Proposal‑based controllers—learned policies, language‑model planners, and other black‑box generators—are increasingly deployed behind runtime verification gates. We ask when the closed‑loop safety guarantee can be decoupled from the generator. The prevailing per‑candidate certification pattern does not compose: under retry or best‑of‑$k$ selection a per‑candidate false‑admission level $\alpha$ inflates to $1-(1-\alpha)^{k}$.\
Main theorem shows that simultaneous setwise soundness—certifying a set of admissible proposals that contains no non‑viable action—is necessary and sufficient for generator‑independent admission soundness. This guarantees that, in the worst case over all generators, the probability of executing a non‑viable proposal equals the probability of setwise failure. Combined with a design‑time certificate and a no‑bypass rule, it is sufficient for contract safety, with violation bound $\Gamma+\sum_{t}\varepsilon_{t}+\eta$ invariant under arbitrary (even adversarial) generator replacement.\
Second theorem bounds any admission mechanism under partial observation: for a fixed probing and admission policy, if two state hypotheses whose information laws lie within total‑variation distance $\delta$ require different safe decisions, then $\bar{a}+\beta+\delta\ge1$.\
At the implementation level, a sequential risk ledger together with time‑uniform confidence tubes makes the guarantee realizable and shows that deterministic admission computations concentrate all statistical risk in state estimation. Simplex‑style runtime assurance and control‑barrier‑function filtering emerge as degenerate cases of the framework.\
Review