Browse the territories, or toggle the patterns in them.
Binding a tamper-evident record of origin and edit history to a digital file at the point of intake. An agency can settle a question about a submission's origin from the record itself, without contacting anyone who handled the file.
Letting a submitter prove who they are, what they're qualified for, or what authority they hold, using a portable credential an agency can check. An agency gets a claim it can check at intake, without collecting identity documents it then has to protect.
Asking the submitter to state, in a structured way, how their submission was prepared: personally, with help, with AI tools, or on an organization's behalf. The declaration gives reviewers a preparation signal on every submission without adding work that deters honest submitters.
Confirming that a human was involved in a submission without necessarily learning who they are. A reviewer deciding what to act on can see whether a human was confirmed, and at what strength.
Capturing how a submission was put together (timing, structure, what was typed and what was pasted) as a byproduct of the intake itself, so the preparation signal itself costs the submitter no extra effort to produce. Reviewers get context on how an entry was prepared without asking the submitter for a separate declaration or proof of how they wrote it.
Letting a submitter show how their text was built: which parts they wrote, which came from a tool or a template, and what sources fed it. Reviewers can give a submitter's own account the weight template text can’t claim.
Giving an unverified declaration real weight instead of asking every submitter to prove it up front. Without something backing the declaration, an agency must either demand proof most submitters can't produce, or treat every declaration as meaningless.
Letting a user grant an agent exactly one bounded permission (lodge this return, touch nothing else) in a form the service can enforce. If the agent misbehaves, the harm stops at the boundary of the one permission the user granted.
Adapting the power of attorney, the oldest instrument for scoped, revocable delegation, to a delegate that is software rather than a named person. When a delegation is disputed, agencies and users inherit a legal instrument courts already know how to read.
Taking a user's authorization through a consent flow the user completes with the government rather than with the agent: scoped permissions, strong authentication, and a standing dashboard for review and revocation. A compromised or over-reaching agent can't use credentials it never held.
Giving every delegation a durable, verifiable record: what was authorized, by whom, for how long, and what was done under it. When a delegation is later disputed, the user and the agency can point to the same record of what was authorized.
A registry an agency can query at the moment an agent acts, so a delegation can be checked without contacting the user, who is usually not there.
Tying every delegation to a user identity verified to a known assurance level. When a delegation is challenged, the agency can trace it to a person whose identity was verified at a known level.
Pausing an agent at the sensitive or irreversible step and putting that one decision back in the user's hands, at a confirmation strength matched to the stakes. Routine actions proceed on the standing grant; consequential ones wait for the user.
Requiring the user to nominate the agent that will act for them, rather than letting the agent nominate itself. The nomination record lets an agency refuse any agent the user never appointed.
Letting a user write the standing rules for their agent in advance (what it may do, when, and for what purpose) so the service can grant or refuse access later without the user present. A request outside the rules is refused by the service itself, whatever the agent claims the user wanted.
Delegation for the highest-stakes government decisions, the kind that can't be undone once acted on, borrowed from healthcare proxies and advance directives. Services making irreversible decisions get a delegation model medicine has already tested at those stakes.
An identity layer for the agent itself, so a relying agency can prove who authorized it, check what it may do, and stop it. An agency can confirm an agent's authority, or end it, without asking the user to understand the protocol underneath.
Testing that a user's grant of authority to an agent is freely given, not coerced: porting the anti-duress safeguards of fiduciary regimes into the digital delegation flow, proportionate to the stakes of the delegated action.
When a user's delegated agent is hijacked, spoofed, or tricked into acting beyond its scope, containing it: cutting off the agent's standing authority before the harm compounds.
Letting a person state their own terms for how their data and interactions are handled, in a machine-readable form chosen from a neutral roster, so that a service (and the agents on both sides) can read the terms, agree to them, and keep a shared record of the agreement.
A mandatory pause before a consequential agent action becomes binding, so a mistake can be caught before it takes effect.
A durable, human-readable receipt for every action an agent takes, serving as the shared record a user and an agency can each check if they later disagree about what happened.
One complete log of everything an agent did, projected into a different view for each reader who needs to check it. A disputed action can be reconstructed months later from one authoritative record rather than from competing recollections.
Making an agent's decision state reasons the affected person can understand and use, to the standard administrative law already demands of human decision- makers. A person contesting the decision can argue against its actual grounds instead of guessing at them.
A path from any single agent action to a dispute about it, so an affected person can raise a dispute without first reconstructing what the agent did.
A plain-language statement, shown before the user authorizes an agent's action, of who is responsible if it goes wrong. The user decides whether to proceed with that answer already in view.
A label on every agent action for how much of it can be walked back: reversible, amendable, compensable, or irreversible. A user learns that an action can't be undone while there is still time to decline it.
A population-level circuit breaker for fleets of agents, catching and halting a repeating fault before each affected person has to notice their own case.
A notice the state's agent must issue before an adverse automated action takes effect, stating in plain language that automation acted and what it relied on. It gives the affected person, and their own agent, a chance to see and respond to a decision before it takes hold, instead of learning about it only after the fact.
A "contest this" control on the notice a government agent sends before an adverse decision takes effect, suspending enforcement the instant it's used: no recovery, no penalty, no interest while a time-bound human review runs. A person can push back before the decision takes hold instead of after, and a service team runs the review against a fixed clock rather than an open-ended pause.
Holding any agent the state operates to the duty set expected of a person's agent (a receipt for every action, a disclosed liability allocation, a verified reversibility classification), and often to a higher standard. It gives a policymaker one duty schedule to hold government automation to, and gives the service team building a state-side agent the accountability bar to design against before a dispute tests it.
Showing how sure the agent is, in terms a user can act on: a confidence band tied to what happens next, so a firm determination and a best guess never look alike. A user can tell when an answer needs checking before they act on it.
A trust mark for government AI services that certifies a defined standard the service is held to. The mark names what it stands for, so a user knows at a glance what kind of claim it's making.
How much autonomy a user grants an agent over their affairs, growing only as trust is earned rather than handed over all at once. At every point, the user decides how far it goes.
Telling the user they are dealing with AI, what it can do, and what it is doing right now, at the moments that matter rather than in a terms page. The standing record lets an auditor confirm, after the fact, that the user was told.
Naming how much of an action a machine decides, in a plain label a user can grasp at a glance. A user reading the label knows whether a person or a machine settled the outcome they're about to rely on.
Making it clear, at every point in an agent-run decision, that a person reviews it. A user can tell whether that review is real.
Delegation that expands on demonstrated use and contracts the moment the user wants it gone. A user can withdraw delegation at any point without losing access to the outcome they came for.
The outbound decision itself declares what was automated and to what degree, in a form both the person and their agent can read. Reliance can then be calibrated decision by decision.
A cap on how many submissions one verified person can make in a period. One person with a fast agent can no longer crowd out the applicants who file by hand.
An intake built from constrained, verifiable fields instead of free narrative, tying assessment to data rather than to how the application reads.
Confirming a real, distinct human is behind a request, without a puzzle that machines now beat and many disabled people never could. The service keeps out bulk automation without turning away the disabled users the old puzzles excluded.
Rationing a scarce public resource by what the affected community deliberately prioritizes, rather than by who produces the most polished application. Deliberation is a signal agents can't manufacture, so the allocation stays tied to what affected people want.
Setting the signature thresholds that convert public concern into government response. A threshold crossed by manufactured signatures forces a government response that no real breadth of concern asked for.
Auditing every point of administrative friction before agents strip it out, asking what it costs and what it was holding in place. Stripping friction without the audit also strips the rationing or reflection some of that friction performed.
Reading appeal volume and overturn rate together as an early-warning gauge on decision quality and access. A rise in appeals with most decided for the claimant means the first decisions were wrong.
Grouping a flood of submissions by what they argue, so a reviewer reads each distinct argument once instead of the same template ten thousand times. It keeps mass campaigns from inflating the record while giving reviewers and the public confidence that no substantive position was missed.
Recovering who stands behind mass submissions: which campaign, how large, who organized it, and by what route each entry was filed. Decision-makers can see which campaign produced a flood of comments and how many distinct people stand behind it.
Mapping where genuine agreement sits across a consultation, by weighting positions on how widely they are shared across distinct groups rather than how often one group repeats them. A position's reported weight reflects how many different groups hold it, which volume alone can't counterfeit.
Reporting consultation results so volume and breadth don't collapse into one number. A decision-maker citing the consultation can say how many people asked for something, separate from how many submissions said it.
Telling a submitter, before they file, that their text matches a known template and that their own experience would add weight. The consultation gains first-hand accounts.
Weighting participation by the intensity and persistence of support behind a position, not by how many submissions repeat it. A participant spends a limited budget of voice on what matters most to them, rather than being counted the same regardless of how strongly they feel.
Protecting the integrity of a government agent that reads, summarizes, clusters, or ranks user submissions from adversarial content inside those submissions, through structural controls that hold regardless of how the injection is worded.
Letting a legitimate agent prove it is a known, authorized agent at the moment it makes a request, the inversion of proving a human is present. A service can then admit and account for declared agent traffic instead of guessing an actor from its behavior.
A service stating, in machine-readable form on the channel itself, what agent traffic is welcome there and for what purposes. The declaration states the policy; confirming which agent is making a request is a separate duty.
A free, government-provided agent at every service entry point, aligned to the user and auditable by the public. A user without a bank, employer, or subscription that supplies an agent still gets one at the door of the service.
Keeping what the user said intact through an agent's rewriting: the original travels with the polished version, and meaning-changing edits are flagged before anything is sent. What the person said remains on the record, available whenever the polished version is disputed.
A non-agent route to every outcome, held at genuine parity of quality and timeliness with the agent route. A person who declines the agent route still gets the benefit, license, or decision on the same terms and timetable.
Holding the agent interface itself to the recognized accessibility floor, and extending that floor to how the agent converses, not only how it renders.
Agent intake that works across literacy levels and languages: plain language by default, an honest indicator of how well the agent handles the user's language, and a human interpreter when it doesn't. That disclosure stops the service from settling consequential matters in a language the agent only appears to understand.
Giving the communities a service is built for a hand in how its agent talks, before it ships and after: co-designed conversational behavior, and standing oversight of the live system by the people it affects. Failure modes only an affected community would recognize get raised while they can still be fixed.
Making visible whose interests a commercially supplied agent serves when it acts for a user, with an uncompromised public alternative one action away. A user deciding whether to rely on a supplied agent can see whose interests it serves besides their own.
A capable, government-provided agent for high-stakes interactions (an appeal, a dispute, an enforcement action), offered to users who lack their own, with a human escalation path throughout. The outcome of an appeal or enforcement action stops tracking whether the person could afford a capable agent.
Naming, before an agent channel launches, the populations it will fail, and committing outreach and a working alternative route for each. A population the channel will fail is provided for before launch instead of surfacing later in complaint and harm data.
A public registry and certification mark for civic tools, readable by a user as a badge and by an agent as machine-readable code. Every user, agent, and agency relying on a tool checks the same assessment instead of each vetting it alone.
A standard, glanceable label on every civic tool: what it does, what data it uses, who is accountable, where it falls short. A user choosing a tool and an agent invoking one make the decision on the same disclosed facts.
A queryable record of what a tool is built from, kept current as its dependencies change.
Review depth scaled to consequence: an automated check every tool passes quickly, human review reserved for the tools that can do real harm, and takedown when something slips through. Reserving human review for the tools that can do real harm keeps certification fast enough that developers seek it.
Certifying a tool by what its output can affect, and holding it to that claim for as long as it runs: monitoring for drift, checking for bias, renewing rather than expiring. A tool that drifts after approval is caught by the monitoring instead of keeping a certification it no longer meets.
Turning a voluntary risk-management framework into a certifiable standard, with a bar a tool can be checked against.
Anchoring every substantive claim an agent makes to a source the user or the next agent can check: per-claim citations, a source panel, and typed read-only retrieval for the answers that matter most. A user or a downstream agent can check any claim against its source before acting on it.
A certification ladder the long tail can climb, with a rung matched to what a tool can affect. A tool built by one developer can still qualify for a checkable trust signal, keeping the long tail inside the certification system.
Telling the user, at the moment their data is processed, where it goes, whose law can reach it, and whether it stays onshore. A person deciding whether to share something sensitive knows, before sharing, whether a foreign authority could compel it.
Matching the sovereignty of the infrastructure to the sensitivity of the interaction: routine tasks proceed with disclosure, sensitive ones require hosting no foreign entity can compel. A person raising a sensitive matter gets the stronger hosting automatically rather than by knowing to ask for it.
A public, machine-readable account of which AI system powers each government service, delivered to the user at the point of use rather than left in a register. A person challenging an outcome can name the specific system that produced it, the fact every accountability process needs first.
Making the legal basis for a cross-border data transfer checkable before the data moves: an agent queries the status, the user sees a plain assurance. A transfer whose legal basis has lapsed fails before the data moves.
Encoding a sector's data-residency law as a hard constraint the platform enforces before routing, with a plain assurance to the user that it held. Health and finance data stays where the statute says.
A provenance label for the AI model behind a government service: who built it, where it was trained, where it runs, whose law governs it. A person can see whether the model handling their case answers to their own country's law.
Making the whole AI supply chain's jurisdictional exposure inspectable, not just the top layer's: a sovereignty bill of materials an agent can query before committing data. A sovereign front end with foreign dependencies underneath is disclosed as exactly that.
Firing sovereignty disclosure only at the moments jurisdiction changes the user's protection: silent when infrastructure matches the data's sensitivity, unmistakable when it doesn't. Because the warning fires only when the user's protection changes, users keep reading it.