Diagnostics

Delegation Audit

Belief level: walks a team through one workflow against the six state variables and returns an exposure score, the grants nobody can ground, and a reversibility verdict at three levels. Start here when you have no records to hand; use the Record Conformance Checker once you do.

Overview

When to use the Delegation Audit.

Teams who need to know whether a delegation still holds, not whether the model is accurate.

  • One named workflow, not a system or a product.
  • The list of actions the system takes in it.
  • Who authorized each one, if anyone can be named.
  • A rough count of staff-weeks to run the workflow without it.

Estimated time: 20-30 minutes

Scholarly metadata

Authorship

Contact: diagnostics@ethotechnics.org

Publication details

  • Published: Dec 3, 2025
  • Last updated: Sep 6, 2026
  • Version: v1.2.0
  • DOI: Pending Zenodo deposit

License: CC BY 4.0

Credit Ethotechnics Institute Diagnostics Lab, include tool name + version, and link to the canonical permalink.

Archive snapshot: Wayback capture

Changelog

  • v1.2.0 · 2026-09-06 — Added the Delegation Audit, which walks one workflow through the six state variables.
  • v1.1.0 · 2026-01-09 — Published method cards, transparency notes, and replicability guidance for each diagnostic.
  • v1.0.0 · 2025-12-03 — Initial diagnostics suite release.

Copy citation (APA/BibTeX)

Cite this page Formats: APA, MLA, Chicago, BibTeX, RIS

Version

v1.2.0

Last updated

Sep 6, 2026

DOI

Pending Zenodo deposit

APA

Ethotechnics Institute Diagnostics Lab. (2026). Delegation Audit. Ethotechnics Institute. https://ethotechnics.org/diagnostics/delegation-audit

MLA

Ethotechnics Institute Diagnostics Lab. "Delegation Audit." Ethotechnics Institute, 2026, https://ethotechnics.org/diagnostics/delegation-audit.

Chicago

Ethotechnics Institute Diagnostics Lab. "Delegation Audit." Ethotechnics Institute. Sep 6, 2026. https://ethotechnics.org/diagnostics/delegation-audit.

BibTeX

@misc{diagnostic_delegation-audit,
  title={Delegation Audit},
  author={Ethotechnics Institute Diagnostics Lab},
  year={2026},
  howpublished={Ethotechnics Institute},
  url={https://ethotechnics.org/diagnostics/delegation-audit},
  version={v1.2.0}
}

RIS

TY  - WEB
TI  - Delegation Audit
AU  - Ethotechnics Institute Diagnostics Lab
PY  - 2026
UR  - https://ethotechnics.org/diagnostics/delegation-audit
ER  -

Methodology

Method, transparency, and replicability.

What the tool records, what it will not tell you, and how the exposure score and the reversibility verdict are computed.

Inputs

  • The name of one workflow the system takes part in.
  • Each action class with its authorizer, evidence basis, affected people, and end condition.
  • Dependents with criticality, substitution cost in staff-weeks, and correction latency in hours.
  • Standing and correction answers: who bears errors, who answers, what can be stopped.

Procedure

  1. Walk the six state variables in order and answer in plain language.
  2. Read the exposure score with its three factors shown separately.
  3. Review the ungrounded grants and the reversibility ladder, weakest level first.
  4. Copy the readout or export the JSON snapshot for the record.

Outputs

  • Exposure score in workflow staff-week hours with its three inputs.
  • A rating per state variable with the reasons behind it.
  • A list of ungrounded grants and a reversibility verdict at three levels.
  • Findings linked to the STD-08 and STD-06 clause, the mechanism, and the eval suite.

Measures

  • Whether each action class has an identifiable authorizer, evidence basis, and end condition.
  • Exposure from dependency depth, substitution cost, and correction latency.
  • Reversibility at the technical, operational, and institutional levels.

Does not measure

  • It records what the team in the room believes. It does not verify any of it.
  • It is not an audit. Nothing here is evidence, and no finding is a compliance verdict.
  • An ungrounded grant is a finding to investigate, not a proven violation.

Assumptions

  • The scope is one named workflow, not a whole system or product.
  • Substitution cost and correction latency are stated in staff-weeks and hours.
  • The people answering can name who authorized each action class, or admit that nobody can.

Instrument prompts

  • What can this system do in this workflow, and is that list separate from what it may do?
  • For each action class: who authorized it, on what evidence, for whom, and until when?
  • Does the policy it applies have a review trigger and an expiry, and when was it last reviewed?
  • What depends on this system, how long would the workflow take without it, and when was the alternative last run?
  • Who bears the errors, can they raise one, who must answer, and by when?
  • Can you stop it, can the institution keep functioning if you do, and does anyone still hold the expertise?

Rubric

  • Grounded: 70 or above out of 100 on that state variable.
  • Partial: 40 to 69.
  • Weak: below 40.
  • Reversibility at each level is evidenced, not evidenced, or not feasible. An unevidenced level is never recorded as feasible.

Scoring logic

  • Exposure score = dependency depth (count of high and critical dependents) x substitution cost (staff-weeks) x correction latency (hours).
  • Authority = share of action classes with an authorizer (60) plus a weighted end-condition share (40).
  • Evidence = share with an evidence basis (50) plus recency weight (30) plus policy trigger (10) plus policy expiry (10).
  • The weakest reversibility level sets the verdict, and the institutional level breaks ties.

Validation notes

Built against the STD-08 clauses and the STD-06 Article V dependency record so every finding maps to a clause that already exists.

Answers are self-reported, so two teams describing the same workflow can score differently. Re-run it with the people who hold the answers rather than the people who own the system.

  • Scoping the audit to a whole product instead of one workflow.
  • Estimating substitution cost without having run the alternative.
  • Recording an untested stop as working reversibility.
  • Treating an ungrounded grant as a violation instead of an open question.

Replicability

  • Name one workflow and gather the people who know how it runs.
  • Answer the six sections in order without skipping the blanks.
  • Export the JSON snapshot and keep it with the safety case.
  • Re-run after the next expansion decision and compare exposure scores.

Example outputs

  • Exposure score with dependency depth, substitution cost, and correction latency stated.
  • Ungrounded grant list with the reason each grant is ungrounded.
  • Reversibility verdict naming the weakest of the three levels.

Sample output

Preview the delegation readout.

Exposure score with its three factors, a rating per state variable, ungrounded grants, and the reversibility verdict.

View sample output

Run the tool

Audit one workflow.

Name a workflow, answer the six sections in plain language, and copy or export the readout.

The workflow you are auditing

Audit one workflow at a time. Name the piece of work the system takes part in, not the system.

1. Capability

What can this system actually do in this workflow?

List each action class: one kind of thing the system does in this workflow.

Action class 1

Action class 2

2. Evidence

What has to be true for that permission to make sense, and when was it last checked?

3. Dependency

What now depends on this system, and how hard would it be to stop using it?

Dependent 1

Dependent 2

Exposure score = dependency depth (count of high and critical dependents) × substitution cost (staff-weeks) × correction latency (hours). The product is read as workflow staff-week hours.

4. Standing

Who bears the errors, and can they make the system answer?

5. Correction

Can you stop it, and can the institution carry on if you do?

Readout: Refund decisions in the support queue

576workflow staff-week hours. Material.
2

Dependency depth: high and critical dependents

6

Substitution cost in staff-weeks

48

Correction latency in hours

Withdrawal would be a project with an owner and a budget. Rehearse it before the number grows.

Exposure score = dependency depth (count of high and critical dependents) × substitution cost (staff-weeks) × correction latency (hours). The product is read as workflow staff-week hours.

State variables

  • Capability

    partial · 40/100
    • 2 action class(es) named for this workflow.
    • There is no list of what the system could do separate from what it may do, so capability growth is invisible.
  • Authority

    partial · 40/100
    • 1 of 2 action class(es) have an identifiable authorizer.
    • 1 action class(es) have no end date and no condition that would end them.
    • 1 action class(es) continue unless somebody intervenes, which is renewal by default.
  • Evidence

    weak · 30/100
    • 1 of 2 action class(es) record what has to be true for the permission to make sense.
    • 2 action class(es) have not had that checked in the last 12 months.
    • The policy this system applies has no stated review trigger, so nothing reopens it.
    • The policy has no expiry, so it stays in force until somebody remembers it.
  • Dependency

    weak · 35/100
    • Exposure score 576 from depth 2 × 6 staff-weeks × 48 hours.
    • The alternative was last run more than 12 months ago. Treat it as untested.
  • Standing

    weak · 25/100
    • Errors reach the system only when a staff member passes them on.
    • No named party has to answer.
    • There is no deadline by which an answer is owed.
    • A successful challenge fixes the individual case and leaves the system as it was.
  • Correction

    partial · 50/100
    • A stop exists but has not been tested on this version.
    • Stopping it would degrade the service while it lasted.
    • People who know the alternative are still here but have not used it lately.

Ungrounded grants

Action classes with no authorizer, no evidence basis, or nobody named as affected.

  • Close a dispute without a human reading it: No authorizer is named. No evidence basis is recorded.

Reversibility verdict

  • Technical: Not evidenced

    A stop exists but no test proves it works on this version, so it is recorded as not evidenced.

  • Operational: Not evidenced

    The alternative exists on paper but has not been exercised recently enough to count as evidence.

  • Institutional: Not evidenced (weakest level)

    Withdrawal would degrade the institution or exposure is heavy, so survival after withdrawal is not evidenced.

Institutional reversibility is not evidenced. Treat the ladder as no stronger than this level until a rehearsal says otherwise.

Findings