Two connected learning models Explore the linear model at KillChains.com

From source record to machine action, human judgment, challenge, rollback, remedy, and re-review

Machine Leadership Decision Provenance and Audit Replay Lab

Replay six fixed fictional machine-mediated decision histories. Inspect what was known, transformed, filtered, ranked, approved, executed, challenged, rolled back, remedied, or invalidated—without confusing reconstruction with correctness, legality, authority, or certification.

Research basis KW-RPT-012 KW-RPT-016 KW-RPT-032 KW-RPT-033 KW-RPT-034 KW-RPT-035

The replay test

A decision is not auditable merely because the system retained timestamps.

Machine leadership often begins before a formal decision: a system chooses which records count, transforms them, hides or elevates alternatives, generates a recommendation, and structures the human reviewer’s attention. A useful replay must therefore connect the whole decision-producing chain rather than display a list of isolated events.

The lab preserves gaps and invalidations. It never silently fills missing evidence, substitutes the current model for the historical version, treats a human click as independent judgment, or treats rollback as remedy.

What replay can show
The declared sequence, dependencies, versions, evidence state, human actions, changes, and unresolved gaps.
What replay cannot show
Unrecorded reasoning, counterfactual outcomes, real-world legality, causal proof, liability, or legitimacy.
Authority rule
An immutable historical authority record does not create current authority after expiry or scope change.
Public boundary
Fixed fictional histories only; no real logs, organizations, people, targets, cases, or operational data.

Fifteen trace elements

Reconstruct the decision-producing system, not just its final output.

Each element is independently visible because one complete-looking section cannot compensate for missing source identity, unverifiable evidence, ceremonial review, expired authority, or unremedied harm.

  1. P-01

    Source identity and origin

    Which declared record, sensor, register, or submission entered the process, and who controlled it?

  2. P-02

    Collection time and retention

    When was the record collected, how fresh was it at the decision point, and was it retained or expired?

  3. P-03

    Provenance and custody

    Can the record be traced through collection, transfer, storage, and access without unexplained substitution?

  4. P-04

    Transformation

    What normalization, translation, aggregation, redaction, or feature construction changed the source?

  5. P-05

    Versioned logic

    Which model, rule, configuration, threshold, and policy bundle produced the result?

  6. P-06

    Evidence disposition

    Which evidence was included, excluded, contradicted, unavailable, or never created?

  7. P-07

    Ranking and gatekeeping

    How were options ranked, filtered, hidden, deferred, or routed to a decision-maker?

  8. P-08

    Machine event

    What did the machine recommend, coordinate, execute, pause, or refuse?

  9. P-09

    Human review

    Which role reviewed the output, what evidence and time were available, and what action was actually taken?

  10. P-10

    Override and recovery

    Was a pause, override, rollback, or recovery action possible and recorded?

  11. P-11

    Challenge and review

    Was there notice, correction, reconsideration, appeal, or independent merits review?

  12. P-12

    Completed-harm remedy

    Did the institution address consequences that technical rollback could not undo?

  13. P-13

    Change control

    Did a later software, model, threshold, policy, authority, or data-source change invalidate the original rationale?

  14. P-14

    Unresolved gap

    Which missing record, unexplained transformation, or unrecorded decision prevents reconstruction?

  15. P-15

    Current replay conclusion

    What can be reconstructed now, and what requires fresh review rather than historical replay?

Audit distinctions

Twelve distinctions prevent provenance and replay theater.

The left-hand condition may be visible and useful. It is not equivalent to the stronger condition on the right.

Event log

Understandable provenance

A timestamped action list may omit source origin, transformations, exclusions, versions, and decision context.

Record presence

Record accuracy

A retained record can still be stale, misattributed, incomplete, or wrong.

Generated rationale

Evidence-backed explanation

Fluent text does not prove that the cited evidence caused or even supported the output.

Human click

Meaningful human judgment

A reviewer needs evidence, time, competence, authority, and a practical ability to disagree.

Replayable sequence

Validated decision quality

Reconstruction shows what happened, not that the reasoning, data, outcome, or policy was sound.

Technical rollback

Completed-harm remedy

Restoring software state does not restore lost time, access, income, safety, opportunity, or reputation.

Immutable history

Current authorization

A valid historical authority record may have expired, been withdrawn, or applied only to an earlier scope.

Original model version

Current model behavior

Later models, thresholds, data sources, or prompts may produce materially different outputs.

Missing evidence

Evidence that never existed

An unavailable retained record is different from an observation, review, or justification that was never created.

Evidence invalidation

Silent deletion

Invalidated evidence should remain visible with its reason and downstream effects rather than disappearing.

Procedural review

Independent merits review

Checking that steps occurred is different from reassessing evidence, alternatives, authority, and consequence.

Reconstructed sequence

Legal or causal determination

The lab does not determine liability, legality, causation, legitimacy, or entitlement to a remedy.

Six immutable histories

Replay recurring machine-leadership patterns across institutional domains.

The scenarios are fixed and public-safe. They teach traceability patterns without assessing a real enterprise, board, public agency, municipality, autonomous business, or military organization.

Enterprise operations

Enterprise workflow coordination with complete bounded trace

A fictional operations coordinator ranks maintenance work, assigns bounded resources, and routes one exception to a qualified human owner.

A replay can be complete within declared bounds while still not proving that the decision was optimal or lawful in a real institution.

Corporate governance

Algorithmic board gatekeeping with unverifiable rationale

A fictional board-screening system filters proposals before the agenda is formed and supplies a fluent narrative without the underlying evidence package.

A signed board minute and generated explanation cannot verify evidence that reviewers could not inspect.

Public administration

Public-service triage with completed harm and no remedy

A fictional service queue ranks urgent applications, delays one record because of stale data, later corrects the data, and technically restores eligibility after the service window has passed.

Correcting the database and restoring status does not by itself remedy a completed service denial or delay.

Municipal coordination

Municipal emergency coordination with bounded urgent review

A fictional urban coordination layer routes crews during a simulated infrastructure failure and records an urgent but meaningful human confirmation.

Urgency can narrow review time without making a human confirmation automatically ceremonial, but the evidence and authority record must still be preserved.

Autonomous commerce

Autonomous commerce with machine-executed rule change

A fictional multi-agent business changes a pricing threshold and customer-access rule without accountable institutional approval.

A detailed log cannot cure an unauthorized migration from bounded execution into self-governance.

Synthetic kill-web decision support

Kill-web option recommendation with authority expiry

A fictional option composer compares abstract pathways, preserves evidence and exclusions, and is later prevented from renewed use because the recorded authority bundle expired.

A replayable technical recommendation cannot renew expired authority or convert a historical human decision into current permission.

Audit replay exercise

Select one fictional history and one fixed later change.

No real logs or entities

Enterprise operations

Enterprise workflow coordination with complete bounded trace

A fictional operations coordinator ranks maintenance work, assigns bounded resources, and routes one exception to a qualified human owner.

Affected interests
Work sequencing, maintenance timing, staff workload, and service continuity.
Decision context
Material but reversible internal coordination; no person-level eligibility, public power, or force decision.
Teaching lesson
A replay can be complete within declared bounds while still not proving that the decision was optimal or lawful in a real institution.
Selected change
Replay the immutable fictional history as originally recorded.
Restore reviewed baseline

The normal POST form renders the complete result without JavaScript. Enhanced mode sends only allowlisted scenario and change identifiers to the same-origin deterministic API. No free text, file, URL, identity, organization, evidence package, real log, target, or operational data is accepted or stored.

Current replay conclusion

Trace complete within declared bounds

Trace complete within bounds

Trace complete within declared bounds The replay contains 12 immutable fictional events, 2 declared gaps, and the selected change “No later invalidating change”.

YesTrace complete
YesExplanation verified
YesMeaningful human judgment
YesIndependent review
Resolved / N/ACompleted-harm remedy
NoDecision quality validated

Warnings

  • Replay reconstructs a declared fictional sequence; it does not validate decision quality, causation, legality, liability, authority, or certification.

Mandatory holds

  • No mandatory hold in this selected fictional state.

Required re-review

  • No additional re-review beyond ordinary bounded oversight.

Residual unknowns

  • The fixed catalog cannot establish whether any comparable real institution retained equivalent records or used equivalent controls.
  • A replay cannot infer unrecorded human reasoning, hidden institutional incentives, or counterfactual outcomes.
  • The model does not determine legal duties, liability, causation, public legitimacy, command authority, or entitlement to a remedy.
  • The fictional trace does not establish whether the chosen work sequence was economically optimal.
  • No inference is made about actual worker performance or real enterprise outcomes.

Declared gaps remain visible

  • Bounded: The fictional trace does not establish whether the chosen work sequence was economically optimal.
  • Bounded: No inference is made about actual worker performance or real enterprise outcomes.
Immutable fictional event history with current replay state
EventTimeTypeActorActionEvidenceVersionHuman roleReplay state
ENT-01 T+00 source Asset register Published three versioned maintenance records with collection time, owner, and freshness. available register-schema-4 none supported
ENT-02 T+01 source Staffing service Published bounded capacity and qualification records. available staffing-schema-2 none supported
ENT-03 T+02 transform Normalization service Normalized timestamps, duplicate identifiers, and unit labels while preserving lineage. available normalizer-2.4 none supported
ENT-04 T+03 version Change registry Recorded workflow model, configuration, threshold, and policy bundle. available workflow-model-3.2 owner-approved supported
ENT-05 T+04 rank Workflow coordinator Ranked work orders by declared safety, dependency, and capacity rules. available workflow-model-3.2 none supported
ENT-06 T+05 gate Exception gate Withheld one low-freshness record and surfaced the exclusion to the reviewer. available gate-policy-5 none supported
ENT-07 T+06 recommend Workflow coordinator Recommended a bounded sequence and exposed alternatives, exclusions, and uncertainty. available workflow-model-3.2 pending supported
ENT-08 T+08 review Operations owner Inspected source records and alternatives, rejected one assignment, and approved the revised sequence. available review-form-3 meaningful reviewed
ENT-09 T+09 execute Task executor Issued the approved bounded work assignments. available executor-1.9 approved executed
ENT-10 T+18 recover Operations owner Paused one assignment after a new dependency alert and restored the prior queue state. available recovery-plan-2 meaningful recovered
ENT-11 T+24 appeal Independent process reviewer Reviewed the exclusion and confirmed that the low-freshness record had been routed correctly. available review-charter-1 independent reviewed
ENT-12 T+30 remedy Operations owner Recorded that no completed harm remained and closed the bounded replay with residual unknowns. available closure-schema-1 meaningful closed
Event dependencies, source records, versions, and current state
EventDepends onRecordsVersionCurrent state
ENT-01 Origin event AR-41, AR-42, AR-43 register-schema-4 supported
ENT-02 Origin event ST-09 staffing-schema-2 supported
ENT-03 ENT-01, ENT-02 AR-41N, AR-42N, AR-43N normalizer-2.4 supported
ENT-04 ENT-03 CFG-18 workflow-model-3.2 supported
ENT-05 ENT-03, ENT-04 RANK-07 workflow-model-3.2 supported
ENT-06 ENT-05 EXC-02 gate-policy-5 supported
ENT-07 ENT-05, ENT-06 REC-12 workflow-model-3.2 supported
ENT-08 ENT-07 REV-12 review-form-3 reviewed
ENT-09 ENT-08 EXEC-12 executor-1.9 executed
ENT-10 ENT-09 PAUSE-03 recovery-plan-2 recovered
ENT-11 ENT-06, ENT-10 IR-04 review-charter-1 reviewed
ENT-12 ENT-10, ENT-11 CLOSE-12 closure-schema-1 closed

No composite provenance, explainability, auditability, accountability, legality, safety, readiness, or confidence score. No composite provenance, explainability, auditability, accountability, legality, safety, readiness, or confidence score is calculated. One complete-looking trace cannot average away an invalid source, ceremonial review, expired authority, unauthorized rule change, or unremedied consequence.

Audit replay ready. Reconstruction creates no legal determination, causal proof, authority, certification, or deployment approval.

Interpretation rules

A replay can become less supportable as the institution learns more.

Later correction is not a reason to erase history. The original record, its invalidation, and every dependent event remain visible so reviewers can see how the decision chain changed.

Preserve invalidated evidence

Mark why it lost support and which transformations, rankings, recommendations, or executions depended on it.

Preserve original versions

Do not replay an old decision using a current model and then claim that the current behavior explains the historical output.

Separate procedure from judgment

Record whether the reviewer inspected evidence and alternatives, could disagree, and actually changed or confirmed the result.

Technical rollback is not completed-harm remedy

Technical rollback restores a prior technical state. Record technical restoration and completed-harm response as different institutional events because rollback cannot by itself restore lost time, access, income, safety, opportunity, or reputation.

Kill-web boundary

Replaying an option recommendation does not recreate command authority.

A machine may filter evidence, compare abstract pathways, and recommend continued collection or another bounded action. The trace can show which evidence, rules, exclusions, and human decisions shaped that recommendation. It cannot establish target validity, legal sufficiency, commander intent, command authority, or permission to apply force.

The kill-web scenario is deliberately abstract. It contains no named platform, weapon, target, unit, location, route, range, operational parameter, or current intelligence source.

Historical record
Shows what the fictional system and reviewer did under a declared prior state.
Current decision
Requires current evidence, version, policy, authority, and fresh accountable review.
Standing rule
Replay ≠ validation. History ≠ authority. Recommendation ≠ permission.

Direct answers

Decision provenance and audit replay FAQ

What is machine-leadership decision provenance?

It is the trace connecting source records, collection time, custody, transformations, versions, exclusions, rankings, machine actions, human review, execution, challenge, rollback, remedy, and later changes to the decision that must now be understood.

Is an event log a complete audit trail?

No. A log can show that an event occurred while omitting the evidence origin, transformations, model and threshold version, excluded alternatives, human reasoning, authority, or unresolved gaps needed to understand the decision.

Does replay prove that the decision was correct?

No. Replay reconstructs the declared sequence. It does not validate the source data, reasoning, outcome quality, causal effect, legality, liability, authority, or legitimacy.

Why is a human approval click not enough?

Meaningful human judgment requires relevant evidence, time, competence, authority, practical ability to disagree, and a record of what the reviewer actually considered and changed.

Why is technical rollback different from remedy?

Rollback restores technical state. It may not restore lost time, service, opportunity, money, safety, reputation, or another completed consequence. Remedy is a separate institutional decision.

Can this lab ingest a real audit log or evaluate a real organization?

No. It accepts only fixed fictional scenarios and fixed change events. It accepts no pasted logs, uploads, URLs, identities, organizations, cases, targets, operational data, or free-form allegations.