{"schema_version":1,"experiment_id":"eoa_inverse_innovation_exp06_four_proposal_generalization60_20260803","cell_id":"ritualized_meaning_and_commitment_enactment__human_computer_interaction","arm":"COMPLETE_PROPOSAL_PORTFOLIO","candidate_id":"hci_human_ai_delegation_boundary_enactment_v0","proposal_index":4,"version":0,"title":"Delegation Boundary Enactment for Human–AI Workgroups","problem":"A customer-operations workgroup uses an AI agent to draft replies, update shared records, recommend credits, and schedule follow-up. Team members can hold incompatible assumptions about when the system is merely proposing, when it may execute, and which human remains accountable. As models, connected tools, staff, and operating pressures change, an earlier delegation policy can persist as abstract documentation even though the agent's practical action possibilities and the team's interpretation of them have changed.","actors":["Customer-operations staff who interact with the AI agent","Supervisors with business-process authority","System administrators controlling tools and permissions","Security, privacy, legal, or compliance reviewers","Customers and other people affected by agent-assisted actions","Customer or frontline representative with standing to witness consequences","Rotating enactment steward","Independent consent and harm reviewer","AI-system provider or internal platform team"],"observable_state":"For the same boundary scenario, participants disagree about whether the agent may draft, recommend, modify a record, communicate externally, or commit a consequential action. A connected tool permits conduct that the written delegation policy forbids, an action log lacks a named accountable human, a model or tool update has not triggered reconsideration, or staff describe human review as required while routinely treating it as ceremonial.","consequence":"The agent can act under stale or contradictory expectations, human review can become a nominal gesture, affected people may be unable to identify who owns correction, and the organization can proclaim human accountability without maintaining the permissions and obligations that make it true.","affected_objective":"Shared, revisable, and technically enforced boundaries of agency, review, accountability, and repair in ongoing human–AI work.","intervention":"Establish a recurring Delegation Boundary Enactment at initial AI deployment, after any material model, tool, data, or workflow change, and quarterly while delegated operation continues. Before the event, reviewers map actual agent capabilities, permissions, affected parties, and power asymmetries. The agent then enters a marked observer-only state, and a nonfunctional physical or digital authorization key is placed visibly with the human group. The steward states the contestable meaning claim: delegation transfers bounded action capability, not human or organizational accountability. Participants reenact a small set of provenance-labeled work scenarios from customer request through agent proposal, human judgment, execution, notification, and correction. At every transition between draft, recommendation, and action, the symbolic key circulates among roles, giving each a turn to renew, revise, decline, defer, or privately challenge the proposed boundary. Named witnesses recognize where authority and accountability actually sit without treating performance as operational authorization. Closure converts the enacted boundaries into real permissions, approval gates, escalation rules, named owners, logging requirements, and customer-remedy paths through existing authorized administrators. A debrief compares intended and experienced meaning. Rotating stewardship, skeptical audits, repair, and retirement keep the enactment and the deployed agent answerable to later change.","structural_mapping":[{"archetype_element":"Explicit and contestable purpose","domain_realization":"The practice enacts a claim that AI delegation is bounded and does not discharge human or organizational accountability; participants may contest how that claim applies to particular work."},{"archetype_element":"Participant and stakeholder boundary","domain_realization":"Operators, supervisors, administrators, specialist reviewers, customers, frontline representatives, system providers, witnesses, and affected nonparticipants receive distinct standing rather than being collapsed into a generic user category."},{"archetype_element":"Legitimacy, consent, and exit","domain_realization":"Workplace power, evaluation risk, private objections, accommodations, role substitution, and nonretaliatory exit are reviewed before participation; attendance is not treated as assent."},{"archetype_element":"Recurring time and trigger","domain_realization":"The enactment recurs at deployment, material capability changes, and a fixed review cadence, preventing the original policy from silently governing a changed system."},{"archetype_element":"Symbolic threshold","domain_realization":"Placing the agent in observer-only mode and visibly locating the nonfunctional authorization key with the humans marks a temporary shift from delegated operation to collective examination of delegation."},{"archetype_element":"Symbolic frame and shared narrative","domain_realization":"The scenario sequence represents agency as a chain of proposals, judgments, permissions, actions, consequences, and repair rather than as the vague instruction to keep a human in the loop."},{"archetype_element":"Recognizable script and roles","domain_realization":"The stable sequence is capability mapping, consent review, observer-only threshold, scenario reenactment, key circulation, boundary renewal, witnessing, technical closure, debrief, and handoff."},{"archetype_element":"Embodied and plural participation","domain_realization":"Participants manipulate or pass the symbolic key, pause a scenario, speak, write privately, appoint a representative, or decline a turn; no unison response is required."},{"archetype_element":"Recognition and practical consequence","domain_realization":"Witnesses name the actual accountable role at each boundary, while closure maps the declaration to authenticated permissions, gates, logs, escalation paths, and correction duties."},{"archetype_element":"Accessibility and emotional-safety envelope","domain_realization":"Scenarios avoid unnecessary exposure of real customer or employee failures, provide accessible equivalents to passing the key, allow private dissent, and prohibit using mistakes or abstention in performance assessment."},{"archetype_element":"Memory and stewardship handoff","domain_realization":"A versioned delegation record preserves capability scope, scenario provenance, boundary decisions, dissent, open obligations, and official stewardship transfers without retaining unnecessary personal testimony."},{"archetype_element":"Drift, repair, and retirement","domain_realization":"Audits compare the enacted boundaries with permissions, logs, review behavior, and customer remedies; authorized procedures can suspend tools, correct claims, transfer obligations, release symbols, or retire the agent and observance."}],"mechanism_mapping":[{"mechanism_slug":"ritual_design_canvas","role":"Co-locates the accountability claim, agent capabilities, affected parties, scenario sequence, symbolic key, participation rules, technical outputs, evidence, and retirement conditions.","counterfactual_removal":"Without it, the enactment could dramatize human control without revealing contradictions between its narrative, actual permissions, and practical accountability."},{"mechanism_slug":"ritual_access_and_consent_review","role":"Creates pre-enactment veto points for workplace coercion, accessibility, confidential cases, evaluation pressure, affected-party standing, recording, and private challenge paths.","counterfactual_removal":"Without it, employees could be compelled to perform confidence in a delegation policy they cannot safely question."},{"mechanism_slug":"opening_marking_and_threshold_gesture","role":"Observer-only mode and the visible placement of the symbolic authorization key separate ordinary agent operation from the interval in which delegation becomes collectively inspectable.","counterfactual_removal":"Without the threshold, scenario discussion becomes another training exercise and does not enact the temporary return of attention and authority to the human group."},{"mechanism_slug":"symbolic_object_circulation","role":"The nonfunctional authorization key visibly transfers the turn to inspect, challenge, or affirm each boundary among operators, administrators, reviewers, and affected-role witnesses.","counterfactual_removal":"Without circulation, supervisors or technical specialists could monopolize the account of agency while less powerful participants remain spectators."},{"mechanism_slug":"collective_commitment_renewal","role":"Requires the group to renew, revise, decline, or defer existing delegation commitments after capability, staffing, and workflow changes and to identify the duties that follow.","counterfactual_removal":"Without recurring re-consent, an original human-oversight promise can survive rhetorically while its permissions and review practices drift."},{"mechanism_slug":"witnessing_and_public_recognition","role":"Named witnesses acknowledge within the bounded workgroup where authority, accountability, customer consequence, and correction duties actually reside.","counterfactual_removal":"Without credible witnessing, boundary statements remain private interpretations that other roles cannot recognize when work crosses between proposal and action."},{"mechanism_slug":"role_rotation_and_stewardship_rite","role":"Transfers facilitation, scenario records, review access, open obligations, and procedural knowledge on a scheduled cadence while leaving formal system authority with authorized roles.","counterfactual_removal":"Without rotation of real stewardship capability, a deployment founder or AI specialist could permanently control the interpretation of acceptable delegation."},{"mechanism_slug":"after_ritual_meaning_debrief","role":"Compares the intended accountability meaning with participant experience immediately afterward, including confusion, pressure, missing stakeholders, unrealistic scenarios, and follow-through owed.","counterfactual_removal":"Without the debrief, the official boundary record can conceal manufactured agreement or a scenario sequence that participants experienced as misleading."},{"mechanism_slug":"ritual_drift_and_harm_audit","role":"Periodically tests for rote human approval, permission creep, selective logs, accountability diffusion, coerced affirmation, excluded customer consequences, and claim-versus-conduct drift.","counterfactual_removal":"Without skeptical audit, the organization could continue performing human accountability after review has become ceremonial or the agent's operational scope has expanded."},{"mechanism_slug":"ritual_retirement_or_repair_ceremony","role":"Provides a transparent procedure to acknowledge failed delegation, disable affected capabilities, transfer correction duties, archive the record, release the symbolic key from required use, and end the observance or deployed agent.","counterfactual_removal":"Without a legitimate ending path, the agent can remain symbolically authorized after trust or usefulness ends, or be removed while unresolved customer and data obligations disappear."}],"causal_chain":["Actual agent capabilities, tool permissions, logs, workflow transitions, affected parties, and prior delegation claims are assembled into one inspectable record.","A consent and standing review determines whether the enactment can proceed, requires adjustment, or must be held.","Observer-only mode and the authorization-key gesture interrupt normal automation and make agency allocation the shared object of attention.","Reenacted boundary scenarios expose where participants' mental models diverge about proposal, judgment, execution, communication, and correction.","Circulation of the symbolic key distributes voice and makes each transfer of agency socially visible without granting technical authority.","Participants explicitly renew, revise, decline, or defer delegation boundaries rather than allowing the original policy to persist by default.","Witnessing makes the accountable human and affected-party consequences recognizable across functional roles.","Authorized closure translates enacted boundaries into real permissions, approval gates, logging, owners, escalation, and remedy procedures.","Debrief, versioned memory, rotating stewardship, audit, repair, and retirement keep the symbolic claim aligned with later system behavior."],"baseline":"An organization uses written acceptable-use policies, onboarding, role-based permissions, human-approval screens, audit logs, and supervisor escalation. These controls can specify or enforce portions of delegation, but they may remain distributed across systems and need not create a recurring collective occasion in which operators, administrators, decision owners, and affected-role witnesses enact and reconsider the complete chain from AI proposal to consequence and repair.","nearest_rivals":["Least-privilege permissions and role-based access control: stronger for technically preventing unauthorized operations, but unable by themselves to establish shared interpretation, affected-party standing, or accountable use of actions that remain permitted.","A mandatory human-approval gate: stronger for inserting a decision point into each transaction, but repeated approval can become ceremonial and the interface does not necessarily clarify what evidence, authority, or correction duty the approving person accepts.","Policy documents and annual AI training: stronger for scalable instruction and standardized expectations, but comprehension does not ensure that heterogeneous mental models become socially visible or that policy changes reach live permissions.","Audit logs and retrospective review: stronger for reconstructing recorded actions after execution, but they do not prospectively renew legitimate delegation boundaries or guarantee that responsibility is recognized before harm.","A technical tabletop or red-team exercise: stronger for discovering failure modes and control gaps, but it may remain expert-led and episodic rather than renewing the workgroup's shared meaning, standing, and continuing obligations.","Model cards, capability notices, and update notes: stronger for communicating system changes, but information transfer alone does not determine how a particular workgroup will divide judgment, action, accountability, and repair."],"remaining_contrastive_claim":"The proposal does not claim that symbolic enactment makes AI safe or substitutes for technical control. Its contrastive hypothesis is that recurrently reenacting and witnessing transfers of agency can expose incompatible human mental models and connect a shared accountability claim to permissions and remedy obligations in ways that access controls, approval clicks, training, and logs do not structurally require.","authority_safety":{"decision_authority":"Business-process owners decide which work may be delegated; authorized administrators control technical permissions; security, privacy, legal, and compliance roles retain their existing vetoes; individual operators control their participation and private input. The facilitator and symbolic key confer no operational authority. Customers or their representatives may identify consequences and challenge assumptions but do not acquire responsibilities outside their legitimate standing.","authorized_first_step":"A volunteer workgroup may enact the complete sequence in a sandbox using synthetic customer cases, a nonproduction agent with external actions disabled, mock permissions, and simulated logs. The rehearsal may produce proposed controls but cannot change production access or contact a real customer.","excluded_actions":["Treating possession of the symbolic key, a gesture, attendance, silence, or a spoken response as operational authorization","Connecting the rehearsal agent to production data, communications, payment, identity, or record systems","Changing production permissions during the initial rehearsal","Using participant hesitation, errors, dissent, or abstention in performance evaluation or discipline","Requiring disclosure of confidential customer cases or employee mistakes","Allowing majority agreement to override an existing security, privacy, legal, compliance, or affected-person safeguard","Calling a nominal approval click meaningful human review without adequate time, evidence, and authority","Using the enactment to transfer accountability from the deploying organization to frontline staff or customers","Substituting the practice for secure engineering, testing, monitoring, incident response, or enforceable access controls","Retaining recordings or private responses without specific consent"],"halt_rollback":"Any participant may pass, leave, or move to private input without explanation. The independent reviewer must halt for coercion, inaccessible participation, disputed authority, confidential-data exposure, uncontrolled agent action, misleading capability representation, or acute interpersonal harm. Rollback disables the sandbox agent, revokes temporary credentials, cancels mock external actions, quarantines sensitive records, restores the verified prior production configuration, and routes discovered control gaps through existing authorized processes without recording private testimony unnecessarily."},"negative_tests":{"strongest_counterevidence":"Existing permissions, approval gates, update procedures, training, and logs already produce consistent role-specific answers across realistic boundary cases; each executed action has an identifiable accountable human and effective correction path; material capability changes trigger prompt reauthorization; and operators can safely challenge delegation without a collective enactment.","problem_falsifier":"A bounded audit finds no divergence between written policy, participant mental models, actual permissions, approval behavior, logs, and customer-remedy ownership across staff and system changes. If delegation boundaries remain legible and actively governed through ordinary controls, the proposed abstraction-and-drift problem is absent.","intervention_falsifier":"Participants perform the scenarios fluently but retain incompatible boundary interpretations, enacted choices do not produce verifiable permission or workflow changes, or the ritual increases conformity pressure and diffuses responsibility. It is also falsified as the appropriate intervention if a technical permission correction or clearer policy alone resolves the observed gaps and the symbolic, recurring, and witnessing elements add no necessary governance function.","risks":["The enactment could create confidence in human control that actual permissions do not support.","The symbolic key could be confused with real authorization or fetishized as proof of accountability.","Supervisors could use visible choices to identify or punish skeptical employees.","Scripted cases could exclude rare but consequential customer experiences.","Repeated scenario approval could become as rote as the interface click it is intended to examine.","Frontline staff could receive symbolic accountability without sufficient authority, time, or resources.","The AI provider or deploying organization could use the ritual to shift responsibility onto individual operators.","Observer-only mode could be incomplete or misrepresented.","Logs and closure records could expose employee or customer information.","Ceremonial repair could substitute for customer remedy, technical correction, or organizational accountability."]},"next_evidence_step":"After sandbox safety review, run two bounded enactments with one volunteer workgroup: one against the current synthetic capability set and one after a simulated model or tool change. Before each enactment, privately elicit role-specific decisions for fixed boundary scenarios; afterward, compare those decisions with the witnessed delegation record, mock permissions, approval gates, named owners, logs, and remedy paths. Verify every closure item through simulated execution, collect optional private accounts of pressure and comprehensibility, and require an independent proceed, adapt, hold, or retire verdict. Treat the result as a test of feasibility, causal alignment, renewal under change, and safety rather than general effectiveness.","prior_art_status":"UNSEARCHED","diversity_from_prior_proposals":"Proposal 1 governed a product team's commitments to user consequences before releasing an interface; its path ran from fragmented research and promises to witnessed release obligations. Proposal 2 governed consent among people living with ambient sensors; its path ran from invisible spatial data practices to household boundaries and device settings. Proposal 3 governed digital remains after death or incapacity; its path ran from fragmented legacy traces and plural remembrance to authenticated memorial stewardship. Proposal 4 instead governs the live allocation of agency between workers and an action-capable AI system. Its intervention reenacts transitions from proposal to judgment, execution, communication, and correction while the agent is temporarily observer-only; its causal path runs from conflicting mental models of delegation through symbolic transfer and witnessed role decisions to actual permissions, approval gates, logs, and remedy ownership. It is independently adoptable as an operational human–AI governance protocol and neither extends product release review, household sensing governance, nor digital-legacy stewardship.","revision_record":{"parent_version":null,"progress_targets_addressed":["Materially different human–AI agency-allocation problem","Distinct scenario-enactment intervention and causal path","Separation of symbolic participation from operational authorization","Technical closure through permissions, approval gates, logs, and remedies","Workplace consent, accountability, repair, and retirement safeguards","Explicit diversity from proposals 1, 2, and 3","Bounded two-cycle evidence under simulated capability change"],"conceptual_changes":[],"operational_changes":[],"evidence_changes":[],"claim_changes":[]}}