Policy Exception Review¶
Protocol — instantiates Situational Attribution Check
A governance review that checks notice, feasibility, access, rule design, and enforcement context before deciding how to respond to noncompliance.
Policy Exception Review is the governance protocol that, when an apparent rule breach surfaces, checks the rule's own conditions — was there clear notice, was compliance feasible, was the approval path accessible, is the rule well-designed, and is it enforced consistently — before deciding how to respond. Its defining move is that it puts the policy, not only the person, on the stand: "willful violation" is one possible finding among several, alongside "never properly notified," "compliance was infeasible," "the rule is broken," and "enforced against some and not others." Throughout, it holds the accountability line explicit — the standard and the harm remain named regardless of what the review finds — and it produces a response that may fix the rule rather than punish the actor, while logging the rule-design gap so the next case is cleaner. It distinguishes a bad actor from a bad rule without letting either hide the other.
Example¶
Security flags that an employee has been using an unapproved SaaS analytics tool with company data — a clear shadow-IT policy breach, and the reflex is a written violation. The Policy Exception Review checks the rule's conditions first. Notice: the tool ban lives on page 34 of an onboarding handbook nobody re-reads; it was never surfaced to this team. Feasibility: the approved alternative took procurement six weeks, past the deadline the employee was under. Access: the exception-request path is a form buried three levels into an intranet nobody could find. Rule design: the policy is a blanket ban with no fast-track for low-risk tools. Enforcement consistency: three other teams run similar tools unsanctioned, so singling this person out would be unfair on its face. The finding is a notice-and-design failure, not defiance. The accountability line still holds — company data did touch an unvetted vendor, and that must be remediated — but the response becomes a fast-track approval path, clearer notice, and a proportionate note, with the rule gap logged for revision, not a disciplinary mark.
How it works¶
- Run the fixed governance checks — notice, feasibility, access, rule design, enforcement consistency — before choosing a response, so the rule is examined alongside the actor.
- Hold the accountability line in parallel. In its own place, name the standard that applied and the harm that occurred; explaining a breach never erases them.
- Select from a response menu that spans rule redesign, clearer notice, a feasible path, proportionate enforcement, and escalation for genuine willful disregard.
- Log the rule-design gap so a recurring notice or feasibility failure becomes a policy fix rather than a stream of individual cases.
Tuning parameters¶
- Notice / feasibility bar — how much clarity and how feasible a path the rule must have provided before noncompliance counts as a choice; a high bar protects actors, a low one protects the standard.
- Consistency-audit scope — how widely enforcement across peers is checked; a wider scope catches selective enforcement but is slower.
- Design-defect discount — how much a broken or unnoticed rule reduces the individual response; too generous erodes the standard, too stingy punishes the rule's victims.
- Escalation threshold — where repeated or clearly willful breach exits the review into enforcement.
When it helps, and when it misleads¶
Its strength is that it converts "bad actor" into a real distinction — unclear notice, infeasible compliance, bad rule design, selective enforcement, or genuine defiance — and it catches the unfairness of enforcing a rule against one person while others go untouched. It also turns a repeated breach into a signal to fix the rule instead of processing endless individual cases.
Its failure mode is excuse drift, where every breach becomes "the rule's fault" and the standard quietly erodes, and its mirror, blame laundering — running the review for show while keeping the punishment already decided. The discipline that guards against both is procedural justice[n1]: apply the same checks consistently across status groups, and document explicitly how the context evidence changed, or did not change, the response — so the review is a real test, not a ceremony.
How it implements the components¶
accountability_boundary— it holds the standard and the harm explicit throughout, ensuring that examining the rule's conditions informs the response without dissolving the obligation.impact_or_standard_reference— it names which rule or standard applied and who or what was harmed, keeping consequence anchored while culpability is sorted.response_adjustment— the output is a fitted response drawn from a menu spanning rule redesign, clearer notice, a feasible path, proportionate enforcement, or escalation.context_learning_record— a recurring notice, feasibility, or design defect is logged as a policy fix so the same breach stops being re-litigated one person at a time.
It judges the breach against the rule but does not capture the actor's own account (actor_perspective_record — Actor Perspective Interview), build the evidenced conditions map (situational_factor_map — Context Reconstruction Interview), or record the initial person-centered story as a reviewable hypothesis (trait_attribution — Behavior-Context Mapping Template).
Related¶
- Instantiates: Situational Attribution Check — it is the check applied to a rule breach, sorting notice, feasibility, design, and enforcement before the response.
- Consumes: Context Reconstruction Interview — the reconstructed conditions feed the notice, feasibility, and access checks.
- Sibling mechanisms: Actor Perspective Interview · Context Reconstruction Interview · Behavior-Context Mapping Template · Constraint and Incentive Checklist · Empathy Mapping · Incident Timeline Review · Performance Context Review · Just Culture Review
Editorial Notes¶
Form Classification¶
Form family: Assessment, Review & Assurance
Rationale: The review evaluates notice, feasibility, access, rule design, enforcement consistency, and harm before issuing a response disposition.
Nearest alternative: Decision, Gate & Allocation — A response is selected, but it is the finding of a criteria-based governance review.
Review outcome: Adjudicated after independent review; high confidence.
Origin Attribution¶
Primary origin: Public Administration & Policy
Origin pattern: Cross-disciplinary synthesis
Present-day reach: Multi-domain
Rationale: Contextual review of noncompliance belongs to administrative implementation, where feasibility, access, and enforcement conditions matter.
Related originating lineages:
- Law & Governance — Law contributes proportionality, notice, procedural fairness, and structured treatment of exceptions.
Review resolution: Both blind reviewers agree that public administration policy is the primary origin. Reconciliation resolves domain reach disagreement, encyclopedia synthesis disagreement. Formative alternate lineages are retained as law_governance; later breadth of use is recorded separately as domain_reach=multi_domain, while origin_mode=cross_disciplinary_synthesis describes the relationship among origin lineages.
Encyclopedia synthesis: The exact catalogued form synthesizes established practice rather than reproducing a single standard historical label.
Review outcome: Reconciled after independent review; high confidence.
Notes¶
[n1] Procedural justice — Tom Tyler's finding that people accept outcomes, even adverse ones, when the process that produced them is consistent, transparent, and unbiased. Legitimacy flows from fair process as much as fair result, which is why applying the review's checks evenly across status groups is a discipline, not a courtesy. ↩