T3

Accountability & Audit

When an agent acts for a user, much of what it does happens out of sight. The user may not see the steps it took, and the agency sees a result without knowing how it was reached. The agency’s own automation works at a different scale: one process applies the same step to a whole population, so a single fault reaches everyone it touches.

Visibility therefore has to hold at two scales. For a single interaction it means a record of what was done in a person’s name, and a route to correct it. Across a population it means finding a fault in the process itself, which no single case will show.

01

Policy challenge

When an agent acts in a user's name, responsibility for what it did becomes hard to fix: the user, the agency, and the agent's provider can each point elsewhere, while the record of what was done is thin or absent.

As agents handle more of each interaction, two failures become more likely. Errors are found late, after a decision has been acted on and when reversing it costs the most. A single fault in an automated process repeats across a whole population before anyone finds it. In both, the harm has landed before responsibility can be placed.

02

Design challenge

Make what an agent did legible and accountable, whether it acted in a user's name or the state's own agent acted on a person: reviewable by the affected person before it takes effect, and a trail that fixes responsibility after.

Give a clear path to challenge, reverse, or seek recourse when it goes wrong.

Catch and stop a systemic fault before it reaches population scale.

Keep a path open for people who can't read or check that record themselves, or who must rely on a trusted person to do it for them.

Patterns in this territory

11 shown
3.1 Emerging

Review before commit checkpoint

A mandatory pause before a consequential agent action becomes binding, so a mistake can be caught before it takes effect.

3.2 Emerging

Confirmation receipt showing what happened

A durable, human-readable receipt for every action an agent takes, serving as the shared record a user and an agency can each check if they later disagree about what happened.

3.3 Frontier

Audit trail with role-based views

One complete log of everything an agent did, projected into a different view for each reader who needs to check it. A disputed action can be reconstructed months later from one authoritative record rather than from competing recollections.

3.4 Frontier

Reasons for decision

Making an agent's decision state reasons the affected person can understand and use, to the standard administrative law already demands of human decision- makers. A person contesting the decision can argue against its actual grounds instead of guessing at them.

3.5 Frontier

Recourse and dispute resolution

A path from any single agent action to a dispute about it, so an affected person can raise a dispute without first reconstructing what the agent did.

3.6 Frontier

Showing liability at the point of action

A plain-language statement, shown before the user authorizes an agent's action, of who is responsible if it goes wrong. The user decides whether to proceed with that answer already in view.

3.7 Frontier

Reversibility and undo

A label on every agent action for how much of it can be walked back: reversible, amendable, compensable, or irreversible. A user learns that an action can't be undone while there is still time to decline it.

3.8 Frontier

Circuit breaker for agent actions

A population-level circuit breaker for fleets of agents, catching and halting a repeating fault before each affected person has to notice their own case.

3.9 Frontier

Notice of automated action before effect

A notice the state's agent must issue before an adverse automated action takes effect, stating in plain language that automation acted and what it relied on. It gives the affected person, and their own agent, a chance to see and respond to a decision before it takes hold, instead of learning about it only after the fact.

3.10 Frontier

Contest before consequence

A "contest this" control on the notice a government agent sends before an adverse decision takes effect, suspending enforcement the instant it's used: no recovery, no penalty, no interest while a time-bound human review runs. A person can push back before the decision takes hold instead of after, and a service team runs the review against a fixed clock rather than an open-ended pause.

3.11 Frontier

Symmetric duties on the state's agent

Holding any agent the state operates to the duty set expected of a person's agent (a receipt for every action, a disclosed liability allocation, a verified reversibility classification), and often to a higher standard. It gives a policymaker one duty schedule to hold government automation to, and gives the service team building a state-side agent the accountability bar to design against before a dispute tests it.

Case studies that touch this territory