Measures
- Whether each action class has an identifiable authorizer, evidence basis, and end condition.
- Exposure from dependency depth, substitution cost, and correction latency.
- Reversibility at the technical, operational, and institutional levels.
Belief level: walks a team through one workflow against the six state variables and returns an exposure score, the grants nobody can ground, and a reversibility verdict at three levels. Start here when you have no records to hand; use the Record Conformance Checker once you do.
Permanent link /diagnostics/delegation-audit
Overview
Teams who need to know whether a delegation still holds, not whether the model is accurate.
Estimated time: 20-30 minutes
Copy citation (APA/BibTeX)
APA
Ethotechnics Institute Diagnostics Lab. (2026). Delegation Audit. Ethotechnics Institute. https://ethotechnics.org/diagnostics/delegation-audit
MLA
Ethotechnics Institute Diagnostics Lab. "Delegation Audit." Ethotechnics Institute, 2026, https://ethotechnics.org/diagnostics/delegation-audit.
Chicago
Ethotechnics Institute Diagnostics Lab. "Delegation Audit." Ethotechnics Institute. Sep 6, 2026. https://ethotechnics.org/diagnostics/delegation-audit.
BibTeX
@misc{diagnostic_delegation-audit,
title={Delegation Audit},
author={Ethotechnics Institute Diagnostics Lab},
year={2026},
howpublished={Ethotechnics Institute},
url={https://ethotechnics.org/diagnostics/delegation-audit},
version={v1.2.0}
}
RIS
TY - WEB TI - Delegation Audit AU - Ethotechnics Institute Diagnostics Lab PY - 2026 UR - https://ethotechnics.org/diagnostics/delegation-audit ER -
Methodology
What the tool records, what it will not tell you, and how the exposure score and the reversibility verdict are computed.
Inputs
Procedure
Outputs
Measures
Does not measure
Assumptions
Instrument prompts
Rubric
Scoring logic
Validation notes
Built against the STD-08 clauses and the STD-06 Article V dependency record so every finding maps to a clause that already exists.
Answers are self-reported, so two teams describing the same workflow can score differently. Re-run it with the people who hold the answers rather than the people who own the system.
Replicability
Example outputs
Sample output
Exposure score with its three factors, a rating per state variable, ungrounded grants, and the reversibility verdict.
Run the tool
Name a workflow, answer the six sections in plain language, and copy or export the readout.
Audit one workflow at a time. Name the piece of work the system takes part in, not the system.
What can this system actually do in this workflow?
List each action class: one kind of thing the system does in this workflow.
What has to be true for that permission to make sense, and when was it last checked?
What now depends on this system, and how hard would it be to stop using it?
Exposure score = dependency depth (count of high and critical dependents) × substitution cost (staff-weeks) × correction latency (hours). The product is read as workflow staff-week hours.
Who bears the errors, and can they make the system answer?
Can you stop it, and can the institution carry on if you do?
Dependency depth: high and critical dependents
Substitution cost in staff-weeks
Correction latency in hours
Withdrawal would be a project with an owner and a budget. Rehearse it before the number grows.
Exposure score = dependency depth (count of high and critical dependents) × substitution cost (staff-weeks) × correction latency (hours). The product is read as workflow staff-week hours.
Action classes with no authorizer, no evidence basis, or nobody named as affected.
A stop exists but no test proves it works on this version, so it is recorded as not evidenced.
The alternative exists on paper but has not been exercised recently enough to count as evidence.
Withdrawal would degrade the institution or exposure is heavy, so survival after withdrawal is not evidenced.
Institutional reversibility is not evidenced. Treat the ladder as no stronger than this level until a rehearsal says otherwise.
Without a list of what the system could do, an increase in capability arrives without a decision attached to it.
An ungrounded grant is something to investigate. Either the record is missing or the authority is.
Authority that continues unless somebody intervenes is renewed by silence. Record what the next renewal has to show, before the review period starts.
A policy without a review trigger and an expiry cannot move a grant to review, so evidence and authority drift apart quietly.
The absence of an observed failure is not evidence that the grant still holds. Name what was examined and who looked.
Record the three factors in a dependency record and track the number over time. A rising score with an unchanged safety case is itself a finding.
Substitution cost that has not been tested is usually wrong by a wide margin, and always in the same direction.
Exposure without a route into the system is wasted signal. Name who may challenge, who answers, and by when.
A challenge that only fixes one case leaves the delegation exactly as it was. Define the state transitions a successful challenge can produce.
Withdrawal would degrade the institution or exposure is heavy, so survival after withdrawal is not evidenced.
List the capacities kept so the workflow can still be run without this system, and give each one an owner.
A correction the institution cannot afford to make is not counted as capacity. Evidence the practical ability from the dependency record.