Standards
Normative specifications and safety requirements
Search standards, diagnostics, glossary entries, and field notes in one place.
Scope
Search standards, diagnostics, the glossary, and field notes with URL-based queries for easy sharing.
Quick search
Jump straight into frequent topics or paste a query in the main search field to refine with filters.
Jump to
Key sections
Search
Search is URL-based, so you can share queries with ?q= in the address bar.
Starter queries
Filter by collection
Viewing all collections.
Showing 247 results.
Showing ranked matches based on title, collection, and tag overlap.
Active query: none. Filters: all collections.
Normative specifications and safety requirements
Readiness checks, burden modeling, and validators
Kill switches, appeals queues, and safe state controls
Evaluation test cases and governability benchmarks
Curated reference index and crosswalks
Definitive terms for accountable systems
Operational observations and implementation memos
Working papers and empirical governance studies
Quick-start triage for operators, authors, and auditors
Mission, governance principles, and contributors
Contribute proposals, report issues, and join reviews
Responsible disclosure and security guidelines
Quantifies task load, cognitive friction, and risk exposure so you can reroute toil before it burns people out.
Lightweight evaluation to check if a model and its surrounding UI respect consent and context limits.
Tabletop simulation that plays through outages, maintenance windows, and handoffs to stress-test coverage.
Maps decision speed, intervention readiness, and revenue exposure to quantify maintenance debt risk.
Charts compound decay against refusal windows to spot saturation risk across a 24-month horizon.
Scores escalation readiness so you can see where owners, on-call coverage, and drill cadence are still thin.
Benchmarks evidence pack maturity so teams can prioritize what is missing before audits.
The craft of designing systems that can behave morally. Where ethics asks “What should I do?” and systems theory asks “How does it behave?”, Ethotechnics asks: How can it behave well? Moral behavior is treated as an architectural capability, not a personal virtue.
Observable patterns of system behavior that prevent harm, share burden fairly, and keep people contestable and whole. Moral behavior is evaluated through MPIs such as time-to-halt, reversibility, and fair burden distribution—not by stated intent.
The route moral responsibility travels through a system—across automation, humans, and institutions. A clear ethical load path shows who can stop, reverse, or repair harm at each stage, linking design authority, oversight horizons, and the repair log.
A structured assessment of a system’s capacity to stop harm, reverse it, distribute burden fairly, remain contestable, and enable accountability. Audits surface where stoppability or reversibility fail and guide concrete remediation steps.
The degree to which tools and institutions expand people’s agency, cooperation, and right of refusal instead of enclosing them. Convivial systems keep permission surfaces wide and make opting out safe, so people can shape the service without being consumed by it.
A developmental scale describing how fully a system embodies Ethotechnic capabilities. Early maturity focuses on stopping acute harms; later stages add graceful degradation, contestability, and regular care retrospectives. The highest level treats ethics as continuous operations, with published SLJs and funded maintenance practice.
An approach that prioritizes system mechanics—defaults, authority, clocks, reversibility—over declared values or intentions, because mechanics determine outcomes under load.
The claim that “ethical” outcomes depend less on what institutions say they value and more on the enforceable structure of how decisions are made and reversed.
A way of seeing power as state transitions plus time: who can change state, how quickly, and whether reversal is time-bound.
The set of design features that make contestation real: decision objects, clock-start, binding authority, evidence parity, and guaranteed override paths.
A safety lens where governance is modeled as feedback: detect harm, trigger intervention, enforce constraints, and learn. Useful for translating Ethotechnics into engineering terms.
The delay between harm occurring and the system recognizing it. Automated systems create harms faster than human oversight can register, demanding velocity friction and ethical interrupts.
Responsibility dissolves across teams, tools, and incentives until no one can intervene. A defining pattern of modern institutions and a direct threat to clear design authority.
When a system pulls value—data, attention, labor, or social capital—without returning care, consent, or repair. Extraction hides true costs through externalization and steep burden gradients, hollowing trust.
Systems that depend on workers or users absorbing fragility through burnout, emotional labor, or unpaid cognitive work—often mislabeled as “resilience.” Ethotechnic practice aims to invert this burden with fair burden distribution.
The natural tendency of systems to externalize harm over time unless constrained by protective friction and moral performance indicators.
Pushing risk, cost, or harm onto other teams, communities, or the future so metrics look clean. Externalization shows up as pollution, shadow labor, or brittle dependencies that live outside audits. Ethotechnics counters it with oversight horizons, MPIs, and transparent repair logs.
When a system shatters under real-world variance—unexpected inputs, refusals, or edge cases—forcing humans to absorb impact. Brittleness signals missing soft edges, thin graceful degradation, and poor refusal tolerance.
Metric-chasing that narrows attention to throughput or growth while ignoring MPIs. Myopic optimization erodes contestability, raises failure load, and often fuels extraction.
Using detailed metrics or probabilistic scores to disguise inequity as objectivity. Precision laundering hides burden gradients and externalization behind statistical gloss, undermining explainability for accountability.
When rigid policy checklists replace judgment, causing teams to follow rules while harm worsens. Compliance collapses occur when design authority is weak and contestability is low, leaving no path to pause or repair.
Harm that does not produce immediately legible signals—silence, withdrawal, dropout, dissociation—and is therefore misread as “no issue.”
The accumulated gap between capability and governability, whose interest is paid as incidents, backlash, and legal constraint.
A precise mismatch where system power exceeds controls (brakes, owners, audits, reversibility, recourse).
A system’s ability to halt harmful processes quickly and automatically—without requiring heroism or escalation. Stoppability diagram
The ease with which a system can undo a harmful state change—restore access, correct a record, reverse a flag—without extraordinary effort or power. Reversibility is a governance property: it determines whether mistakes are survivable. Reversibility diagram
Failures do not fall hardest on the most vulnerable. Burden is treated as a design variable and measured via the user burden ratio. Fair burden distribution diagram
The property of a system that allows affected people to force a decision to become a contestable object: something with reasons, a clock, an accountable authority, and a pathway to reversal. A system has contestability when “that’s wrong” can reliably become “here is the specific decision, here is who can change it, and here is when they must respond.” Contestability diagram
A system’s ability to let people say “no” without punishment or degradation—including refusing data extraction, risky defaults, or coercive workflows—while still preserving basic access and dignity. Refusability is not “opt-out exists”; it’s whether refusal is treated as a legitimate state rather than an error condition.
Explanations that are actionable, not decorative. They reveal who made a decision and how it can be corrected, enabling contestability and audits. Explainability diagram
The system remains usable when people opt out, are confused, make mistakes, or withdraw cooperation. Refusal tolerance prevents extraction by endurance by ensuring refusals do not silently convert into extra unpaid work. Called “human” because it protects humans from being turned into the crumple zone when they refuse.
A design principle where systems degrade safely under stress—reduced capability rather than catastrophic denial—especially under accessibility constraints.
Boundary conditions designed to cushion people instead of penalizing them—graduated responses, warnings before lockouts, and reversible defaults. Soft edges reduce failure load and guard against brittleness.
The system defaults to the safest possible behavior when uncertain, prioritizing stoppability.
The system defaults to permissiveness under failure—sometimes necessary, sometimes dangerous. Must be paired with velocity friction.
A harmful state where systems fail without signaling it; the worst possible form of failure because it hides moral latency.
Originally: machines absorb force so people survive. Digitally: people absorb system failures so machines stay smooth. Ethotechnics reverses this direction of impact.
How plainly a system exposes the human impact of its decisions in real time. High harm visibility pairs logs, narratives, and alerts so oversight horizons extend beyond dashboards and ethical interrupts trigger on lived effects, not just technical anomalies.
Places in a system where harm occurs but no one can see, trace, or intervene. Closing dead zones is a goal of oversight horizons .
The predefined point where automated control must yield to human judgment because risk, ambiguity, or moral latency is rising. Escalation horizons activate ethical interrupts and route cases to accountable stewards before crossing an irreversible boundary .
The moments, interfaces, and channels where people experience system decisions and can intervene. Mapping the interaction surface reveals where to place dignity friction , widen the permission surface , and detect dead-user zones .
Systems split into high-contestability (slower, trusted, deployable in high stakes) and low-contestability (fast, then blocked).
A scheduled calm state where teams intentionally slow or stop throughput so inspections, upgrades, and rehearsals can happen without crisis pressure. Maintenance windows make stoppability routine instead of reactive. Each window is negotiated with the people impacted, includes published service guarantees, and documents which safeguards were tested so unfinished work rolls into the shared repair log .
A facilitated reflection held while the system is still in a warning band to examine how maintenance load, emotional labor, and unresolved incidents are accumulating. Care retrospectives combine telemetry with frontline testimony. They redistribute responsibilities before burnout or harm escalates, triggering new maintenance windows or policy fixes when the team cannot keep absorbing risk.
A living record of every mitigation, decision, and resource commitment made after a fault. Repair logs make accountability legible by linking people harmed, who intervened, and what evidence was used. They inform future care retrospectives , power audits, and service-level reports so follow-up work is traceable and burden does not drift back to the same communities.
The bodily, cognitive, emotional, and temporal limits all humans share. Ethotechnics treats finitude as a design input, not an inconvenience.
The load level at which human decision quality collapses—too many alerts, too little time, or excessive context switching. Ethotechnic design lowers saturation by adding velocity friction , simplifying interaction surfaces , and staffing to real maintenance metabolism .
The sustainable amount of emotional labor a system asks of people—care teams, moderators, frontline staff, or users. When compassion bandwidth is exceeded, dread work grows and extraction by endurance sets in.
The feeling of being personally at fault for harms produced by system design. Often a signal that moral overhead is too high.
Tasks people avoid because the system punishes mistakes or withholds relief. Dread work signals missing soft edges , low contestability , and declining compassion bandwidth .
The idea that modern systems sort people by their capacity to perform sustained administrative labor—tracking tasks, managing documentation, navigating ambiguity—making disability and burnout into structural disadvantage.
A discipline that studies how systems interact with real human limits—fatigue, confusion, stress—often revealing that “user error” is actually design failure.
Design that treats front-line workers as key safety components and ensures they have authority, tools, and non-punitive reporting to prevent harm.
Legibility: being representable in the system’s categories and workflows. Illegibility: being real but not representable, leading to churn, delay, or denial.
The number of times a person can decline, pause, or question a request without retaliation. Healthy refusal budgets, backed by refusal tolerance and rights of exit , prevent coercion and surface heat maps of refusal .
How a system allocates the cost of operation or failure—time, attention, stress, and emotional labor.
The slope of effort and risk across roles or communities. A steep burden gradient means those with the least power carry the heaviest operational load while decision-makers feel little friction. Mapping the gradient exposes where to redistribute work through fair burden distribution and reduce moral overhead .
The amount of harm generated when the system fails. Ethotechnics seeks low-failure-load architectures supported by graceful degradation .
Moments when system failure pushes labor onto humans, often triggering moral overhead .
A mechanism where systems offload the labor of safety, clarity, and follow-through onto individuals (forms, documentation, vigilance) while keeping institutional obligation low. It’s how “choice” becomes unpaid work.
The ongoing monitoring burden imposed on individuals to prevent harm: checking portals, tracking deadlines, resubmitting documents, watching for silent rule changes. Attention becomes a cost of staying eligible.
The baseline flow of upkeep—patching, cleaning, rehearsing, and caring—that keeps a service alive when nothing is on fire. Healthy maintenance metabolism is budgeted, scheduled, and shared rather than squeezed between crises. Falling below it signals rising maintenance debt and invites maintenance windows before fragility compounds.
Accumulated obligations from skipping basic upkeep. The interest is paid in slower recovery, brittle systems, and people burning out to keep things running. Paying it down requires restoring the maintenance metabolism , scheduling maintenance windows , and tracking work in the repair log .
Extra work users or operators must do to behave ethically within a bad system.
Uncompensated seizure of life-hours (time, attention, opportunity cost) as the price of accessing a right or correction. Temporal exaction is a form of extraction that inflates the user burden ratio.
A composite measure of how much effort, time, and emotional labor people expend to use or recover from a system. Inputs include the user burden ratio , human substitution index , and failure load ; rising scores signal extraction or asymmetric sustaining .
The maximum allowable procedural burden a system can impose on someone seeking safety, correction, or relief. Ceilings are defined per harm class and enforced through UI, staffing, and policy.
When one group continually absorbs the toil of keeping a system alive so another group can move fast or claim success. It often hides behind gratitude for “resilience” while masking extraction . Ethotechnic practice flattens this by lowering the burden gradient and designing for stoppability so resilience is institutional, not personal.
The unpaid labor, vigilance, or emotional buffering people contribute to keep brittle systems functioning. Fragility subsidies hide true costs, inflate success metrics, and deepen asymmetric sustaining .
Key metrics that show a system’s ethical functioning: time-to-halt (TTH), reversibility rate, appeal success rate, burden ratios, and more. MPIs complement traditional KPIs by tracking how safely and fairly a system operates, not just how fast it grows. Moral performance indicators diagram
Operational metrics tied directly to fairness, safety, and dignity. SLJs should sit alongside uptime and latency commitments.
How well a system delivers review → reversal → remedy under realistic load and stress.
A diagnostic mapping of where energy, care, time, and money circulate inside an institution. It visualizes maintenance metabolism, burden gradients , and points of extraction . Teams use the map to set SLJs , redesign roles, and decide where to invest new maintenance windows .
Seconds between a harmful process beginning and the system stopping it—an essential complement to stoppability . Time to halt diagram
How long it takes to reverse harm and return a person to their prior state. Low TTR is a signal of effective reversibility .
The percentage of appeals resolved in favor of the user , a leading indicator of true contestability .
The share of system actions that cannot be undone. Aim to keep this as low as possible through reversibility and graceful degradation .
A predefined cap on the share of actions allowed to be effectively irreversible in a given system or workflow class. Budgets force designers to minimize irreversible boundaries and build rollback lanes for everything else.
How much work a user must perform to correct or navigate system errors. This metric feeds directly into fair burden distribution .
A measure of how often humans must step in to compensate for system shortcomings—manual reviews, ad-hoc patches, or empathy work. A rising index exposes heroism-dependent systems and motivates investment in graceful degradation .
The trustworthiness of alerts, metrics, and reports used to govern a system. High credibility pairs transparent sampling, explainability for accountability , and human testimony so warnings trigger action instead of alert fatigue or dismissal.
The time, money, emotional labor, documentation, and social risk required to undo an outcome. High reversal cost makes errors durable and turns “rights” into luxuries.
How long a wrong state persists once created, and how far it propagates (downstream systems, eligibility, reputation). A system is dangerous when it can create durable errors quickly but correct them slowly.
The accumulated harm a system has caused but not repaired. Moral debt accrues interest as moral latency grows and people lose trust; it is paid down through pathways to restitution , transparent repair logs , and lowered time-to-restore .
The accountable power to set moral constraints, choose safeguards, and fund enforcement. Clear design authority aligns incentives, protects contestability , and prevents accountability diffusion .
The distance regulators, auditors, or affected communities can see into a system’s decisions and their effects. Extending the horizon—through harm visibility , traceable models, and shared repair logs —shrinks dead zones .
A system is legitimate insofar as affected parties have standing, voice, and remedy against its decisions/actions.
The practical capacity to monitor, review, and repair is a political/organizational legitimacy input, not overhead.
People should automatically get “what happened” records: actions taken, permissions used, reasons, and accountable owners.
Sovereignty is the ability to impose enforceable constraints on infrastructure operating in your territory.
Global competition shifts to whose regimes for auditability, liability, and redress become default through supply chains and procurement.
Governance infrastructure can either enable rights-preserving contestability or scaled conduct control, depending on who has standing and remedy.
What users can do without institutional approval — a measure of autonomy and a prerequisite for contestability .
Agent autonomy is a conditional privilege granted only when monitoring, brakes, and recourse capacity are demonstrably adequate.
Guaranteed, non-punitive ways to leave a system (or refuse a pathway) while preserving access to essentials, records, and future participation. Exit rights treat departure as a legitimate action, not a breach.
The pathways an institution uses to push risk or cleanup onto others: contractors, users, bystanders, or future teams. Mapping these channels exposes externalization and informs fair burden distribution .
A negotiated period where teams pause growth work to focus on care, maintenance, and accountability. Stewardship windows bundle maintenance windows , publish SLJs for the pause, and commit to closing items in the repair log before resuming throughput.
Control exercised by keeping matters unresolved long enough that time itself produces the outcome. Governance by suspension relies on non-decisions and exploits endurance asymmetry.
Institutions can persist indefinitely; humans cannot. This makes delay an allocation mechanism that underwrites continuity privilege and punitive friction.
Unequal access to enforceability produced by unequal capacity to maintain standing over time (attention, health, documentation, slack). Continuity privilege steepens the burden gradient for those without reserves.
Unequal enforceability produced by unequal ability to delegate persistence (agents, intermediaries, automation). Proxy privilege lets some parties bypass futility thresholds that others face alone.
The principle that delay produced predictably by system rules (queues, resets, blocked escalation, absent deadlines) is attributable power, not mere inaction.
A fixed maximum time-to-resolution; breach triggers an enforceable disposition. Bounded duration pairs with stable clocks and time transparency.
A persistent cumulative record; no forced repetition of validated inputs. Continuity of state reduces temporal exaction and protects contestability.
No adverse consequences while review is pending (except narrow, reviewable emergency exception). Safe pause preserves the utility window and keeps people whole during appeal.
A named responsible party with authority to override automation when bounds are breached. Traceable ownership clarifies design authority and accelerates time-to-restore.
Legible process state: current step, blocking condition, time remaining, next decision point, escalation triggers; no fake progress. Time transparency supports contestability and stable clocks.
The degree to which a system’s outputs create enforceable obligations—deadlines, duties, remedies, or reversals—rather than mere communications. Bindingness is the difference between “we received your request” and “we must decide by Friday or you win.”
The condition where a system can interact, respond, and even apologize without being compelled to change state. Non-bindingness is power without accountability: activity without obligation.
Standing is the recognized right to make the system bind itself to engage, decide, and remedy—regardless of whether your story is believed, liked, or emotionally legible. “Belief” is narrative validation; standing is enforceable access to decision power.
A person or role that can change the underlying state and is obligated to respond. Binding authority is not “a human is involved”; it’s a human with power + duty + traceable accountability.
A condition where affected people have a fair chance to meet the evidentiary burden—access to the relevant facts, rules, and records—rather than being asked to prove things the institution can’t or won’t disclose. Without evidence parity, appeals become theater.
The mapping of who can change what state, at which stage, under what constraints. Authority chains determine whether escalation is real.
A pattern where escalation changes how the institution speaks without changing who has power to reverse outcomes. Authority mutates when the channel upgrades (more polite, more official, more complex) but the underlying ability to bind remains absent.
The idea that the baseline state—what happens if nobody intervenes—is a primary allocator of outcomes and costs. Defaults govern by deciding who must spend time, attention, and stamina to avoid harm.
A stratification system where people are divided by their ability to force binding action: who can start clocks, reach authorities, obtain reversals, and make claims legible. It’s a caste system of enforceability, not worth.
A channel change that does not increase binding power—more forms, more tiers, more waiting—while the underlying decision remains unchangeable. It’s escalation as delay management, not remedy.
The set of mechanisms that can correct harm: appeal, review, reversal, compensation, restoration. Redress is real when it is time-bound and reaches binding authority.
A clearly defined mechanism that can supersede the default workflow when the default would cause harm—e.g., human escalation with real authority, emergency reversal, exception handling with deadlines. Override paths are where “care” becomes material.
An exit process designed to protect the leaver: clear steps, data portability, timelines, anti-retaliation constraints, and closure that doesn’t require ongoing performance. Structured exit turns leaving into a governed pathway instead of an endurance test.
When access to contestation, speed, or binding review is effectively purchased—through fees, premium support, lawyers, consultants, or time flexibility. Rights exist, but only for those who can pay in money or stamina.
The idea that control over records—what is logged, who can see it, what counts as evidence—shapes who can contest outcomes. Recordkeeping is governance.
A trace of events and decisions—what happened, when, by whom, under what rule—used for accountability. Audit trails matter only if they connect to reversal power.
The world as the system recognizes it: what counts, what is recordable, what triggers action. Administrative reality often diverges from lived reality.
A take-it-or-leave-it contract offered by a more powerful party where negotiation is impossible; a common substrate for coerced “choice.”
Mechanisms that suppress exit stories—legal threats, informal retaliation, reputational control—preventing systems from being held accountable by shared evidence.
Friction that slows harmful processes and keeps moral latency within safe bounds.
Friction that punishes users—often hidden in bureaucratic loops. Signals extraction by endurance .
Friction that preserves autonomy, such as double checks on irreversible actions.
Friction added specifically to prevent runaway system behaviors. Often implemented through ethical interrupts .
A deliberate release point that lets people slow, pause, or reroute automation before harm compounds. Safety valves pair stoppability with dignity friction so high-stakes flows default to reversible states and route to humans without penalty.
The sequenced touchpoints where a person learns what a system will do, grants or denies permission, and can revise that choice over time. Strong consent journeys use anticipatory consent , visible permission surfaces , and healthy refusal budgets so pausing or exiting does not jeopardize access or care.
“Agreement” obtained through defaults, asymmetry, or threats of exclusion—consent produced by lack of viable refusal.
The calibrated blend of protective, dignity, and velocity frictions.
Add checkpoints where stakes are high so that fairness and safety survive speed and scale.
Harms that spread unchecked because safeguards or pauses were stripped away. Frictionless harm is the inverse of protective friction ; it appears when velocity friction and dignity friction are absent.
The precise moment when a choice shifts from reversible to consequential. Making the decision edge visible enables dignity friction , clearer consent, and routing to ethical interrupts when risk spikes.
The part of a system where decisions become visible, addressable, and contestable. Many systems minimize the decision surface to avoid accountability.
A discrete, attributable, contestable output: outcome + reason + timestamp + accountable owner. Decision artifacts anchor traceable ownership and make contestability measurable.
A discrete, addressable unit of institutional action that can be challenged: what was decided, when, under which rule, by what authority, with what evidence. Decision objects are the “handles” that make contestation possible.
The process by which a complaint, harm, or request becomes a decision object—assigned an identifier, a category, an owner, a standard of review, and a clock. Systems often block accountability by preventing object formation (“nothing exists to appeal”).
A stable administrative disposition where a system withholds a contestable outcome (pending, in review) while consequences accrue. Non-decisions stretch moral latency and keep people in limbo.
A default state where nothing is decided and no one is obligated—often presented as neutral but functioning as an outcome allocator. Pendingness becomes harm when it lacks a clock, an owner, or a forced next step.
The moment a claim becomes resolved in a way that changes the underlying state—approved, denied with appeal rights, remediated, reversed, paid, restored, or otherwise closed with consequences. Settlement is not closure in the CRM; it’s resolution that binds.
An institutional mode where claims are acknowledged and processed indefinitely without producing a binding resolution. The system offers intake, updates, and politeness while keeping obligation optional.
A non-resettable timeline for a case; the system cannot restart time via re-ticketing, re-verification, or channel switching. Stable clocks enforce bounded duration and keep timelines legible.
Clock-start: the moment a system becomes time-bound—deadlines begin, obligations attach, escalation becomes meaningful. Clock mismatch: when institutional execution is fast (instant flags, freezes, denials) but redress is slow (weeks-months-human review), making errors durable and contestation scarce.
A governance asymmetry where harmful state changes are immediate but appeals are delayed, discretionary, and exhausting. This is one of the main engines of modern coercion.
The time span during which relief can still prevent the relevant harm. Designing for a clear utility window keeps time-to-restore accountable.
Crossing the utility window; relief arrives too late to matter. Utility expiry should trigger constructive denial or repair.
The point where time-on-task or repetition becomes so costly that valid claimants predictably abandon pursuit. Systems that hit the futility threshold signal punitive friction and low contestability.
A legal state where delay is treated as refusal because it destroys utility or makes pursuit futile. Constructive denial recognizes utility expiry and forces accountable remedies.
Any system action that meaningfully alters a person’s status, access, or trajectory. Critical actions require dignity friction .
A state where reversal is practically unavailable (too slow, too expensive, too discretionary) even if it is theoretically possible. Irreversibility is often produced by missing clocks, missing authority, or asymmetric evidence demands.
A threshold the system cannot automatically undo—account closures, public releases, or data publication. Crossing it demands heightened contestability , audited explanations , and explicit time-to-restore plans.
A guaranteed fallback mechanism that triggers when the main process fails—timeouts, automatic approvals, emergency restoration, or external review.
A designed ability to revert the system to a prior safe state—restoring access, undoing propagation, correcting records—ideally with minimal friction.
Default state transitions that happen without active consent—closing claims, renewing contracts, expanding data use—often presented as convenience while functioning as governance by inertia.
Automatic system-level halts triggered by anomalies or harm indicators. Ethical interrupts operationalize stoppability .
Systems that rely on extraordinary effort, unpaid care, or silent sacrifice to function. They mask poor stoppability and high failure load .
Simulated warmth—chatbots, scripted apologies, tone guidelines—used to mask structural harm or delay fixes. Empathy surrogacy diverts attention from repair and weakens contestability by substituting sentiment for remedy.
Small automated mistakes that amplify across the system. Prevented through ethical interrupts and SLJs .
Hidden behaviors that appear under stress—shadow queues, silent throttling, or undocumented overrides. Invisible fallbacks obscure ethical load paths and should be surfaced through graceful rollback lanes and rehearsed in maintenance windows .
Places where people affected by decisions cannot contest, appeal, or exit—opaque rankings, automated bans, or unmoderated queues. Closing dead-user zones requires widening the permission surface and raising appeal passage rates .
When harmful defaults become entrenched through dependencies, network effects, or contracts that block reform. Moral lock-in is prevented by moral feature gating , contestability , and vigilant moral drift control .
The process of converting coercive or indifferent outcomes into reputational legitimacy through procedural signals—case IDs, polite updates, “in review”—without delivering binding resolution. The system looks responsible while staying unbound.
Coercion delivered through soothing language and “helpful” workflows that make refusal costly or stigmatized. Polite coercion is power that avoids looking like power.
A repeating pattern where the system continually requests more evidence or re-uploads without moving toward a binding decision. Often used to shift labor onto claimants and to manufacture dropout.
Requests for ever-greater specificity that function less as truth-seeking and more as denial hooks—ways to keep a case non-objectified or non-decidable. Precision demands are a technique of delay.
A record of “process” used to defend outcomes (“we followed procedure”) even when the procedure cannot bind the institution to remedy. The alibi is the trace of activity, not accountability.
The use of “appropriate tone” requirements to control access to remedy—penalizing anger, urgency, neurodivergent communication, or exhaustion. Tone policing converts distress into disqualification.
When systems treat nonresponse, fatigue, or disappearance as consent or closure (“case closed—no reply”), laundering coercion into “resolved.” Dropout becomes the mechanism that protects the institution.
The engineered cycling of people through forms, queues, and handoffs until they give up, miss a deadline, or become “inactive,” allowing the system to close without settlement.
Compliance regimes focused on producing documentation of doing the right thing rather than mechanisms that can actually prevent harm or force remedy. The paperwork stands in for power.
Disclosures that do not increase contestability—more text, more dashboards, more “explanations”—without deadlines, authority, or reversal paths. Visibility substitutes for enforceability.
A focus on explaining model decisions that distracts from the harder question: can the decision be contested, reversed, and time-bounded? The decoy offers epistemics where governance is needed.
A human reviewer inserted to create legitimacy while lacking binding authority, deadlines, or meaningful discretion. The loop becomes a comfort signal, not a power shift.
A style of analysis (and sometimes art) that treats procedures, channels, and workflows as the real plot—where power is shown through process.
A label for stories where the drama is the intake/eligibility channel—forms, interviews, caseworkers, waiting rooms—rather than a single decisive confrontation.
Instrumentation and controls that detect when system behavior drifts from ethical baselines—through MPIs or user testimony—and automatically trigger interrupts or design changes.
Measures of how forgiving an infrastructure is to human variance: error tolerance, recovery time, and soft edges . Higher coefficients correlate with lower failure load and safer degradation .
How effort and risk stretch or rebound between actors when conditions change. Mapping burden elasticity alongside the burden gradient prevents crises from snapping back onto the least powerful.
Overlapping care pathways—humans, automation, and policy—that ensure someone is caught when another safeguard fails. Care redundancy pairs with graceful degradation to keep failure load low.
Mechanisms that let people challenge not just outcomes but the rules of challenge themselves—who may appeal, what evidence counts, and who sits on review panels. Meta-contestability keeps contestability from ossifying.
Inferring user states—fatigue, distress, inattention—to adapt pacing, add protective friction , or route to humans before harm compounds. Models must respect anticipatory consent and avoid new burden transfers .
Designing for unavoidable delay between action and ethical evaluation by staging risky steps, adding velocity friction , or seeking care floor guarantees while fuller review occurs.
Coordination methods that keep responsibility legible across teams and automation: shared playbooks, auditable handoffs, and repair logs . Protocols prevent accountability diffusion when work moves.
A common vocabulary for classifying moral failure modes— optimization myopia , brittleness , extraction , and more—so incidents can be compared, learned from, and prevented.
Dynamic flows that reroute tasks when someone pauses or declines, preserving context and avoiding retaliation. Adaptive pathways extend refusal budgets and strengthen refusal tolerance .
Automated follow-up that checks on impacted people after incidents, schedules remedies, and prompts humans to close the loop. Done well, it lowers moral debt without creating new moral overhead .
The measurable upside—trust, retention, safety—generated when systems align with human values. Tracking the dividend builds the business case for sustained investment in MPIs and maintenance metabolism .
Explicit allowances for uncertainty that prevent premature automation or brittle enforcement. Ambiguity budgets reserve time, human review, or maintenance windows until context is sufficient.
Consent models that preview future data uses and let people pre-approve, defer, or block them. Anticipatory consent supports rights of exit and counters precision laundering of unclear terms.
Dynamic thresholds defining when moral risk exceeds the system’s mandate and operations must halt or escalate. Boundaries are tied to SLJs and enforced through ethical circuit breakers .
Baseline commitments a service maintains even during outages or crises—live support, data export, or safe defaults. Care floors protect users when graceful degradation activates.
Signals that show whether interactions feel humane—response tone, wait times during distress, quality of follow-up. Compassion telemetry complements technical metrics to protect compassion bandwidth .
Instrumentation that makes value conflicts visible in logs and dashboards before they erupt—flagging when SLJs trade off against throughput or when appeals spike. High observability enables earlier moral drift control .
Limits that prevent tools from being repurposed for harassment, exploitation, or coercion—rate limits, anomaly detection, and human override lanes tuned for abuse scenarios.
Regular drills that stress-test moral responses, not just uptime. They practice ethical interrupts , validate care floors , and update repair logs with lessons.
Caps on data collection and use that respect personhood and context, not just legal checkbox consent. Budgets align with anticipatory consent and guard against extraction .
A register of deferred decisions and their moral interest, reviewed before debt compounds into harm. The ledger feeds maintenance windows and informs MPIs .
Design slack that absorbs variance so marginalized groups do not pay first or most when errors occur. Buffers include staggered rollouts, rollback lanes , and targeted support funds.
Automated stops that trip when moral risk indicators cross predefined set points—surges in appeals, bias metrics, or moral debt . They are the safety counterpart to financial circuit breakers.
Deliberate exercises that probe how systems behave under moral stress—simulated harassment, mass appeals, or outage scenarios—to validate ethical circuit breakers and care floors .
Signals that detect operator or user fatigue—error streaks, long queues, late-night decisions—and automatically slow, pause, or hand off flows before mistakes multiply. Triggers protect compassion bandwidth .
Planned allocations of protective and dignity frictions across journeys to balance safety with usability, rather than defaulting to speed.
Prepared routes to revert harmful decisions while preserving dignity, evidence, and service continuity. Rollback lanes keep irreversibility indices low and shorten time-to-restore .
Time-boxed periods where people can report or reverse harmful actions without penalty, encouraging disclosure and faster repair . Amnesty windows often follow rehearsal loops or incidents.
Visualizations showing where users opt out, churn, or appeal—revealing coercion hotspots early. Heat maps help tune refusal budgets and redesign interaction surfaces .
Guaranteed routes for human judgment to supersede automation when stakes are high or context is missing. Override lanes accompany ethical interrupts and require clear ethical load paths .
Linked records that keep lessons from past incidents attached to similar workflows so knowledge stays actionable. Memory chains inform ethical load tests and prevent moral lock-in on bad patterns.
Pre-launch walkthroughs that simulate ethical dilemmas to harden designs before they reach the public. Dry runs test circuit breakers , rollback lanes , and documentation.
Controls that block feature launch until moral readiness criteria—oversight plans, contestability pathways, and care floors —are met.
Documented steps a system must take to repair harm: acknowledgement, remedy, verification, and follow-up. Pathways reduce moral debt and belong in the repair log .
Routing logic that accounts for who can decline tasks and ensures refusals are respected without retaliation or silent penalization. It preserves refusal budgets and keeps workflows humane.
Assurances that regardless of pathway, people can access relief with predictable effort and support. Relief invariants are tested in crisis rehearsals and anchored by care floors .
Minimum participation rules for authorizing fixes so impacted communities have a seat in deciding remedies. Repair quorums counter accountability diffusion and legitimize restitution .
Built-in mechanisms that enforce rest and recovery—rotation policies, cooldown timers, enforced downtime—so fatigue does not translate into harm. Enforcement protects maintenance metabolism and compassion bandwidth .
Designers steward human dignity and collective resources; they must leave systems safer and more reparable than they found them. Conservancy prioritizes repair , stoppability , and minimizing moral debt .
When harm occurs, the system shoulders effort before the person harmed does. Burden inversion lowers the user burden ratio and demands rapid restoration .
Halt harmful behavior first, then justify or refine it. Systems must trigger ethical interrupts before offering explanations, preserving reversibility .
Ethical performance depends on continuous upkeep—funded maintenance metabolism , scheduled maintenance windows , and transparent logs .
Design so that when failures occur, human impact is contained. This principle motivates graceful degradation , care floors , and low irreversibility indices .
Critical actions must be undoable or paired with rollback lanes . The mandate aligns with time-to-restore targets and contestability .
People affected by system decisions can challenge, change, or overturn them—and win. Guarantees include wide permission surfaces , high appeal passage rates , and transparent design authority .
Design sprint notes on re-requesting consent with clear exits and translated summaries.
How a support team added in-product appeal flows without derailing delivery.
Lessons learned from simulating service degradation and renegotiating stewardship windows.
No results yet. Try another keyword or clear the search query.