Government
Who is accountable when an automated system acts on a citizen’s record?
The question a public accounts committee asks first, and the one architectures answer last.
The answer
A named human, identified before the system goes live, who owned the policy the action was taken under. Accountability cannot be assigned to a model, a vendor, or a process — and if the design cannot say which person was responsible for a given decision at the moment it was made, the system is not ready to touch a citizen’s record regardless of how well it performs.
What has to be reconstructable
Which inputs the system saw. Which version of which policy applied. What it produced. Which human owned that policy at the time, and who could have overridden the outcome. Reconstructable years later from the record itself — not from anyone’s memory, and not from a log retention window that expired before the review.
Why this is an architecture question, not a policy annex
Every one of those facts has to be captured at the moment of the decision by a system designed to capture it. Retrofitting them is the single most expensive change a public-sector programme can be asked to make, and it is usually requested by the first reviewer rather than the first user.
Talk to the practice
Tell us what you are trying to build and what has to be true for it to work.
Contact