Failure state: User harmed
A user experienced material harm and the system cannot clearly acknowledge what happened, what is owed, or how repair will occur.
The cost of the failure is externalized to the affected user.
Next required artifact
Start with Decision record template. It fixes the owner, the evidence scope, and the reversal path before the response drifts.
- Assign the accountable owner now.
- Capture evidence and timestamps in the first artifact.
- Confirm escalation handoff before opening additional tracks.
Response workflow (triage → stabilize → evidence)
Mechanism, drawn
One artifact per stage
Each stage opens one artifact. The first fixes the owner, the evidence scope, and the reversal path.
-
Triage
Decision record template
Capture the failure state and decision context before evidence drifts.
Next checks: Run governability check · Review contestability standard
-
Stabilize
Harm receipt format
Stop or narrow the harmful flow while the owner and the escalation path are in place.
Next checks: Open escalation simulation · Review human impact safety case
-
Evidence
Reversal SLA template
Assemble the records and the evidence pack, so each repair obligation can be audited against its clock.
Next checks: Check record conformance · Review temporal-rights standard
If a field in these artifacts is hard to fill, that is the governance gap this failure state exposes.