A concrete walkthrough
This is deliberately mundane. No hypotheticals, no edge cases.
Pilot Scenario: Automated Benefits Eligibility System
(U.S. State Agency)
Current state (baseline)
- Vendor-provided eligibility scoring system
- Automated triage flags high-risk claims
- Caseworkers review flagged cases
- Oversight via audits and post-hoc appeals
Authority is effectively embedded in:
- model thresholds
- routing logic
- continuity of deployment
ACP intervention points
1. Claim identification
System output: “Claim flagged as high-risk.”
This is recognized as a claim, not a fact.
2. Ratification requirement
Before denial or delay:
- a designated authority must ratify reliance on the claim
- ratification is logged, time-bounded, and revocable
No ratification → no adverse action.
3. Continuity check
Every fixed interval:
- continued use of the scoring system requires re-ratification
- justification must address observed outcomes, not just design intent
Failure to re-ratify pauses automated routing.
4. Refusal pathway
If ratification is refused:
- system does not escalate automatically
- alternative process (manual review) is triggered
- refusal is recorded, not penalized
5. Accountability shift
When harm occurs:
- responsibility attaches to ratifiers
- not vendors
- not governance teams
- not “the system”
Authority and responsibility converge.
What changes (and what doesn’t)
Does not change
- model architecture
- vendor relationship
- statutory eligibility criteria
Does change
- where authority sits
- how continuity is justified
- who must own decisions
Failure mode (acceptable)
If no one is willing to ratify:
- the system cannot operate
- that failure is visible
- governance is functioning
Closing alignment across artifacts
- Artifact 8 establishes constraint
- Artifact 9 makes it legally legible
- Artifact 10 proves it is operationally real
None of these promise safety; all of them remove evasion.
Member discussion: