Accountability & Audit
Review before commit checkpoint
The policy rule 'no consequential agent action is binding without a human checkpoint' becomes a summary-list review screen that names each item's data source and offers a change link before the action is committed.
Check before we submit
Your assistant has prepared this. Nothing is sent until you confirm. You can change anything the assistant wrote; details drawn from your records are fixed.
On what authority
Confirmation receipt showing what happened
The policy rule 'every agent action produces a durable attributable record' becomes a confirmation page with agent attribution, delegation reference, data-source list, and a downloadable receipt ID.
City Digital Services will assess your return. You’ll receive your notice of assessment within 14 days. This receipt stays in Your activity. You don’t need to keep this page open.
Audit trail with role-based views
The policy rule 'log everything once, show the right grain per audience' becomes a role switch that re-projects one audit record as user summary, caseworker lineage, or full trace.
Your assistant submitted your return using your employer and bank records.
You reviewed and confirmed it, after editing one figure.
An automated assessment worked out your $312.40 refund.
A caseworker will check the assessment before it’s final.
The user’s view leaves out API calls and model IDs. It favors a timeline that’s easy to read over one that lists everything.
Reasons for decision
The legal duty to give 'reasons for decision' becomes a structured reasons panel ('decided X because of Y, having considered Z') shown before submit and retained for any later dispute.
Recourse and dispute resolution
The chargeback model's 'anchor the dispute to a specific transaction and shift the burden to investigate' becomes a dispute button on the receipt that pre-fills the complaint from the action record.
Dispute action TX-2026-4829
We’ve filled in the record for you. You only need to tell us what went wrong.
New disputes arrive with the action record attached. The response clock starts when a dispute is received.
Submit the dispute on the left to watch it arrive here. Each dispute is tagged to an agent or model version and also counts toward the overall error rate. When many users report the same fault, it registers as one pattern rather than as unconnected phone calls.
Showing liability at the point of action
The PSD2 'liability is pre-determined and disclosed before the transaction' rule becomes a plain-language liability line at the checkpoint: 'You are authorizing [agent] to [action]. If this contains errors, [allocation].'
The statement is always shown, and the record notes that it was shown. The accredited and pending versions never require a checkbox to continue — forcing routine acknowledgment trains click-through. Only the not-accredited state gates authorization behind an explicit opt-in. The version that appears follows from the provider’s accreditation status.
Reversibility and undo
The legal classification of an action's reversibility becomes a plain-language badge ('this can be amended within 28 days' / 'this cannot be undone') shown before the user authorizes the agent.
File your property tax relief application
You can correct this until your assessment issues. After that, you would lodge a formal objection.
Circuit breaker for agent actions
The policy setting 'stop systemic error before it scales' becomes a circuit-breaker console: per-agent and per-model error-rate gauges against declared thresholds, an auto-suspend state, and a bulk-remediation action that notifies and reverses for every affected user.
The access side of this pattern protects the user. Remediation is automatic: every affected user is notified, and their transaction is reversed. While the fleet is halted, a staffed fallback channel handles urgent transactions.
No surfaces match this filter.