The method
The seven-stage chain, the six safeguards, and the twelve laws
Search standards, diagnostics, glossary entries, and field notes in one place.
Quick search
Jump straight into frequent topics or paste a query in the main search field to refine with filters.
Search is URL-based, so you can share queries with ?q= in the address bar.
Starter queries
Filter by collection
Viewing all collections.
Showing 389 results.
Showing ranked matches based on title, collection, and tag overlap.
Active query: none. Filters: all collections.
The seven-stage chain, the six safeguards, and the twelve laws
Each law and the condition a clause binds
Citable clauses, stated so a system can fail them
EU AI Act, NIST AI RMF, and ISO 42001 alignment
What a clause needs you to be able to show
Kill switches, appeals queues, and safe state controls
Test suites for delegation validity, burden, standing, appeal, and correction
Each check and the claim it tests, plus the claims no check covers yet
Specifications, each with a working form, for scoring a user journey's time, friction, and delay
Levels of evidence, how each is gamed, and how to detect it
Bring a workflow: should this decision still be automated?
Bring workload ratings: where the work a system creates concentrates
Bring a decision log: does it meet the level it claims?
Bring the decision it makes: six contexts, each with the check to run first
Also the corrective capacity self-assessment and checks for a person a system decided about
Defined terms, each at a stable URL you can cite
Governance practices by domain, each filed under the safeguards it serves
Five public failures scored on six safeguards
Dated notes on outside changes that bear on the standards
Essays on why the laws hold, kept separate from the requirements
Scores five self-reported answers: how fast the system's reach grew, how challenges are received, how fast decisions are reversed, whether exceptions change the rules, and whether staff workarounds are tracked. The score is a starting point for discussion, not a measurement of the institution's ability to correct itself.
The normative principle that an institution loses the moral justification for demanding human compensatory resilience when that resilience serves as a permanent substitute for correctable institutional failure.
An operational condition where an automated system or institution appears to meet service-level agreements and throughput targets only because human operators, caseworkers, or subjects exert unmeasured, uncredited compensatory labor to absorb system errors. The labor can fall on personal time, and its costs can reach the staff members' own households, outside any measure the institution keeps.
The baseline operational effectiveness of an automated system or procedure evaluated without reliance on uncredited human compensation, shadow workarounds, or downstream harm absorption.
The requirement that an institution adapt its operational cadence, procedures, and expectations to human biological, cognitive, and social constraints, rather than forcing human participants to continually absorb friction and mutilate their own capacities to preserve an unviable operating model.
A failure mode where an institution preserves apparent operational stability and output velocity by depleting the unrecorded human capacities—such as health, attention, relationships, and moral integrity—on which that stability fundamentally depends.
An operational condition where executive instrumentation registers nominal performance and throughput because human workers outside the machine ledger absorb system friction through unpaid labor, manual intervention, and exhaustion.
An evaluation architecture that pairs visible operational metrics (throughput, resolution speed, and cost per interaction) with an independent audit ledger tracking unrecorded human labor, replenishment rates, and corrective standing.
The deliberate collective refusal by human operators, caseworkers, or subjects to absorb automated system failures or perform uncounted compensatory labor, returning the true cost of unviable system operations to the institution in real time.
The engineering discipline that keeps capability, authority, evidence, dependency, standing, and correction coupled so increasing machine agency cannot silently become unreviewable institutional power. Where ethics asks “What should we do?”, Ethotechnics specifies the mechanisms meant to make it happen and the records that show whether they did.
Observable patterns of system behavior that prevent harm, share burden fairly, and keep people able to contest and recover. Moral behavior is evaluated through MPIs such as time-to-halt, reversibility, and fair burden distribution, not by stated intent.
The route responsibility for outcomes travels through a system, across automation, people, and institutions. A clear ethical load path shows who can stop, reverse, or repair harm at each stage, linking design authority, oversight horizons, and the repair log.
A structured assessment of a system’s capacity to stop harm, reverse it, distribute burden fairly, remain contestable, and enable accountability. Audits surface where stoppability or reversibility fail and guide remediation steps.
The degree to which tools and institutions expand people’s agency, cooperation, and right of refusal instead of enclosing them. Convivial systems keep permission surfaces wide and make opting out safe, so people can shape the service without being consumed by it.
A developmental scale describing how fully a system embodies Ethotechnic capabilities. Early maturity focuses on stopping acute harms; later stages add graceful degradation, contestability, and regular care retrospectives. At the highest level, halt, reversal, and appeal are run as continuous operations, with published SLJs and funded maintenance.
An approach that prioritizes system mechanics—defaults, authority, clocks, reversibility—over declared values or intentions, because mechanics determine outcomes under load.
The claim that “ethical” outcomes depend less on what institutions say they value and more on the enforceable structure of how decisions are made and reversed.
A way of seeing power as state transitions plus time: who can change state, how quickly, and whether reversal is time-bound.
The set of design features that make contestation real: decision objects, clock-start, binding authority, evidence parity, and guaranteed override paths.
A safety lens where governance is modeled as feedback: detect harm, trigger intervention, enforce constraints, and learn. Useful for translating Ethotechnics into engineering terms.
The delay between harm occurring and the system recognizing it. Automated systems create harms faster than human oversight can register, demanding velocity friction and ethical interrupts.
Responsibility dissolves across teams, tools, and incentives until no one can intervene. It erodes design authority and leaves harm without an owner.
When a system pulls value—data, attention, labor, or social capital—without returning care, consent, or repair. Extraction hides true costs through externalization and steep burden gradients, hollowing trust.
Systems that depend on workers or users absorbing fragility through burnout, emotional labor, or unpaid cognitive work—often mislabeled as “resilience.” Ethotechnic practice aims to invert this burden with fair burden distribution.
The natural tendency of systems to externalize harm over time unless constrained by protective friction and moral performance indicators.
Pushing risk, cost, or harm onto other teams, communities, or the future so metrics look clean. Externalization shows up as pollution, shadow labor, or brittle dependencies that live outside audits. Ethotechnics counters it with oversight horizons, MPIs, and transparent repair logs.
When a system shatters under ordinary variance (unexpected inputs, refusals, or edge cases) and people have to absorb the impact. Brittleness signals missing soft edges, thin graceful degradation, and poor refusal tolerance.
Metric-chasing that narrows attention to throughput or growth while ignoring MPIs. Myopic optimization erodes contestability, raises failure load, and often fuels extraction.
Using detailed metrics or probabilistic scores to disguise inequity as objectivity. Precision laundering hides burden gradients and externalization behind statistical gloss, undermining explainability for accountability.
When rigid policy checklists replace judgment, causing teams to follow rules while harm worsens. Compliance collapses occur when design authority is weak and contestability is low, leaving no path to pause or repair.
Harm that does not produce immediately legible signals—silence, withdrawal, dropout, dissociation—and is therefore misread as “no issue.”
The accumulated gap between capability and governability, whose interest is paid as incidents, backlash, and legal constraint.
A precise mismatch where system power exceeds controls (brakes, owners, audits, reversibility, recourse).
A system’s ability to halt harmful processes quickly and automatically—without requiring heroism or escalation.
The ease with which a system can undo a harmful state change—restore access, correct a record, reverse a flag—without extraordinary effort or power. Reversibility is a governance property: it determines whether mistakes are survivable.
Failures do not fall hardest on the most vulnerable. Burden is treated as a design variable and measured via the user burden ratio.
The property of a system that allows affected people to force a decision to become a contestable object: something with reasons, a clock, an accountable authority, and a pathway to reversal. A system has contestability when “that’s wrong” can reliably become “here is the specific decision, here is who can change it, and here is when they must respond.”
A system’s ability to let people say “no” without punishment or degradation—including refusing data extraction, risky defaults, or coercive workflows—while still preserving basic access and dignity. Refusability is not “opt-out exists”; it’s whether refusal is treated as a legitimate state rather than an error condition.
Explanations a person can act on, not decorative ones. They reveal who made a decision and how it can be corrected, enabling contestability and audits.
The system remains usable when people opt out, are confused, make mistakes, or withdraw cooperation. Refusal tolerance prevents extraction by endurance by ensuring refusals do not silently convert into extra unpaid work. Called “human” because it protects humans from being turned into the crumple zone when they refuse.
A design principle where systems degrade safely under stress—reduced capability rather than catastrophic denial—especially under accessibility constraints.
Boundary conditions designed to cushion people instead of penalizing them—graduated responses, warnings before lockouts, and reversible defaults. Soft edges reduce failure load and guard against brittleness.
The system defaults to the safest possible behavior when uncertain, prioritizing stoppability.
The system defaults to permissiveness under failure—sometimes necessary, sometimes dangerous. Must be paired with velocity friction.
A harmful state where a system fails without signaling it. It is the worst form of failure because it hides moral latency: harm accrues while every indicator reads normal.
Originally: machines absorb force so people survive. Digitally: people absorb system failures so machines stay smooth. Ethotechnics reverses this direction of impact.
How plainly a system exposes the human impact of its decisions in real time. High harm visibility pairs logs, narratives, and alerts so oversight horizons extend beyond dashboards and ethical interrupts trigger on effects on people as well as on technical anomalies.
Places in a system where harm occurs but no one can see, trace, or intervene. Closing dead zones is a goal of oversight horizons.
The predefined point where automated control must yield to human judgment because risk, ambiguity, or moral latency is rising. Escalation horizons activate ethical interrupts and route cases to accountable stewards before crossing an irreversible boundary.
The moments, interfaces, and channels where people experience system decisions and can intervene. Mapping the interaction surface reveals where to place dignity friction, widen the permission surface, and detect dead-user zones.
Systems split into high-contestability (slower, trusted, deployable in high stakes) and low-contestability (fast, then blocked).
A scheduled calm state where teams intentionally slow or stop throughput so inspections, upgrades, and rehearsals can happen without crisis pressure. Maintenance windows make stoppability routine instead of reactive. Each window is negotiated with the people impacted, includes published service guarantees, and documents which safeguards were tested so unfinished work rolls into the shared repair log.
A facilitated reflection held while the system is still in a warning band to examine how maintenance load, emotional labor, and unresolved incidents are accumulating. Care retrospectives combine telemetry with frontline testimony. They redistribute responsibilities before burnout or harm escalates, triggering new maintenance windows or policy fixes when the team cannot keep absorbing risk.
A living record of every mitigation, decision, and resource commitment made after a fault. Repair logs make accountability legible by linking people harmed, who intervened, and what evidence was used. They inform future care retrospectives, power audits, and service-level reports so follow-up work is traceable and burden does not drift back to the same communities.
The bodily, cognitive, emotional, and temporal limits all humans share. Ethotechnics treats finitude as a design input, not an inconvenience.
The load level at which human decision quality collapses—too many alerts, too little time, or excessive context switching. Ethotechnic design lowers saturation by adding velocity friction, simplifying interaction surfaces, and staffing to real maintenance metabolism.
The sustainable amount of emotional labor a system asks of people—care teams, moderators, frontline staff, or users. When compassion bandwidth is exceeded, dread work grows and extraction by endurance sets in.
The feeling of being personally at fault for harms produced by system design. Often a signal that moral overhead is too high.
Tasks people avoid because the system punishes mistakes or withholds relief. Dread work signals missing soft edges, low contestability, and declining compassion bandwidth.
The idea that modern systems sort people by their capacity to perform sustained administrative labor—tracking tasks, managing documentation, navigating ambiguity—making disability and burnout into structural disadvantage.
A discipline that studies how systems interact with real human limits—fatigue, confusion, stress—often revealing that “user error” is design failure.
Design that treats front-line workers as safety components and ensures they have authority, tools, and non-punitive reporting to prevent harm.
The number of times a person can decline, pause, or question a request without retaliation. A refusal budget backed by refusal tolerance and rights of exit prevents coercion, and heat maps of refusal show where budgets are running out.
How a system allocates the cost of operation or failure—time, attention, stress, and emotional labor.
The slope of effort and risk across roles or communities. A steep burden gradient means those with the least power carry the heaviest operational load while decision-makers feel little friction. Mapping the gradient exposes where to redistribute work through fair burden distribution and reduce moral overhead.
The amount of harm generated when the system fails, and how many people it reaches. The aim is an architecture whose failures stay small, supported by graceful degradation.
Moments when system failure pushes labor onto humans, often triggering moral overhead.
A mechanism where systems offload the labor of safety, clarity, and follow-through onto individuals (forms, documentation, vigilance) while keeping institutional obligation low. It’s how “choice” becomes unpaid work.
The ongoing monitoring burden imposed on individuals to prevent harm: checking portals, tracking deadlines, resubmitting documents, watching for silent rule changes. Attention becomes a cost of staying eligible.
The baseline flow of upkeep—patching, cleaning, rehearsing, and caring—that keeps a service alive when nothing is on fire. Healthy maintenance metabolism is budgeted, scheduled, and shared rather than squeezed between crises. Falling below it signals rising maintenance debt and invites maintenance windows before fragility compounds.
Accumulated obligations from skipping basic upkeep. The interest is paid in slower recovery, brittle systems, and people burning out to keep things running. Paying it down requires restoring the maintenance metabolism, scheduling maintenance windows, and tracking work in the repair log.
Extra work users or operators must do to behave ethically within a bad system.
Uncompensated seizure of life-hours (time, attention, opportunity cost) as the price of accessing a right or correction. Temporal exaction is a form of extraction that inflates the user burden ratio.
A composite measure of how much effort, time, and emotional labor people expend to use or recover from a system. Inputs include the user burden ratio, human substitution index, and failure load; rising scores signal extraction or asymmetric sustaining.
The maximum allowable procedural burden a system can impose on someone seeking safety, correction, or relief. Ceilings are defined per harm class and enforced through UI, staffing, and policy.
When one group continually absorbs the toil of keeping a system alive so another group can move fast or claim success. It often hides behind gratitude for “resilience” while masking extraction. Ethotechnic practice flattens this by lowering the burden gradient and designing for stoppability so resilience is institutional, not personal.
The unpaid labor, vigilance, or emotional buffering people contribute to keep brittle systems functioning. Fragility subsidies hide true costs, inflate success metrics, and deepen asymmetric sustaining.
Metrics that show whether a system can still be stopped, reversed, and challenged, such as time-to-halt (TTH), reversibility rate, appeal success rate, and burden ratios. MPIs sit beside KPIs and track how safely and fairly a system operates, where KPIs track how fast it grows.
Operational metrics tied directly to fairness, safety, and dignity. SLJs should sit alongside uptime and latency commitments.
How well a system delivers review → reversal → remedy under realistic load and stress.
A diagnostic map of where labor, emotional labor, time, and money go inside an institution. It visualizes maintenance metabolism, burden gradients, and points of extraction. Teams use the map to set SLJs, redesign roles, and decide where to invest new maintenance windows.
Seconds between a harmful process beginning and the system stopping it. It is the measured side of stoppability.
How long it takes to reverse harm and return a person to their prior state. Low TTR is a signal of reversibility.
The percentage of appeals resolved in favor of the user, a leading indicator of true contestability.
The share of system actions that cannot be undone. Aim to keep this as low as possible through reversibility and graceful degradation.
A predefined cap on the share of actions allowed to be effectively irreversible in a given system or workflow class. Budgets force designers to minimize irreversible boundaries and build rollback lanes for everything else.
How much work a user must perform to correct or navigate system errors. This metric feeds directly into fair burden distribution.
A measure of how often humans must step in to compensate for system shortcomings—manual reviews, ad-hoc patches, or empathy work. A rising index exposes heroism-dependent systems and motivates investment in graceful degradation.
The trustworthiness of alerts, metrics, and reports used to govern a system. High credibility pairs transparent sampling, explainability for accountability, and human testimony so warnings trigger action instead of alert fatigue or dismissal.
The time, money, emotional labor, documentation, and social risk required to undo an outcome. High reversal cost makes errors durable and turns “rights” into luxuries.
How long a wrong state persists once created, and how far it propagates (downstream systems, eligibility, reputation). A system is dangerous when it can create durable errors quickly but correct them slowly.
The accumulated harm a system has caused but not repaired. Moral debt accrues interest as moral latency grows and people lose trust; it is paid down through pathways to restitution, transparent repair logs, and lowered time-to-restore.
The accountable power to set the constraints a system operates under, choose its safeguards, and fund their enforcement. Clear design authority aligns incentives, protects contestability, and prevents accountability diffusion.
The distance regulators, auditors, or affected communities can see into a system’s decisions and their effects. Extending the horizon through harm visibility, traceable models, and shared repair logs shrinks dead zones.
A system is legitimate insofar as affected parties have standing, voice, and remedy against its decisions/actions.
The capacity to monitor, review, and repair is a political/organizational legitimacy input, not overhead.
People should automatically get “what happened” records: actions taken, permissions used, reasons, and accountable owners.
Sovereignty is the ability to impose enforceable constraints on infrastructure operating in your territory.
Global competition shifts to whose regimes for auditability, liability, and redress become default through supply chains and procurement.
Governance infrastructure can either enable rights-preserving contestability or scaled conduct control, depending on who has standing and remedy.
The set of authority grants in force for a system at a given moment, each carrying an evidence basis, a scope, a state, and an expiry. Contestability depends on each grant in it being open to challenge.
Agent autonomy is a conditional privilege granted only when monitoring, brakes, and recourse capacity are demonstrably adequate.
Guaranteed, non-punitive ways to leave a system (or refuse a pathway) while preserving access to essentials, records, and future participation. Exit rights treat departure as a legitimate action, not a breach.
The pathways an institution uses to push risk or cleanup onto others: contractors, users, bystanders, or future teams. Mapping these channels exposes externalization and informs fair burden distribution.
A negotiated period where teams pause growth work to do maintenance, close open repairs, and fix gaps in ownership. Stewardship windows bundle maintenance windows, publish SLJs for the pause, and commit to closing items in the repair log before resuming throughput.
Control exercised by keeping matters unresolved long enough that time itself produces the outcome. Governance by suspension relies on non-decisions and exploits endurance asymmetry.
Institutions can persist indefinitely; humans cannot. This makes delay an allocation mechanism that underwrites continuity privilege and punitive friction.
Unequal access to enforceability produced by unequal capacity to maintain standing over time (attention, health, documentation, slack). Continuity privilege steepens the burden gradient for those without reserves.
Unequal enforceability produced by unequal ability to delegate persistence (agents, intermediaries, automation). Proxy privilege lets some parties bypass futility thresholds that others face alone.
The principle that delay produced predictably by system rules (queues, resets, blocked escalation, absent deadlines) is attributable power, not mere inaction.
A fixed maximum time-to-resolution; breach triggers an enforceable disposition. Bounded duration pairs with stable clocks and time transparency.
A persistent cumulative record; no forced repetition of validated inputs. Continuity of state reduces temporal exaction and protects contestability.
No adverse consequences while review is pending (except narrow, reviewable emergency exception). Safe pause preserves the utility window and keeps people whole during appeal.
A named responsible party with authority to override automation when bounds are breached. Traceable ownership clarifies design authority and accelerates time-to-restore.
Legible process state: current step, blocking condition, time remaining, next decision point, escalation triggers; no fake progress. Time transparency supports contestability and stable clocks.
The degree to which a system’s outputs create enforceable obligations—deadlines, duties, remedies, or reversals—rather than mere communications. Bindingness is the difference between “we received your request” and “we must decide by Friday or you win.”
The condition where a system can interact, respond, and even apologize without being compelled to change state. Non-bindingness is power without accountability: activity without obligation.
Standing is the recognized right to make the system bind itself to engage, decide, and remedy—regardless of whether your story is believed, liked, or emotionally legible. “Belief” is narrative validation; standing is enforceable access to decision power.
A person or role that can change the underlying state and is obligated to respond. Binding authority is not “a human is involved”; it’s a human with power + duty + traceable accountability.
A condition where affected people have a fair chance to meet the evidentiary burden—access to the relevant facts, rules, and records—rather than being asked to prove things the institution can’t or won’t disclose. Without evidence parity, appeals become theater.
The mapping of who can change what state, at which stage, under what constraints. Authority chains determine whether escalation is real.
A pattern where escalation changes how the institution speaks without changing who has power to reverse outcomes. Authority mutates when the channel upgrades (more polite, more official, more complex) but the underlying ability to bind remains absent.
The idea that the baseline state—what happens if nobody intervenes—is a primary allocator of outcomes and costs. Defaults govern by deciding who must spend time, attention, and stamina to avoid harm.
A stratification system where people are divided by their ability to force binding action: who can start clocks, reach authorities, obtain reversals, and make claims legible. It’s a caste system of enforceability, not worth.
A channel change that does not increase binding power—more forms, more tiers, more waiting—while the underlying decision remains unchangeable. It’s escalation as delay management, not remedy.
The set of mechanisms that can correct harm: appeal, review, reversal, compensation, restoration. Redress is real when it is time-bound and reaches binding authority.
A defined mechanism that can supersede the default workflow when the default would cause harm: human escalation with real authority, emergency reversal, or exception handling with deadlines. Override paths are where a stated commitment to people becomes a mechanism.
An exit process designed to protect the leaver: clear steps, data portability, timelines, anti-retaliation constraints, and closure that doesn’t require ongoing performance. Structured exit turns leaving into a governed pathway instead of an endurance test.
When access to contestation, speed, or binding review is effectively purchased—through fees, premium support, lawyers, consultants, or time flexibility. Rights exist, but only for those who can pay in money or stamina.
The idea that control over records—what is logged, who can see it, what counts as evidence—shapes who can contest outcomes. Recordkeeping is governance.
A trace of events and decisions—what happened, when, by whom, under what rule—used for accountability. Audit trails matter only if they connect to reversal power.
The world as the system recognizes it: what counts, what is recordable, what triggers action. Administrative reality often diverges from lived reality.
A take-it-or-leave-it contract offered by a more powerful party where negotiation is impossible; a common substrate for coerced “choice.”
Mechanisms that suppress exit stories—legal threats, informal retaliation, reputational control—preventing systems from being held accountable by shared evidence.
Friction that slows harmful processes and keeps moral latency within safe bounds.
Friction that punishes users—often hidden in bureaucratic loops. Signals extraction by endurance.
Friction that preserves autonomy, such as double checks on irreversible actions.
Friction added specifically to prevent runaway system behaviors. Often implemented through ethical interrupts.
A deliberate release point that lets people slow, pause, or reroute automation before harm compounds. Safety valves pair stoppability with dignity friction so flows with serious consequences default to reversible states and route to humans without penalty.
The sequenced touchpoints where a person learns what a system will do, grants or denies permission, and can revise that choice over time. Strong consent journeys use anticipatory consent, visible permission surfaces, and healthy refusal budgets so pausing or exiting does not jeopardize access or service.
“Agreement” obtained through defaults, asymmetry, or threats of exclusion—consent produced by lack of viable refusal.
The combination of protective, dignity, and velocity friction across a workflow, placed so the process slows only where risk, irreversibility, or coercion pressure is high.
Deliberate slowdowns or checkpoints inserted where harm would be costly or irreversible, so fairness and safety survive speed and scale.
Harms that spread unchecked because safeguards or pauses were stripped away. Frictionless harm is the inverse of protective friction; it appears when velocity friction and dignity friction are absent.
The precise moment when a choice shifts from reversible to consequential. Making the decision edge visible enables dignity friction, clearer consent, and routing to ethical interrupts when risk spikes.
The part of a system where decisions become visible, addressable, and contestable. Many systems minimize the decision surface to avoid accountability.
A discrete, attributable, contestable output: outcome + reason + timestamp + accountable owner. Decision artifacts anchor traceable ownership and make contestability measurable.
A discrete, addressable unit of institutional action that can be challenged: what was decided, when, under which rule, by what authority, with what evidence. Decision objects are the “handles” that make contestation possible.
The process by which a complaint, harm, or request becomes a decision object—assigned an identifier, a category, an owner, a standard of review, and a clock. Systems often block accountability by preventing object formation (“nothing exists to appeal”).
A stable administrative disposition where a system withholds a contestable outcome (pending, in review) while consequences accrue. Non-decisions stretch moral latency and keep people in limbo.
A default state where nothing is decided and no one is obligated—often presented as neutral but functioning as an outcome allocator. Pendingness becomes harm when it lacks a clock, an owner, or a forced next step.
The moment a claim becomes resolved in a way that changes the underlying state—approved, denied with appeal rights, remediated, reversed, paid, restored, or otherwise closed with consequences. Settlement is not closure in the CRM; it’s resolution that binds.
An institutional mode where claims are acknowledged and processed indefinitely without producing a binding resolution. The system offers intake, updates, and politeness while keeping obligation optional.
A non-resettable timeline for a case; the system cannot restart time via re-ticketing, re-verification, or channel switching. Stable clocks enforce bounded duration and keep timelines legible.
Clock-start: the moment a system becomes time-bound—deadlines begin, obligations attach, escalation becomes meaningful. Clock mismatch: when institutional execution is fast (instant flags, freezes, denials) but redress is slow (weeks-months-human review), making errors durable and contestation scarce.
A governance asymmetry where harmful state changes are immediate but appeals are delayed, discretionary, and exhausting. This is one of the main engines of modern coercion.
The time span during which relief can still prevent the relevant harm. Designing for a clear utility window keeps time-to-restore accountable.
Crossing the utility window; relief arrives too late to matter. Utility expiry should trigger constructive denial or repair.
The point where time-on-task or repetition becomes so costly that valid claimants predictably abandon pursuit. Systems that hit the futility threshold signal punitive friction and low contestability.
A legal state where delay is treated as refusal because it destroys utility or makes pursuit futile. Constructive denial recognizes utility expiry and forces accountable remedies.
Any system action that meaningfully alters a person’s status, access, or trajectory. Critical actions require dignity friction.
A state where reversal is practically unavailable (too slow, too expensive, too discretionary) even if it is theoretically possible. Irreversibility is often produced by missing clocks, missing authority, or asymmetric evidence demands.
A threshold the system cannot automatically undo—account closures, public releases, or data publication. Crossing it demands heightened contestability, audited explanations, and explicit time-to-restore plans.
A guaranteed fallback mechanism that triggers when the main process fails—timeouts, automatic approvals, emergency restoration, or external review.
A designed ability to revert the system to a prior safe state—restoring access, undoing propagation, correcting records—ideally with minimal friction.
Default state transitions that happen without active consent—closing claims, renewing contracts, expanding data use—often presented as convenience while functioning as governance by inertia.
Automatic system-level halts triggered by anomalies or harm indicators. Ethical interrupts operationalize stoppability.
Systems that rely on extraordinary effort, unpaid care, or silent sacrifice to function. They mask poor stoppability and high failure load.
Simulated warmth—chatbots, scripted apologies, tone guidelines—used to mask structural harm or delay fixes. Empathy surrogacy diverts attention from repair and weakens contestability by substituting sentiment for remedy.
Small automated mistakes that amplify across the system. Prevented through ethical interrupts and SLJs.
Hidden behaviors that appear under stress—shadow queues, silent throttling, or undocumented overrides. Invisible fallbacks obscure ethical load paths and should be surfaced through graceful rollback lanes and rehearsed in maintenance windows.
Places where people affected by decisions cannot contest, appeal, or exit—opaque rankings, automated bans, or unmoderated queues. Closing dead-user zones requires widening the permission surface and raising appeal passage rates.
When harmful defaults become entrenched through dependencies, network effects, or contracts that block reform. Moral lock-in is prevented by moral feature gating, contestability, and continuous moral drift control.
The process of converting coercive or indifferent outcomes into reputational legitimacy through procedural signals—case IDs, polite updates, “in review”—without delivering binding resolution. The system looks responsible while staying unbound.
Coercion delivered through soothing language and “helpful” workflows that make refusal costly or stigmatized. Polite coercion is power that avoids looking like power.
A repeating pattern where the system continually requests more evidence or re-uploads without moving toward a binding decision. Often used to shift labor onto claimants and to manufacture dropout.
Requests for ever-greater specificity that function less as truth-seeking and more as denial hooks—ways to keep a case non-objectified or non-decidable. Precision demands are a technique of delay.
A record of “process” used to defend outcomes (“we followed procedure”) even when the procedure cannot bind the institution to remedy. The alibi is the trace of activity, not accountability.
The use of “appropriate tone” requirements to control access to remedy—penalizing anger, urgency, neurodivergent communication, or exhaustion. Tone policing converts distress into disqualification.
When systems treat nonresponse, fatigue, or disappearance as consent or closure (“case closed—no reply”), laundering coercion into “resolved.” Dropout becomes the mechanism that protects the institution.
The engineered cycling of people through forms, queues, and handoffs until they give up, miss a deadline, or become “inactive,” allowing the system to close without settlement.
Compliance regimes focused on producing documentation of doing the right thing rather than mechanisms that can prevent harm or force remedy. The paperwork stands in for power.
Disclosures that do not increase contestability—more text, more dashboards, more “explanations”—without deadlines, authority, or reversal paths. Visibility substitutes for enforceability.
A focus on explaining model decisions that distracts from the harder question: can the decision be contested, reversed, and time-bounded? The decoy offers epistemics where governance is needed.
A human reviewer inserted to create legitimacy while lacking binding authority, deadlines, or meaningful discretion. The loop becomes a comfort signal, not a power shift.
Instrumentation that detects when a system’s behavior drifts from the baseline its authority was granted against, using MPIs or reports from affected people, and automatically triggers interrupts or design changes.
Measures of how much ordinary human variance an infrastructure tolerates before it fails someone: error tolerance, recovery time, and soft edges. Higher coefficients are expected to track lower failure load and safer degradation.
How effort and risk move between parties when conditions change, and whether they move back afterward. Mapping burden elasticity alongside the burden gradient shows whether a crisis will land on the people with the least power to refuse it.
Overlapping routes through people, automated checks, and policy guarantees, so that when one safeguard fails another still catches the person. Care redundancy pairs with graceful degradation to keep failure load low.
Mechanisms that let people challenge the rules of challenge as well as its outcomes: who may appeal, what evidence counts, and who sits on review panels. Meta-contestability keeps contestability from ossifying.
Inferring user states such as fatigue, distress, or inattention to slow the pace, add protective friction, or route to a person before harm compounds. The models must respect anticipatory consent and must not create new burden transfers.
Designing for the unavoidable delay between an action and its review: staging risky steps, adding velocity friction, or holding care floor guarantees in place until the fuller review is done.
Coordination methods that keep a named owner attached to work as it moves across teams and automation: shared playbooks, auditable handoffs, and repair logs. The protocols prevent accountability diffusion at the handoff.
A shared classification of failure modes, such as optimization myopia, brittleness, and extraction, so incidents can be compared across systems, learned from, and prevented.
Flows that reroute a task when someone pauses or declines, keeping the case context and imposing no penalty. Adaptive pathways extend refusal budgets and strengthen refusal tolerance.
Automated follow-up after an incident that checks on the people affected, schedules remedies, and prompts a named person to close the case. Done well, it lowers moral debt without adding moral overhead.
The measurable gains in trust, retention, and safety when a system serves the people it acts on as intended. Tracking the dividend is the budget argument for sustained funding of MPIs and maintenance metabolism.
Explicit allowances for uncertainty that hold back automation or strict enforcement until there is enough context. The budget reserves time, human review, or maintenance windows for the cases that need them.
Consent models that preview future data uses and let people pre-approve, defer, or block them. Anticipatory consent supports rights of exit and counters precision laundering of unclear terms.
Thresholds, revised as conditions change, that mark where harm exceeds the system’s mandate and operations must halt or escalate. Boundaries are tied to SLJs and enforced through ethical circuit breakers.
Baseline commitments a service keeps during outages or crises: live support, data export, or safe defaults. Care floors protect users while graceful degradation is active.
Signals about how people are treated in an interaction: response tone, wait times during distress, and whether follow-up happened. They sit beside technical metrics and protect compassion bandwidth.
Logging that records a conflict between values when it happens, for example when SLJs are traded against throughput or appeals spike. The record lets the conflict be reviewed before it escalates and lets moral drift control start sooner.
Limits that stop tools from being repurposed for harassment, exploitation, or coercion: rate limits, anomaly detection, and human override lanes tuned for abuse cases.
Regular drills that test how a system responds to harm, as well as whether it stays up. They exercise ethical interrupts, check care floors, and record findings in the repair log.
Caps on what data is collected and how it is used, set by context and purpose rather than by what a consent checkbox legally allows. Budgets align with anticipatory consent and guard against extraction.
A register of deferred decisions and the harm each one accrues while it waits, reviewed before that harm compounds. The ledger feeds maintenance windows and informs MPIs.
Design slack that absorbs variance so marginalized groups do not pay first or most when errors occur. Buffers include staggered rollouts, rollback lanes, and targeted support funds.
Automated stops that trip when a risk indicator crosses a set point: a surge in appeals, a bias metric, or rising moral debt. They are the safety counterpart to financial circuit breakers.
Exercises that probe how a system behaves when its safeguards are under stress, such as simulated harassment, mass appeals, or outages, to check that ethical circuit breakers trip and care floors hold.
Signals that detect operator or user fatigue, such as error streaks, long queues, and late-night decisions, and automatically slow, pause, or hand off a flow before mistakes multiply. The triggers protect compassion bandwidth.
A planned allocation of protective and dignity friction across a workflow, set step by step according to risk, instead of removing friction wherever it slows things down.
Prepared routes to revert harmful decisions while preserving dignity, evidence, and service continuity. Rollback lanes keep irreversibility indices low and shorten time-to-restore.
Time-boxed periods where people can report or reverse harmful actions without penalty, encouraging disclosure and faster repair. Amnesty windows often follow rehearsal loops or incidents.
Maps of where people opt out, churn, or appeal, which show early where refusal is being made costly. They are used to tune refusal budgets and redesign interaction surfaces.
Guaranteed routes for human judgment to supersede automation when stakes are high or context is missing. Override lanes accompany ethical interrupts and require clear ethical load paths.
Linked records that attach the findings from past incidents to the workflows most like them, so the next team sees them before repeating the failure. Memory chains inform ethical load tests and prevent moral lock-in on bad patterns.
Pre-launch walkthroughs that play out the hard cases a design will meet, such as conflicting obligations or a wrong decision nobody can reverse, before it reaches the public. Dry runs test circuit breakers, rollback lanes, and documentation.
Controls that block a feature launch until readiness criteria are met: oversight plans, contestability pathways, and care floors.
Documented steps a system must take to repair harm: acknowledgement, remedy, verification, and follow-up. Pathways reduce moral debt and belong in the repair log.
Routing logic that knows who can decline a task and makes sure a refusal is honored without retaliation or a silent penalty. It preserves refusal budgets so that declining stays a real option.
Guarantees that relief takes the same predictable effort and support whichever path a person comes in by. Relief invariants are tested in crisis rehearsals and anchored by care floors.
Minimum participation rules for authorizing fixes so impacted communities have a seat in deciding remedies. Repair quorums counter accountability diffusion and legitimize restitution.
Built-in mechanisms that enforce rest and recovery—rotation policies, cooldown timers, enforced downtime—so fatigue does not translate into harm. Enforcement protects maintenance metabolism and compassion bandwidth.
Designers hold the people a system affects and the resources it draws on in trust, and must leave systems safer and easier to repair than they found them. Conservancy prioritizes repair, stoppability, and reducing moral debt.
When harm occurs, the system shoulders effort before the person harmed does. Burden inversion lowers the user burden ratio and demands rapid restoration.
Halt harmful behavior first, then justify or refine it. Systems must trigger ethical interrupts before offering explanations, preserving reversibility.
A system stays safe to rely on only while it is maintained: funded maintenance metabolism, scheduled maintenance windows, and transparent logs.
Design so that when failures occur, human impact is contained. This principle motivates graceful degradation, care floors, and low irreversibility indices.
Critical actions must be undoable or paired with rollback lanes. The mandate aligns with time-to-restore targets and contestability.
People affected by system decisions can challenge, change, or overturn them, and can win. Guarantees include wide permission surfaces, high appeal passage rates, and transparent design authority.
Achieving internal process simplification by externalizing friction, edge cases, and ambiguity onto humans without accounting for the transfer. Diagnostic: ask whether the world became simpler or whether people were forced to become more adaptive.
The technocratic fallacy that what a formal system cannot represent ceases to exist or requires no governance. Countered by the invariant: not represented implies unresolved.
The friction, ambiguity, and repair labor that remains unresolved after a formal model simplifies a workflow. Formal systems do not eliminate what they cannot represent; they redistribute the burden of dealing with it.
An accounting distortion measuring velocity strictly inside the machine boundary while treating external human attention, troubleshooting, and dispute labor as zero cost.
A governance discipline centered on authority grants, standing, and enforceable recourse rather than behavioral alignment. Focuses on what authority a system holds and what happens at the point of model failure.
The engineering discipline required after metric optimization reaches its boundary, focusing on independent review, measuring uncounted absorption, and failure-point standing.
How understandable a system’s actions, reasoning, and ownership are to the people affected. Legibility lets people find who decided, why, and how to respond; it does not guarantee the decision can be changed.
Alignment achieved across tools, interfaces, incentives, workflows, and structures, as well as inside a model. Sociotechnical alignment keeps the ethical load path intact under pressure.
The capacity to act with consequence on an institution’s behalf, held by a machine, a human, or both. Delegated agency is created by an authority grant and exercised through a decision system, not a property of the model itself.
A decision that changes someone’s access, money, obligations, safety, or standing and that the institution must answer for. The consequential decision is the unit of governance in Ethotechnics.
The assembled machinery that produces a consequential decision: models, rules engines, queues, humans, policies, and the data they read. Ethotechnics governs the whole system, not any single component.
A delegation whose authority, evidence, and correction capacity are all currently in force. Justification is a present-tense test, not a fact about the launch review.
Negative outcomes for which no individual or role is accountable, even though the system caused them. Unowned harm signals accountability diffusion and weak traceable ownership.
Public displays of ethical concern without operational mechanisms that change system behavior. Ethics theater often masks compliance collapse and low contestability.
The gap that opens when what a system does moves away from what its authority grant permits or its evidence supports. Drift accumulates through steps that each look too small to review.
Scope growth by accretion, where each extension of an automated system is too small to trigger review and no single step widens the delegation. The ratchet turns one way only.
The state where a system has absorbed enough of an institution’s capability, staff, and decision paths that the institution can no longer evaluate, constrain, or replace it.
Review that approves at a rate and speed incompatible with real scrutiny. The artifact of review exists; the control does not.
Reliance on a system that has become invisible because it is ordinary: no one records it, no fallback is maintained, and withdrawal is no longer a question anyone asks.
The decay of correction capacity in the absence of replenishment: experts leave, alternatives lapse, rollback scripts stop being run. The institution becomes less able to correct without any decision causing it.
The condition where the questions an institution asks about a system’s scope come to track the system’s own categories and vocabulary. The system’s answers shape the next question asked.
Handling an exception without changing the rule, category, workflow, or authority that produced it. Each case is closed and nothing upstream changes.
The rule that a recurring workaround raises a presumption of upstream design failure. The first reading of repeated improvisation is that the formal system does not fit the world it operates in.
An institution's continued reliance on compensatory work it knows about, kept because relying on it costs the institution less than ending it. It is a conflict of interest, not an information gap. Measuring the work more closely does not address it; authority over the conditions that produce the work does.
The pattern where automation relocates rather than removes judgment, reappearing in thresholds, categories, exception rules, and appeal routing—along with authority over it.
The degree to which a system can be steered, paused, audited, corrected, or shut down after deployment. High governability requires stoppability, reversibility, and durable contestability.
The ability to recognize failures as incidents rather than anomalies and respond with containment, logging, escalation, and repair.
The practice of finding out what an assembled decision system can do, including reachable tools, side effects, and action classes nobody intended to expose. The output is a catalog, not a permission.
The measured ability to intervene: which interventions exist, who may invoke them, how long they take, and how much load the institution can absorb. Counted in people, clocks, and rehearsals, not asserted in policy.
The first level of the reversibility ladder: the mechanism exists and works, proven on the running version. A floor rather than a finding—a working switch says nothing about the levels above it.
The second level of the reversibility ladder: people and processes can absorb the correction. Staff know the fallback, queues hold the load, and the manual path has been exercised recently enough to work.
The third level of the reversibility ladder: the organization survives having made the correction. Commitments, contracts, reputations, and budgets stay serviceable after withdrawal.
Who may intervene, on what signal, with what information and authority, on what timescale, and what happens on disagreement. It replaces “human in the loop” as a control name.
Designing a system so audit questions can be answered later by recording evidence, authority, and reasoning at decision time. It cannot be retrofitted onto decisions already made.
The property that no single provider is necessary to both execute and evaluate a consequential process. A system that grades its own homework has no detection component.
The modification of a system by its own exceptions: a recurring failure changes the rule, category, workflow, or authority that produced it. The counterpart of exception absorption.
The capacity to fix a particular bad decision: an appeal is heard, a reversal issued, a person restored. Locally corrigible, but the pattern may remain.
The capacity to modify the machinery that keeps producing failures: repeated exceptions change the rule, category, workflow, or authority generating them.
Learning that changes what an institution is permitted to do, as distinct from what a model predicts. The test is whether the failure altered the evidentiary rule, authority, or allocation of burden.
The accumulated gap between an institution’s capacity to act and its capacity to detect, contest, reverse, and repair errors. Grows as action capacity compounds while correction machinery stays fixed.
A positive capability to decline to act in three forms: epistemic (evidence insufficient), jurisdictional (not mine to decide), and remedial (acting now would cause uncorrectable harm).
The divergence between what a system can technically do and what any recorded justification permits. The automation ratchet is its engine and authority drift is its balance.
“Restored” means the person is back to the prior state in every downstream system, not only unblocked in the one that erred. Time-to-restore includes reconciliation with dependencies.
A record of where a harmful decision propagated across vendors, data brokers, internal teams, and agencies, so remedies follow the harm.
A queue users cannot see—internal backlogs, vendor queues, or “pending review” pools—that still determines outcomes. Erodes time transparency and contestability.
The current status of an authority grant, drawn from a closed set such as allowed, review_required, suspended, and withdrawn. States are what triggers can move.
The record of what a decision system can do, maintained separately from what it is permitted to do. The catalog is what an authority grant is written against.
The current degree to which an institution relies on a system: who depends on it, what breaks without it, what expertise is retained, and how long substitution would take.
A nine-property classification of a deployment—access, control, update authority, stability, revocation, substitutability, observability, standing, and dependency—replacing the open-versus-closed question.
When composure, clarity, gratitude, or “professionalism” become requirements for baseline safety or remedy. Turns emotional labor into a gate.
Baseline safety and remedy should not change based on distress, fatigue, disability, fear, or anger. The primary threat model is virtue as access control.
The way systems nudge, constrain, or normalize user behavior through defaults and design choices.
Anyone who absorbs the consequences of a system’s errors: the people its decisions fall on, and the staff whose corrective labor keeps it usable.
The finite human resource an arrangement consumes when it demands that people adapt to it: attention, memory, flexibility, time, health, and care.
It is cheap or fast to harm or change someone’s state, but slow and costly to reverse. Inflates time-to-restore and compounds moral debt.
Who gets the right outcome is determined by who can survive the correction path, not who is substantively right. Weaponizes endurance asymmetry.
Rights exist in theory, but the option to claim them is priced in paperwork, waiting, and persistence.
Designing systems so creators and operators bear the costs of failures instead of externalizing them to users or society.
Responsibility for a system continues after deployment through monitoring, updates, incident response, and repair.
The hidden harm of being bounced between phone, email, chat, and portal channels, often resetting clocks or losing context.
A hard cap on documentation demands placed on claimants for a given harm class, enforcing fair burden distribution during appeals.
Reusing previously verified information so people do not have to re-prove identity or harm repeatedly. Applies continuity of state to documentation.
When verification itself causes harm through delays, denials, exclusion, or stress spirals, increasing the burden index and eroding contestability.
Human effort required because an arrangement failed to accommodate foreseeable reality. Distinct from the productive adaptation that learning and care require.
The time a chain of delegations takes, measured from decision records rather than nominal per-hop promises. Hops compose additively and can consume the human’s intervention window.
The deployer-side duty to find harm nobody complained about, computed per affected population from records the operator already retains, on a declared cadence.
A measure of how likely identity or eligibility checks are to fail under ordinary life variance. High fragility indicates brittle verification design, not user fault.
The time from a person saying “I revoke consent” to behavior changing everywhere it should. Low latency keeps consent journeys credible.
The rate at which unrepaired harm compounds through financial penalties, health risk, displacement, or reputational spread. Converts moral debt into time-bound obligations.
A composite indicator of structural risk: dependency depth multiplied by substitution cost multiplied by correction latency, read as a trend rather than a single number.
What it would take to replace a system with an alternative meeting the same obligation: staff-weeks, retained expertise, exit terms, and elapsed time.
The level of the stack at which an evaluation holds—model, agent, delegation, institution, or consequence—so a clean result at one level is never read as another.
What it costs the dependent party to stop depending on a system: money, time, reconstructed records, and lost access. Measured from the side the decisions land on.
The rate at which challenges arrive against the capacity to answer them. Congestion is the point where the open circuit is usually lost.
The signature binding a record to a named key holder at a point in time, so authority attributable to no one is distinguishable from authority nobody signed.
The object naming the party that accepts liability for a delegation’s latency and errors, the instrument binding them, and the carve-outs they claim.
An exclusion, cap, or condition the accepting party claims against a recorded liability. Recorded before harm, in the issuer’s words, not assembled after.
A sequence of delegations that together produce one consequential decision. The chain is itself a delegation, governed at the layer where it fails.
Autonomy granted only within explicit limits; approaching or crossing them triggers escalation to design authority or oversight. The limits live in an authority grant.
The practice of not exceeding one’s mandate, even when doing so appears helpful or efficient. Enforces the permission surface and respects bounded autonomy.
An explicit, ongoing role responsible for system behavior over time, with authority to pause, fix, or retire it.
Whether responsibility stays attached across time, handoffs, and narrative resets instead of evaporating.
The ability to remain wrong without consequence by stretching time (“pending,” “in review”). Operationalizes latency-as-action.
The correction path works only if someone performs well under stress; the system treats composure as eligibility.
After harm is reported or help is requested, who becomes bound—institution or claimant—and what obligations lock in.
Being “heard” is treated as if it discharges obligation, pressuring the claimant to stop escalating without repair.
Responsibility exists but no owner or time-bound state transition is attached; people are bounced between channels.
Person-level reason codes that convert structural scarcity into individual failure (“withdrew,” “no response,” “noncompliant”).
An anti-pattern where drop-off is counted as success and metrics improve when people give up. Hides unmet obligations behind completion dashboards.
Legitimacy treated as measurable requirements: standing and remedy for the people a system decides about, a named authority on stated evidence, a halt path, and time-bounded repair.
Consent and silence extracted under duress during departures, often via NDAs, retaliation risk, or narrative erasure.
Where the system can punish people for contesting, pausing, refusing, or exiting—throttling, stricter scrutiny, or service withdrawal.
A binding commitment that contesting, pausing, refusing, or exiting will not trigger adverse treatment.
Appeals are judged on merits with transparent criteria, named authority, and documented outcomes—not absorbed into procedural theater.
Escalation paths work under load, after hours, and for novices, as shown in drills rather than in documentation.
A formally granted power to undo harmful decisions, not merely recommend reconsideration. Turns reversibility into an enforceable capability.
A tiered remedy system moving from apology to reversal, compensation, repair service, and systemic fix triggers.
Manual and automated channels must offer equivalent remedy outcomes, timelines, and authority, so no one is penalized for choosing an accessible path.
Cases do not become orphaned across handoffs; ownership persists through vacations, organizational changes, and vendor transfers.
Delegation that stays tied to the evidence that justified it, so the grant can be narrowed, suspended, or withdrawn when that evidence changes.
The record permitting a named holder to take a bounded class of actions, for whom, under what conditions, and until when. What makes authority reviewable and withdrawable.
The stance that authority is held for a term against a renewable justification rather than owned outright. It expires by default; renewal requires fresh evidence.
A versioned statement of the propositions a delegation rests on, each with an expiry. Grants cite policy records so assumptions decay visibly instead of silently.
A declared rule connecting an observation to a state change: when this threshold occurs, this grant moves to this state, answered by this owner, within this clock.
The duty an institution takes on when it delegates consequential action: to notice, stop, reverse, and repair what the delegate does.
Institutional capability deliberately maintained so the institution can still question, replace, or withdraw a system: retained expertise, manual paths, and independent records.
The recognized capacity of an error-bearing party to initiate correction: a challenge that must be received, answered, judged, and able to change state.
The apparatus making standing real: who may challenge which decisions, with what evidence, responders, deadlines, and possible state transitions.
The property of a challenge that obliges a response and can change a state, as distinct from a veto that stops action outright.
The distinction between consenting to enter a dependency and consenting to every degree of dependency its operation later produces.
Power gained because others cannot cheaply make you answer for being wrong—through impossible complaints, proprietary evidence, or appeals that arrive after harm is irreversible.
Whatever prevents the consequences of institutional decisions from traveling back to the actors who can revise the generating rules. Distance from corrective consequence.
The capacity of the governed world to force a system to reconsider—not merely to complain. Contradiction is consequential when it has state-changing force.
Halt authority tiered by blast radius: a frontline operator pausing one case, a supervisor halting a queue, a steward stopping a system.
The authorization decision preceding any grant: whether the system should act at all. Records the evidence, scope, and outcome—including deliberate non-use.
Dependence runs both ways. A population’s reliance on an institution’s system generates duties: notice, preservation of exit, and continuity at withdrawal.
The effective capacity of affected people to make an arrangement change when its demands become unreasonable—to force reconsideration or reversal, not merely complain.
Paperwork and friction are not incidental; they are rationing mechanisms that should be capped, disclosed, or penalized.
An enforceable timer governing system obligations once a decision enters a pending or contested state. Time itself becomes a governed surface.
Specifies maximum time, authority, and procedure for undoing a contested or erroneous decision. Reversal performance is a reliability metric, not an exception.
The system marks something resolved without repairing the underlying harm; the residual cost remains with the person.
The level of confidence, authorization, and oversight required before information becomes action. Protects against low-signal decisions.
Situations where the right action is unclear, requiring caution, clarification, or human judgment rather than confident automation.
A claimant-facing artifact documenting what happened, what the system believes, and what it will do next, by when.
A threshold where small variance causes catastrophic loss of service—lockout, termination, or loss of benefits. Mitigated with soft edges and gradual ramps.
A separate authorization decision when a delegation is widened in scope, population, autonomy, or consequence. The direct block on the automation ratchet.
The property that a decisive action does not close its own categories, evidence, or jurisdiction against revision. Appeal interrupts the conversion of decision into finality.
A scheduled exercise where a system is stood down and the fallback carries real work, producing timings and failures. Evidence, not a claim.
Policy is a state of the running system, not an input consumed at deployment. A policy record has a version, assumptions, an expiry, and a current status.
The condition where a human is part of the control system: they can see the problem, hold authority to act, have time, a path to disagree, and incentives permitting disagreement.
A fact about a system does not become a fact about its authority on its own. Capability and success are evidence, never a grant; authority changes only through recorded state transitions.
A model of a person is not the person. No representation acquires automatic authority to extinguish the represented person’s standing against it.
A system should improve its representation of people and preserve their contestation at once. An incomplete and contestable system is safer than a complete and final one.
Rights as interruptions of illegitimate conversions: privacy, due process, consent, appeal, and separation of powers each keep a capability from becoming an authorization.
The case a representation excludes is potentially evidence about the category, not merely noise. Dissent and standing are epistemic, not only political.
The causal distance between an institutional error and the actors who can revise the generating rule should stay short. Proximity is not visibility.
An institution’s obligations to remain contestable and revisable grow with its capacity to classify, monitor, automate, and scale. Capability may expand only as fast as correction checks it.
TypeSafe AI's Jev returns typed answers and a confidence margin instead of text, at a small fraction of a language model's cost and latency. On its first day, Vercel said about 13% of its paid AI Gateway teams had used it, and agent frameworks were using it to gate tool calls, route tickets, and choose which model answers. Authority moved into the threshold, the router, and the reviewer's queue, and the reasons stopped coming from the thing that decided. STD-08, STD-09, and STD-02 now name each of those places.
No results yet. Try another keyword or clear the search query.