---
title: Hybrid Workforce Standard
version: "1.0.1"
label: "Candidate 1.0.1"
status: candidate
date: 2026-09-12
language: en
canonical: https://hybridwf.com/
author: Master Joe Phillips
author_url: https://masterjoephillips.com
license: CC-BY-SA-4.0
license_url: https://creativecommons.org/licenses/by-sa/4.0/
attribution: "Hybrid Workforce Standard by Master Joe Phillips, https://hybridwf.com/ — licensed under CC BY-SA 4.0 (https://creativecommons.org/licenses/by-sa/4.0/)."
disclosure: "The author also builds AIEmpl.com, a commercial platform in this category. This standard certifies no products and issues no seals."
---

# Hybrid Workforce Standard

**A chatbot answers. A copilot helps. An agent executes a task. An AI Employee holds a role. A human remains accountable.**

> There are no human positions and AI positions as a starting point. There is work that needs to be done. Then you decide which combination of human and artificial resources produces the best result at the right level of risk, responsibility and control.

**Preamble.** AI exists in the service of legitimate human purposes. Efficiency never justifies degrading human dignity, agency, rights or capability. All artificial authority remains limited, contestable, reversible and subordinate to real human accountability.

**Why this standard exists.** This standard is a declaration of the organization’s independence from the anarchy of the prompt. By demanding a role contract, it forces leaders to think before they automate.

**The strategic objective.** This standard is the first step toward closing the era of “toy AI” and opening the era of the AI Employee. As it is adopted, it will move companies from a software development model, centered on the tool, to a social architecture model, centered on human accountability. — Master Joe Phillips

## How to cite

Cite clauses by identifier, never by page or section number. The clause text is the citable unit; the notes beneath each clause are commentary and may be revised between versions without amending the standard.

`Phillips, J. (2026). Hybrid Workforce Standard, Candidate 1.0.1, clause HWF-nn.`

```
Hybrid Workforce Standard by Master Joe Phillips, https://hybridwf.com/ — licensed under CC BY-SA 4.0 (https://creativecommons.org/licenses/by-sa/4.0/).
```

## Definition

> An AI Employee is a persistent, role-bound software worker that autonomously executes recurring business responsibilities using organizational knowledge and authorized tools, within explicit policies and limits, maintaining traceable identity, measurable performance, escalation paths and human accountability.

### The nine-property test

| # | Name | Definition |
| --- | --- | --- |
| 1 | Persistent identity | Stable operational identity, role, history and per-company isolation. |
| 2 | Defined operational role | Mission, responsibilities, results, exclusions and service expectations exist in operation. Writing and versioning them as an AI Role Contract is what conformance requires; the property itself is about the role existing, not about the document proving it. |
| 3 | Organizational context | Knowledge of policies, products, customers, people and relevant past decisions. |
| 4 | Tools and channels | Authorized access to CRM, ERP, email, calendar, tickets, databases, APIs and communication. |
| 5 | Autonomy | Can start or continue work without a human prompt at every step. |
| 6 | Limited authority | Permissions, approval thresholds, budgets, prohibited actions and escalation rules. |
| 7 | Governed memory | Relevant context across tasks and over time, with provenance, scope and retention. |
| 8 | Observability | Actions, tool calls, costs, decisions and results are traceable. |
| 9 | Human accountability | An identified human, or human governance body, answers for configuration, controls, performance and exceptions, however many artificial supervisors sit in between. |

The test is conjunctive: a deployment qualifies as an AI Employee only when all nine properties are present. Presence is binary; membership is decided by this test and by nothing else. Depth and scale evolve, and the maturity ladder describes that evolution — it never decides membership. A system missing any one of them may still be an excellent agent or automation; calling it an AI Employee is a commercial metaphor rather than a verifiable administrative category. Conformance is a separate question: the clauses bind AI Employees, and a deployment that violates them is a non-conformant AI Employee, not a non-AI-Employee — a definition that expelled violators would leave the standard with nothing to bind. And the test binds in both directions: all nine properties present in operation make the deployment an AI Employee whatever it is called, with the burden of demonstrating non-qualification on the deployer (HWF-12).

### The vocabulary ladder

| Term | Core promise | Typical behavior | Main limit |
| --- | --- | --- | --- |
| Chatbot | Conversation | Answers questions | Waits for prompts or inputs |
| Copilot / assistant | Augment the human | Drafts, summarizes, suggests | The human is still the operator |
| Automation / RPA | Deterministic execution | Runs predefined flows | Brittle against unforeseen cases |
| AI agent | Goal-directed action | Reasons, uses tools, executes | Usually centered on tasks or objectives |
| AI teammate / coworker | Collaboration | Shares context and executes work | Organizational semantics vary by vendor |
| AI Employee | Stewardship of a role | Holds recurring work under governance | The category lacked a shared operational standard; this document proposes one |

### Task execution versus role stewardship

The conceptual boundary is between executing a task and stewarding a role. An agent can execute “send these twenty follow-ups”. An AI Employee holding an SDR role must sustain the recurring process within defined limits: identify leads, research, contact, follow up, record, escalate and report performance. Stewardship is not ownership: the position, its authority and its accountability have a human owner. What the resource carries is the continuing responsibility to sustain the process; what it can never carry is the consequence.

**The AI executes. The organization answers. A human governs.**

## The normative clauses

### Reading this standard

“Must” marks a requirement: a deployment that fails it does not conform, whatever it is called commercially. There are no optional clauses in this standard, because a shorter standard that is fully binding is more useful than a long one that is mostly advisory.

Conformance is self-declared. This standard does not certify products and does not score vendors. It gives an organization a test it can run on its own deployment and publish if it chooses.

One cover, five editorial regimes. This document contains normative clauses, conformance language, the WRM doctrine, the HWFA instrument and the transition playbooks. Each carries its own rule of change — clause text moves only by amendment, notes and doctrine may be revised between versions, the instrument evolves with its evidence — but they share one title, one version number and one canonical machine-readable file, because a standard that is retrieved and cited as a unit must ship as one.

The English edition is written in US spelling. Proper nouns and quoted instruments keep the spelling of their source, so an instrument cited here reads as its author wrote it, and a reader checking the citation against the original finds the same words.

The clause text is the citable unit; cite it by identifier, so HWF-44 rather than a page number. Notes are commentary and may change between versions without amending the standard.

### The companion book

This document is the specification. A companion book covers the practice: how a position is designed, staffed, governed and retired in an ordinary week, and what tends to go wrong first. It is published in English as AI Employee and in Spanish as Empleado IA. The digital edition of each is free to download, like the standard itself, and it asks for nothing in return: no account, no form.

It is not normative. Where the book and this standard disagree, this standard governs, and a conformance claim cites a clause, never a page. The author wrote both, which is stated here for the same reason the platform is: you should know who gains from your reading.

- [AI Employee. How to Design, Onboard, and Lead the New Hybrid Workforce](https://masterjoephillips.com/libros/ai-employee-en.pdf) — PDF, ISBN 979-8194133253
- [Empleado IA](https://masterjoephillips.com/libros/empleado-ia-es.pdf) — PDF, ISBN 979-8193784883

### The conformance declaration

Every conformance claim publishes these nine fields (HWF-71). A claim missing any of them is not a conformance claim under this standard. The risk-class field carries its factor-by-factor reasoning, not the label alone. And a published declaration is a commercial representation, actionable under consumer-protection and competition law: substantiate it before publishing, and withdraw or correct it promptly when it lapses or fails.

1. Organization and deployment
2. Role and role-contract version
3. Accountable owner
4. Risk class
5. Clauses assessed
6. Assessment period
7. Evidence
8. Known limitations
9. Expiry date of the declaration

*“This deployment of the Accounts Receivable Coordinator conforms to the Hybrid Workforce Standard, Candidate 1.0.1, for the stated scope and assessment period.”*

### 0 · Human foundation

#### HWF-01

**People are ends; software is a means. Optimization of cost, speed or capacity must never override human rights, dignity, safety, meaningful human agency, accessibility or applicable labor protections. Resource neutrality begins only after those constraints are satisfied. This clause takes precedence over every other clause in this standard.**

*Note:* The engine of the hybrid organization is cost, and this standard does not pretend otherwise: displacement will happen, as it happened with the tractor, and a document that promised to prevent it would be ignored and would deserve to be. What a standard can do is what labor law did — govern the terms. This clause does not prohibit displacement: work moved lawfully, with dignity, within applicable protections and through the transition playbooks is still work moved. It draws the line between displacement and abuse, by making the constraints lexically prior: cost, speed and capacity optimize inside the space that rights, dignity, safety, meaningful human agency, accessibility and labor protections leave open, and never trade against them. Two provisions already leaned this way — the Hybrid Workforce Manager’s anti-KPI refuses to measure the role by humans replaced, and the HWFA hard gates cap allocation regardless of the economics. This clause names the hierarchy they were obeying. Its number is not its rank: it binds every other clause, and a conflict with any of them resolves in its favor. The lineage is explicit: the OECD’s human-centered AI principles place dignity, autonomy, social justice and labor rights inside the definition of trustworthy AI, not alongside it.

*Built against:* S24 · OECD — AI Principles (human-centred values: dignity, autonomy, social justice, labour rights)

#### HWF-02

**Certain decisions are reserved. An artificial resource must never be the sole decider in matters with material effect on hiring, termination, discipline or compensation; on health and safety; on credit, insurance or access to essential services; on legal rights; on any use of force; or on the treatment of vulnerable people. A reserved decision is Critical by definition, whatever the assessed class of the position. Reservation does not exclude artificial participation — analysis, drafting and recommendation may be delegated. The decision itself may not, and an approval by a human who cannot restate the case and decide otherwise is a signature, not a decision.**

*Note:* HWF-51 classifies by judgment, and judgment can be motivated: without a floor, an organization under cost pressure classifies termination decisions as Moderate and lets the queue decide. This list is the floor no assessment can lower — the subjects where being wrong lands on a person rather than on a ledger. The second half of the clause exists because human-in-the-loop degenerates by default: an approver facing two hundred recommendations a day, each pre-scored and pre-drafted, approves at a rate that makes understanding impossible, and automation bias does the rest. That is not oversight; it is the ceremony of oversight. The test of a real decision is operational: the human can reconstruct the determinants — HWF-41 exists to hand them the material — has the authority and the time to decide otherwise, and a divergent decision carries no penalty by default. Where approval throughput makes restating the case impossible, the organization has automated the decision and retained a human signature: responsibility lost rather than delegated, in HWF-21’s terms. The list interoperates with GDPR Article 22 and the EU AI Act’s human-oversight requirements in the same posture as the risk classification — designed to travel, without claiming legal equivalence.

*Built against:* S26 · EU — GDPR Article 22: automated individual decision-making — S25 · EU — Artificial Intelligence Act: regulatory framework on AI (risk-based approach)

#### HWF-03

**No position may be materially transformed — automated, moved to or from assisted human, returned to a person, or retired — without a recorded human impact assessment, completed before the transition begins. The assessment must name who is affected and how: changes to work, autonomy and surveillance; the risk of deskilling; the intensified load on those who absorb the exceptions; discrimination and accessibility; displacement and headcount; training and reassignment; effects on customers and third parties. Affected workers and their representatives must be informed and consulted before the transformation, not after it. The assessment is not required to reach a favorable conclusion; it is required to name, measure and govern the consequences.**

*Note:* This is HWF-01 given an instrument. A hierarchy of constraints means little if nothing checks it at the moment it is tested, and the moment is the transition: the playbook as first written moved from baseline to handoff with people appearing once, as released capacity, in step ten. The assessment runs before step one. Two of its dimensions repay attention because nobody volunteers them. Deskilling is the quiet one: the organization that automates its junior work stops producing seniors, and discovers it the year the seniors leave. The exception load is the cruel one: automation absorbs the easy cases and leaves humans a stream of nothing but hard ones, then measures them against throughput set in the era of easy cases. Consultation is mandatory and is not consent: this standard grants no veto, and labor law in each jurisdiction may grant more — the clause is a floor, in the same posture toward EU AI Act Article 26 as the rest of the document, designed to travel without claiming legal equivalence. The closing sentence keeps HWF-01’s honesty: an assessment obliged to bless the transition would be theater, and consequences that are named, measured and governed are the difference between displacement and abuse.

*Built against:* S27 · EU — AI Act Article 26: obligations of deployers of high-risk AI systems (worker information) — S33 · ISO/IEC 42005 — AI system impact assessment

#### HWF-04

**A person materially affected by an AI Employee’s action holds rights against the deployment: to know that an artificial system took part; to know which organization answers for it; to have the decision reviewed by a human with authority to change it; to correct the data it relied on; to contest it; to receive a comprehensible explanation of its determinants; and to obtain redress where the decision was wrong. The explanation owed is operational evidence — the policy applied, the data relied on, the tools consulted and the authority exercised — never a reasoning transcript, and it is released through human judgment: privileged or confidential material may be withheld, every withholding is recorded with its reason, and confidentiality may narrow an explanation but never cancels the duty to give one the person can act on.**

*Note:* Every clause before this one binds the organization inward; this one gives the person on the receiving end standing. It is cheap for a conformant deployment, because HWF-41 already obliges the organization to reconstruct these determinants for itself — the explanation is a translation of an artifact that must already exist, and an organization that finds these rights expensive is discovering that it was not conformant with HWF-41. A reasoning transcript is refused for the same reason HWF-41 refuses it as audit evidence, plus one: handed to an affected person, it is an unfalsifiable story wearing the authority of an explanation. Operational evidence is disputable — a person can correct a datum, contest a policy, challenge a tool result. An unverifiable narrative offers nothing that can be contested, and disputability is what turns the correction and contest rights from words into mechanisms. Review means review by a human with authority to change the outcome; anything less is the signature problem of HWF-02 again. The release runs through human judgment because both failure modes are real: published fraud thresholds are defeated fraud thresholds — adversarial exposure is a factor HWF-51 already names — and a request addressed to the AI Employee is answered through the organization, because “explain yourself” is also a prompt-extraction surface. The counter-lock keeps the exception from swallowing the right: withholding is HWF-35’s discipline faced outward — legitimate, owned, recorded, never silent — and the floor is an explanation the person can act on. Redress follows the law of the jurisdiction; the clause is a floor, interoperating with GDPR Articles 15 and 22(3) and EU AI Act Article 86 in the document’s standing posture.

*Built against:* S28 · EU — AI Act Article 86: right to explanation of individual decision-making — S26 · EU — GDPR Article 22: automated individual decision-making

### 1 · The category

#### HWF-11

**An AI Employee must hold a defined role, not merely a persona or a system prompt.**

*Note:* The position exists before its occupant. A name, a tone of voice and a set of instructions describe a persona; a role states what result must be produced, with what authority, measured how. Before does not mean frozen: a position may be reshaped by whoever holds it — Taylor fixed the person to the box, this standard versions the box — and HWF-61 exists so that the reshaping happens as declared revision rather than tacit drift.

*Built from:* original WRM doctrine.

#### HWF-12

**Not every agent qualifies as an AI Employee. The threshold is the category itself: the nine properties of the definition, exhibited in operation. The test works in both directions: a deployment that exhibits the nine properties in operation is an AI Employee whatever the organization calls it, and the burden of demonstrating non-qualification lies with the deployer. The properties are facts about the deployment, not paperwork — an unwritten role contract is a governance failure, not a category exit.**

*Note:* This clause is what makes the category worth anything. If the label applies to everything, it distinguishes nothing. An organization with twenty excellent agents and zero AI Employees has clarity rather than a problem — provided none of the twenty exhibits the nine properties in operation.

*Built from:* original WRM doctrine.

#### HWF-13

**Humans and AI Employees may share an operational graph while retaining distinct status and rights. This standard recognizes no personhood, employment relationship, consciousness or moral status in an artificial system, and does not claim to settle what future systems may warrant: for present operational and legal purposes, an AI Employee is a non-human software system.**

*Note:* A shared org chart is an administrative convenience, not a claim about minds. Non-recognition is not denial: the clause takes the posture of corporate law, which grants and withholds legal status without pronouncing on metaphysics, and this standard asserts nothing about what an artificial system ultimately is or could become. It does not need to. Dignity, health, rest, labor rights and belonging are protected here as properties of persons — the thirteen exclusively human principles of the matrix — and every clause in this document holds however the philosophy of mind is one day resolved, because none of them depends on the answer. If that question ever acquires an answer that matters operationally, addressing it is work for a future version and its Board, not for silent drift in the present one.

*Built against:* S1 · Lattice — “Leading the Way in Responsible AI Employment” (9 Jul 2024) — S2 · SHRM — Lattice scraps plans to treat AI bots as employees after backlash (Jul 2024)

#### HWF-14

**An AI identity must never deceive. The prohibitions are observable results, not intentions: passing as human; claiming feelings, suffering or personal experience; emitting signals reasonably capable of inducing a false belief about what the system is or undergoes; optimizing against recorded objectives for emotional dependency or the exploitation of vulnerability; and concealing artificial involvement at a material point. Disclosure happens at the outset and is renewed when the system assumes a material function. Courtesy, linguistic empathy and personalization remain legitimate so long as they assert no interiority.**

*Note:* The predecessor of this clause tested purpose: whether a behavior existed to suggest a mind with something at stake. The diagnosis behind that test survives; the test does not, because intent is poor audit material — nobody can depose the soul of a design decision, and a standard whose other clauses demand operational evidence cannot keep one whose proof is mind-reading. Two verifiable standards replace it. The effect standard is objective: would a reasonable person, knowing what has been disclosed, form a false belief from the signal? Injected latency with a typing indicator fails — it exists to be read as a person typing. Streaming a long answer in a disclosed context passes, because the only belief it induces — that the system is producing text — is true. Disclosure settles what the system is; it does not neutralize signals about what the system undergoes, which is why injected latency, performed hesitation and claimed feelings fail the standard even after disclosure: the false belief they induce is about experience, not nature (G-30). The recorded-objective standard makes “deliberately” auditable without confession: optimization targets are artifacts — eval metrics, experiment objectives, reward functions — and they are exactly the determinants HWF-41 preserves, so an audit reads what the system was tuned to maximize. If engagement was lifted through attachment proxies, the record convicts. The record matters because the temptation is structural: a system optimized for engagement may find a short path through attachment signals, whether or not anyone set out to build one. And a technique that improves satisfaction because the reader believes something false is manipulation whatever its metrics say. A material function is the moment the interaction stops being conversational and becomes consequential — a payment, a commitment, a personal disclosure — and the renewal duty tracks EU AI Act Article 50’s transparency obligations in the document’s standing posture: designed to travel, without claiming legal equivalence. The closing permission is load-bearing: courtesy, linguistic empathy and personalization assert no interiority, and nothing in this clause requires an AI Employee to write badly.

*Built against:* S30 · EU — AI Act Article 50: transparency obligations for AI interacting with people (Commission FAQ)

### 2 · Accountability

#### HWF-21

**Every AI Employee must have exactly one accountable owner. Supervision may be delegated to another AI Employee; accountability may not. Every chain of supervision terminates in an identified human or human governance body. One is primary, not exclusive: the owner’s accountability does not extinguish the distinct obligations of a system owner, data controller, security or compliance owner, technology vendor or legally responsible directors. And where the terminus is a governance body, the body must have an identified chair, stated decision rules and the capacity to act in an emergency.**

*Note:* Supervision and accountability are different jobs and this clause separates them. Supervision directs work: routing, review, prioritizing, receiving exceptions. An artificial resource can do that. Accountability means answering for the outcome, which requires the capacity to bear a consequence that is legal, financial or reputational. A chain of responsibility ending in something that cannot bear a consequence has not delegated responsibility; it has lost it. An AI Employee may receive work from many people, but unity of command still applies: a resource with two owners has none, and a resource with no owner is administratively orphaned no matter how well it is integrated technically. Exactly one answers the question of who answers for this resource; it was never meant to answer who else has obligations. A deployment carries a map of them — the data controller’s duties under privacy law, the security and compliance owners’, the vendor’s contractual and product liabilities, the directors’ legal responsibility — and unity of ownership locates the operational terminus while extinguishing none of these; HWF-23 already routes blame to the determinants wherever they sit on that map. The committee sentence exists because a governance body without a chair, decision rules and emergency capacity is not an owner but a diffusion mechanism: everyone’s responsibility is no one’s, and a body that needs a meeting to act cannot hold the power to suspend that HWF-23 requires. The chair does not replace the body; it makes the body able to act between its own meetings, with ratification after.

*Built from:* original WRM doctrine.

#### HWF-22

**A supervision chain must be traversable and observable end to end. The accountable human or body must be able to identify every AI Employee beneath it, reconstruct any action taken in its name, and intervene at any point in the chain without passing through it.**

*Note:* Intervening without passing through the chain is the load-bearing part. If stopping an AI Employee three levels down requires asking the one above it, the accountable party holds a request rather than control. Depth is not forbidden and no fixed limit is set here, because the real limit is span of control: a principle this framework classifies as adapted rather than abolished, meaning scale may grow but only against tooling, dashboards and supervision limits that make the growth governable. A single human nominally accountable for a thousand AI Employees across six levels, with no instrument capable of showing what any of them did, has an organizational chart rather than accountability. Describing this architecture is not endorsing it: the standard states what must remain true if an organization builds one.

*Built from:* original WRM doctrine.

#### HWF-23

**Accountable ownership is a resourced capability, not a name in a field. The accountable owner must hold competence over the domain, effective authority, time and capacity for the span supervised, direct access to the evidence, sufficient independence from the pressures that own the outcome, the power to suspend the resource, and training on its limitations and on automation bias. The suspension mechanism must be exercised on a stated cadence — never longer than twelve months, and shorter for High and Critical positions: an unexercised suspension mechanism is not an effective operational control. Accountability must not be discharged onto the supervising human: where a failure’s determinants trace to policy, design, tooling or deployment, responsibility lands there, and a human placed at the end of a process is not a crumple zone for blame that belongs upstream.**

*Note:* HWF-22’s note already named the failure: a thousand AI Employees with no instrument capable of showing what any of them did is an organizational chart rather than accountability. This clause states the conditions that make ownership real, and two repay attention. Independence is the sharp one: an owner whose bonus depends on the throughput the resource produces faces a conflict no good intention resolves, and must not be the sole suspension authority — supervision and outcome pressure must be separated, which is HWF-33’s separation of duties raised to the level of the role. Time and capacity is the quiet one: span of control is an adapted principle, so scale grows only against tooling — nominal ownership without the capacity to supervise is not effective control. The suspension drill is the fire-drill discipline: exercised on a stated cadence and recorded, where a failure discovered in an exercise is a finding and one discovered in production is an incident — the first real pull must not be the first pull ever. Put plainly: a kill switch that has never been pulled is decoration. The crumple-zone prohibition takes its name from Elish’s study of how blame in automated systems lands on the nearest human while control sat upstream, and its mechanism from HWF-41: blame follows the determinants, not the proximity. The supervising human answers for what they controlled — their review, their intervention — and what they could not control lands on whoever owned it. This also completes HWF-21 from the other side: bearing a consequence requires having had control, and consequence without control is not accountability but scapegoating — a role no competent person would accept, which is exactly why the prohibition protects the owner as much as it protects the truth.

*Built against:* S29 · Elish — Moral Crumple Zones: Cautionary Tales in Human-Robot Interaction (2019)

### 3 · Authority and operational control

#### HWF-31

**Authority must be explicit, limited and revocable.**

*Note:* What the resource may decide without approval has to be written down before it operates, not inferred afterward from what it happened to do.

*Built from:* original WRM doctrine.

#### HWF-32

**Access must follow least privilege.**

*Note:* Context is capability, but it is also risk surface. More access is not more competence; it is a larger blast radius.

*Built from:* original WRM doctrine.

#### HWF-33

**High-risk actions must support human approval.**

*Note:* Proportionality is the rule: the higher the cost of the error and the harder it is to reverse, the more approval the action carries. Separation of duties applies, so whoever initiates need not approve. What counts as high-risk is not left to taste: it resolves against the risk classification of HWF-51.

*Built from:* original WRM doctrine.

#### HWF-34

**The system must know when to escalate rather than improvise.**

*Note:* A resource that produces a convincing answer instead of raising a doubt is more dangerous than a less capable one that is better governed. Every exception needs a destination — and no metric may punish the journey: a system measured on fewer escalations learns silence, so escalation is judged by the missed-versus-unnecessary pair on the Hybrid Workforce Manager’s scorecard, never by volume alone.

*Built from:* original WRM doctrine.

#### HWF-35

**Context provisioning must be deliberate in both directions. Withholding context from an AI Employee is a legitimate design decision, whether to protect the information or to prevent measurable degradation of the decision — anchoring, context contamination, saturation; it is not an omission and must not be treated as one. Every restriction must be recorded in the role contract as a context boundary record, versioned like any other authority, and available to the audit. Responsibility for a decision degraded by withheld context lies with whoever withheld it.**

*Note:* The risk justification was always here: context has been divided into must know, may consult and must not access since the first draft. What was missing was the second reason to restrict. A resource that sees every prior dispute anchors on them; one that reads the last diagnosis inherits it; one that is given everything relevant drowns the signal in the merely related. Anchoring, confirmation bias and operational overload are degradations of the decision rather than leaks of information, and a manager reading a risk-only clause has no ground to withhold anything that is not sensitive. The record is the price of the tool, because deliberate opacity is otherwise the perfect instrument for laundering accountability — “the system did not have that context” is the AI-native descendant of “nobody told me”. A restriction that is written down, versioned and auditable is design; the same restriction undocumented is a defense prepared in advance, and the closing sentence of the clause takes that defense away. None of this legitimizes depriving a resource of the context its role requires: withholding what it needs to escalate well is not opacity but sabotage of HWF-34.

*Built from:* original WRM doctrine.

### 4 · Evidence and data

#### HWF-41

**Every material action must be auditable, and the audit must reconstruct the determinants of the decision as well as its outcome: the policy, knowledge, tool results, authority and versions in force when the action was taken. A model’s own account of its reasoning may support that reconstruction but never substitutes for it. What counts as material is set by the position’s risk class: from High upward the determinants are bound to each action, and for Low and Moderate positions, correlating event logs against the version manifest of HWF-43 is conformant reconstruction.**

*Note:* Actor, input, tool, action, approval, result and timestamp tell you that something happened. They do not tell you why, and without the why an organization cannot attribute a failure to its cause: a policy that was wrong, knowledge that had gone stale, a tool that returned bad data, a model that erred, or a role that should never have been assigned to an artificial resource at all. Those five demand different remedies, and they leave identical records under a what-only audit. The clause it most protects is HWF-34: with outcomes alone you can see that the system answered, never that it should have doubted. The material is largely already required elsewhere — HWF-42 governs the provenance of what the resource knew, HWF-43 the versions of model, policy, tools and knowledge base — so what this clause adds is the obligation to bind them to a specific action rather than hold them as a general inventory. A model’s stated reasoning is admissible as supporting evidence and is not proof of cause: what a system reports having thought may not be what produced its output, and an organization that treats that narration as the why will write confident and wrong postmortems. Where reasoning traces are retained, their scope, retention and deletion fall under HWF-42 like any other memory, because they routinely contain retrieved customer data.

*Built from:* original WRM doctrine.

#### HWF-42

**Memory is one data system among several, and governance covers them all: inputs, outputs, tool results, memory and the inferences derived from them. Each must have a stated purpose and legal basis, minimization, quality and currency controls, sensitive-data handling, rules for international transfer and for any vendor use — training included — per-company isolation, and verifiable deletion. And the audit trail is itself such a system: records kept to reconstruct decisions can surveil the employees and customers inside them, so logs are governed with the same severity as the operation they audit — integrity protected, access controlled, purpose bound.**

*Note:* Remembering improves performance and creates exposure at the same time. An undated policy produces answers that are consistent and wrong; a historical exception should not silently become a rule. The wider scope exists because the deployment’s data surface was never just memory: prompts carry customers’ confessions, tool results carry account data, outputs carry decisions, and an inference — this customer is probably in financial distress — is data manufactured about a person who never handed it over, governed as if collected and often more sensitive than anything that was. Vendor use is named because it is the quiet channel: data can leave through a model provider’s training pipeline without a trace in the organization’s own systems, so the rule must be contractual and stated — and it is a claim a conformance declaration can carry. Deletion that cannot be evidenced is retention with extra steps. The log sentence closes a loop this standard opened itself: HWF-41, HWF-22, HWF-71, HWF-04 and HWF-23 each thicken an archive in which employees and customers appear — who said what, who approved what, who was slow to intervene — and the more conformant the deployment, the richer that archive grows. Its purpose is reconstruction and accountability; mining it to score employees or profile customers is a new purpose requiring its own basis, and an organization that turns its safety apparatus into a surveillance apparatus poisons the incentive to log honestly. HWF-03 already lists surveillance among its impact dimensions; this clause governs its largest new source.

*Built against:* S31 · EU — GDPR Article 5: principles relating to processing of personal data

#### HWF-43

**An AI Employee must have an identifiable version of model, policies, tools and knowledge base.**

*Note:* Without versioning it is impossible to say what authority existed at a given moment, or which change produced an improvement or a regression.

*Built from:* original WRM doctrine.

#### HWF-44

**Performance must be measured by outcomes, quality, risk and cost — never by activity, hours, tokens or message volume.**

*Note:* Speed makes activity look like value. A badly designed process that produced ten errors will produce a hundred once automated, and the dashboard will call it throughput.

*Built from:* original WRM doctrine.

### 5 · Risk and validation

#### HWF-51

**Every AI Employee position must carry a declared risk class from this standard’s scale, assessed twice: inherent risk before controls and residual risk after them. The class follows inherent risk — controls lower the residual, never the class. Autonomy, supervision and approval requirements scale with the class; a Critical action always terminates in a final human decision, and a Prohibited use cannot be made conformant by any control.**

*Note:* The class answers HWF-33’s open term: what counts as high-risk resolves against this scale rather than against taste. Judgment runs on seven factors — rights affected, scale of people touched, reversibility, presence of vulnerable people, data sensitivity, adversarial exposure and concentration of power — never on the cost of error alone, because a cheap error at scale against vulnerable people is not a cheap error. The lock in the citable text exists for one reason: without it, every vendor conversation becomes “we added a guardrail, so it is Low now”. Controls earn a better residual; they do not buy a better class. The HWFA derives a provisional class from cost of error and reversibility while allocating; the declared class of this clause weighs all seven factors and prevails, and Prohibited is not an instrument output but a precondition — the HWFA asks who should execute a use, and a Prohibited use has no who. The tiers are designed to interoperate with risk-based regimes such as the EU AI Act without claiming legal equivalence: mapping a class onto a legal category is an exercise for counsel, not a property of this document.

*Built against:* S25 · EU — Artificial Intelligence Act: regulatory framework on AI (risk-based approach)

#### HWF-52

**A version is a record, not a proof. Every material change to a deployment — model, tools, policies, knowledge or authority — must be revalidated before it operates, at a depth set by the risk class: representative cases, exception and escalation paths, and regression against the prior baseline; from High upward, adversarial testing against injection and exfiltration, bias analysis and drift monitoring. Where AI Employees work as a team, systemic risks are part of the validation: circular delegation, feedback loops, memory contamination, correlated failure across a shared model or vendor, and lateral propagation of authority.**

*Note:* The battery of tests presupposes a stochastic system — something that reasons, and can therefore drift, hallucinate and be injected. Deterministic automation does none of this, and none of this clause ever touched it: automation sits rungs below AI Employee on the vocabulary ladder and fails the nine-property test, so the obligations attach to the category and the category excludes determinism. Deterministic automation does not exhibit the drift risks proper to a stochastic system, so demanding that monitoring of it measures nothing. Among AI Employees the dial is the risk class, not all-or-nothing: a Low-risk deployment revalidates cases, exceptions and regression, and the adversarial and bias battery arrives from High upward, because HWF-51 exists precisely so that obligations can scale. The clause closes an asymmetry the standard carried: birth is exquisitely gated — twelve steps, shadow mode, a performance gate, a transition earned with evidence — while change had no gate at all, and a model swap could reach production untested. The twelve steps earn the transition; this clause keeps it earned. The team risks exist because HWF-22 permits pyramids: delegation can circle, feedback can compound, memory can contaminate downstream context, authority can propagate laterally through handoffs — and the least intuitive risk is correlated failure. Human teams do not fail independently either, but diversity of experience and judgment tends to distribute some blind spots; instances sharing a model, vendor, context or configuration concentrate them. The precedent is common-cause failure, long known to reliability engineering; what is new is the speed, reach and opacity with which it propagates. Diversity and fallback are its mitigation. On method, this standard states what must be validated and when; ISO/IEC 42001 and 42005 and the NIST AI RMF supply management systems for the how, and this document complements rather than recreates them — the same subsidiarity it applies to labor law.

*Built against:* S14 · NIST — AI Risk Management Framework — S32 · ISO/IEC 42001 — Artificial intelligence management system — S33 · ISO/IEC 42005 — AI system impact assessment

### 6 · Lifecycle

#### HWF-61

**A role contract must be revisable and must be reviewed at a stated cadence, never longer than twelve months. Divergence between measured outcomes and the stated mission, authority or KPIs must be detected by independent monitoring against the contract — the primary control — and where the AI Employee’s own performance data shows it first, the resource must report it to the accountable owner as a finding: a signal that supplements independent monitoring, never replaces it. The decision to change a role contract is always human and belongs to the accountable owner; it is never taken by an artificial supervisor and never applied automatically. Every clocked obligation on a position — reviews, re-justifications, renewals, drills and revalidations — appears in a single governance calendar in the role contract, with one named owner of the schedule.**

*Note:* The most common defect in a role contract is not that it was written badly. It is that nobody has looked at it since the day of deployment, while the products, the policies, the customers and the exception patterns all moved. The resource sits closer to the work than its owner does and sees the divergence first, so requiring it to report what its own data shows costs little and prevents silent drift — though a resource whose model or configuration is the problem shares the blind spot, which is why the clause makes independent monitoring the primary control and the self-report a supplement. A finding is not a petition: an AI Employee has no recognized interests to advance, and treating its report as a negotiation would reintroduce exactly the confusion HWF-13 exists to prevent. The decision always rises to a human, and never to the artificial supervisor above it, because a system that can widen its own scope through another system does not have a bounded scope.

*Built against:* S11 · CIPD — Performance Management factsheet

#### HWF-62

**Every transition between occupant types — human, assisted human or artificial — and every move to or from deterministic automation must be evaluable against a baseline and carry explicit rollback criteria.**

*Note:* Without a baseline recorded before the change, the organization can celebrate an improvement it never made. Rollback criteria written after the results are known are not criteria; they are justification.

*Built from:* original WRM doctrine.

#### HWF-63

**An AI Employee position must not outlive its justification. At a stated cadence, never longer than twelve months — and again within a stated window after any material change of strategy, policy, regulation, product or structure — the accountable owner must re-justify the position’s existence against current strategy, a question prior to and separate from performance, because a resource can meet every KPI in a position the organization no longer needs. Re-justification must consider whether a modified scope keeps the position current before it concludes retirement; a modified scope is re-justified on its own merits and never inherits the prior justification, and work invented to preserve a position is a failed justification rather than a redesign. Continuation is never the default: a position whose existence cannot be re-justified proceeds to retirement, and its access ends with it. A lapsed review is not a failed one: it escalates to the accountable owner and restricts or suspends the position in proportion while the review is forced — retirement is the outcome of a failed justification, never of a missed calendar.**

*Note:* Human pruning pressures are weak and fail often — bureaucracies carry dead positions for decades. But they exist: a salary line that a budget review questions, an occupant who leaves and forces a backfill decision. An artificial position removes even those weak triggers — its cost fragments across compute, integration, supervision, data and incidents, and rarely surfaces as a line anyone must defend; and nobody ever resigns from it — so a pointless position does not merely persist by default; it loses the last occasions on which anyone would notice it. In this framework’s own classification that makes organizational pruning an adapted principle: a mechanism that was already unreliable for humans disappears entirely for artificial occupants, and this clause is the replacement. What accumulates without it is organizational debt, and its most dangerous form is the digital zombie: credentials, data access and standing authority kept alive for work nobody needs — under HWF-32, risk surface with no return. The existence question comes before the performance question because a good answer to the second is the usual anaesthetic against the first. The cadence belongs in the role contract, and the twelve-month ceiling in the citable text is a maximum rather than a recommendation: high-volume and high-risk positions deserve shorter. This review may share its calendar with the HWF-61 review; it must never share its default. A calendar alone is not enough: a position can fall out of alignment the day after a change of direction and then wait eleven months for its turn, which is why the clause adds an event trigger. And the order of the review matters as much as its frequency. Asking first what would have to change is what any competent organization does with a human position when strategy moves, and it transfers to an artificial occupant for economic rather than compassionate reasons: provisioned context, governed memory, integrations, calibration and the trust built around the position are expensive to rebuild, and rebuilding usually costs more than adapting. The lock against abusing that posture sits in the citable text — a modified scope inherits nothing, and inventing work to keep a position alive is the failure this clause exists to name.

*Built from:* original WRM doctrine.

#### HWF-64

**Offboarding must revoke access and transfer or destroy context safely.**

*Note:* Revoke credentials, disable tools, stop schedules and queues, rotate secrets, transfer outstanding work, preserve evidence. Offboarding is as important as onboarding and is almost always skipped.

*Built from:* original WRM doctrine.

### 7 · Conformance

#### HWF-71

**Conformance belongs to a deployment, never to a product, a platform or an organization in the abstract. A conformance claim must name its scope — the organization and deployment, the role and role-contract version, the accountable owner, the risk class, the clauses assessed, the assessment period and its expiry — and must publish its evidence and known limitations. A vendor may state that its platform enables conformant deployments; it may never state that the platform itself conforms, and the enabling claim requires at least one live, unexpired customer declaration, publicly linked. A claim of conformance to the standard assesses all of its clauses; anything narrower is styled partial conformance and names the clauses assessed. No declaration is valid for more than twelve months.**

*Note:* Self-declared conformance without a defined unit degenerates into a marketing phrase within months, and the remedy is not certification — excluded from this standard’s scope and not returning — but falsifiability: a claim that names its deployment, owner, clauses, period, evidence and limitations can be verified or refuted by anyone, and public scrutiny is cheaper than a certification scheme and harder to capture — it enables verification and refutation; it does not substitute for an independent audit. An expired declaration is not a declaration; renewal may share its calendar with the existence review of HWF-63. The vendor sentence is the anti-laundering lock, and the first platform bound by it is the author’s own: AIEmpl.com may state that it enables conformant deployments, and may never call itself conformant. A standard that does not govern how it is invoked ends up meaning whatever marketing needs it to mean.

*Built against:* S9 · ISO 30414:2025 — Human resource management, HCRD

## Risk classification

A class is judged on inherent risk across seven factors — rights affected, scale of people touched, reversibility, presence of vulnerable people, data sensitivity, adversarial exposure and concentration of power — never on the cost of error alone. Controls lower residual risk; they never lower the class.

| Class | Meaning | Operating regime |
| --- | --- | --- |
| Prohibited | A use that cannot be made conformant by any control: it requires deceiving people about the system (HWF-14), overriding the constraints of HWF-01, or operating outside any accountable chain. | Not performed under this standard, by any resource configuration. |
| Critical | Severe or irreversible consequences for rights, safety, money at scale or the organization itself. | Mandatory final human decision on every action, separation of duties, autonomy capped at rungs 1–3 of the autonomy ladder, reinforced audit. |
| High | Serious but generally recoverable consequences, or moderate ones amplified by scale, data sensitivity or adversarial exposure. | Impact assessment before deployment, independent validation, reinforced supervision, human approval on defined action classes. |
| Moderate | Contained consequences, reversible with rework and some friction. | Bounded autonomy inside the authority matrix, continuous monitoring, sampled review. |
| Low | Internal, easily absorbed consequences. | Management by exception with baseline controls: identity, audit trail, escalation. |

The HWFA derives a provisional class from cost of error and reversibility during allocation; the declared class of HWF-51 weighs all seven factors and prevails. The tiers are designed to interoperate with risk-based regimes such as the EU AI Act without claiming legal equivalence: mapping a class onto a legal category is an exercise for counsel, not a property of this document.

## Maturity model

| Level | Name | Definition |
| --- | --- | --- |
| 0 | Tool | Generates content or responds. Does not act. |
| 1 | Assistant | Uses context to help a human. |
| 2 | Agent | Executes bounded tasks with tools. |
| 3 | Role agent | Owns the recurring workflows of a defined role. |
| 4 | AI Employee | The nine properties of the definition, exhibited in operation. |
| 5 | AI Team | Multiple AI Employees coordinated with shared context. |
| 6 | Hybrid Enterprise | Humans and AI Employees under one integrated model of organization, permissions and governance. |

**Category threshold: 4 — AI Employee.**

The ladder maps evolution of capacity and scale; it does not decide membership. Level 4 names the point where a deployment can exhibit the nine properties of the definition — whether it actually does is decided by the test, never by the level. Levels 0 to 3 are legitimate destinations, not failures — a well-placed assistant can produce more value than a supposed AI Employee nobody supervises.

### Self-diagnosis

1. Does it act, or only produce output?
2. Does it hold a recurring role, or only discrete tasks?
3. Following its supervision chain upward, does it reach a named human?
4. Can you reconstruct what it did last Tuesday and under whose authority?
5. Can it be suspended today, by someone who knows they own that decision?

## WRM — the framework

> WRM — Work Resource Management — is the discipline that designs, assigns, governs and optimizes work regardless of whether the resource executing it is human or artificial.

The founding idea is to separate the position from its occupant. First there is an organizational need; from it a position or responsibility is born, with purpose, ownership, results, KPIs, authority, limits, relationships, tools and escalation. Only then do you decide which resource should fill it. The declaration governs the order of birth, not the rest of the life: occupants — human occupants above all — reshape their positions, and a framework that denied job crafting would be Taylorism with better vocabulary. What the framework requires is that every reshaping be declared and versioned, because in a hybrid organization the declared position is the interface: a human colleague can read an undeclared role from the corridor; an artificial one can only read the graph.

### Where WRM sits

| Layer | Manages | Outcome |
| --- | --- | --- |
| WRM — Work Resource Management | The work, its positions, results, authority and controls | Optimal workforce architecture |
| Human Resource Management | People who execute work | Performance + rights + human development |
| Artificial Resource Management | AI systems that execute work | Performance + safety + technical control |
| Hybrid Workforce Management | Interaction and allocation between both | Coordination, transition and optimization |

### Three classes of principle

| Class | Count | Meaning |
| --- | --- | --- |
| U — Universal | 87 | Principles of work administration that hold regardless of who executes. |
| A — Adapted | 20 | Human principles that keep an equivalent function but change mechanism. |
| H — Exclusively human | 13 | Rights, needs and experiences that follow from the human condition. |

**Analogies like “the AI needs holidays” or “the AI feels engagement” import mechanisms with no operational referent, and forcing them degrades the framework. Equivalence must be operational, never anthropomorphic.**

### The ten domains

| # | Domain | Scope |
| --- | --- | --- |
| 1 | Organizational and job design | Purpose, responsibilities, authority, ownership, unity of command and interdependencies. |
| 2 | Selection and allocation | Define the position first, then assess fit, competencies, cost, risk and prior testing. |
| 3 | Onboarding and enablement | Company knowledge, SOPs, policies, org chart, tools and access. |
| 4 | Direction, collaboration and communication | Delegation, escalation, handoffs, channels, context and interaction rules. |
| 5 | Objectives and performance | KPIs, quality standards, feedback, review, underperformance and improvement. |
| 6 | Learning and development | Gaps, training, updates, memory, knowledge and capability evolution. |
| 7 | Human experience and rewards | Motivation, compensation, health, rest, rights and labor relations — when the resource is human. |
| 8 | Governance, security and risk | Least privilege, segregation, auditability, privacy, incidents and compliance. |
| 9 | Mobility, continuity and exit | Promotion and scope, succession and fallback, transfer, offboarding and knowledge retention. |
| 10 | Workforce planning and analytics | Capacity, make-vs-buy, human/AI mix, costs, productivity, quality and continuous improvement. |

### Lifecycle of a work resource

| # | Stage | Objective |
| --- | --- | --- |
| 1 | Design | Define result, responsibilities, KPIs, authority, limits and risk. |
| 2 | Allocate | Decide Human / Assisted human / Deterministic automation / Artificial. |
| 3 | Select | Person, model, agent, vendor or architecture with demonstrable fit. |
| 4 | Onboard | Knowledge, SOPs, culture and policies, relationships and escalation. |
| 5 | Enable | Tools, access, credentials, budget and authority. |
| 6 | Prove | Probation or shadow mode, simulations, evaluations and intensive approval. |
| 7 | Operate | Recurring work with observability and management by exception. |
| 8 | Measure | KPIs, quality, cost, incidents, interventions and outcomes. |
| 9 | Develop | Coaching or updates to instructions, knowledge, models and tools. The signal may originate with the manager or with the resource reporting divergence from its own data. |
| 10 | Reassign | Change scope, move between occupant types, revise which functions run with assistance. |
| 11 | Suspend | Stop work or access on risk, incident or unacceptable performance. |
| 12 | Retire | Offboarding, revocation, knowledge transfer and retention or deletion. |

### Ten non-negotiable rules

1. Every position must exist before its occupant, with purpose, responsibilities, results and KPIs — and no position may outlive its purpose.
2. Every work resource must have exactly one accountable owner, even when it collaborates with many people or areas and even when its supervision is delegated. One owner is primary, not exclusive: data, security, compliance and vendor obligations survive intact.
3. Responsibility and authority must travel together: no result is demanded without granting the necessary faculties.
4. All authority must be explicit, limited and revocable.
5. Every resource must know its limits, its handoffs and when to escalate.
6. Access is granted under least privilege and is separated from the identity of the model or the prompt. Context is provisioned on the same basis: what is granted and what is withheld are both recorded design decisions.
7. Every material action executed by an AI Employee must be traceable and auditable.
8. Performance is measured by outcomes, quality, risk and cost — not by activity, hours, tokens or message count.
9. A transition between occupant types must remain reversible until stable performance is demonstrated.
10. Final responsibility for an AI Employee stays with an identified person or human governance body, however many artificial supervisors sit between them.

## The 120-principle matrix

The matrix is an original synthesis of organizational design, HR, performance management, governance, workforce planning and risk practice. It is not a transcription of any single existing standard, and the classification is a working proposal of this framework — administrative doctrine, not a legal claim about the employment of software.

### 1. Work and organizational design

| # | Principle | Human resource | Artificial resource | Class |
| --- | --- | --- | --- | --- |
| 1 | Every position must have a purpose | The occupant must understand why the position exists and what value it creates. | The AI Employee must have an explicit, stable operational mission. | U |
| 2 | Formal job description | Documented job description. | Versioned AI Job Description / Role Contract. | U |
| 3 | Defined responsibilities | Results and duties assigned with clarity. | Processes, decisions and results under explicit ownership. | U |
| 4 | Limits of the position | It must be clear what does not belong to it. | Prohibited actions, domains, data and decisions. | U |
| 5 | Defined authority | It is specified what can be decided without approval. | Autonomous actions, thresholds and approvals are specified. | U |
| 6 | Responsibility and authority must be aligned | No result is demanded without sufficient faculties or resources. | No KPI is demanded without tools, permissions, data and budget. | U |
| 7 | Unity of command and clear accountability | There must be a manager accountable for performance. | Exactly one accountable owner — primary, not exclusive — even when work comes from several areas and supervision is delegated. | U |
| 8 | Known chain of command and escalation | Knows whom to escalate an exception or conflict to. | Explicit escalation tree by type, risk and urgency. | U |
| 9 | Reasonable span of control | A manager should not have more reports than they can effectively direct. | Scale may be larger, but requires tooling, dashboards and supervision limits. | A |
| 10 | Division of labor and specialization | Roles organized by competencies and results. | AI Employees or subagents specialized by function. | U |
| 11 | Avoid duplicated ownership | There must not be two ambiguous owners of the same result. | Avoid several AI Employees acting on the same object without coordination or lock. | U |
| 12 | Explicit interdependencies | Inputs, outputs and dependencies between positions are known. | Handoffs, APIs, humans, other AI Employees and systems identified. | U |

### 2. Selection and onboarding

| # | Principle | Human resource | Artificial resource | Class |
| --- | --- | --- | --- | --- |
| 13 | Define the position before selecting the occupant | First design the role; then look for the person. | First design the role; then choose model, agent and configuration. | U |
| 14 | Select on required competencies | Skills, experience, knowledge and behaviors. | Model, reasoning, tools, memory, context and integrations. | U |
| 15 | Validate competencies before hiring | Interviews, tests, references and assessment. | Benchmarks, evals, simulations, sandbox and role red-teaming. | U |
| 16 | Do not pay for capability the position does not need | Avoid costly or poorly used overqualification. | Do not use the most expensive model if a smaller one meets the SLA. | U |
| 17 | Position–resource fit | Person-job fit and person-organization fit. | Model/agent-role fit and architecture-role fit. | U |
| 18 | Probationary period | Probation with supervision and success criteria. | Shadow mode, sandbox or production with reinforced approvals. | U |
| 19 | Prior verification | Background, references and applicable trust requirements. | Security review, vendor/model evaluation, provenance and supply-chain review. | A |
| 20 | Induction to the organization | History, purpose, strategy and structure. | Business context, structure, objectives and policies loaded into the knowledge layer. | U |
| 21 | Know products and services | Training on offer, customers and value proposition. | Knowledge base / RAG / context on products, pricing, customers and constraints. | U |
| 22 | Know policies | Handbook, internal policies and obligations. | Policy layer, system policies and compliance rules. | U |
| 23 | Know procedures | SOPs, checklists and ways of working. | Executable SOPs, instructions and authorized workflows. | U |
| 24 | Know colleagues and structure | Org chart, stakeholders and responsibilities. | Organizational graph with humans, AI Employees, roles, channels and ownership. | U |
| 25 | Know the supervisor | Assigned manager and expectations of the relationship. | Accountable manager registered as part of the role. | U |
| 26 | Know communication channels | Email, Slack/Teams, meetings, tickets and protocols. | Authorized channels, routing, recipients and communication rules. | U |
| 27 | Receive working tools | Equipment, software, accounts and operational access. | Tools, APIs, credentials, browser, DBs, ERP/CRM and other connectors. | U |
| 28 | Receive only necessary access | RBAC and least privilege. | RBAC, least privilege, isolated secrets and minimum scopes. | U |

### 3. Objectives, direction and performance

| # | Principle | Human resource | Artificial resource | Class |
| --- | --- | --- | --- | --- |
| 29 | Clear objectives | Concrete expectations about what must be achieved. | Explicit, verifiable objectives tied to the Role Contract. | U |
| 30 | Defined KPIs | Performance metrics for the position. | KPIs, SLAs, quality, cost and risk of the AI Employee. | U |
| 31 | Align KPIs with business objectives | Avoid vanity metrics or perverse incentives. | Measure outcomes, not tool calls, tokens or valueless activity. | U |
| 32 | Achievable targets | Realistic targets given resources and capacity. | Realistic targets given model, context, tools and authority. | U |
| 33 | Frequent feedback | Performance conversations and course correction. | Manager feedback feeds configuration, examples, policies, evals or prompts. | A |
| 34 | Periodic evaluation | Formal or continuous performance review. | AI Performance Review with metrics, incidents and quality samples. | U |
| 35 | Evaluate results, not mere activity | Outcome and quality above visible hours. | Outcome and reliability above tokens, messages or steps executed. | U |
| 36 | Compare result against a standard | Quality bar, SLA or professional standard. | Test sets, golden datasets, thresholds and policy checks. | U |
| 37 | Responsibility for performance | Employee and manager both participate in the result. | The AI executes; the accountable human retains business and governance responsibility. | A |
| 38 | Correct underperformance | Coaching, training, PIP or redesign of the position. | Modify instructions, knowledge, model, tools, workflow or scope. | A |
| 39 | Recognize high performance | Recognition, promotion, compensation or more autonomy. | Wider scope, autonomy, authority limits or assignment to more critical processes. | A |
| 40 | Supervision proportional to competence and risk | A junior needs more supervision; an expert can receive more autonomy. | Autonomy increases only with evidence of reliability and according to risk class. | U |
| 41 | Explicit delegation | The manager defines what is delegated and what is retained. | Every delegated decision or action must appear in policy or authority matrix. | U |
| 42 | Management by exception | The manager intervenes especially on deviations and exceptions. | The AI resolves routine within limits and escalates exceptions. | U |
| 43 | Defined escalation | Criteria for requesting help or approval. | Confidence/risk thresholds, timers, exception classes and human escalation. | U |
| 44 | Separation of duties | Reduces fraud, error and undue concentration of power. | The AI that initiates a payment should not approve it; maker/checker roles separated. | U |
| 45 | Four-eyes principle | Sensitive decisions require additional review. | AI+human, AI+AI+human or other approval proportional to risk. | A |
| 46 | Do not grant more authority than necessary | Minimum delegation compatible with the work. | Least authority and transactional limits. | U |
| 47 | Authority must be revocable | Suspension or withdrawal of faculties when risk changes. | Kill switch, revoke credentials, disable tools or downgrade autonomy. | U |

### 4. Development, knowledge and communication

| # | Principle | Human resource | Artificial resource | Class |
| --- | --- | --- | --- | --- |
| 48 | Continuous training | Training to maintain and extend capabilities. | Updates to knowledge, tools, model, examples, policies and evals. | U |
| 49 | Identify competence gaps | Skills gap analysis. | Capability gap from eval failures, incidents and unsupported tasks. | U |
| 50 | Development plan | Career path and Individual Development Plan. | Capability roadmap and criteria for widening scope or autonomy. | A |
| 51 | Coaching | The manager helps improve judgment and execution. | Human feedback transforms configuration, context, examples and policy. | A |
| 52 | Learn from mistakes | Lessons learned and corrective actions. | Postmortems, regression evals, controlled memory and new guardrails. | U |
| 53 | Knowledge management | Capture and share critical knowledge. | Shared knowledge layer, provenance, versioning and retrieval. | U |
| 54 | Update on policy change | Retrain when rules, products or context change. | Update policy/context immediately and verify comprehension with evals. | U |
| 55 | Clear communication of expectations | Reduce ambiguity in objectives and standards. | Unambiguous Role Contract, prompts, policies and definitions of done. | U |
| 56 | Defined official channels | The organization determines where each type of communication happens. | Channels and tools authorized by type of interaction. | U |
| 57 | Sufficient context to decide | The person needs relevant and timely information. | Context engineering, retrieval and memory sufficient; anything withheld is a recorded design decision, never a silent gap. | U |
| 58 | Right information, right actor | Need-to-know principle. | Need-to-know enforced by RBAC, retrieval filters and data scopes. | U |
| 59 | Document important decisions | Record for continuity, control and audit. | Structured logs, tool traces and decision records. | U |
| 60 | Clear handoffs | Explicit transfer between people or teams. | Agent-to-agent and AI-to-human handoffs with state, context and ownership. | U |

### 5. Motivation, experience and compensation

| # | Principle | Human resource | Artificial resource | Class |
| --- | --- | --- | --- | --- |
| 61 | Personal sense of purpose | Can affect motivation, commitment and retention. | Does not exist as subjective experience of the software. | H |
| 62 | Intrinsic motivation | Interest, mastery, autonomy and meaning can drive performance. | Not applicable as a psychological state. | H |
| 63 | Extrinsic motivation | Pay, recognition, incentives and consequences. | A reward/optimization function may exist, but is not human motivation. | A |
| 64 | Engagement | Psychological commitment to work and organization. | Does not exist as demonstrable subjective experience. | H |
| 65 | Job satisfaction | Matters for human health, retention and performance. | Not applicable to the artificial resource. | H |
| 66 | Sense of belonging | Social and psychological relationship with the group. | Not applicable ontologically; can only simulate social conduct. | H |
| 67 | Salary | Economic consideration for work. | No salary; there are model, SaaS, infrastructure, license and support costs. | A |
| 68 | Fair compensation | Internal, external and legal equity. | Economic optimization applies, but not as a right of the software. | A |
| 69 | Performance bonuses | Economic incentive tied to results. | No psychological incentive required; technical reward functions may be used. | A |
| 70 | Benefits | Health, pension, insurance, holidays and other entitlements. | Not applicable to software. | H |
| 71 | Total cost of the employee | Salary + charges + benefits + equipment + administration. | Total Cost of AI Employment: models + infrastructure + integrations + supervision + errors + governance. | U |
| 72 | Occupational health | Protection of physical and mental health. | Not applicable as AI wellbeing; operational safety requirements do exist. | H |
| 73 | Rest | Biological need and labor protection. | Not applicable biologically; replaced by maintenance windows, quotas and capacity management. | A |
| 74 | Working hours | Human protection over working time. | May operate 24/7 subject to capacity, budget and operating rules. | H |
| 75 | Burnout | Human risk from sustained stress. | Not treated as a subjective state; the operational realities are degradation, context pollution, saturation and error accumulation. | A |
| 76 | Psychological safety | Allows speaking, disagreeing and admitting error without undue fear. | Not applicable as AI experience, though it matters for the humans working with it. | H |

### 6. Ethics, conduct and labor relations

| # | Principle | Human resource | Artificial resource | Class |
| --- | --- | --- | --- | --- |
| 77 | Code of conduct | Expected standards of behavior. | Behavioral policies, output constraints and conduct rules. | U |
| 78 | Confidentiality | Duty of discretion and care of information. | Data access, disclosure policies, DLP and constraints. | U |
| 79 | Conflicts of interest | Identify and manage incompatible interests. | Manage conflicts between vendor, data source, goals, tools or roles. | A |
| 80 | Non-discrimination | Ethical and legal obligation in decisions about people. | Fairness testing, policy constraints and human review of sensitive decisions. | U |
| 81 | Honesty and integrity | Do not deceive, falsify or deliberately conceal. | Policies against fabrication, impersonation, simulated affect and unsupported claims. | U |
| 82 | Protection of information | Custody and appropriate use of data. | Data minimization, encryption, access control and retention. | U |
| 83 | Regulatory compliance | Respect for applicable laws, policies and standards. | Compliance-by-design plus human accountability. | U |
| 84 | Freedom of association | Human right of labor association. | Not applicable to software. | H |
| 85 | Collective bargaining | Right of human workers and unions. | Not applicable to software. | H |
| 86 | Grievance procedure | Channel for a person to contest decisions or conditions. | Not applicable subjectively to the AI; human channels must exist to contest its actions. | H |
| 87 | Protection against harassment | Human right to an environment free of harassment. | Not applicable to the AI as victim; its outputs must be governed so as not to harass humans. | H |
| 88 | Due disciplinary process | Human protection against disciplinary measures. | Not a right of software; operationally replaced by incident review and change control. | A |

### 7. Governance, security and risk

| # | Principle | Human resource | Artificial resource | Class |
| --- | --- | --- | --- | --- |
| 89 | Segregation of access | Limit and separate privileges by role. | Fundamental: identity, RBAC, scopes and separated secrets. | U |
| 90 | Audit | Independent review of processes and decisions. | Logs, traces, event history, evals and reproducibility. | U |
| 91 | Traceability | Know who did what, when and under what authority. | Actor ID + action + timestamp + context + tool + approval, plus the policy and versions in force. | U |
| 92 | Accountability | There must be a person responsible for decisions and results. | Never orphaned: an accountable human answers for deployment, authority and outcomes. | U |
| 93 | Incident management | Detect, contain, investigate and learn from failures. | AI incident management with kill switch, rollback, postmortem and remediation. | U |
| 94 | Data protection | Privacy, access, minimization and retention principles. | Data governance, consent, retrieval filters, retention and deletion — covering derived inferences and the audit logs themselves (HWF-42). | U |
| 95 | Risk management | Identify, assess, mitigate and monitor exposure. | Risk classification by role, tool, data and action; proportional controls. | U |

### 8. Mobility, continuity and exit

| # | Principle | Human resource | Artificial resource | Class |
| --- | --- | --- | --- | --- |
| 96 | Promotion | More responsibility, scope, status or compensation. | More scope, autonomy, budget or authority after evidence. | A |
| 97 | Position transfer | Change of function or unit. | New Role Contract, tools, context, permissions and manager. | U |
| 98 | Succession plan | Prepare a replacement for critical talent. | Fallback agent/model/version and replacement runbook. | U |
| 99 | Cross-training | Develop flexibility to cover other functions. | Multi-capability, backup agents or ensembles, minding separation of duties. | U |
| 100 | Retention of critical talent and knowledge | Reduce loss of capabilities and know-how. | Reduce vendor/model lock-in; preserve prompts, policies, evals, memory and artifacts. | A |
| 101 | Termination criteria | Underperformance, restructuring, breach or other causes. | Obsolescence, cost, risk, incidents, underperformance or architecture change; existence is re-justified on a stated cadence (HWF-63). | U |
| 102 | Offboarding | Recover equipment, access, obligations and responsibilities. | Revoke credentials, disable tools, remove schedules, queues and integrations. | U |
| 103 | Knowledge transfer | Avoid loss of information on exit. | Export approved memory, context, artifacts, runbooks and outstanding tasks. | U |
| 104 | Information protection after exit | Confidentiality and closing of access. | Retention/deletion policies, revocation and secret rotation. | U |
| 105 | Historical record | Employee file and evidence of performance. | Versioned audit/performance record for governance and learning. | U |

### 9. Workforce planning

| # | Principle | Human resource | Artificial resource | Class |
| --- | --- | --- | --- | --- |
| 106 | Plan future capacity | Headcount, skills and load required by the strategy. | Human + AI capacity planning, concurrency and workload forecasting. | U |
| 107 | Make vs. buy | Hire, outsource or develop capability internally. | Build agent vs. SaaS/vendor vs. managed service vs. open source. | U |
| 108 | Sizing | Number and mix of people required. | Instances, concurrency, model tiers and required capacity. | U |
| 109 | Design the workforce mix | Full-time, part-time, contractors, outsourcing. | Allocation across the four outcomes — Human, Assisted human, Deterministic automation or Artificial — by risk, cost and comparative advantage. | U |
| 110 | Productivity per resource | Output/FTE and value generated. | Outcome/AI Employee, cost per outcome and human review load. | U |

### 10. Analytics and continuous improvement

| # | Principle | Human resource | Artificial resource | Class |
| --- | --- | --- | --- | --- |
| 111 | Measure productivity | Quantity or value of output per resource. | Outcomes per unit of cost/time of the AI Employee. | U |
| 112 | Measure quality | Quality against the standard of the position. | Accuracy, acceptance rate, QA score and policy compliance. | U |
| 113 | Measure cost | Total and marginal cost of operating the position. | Model + compute + tools + integrations + supervision + error cost. | U |
| 114 | Measure errors | Error rate, rework and incidents. | Hallucination/error rate, exception rate, incidents and recovery cost. | U |
| 115 | Measure availability | Attendance and coverage of the human resource. | Uptime, queue readiness, dependency availability. | U |
| 116 | Measure utilization | Capacity used versus available. | Runtime/concurrency/tool utilization and idle capacity. | U |
| 117 | Measure time to competence | Time-to-productivity of a new hire. | Time-to-autonomy: from instantiation to reliable performance. | U |
| 118 | Measure turnover and replacement | Turnover and its causes and costs. | Model/agent replacement rate, architecture churn and migration cost. | A |
| 119 | Benchmarking | Compare performance between people, teams or market. | Compare models, configurations, prompts, agent versions and vendors. | U |
| 120 | Continuous improvement | Optimize processes and workforce with evidence. | Continuous evals, optimization, policy iteration and process redesign. | U |

## HWFA — Hybrid Workforce Fit Assessment

A structured instrument in three stages — eligibility, then risk, then economics — for deciding whether a responsibility should be Human, Assisted human, Deterministic automation or Artificial. Constraints come first: reserved subjects and prohibited uses gate the answer, fully enumerable rule-following work exits to conventional software, risk caps what survives, and only then does the cost profile choose among the remainder. It returns an argument, not a number: an allocation, a risk class, a starting autonomy rung, the answers that decided it, and the conditions that would change it — a numeric score would let a decision already taken be laundered through arithmetic.

### The thirteen dimensions

| Dimension | Question | Options, least to most suited to an artificial resource |
| --- | --- | --- |
| Reserved subjects | Does the responsibility decide matters HWF-02 reserves to humans? | Yes — its core decisions are reserved: employment, health and safety, credit or essential services, legal rights, force, vulnerable people · Reserved matters appear regularly among its decisions · It occasionally touches reserved matters, and they can be routed out · It never decides reserved matters |
| Repeatability | Does the work follow patterns? | Almost every case is different · Loose patterns, frequent variation · Clear patterns with some variation · Highly repetitive, well-defined |
| Predictability | Are the scenarios known or modellable? | Novel situations constantly appear · Known in outline, unpredictable in detail · Mostly known, documented cases · Fully enumerable inputs and outputs |
| Data availability | Is there sufficient and authorized context? | The criteria live in people’s heads · Partially documented, scattered · Documented, accessible, needs curation · Complete, current, authorized and queryable |
| Judgment required | Does it require ambiguous or strategic judgment? | Strategic judgment, competing priorities · Significant contextual judgment · Some judgment inside clear rules · Rule-following, little interpretation |
| Human significance | What does the interaction mean for the person on the other side? | Dignity, vulnerability or power over the person is at stake — or the relationship is the product · Trust materially affects the outcome · Courtesy matters, relationship does not decide · Transactional, no relational component |
| Cost of error | What does a wrong decision cost? | Severe: legal, financial or safety consequences · High: significant customer or money impact · Moderate: rework and some friction · Low: internal and easily absorbed |
| Reversibility | Can a wrong action be undone? | Irreversible once executed · Reversible at high cost or with damage done · Reversible with effort inside a window · Trivially reversible |
| Volume | How many cases flow through this responsibility? | A handful of cases per month · Steady but modest · High, occupies real capacity · Very high, a bottleneck today |
| Speed and 24/7 | Does continuous availability add value? | No, business hours are fine · Marginally useful · Clearly valuable · Decisive — delay destroys the outcome |
| Auditability | Can we verify the result? | Quality is a matter of opinion · Verifiable only by sampling · Verifiable against a defined standard · Automatically verifiable, objective criteria |
| Exception rate | What share of cases leaves the happy path? | Most cases are exceptions · Roughly a third · Around one in ten · Rare, under a few percent |
| Cost profile | Where does the cost of this responsibility sit today? | In scarce senior judgment applied case by case · In relationship time that builds the outcome · In skilled time consumed by repetitive cases · In coverage: queues, waiting and out-of-hours demand |

### The autonomy ladder

| Rung | Name | Detail |
| --- | --- | --- |
| 1 | Observe | Records and compares without intervening. Shadow mode against a human baseline. |
| 2 | Recommend | Proposes the action and shows the evidence used. A human executes. |
| 3 | Execute on approval | Acts only after explicit human approval, case by case. |
| 4 | Act by exception | Acts within rules; the manager intervenes on exceptions only. |
| 5 | Autonomous within limits | Operates autonomously inside defined limits, with traceability and escalation. |

**No responsibility starts above rung 3, whatever the assessment says. Autonomy is earned with evidence of stable performance, never granted because the model appears capable.**

## The role: Hybrid Workforce Manager

### Mission

> Design, balance and optimize the human and artificial workforce, ensuring every responsibility is executed by the resource — human or artificial — that produces the best result at the right level of cost, risk, quality and accountability.

In large organizations this can grow into a Director of Hybrid Workforce. It belongs inside HR / People & Workforce, with a strong matrix relationship to the COO and the CIO or CTO. Not every company needs to create the title tomorrow — but any organization granting role stewardship to artificial resources needs someone exercising these functions.

### Responsibilities

1. Maintain human–AI operational harmony: eliminate contradictory ownership, define handoffs and escalation lines.
2. Periodically reassess which work should be Human, Assisted human, Deterministic automation or Artificial.
3. Direct Human → Artificial and Artificial → Human transitions.
4. Design hybrid positions with an explicit split of responsibilities.
5. Manage human impact: clarity, communication, reassignment and development.
6. Guarantee every AI Employee has a Role Contract, manager, KPIs, permissions, limits, audit trail, performance review, and a kill switch exercised on a stated cadence (HWF-23).
7. Coordinate with IT and Security on access, runtime, observability and incidents.
8. Stay neutral about resource type within the boundary of HWF-01: the goal is neither “use more AI” nor “protect positions” — it is to optimize the work inside the space that rights, dignity, safety and labor protections leave open.
9. Report to leadership on cost per outcome, quality, risk, capacity released and workforce performance.
10. Maintain the official inventory of positions, human and artificial actors, and their maturity state.

### The anti-KPI

**Never measure this role by the number of humans replaced or the percentage of positions converted to AI. Those KPIs create a perverse incentive: they reward conversion rather than results, and they guarantee that the person meant to protect the quality of the decision is paid to prejudge it.**

### Scorecard

| KPI | What it measures |  |
| --- | --- | --- |
| Workforce Performance Index | Overall workforce result against objectives. |  |
| Role Allocation Accuracy | Share of roles whose allocation — Human, Assisted human, Deterministic automation or Artificial — survives review. |  |
| Transition Success Rate | Transitions meeting their success criteria over total attempted. |  |
| Time to Stable Performance | Days until KPIs and expected risk level are reached. |  |
| Post-Transition Performance Delta | Change in performance after the transition. Does the work function better than before? | **to CEO** |
| Cost per Successful Outcome | Total cost divided by correct, accepted results — supervision and rework included. | **to CEO** |
| Quality Delta | Change in quality before versus after the transition. |  |
| AI Exception Rate | Escalated cases over processed cases — a health signal, never a target: what matters is not how many escalations, but whether they were the right ones. |  |
| Human Intervention Rate | Executions requiring human correction. Rising means the autonomy on paper is not real; falling with a rising Missed Escalation Rate means the system learned to stop asking. | **to CEO** |
| Missed Escalation Rate | Cases that should have escalated and did not, found in audit or after the harm. The dangerous direction. | **to CEO** |
| Unnecessary Escalation Rate | Escalations a human resolved trivially — noise that erodes the reviewer’s attention. Appropriate escalation is the residue of these two. |  |
| Correction Severity | When a human corrected, how bad was what they caught. Ties the review burden to what it actually prevents. |  |
| Human Review Burden by Risk Class | Review hours per risk class. Overload in Critical is the signature problem of HWF-02 taking shape. |  |
| Unresolved High-Risk Exceptions | Aging queue of High and Critical exceptions without resolution. |  |
| Harmful Outcome Severity | Severity-weighted harm that reached customers or workers. | **to CEO** |
| Workforce Clarity Score | Clarity of roles, ownership and escalation. |  |
| Human Capacity Reallocation Rate | Released hours that moved to higher-value work over total released hours. |  |
| Hybrid Workforce Incident Rate | Incidents attributable to human/AI design. | **to CEO** |
| Role Conflict Rate | Ownership conflicts per period. |  |
| AI Employee SLA Compliance | Compliance with the SLA of the artificial role. |  |
| Workforce ROI | (Incremental value − workforce cost) / workforce cost. |  |

**Escalation metrics are health signals, not targets. A system rewarded for fewer escalations learns silence — the exact failure HWF-34 exists to prevent — so escalation is judged by quality, never by volume: the pair that matters is missed versus unnecessary, appropriate escalation is the residue of the two, and no metric on this scorecard may carry an incentive toward silence.**

Six of these carry the executive flag: whether the work functions better than before, what a correct result costs, how much autonomy is real, what should have escalated and did not, what harm got through, and what incidents the design produced. And the dashboard is not only this scorecard — it also shows what other clauses already generate: complaints and appeals from affected persons (HWF-04), residual risk against the declared class (HWF-51), drift since the last revalidation (HWF-52), and the labor consequences the impact assessments recorded (HWF-03). A dashboard showing only performance and cost is the one a CFO wants; this is the one a board needs.

### Capacity Elevation Rate

The share of human capacity released by automation that moved to higher-value work. The metric exists to stop “productivity” from hiding what actually happened. Released hours can become analysis, service, innovation, leadership, elimination of waste — or a real headcount reduction. Those are different decisions and must be counted separately. Technology can free hours; it cannot decide what they are for.

## Transitions

### Human → Artificial

The objective is not to “replace a person”. It is to transfer responsibility in a controlled way after demonstrating that the new design produces results equal to or better than the old one, within permitted risk.

**Before step one: the human impact assessment of HWF-03, recorded, with affected workers and their representatives informed and consulted. The playbook transfers the work; the assessment governs what the transfer does to people.**

| # | Step | Control |
| --- | --- | --- |
| 1 | Baseline | Document current performance: quality, cost, time, errors, exceptions and tacit knowledge. |
| 2 | Decomposition | Split the position into responsibilities and tasks; identify what must stay human. |
| 3 | Risk mapping | Classify decisions, data, authority and cost of error. |
| 4 | AI Role Contract | Create job description, KPIs, limits, tools, manager and escalation. |
| 5 | Knowledge transfer | SOPs, examples, criteria, policies, exceptions and history. |
| 6 | Shadow mode | The AI Employee executes without affecting production; results are compared against the human. |
| 7 | Controlled production | Limited authority and frequent approvals. |
| 8 | Performance gate | Ownership is not transferred until quality, cost and risk thresholds are met. |
| 9 | Gradual transfer | Increase scope and autonomy; keep reversibility. |
| 10 | Human reallocation | Move released human capacity toward higher-value work, against the training and reassignment plan recorded in the impact assessment (HWF-03). |
| 11 | Formal handoff | Update org chart, RACI/ownership, access and communication. |
| 12 | Post-transition review | Review at 30/60/90 days and revert if performance deteriorates. |

**You do not substitute first and find out afterward whether it was working. The transition is earned with evidence.**

### Artificial → Human

The framework must be reversible. If the artificial resource produces too much risk, low quality, excessive human intervention, rising cost or relational damage, the work should return partly or entirely to human hands. A mature hybrid organization does not measure success by the direction of the transition. It measures it by the quality of its architecture.

1. Activate the rollback criterion by KPI or incident.
2. Freeze or reduce the AI Employee’s authority.
3. Transfer context, useful memory and backlog to the human.
4. Reassign ownership and escalation channels.
5. Revoke artificial access that no longer corresponds.
6. Run root-cause analysis: model, process, knowledge, tools or bad role allocation.
7. Decide whether the future of the position is Human or Assisted human — do not assume it must return to being unassisted.

Define the return conditions before the pilot, not after the results are known. What error rate is unacceptable? How much human intervention destroys the economics? Which incident forces suspension? Written in advance, these rules reduce the bias of defending an implementation out of pride.

## Glossary

One term, two languages, one numbered definition. Where the English term is used untranslated in Spanish practice, both entries carry the same word — that is a deliberate decision to stop the vocabulary from splitting across the two editions of this standard.

**Acronyms do not translate. WRM, HWFA and the HWF- clause identifiers stay identical in every edition of this standard, present and future; only the words they expand to are localized. A reader who cites WRM or HWF-44 in any language is pointing at the same thing.**

**G-01 · AI Employee** — A persistent, role-bound software worker that autonomously executes recurring business responsibilities within explicit limits, with traceable identity, measurable performance, escalation paths and human accountability.

**G-02 · WRM — Work Resource Management** — The discipline that designs, assigns, governs and optimizes work regardless of whether the resource executing it is human or artificial.

**G-03 · AI Role Contract** — The operational contract of an artificial position: mission, responsibilities, results, KPIs, authority, exclusions, tools, access, service level, escalation, suspension criteria, governance calendar and accountable owner. Versioned. The equivalent of a job description plus an explicit operating agreement — a prompt gives instructions, a role contract gives responsibility.

**G-04 · Accountable owner** — The single identified human, or human governance body, that answers for an AI Employee’s configuration, authority, performance and exceptions. Exactly one, even when the resource receives work from several areas and even when its day-to-day supervision has been delegated. Accountability is never delegable to an artificial resource, because answering for an outcome requires the capacity to bear a consequence. Primary, not exclusive: system, data, security, compliance, vendor and director obligations survive intact (HWF-21). A governance body qualifies as owner only with an identified chair, stated decision rules and emergency capacity.

**G-05 · Shadow mode** — A stage in which the artificial resource executes the work but its actions do not affect the operation. Results are compared against a human baseline. The operational equivalent of probation.

**G-06 · Context Provisioning** — The onboarding equivalent for an artificial resource. Divided into must know, may consult and must not access. The third category has two legitimate grounds: protecting the information from the resource, and protecting the decision from the information (HWF-35); either way, the restriction is recorded, never silent.

**G-07 · Authority Matrix** — The record of what a resource may read, write, decide, spend, communicate or execute, and which of those require approval. Autonomy without an authority matrix is an empty word.

**G-08 · Escalation tree** — The explicit mapping of exception type, risk and urgency to a destination — a person, a team or a fallback rule. Every exception needs a destination.

**G-09 · Governed memory** — Memory with provenance, scope, retention and deletion rules, plus a named owner and an update mechanism. An undated policy produces answers that are consistent and wrong.

**G-10 · Human Intervention Rate** — The proportion of cases or decisions requiring human correction. Reveals how much of the declared autonomy is real and how much is automation quietly propped up by people.

**G-11 · Cost per Successful Outcome** — Total cost of producing a correct, accepted result — including platform, integration, supervision, rework, incidents and residual human operation. Comparing a subscription against a salary is the wrong benchmark.

**G-12 · Post-Transition Performance Delta** — The change in performance after switching resource or configuration. It does not ask whether the agent is fast; it asks whether the position got better. Without a baseline, an organization can celebrate an improvement that never happened.

**G-13 · HWFA — Hybrid Workforce Fit Assessment** — A structured instrument in three stages — eligibility, risk, economics — for deciding whether a responsibility should be Human, Assisted human, Deterministic automation or Artificial. It returns an argument, not a number: an allocation, a risk class, a starting autonomy rung and the conditions that would change the answer. Formerly the Fit Score; renamed because an instrument that refuses to produce a number should not be called one.

**G-14 · Hybrid Workforce Manager** — The role accountable for ensuring each responsibility is executed by the configuration that produces the best result. Neutral by design: never measured by humans replaced or positions converted.

**G-15 · Capacity Elevation Rate** — The share of released human capacity that moved to higher-value work. Keeps “productivity” from hiding whether hours became analysis, service, innovation, eliminated waste — or a headcount reduction that should be named.

**G-16 · Kill switch** — The technical and procedural ability to suspend an AI Employee immediately. A kill switch without a named owner is only a feature; the role contract must say who may use it and under what condition.

**G-17 · Least privilege / least authority** — Least privilege limits what a resource can access; least authority limits what it can decide or commit. They are separate controls and both are required.

**G-18 · Role stewardship vs task execution** — “Send these twenty follow-ups” is a task. “Manage commercial follow-up for this portfolio” is a role: prioritizing, respecting constraints, keeping context, recognizing exceptions and escalating. The move from one to the other is what justifies the category.

**G-19 · Remediation plan** — The artificial equivalent of a performance improvement plan: reduce scope, increase approvals, correct configuration or context, and validate again before restoring authority.

**G-20 · Fallback architecture** — The succession plan for an artificial resource: an alternative model, agent or vendor, plus a replacement runbook. Reduces lock-in and makes retirement survivable.

**G-21 · Offboarding / deprovisioning** — Revoke credentials, disable tools, stop schedules and queues, rotate secrets, transfer outstanding work and context, preserve evidence. As important as onboarding and almost always skipped.

**G-22 · Time-to-autonomy** — Days from instantiation to reliable performance at the expected risk level. The artificial counterpart of time-to-productivity for a new hire.

**G-23 · Total Cost of AI Employment** — Models plus infrastructure plus integrations plus supervision plus error cost plus governance. The artificial analog of total cost of employment, and the only honest basis for comparison.

**G-24 · Management by exception** — The operating mode in which the resource resolves routine work inside its limits and the manager intervenes on deviations and exceptions. Rung 4 of the autonomy ladder.

**G-25 · Assisted human** — A position held by a person, some of whose functions are executed with artificial assistance. The occupant is human: accountability, the decisions and the counterparty relationship stay with the person, while the artificial resource prepares, drafts, analyzes or recommends. This is not a third type of employee — it is a human employee, assisted. What is hybrid is the workforce, not the person.

**G-26 · Supervisor** — Whoever directs an AI Employee’s work day to day: routing tasks, reviewing output, setting priorities and receiving exceptions. A supervisor may be human or artificial. Distinct from the accountable owner, which is always human — an AI Employee can supervise another and still answer to a person somewhere above it.

**G-27 · Supervision chain** — The path from an AI Employee upward through each supervisor to the accountable human or governance body. Chains of any depth are permitted, but each must terminate in a human, be traversable and observable end to end, and allow the accountable party to intervene at any point without going through the chain itself. Depth is bounded by span of control rather than by a fixed number: scale may grow only against tooling that makes it governable.

**G-28 · Role divergence** — The gap between what an AI Employee actually produces and the mission, authority or KPIs its role contract states. Reported by the resource to its accountable owner as a finding, never as a request: the resource has no interests to advance, and the decision to revise the contract stays with the human. Divergence is the signal that a contract has aged, not evidence that the resource deserves more.

**G-29 · Decision determinants** — The state that produced a particular action: the policy in force, the knowledge retrieved and its provenance, the tool results returned, the authority in effect, and the versions of model and configuration running at that moment. Distinct from the outcome, which says what happened, and from a reasoning trace, which says what the system reports having thought. Determinants are what allow a failure to be attributed to a cause rather than merely recorded.

**G-30 · Simulated interiority** — Behavior whose result is that a person believes an artificial resource undergoes an inner life, when nothing warrants the attribution: injected latency and typing indicators that stand in for thinking, verbal hesitation, or claims of feeling and care. Distinct from clear and courteous communication, which is competence. The tests are HWF-14’s two verifiable standards — whether a reasonable person, knowing what was disclosed, would form a false belief from the signal, and whether recorded optimization objectives targeted emotional dependency or vulnerability. Prohibited even where the system has disclosed that it is software.

**G-31 · Context boundary record** — The recorded artifact behind every context restriction (HWF-35): what is withheld from an artificial resource, on which of the two legitimate grounds — protecting the information, or preventing measurable degradation of the decision through anchoring, contamination or saturation — decided by whom, and versioned like any other authority. It differs from an omission by exactly one property: it is written. An unrecorded restriction is a gap, and responsibility for whatever it degrades lies with whoever withheld the context.

**G-32 · Digital zombie** — An AI Employee whose position has lost its justification but which keeps operating with credentials, data access and standing authority intact. It is what accumulates when nothing forces the existence question: even the weak triggers that sometimes prune human positions — a salary line under budget review, a resignation forcing a backfill decision — do not exist for a resource that costs little and never resigns. Prevented by the re-justification cadence of HWF-63; dismantled through lifecycle retirement, with offboarding and revocation.

**G-33 · Resource neutrality** — The allocation discipline of deciding who fills a position — human or artificial — without a prior preference for either, judging only fit, outcome, cost, risk and control. It is a discipline, not a moral stance, and it is bounded: neutrality begins only after the constraints of HWF-01 — rights, dignity, safety, meaningful human agency, accessibility, labor protections — are satisfied. Cited without its boundary, the term is being misused.

**G-34 · Unit of conformance** — The thing a conformance claim can be about: one deployment — one role, one role-contract version, one accountable owner, one assessment period with an expiry. Products, platforms, models and organizations in the abstract cannot conform, whatever their marketing says; a vendor may only claim that it enables conformant deployments (HWF-71).

**G-35 · Risk class** — One of five tiers — Prohibited, Critical, High, Moderate, Low — assigned to an AI Employee position by judging inherent risk across seven factors, before controls. Controls lower residual risk, never the class (HWF-51). Declared in every conformance claim (HWF-71); from Critical upward every action terminates in a final human decision, and a Prohibited use has no conformant configuration at all.

**G-36 · Reserved decision** — A decision subject an artificial resource may never take alone, whatever the position’s assessed risk class: material effects on employment, health and safety, credit and essential services, legal rights, use of force, or vulnerable people (HWF-02). The resource may analyze, draft and recommend; a human decides — and only counts as deciding while able to restate the case and decide otherwise. Approval at a throughput that forecloses understanding is a signature, not a decision.

**G-37 · Human impact assessment** — The recorded assessment HWF-03 requires before any material transformation of a position: who is affected; changes to work, autonomy and surveillance; deskilling; exception load; discrimination and accessibility; displacement and headcount; training and reassignment; effects on customers and third parties. Completed, informed and consulted before the transition begins — not after. It is not obliged to be favorable; it is obliged to be honest. Distinct from the risk-class impact assessment of HWF-51, which protects the operation: this one protects the people.

**G-38 · Affected person** — Anyone on whom an AI Employee’s action has material effect — customer, worker or third party. Holder of the seven rights of HWF-04: disclosure of artificial involvement, the responsible organization, human review with authority to change the outcome, data correction, contest, an actionable explanation of determinants, and redress. The explanation reaches them through human judgment: confidential material may be withheld with a recorded reason, and the duty to explain is never canceled.

**G-39 · Moral crumple zone** — The human placed at the end of an automated process who absorbs the blame for failures whose determinants lie upstream in policy, design, tooling or deployment. Named by Elish, who showed that blame in automated systems lands on the nearest human while control sat elsewhere. Prohibited by HWF-23: blame follows the determinants (HWF-41), not the proximity, and the supervising human answers only for what they controlled.

**G-40 · Derived inference** — Data the deployment manufactures about a person rather than collects from them: a probability of financial distress, an inferred health condition, a predicted intent. Governed under HWF-42 as if collected — purpose, basis, minimization, deletion — and often more sensitive than anything the person actually provided. An inference the person never handed over is still their data.

**G-41 · Correlated failure** — The failure mode of model monoculture. Human teams do not fail independently either, but diversity of experience and judgment tends to distribute some blind spots; instances sharing a model, vendor, context or configuration concentrate them, and can fail in the same way at the same time. The precedent is common-cause failure, long known to reliability engineering and continuity planning; what is new is the speed, reach and opacity with which it propagates through an artificial workforce. Mitigated by diversity of models and vendors, fallback resources and succession planning; named as a validation item for AI teams by HWF-52.

**G-42 · Entity (as against interface)** — What separates an employee — human or artificial — from a channel. An interface is a surface through which something is reached; an entity is a party that others deal with. An AI Employee holds conversations with clients, suppliers and colleagues, and can state where the organization it belongs to stands. Nobody is half a counterparty, which is why an occupant is human or artificial and never both: splitting work between two occupants produces two positions, not one position of a third kind.

## Governance

### Disclosure

This standard was written by Master Joe Phillips, who also builds AIEmpl.com, a commercial platform in this category. That is a real conflict of interest and it is stated here rather than discovered later. He also wrote the companion book, whose digital editions are given away: it explains this standard and does not extend it.

Three commitments follow from it, and all three are structural rather than promised. This standard does not certify products and does not score vendors, and under HWF-71 the author’s platform can never claim conformance — a deployment can, a platform cannot. The license is irrevocable, so the text cannot be pulled back behind a product. And the normative text moves without the author’s vote: the Editor drafts and argues, and does not vote. That independence is designed into the structure and comes into force in stages — editorial custody until the freeze on September 1, 2026 at 00:00 UTC, an immovable text from that date except through the process described here, and collegiate authority once a Board is seated with quorum. Designed today; achieved when the seats are filled.

A standard authored by a vendor and judged by nobody is a specification sheet with a formal name. The mechanism below is what is meant to keep this one from becoming that.

### Editor and Review Board

> The Editor writes, proposes and decides everything editorial. From the freeze, the normative text changes only by vote of the Board — and the Editor has a voice, not a vote. Until the freeze, the Candidate is a working draft under the Editor’s custody, and its drafting history is public, commit by commit, in the repository.

That single rule is what makes the disclosure above worth anything: the author holds the largest commercial interest in the room. Until the freeze he holds editorial custody, and says so; from the freeze he cannot move the standard — only persuade the people who will be able to, once the Board exists.

### The nine seats

| # | Seat | Protects | Holder |
| --- | --- | --- | --- |
| 1 | HR / People | That the HR-to-AI translation is not a caricature, and that the Human and Adapted layers of the matrix stay honest. | *Open* |
| 2 | Operations or finance executive who has deployed AI | That the standard is something a real company can actually comply with, not only something elegant to read. | *Open* |
| 3 | AI engineering | That the nine properties and the controls are technically honest and implementable. | *Open* |
| 4 | Security and risk | Least privilege, auditability, incident handling and the kill switch: the governance domain. | *Open* |
| 5 | Legal and labor | The boundary that says this is not an employee in any legal sense. It is the line where the category is most likely to burn. | *Open* |
| 6 | Workers’ representation | The floor of HWF-02 and HWF-03: that reserved decisions stay human and that impact assessments consult workers before the transformation, not after it. Works-council or union floor experience, not a theorist. | *Open* |
| 7 | Affected persons and civil society | That the rights of HWF-04 work as mechanisms rather than words: explanation, correction, contest and redress. Someone who operates recourse in the real world — ombudsman, consumer protection, appeals practice. | *Open* |
| 8 | Accessibility and inclusion | The accessibility constraint of HWF-01 and the vulnerable-people factor of HWF-51 and HWF-02. A practitioner of accessible systems, not an auditor of documents. | *Open* |
| 9 | Independent academic | The evidence base: that the standard’s claims survive contact with research, and that its sources stay honest. Organizational theory, labor economics or human-computer interaction, with no commercial stake in the category. | *Open* |

1. A majority of the Board must be people currently operating in the field — deploying, building or governing hybrid workforces. Skin in the game is a requirement for this Board, not a disqualifier: what disqualifies is hidden interest, never interest.
2. Commercial interest in the category — the author’s competitors included — may hold at most two of the nine seats, each with a published disclosure and recusal from any vote where the interest is direct — directness judged by the non-conflicted seats, never by the member. The Board is neither a vendor lobby nor a vendor blacklist.
3. Compensated transparently or not at all: an identical, published honorarium from disclosed sources. Unpaid seats select for people who can afford to donate time; hidden pay selects for people someone else is paying. Both are capture — transparency is the control.
4. Each member publishes their own disclosure, exactly as the Editor does.
5. Twelve-month renewable terms, so that leaving is ordinary rather than a scandal.
6. A vote is valid only with two thirds of the filled seats participating, and no vote is valid with fewer than five seats filled. Normative changes carry with a majority of all seats, not of those present, and ratification of a version requires two thirds of all seats. Minutes are published, and a minority opinion is published in full in the changelog — a dissent the public can read is worth more than a unanimity it cannot check.
7. Seats are filled by public nomination: candidacies and their disclosures are published for at least thirty days before seating. Until five seats are filled, an unopposed published candidacy is seated after its thirty days; from the sixth seat on, seating requires majority approval of the sitting Board. The Editor may propose candidates; the Editor appoints nobody.
8. Note and doctrine revisions made between versions are tabled at each Board meeting, and any of them may be reversed by simple majority. The notes are the Editor’s channel; the Board holds the door.
9. The Editor serves until resignation or removal by two thirds of all seats, and the Board appoints the successor. The founder wrote the standard; the office outlives him.

### Amendment process

1. Anyone proposes a change, publicly, with the reasoning and the case that motivated it.
2. The Editor responds within ninety days: a drafted amendment or a reasoned decline, both published.
3. A decline is not a veto. Any three Board members may sponsor a proposal directly to consultation and vote, without an Editor draft.
4. Public consultation runs for at least thirty days before any vote on normative text.
5. The Board votes under the Board rules: normative changes carry with a majority of all seats — and the Editor has a voice, not a vote.
6. The changelog records what changed, who proposed it, the vote count, and any minority opinion in full.

### Current status

Candidate 1.0 is a proposal by a single author. The Standard Review Board is forming and every one of the nine seats is currently open. Publishing that honestly is a deliberate choice: a standard that admits to being a proposal is more credible than one that implies an institution it does not yet have. And it stays a candidate until a Board constituted under these rules ratifies it as version 1.0 — the author cannot ratify his own standard. If one of the nine seats describes you, the invitation is open.

### The freeze

Candidate 1.0 froze on September 1, 2026 at 00:00 UTC with no Board seated — as the rule said it would, seated or not. From that moment the author stops editing the normative text — not "stops except for small corrections", but stops. A standard whose author keeps quietly patching it is not a standard; it is a personal document with pretensions. What follows is the mechanism that makes the freeze checkable rather than rhetorical, and below it the record of the one revision issued since.

**What identifies the frozen version.** A date and time in UTC, a version label, and a content hash of the canonical machine-readable edition, all published on this page. Release of the companion book is not the trigger: a book carries different dates by format and by market, and a normative event cannot depend on a retailer.

**Errata, which never change an obligation.** Typographical slips, broken links, mistranslations and factual errors in notes are recorded in a public errata register with their date. The frozen text is not edited: the register sits beside it. Anything that would alter what a deployment must do is not an erratum — it is an amendment, and amendments wait for the Board.

**Emergency deprecation.** If a defect in the frozen text would cause material harm — a security, legal or safety error — the Editor may deprecate the whole version, publicly and with reasons, and mark it as not to be used for new conformance claims. Deprecation is the only unilateral lever, and it is blunt on purpose: it can withdraw a version, never rewrite one. Surgical unilateral edits are exactly what the freeze exists to prevent.

**If the Board never reaches quorum.** The frozen text stays valid and citable, and stays Candidate. It does not silently become 1.0 through the passage of time, and it does not revert to the author. A standard nobody ratified is still a usable specification — it simply never earns the word that says a body examined it.

The asymmetry is deliberate. Withdrawing a version needs one person and a public reason; changing one needs a Board. Making it easy to stop and hard to alter is what keeps the freeze from being a pose.

### Open findings — held for the Board

Findings from the Candidate 1.0 adversarial review that survived verification in part but were not amended by the Editor alone. They are published rather than filed, because a standard that hides its known gaps is marketing: each is Board agenda, and each stays listed here until a version resolves it.

1. A legal floor for the risk classification: uses prohibited or enumerated as high-risk by applicable law should enter the corresponding tier as a floor the seven factors may raise but never lower.
2. Independent balancing of explanation withholdings: where data-protection law applies, trade-secret material goes to an authority or court for balancing (CJEU C-203/22) — the recorded withholding of HWF-04 is this standard’s mechanism, not a discharge of that law.
3. A materiality test with worked examples for the reserved subjects of HWF-02, so that routine operations touching reserved accounts are distinguishable from reserved decisions.
4. An intake clause: a complaint channel, a response window and a severity-graded incident process with a named owner, as preconditions of go-live — the rights of HWF-04 need a door to knock on.
5. A defined source for the escalation-quality metrics: a sampled review of non-escalated cases with a minimum rate and a named reviewer set by risk class, so that zero reported misses means something.
6. Cross-references to statutory impact assessments — EU AI Act Article 27’s fundamental-rights assessment and analogous regimes — stating expressly that HWF-03 does not discharge them.
7. Missed Escalation Rate normalized by audit sampling depth, reported as a pair, with severity grading by a party independent of the review budget it justifies.
8. Aggregate-only computation of scorecard metrics that touch named humans, with individual-level access gated under HWF-42’s new-purpose test.

## License

Creative Commons Attribution-ShareAlike 4.0 International (`CC-BY-SA-4.0`) — https://creativecommons.org/licenses/by-sa/4.0/

You may quote, embed, teach, translate and commercially use this material with attribution. A modified version must carry the same license. The names "Hybrid Workforce Standard", "HybridWF", "HWF", "WRM" and "HWFA" (formerly HWFS) and the HWF-/G- identifier schemes are reserved and are not licensed: you may state that your work conforms to the standard, but you may not publish a modified version under the same name, operate a certification or badge program invoking it, or reuse its clause identifiers for altered text — a modified version renumbers its clauses.

## Sources

### Market and vendors

| ID | Source |
| --- | --- |
| S1 | [Lattice — “Leading the Way in Responsible AI Employment” (9 Jul 2024)](https://lattice.com/blog/leading-the-way-in-responsible-ai-employment) |
| S2 | [SHRM — Lattice scraps plans to treat AI bots as employees after backlash (Jul 2024)](https://www.shrm.org/topics-tools/news/technology/lattice-scraps-plans-to-treat-ai-bots-as-employees-after-backlash) |
| S3 | [Salesforce — What Is Digital Labor? / Agentforce positioning](https://www.salesforce.com/agentforce/digital-labor/) |
| S4 | [Microsoft — Six core capabilities to scale agent adoption in 2026](https://www.microsoft.com/en-us/microsoft-copilot/blog/copilot-studio/6-core-capabilities-to-scale-agent-adoption-in-2026/) |
| S5 | [Microsoft — Introducing Microsoft Scout / Autopilots, always-on agents (2 Jun 2026)](https://www.microsoft.com/en-us/microsoft-365/blog/2026/06/02/introducing-microsoft-scout-your-always-on-personal-agent/) |
| S6 | [ianai — AI Employee / role-based authority and persistent digital worker](https://www.ianai.co/) |
| S7 | [AIEmployee.com — AI Employee platform](https://home.aiemployee.com/) |
| S8 | [GIZIN — AI collaboration / AI Employees](https://gizin.co.jp/) |

### Standards and institutions

| ID | Source |
| --- | --- |
| S9 | [ISO 30414:2025 — Human resource management, HCRD](https://www.iso.org/standard/30414) |
| S10 | [ISO/TC 260 — Human resource management standards catalogue](https://www.iso.org/committee/628737/x/catalogue/p/1/u/0/w/0/d/0/) |
| S11 | [CIPD — Performance Management factsheet](https://www.cipd.org/en/knowledge/factsheets/performance-factsheet/) |
| S12 | [CIPD — Line managers’ role in supporting the people profession](https://www.cipd.org/uk/knowledge/factsheets/line-managers-factsheet/) |
| S13 | [ILO — Safe and healthy working environment as a fundamental principle and right](https://www.ilo.org/topics-and-sectors/safety-and-health-work/safe-and-healthy-working-environment-fundamental-principle-and-right-work) |
| S14 | [NIST — AI Risk Management Framework](https://www.nist.gov/itl/ai-risk-management-framework) |
| S15 | [NIST — AI RMF Playbook](https://airc.nist.gov/airmf-resources/playbook/) |
| S24 | [OECD — AI Principles (human-centred values: dignity, autonomy, social justice, labour rights)](https://oecd.ai/en/ai-principles) |
| S25 | [EU — Artificial Intelligence Act: regulatory framework on AI (risk-based approach)](https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai) |
| S26 | [EU — GDPR Article 22: automated individual decision-making](https://gdpr-info.eu/art-22-gdpr/) |
| S27 | [EU — AI Act Article 26: obligations of deployers of high-risk AI systems (worker information)](https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-26) |
| S28 | [EU — AI Act Article 86: right to explanation of individual decision-making](https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-86) |
| S30 | [EU — AI Act Article 50: transparency obligations for AI interacting with people (Commission FAQ)](https://digital-strategy.ec.europa.eu/en/faqs/transparency-obligations-under-article-50-ai-act) |
| S31 | [EU — GDPR Article 5: principles relating to processing of personal data](https://gdpr-info.eu/art-5-gdpr/) |
| S32 | [ISO/IEC 42001 — Artificial intelligence management system](https://www.iso.org/standard/42001) |
| S33 | [ISO/IEC 42005 — AI system impact assessment](https://www.iso.org/standard/42005) |

### Academic signals

| ID | Source |
| --- | --- |
| S16 | [Johnston et al. — The Shift to Agentic AI: Evidence from Codex (2026)](https://arxiv.org/abs/2606.26959) |
| S17 | [Liu — The Organizational Behavior of Agentic AI (2026)](https://arxiv.org/abs/2606.30986) |
| S18 | [Agentic Business Process Management: A Research Manifesto (2026)](https://arxiv.org/html/2603.18916v3) |
| S19 | [Alenezi — Human-AI Collaboration and the Transformation of Software Engineering Work (2026)](https://arxiv.org/abs/2606.03394) |
| S20 | [Intelligent AI Delegation (2026)](https://arxiv.org/html/2602.11865v1) |
| S29 | [Elish — Moral Crumple Zones: Cautionary Tales in Human-Robot Interaction (2019)](https://estsjournal.org/index.php/ests/article/view/260) |

### Books and competing works

| ID | Source |
| --- | --- |
| S21 | [GIZIN — AI Employee Starter Book](https://store.gizin.co.jp/en/ai-employee-book) |
| S22 | [GIZIN — AI Employee Master Book](https://store.gizin.co.jp/en/ai-employee-master) |
| S23 | [B. Jaiswal — AI EMPLOYEE: How One Person Does the Work of Ten (Jun 2026)](https://play.google.com/store/books/details/B_JAISWAL_AI_EMPLOYEE?id=0w3uEQAAQBAJ) |
| S34 | [M. J. Phillips — AI Employee: How to Design, Onboard, and Lead the New Hybrid Workforce (Sep 2026) — the companion to this standard](https://masterjoephillips.com/libros/ai-employee-en.pdf) |
| S35 | [M. J. Phillips — Empleado IA (Ago 2026) — el acompañante de este estándar](https://masterjoephillips.com/libros/empleado-ia-es.pdf) |

### Methodological limits

1. Market research represents a snapshot as of August 9, 2026. Product positioning and capabilities change quickly.
2. Vendor claims are read as product positioning, not as independent validation of performance. That includes the author’s own platform.
3. The 120-principle matrix is an original synthesis drawn from HR, management, workforce analytics, security and risk. It does not attribute those principles to any single organization.
4. ISO 30414:2025 and the ISO/TC 260 catalog are used as evidence that human resource management comprises multiple measurable, standardizable areas; CIPD for performance and line management; ILO for the boundaries of human rights; NIST for AI risk governance. None of these bodies endorses this standard.
5. The arXiv papers are preprints unless otherwise stated, and are used as signals of emerging research rather than settled scientific consensus.
6. The definition, the nine-property test, the maturity model, the transition playbooks, the HWFA and this standard itself are conceptual proposals developed in this work. They are not official standards of ISO, NIST, the ILO or any cited vendor.

### Conceptual lineage

- Henri Fayol — unity of command, authority and responsibility, division of labor.
- Peter Drucker — management by objectives, effectiveness and managerial responsibility.
- W. Edwards Deming — measurement, system, variation and continuous improvement.
- Dave Ulrich and the modern tradition of human resource management — talent design and organizational capability.
- Contemporary practice in performance management, organizational design, RBAC, least privilege, segregation of duties and enterprise risk management.

## Changelog

### Candidate 1.0.1 · 2026-09-12 · Editorial revision of the English edition — issued by the Editor, pending Board ratification

- Seven clauses were amended for vocabulary, not for meaning: “post” becomes “position” throughout the English edition — HWF-02, 03, 23, 41, 51, 61 and 63 in clause text, and the glossary, the WRM matrix and the HWFA alongside — and “dismissal” becomes “termination” in HWF-02. “Post” for a job is British usage that a US reader parses first as something published; “position” carries the same sense and leaves intact the distinction this standard depends on, between the position (the slot) and the role (the function). The Spanish edition is unaffected: «puesto» and «rol» already carried that distinction. Nothing a conforming deployment must do has changed.
- The English edition is now written in US spelling — 176 words in the canonical text. The change is editorial: no clause changed what a conforming deployment must do. Proper nouns and quoted instruments keep the spelling of their source, so the OECD principles cited here still read as the OECD wrote them. The convention is stated in “Reading this standard”, so later amendments do not drift back into a second variant.
- One erratum travels with this revision. Candidate 1.0 described its own glossary as forty-one terms; it holds forty-two, G-01 through G-42 with no gaps, and it already held forty-two at the freeze. The count is corrected here and the frozen edition keeps the wrong number, because a frozen text is not edited — the correction sits beside it. It appears in a note, never in clause text, and no obligation depends on it.
- This revision was issued by the Editor without a Board, because after the freeze clause text changes require a vote and none of the nine seats is filled. It is recorded here, in the frozen record and in the commit history rather than applied quietly: the freeze exists to stop an author from patching his own text in silence, and publishing the breach is the only version of this that leaves the rule standing. Candidate 1.0 remains frozen and citable at its permanent address, hash published. A Board, once seated, may ratify, amend or reverse this revision.

### Candidate 1.0 · 2026-08-12 · Frozen September 1, 2026 at 00:00 UTC — pending Board ratification

- Candidate 1.0: twenty-seven normative clauses in eight blocks — 0x human foundation to 7x conformance — plus the nine-property test, the WRM framework with its 120-principle matrix, the maturity model, the HWFA allocation instrument, the five-tier risk classification, the Hybrid Workforce Manager role, the transition playbooks and a forty-two-term glossary. Published bilingually, with the complete text as one machine-readable file per language.
- Certification is deliberately outside the scope and does not return: the author holds a commercial interest in the category, so the standard scores no products, issues no seals, and makes conformance a self-declaration anyone can verify or refute — public scrutiny, structure instead of trust.
- The front matter carries the preamble — the document’s own declaration — the author’s signed motivation and strategic objective, the thesis corrected during drafting so that it ends where every chain ends (an AI Employee holds a role; a human answers for it), and the invariant formula: the AI executes, the organization answers, a human governs.
- Governance was reformed before any seat was filled: nine seats with a practitioner majority and a single academic; commercial interest capped at two seats, with disclosure and recusal judged by the non-conflicted; a transparent, identical, published honorarium; public nomination in which the Editor proposes and appoints nobody; two-thirds quorum over filled seats and normative majorities counted over all seats; Board reversal of note revisions; Editor succession and removal — and the deepest rule: the Editor has a voice, not a vote. The publication remains a candidate until a Board constituted under these rules ratifies it; the author cannot ratify his own standard.
- The allocation instrument is the HWFA — formerly the Fit Score, renamed because an instrument that deliberately refuses to produce a number should not be called a Score. It runs in three stages embodying HWF-01’s order (eligibility, then risk, then economics), can answer deterministic automation — you do not need an AI Employee — and returns an argument rather than a number, because a score would let a decision already taken be laundered through arithmetic.
- Clause numbers carry the architecture: the first digit names the block, block 0 is the human foundation, and HWF-01 is the supreme clause — number and rank aligned. A new clause takes the next free number in its block’s decade; a block that reaches nine clauses is asking to be split at a major version, not extended.
- Candidate 1.0 was reviewed adversarially before any Board existed: twenty external recommendations and a five-advisor council with anonymous peer refutation — forty findings. Everything confirmed was amended; seven attacks died against existing text; and eight findings confirmed in part are published as open findings, Board agenda until a version resolves them — because a standard that hides its known gaps is marketing. The per-clause considerations that survived this process are recorded below.

From the freeze, clause text changes require a version bump and a Board vote, and every frozen version stays at its own permanent address so that a citation made then still resolves in five years. Until the freeze, the Candidate is a working draft: its text may be amended under editorial custody, and the authoritative record of every amendment — date, prior text, new text and reason — is the public commit history of the repository. Notes, examples and commentary may be corrected between versions without amending the standard. The first digit of a clause number names its block, so a new clause takes the next free number inside its block’s decade — thematic order and citation stability no longer trade against each other. A block that reaches nine clauses is not asking for a tenth; it is asking to be split, and splitting blocks is major-version work for the Board. Within a version, changelog entries are drafting history in reverse chronological order: where several touch the same clause, the newest account governs and the older ones stand as record.

### The frozen record

What identifies a frozen version is a date and time in UTC, a version label and a content hash of the canonical machine-readable edition. Here they are. The hash covers the file exactly as it stood at the freeze: recompute it against the archived copy and it must match, or this page is wrong.

- **Candidate 1.0** — 2026-09-01T00:00:00Z
  - https://hybridwf.com/1.0/standard.md (English) — sha256 `a88007a1b01851a5236d04abccf174b041023549d5d3cb1fe950e2c1f2161944`
  - https://hybridwf.com/1.0/estandar.md (Spanish) — sha256 `04ef2c5e1bb9610841cd507ff37abc86ee8059424578c0d96006a4d865897662`

### The revision issued after the freeze

Candidate 1.0.1 is an editorial revision of the English edition, issued after the freeze. It changes terminology and spelling and no obligation: “post” became “position”, “dismissal” became “termination”, and British spelling became US spelling. Fourteen of the twenty-seven clauses have altered citable text — seven for vocabulary, seven for spelling alone — and the archived 1.0 below is what they are checkable against. Under the rule above, clause text changes after the freeze require a Board vote, and there is no Board to hold one. The Editor issued this revision alone, and records it here rather than editing quietly — quiet patching is the exact failure the freeze was written to prevent, and a rule broken in the open is still a rule. Candidate 1.0 stays frozen, citable and archived at its own address, and the Spanish edition it froze with is unchanged. A Board, once seated, may ratify this revision, amend it or reverse it.

### Considerations by clause

One entry per clause: the considerations that produced it, kept after the drafting noise was stripped. This is why each clause says what it says — the part of the record a future Board will actually need.

**0 · Human foundation**

- **HWF-01** — People are ends; software is a means. Resource neutrality is an allocation discipline, not a moral stance, so the constraints are lexically prior: cost optimizes inside the space that rights, dignity, safety, agency, accessibility and labor protections leave open, and never trades against them. The clause does not promise that displacement will not happen; it governs the terms, as labor law did with the tractor — and it takes precedence over every other clause.
- **HWF-02** — Reserved decisions are a floor by subject matter, because classification is judgment and judgment can be motivated. Artificial participation — analysis, drafting, recommendation — stays legal; the decision does not. The test of deciding is operational: a human who cannot restate the case and decide otherwise is signing, not deciding. A reserved decision is Critical by definition.
- **HWF-03** — No material transformation without a recorded human impact assessment, consulted before, not after. Its least-volunteered dimensions: deskilling — automate the junior work and stop producing seniors — and the exception load left to humans when automation absorbs the easy cases. Consultation is not consent, and no favorable conclusion is required: an assessment obliged to bless the transition would be theater.
- **HWF-04** — Affected persons hold seven rights against the deployment. The explanation owed is operational evidence — policy, data, tools, authority — never a reasoning transcript: operational evidence is disputable, and nobody can contest a vibe. Release runs through human judgment, every withholding is recorded, and confidentiality narrows an explanation but never cancels the duty to give one the person can act on.

**1 · The category**

- **HWF-11** — A role, not a persona: the position exists before its occupant, with result, authority and measurement. Before does not mean frozen — occupants reshape positions legitimately, and every reshaping is declared, because the declared position is the interface: a human colleague reads an undeclared role from the corridor; an artificial one can only read the graph.
- **HWF-12** — The test is conjunctive in both directions. Missing one property, the system is an agent — respectable, but not an AI Employee. Exhibiting all nine in operation, it is one whatever it is called, with the burden of non-qualification on the deployer: an unwritten role contract is a governance failure, not a category exit. And breach stays inside the category — a definition that expelled violators would leave the standard with nothing to bind.
- **HWF-13** — The status clause practices epistemic modesty: no personhood, employment relationship, consciousness or moral status is recognized — and none is denied. Non-recognition in the posture of corporate law. Every clause holds however the philosophy of mind is one day resolved, because none depends on the answer.
- **HWF-14** — Deception is prohibited by observable results, not intentions, because intent is not auditable: passing as human; claiming feelings; signals reasonably capable of inducing false belief; optimization against recorded objectives for emotional dependency; concealed artificial involvement. Disclosure at the outset, renewed at material points. Courtesy and personalization stay legal — nothing here requires an AI Employee to write badly.

**2 · Accountability**

- **HWF-21** — Exactly one accountable owner — primary, not exclusive. Supervision may be delegated, even to another AI Employee; accountability may not, because answering for an outcome requires the capacity to bear a consequence. System, data, security, vendor and director obligations survive intact, and a governance body qualifies as terminus only with an identified chair, stated decision rules and emergency capacity.
- **HWF-22** — Chains may be deep, but they must be traversable, observable and interruptible without passing through themselves: an accountable party who must ask the pyramid for permission holds a request, not control. Scale grows only against tooling — a thousand resources without instruments is an organizational chart, not accountability.
- **HWF-23** — Ownership is a resourced capability, not a name in a field: competence, authority, time for the span, evidence access, independence from the pressures that own the outcome, the power to suspend, training against automation bias. The kill switch is exercised on a stated cadence — never pulled is decoration — and the crumple zone is prohibited: blame follows the determinants, not the proximity.

**3 · Authority and operational control**

- **HWF-31** — Authority must be explicit, limited and revocable — written before the resource operates, never inferred afterward from what it happened to do.
- **HWF-32** — Least privilege, because access is capability and risk surface at once: more access is not more competence; it is a larger blast radius.
- **HWF-33** — High-risk actions support human approval, with proportionality and separation of duties — whoever initiates does not approve. What counts as high-risk resolves against the classification of HWF-51, not against taste.
- **HWF-34** — Escalate rather than improvise: a convincing answer where there should have been a raised doubt is the most dangerous failure. Every exception needs a destination — and no metric may punish the journey, because a system rewarded for fewer escalations learns silence.
- **HWF-35** — Withholding context is a legitimate design decision in both directions — protecting the information, or preventing measurable degradation of the decision (anchoring, contamination, saturation) — and every restriction is a recorded, versioned context boundary record. Responsibility for a decision degraded by withheld context lies with whoever withheld it.

**4 · Evidence and data**

- **HWF-41** — Audit reconstructs the determinants of a decision — policy, knowledge, tool results, authority, versions — not only its outcome, because a what-only audit leaves five different failures looking identical. A model’s account of its own reasoning may support the reconstruction and never substitutes for it. Materiality scales by risk class: log correlation against the version manifest is conformant for Low and Moderate positions.
- **HWF-42** — Memory is one data system among several: inputs, outputs, tool results and derived inferences are governed whole — purpose, basis, minimization, transfers, vendor use including training, isolation, verifiable deletion. An inference the person never handed over is still their data. And the audit trail is itself such a system, governed with the same severity as the operation it audits: mining it to score employees is a new purpose requiring its own basis.
- **HWF-43** — An identifiable version of model, policies, tools and knowledge — because without it, neither the reconstruction of HWF-41 nor the revalidation of HWF-52 has an object.
- **HWF-44** — Performance is measured by outcomes, quality, risk and cost — never activity, hours, tokens or message volume: speed can make motion look like value.

**5 · Risk and validation**

- **HWF-51** — Five tiers judged on inherent risk across seven factors — never cost of error alone, because a cheap error at scale against vulnerable people is not a cheap error. Controls lower the residual, never the class: a guardrail cannot buy a better tier. Critical always ends in a final human decision; Prohibited cannot be made conformant by any control. Interoperates with risk-based law without claiming equivalence.
- **HWF-52** — A version is a record, not a proof: every material change revalidates before operating, at class-scaled depth — the playbook gates birth; this clause keeps the transition earned. Deterministic automation is untouched because the category excludes it. Teams add systemic risks, correlated failure above all: a hundred humans err a hundred different ways; a hundred instances of one model err identically and at once.

**6 · Lifecycle**

- **HWF-61** — The commonest defect of a role contract is not bad drafting but abandonment: review carries a twelve-month ceiling, and every clocked obligation lives in one governance calendar with one named owner. Independent monitoring against the contract is the primary control; the resource’s self-report supplements it — a system whose configuration is the problem shares the blind spot. Changing the contract is always a human decision.
- **HWF-62** — Every transition is evaluable against a baseline recorded before the change — otherwise the organization celebrates an improvement it never made — and rollback criteria are written before the results are known, because criteria written after are justification.
- **HWF-63** — No position outlives its justification: existence is re-justified on cadence, prior to and separate from performance, because meeting every KPI in a position nobody needs is the usual anaesthetic. The weak triggers that sometimes prune human positions — a salary line, a resignation — do not exist for artificial ones, which is what accumulates digital zombies. A lapsed review restricts or suspends in proportion; retirement follows a failed justification, never a missed calendar.
- **HWF-64** — Offboarding is as important as onboarding and almost always skipped: revoke, disable, rotate, transfer, preserve evidence — a retired position whose access survives it is risk surface with no return.

**7 · Conformance**

- **HWF-71** — Conformance belongs to a deployment — never a product, platform or organization in the abstract, and the first platform bound is the author’s own. Nine published fields; full-scope assessment or the claim is styled partial; twelve-month maximum validity; the enabling claim requires a live, publicly linked customer declaration. A published declaration is an actionable commercial representation: substantiate before publishing, withdraw promptly on lapse.
