The authority map
Formal authority and practical capacity, mapped separately, role by role. Where they diverge, power has reconcentrated without any change to the constitution.
Who can actually do what the org chart says someone can?
What Ethotechnics supplies to scholars who already hold the values, to governance mechanisms it does not replace, and to the counterpositions that would make it unnecessary overhead. A dated research note with six worked examples.
On this page
Read this first
A dated research note mapping what Ethotechnics supplies to three audiences it does not command: scholars who already hold the values, governance thinkers who prefer a different mechanism, and the counterpositions that would make the framework unnecessary overhead if they are right.
The name of the note: crossings, because each row is a place where this framework meets work that already exists. At each crossing it supplies an instrument, a completion, or a concession about where the argument is weakest.
One term does the binding work. Counterpower is the capacity that keeps delegated power correctable — the ability, held by someone other than the operator, to halt, reverse, repair, or change what the system does. The framework's claim is not that institutions lack governance. It is that counterpower depreciates: every mechanism that provides it is itself changed by the dependency that prolonged delegation creates, and the depreciation is measurable.
Five capacities
Nine crossings, five capacities. Each instrument is a measurement for one of them.
Formal authority and practical capacity, mapped separately, role by role. Where they diverge, power has reconcentrated without any change to the constitution.
Who can actually do what the org chart says someone can?
Voice, hearing, review, state change, repair, structural change: the rungs an individual correction can climb, and the efficacy gradient between them.
How far up the ladder does one person's correction travel?
Oversight and corrective capacity read as a function of time under reliable automation, O(t), rather than as a property of the org chart.
What does this arrangement's oversight contain at year five?
Reversal simulated, not asked about: halt the system, substitute the vendor, leave the service, and price the procedure in time, money, and who can authorize it.
If this system had to be shut down this quarter, what would it take?
Observed performance decomposed into intrinsic performance and the compensatory human work that bridges the difference: P_obs = C_des + H_comp.
How much of the reported number is work moved onto people the metric does not count?
Crossings
Nine scholar-instrument pairings. The traditions are the scholars' own; the instruments are what the values were missing.
| Tradition | What it holds | What Ethotechnics supplies |
|---|---|---|
| Power-sharing Danielle Allen | A normative account of power-sharing: institutions are legitimate when they distribute the power to shape the decisions that bind people, not only the goods those decisions produce. | Effective-power audit. The measurement the norm needs: formal authority mapped against practical capacity, role by role, so that reconcentration can be detected while the constitution still reads as shared. Delegation audit , Corrective power, glossary , Dependence without standing |
| Right to contest Margot Kaminski, Jennifer Urban | A theory of the individual right to contest AI decisions, and of what the procedural promise in law needs before a contest can function. | Corrigibility ladder. The ladder that specifies the right: voice, hearing, review, state change, repair, structural change, with an efficacy gradient between the rungs. A contest that stops at hearing is a hearing, not correction. Corrective standing, glossary , STD-02 contestability and recourse , Exception learning |
| Contestable AI Kars Alfrink, Neelke Doorn | A design framework for keeping AI systems contestable across their lifecycle: what a system must be like for the people it decides about to condition, control, and contest it. | Contestability-maintenance test. The maintenance question the design framework leaves open: contestability depreciates as dependence grows, and nothing in the lifecycle reads the level. A design built for year one can be unusable by year five. Contestability, glossary , Contestability eval suite , STD-02 contestability and recourse |
| Reviewability Lee Cobbe, Jatinder Singh | A sociotechnical account of reviewability: a decision is reviewable only where a reviewer with the access, competence, and duty to review it actually exists. | Reviewability-to-action bridge. The bridge from review to consequence: observability, reviewability, standing, state-changing authority, structural correction. A review that cannot change anything is documentation. Appeal paths , Standing mechanism, glossary , Law VIII |
| Oversight Samir Passi, Jatinder Singh | A decomposition of oversight into knowledge, observation, control, and timely intervention: the capacities an oversight arrangement must contain to be real. | Oversight depreciation model. The time index those capacities lack. Oversight is read as O(t): what the arrangement contains at year one, and what five years of reliable automation leave of it. Oversight horizon, glossary , Meaningful-control eval suite , The human subsidy |
| Meaningful human control Juri Santoni de Sio, Jeroen van den Hoven | The tracking and tracing conditions: a system is meaningfully controlled when its behavior tracks a human's moral decision and its outcomes trace to a human who could have acted differently. | Effective-control test. The conditions as a test rather than a list: formal control, information, competence, and intervention feasibility, all of them required. Any one missing, and the control is not meaningful however complete the approval chain. Meaningful-control eval suite , Delegated agency, glossary , The sovereign override |
| Moral crumple zones Madeleine Clare Elish | The diagnosis that responsibility for an automated failure collapses onto the operator nearest the point of failure, while control sat elsewhere. | Power-responsibility matrix. The matrix that makes the mismatch legible before the failure: six variables — capability, authority, evidence, dependency, standing, correction — mapped separately for each role, so the single verdict of human error cannot absorb them. Crumple zone, glossary , Insulation , The casebook |
| Resilience engineering David Woods | Adaptive capacity theory: systems stay safe on the spare capacity people spend absorbing surprises, and that capacity is finite and usually invisible until it is gone. | Reserve accounting. The capacity as an account: consumed on one side, regenerated on the other. It separates resilience from performance purchased by depletion — a system can meet every target on a reserve it is not refilling. The consumption of adaptive capacity , Adaptive capacity, glossary , Rescue register |
| Administrative burden Pamela Herd, Donald Moynihan | Measurement of the learning, compliance, and psychological costs a process imposes on the people it serves, and the finding that burden is a policy choice. | Compensated-performance accounting. The decomposition that turns burden measurement on the institution's own numbers: observed performance separates into intrinsic performance and compensatory human work, P_obs = C_des + H_comp. A system that meets its targets on unrecorded compensatory work is not performing better. It is moving the cost. Compensated performance, glossary , Burden dashboards , What outcomes hide |
Worked example 1 · Effective-power audit
Formal authority against practical capacity, role by role, in one emergency department.
An emergency department has run an AI triage assistant for four years. The assistant proposes an acuity level for every arriving patient. The policy adopted at launch says a nurse may override any proposal. The policy has never been amended.
The audit separates formal authority from effective power. Formal authority is what the policy grants. Effective power is what a role can do inside its shift, with its tools, within its working day. The audit maps both, and the gap between them is the finding.
Four questions, each answerable from records the hospital already keeps:
The finding the audit exists to catch: authority that reconcentrates without a single amendment to the constitution. Four years of small, individually reasonable decisions — a vendor contract here, an audit-sampling rule there — moved the thresholds into a file no nurse can read, reviewed by a committee that depends on the vendor's own analysis. The policy still says the nurses govern the acuity levels.
The audit's measure: formal authority and effective power scored separately for each role, and the widening between them read over time. A one-time audit shows the gap. Repeated audits show whether the gap widens — the reconcentration the constitutional language cannot see.
Constructed scenario. The records it reads are ordinary: override logs, screen-flow timings, committee minutes, and the vendor's configuration history.
Worked example 2 · Corrigibility ladder
Six rungs from voice to structural change, and the efficacy gradient between them.
A benefits agency automates its initial eligibility decisions. A claimant receives a denial that is wrong. The ladder asks how far her correction can travel, and what each rung changes.
The gradient: each rung costs her more time than the last, and each rung's benefit shrinks. Rung four is what most institutions call contestability. The ladder's measure is the gap between the rung a policy promises and the rung a claimant can reach.
The casebook supplies the public case. At Robodebt, the tribunal ruled dozens of individual debts unlawful between 2017 and 2019. Each ruling reached rung four: the individual debt was fixed. Repayments are documented for the later 2021 class-action settlement. No ruling reached rung six. The scheme ran until November 2019, when the government conceded a Federal Court case it was about to lose.
Constructed scenario; the public case is not. Robodebt in the casebook →
Worked example 3 · Oversight depreciation
Four oversight capacities, measured at year one and again at year five.
A radiology department has run an AI interpretation assistant for five years. Its error rate at year one was high. At year five it is low. The oversight arrangement has not changed: a radiologist reviews every report the assistant drafts. The test asks what that arrangement contains at year five.
Oversight is read as a function of time under reliable automation, not as a property of the org chart. Four capacities, measured at year one and again at year five:
The mechanism the test is built to catch: reliability consumes oversight. A system that is right 99% of the time for three years reshapes the humans around it — the confirmatory read becomes a skim, the disagreement becomes a workflow exception, and the skill that made disagreement possible thins from disuse. The oversight in the diagram is not the oversight in the department.
The test's measure: at year five, seed the review queue with cases the assistant got wrong, and record whether the reviewer catches them, how long the catch takes, and what her flag changes downstream. That experiment has not been run. The test specifies what would count as evidence.
Constructed scenario. The four capacities follow the oversight decomposition in the crossings table above.
Worked example 4 · Power-responsibility matrix
Six variables mapped separately for each role around one near-miss.
An early-warning system scores every admitted patient for deterioration risk. During one night shift, a patient's condition worsened while her score stayed low. The bedside nurse escalated her manually, and she recovered. Nobody was harmed. The hospital's incident review opens.
The matrix asks one question per cell: at the moment of failure, who held what? Rows are the roles around the failure. Columns are the six variables the casebook scores.
| Role | Capability | Authority | Evidence | Dependency | Standing | Correction |
|---|---|---|---|---|---|---|
| Bedside nurse | Sees the patient | Care only | Holds the ground truth | Works around the false lows daily | None | The case, not the rule |
| Attending physician | Sees the chart | Care and staffing | Sees the score | Treats the score as baseline | Committee seat | Slow |
| Informatics team | Sees the model | Configuration only | System logs | Owns the integration | Escalates to vendor | Patches |
| Vendor | The model only | The thresholds | Aggregate statistics | None in this hospital | The contract | The next release |
| Hospital board | Aggregate reports | Policy and contract | Committee minutes | Contractual, not clinical | None | Committee cycle |
The pathologies the matrix surfaces:
The matrix's point is not that anyone behaved badly. A system failure names six different failures with six different owners, and an inquiry that collapses them into one verdict files them all under the role nearest the bed. That is the crumple zone, produced structurally rather than rhetorically.
Constructed scenario. The variables are the casebook's six: capability, authority, evidence, dependency, standing, and correction.
Worked example 5 · Reserve accounting
Adaptive capacity consumed against regenerated, for one cutover quarter.
A hospital replaced its laboratory information system in one quarter. The lab met its turnaround targets through the cutover. The board's report reads: migration successful, targets met. The balance sheet asks what the targets were met with.
Adaptive capacity — the spare capacity people spend absorbing surprises — is treated as an account. Withdrawals on one side. Deposits on the other.
Withdrawals
Deposits
The balance sheet's measure: reserve drawn against reserve rebuilt. In this quarter, about 180 hours drawn and none rebuilt, and the deposit mechanism — the training rotation — is what the quarter suspended. The turnaround metric reports full target attainment. The balance sheet reports a reserve consumed faster than it regenerates.
The two reports recommend different actions. The metric says repeat the approach. The balance sheet says rebuild the reserve before the next surprise, because a reserve drawn down and not refilled converts resilience into a countdown. The department is now betting on a quarter without surprises.
This is adaptive capacity theory as an instrument. The capacity is real, finite, and invisible until the surprise that needs it. The balance sheet makes the withdrawal visible at withdrawal, not at collapse.
Constructed scenario. Adaptive capacity, its finiteness, and its invisibility are the resilience-engineering findings; the account form is this site's.
Worked example 6 · Compensated performance
What the measured number is made of.
A clinic deploys a documentation assistant. Six months later, a note takes six minutes, down from ten. The pilot reports success.
The equation decomposes the measured number into the performance the system produces and the performance produced by the human work that compensates for it:
P_obs = C_des + H_comp
The measured number is real. The equation's question is what it is made of. Without an H_comp record, the clinic cannot tell a thirty it is buying from a twenty-two it is subsidizing — and the assistant works, and the assistant works when clinicians repair it, are different procurement decisions.
The three repaired after hours have a location and a cost, and neither appears in the pilot's numbers. That absence is the mechanism this framework names: the metric improves because someone caught it, and the catching is on no ledger.
Administrative burden theory prices the costs a process imposes on the people it serves. The equation turns the same measurement on the institution's own performance: the burden is what keeps the number green. The equation is stated formally in the essay on the consumption of adaptive capacity, and the record that would carry H_comp is specified in the burden dashboard pattern.
Constructed scenario. The equation and the record are this site's: performance decomposition, the consumption of adaptive capacity, and burden dashboards.
Eight pairings for people whose preferred corrective mechanism differs. Each addition states what the mechanism's own theory leaves unmeasured, and the record that would show whether it still works.
A mechanism that corrects in year one can be nominal by year ten, because the dependency that prolonged delegation creates changes the mechanism itself. Each completion below supplies the record that would show which of the two is happening.
| Interlocutor | What Ethotechnics adds | What it makes testable |
|---|---|---|
| Adam Thierer Permissionless innovation | Dependency theory. Permission to experiment is not permission to accumulate irreversible dependency. A deployment's dependency profile — switching cost, substitution difficulty, who bears its errors — is a separate variable from the permission that authorized it, and it changes while the permission does not. | Whether an authorization measured its dependency and not only its permissions, and whether the dependency measured at launch still matches the dependency today. |
| Huddleston User sovereignty | An exit specification. Exit is a capacity, not a clause: it takes a substitutable service, portable data and history, a cost the user can pay, and a path that does not also exit the household's insurance, the child's school, or the job. That exit exists and that exit is usable are different claims. | The operational exit test: can a user leave within a stated time and cost, with data, history, and substitutes intact, and does anyone record how often users complete an exit? |
| Chilson Open models | Institutional openness. An open artifact does not guarantee an open institutional future. Weights can stay downloadable while the practice consolidates: the fine-tuning pipeline, the evaluation suite, and the operating expertise concentrate in a few hands, and organizational optionality collapses with the license untouched. | A periodic count of independent operators: who outside the originating lab can run, evaluate, and adapt the artifact to production standard, and has that count moved since release? |
| Daniel Castro Benefit-cost analysis | Optionality accounting. The cost side of the ledger prices compliance but not depletion: the options a deployment forecloses — reversibility, substitution, later correction — are paid later, by other people, and so are never entered. Optionality accounting puts them on the ledger at authorization. | A cost line for foreclosed options in each regulatory impact analysis: what unwinding the system costs, who bears it, and whether that price was stated before deployment. |
| Tyler Cowen Industry self-regulation | A constitutional test for the self-regulatory body. It can discipline an industry only if it can obtain evidence independent of its members, protect challengers inside its firms, owe responses on a clock, and impose costs on a member the industry cannot replace. | Four records, held by the body: evidence obtained independently, challengers protected, responses delivered by their dates, and a sanction actually imposed on an indispensable member. |
| Andrew Ng Application-layer regulation | Delegation-layer governance. The boundary that matters is not model versus application but delegation structure: what the system decides, at what consequence, for whom, with what exposure, and what correction exists. A pipeline of innocuous components can be delegated into a decision no one can reverse. | For any regulated application: a delegation record covering the pipeline and not just the interface — who authorized it, at what consequence, with what exposure, and what correction exists. |
| Dean Ball Institutional adaptation | A failure criterion for adaptation. Adaptation is a prediction, and a prediction needs its failure condition named in advance. Adaptive capacity is a variable: an institution can adapt toward dependence on the very system it is supposed to discipline. | A published threshold at which adaptation is judged to have failed — oversight capacity falling below a floor while dependence rises — and who is obliged to act when it fires. |
| Cary Coglianese Management-based regulation | The political economy of the leash. A leash works only if the handler keeps expertise, independence, and the ability to pull. All three decay under prolonged reliable automation: the handler stops practicing judgment, the leash's funding becomes a line item in the system's budget, and pulling becomes the act that breaks a workflow everyone depends on. | The handler's three records: a dated exercise of independent judgment, a budget line the system's operator does not control, and the last pull — when it was made and what it changed. |
Counterpositions
Five positions, each stated in its own terms, each with the measurement that would settle it.
An opponent worth engaging does not defend unaccountable power. The opponent holds that competition, exit, reputation, tort liability, sectoral regulation, and ordinary democratic institutions already correct these systems, and that a new framework is overhead.
The framework's case does not need every mechanism to fail. It needs the failure conditions to be identifiable and measurable where they exist. If no such conditions exist, this note should be read as the framework's falsification condition.
| Position | The challenge | What the framework must demonstrate | The question that settles it |
|---|---|---|---|
| Markets and exit Thierer, Huddleston | Users can see a bad system's failures and take their business elsewhere. Competition prices failure and forces correction without new bureaucracy, and exit is the consumer protection that needs no administrator. | Identifiable conditions under which exit stays formal while becoming unusable: switching costs the user does not control, data and history the user cannot take, and settings — employer systems, public benefits, a region's only hospital — where exit means exiting more than the product. The claim is not that exit fails everywhere. It is that exit's quality is a variable, and nobody measures it. | For a system with measurable lock-in, how many of the people it decides about completed an exit in a year, what did exit cost them, and did any rule change because they left? |
| Liability and existing law Thierer | Courts, tort law, and existing statutes address harm when it occurs. Liability prices failure better than a regulator can anticipate it, and prior restraint should not precede the harm it guesses at. | Failure shapes the ex-post system cannot reach: harms that arrive in individually small units no lawyer takes, harms whose evidence is generated and held by the operator, and settlements that pay the plaintiff without touching the rule. Several cases in this site's casebook persisted for years under existing law; the 2020 exam-grades system was halted after four days. | In each casebook case, what did litigation change in the rule, how long did that take, and how many people the system decided about never filed? |
| Sectoral regulators and adaptive institutions Ball, Coglianese | Existing institutions adapt. Management-based regulation — let the operator plan, verify, and document — outperforms fixed guardrails, because the operator knows the system and the sectoral regulator knows the sector. | A way to detect when the adapting institution loses its independence from what it adapts to: the regulator's expertise hired out of the industry it oversees, its evidence supplied by the operator, and its management plan authored by the party it would have to fault. | Which regulator publishes a measure of its own capacity to halt a system it oversees — expertise, independent evidence, the last halt exercised — and what was that capacity at year five of its most depended-upon system? |
| Democratic authorization The position that legislatures, courts, and administrative process are the correction | A program is authorized, funded, and overseen through ordinary politics. If it misgoverns, the remedy is political: ministers, committees, elections. An individual right to contest each decision adds a second channel and dilutes the first. | That authorization for a program and correction for a decision can come apart. The legislature can authorize, defund, or abolish a scheme, and still leave no channel inside it that turns one person's harm into a change in the rule that produced the harm. Automated harm concentrates in exactly that gap, because the system makes thousands of decisions no legislature reviews. | In the casebook's Robodebt entry, a tribunal ruled dozens of individual debts unlawful between 2017 and 2019 while the scheme ran. What channel available in 2017 would have carried any of those rulings to the rule, and how long did the surviving channel take? |
| Transparency and reputation The disclosure-and-audit position: impact assessments, model cards, and published audits let publicity do the disciplining | Institutions compelled to publish their governance will be disciplined by journalists, researchers, and procurement. Sunlight costs less than supervision, and it is workable under existing corporate and reputational pressure. | That publication without decision consequences is a stable state: documents produced for the file, metrics that improve while the underlying work moves onto unpaid labor, and audiences that read the disclosure without holding the standing to act on it. | Since 2020, which published AI-governance artifact — a model card, an impact assessment, an audit — changed a decision right at an institution, and who held the standing that made the change? |
Translations
Each law carries a political proposition. The translations are stated so that a reader who rejects the politics can see which engineering record they are rejecting.
The engineering vocabulary is not a retreat from politics. Each law encodes a proposition about how power should be held, and the records enforce the proposition whether or not a reader notices it. The twelve translations:
| Law | Political proposition |
|---|---|
| I. Capability does not imply authority | Ability does not create a right to rule. What a system can do is a fact about the system; what it may do is a decision someone has to make and renew. |
| II. Authority decays unless its justification is renewed | Political authority is held on condition. A delegation that has stopped serving the people it was granted for must be renewed by them, not by its own momentum. |
| III. Evidence and authority must remain coupled | Power that cannot be argued against is not accountable power. Whoever holds authority must stay answerable to the evidence that would defeat it. |
| IV. Every consequential delegation creates a correction obligation | Delegating a decision creates a debtor. Whoever is delegated owes the person decided about a working correction when the decision is wrong. |
| V. Dependence converts technical risk into structural risk | Once people cannot leave, a technical failure stops being an accident and becomes a governing event, so the decision to create dependence is itself a political decision. |
| VI. Nominal reversibility is not operational reversibility | A right that exists on paper but costs more than the person can pay is not a right. Rights are measured by the price of exercising them. |
| VII. Error-bearing parties require standing proportional to exposure | The people who bear a system's errors are owed a voice proportional to what they bear. Bearing the risk is the basis of the claim. |
| VIII. Observability without state transition is theater | Being seen is not being heard. The obligation is not to publish failures but to let them change something. |
| IX. Human oversight is a control only if the human can alter system state | A supervisor without authority is an alibi. Naming a human in the loop distributes blame, not power. |
| X. The relevant eval sits at the highest layer where harm can emerge | Test the assembly that can hurt people, not the component that cannot. The unit of accountability is the system that decides, not the model that suggests. |
| XI. Successful automation increases its own governance burden | Success creates the dependence that demands supervision. The better a system works, the more its governance must grow, because success is what makes its failures structural. |
| XII. No system may erase the conditions of its own contestability | What can be contested must remain contestable. The power to change the rules of challenge is the first power that has to be limited. |
What the note rests on, and when to treat it as stale.
Positions are summarized from published books, articles, and public commentary by the scholars and commentators named. Instrument names, laws, glossary terms, and case scores are this site's.
Published October 3, 2026. If no revision has been published by October 2027, treat the note as stale.
Copy citation (APA/BibTeX)
APA
Kanav Jain. (2026). Scholarly crossings. Ethotechnics Institute. https://ethotechnics.org/research/scholarly-crossings
MLA
Kanav Jain. "Scholarly crossings." Ethotechnics Institute, 2026, https://ethotechnics.org/research/scholarly-crossings.
Chicago
Kanav Jain. "Scholarly crossings." Ethotechnics Institute. Oct 3, 2026. https://ethotechnics.org/research/scholarly-crossings.
BibTeX
@misc{ethotechnics_research_scholarly_crossings,
title={Scholarly crossings},
author={Kanav Jain},
year={2026},
howpublished={Ethotechnics Institute},
url={https://ethotechnics.org/research/scholarly-crossings},
version={1.0.0}
}
RIS
TY - WEB TI - Scholarly crossings AU - Kanav Jain PY - 2026 UR - https://ethotechnics.org/research/scholarly-crossings ER -