voting.

The theorem’s content is ¬(ABCD)\neg(A \wedge B \wedge C \wedge D). Every rule satisfies some subset of the conditions and the theorem forbids only the full set, so the maximal survivors are the rules satisfying three of the four. There are four such subsets and each is inhabited — which is what the table demonstrates and is not automatic. A theorem can have conditions that are jointly impossible in several ways at once, so that dropping one leaves the remainder still impossible; here, dropping any one leaves the remaining three satisfiable, and each is satisfiable by something recognisable.

That the four escapes are each realised by an institution somebody uses is the substantive content of this rung, and it is not something the impossibility theorem says. The theorem draws a line; the search says that every point just inside the line is occupied.

The same reading applies to the neighbouring theorems. Arrow’s four conditions escape to a dictator, to Borda-style rules that violate independence, to incomplete social orderings, and to single-peaked domains — the same four kinds of move, on a different agenda. The theorem that a rule can be manipulated escapes to dictatorship, to restricted domains, or to randomisation, which is a fifth kind of move available there and not here.

What the pictures cannot show

Every figure is exhaustive over the profiles of one agenda: two premises and their conjunction. The theorem is about a class of agendas, and which agendas force the impossibility is a real question with a real answer — an agenda does it exactly when it contains a minimally inconsistent subset of three or more propositions — that no figure here establishes.

The rules swept are also not all rules. The escapes table checks five named rules against four conditions; it does not enumerate every rule that gives up anonymity, and the claim that the dictatorship is essentially the only such escape is Arrow-style and is not searched for here.

And the domain-restriction figure counts profiles, which treats every profile as equally likely. A real body’s profiles are correlated in whatever way its members’ views are correlated, so the fraction of aligned profiles under a uniform count says nothing about the frequency of the paradox in practice. It is a statement about the space, not about any body in it.

Where the ladder goes next

Named here as a debt: distance-based rules, which choose the consistent judgement set closest to the majority’s and are the escape this rung does not include — they give up systematicity, like the premise-based procedure, but in a way that treats the propositions symmetrically, and their behaviour on the profiles above is worth measuring.

Also unwritten: which agendas are safe. The characterisation by minimally inconsistent subsets is the real theorem behind all of this, and it explains why a body voting on unconnected questions never has the problem.

Sideways, the paradox this escapes is the first rung, the impossibility it escapes is the second, the two procedures compared in detail are the third, and the cyclic majority that started the whole subject is Condorcet’s.

What is worth carrying away

An impossibility theorem is a menu, and reading it as a prohibition wastes it.

Four conditions cannot hold together. That sentence forbids nothing anybody wanted to do; what it does is enumerate the four families of institution that remain, and the useful work is pricing them. Here the prices are a dictator, a verdict nobody holds, silence on nine profiles in ten, and a bet that the awkward profiles will not arise.

The habit worth taking is to convert each condition into the escape it guards. A condition is worth keeping exactly to the extent that the rules violating it are bad, and that is a question about rules rather than about axioms — so the way to understand a condition is to look at what satisfies everything else and fails it.

The corollary is a warning about the fourth kind of escape. Restricting the domain leaves the rule looking untouched, produces no visible compromise, and is therefore the escape a body is most likely to take without noticing it has taken one. The other three announce their price in the rule itself. This one hides it in an assumption about what will be asked.