Failure state: User harmed

A user experienced material harm and the system cannot clearly acknowledge what happened, what is owed, or how repair will occur.

The cost of the failure is externalized to the affected user.

Next required artifact

Start with Decision record template. It fixes the owner, the evidence scope, and the reversal path before the response drifts.

  1. Assign the accountable owner now.
  2. Capture evidence and timestamps in the first artifact.
  3. Confirm escalation handoff before opening additional tracks.

Response workflow (triage → stabilize → evidence)

Mechanism, drawn

One artifact per stage

Each stage opens one artifact. The first fixes the owner, the evidence scope, and the reversal path.

1 · Triage Decision record template 2 · Stabilize Harm receipt format 3 · Evidence Reversal SLA template
  1. Triage

    Decision record template

    Capture the failure state and decision context before evidence drifts.

    Open Decision record template

    Next checks: Run governability check · Review contestability standard

  2. Stabilize

    Harm receipt format

    Stop or narrow the harmful flow while the owner and the escalation path are in place.

    Open Harm receipt format

    Next checks: Open escalation simulation · Review human impact safety case

  3. Evidence

    Reversal SLA template

    Assemble the records and the evidence pack, so each repair obligation can be audited against its clock.

    Open Reversal SLA template

    Next checks: Check record conformance · Review temporal-rights standard

If a field in these artifacts is hard to fill, that is the governance gap this failure state exposes.