For accountable managers and operations leadership
Oversight that means anything is a bounded grant held by a named person, a category of act the system refuses to perform at all, and a record that already contains the answer. A review queue too large to read is not oversight — it is a signature collected in advance and it will be read that way afterwards.
The question comes months after the act. A complaint, an examination, a journalist, a tribunal, an internal escalation — and it takes one form: who authorised this. What makes it hard is not that the answer is embarrassing. It is that the answer usually has to be assembled, from memory, by people who were not there, under a deadline set by somebody else.
Automation makes the assembly harder in a specific way. When a colleague performs an act, the accountability chain is legible even when it is uncomfortable — a name, a shift, a supervisor. When a step is performed automatically, the same question produces a description of a process, and a description of a process is not an answer to who.
The mitigation everybody reaches for is a review queue, and it fails predictably. A queue sized for a slow operation is read. A queue sized for a fast one is approved in batches by somebody working through it, and the approval is a signature collected in advance. Anyone examining it afterwards can tell the difference from the timestamps alone, and they do.
The subtler failure is influence without decision. A system that does not decide anything, but orders a queue — which application is looked at first, which account is contacted, which case rises — has shaped the outcome while every document truthfully says a person decided. That is the exact arrangement a fair-treatment examination is designed to find, and the defence that a human made the final call does not survive it.
And there is the delegation nobody wrote down. An automated step gets extended by a team who needed it to do slightly more, the extension is sensible, and the authority it now exercises exceeds anything anybody granted. Nothing failed. The boundary simply moved, quietly, in the direction of convenience.
Oversight fails when the reviewing human cannot possibly read what is placed in front of them — so the boundary has to be set where authority is granted rather than at a queue, and some categories of act have to be refused outright rather than routed for approval.
Authority here is a grant rather than a capability. A named person grants a bounded permission — this category of act, within these limits, for this period — and the grant carries an expiry at the moment it is made. Nothing acquires authority by being useful, and an automated step that would exceed its grant stops and asks rather than proceeding and reporting.
The second half is refusal, and it is the half that matters more. Some categories are not routed for approval at all because approval is not the safeguard people imagine. Determining an individual’s eligibility for a benefit, entitlement or service. Deciding a person’s employment, discipline or standing. Scoring a person for treatment. Ordering a queue of people by anything resembling desirability. Those are refused as acts, and the refusal is stated on the page because the buyer is usually the person who would carry the consequence.
The ordering refusal deserves its own sentence because it is the one that gets softened. A system that merely arranges which applications, which accounts or which cases are addressed first has influenced the outcome while every record says a person decided. So the exclusion is drawn at influence rather than at decision, and softening it to "we do not decide" would be a weaker sentence that protects nobody.
What the automated steps do instead is the work around the decision: assembling what is needed, chasing what is missing, preparing what a person will read, performing what has already been decided, and keeping the record. That is where the volume is, it is where the burden is, and none of it requires the system to hold a judgement about a person.
The record is designed so the eventual question is answered rather than reconstructed. Each act carries the grant it was performed under, the named person who holds that grant, what triggered it, what it did, and what a person changed afterwards. That record lands in your systems, which matters: an accountability answer that depends on a supplier producing a report about themselves is the weakest available position and everybody examining it knows so.
Who authorised a specific automated act — measured by reading one record and finding the grant and the named person who holds it.
What an automated step is permitted to do today — measured by the live grant list, readable without asking anybody.
Whether a grant is still live past its reason — measured by every grant carrying an expiry, checkable in the same list.
Whether anything was performed beyond its grant — measured by the record of stops and escalations, which should be non-empty in a real operation.
Whether a person actually engaged with a review — measured by the interval between presentation and decision, visible in your own record.
Whether a refused category was ever attempted — measured by the exclusion list, and the absence of any such act in the record.
no determination of eligibility for a benefit, entitlement or service; no decision about employment, discipline or standing; no scoring of a person for differential treatment; and no ordering of a queue of people by anything resembling desirability, priority or likelihood. Those are refused as acts rather than routed for approval, because approval is not the safeguard it appears to be. No claim that a reviewing person will read what they are shown — which is why the boundary is at the grant.
The named person holding a grant is a person in your directory, not a local account here, so the grant follows your joiner-mover-leaver process. A grant held by somebody who has left is the specific failure this arrangement is built to prevent, and it is prevented by the directory rather than by a review.
Every act, every stop, every escalation and every human intervention lands in your log stream. That is what makes the eventual question answerable from artefacts you hold rather than from a report we author, and it is the difference between an answer and a request.
Where an act touches a system you operate, it does so under a credential you issued and can withdraw. Withdrawing it stops the act without a conversation, which is the only form of control that reliably works during the week somebody is worried.
Because an examination is built to find influence. An arrangement in which a system orders a queue of people and a person approves the top of it produces documents that truthfully say a person decided, and produces outcomes shaped by the ordering. Every fair-treatment examination in every regulated sector is designed to look through the first to the second.
So the exclusion covers ordering by name and it is not softened. Any future material of ours saying only that we do not make the decision is describing a weaker commitment than this page makes, and this page governs. That sentence is here deliberately so a later softening is visibly a change rather than a phrasing.
What we do claim is bounded and checkable. A grant exists, it has an expiry, it is held by a named person from your directory, the act carries it, the record lands in your systems, and an act beyond the grant stops rather than proceeding. Each of those is testable in a trial, and none requires you to believe anything about our intentions.
Every property here is designed rather than independently attested. A SOC 2 Type II attestation is in progress and no report exists yet; it is an attestation with a defined scope and period rather than a certification. No assessment of automated decision-making has been performed by any third party on our behalf.
Insist that the grant list is readable by your team without asking us. A boundary you cannot inspect is one you cannot supervise, and the eventual question will be about a specific act on a specific day rather than about a policy.
Refuse the pattern where volume is routed to a review queue as the safeguard. Ask instead what the system will not do at all, and check that the answer includes ordering rather than stopping at deciding. That single follow-up separates a considered exclusion from a drafted one.
Put the expiry requirement in writing. A grant without one becomes a standing capability by default, and the drift is invisible because nothing fails — it is simply still there long after the reason ended.
And measure engagement rather than assuming it. The interval between something being presented to a person and being decided is visible in your own record, and it is the number that tells you whether your oversight is real. If your own operation produces intervals of seconds at volume, the finding belongs to you rather than to us, and better found now.
A single bounded grant covering one category of act, held by one named manager, exercised for a week with every act landing in your own record.
One grant is enough to answer the questions that matter, because the properties being tested are structural rather than proportional to volume. Does the act carry the grant. Does a boundary stop it. Does the record land where it should. Does revocation work immediately.
Revoke the grant partway through deliberately, and confirm the act stops without anybody contacting us. That is the control that has to work in the week somebody is worried, and it is the one least often tested.
Then read the record as an examiner would, rather than as an operator. If it does not already answer who authorised what, the arrangement has failed the test this page exists to set — and finding that in one week is the entire point of starting with one grant.
It depends entirely on whether the volume is readable, and the timestamps in your own record will answer that faster than any policy discussion. A queue sized for a slow operation gets read; a queue sized for a fast one gets approved in batches, and the interval between presentation and decision reveals which you have. That is why the boundary here sits at the grant rather than at the queue: a bounded permission held by a named person constrains what can happen regardless of how much attention the review actually received.
Because ordering is deciding, wearing different clothes. A system that arranges which applications are looked at first, which accounts are contacted, or which cases rise has shaped the outcome while every document truthfully records that a person decided — and that is precisely the arrangement a fair-treatment examination is designed to look through. Drawing the exclusion at influence rather than at decision costs us scope and it protects the person who would carry the consequence, which is usually the person reading this page.
It will stop sometimes, and a record showing zero stops in a real operation would be evidence that the boundary is drawn too loosely rather than evidence that everything is going well. The stops are the point: each one is a case where the act was about to exceed what somebody granted, and it became a question to a person instead. What reduces them over time is not widening the grant quietly but issuing a considered one — and a widening is a decision your named manager makes and the record shows.
From your own record, without reconstruction, and that is the design goal rather than a side effect. Each act carries the grant it was performed under, the named person holding that grant, what triggered it, what it did, and what a person changed afterwards — and the record lands in your log stream rather than only in ours. An accountability answer that depends on a supplier producing a report about themselves is the weakest available position, and the people who ask these questions know it.
That is the correct worry and it is why every grant carries an expiry set at the moment it is issued. Nothing acquires authority by turning out to be useful. An act that would exceed its grant stops rather than proceeding and reporting, and widening a grant is an act your named manager performs, with the change visible in the same list your team can read. The drift you are describing is invisible in most arrangements precisely because nothing fails when it happens — here the boundary refuses instead of stretching.