Objections
If one of these does not land, nothing else on this site matters. We would rather answer them here than in the third meeting.
On this page
No, and the difference is the entire thesis. A log records that something happened. An adjudication determines whether it may happen, before it does, and its output is a decision rather than an observation.
There is a clean test. If the system would have behaved identically with the control switched off, the control is a log. It may be an excellent log. It is not governing anything.
No. Self-attestation is lawful. It is common, it is often reasonable, and in places the law requires it.
The European conformity route for most high-risk systems is internal control — self-assessment, with no outside body involved, and it is the permitted path. A federal court will admit a record generated by an electronic process on the written certification of a qualified person, and the rule leaves the choice of that person to the party offering the record. A management assertion on internal control is, by design and by law, management attesting about management. None of that is a loophole, and no one breaks the law by following the settled arrangement.
Nor does Justice Chase’s sentence say otherwise. He was describing what a legislature may not rightfully do — confer on a party the power to adjudicate its own case. He was not prohibiting an organization from keeping its own books. What we take from him is the principle, not a violation.
The claim on this site is narrower and harder to dismiss. Lawful and insufficient are different findings, and the second is the one made here: self-attestation stops being adequate at the moment the person is taken out of the decision path, and not before.
The thing slowing you down today is the approval queue, and under time pressure a queue degrades into approval fatigue, which looks like oversight and is not. A test against authority written in advance is not a queue: there is no person to wait for. What it costs in time is a question for a demonstration on your own workload, not for a website.
The more expensive brake is the one nobody counts: the capability you did not field, or fielded narrowly, because you could not evidence what it would do. Restriction is what organizations reach for when adjudication is unavailable.
The safeguard is never the brake on aggression — it is the license for it. Brakes are what let you carry speed into the corner.
You do, and anyone you authorize. The authority, the record, and the choice of who may check it are yours. If checking us required trusting us, we would have rebuilt the original problem one layer up and given it a better name.
The test we apply to everything else applies to us: can a third party check the decision without the cooperation of the system that produced it. If the answer for us were no, we would fail our own test, and deserve to. Until a party you authorize has checked one of our decisions without our help, our passing it is a claim, and the demonstration is where the claim is tested. Designing ourselves out of the trust question is the product.
No. The authority stays yours. You write it: the delegations, the policy, the rules of engagement, the standard of care. The Arbiter decides one thing only, whether a proposed action is inside what you wrote, and it permits or denies on that basis and signs the determination.
It is not a new decider. It is your authority, applied at the moment of action instead of reconstructed afterward.
You do. Where the record is kept and who may check it are your choices, not ours. We recommend that the organization answerable for the decision keep it.
Keeping the record does not mean it rests on your word. Anyone you authorize can check the record later, using methods we publish to them, and reach the same answer without asking us or the system that acted.
Then you have a signed record of what it was measured against, which is what you need to correct it. A wrong denial is visible, attributable and fixable, and the first place to look is how the authority was written. A wrong permission with a record is the same case: it shows what the action was measured against, so the fault can be located, in the grant or in the adjudication, and corrected there. The organization still answers for the outcome; what changes is that it answers with a record.
Compare the alternative. A wrong permission with no record is none of the three: not visible, not attributable, not fixable. Governance was never the absence of error but the presence of a record when there is one.
No. Proof makes lawful action defensible. An organization that cannot show what was authorized is exposed on every decision it made, the lawful ones included. A record of what was proposed, on whose authority, and what was decided shows which decision the fault belongs to. The organization’s accountability for the outcome does not move, and nothing on this site says it does.
Access stays where it already belongs. Who may see the record is governed by law and by the privilege and classification rules that already apply to you, not by us. The record protects the person who acted within authority.
You can build enforcement, and some organizations should. Deciding whether an action is inside a policy is engineering, and you have engineers.
What cannot be built in-house is independence. Independence here means the judgment and the proof stand apart from the system that acted and from us, the party that built the Arbiter. Build one in-house and you are the actor and the builder; the record of what your system did rests on your own word, however good the engineering and however sincere the intent. No amount of internal effort changes that, and it is the reason a company does not audit itself. You keep the authority, the record, and the choice of who may check it; that party needs nothing from the system that acted, and nothing from us beyond the method we publish to them.
Signing proves integrity. It shows the record was not altered after it was written, and that is worth having.
It does not establish that the action was permitted, on whose authority, or against what standard. Those are different questions, and they are the ones an inspector general, an examiner or an opposing counsel asks. An unaltered record of an unauthorized action is an unaltered record of an unauthorized action.
One more
Then it is the one we most want to hear. Tell us which of the six problems is closest to what is costing you, and what we have wrong.
Start a conversationSee the six problems
We are not asking you to trust us. We are asking you to let us prove it.