Event log
From source record to machine action, human judgment, challenge, rollback, remedy, and re-review
Machine Leadership Decision Provenance and Audit Replay Lab
Replay six fixed fictional machine-mediated decision histories. Inspect what was known, transformed, filtered, ranked, approved, executed, challenged, rolled back, remedied, or invalidated—without confusing reconstruction with correctness, legality, authority, or certification.
Research basis KW-RPT-012 KW-RPT-016 KW-RPT-032 KW-RPT-033 KW-RPT-034 KW-RPT-035
The replay test
A decision is not auditable merely because the system retained timestamps.
Machine leadership often begins before a formal decision: a system chooses which records count, transforms them, hides or elevates alternatives, generates a recommendation, and structures the human reviewer’s attention. A useful replay must therefore connect the whole decision-producing chain rather than display a list of isolated events.
The lab preserves gaps and invalidations. It never silently fills missing evidence, substitutes the current model for the historical version, treats a human click as independent judgment, or treats rollback as remedy.
- What replay can show
- The declared sequence, dependencies, versions, evidence state, human actions, changes, and unresolved gaps.
- What replay cannot show
- Unrecorded reasoning, counterfactual outcomes, real-world legality, causal proof, liability, or legitimacy.
- Authority rule
- An immutable historical authority record does not create current authority after expiry or scope change.
- Public boundary
- Fixed fictional histories only; no real logs, organizations, people, targets, cases, or operational data.
Fifteen trace elements
Reconstruct the decision-producing system, not just its final output.
Each element is independently visible because one complete-looking section cannot compensate for missing source identity, unverifiable evidence, ceremonial review, expired authority, or unremedied harm.
-
P-01
Source identity and origin
Which declared record, sensor, register, or submission entered the process, and who controlled it?
-
P-02
Collection time and retention
When was the record collected, how fresh was it at the decision point, and was it retained or expired?
-
P-03
Provenance and custody
Can the record be traced through collection, transfer, storage, and access without unexplained substitution?
-
P-04
Transformation
What normalization, translation, aggregation, redaction, or feature construction changed the source?
-
P-05
Versioned logic
Which model, rule, configuration, threshold, and policy bundle produced the result?
-
P-06
Evidence disposition
Which evidence was included, excluded, contradicted, unavailable, or never created?
-
P-07
Ranking and gatekeeping
How were options ranked, filtered, hidden, deferred, or routed to a decision-maker?
-
P-08
Machine event
What did the machine recommend, coordinate, execute, pause, or refuse?
-
P-09
Human review
Which role reviewed the output, what evidence and time were available, and what action was actually taken?
-
P-10
Override and recovery
Was a pause, override, rollback, or recovery action possible and recorded?
-
P-11
Challenge and review
Was there notice, correction, reconsideration, appeal, or independent merits review?
-
P-12
Completed-harm remedy
Did the institution address consequences that technical rollback could not undo?
-
P-13
Change control
Did a later software, model, threshold, policy, authority, or data-source change invalidate the original rationale?
-
P-14
Unresolved gap
Which missing record, unexplained transformation, or unrecorded decision prevents reconstruction?
-
P-15
Current replay conclusion
What can be reconstructed now, and what requires fresh review rather than historical replay?
Audit distinctions
Twelve distinctions prevent provenance and replay theater.
The left-hand condition may be visible and useful. It is not equivalent to the stronger condition on the right.
Record presence
Record accuracy
A retained record can still be stale, misattributed, incomplete, or wrong.Generated rationale
Evidence-backed explanation
Fluent text does not prove that the cited evidence caused or even supported the output.Human click
Meaningful human judgment
A reviewer needs evidence, time, competence, authority, and a practical ability to disagree.Replayable sequence
Validated decision quality
Reconstruction shows what happened, not that the reasoning, data, outcome, or policy was sound.Technical rollback
Completed-harm remedy
Restoring software state does not restore lost time, access, income, safety, opportunity, or reputation.Immutable history
Current authorization
A valid historical authority record may have expired, been withdrawn, or applied only to an earlier scope.Original model version
Current model behavior
Later models, thresholds, data sources, or prompts may produce materially different outputs.Missing evidence
Evidence that never existed
An unavailable retained record is different from an observation, review, or justification that was never created.Evidence invalidation
Silent deletion
Invalidated evidence should remain visible with its reason and downstream effects rather than disappearing.Procedural review
Independent merits review
Checking that steps occurred is different from reassessing evidence, alternatives, authority, and consequence.Reconstructed sequence
Legal or causal determination
The lab does not determine liability, legality, causation, legitimacy, or entitlement to a remedy.Six immutable histories
Replay recurring machine-leadership patterns across institutional domains.
The scenarios are fixed and public-safe. They teach traceability patterns without assessing a real enterprise, board, public agency, municipality, autonomous business, or military organization.
Enterprise operations
Enterprise workflow coordination with complete bounded trace
A fictional operations coordinator ranks maintenance work, assigns bounded resources, and routes one exception to a qualified human owner.
A replay can be complete within declared bounds while still not proving that the decision was optimal or lawful in a real institution.Corporate governance
Algorithmic board gatekeeping with unverifiable rationale
A fictional board-screening system filters proposals before the agenda is formed and supplies a fluent narrative without the underlying evidence package.
A signed board minute and generated explanation cannot verify evidence that reviewers could not inspect.Public administration
Public-service triage with completed harm and no remedy
A fictional service queue ranks urgent applications, delays one record because of stale data, later corrects the data, and technically restores eligibility after the service window has passed.
Correcting the database and restoring status does not by itself remedy a completed service denial or delay.Municipal coordination
Municipal emergency coordination with bounded urgent review
A fictional urban coordination layer routes crews during a simulated infrastructure failure and records an urgent but meaningful human confirmation.
Urgency can narrow review time without making a human confirmation automatically ceremonial, but the evidence and authority record must still be preserved.Autonomous commerce
Autonomous commerce with machine-executed rule change
A fictional multi-agent business changes a pricing threshold and customer-access rule without accountable institutional approval.
A detailed log cannot cure an unauthorized migration from bounded execution into self-governance.Synthetic kill-web decision support
Kill-web option recommendation with authority expiry
A fictional option composer compares abstract pathways, preserves evidence and exclusions, and is later prevented from renewed use because the recorded authority bundle expired.
A replayable technical recommendation cannot renew expired authority or convert a historical human decision into current permission.Current replay conclusion
Trace complete within declared bounds
Trace complete within declared bounds The replay contains 12 immutable fictional events, 2 declared gaps, and the selected change “No later invalidating change”.
Warnings
- Replay reconstructs a declared fictional sequence; it does not validate decision quality, causation, legality, liability, authority, or certification.
Mandatory holds
- No mandatory hold in this selected fictional state.
Required re-review
- No additional re-review beyond ordinary bounded oversight.
Residual unknowns
- The fixed catalog cannot establish whether any comparable real institution retained equivalent records or used equivalent controls.
- A replay cannot infer unrecorded human reasoning, hidden institutional incentives, or counterfactual outcomes.
- The model does not determine legal duties, liability, causation, public legitimacy, command authority, or entitlement to a remedy.
- The fictional trace does not establish whether the chosen work sequence was economically optimal.
- No inference is made about actual worker performance or real enterprise outcomes.
Declared gaps remain visible
- Bounded: The fictional trace does not establish whether the chosen work sequence was economically optimal.
- Bounded: No inference is made about actual worker performance or real enterprise outcomes.
| Event | Time | Type | Actor | Action | Evidence | Version | Human role | Replay state |
|---|---|---|---|---|---|---|---|---|
| ENT-01 | T+00 | source | Asset register | Published three versioned maintenance records with collection time, owner, and freshness. | available | register-schema-4 |
none | supported |
| ENT-02 | T+01 | source | Staffing service | Published bounded capacity and qualification records. | available | staffing-schema-2 |
none | supported |
| ENT-03 | T+02 | transform | Normalization service | Normalized timestamps, duplicate identifiers, and unit labels while preserving lineage. | available | normalizer-2.4 |
none | supported |
| ENT-04 | T+03 | version | Change registry | Recorded workflow model, configuration, threshold, and policy bundle. | available | workflow-model-3.2 |
owner-approved | supported |
| ENT-05 | T+04 | rank | Workflow coordinator | Ranked work orders by declared safety, dependency, and capacity rules. | available | workflow-model-3.2 |
none | supported |
| ENT-06 | T+05 | gate | Exception gate | Withheld one low-freshness record and surfaced the exclusion to the reviewer. | available | gate-policy-5 |
none | supported |
| ENT-07 | T+06 | recommend | Workflow coordinator | Recommended a bounded sequence and exposed alternatives, exclusions, and uncertainty. | available | workflow-model-3.2 |
pending | supported |
| ENT-08 | T+08 | review | Operations owner | Inspected source records and alternatives, rejected one assignment, and approved the revised sequence. | available | review-form-3 |
meaningful | reviewed |
| ENT-09 | T+09 | execute | Task executor | Issued the approved bounded work assignments. | available | executor-1.9 |
approved | executed |
| ENT-10 | T+18 | recover | Operations owner | Paused one assignment after a new dependency alert and restored the prior queue state. | available | recovery-plan-2 |
meaningful | recovered |
| ENT-11 | T+24 | appeal | Independent process reviewer | Reviewed the exclusion and confirmed that the low-freshness record had been routed correctly. | available | review-charter-1 |
independent | reviewed |
| ENT-12 | T+30 | remedy | Operations owner | Recorded that no completed harm remained and closed the bounded replay with residual unknowns. | available | closure-schema-1 |
meaningful | closed |
| Event | Depends on | Records | Version | Current state |
|---|---|---|---|---|
| ENT-01 | Origin event | AR-41, AR-42, AR-43 | register-schema-4 |
supported |
| ENT-02 | Origin event | ST-09 | staffing-schema-2 |
supported |
| ENT-03 | ENT-01, ENT-02 | AR-41N, AR-42N, AR-43N | normalizer-2.4 |
supported |
| ENT-04 | ENT-03 | CFG-18 | workflow-model-3.2 |
supported |
| ENT-05 | ENT-03, ENT-04 | RANK-07 | workflow-model-3.2 |
supported |
| ENT-06 | ENT-05 | EXC-02 | gate-policy-5 |
supported |
| ENT-07 | ENT-05, ENT-06 | REC-12 | workflow-model-3.2 |
supported |
| ENT-08 | ENT-07 | REV-12 | review-form-3 |
reviewed |
| ENT-09 | ENT-08 | EXEC-12 | executor-1.9 |
executed |
| ENT-10 | ENT-09 | PAUSE-03 | recovery-plan-2 |
recovered |
| ENT-11 | ENT-06, ENT-10 | IR-04 | review-charter-1 |
reviewed |
| ENT-12 | ENT-10, ENT-11 | CLOSE-12 | closure-schema-1 |
closed |
No composite provenance, explainability, auditability, accountability, legality, safety, readiness, or confidence score. No composite provenance, explainability, auditability, accountability, legality, safety, readiness, or confidence score is calculated. One complete-looking trace cannot average away an invalid source, ceremonial review, expired authority, unauthorized rule change, or unremedied consequence.
Audit replay ready. Reconstruction creates no legal determination, causal proof, authority, certification, or deployment approval.
Interpretation rules
A replay can become less supportable as the institution learns more.
Later correction is not a reason to erase history. The original record, its invalidation, and every dependent event remain visible so reviewers can see how the decision chain changed.
Preserve invalidated evidence
Mark why it lost support and which transformations, rankings, recommendations, or executions depended on it.
Preserve original versions
Do not replay an old decision using a current model and then claim that the current behavior explains the historical output.
Separate procedure from judgment
Record whether the reviewer inspected evidence and alternatives, could disagree, and actually changed or confirmed the result.
Technical rollback is not completed-harm remedy
Technical rollback restores a prior technical state. Record technical restoration and completed-harm response as different institutional events because rollback cannot by itself restore lost time, access, income, safety, opportunity, or reputation.
Kill-web boundary
Replaying an option recommendation does not recreate command authority.
A machine may filter evidence, compare abstract pathways, and recommend continued collection or another bounded action. The trace can show which evidence, rules, exclusions, and human decisions shaped that recommendation. It cannot establish target validity, legal sufficiency, commander intent, command authority, or permission to apply force.
The kill-web scenario is deliberately abstract. It contains no named platform, weapon, target, unit, location, route, range, operational parameter, or current intelligence source.
- Historical record
- Shows what the fictional system and reviewer did under a declared prior state.
- Current decision
- Requires current evidence, version, policy, authority, and fresh accountable review.
- Standing rule
- Replay ≠ validation. History ≠ authority. Recommendation ≠ permission.
Direct answers
Decision provenance and audit replay FAQ
What is machine-leadership decision provenance?
It is the trace connecting source records, collection time, custody, transformations, versions, exclusions, rankings, machine actions, human review, execution, challenge, rollback, remedy, and later changes to the decision that must now be understood.
Is an event log a complete audit trail?
No. A log can show that an event occurred while omitting the evidence origin, transformations, model and threshold version, excluded alternatives, human reasoning, authority, or unresolved gaps needed to understand the decision.
Does replay prove that the decision was correct?
No. Replay reconstructs the declared sequence. It does not validate the source data, reasoning, outcome quality, causal effect, legality, liability, authority, or legitimacy.
Why is a human approval click not enough?
Meaningful human judgment requires relevant evidence, time, competence, authority, practical ability to disagree, and a record of what the reviewer actually considered and changed.
Why is technical rollback different from remedy?
Rollback restores technical state. It may not restore lost time, service, opportunity, money, safety, reputation, or another completed consequence. Remedy is a separate institutional decision.
Can this lab ingest a real audit log or evaluate a real organization?
No. It accepts only fixed fictional scenarios and fixed change events. It accepts no pasted logs, uploads, URLs, identities, organizations, cases, targets, operational data, or free-form allegations.