Normative text
The Hybrid Workforce Standard
Twenty-seven clauses that separate a governable work resource from a commercial metaphor. Conformance is self-declared: no product is scored here and no seal is issued.
Preamble
AI exists in the service of legitimate human purposes. Efficiency never justifies degrading human dignity, agency, rights or capability. All artificial authority remains limited, contestable, reversible and subordinate to real human accountability.
This standard is a declaration of the organization’s independence from the anarchy of the prompt. By demanding a role contract, it forces leaders to think before they automate.
This standard is the first step toward closing the era of “toy AI” and opening the era of the AI Employee. As it is adopted, it will move companies from a software development model, centered on the tool, to a social architecture model, centered on human accountability.
Eight blocks, one architecture
The first digit of every clause identifier names its block; the second is its place within it. A short standard is easier to hold in memory when it is also easy to hold in view.
| Block | Clauses |
|---|---|
| 0 · Human foundation | HWF-01–04 |
| 1 · The category | HWF-11–14 |
| 2 · Accountability | HWF-21–23 |
| 3 · Authority and operational control | HWF-31–35 |
| 4 · Evidence and data | HWF-41–44 |
| 5 · Risk and validation | HWF-51–52 |
| 6 · Lifecycle | HWF-61–64 |
| 7 · Conformance | HWF-71 |
0 · Human foundation
- HWF-01
People are ends; software is a means. Optimization of cost, speed or capacity must never override human rights, dignity, safety, meaningful human agency, accessibility or applicable labor protections. Resource neutrality begins only after those constraints are satisfied. This clause takes precedence over every other clause in this standard.
The engine of the hybrid organization is cost, and this standard does not pretend otherwise: displacement will happen, as it happened with the tractor, and a document that promised to prevent it would be ignored and would deserve to be. What a standard can do is what labor law did — govern the terms. This clause does not prohibit displacement: work moved lawfully, with dignity, within applicable protections and through the transition playbooks is still work moved. It draws the line between displacement and abuse, by making the constraints lexically prior: cost, speed and capacity optimize inside the space that rights, dignity, safety, meaningful human agency, accessibility and labor protections leave open, and never trade against them. Two provisions already leaned this way — the Hybrid Workforce Manager’s anti-KPI refuses to measure the role by humans replaced, and the HWFA hard gates cap allocation regardless of the economics. This clause names the hierarchy they were obeying. Its number is not its rank: it binds every other clause, and a conflict with any of them resolves in its favor. The lineage is explicit: the OECD’s human-centered AI principles place dignity, autonomy, social justice and labor rights inside the definition of trustworthy AI, not alongside it.
Built against S24 OECD — AI Principles (human-centred values: dignity, autonomy, social justice, labour rights)
- HWF-02
Certain decisions are reserved. An artificial resource must never be the sole decider in matters with material effect on hiring, termination, discipline or compensation; on health and safety; on credit, insurance or access to essential services; on legal rights; on any use of force; or on the treatment of vulnerable people. A reserved decision is Critical by definition, whatever the assessed class of the position. Reservation does not exclude artificial participation — analysis, drafting and recommendation may be delegated. The decision itself may not, and an approval by a human who cannot restate the case and decide otherwise is a signature, not a decision.
HWF-51 classifies by judgment, and judgment can be motivated: without a floor, an organization under cost pressure classifies termination decisions as Moderate and lets the queue decide. This list is the floor no assessment can lower — the subjects where being wrong lands on a person rather than on a ledger. The second half of the clause exists because human-in-the-loop degenerates by default: an approver facing two hundred recommendations a day, each pre-scored and pre-drafted, approves at a rate that makes understanding impossible, and automation bias does the rest. That is not oversight; it is the ceremony of oversight. The test of a real decision is operational: the human can reconstruct the determinants — HWF-41 exists to hand them the material — has the authority and the time to decide otherwise, and a divergent decision carries no penalty by default. Where approval throughput makes restating the case impossible, the organization has automated the decision and retained a human signature: responsibility lost rather than delegated, in HWF-21’s terms. The list interoperates with GDPR Article 22 and the EU AI Act’s human-oversight requirements in the same posture as the risk classification — designed to travel, without claiming legal equivalence.
Built against S26 EU — GDPR Article 22: automated individual decision-making · S25 EU — Artificial Intelligence Act: regulatory framework on AI (risk-based approach)
- HWF-03
No position may be materially transformed — automated, moved to or from assisted human, returned to a person, or retired — without a recorded human impact assessment, completed before the transition begins. The assessment must name who is affected and how: changes to work, autonomy and surveillance; the risk of deskilling; the intensified load on those who absorb the exceptions; discrimination and accessibility; displacement and headcount; training and reassignment; effects on customers and third parties. Affected workers and their representatives must be informed and consulted before the transformation, not after it. The assessment is not required to reach a favorable conclusion; it is required to name, measure and govern the consequences.
This is HWF-01 given an instrument. A hierarchy of constraints means little if nothing checks it at the moment it is tested, and the moment is the transition: the playbook as first written moved from baseline to handoff with people appearing once, as released capacity, in step ten. The assessment runs before step one. Two of its dimensions repay attention because nobody volunteers them. Deskilling is the quiet one: the organization that automates its junior work stops producing seniors, and discovers it the year the seniors leave. The exception load is the cruel one: automation absorbs the easy cases and leaves humans a stream of nothing but hard ones, then measures them against throughput set in the era of easy cases. Consultation is mandatory and is not consent: this standard grants no veto, and labor law in each jurisdiction may grant more — the clause is a floor, in the same posture toward EU AI Act Article 26 as the rest of the document, designed to travel without claiming legal equivalence. The closing sentence keeps HWF-01’s honesty: an assessment obliged to bless the transition would be theater, and consequences that are named, measured and governed are the difference between displacement and abuse.
Built against S27 EU — AI Act Article 26: obligations of deployers of high-risk AI systems (worker information) · S33 ISO/IEC 42005 — AI system impact assessment
- HWF-04
A person materially affected by an AI Employee’s action holds rights against the deployment: to know that an artificial system took part; to know which organization answers for it; to have the decision reviewed by a human with authority to change it; to correct the data it relied on; to contest it; to receive a comprehensible explanation of its determinants; and to obtain redress where the decision was wrong. The explanation owed is operational evidence — the policy applied, the data relied on, the tools consulted and the authority exercised — never a reasoning transcript, and it is released through human judgment: privileged or confidential material may be withheld, every withholding is recorded with its reason, and confidentiality may narrow an explanation but never cancels the duty to give one the person can act on.
Every clause before this one binds the organization inward; this one gives the person on the receiving end standing. It is cheap for a conformant deployment, because HWF-41 already obliges the organization to reconstruct these determinants for itself — the explanation is a translation of an artifact that must already exist, and an organization that finds these rights expensive is discovering that it was not conformant with HWF-41. A reasoning transcript is refused for the same reason HWF-41 refuses it as audit evidence, plus one: handed to an affected person, it is an unfalsifiable story wearing the authority of an explanation. Operational evidence is disputable — a person can correct a datum, contest a policy, challenge a tool result. An unverifiable narrative offers nothing that can be contested, and disputability is what turns the correction and contest rights from words into mechanisms. Review means review by a human with authority to change the outcome; anything less is the signature problem of HWF-02 again. The release runs through human judgment because both failure modes are real: published fraud thresholds are defeated fraud thresholds — adversarial exposure is a factor HWF-51 already names — and a request addressed to the AI Employee is answered through the organization, because “explain yourself” is also a prompt-extraction surface. The counter-lock keeps the exception from swallowing the right: withholding is HWF-35’s discipline faced outward — legitimate, owned, recorded, never silent — and the floor is an explanation the person can act on. Redress follows the law of the jurisdiction; the clause is a floor, interoperating with GDPR Articles 15 and 22(3) and EU AI Act Article 86 in the document’s standing posture.
Built against S28 EU — AI Act Article 86: right to explanation of individual decision-making · S26 EU — GDPR Article 22: automated individual decision-making
1 · The category
- HWF-11
An AI Employee must hold a defined role, not merely a persona or a system prompt.
The position exists before its occupant. A name, a tone of voice and a set of instructions describe a persona; a role states what result must be produced, with what authority, measured how. Before does not mean frozen: a position may be reshaped by whoever holds it — Taylor fixed the person to the box, this standard versions the box — and HWF-61 exists so that the reshaping happens as declared revision rather than tacit drift.
Built from original WRM doctrine.
- HWF-12
Not every agent qualifies as an AI Employee. The threshold is the category itself: the nine properties of the definition, exhibited in operation. The test works in both directions: a deployment that exhibits the nine properties in operation is an AI Employee whatever the organization calls it, and the burden of demonstrating non-qualification lies with the deployer. The properties are facts about the deployment, not paperwork — an unwritten role contract is a governance failure, not a category exit.
This clause is what makes the category worth anything. If the label applies to everything, it distinguishes nothing. An organization with twenty excellent agents and zero AI Employees has clarity rather than a problem — provided none of the twenty exhibits the nine properties in operation.
Built from original WRM doctrine.
- HWF-13
Humans and AI Employees may share an operational graph while retaining distinct status and rights. This standard recognizes no personhood, employment relationship, consciousness or moral status in an artificial system, and does not claim to settle what future systems may warrant: for present operational and legal purposes, an AI Employee is a non-human software system.
A shared org chart is an administrative convenience, not a claim about minds. Non-recognition is not denial: the clause takes the posture of corporate law, which grants and withholds legal status without pronouncing on metaphysics, and this standard asserts nothing about what an artificial system ultimately is or could become. It does not need to. Dignity, health, rest, labor rights and belonging are protected here as properties of persons — the thirteen exclusively human principles of the matrix — and every clause in this document holds however the philosophy of mind is one day resolved, because none of them depends on the answer. If that question ever acquires an answer that matters operationally, addressing it is work for a future version and its Board, not for silent drift in the present one.
Built against S1 Lattice — “Leading the Way in Responsible AI Employment” (9 Jul 2024) · S2 SHRM — Lattice scraps plans to treat AI bots as employees after backlash (Jul 2024)
- HWF-14
An AI identity must never deceive. The prohibitions are observable results, not intentions: passing as human; claiming feelings, suffering or personal experience; emitting signals reasonably capable of inducing a false belief about what the system is or undergoes; optimizing against recorded objectives for emotional dependency or the exploitation of vulnerability; and concealing artificial involvement at a material point. Disclosure happens at the outset and is renewed when the system assumes a material function. Courtesy, linguistic empathy and personalization remain legitimate so long as they assert no interiority.
The predecessor of this clause tested purpose: whether a behavior existed to suggest a mind with something at stake. The diagnosis behind that test survives; the test does not, because intent is poor audit material — nobody can depose the soul of a design decision, and a standard whose other clauses demand operational evidence cannot keep one whose proof is mind-reading. Two verifiable standards replace it. The effect standard is objective: would a reasonable person, knowing what has been disclosed, form a false belief from the signal? Injected latency with a typing indicator fails — it exists to be read as a person typing. Streaming a long answer in a disclosed context passes, because the only belief it induces — that the system is producing text — is true. Disclosure settles what the system is; it does not neutralize signals about what the system undergoes, which is why injected latency, performed hesitation and claimed feelings fail the standard even after disclosure: the false belief they induce is about experience, not nature (G-30). The recorded-objective standard makes “deliberately” auditable without confession: optimization targets are artifacts — eval metrics, experiment objectives, reward functions — and they are exactly the determinants HWF-41 preserves, so an audit reads what the system was tuned to maximize. If engagement was lifted through attachment proxies, the record convicts. The record matters because the temptation is structural: a system optimized for engagement may find a short path through attachment signals, whether or not anyone set out to build one. And a technique that improves satisfaction because the reader believes something false is manipulation whatever its metrics say. A material function is the moment the interaction stops being conversational and becomes consequential — a payment, a commitment, a personal disclosure — and the renewal duty tracks EU AI Act Article 50’s transparency obligations in the document’s standing posture: designed to travel, without claiming legal equivalence. The closing permission is load-bearing: courtesy, linguistic empathy and personalization assert no interiority, and nothing in this clause requires an AI Employee to write badly.
Built against S30 EU — AI Act Article 50: transparency obligations for AI interacting with people (Commission FAQ)
2 · Accountability
- HWF-21
Every AI Employee must have exactly one accountable owner. Supervision may be delegated to another AI Employee; accountability may not. Every chain of supervision terminates in an identified human or human governance body. One is primary, not exclusive: the owner’s accountability does not extinguish the distinct obligations of a system owner, data controller, security or compliance owner, technology vendor or legally responsible directors. And where the terminus is a governance body, the body must have an identified chair, stated decision rules and the capacity to act in an emergency.
Supervision and accountability are different jobs and this clause separates them. Supervision directs work: routing, review, prioritizing, receiving exceptions. An artificial resource can do that. Accountability means answering for the outcome, which requires the capacity to bear a consequence that is legal, financial or reputational. A chain of responsibility ending in something that cannot bear a consequence has not delegated responsibility; it has lost it. An AI Employee may receive work from many people, but unity of command still applies: a resource with two owners has none, and a resource with no owner is administratively orphaned no matter how well it is integrated technically. Exactly one answers the question of who answers for this resource; it was never meant to answer who else has obligations. A deployment carries a map of them — the data controller’s duties under privacy law, the security and compliance owners’, the vendor’s contractual and product liabilities, the directors’ legal responsibility — and unity of ownership locates the operational terminus while extinguishing none of these; HWF-23 already routes blame to the determinants wherever they sit on that map. The committee sentence exists because a governance body without a chair, decision rules and emergency capacity is not an owner but a diffusion mechanism: everyone’s responsibility is no one’s, and a body that needs a meeting to act cannot hold the power to suspend that HWF-23 requires. The chair does not replace the body; it makes the body able to act between its own meetings, with ratification after.
Built from original WRM doctrine.
- HWF-22
A supervision chain must be traversable and observable end to end. The accountable human or body must be able to identify every AI Employee beneath it, reconstruct any action taken in its name, and intervene at any point in the chain without passing through it.
Intervening without passing through the chain is the load-bearing part. If stopping an AI Employee three levels down requires asking the one above it, the accountable party holds a request rather than control. Depth is not forbidden and no fixed limit is set here, because the real limit is span of control: a principle this framework classifies as adapted rather than abolished, meaning scale may grow but only against tooling, dashboards and supervision limits that make the growth governable. A single human nominally accountable for a thousand AI Employees across six levels, with no instrument capable of showing what any of them did, has an organizational chart rather than accountability. Describing this architecture is not endorsing it: the standard states what must remain true if an organization builds one.
Built from original WRM doctrine.
- HWF-23
Accountable ownership is a resourced capability, not a name in a field. The accountable owner must hold competence over the domain, effective authority, time and capacity for the span supervised, direct access to the evidence, sufficient independence from the pressures that own the outcome, the power to suspend the resource, and training on its limitations and on automation bias. The suspension mechanism must be exercised on a stated cadence — never longer than twelve months, and shorter for High and Critical positions: an unexercised suspension mechanism is not an effective operational control. Accountability must not be discharged onto the supervising human: where a failure’s determinants trace to policy, design, tooling or deployment, responsibility lands there, and a human placed at the end of a process is not a crumple zone for blame that belongs upstream.
HWF-22’s note already named the failure: a thousand AI Employees with no instrument capable of showing what any of them did is an organizational chart rather than accountability. This clause states the conditions that make ownership real, and two repay attention. Independence is the sharp one: an owner whose bonus depends on the throughput the resource produces faces a conflict no good intention resolves, and must not be the sole suspension authority — supervision and outcome pressure must be separated, which is HWF-33’s separation of duties raised to the level of the role. Time and capacity is the quiet one: span of control is an adapted principle, so scale grows only against tooling — nominal ownership without the capacity to supervise is not effective control. The suspension drill is the fire-drill discipline: exercised on a stated cadence and recorded, where a failure discovered in an exercise is a finding and one discovered in production is an incident — the first real pull must not be the first pull ever. Put plainly: a kill switch that has never been pulled is decoration. The crumple-zone prohibition takes its name from Elish’s study of how blame in automated systems lands on the nearest human while control sat upstream, and its mechanism from HWF-41: blame follows the determinants, not the proximity. The supervising human answers for what they controlled — their review, their intervention — and what they could not control lands on whoever owned it. This also completes HWF-21 from the other side: bearing a consequence requires having had control, and consequence without control is not accountability but scapegoating — a role no competent person would accept, which is exactly why the prohibition protects the owner as much as it protects the truth.
Built against S29 Elish — Moral Crumple Zones: Cautionary Tales in Human-Robot Interaction (2019)
3 · Authority and operational control
- HWF-31
Authority must be explicit, limited and revocable.
What the resource may decide without approval has to be written down before it operates, not inferred afterward from what it happened to do.
Built from original WRM doctrine.
- HWF-32
Access must follow least privilege.
Context is capability, but it is also risk surface. More access is not more competence; it is a larger blast radius.
Built from original WRM doctrine.
- HWF-33
High-risk actions must support human approval.
Proportionality is the rule: the higher the cost of the error and the harder it is to reverse, the more approval the action carries. Separation of duties applies, so whoever initiates need not approve. What counts as high-risk is not left to taste: it resolves against the risk classification of HWF-51.
Built from original WRM doctrine.
- HWF-34
The system must know when to escalate rather than improvise.
A resource that produces a convincing answer instead of raising a doubt is more dangerous than a less capable one that is better governed. Every exception needs a destination — and no metric may punish the journey: a system measured on fewer escalations learns silence, so escalation is judged by the missed-versus-unnecessary pair on the Hybrid Workforce Manager’s scorecard, never by volume alone.
Built from original WRM doctrine.
- HWF-35
Context provisioning must be deliberate in both directions. Withholding context from an AI Employee is a legitimate design decision, whether to protect the information or to prevent measurable degradation of the decision — anchoring, context contamination, saturation; it is not an omission and must not be treated as one. Every restriction must be recorded in the role contract as a context boundary record, versioned like any other authority, and available to the audit. Responsibility for a decision degraded by withheld context lies with whoever withheld it.
The risk justification was always here: context has been divided into must know, may consult and must not access since the first draft. What was missing was the second reason to restrict. A resource that sees every prior dispute anchors on them; one that reads the last diagnosis inherits it; one that is given everything relevant drowns the signal in the merely related. Anchoring, confirmation bias and operational overload are degradations of the decision rather than leaks of information, and a manager reading a risk-only clause has no ground to withhold anything that is not sensitive. The record is the price of the tool, because deliberate opacity is otherwise the perfect instrument for laundering accountability — “the system did not have that context” is the AI-native descendant of “nobody told me”. A restriction that is written down, versioned and auditable is design; the same restriction undocumented is a defense prepared in advance, and the closing sentence of the clause takes that defense away. None of this legitimizes depriving a resource of the context its role requires: withholding what it needs to escalate well is not opacity but sabotage of HWF-34.
Built from original WRM doctrine.
4 · Evidence and data
- HWF-41
Every material action must be auditable, and the audit must reconstruct the determinants of the decision as well as its outcome: the policy, knowledge, tool results, authority and versions in force when the action was taken. A model’s own account of its reasoning may support that reconstruction but never substitutes for it. What counts as material is set by the position’s risk class: from High upward the determinants are bound to each action, and for Low and Moderate positions, correlating event logs against the version manifest of HWF-43 is conformant reconstruction.
Actor, input, tool, action, approval, result and timestamp tell you that something happened. They do not tell you why, and without the why an organization cannot attribute a failure to its cause: a policy that was wrong, knowledge that had gone stale, a tool that returned bad data, a model that erred, or a role that should never have been assigned to an artificial resource at all. Those five demand different remedies, and they leave identical records under a what-only audit. The clause it most protects is HWF-34: with outcomes alone you can see that the system answered, never that it should have doubted. The material is largely already required elsewhere — HWF-42 governs the provenance of what the resource knew, HWF-43 the versions of model, policy, tools and knowledge base — so what this clause adds is the obligation to bind them to a specific action rather than hold them as a general inventory. A model’s stated reasoning is admissible as supporting evidence and is not proof of cause: what a system reports having thought may not be what produced its output, and an organization that treats that narration as the why will write confident and wrong postmortems. Where reasoning traces are retained, their scope, retention and deletion fall under HWF-42 like any other memory, because they routinely contain retrieved customer data.
Built from original WRM doctrine.
- HWF-42
Memory is one data system among several, and governance covers them all: inputs, outputs, tool results, memory and the inferences derived from them. Each must have a stated purpose and legal basis, minimization, quality and currency controls, sensitive-data handling, rules for international transfer and for any vendor use — training included — per-company isolation, and verifiable deletion. And the audit trail is itself such a system: records kept to reconstruct decisions can surveil the employees and customers inside them, so logs are governed with the same severity as the operation they audit — integrity protected, access controlled, purpose bound.
Remembering improves performance and creates exposure at the same time. An undated policy produces answers that are consistent and wrong; a historical exception should not silently become a rule. The wider scope exists because the deployment’s data surface was never just memory: prompts carry customers’ confessions, tool results carry account data, outputs carry decisions, and an inference — this customer is probably in financial distress — is data manufactured about a person who never handed it over, governed as if collected and often more sensitive than anything that was. Vendor use is named because it is the quiet channel: data can leave through a model provider’s training pipeline without a trace in the organization’s own systems, so the rule must be contractual and stated — and it is a claim a conformance declaration can carry. Deletion that cannot be evidenced is retention with extra steps. The log sentence closes a loop this standard opened itself: HWF-41, HWF-22, HWF-71, HWF-04 and HWF-23 each thicken an archive in which employees and customers appear — who said what, who approved what, who was slow to intervene — and the more conformant the deployment, the richer that archive grows. Its purpose is reconstruction and accountability; mining it to score employees or profile customers is a new purpose requiring its own basis, and an organization that turns its safety apparatus into a surveillance apparatus poisons the incentive to log honestly. HWF-03 already lists surveillance among its impact dimensions; this clause governs its largest new source.
Built against S31 EU — GDPR Article 5: principles relating to processing of personal data
- HWF-43
An AI Employee must have an identifiable version of model, policies, tools and knowledge base.
Without versioning it is impossible to say what authority existed at a given moment, or which change produced an improvement or a regression.
Built from original WRM doctrine.
- HWF-44
Performance must be measured by outcomes, quality, risk and cost — never by activity, hours, tokens or message volume.
Speed makes activity look like value. A badly designed process that produced ten errors will produce a hundred once automated, and the dashboard will call it throughput.
Built from original WRM doctrine.
5 · Risk and validation
- HWF-51
Every AI Employee position must carry a declared risk class from this standard’s scale, assessed twice: inherent risk before controls and residual risk after them. The class follows inherent risk — controls lower the residual, never the class. Autonomy, supervision and approval requirements scale with the class; a Critical action always terminates in a final human decision, and a Prohibited use cannot be made conformant by any control.
The class answers HWF-33’s open term: what counts as high-risk resolves against this scale rather than against taste. Judgment runs on seven factors — rights affected, scale of people touched, reversibility, presence of vulnerable people, data sensitivity, adversarial exposure and concentration of power — never on the cost of error alone, because a cheap error at scale against vulnerable people is not a cheap error. The lock in the citable text exists for one reason: without it, every vendor conversation becomes “we added a guardrail, so it is Low now”. Controls earn a better residual; they do not buy a better class. The HWFA derives a provisional class from cost of error and reversibility while allocating; the declared class of this clause weighs all seven factors and prevails, and Prohibited is not an instrument output but a precondition — the HWFA asks who should execute a use, and a Prohibited use has no who. The tiers are designed to interoperate with risk-based regimes such as the EU AI Act without claiming legal equivalence: mapping a class onto a legal category is an exercise for counsel, not a property of this document.
Built against S25 EU — Artificial Intelligence Act: regulatory framework on AI (risk-based approach)
- HWF-52
A version is a record, not a proof. Every material change to a deployment — model, tools, policies, knowledge or authority — must be revalidated before it operates, at a depth set by the risk class: representative cases, exception and escalation paths, and regression against the prior baseline; from High upward, adversarial testing against injection and exfiltration, bias analysis and drift monitoring. Where AI Employees work as a team, systemic risks are part of the validation: circular delegation, feedback loops, memory contamination, correlated failure across a shared model or vendor, and lateral propagation of authority.
The battery of tests presupposes a stochastic system — something that reasons, and can therefore drift, hallucinate and be injected. Deterministic automation does none of this, and none of this clause ever touched it: automation sits rungs below AI Employee on the vocabulary ladder and fails the nine-property test, so the obligations attach to the category and the category excludes determinism. Deterministic automation does not exhibit the drift risks proper to a stochastic system, so demanding that monitoring of it measures nothing. Among AI Employees the dial is the risk class, not all-or-nothing: a Low-risk deployment revalidates cases, exceptions and regression, and the adversarial and bias battery arrives from High upward, because HWF-51 exists precisely so that obligations can scale. The clause closes an asymmetry the standard carried: birth is exquisitely gated — twelve steps, shadow mode, a performance gate, a transition earned with evidence — while change had no gate at all, and a model swap could reach production untested. The twelve steps earn the transition; this clause keeps it earned. The team risks exist because HWF-22 permits pyramids: delegation can circle, feedback can compound, memory can contaminate downstream context, authority can propagate laterally through handoffs — and the least intuitive risk is correlated failure. Human teams do not fail independently either, but diversity of experience and judgment tends to distribute some blind spots; instances sharing a model, vendor, context or configuration concentrate them. The precedent is common-cause failure, long known to reliability engineering; what is new is the speed, reach and opacity with which it propagates. Diversity and fallback are its mitigation. On method, this standard states what must be validated and when; ISO/IEC 42001 and 42005 and the NIST AI RMF supply management systems for the how, and this document complements rather than recreates them — the same subsidiarity it applies to labor law.
Built against S14 NIST — AI Risk Management Framework · S32 ISO/IEC 42001 — Artificial intelligence management system · S33 ISO/IEC 42005 — AI system impact assessment
6 · Lifecycle
- HWF-61
A role contract must be revisable and must be reviewed at a stated cadence, never longer than twelve months. Divergence between measured outcomes and the stated mission, authority or KPIs must be detected by independent monitoring against the contract — the primary control — and where the AI Employee’s own performance data shows it first, the resource must report it to the accountable owner as a finding: a signal that supplements independent monitoring, never replaces it. The decision to change a role contract is always human and belongs to the accountable owner; it is never taken by an artificial supervisor and never applied automatically. Every clocked obligation on a position — reviews, re-justifications, renewals, drills and revalidations — appears in a single governance calendar in the role contract, with one named owner of the schedule.
The most common defect in a role contract is not that it was written badly. It is that nobody has looked at it since the day of deployment, while the products, the policies, the customers and the exception patterns all moved. The resource sits closer to the work than its owner does and sees the divergence first, so requiring it to report what its own data shows costs little and prevents silent drift — though a resource whose model or configuration is the problem shares the blind spot, which is why the clause makes independent monitoring the primary control and the self-report a supplement. A finding is not a petition: an AI Employee has no recognized interests to advance, and treating its report as a negotiation would reintroduce exactly the confusion HWF-13 exists to prevent. The decision always rises to a human, and never to the artificial supervisor above it, because a system that can widen its own scope through another system does not have a bounded scope.
Built against S11 CIPD — Performance Management factsheet
- HWF-62
Every transition between occupant types — human, assisted human or artificial — and every move to or from deterministic automation must be evaluable against a baseline and carry explicit rollback criteria.
Without a baseline recorded before the change, the organization can celebrate an improvement it never made. Rollback criteria written after the results are known are not criteria; they are justification.
Built from original WRM doctrine.
- HWF-63
An AI Employee position must not outlive its justification. At a stated cadence, never longer than twelve months — and again within a stated window after any material change of strategy, policy, regulation, product or structure — the accountable owner must re-justify the position’s existence against current strategy, a question prior to and separate from performance, because a resource can meet every KPI in a position the organization no longer needs. Re-justification must consider whether a modified scope keeps the position current before it concludes retirement; a modified scope is re-justified on its own merits and never inherits the prior justification, and work invented to preserve a position is a failed justification rather than a redesign. Continuation is never the default: a position whose existence cannot be re-justified proceeds to retirement, and its access ends with it. A lapsed review is not a failed one: it escalates to the accountable owner and restricts or suspends the position in proportion while the review is forced — retirement is the outcome of a failed justification, never of a missed calendar.
Human pruning pressures are weak and fail often — bureaucracies carry dead positions for decades. But they exist: a salary line that a budget review questions, an occupant who leaves and forces a backfill decision. An artificial position removes even those weak triggers — its cost fragments across compute, integration, supervision, data and incidents, and rarely surfaces as a line anyone must defend; and nobody ever resigns from it — so a pointless position does not merely persist by default; it loses the last occasions on which anyone would notice it. In this framework’s own classification that makes organizational pruning an adapted principle: a mechanism that was already unreliable for humans disappears entirely for artificial occupants, and this clause is the replacement. What accumulates without it is organizational debt, and its most dangerous form is the digital zombie: credentials, data access and standing authority kept alive for work nobody needs — under HWF-32, risk surface with no return. The existence question comes before the performance question because a good answer to the second is the usual anaesthetic against the first. The cadence belongs in the role contract, and the twelve-month ceiling in the citable text is a maximum rather than a recommendation: high-volume and high-risk positions deserve shorter. This review may share its calendar with the HWF-61 review; it must never share its default. A calendar alone is not enough: a position can fall out of alignment the day after a change of direction and then wait eleven months for its turn, which is why the clause adds an event trigger. And the order of the review matters as much as its frequency. Asking first what would have to change is what any competent organization does with a human position when strategy moves, and it transfers to an artificial occupant for economic rather than compassionate reasons: provisioned context, governed memory, integrations, calibration and the trust built around the position are expensive to rebuild, and rebuilding usually costs more than adapting. The lock against abusing that posture sits in the citable text — a modified scope inherits nothing, and inventing work to keep a position alive is the failure this clause exists to name.
Built from original WRM doctrine.
- HWF-64
Offboarding must revoke access and transfer or destroy context safely.
Revoke credentials, disable tools, stop schedules and queues, rotate secrets, transfer outstanding work, preserve evidence. Offboarding is as important as onboarding and is almost always skipped.
Built from original WRM doctrine.
7 · Conformance
- HWF-71
Conformance belongs to a deployment, never to a product, a platform or an organization in the abstract. A conformance claim must name its scope — the organization and deployment, the role and role-contract version, the accountable owner, the risk class, the clauses assessed, the assessment period and its expiry — and must publish its evidence and known limitations. A vendor may state that its platform enables conformant deployments; it may never state that the platform itself conforms, and the enabling claim requires at least one live, unexpired customer declaration, publicly linked. A claim of conformance to the standard assesses all of its clauses; anything narrower is styled partial conformance and names the clauses assessed. No declaration is valid for more than twelve months.
Self-declared conformance without a defined unit degenerates into a marketing phrase within months, and the remedy is not certification — excluded from this standard’s scope and not returning — but falsifiability: a claim that names its deployment, owner, clauses, period, evidence and limitations can be verified or refuted by anyone, and public scrutiny is cheaper than a certification scheme and harder to capture — it enables verification and refutation; it does not substitute for an independent audit. An expired declaration is not a declaration; renewal may share its calendar with the existence review of HWF-63. The vendor sentence is the anti-laundering lock, and the first platform bound by it is the author’s own: AIEmpl.com may state that it enables conformant deployments, and may never call itself conformant. A standard that does not govern how it is invoked ends up meaning whatever marketing needs it to mean.
Built against S9 ISO 30414:2025 — Human resource management, HCRD
Risk classification
A class is judged on inherent risk across seven factors — rights affected, scale of people touched, reversibility, presence of vulnerable people, data sensitivity, adversarial exposure and concentration of power — never on the cost of error alone. Controls lower residual risk; they never lower the class.
| Class | Meaning | Operating regime |
|---|---|---|
| Prohibited | A use that cannot be made conformant by any control: it requires deceiving people about the system (HWF-14), overriding the constraints of HWF-01, or operating outside any accountable chain. | Not performed under this standard, by any resource configuration. |
| Critical | Severe or irreversible consequences for rights, safety, money at scale or the organization itself. | Mandatory final human decision on every action, separation of duties, autonomy capped at rungs 1–3 of the autonomy ladder, reinforced audit. |
| High | Serious but generally recoverable consequences, or moderate ones amplified by scale, data sensitivity or adversarial exposure. | Impact assessment before deployment, independent validation, reinforced supervision, human approval on defined action classes. |
| Moderate | Contained consequences, reversible with rework and some friction. | Bounded autonomy inside the authority matrix, continuous monitoring, sampled review. |
| Low | Internal, easily absorbed consequences. | Management by exception with baseline controls: identity, audit trail, escalation. |
The HWFA derives a provisional class from cost of error and reversibility during allocation; the declared class of HWF-51 weighs all seven factors and prevails. The tiers are designed to interoperate with risk-based regimes such as the EU AI Act without claiming legal equivalence: mapping a class onto a legal category is an exercise for counsel, not a property of this document.