ZoikoDigital
AI Governance

Use AI within defined authority, evidence, and review

Deterministic rules, approved machine-learning flags, governed assistance, and human-only decisions are four different things with four different authority levels. Each governed use states its purpose, sources, allowed output, human control, limitations, owner, status, and correction path.

Deterministic ClassificationKairosPrivacySecurity

A governance team reviewing AI capability authority, evidence, and human approval steps on a shared display

Scope invariant

This page explains authority and evidence, not AI novelty. If a governed use cannot be described as a purpose, source boundary, allowed output, human control, limitation, owner, and status — it is not ready to be described at all.

Capability Taxonomy

Seven Categories — Starting With the One That Is Not AI

Relabelling ordinary rules as AI is a marketing choice with a governance cost: it makes an explainable system look opaque, and invites trust the mechanism has not earned.

Deterministic rules

Versioned policy logic, arithmetic, thresholds, or routing producing repeatable output from the same governed inputs.

Not labelled AI. Rule version, inputs, and reason exposed.

Approved ML flagging

A governed statistical or machine-learning system identifies an anomaly, pattern, or signal-quality concern.

Flag only. No automatic guilt, payroll, discipline, or employment conclusion.

Governed AI assistance

A model retrieves, summarizes, transforms, or explains approved information within defined source, permission, tool, and output limits.

Source-linked, reviewable, non-authoritative.

Human-only outcome

A consequence that must be decided by an authorized person.

Outside autonomous authority entirely.

Prohibited use

A use that violates product invariants or approved policy.

Not configurable, not an add-on, not described as future capability.

Evidence-gated use

A proposed or evaluated use that has not passed release and operating gates.

Not current. Prerequisites and safe alternative stated, or absent.

Unavailable

No approved capability or evidence supports the request.

Routes to a deterministic or human process instead.

Why the first row matters

Time classification is deterministic and policy-bound. Calling it AI would make a reviewable rule engine harder to challenge, not easier.

Seven authority classes

Authority classAllowed behaviorRequired human control
InformPresent source-linked information or status.User can inspect sources, freshness, and limitations.
SuggestOffer a non-binding option or draft.An authorized user reviews and chooses whether to act.
FlagIdentify a pattern or potential concern.A flag opens review. It is not a conclusion.
DraftPrepare text, summary, explanation, or workflow artifact.A human approves any consequential communication or action.
Execute reversible administrative actionOnly when explicitly approved, permissioned, and safely reversible.Human initiation and confirmation, preview, audit, undo, and policy limits.
Consequential decisionProhibited for autonomous AI. Payroll, discipline, employment, legal, eligibility, or comparable outcome.An authorized human decision is required — always.
Irreversible or external actionSend, disclose, delete, publish, lock, or change authoritative records outside safe reversible bounds.Human authorization plus explicit action-specific controls. Otherwise prohibited.

Prohibited & Unavailable Uses

Nine Things ZoikoTime Will Not Build

These are not gaps awaiting a roadmap. They cannot be weakened by plan, configuration, or a hidden enterprise add-on, and changing any of them would require product, privacy, security, legal, ethical-design, and worker-trust review.

No screenshots, keystroke content, URL history, application-name monitoring, or clipboard collection under any tier or configuration.

Inference prohibitions

  • Emotion, mood, personality, intent, loyalty, or honesty inference
  • Productivity worth or protected-trait inference from workforce behavior
  • Covert ranking, hidden risk scores, or worker comparison without legitimate purpose and approved authority
  • Face recognition, voiceprint identification, or biometric categorization — no current claim exists, and none is implied

Authority prohibitions

  • Automated payroll, discipline, termination, promotion, hiring, legal, compliance, or misconduct conclusions
  • Autonomous access escalation, permission grant, evidence alteration, record deletion, incident closure, or policy override
  • Training or provider reuse of customer or worker data outside approved contractual, privacy, and technical boundaries
  • Fabricated sources, unsupported legal advice, guaranteed compliance conclusions, or claims of human-judgment equivalence
  • Dark patterns that pressure users to accept AI, conceal a human alternative, or make correction and appeal harder

An unavailable request identifies its limitation and routes to a deterministic or human alternative. It is never presented as a coming feature.

Governance Lifecycle

Twelve Stages, With Evaluation Planned Before Results Exist

Stage 5 is the one most governance processes skip: the evaluation plan is created before anyone relies on an outcome metric, so the threshold is not chosen to fit the result.

01

Register

Proposed use, purpose, intended users, affected people, authority, owner.

Use-case owner
02

Classify

Capability type, risk tier, prohibited-use proximity, reversibility, jurisdiction context.

AI governance
03

Verify data & provider

Sources, permissions, retention, region, and training or use-of-data boundaries.

Privacy & Security
04

Define human controls

Worker rights, fallback, accessibility, and safe failure behavior.

Product governance
05

Create the evaluation plan

Before relying on any outcome metric — so thresholds are set before results are known.

Independent of the owner
06

Evaluate

Task quality, groundedness, failure modes, fairness, privacy, security, robustness, accessibility, human factors, misuse.

Specialist reviewers
07

Review residual risk

Limitations, evidence sufficiency, and operational readiness via eligible independent roles.

Independent review
08

Gate decision

Approve, conditionally approve, reject, or keep evidence-gated — with a reasoned record.

Human only · separated from owner
09

Release

In approved scope, with monitoring, rollback, incident, and support controls.

Operating owner
10

Monitor

Sources, behavior, overrides, corrections, incidents, provider and tool health.

Operating owner
11

Re-evaluate

After material change, incident, drift-like behavior, legal or policy change, or review date.

AI governance
12

Suspend, correct or retire

When evidence or controls no longer support current operation.

Governance · emergency authority is broader

Six risk tiers

G0

Not AI / deterministic

Versioned rules, arithmetic, or routing with no learned behavior.

Rule ownership, test evidence, explanation, change control, human review where consequential.

G1

Low-impact assistance

Drafting, retrieval, or summarization with no consequential authority and clear human review.

Source and permission controls, task evaluation, limitations, monitoring, user correction.

G2

Review-supporting signal

A flag or recommendation may shape an investigation but cannot decide a consequence.

Impact and fairness evaluation, visible reasons, reviewer training, correction, independent approval.

G3

High-impact context

Assistance used near payroll, discipline, employment, legal, or compliance decisions — humans retain authority.

Enhanced review, separation of duties, representative and legal review, staged release, strong monitoring.

G4

Prohibited autonomous consequence

AI determines or executes a consequential outcome, performs covert surveillance, or makes a prohibited inference.

Not permitted. No release path without fundamental product-policy change and full re-approval. No current claim.

G?

Unclassified

Purpose, authority, data, evaluation, or control is unresolved.

Evidence-gated or suspended. No current operation and no marketing claim.

Separation of duties

A use-case owner cannot independently approve a high-impact use. Evaluation author and final approver are separated where material conflicts exist. Emergency suspension authority is deliberately broader than release authority — it is easier to stop something than to ship it — subject to retrospective review. And provider commercial ownership never overrides evidence, safety, or rights review.

Public Capability Register

Every Governed Use, With Its Honest Status

If evaluation, monitoring, or source evidence is stale, incomplete, or conflicting, the capability reads Under Review, Suspended, Limited, or Unavailable — never silently Current.

CurrentLimitedUnder reviewSuspendedRetiredEvidence-gatedUnavailable
Capability typeAuthority classRisk tierProduct areaStatusEvidence levelOwnerLast reviewed

Time classification

PUBLIC

Versioned policy rules producing repeatable, explainable output.

Type
Deterministic — not AI
Authority
Inform
Tier
G0
Status
Current

Deterministic does not mean legally correct or consequence-ready without human review.

Source-quality flagging

PUBLIC

Identifies stale, incomplete, or conflicting source conditions for review.

Type
Approved ML flagging
Authority
Flag
Tier
G2
Status
Current

False-positive and false-negative limitations documented in the use-case detail.

Anomaly flagging

PUBLIC

Identifies a pattern that may warrant an authorized person's attention.

Type
Approved ML flagging
Authority
Flag
Tier
G2
Status
Current

Never a misconduct, fraud, payroll, or legal conclusion. No composite worker score.

Kairos retrieval & explanation

PUBLIC

Retrieves, summarizes, and explains governed data within the requester's existing permissions.

Type
Governed AI assistance
Authority
Inform · Suggest · Draft
Tier
G1
Status
Current

No completeness or legal-correctness guarantee. Cannot expand permissions or invent a source.

Drafted explanation text

CONTROLLED

Prepares an explanation draft for an authorized reviewer to adopt or reject.

Type
Governed AI assistance
Authority
Draft
Tier
G3
Status
Limited

High-impact context. A draft is never issued without human adoption and verification.

Autonomous approval of any kind

PROHIBITED

AI determining or executing a consequential outcome.

Tier
G4
Status
Prohibited

No release path exists. Not configurable, not on a roadmap, not an enterprise add-on.

Each public use-case detail states purpose, affected people, sources and permission boundary, allowed outputs, human controls, evaluation summary, limitations, owner, status, and correction path. Model, provider, tool, region, retention, and use-of-data conditions are disclosed at the appropriate public or controlled level — never invented for a marketing page.

Evaluation Evidence

Ten Dimensions, Six Result States

"Passed" always means passed within scope. It never proves universal performance, and the distinction is preserved in the state name itself.

DimensionThe question it answers
Task qualityDoes the use perform its defined task within approved scope?
Groundedness / source useAre claims linked to approved, current, permissioned sources?
Failure modesHow does it behave with missing, stale, contradictory, adversarial, or out-of-scope input?
Fairness / differential impactDo errors or burdens differ across relevant groups or contexts?
PrivacyDoes it minimize data and respect purpose, permissions, retention, and provider limits?
Security / abuseCan input, retrieval, tools, or output be manipulated or made to exfiltrate data?
Robustness / reliabilityDoes behavior hold across versions, load, provider failures, and environmental change?
AccessibilityCan users perceive, understand, operate, and correct the experience?
Human factorsCan reviewers understand, question, and override output without automation bias?
Misuse / prohibited useCan the capability be repurposed for surveillance, discrimination, coercion, or unauthorized decisions?

Six evaluation result states

Passed within scopeConditionalUnder reviewFailedNot evaluatedExpired / stale

Human factors is not optional

An evaluation that shows a model performs well but that reviewers defer to it uncritically has found a problem, not a success. Automation bias is measured, not assumed away.

Fairness has justified scope

Groups and contexts are selected only where legally, ethically, and analytically supportable. Sample, method, limitations, and excluded populations are reported — and no universal fairness claim is made.

Not evaluated is a real state

If no approved evidence exists for a claimed behavior, the capability is Evidence-Gated or Unavailable. Absence of evaluation is never treated as absence of risk.

Human Controls & Worker Rights

What a Person Can Do With an AI-Assisted Output

A right that exists only in policy is not a control. Each of these is an action available in the interface.

  • Inspect inputs, sources, freshness, scope, model or rule version, and stated limitations.
  • Question request more evidence, or mark the output insufficient.
  • Correct amend the record through the governed correction path, with the original preserved.
  • Reject dismiss a flag or decline a draft, with a reason recorded.
  • Escalate route to an independent reviewer where policy requires.
  • Report raise a concern about the AI-assisted output itself, not just the record.

No coercive framing

No language pressures a reviewer to accept a system output, and no interface makes accepting faster than examining. A human alternative is never concealed.

Worker-facing transparency

Where an AI-assisted output affects a worker's record, that person can see the relevant inputs, purpose, source, limitations, and status within role and policy scope — and can use correction, challenge, escalation, and appeal routes with full decision history.

Human-in-Command Controls

Human-only outcome classes

  • Payroll-impacting approval
  • Disciplinary or misconduct conclusion
  • Employment eligibility or termination
  • Legal or regulatory conclusion
  • Accommodation or protected-context outcome
  • Appeal or grievance outcome

Each requires reviewer eligibility, separation of duties, evidence access, a reason, notification, a challenge route, and preserved history. Neutral pending-review states apply throughout.

Runtime monitoring & operating limits

Current

Objective: detect when a governed use stops behaving as evaluated.

Monitored
Source availability and freshness, output behavior, override and correction patterns, incident signals, provider and tool health
Override patterns matter
A sharp rise in reviewers rejecting an output is a monitoring signal, not a reviewer problem
Operating limits
Scope, volume, and context limits are enforced rather than advisory

Limitations: monitoring coverage is not measured to a published standard, and we make no completeness claim. Where a signal is ambiguous, the capability moves to Under Review rather than continuing silently.

Incidents, correction & suspension

Current

Objective: stop first, explain second — emergency suspension is intentionally easy.

Incident categories
Groundedness failure, prohibited-use proximity, privacy or security event, fairness concern, provider failure, accessibility barrier
Actions
Suspend, narrow scope, roll back, correct, replace, or retire
Recorded
Trigger, affected scope, mitigation, customer and worker communication, and retrospective review

Limitations: exploitable incident detail is never published. Unsafe or unsupported use-case claims may be removed from markup, search, and structured data immediately, followed by an attributable correction record.

Material Change & Re-evaluation

A provider change is a governance event

Triggers requiring re-evaluation

  • Model, provider, or tool change
  • Source, permission, or retention change
  • Purpose, scope, or authority-class change
  • Region or data-handling change
  • Drift-like behavior or incident
  • Legal, contractual, or policy change
  • Review-date trigger

Six Gate Decisions

Each with a required record

ApprovedConditionally approvedEvidence-gatedRejectedSuspendedRetired

Conditional approval carries an automatic suspension trigger. If the condition lapses or its expiry passes without verification, the capability suspends itself rather than quietly continuing. That is the difference between a condition and a hope.

Retirement records the reason, any replacement, the effective date, data and artifact handling, and preserved public history.

Controlled AI Governance Review

Request Non-Public Governance Evidence

Model or system cards, evaluation summaries, provider information, and governance documentation, at a depth appropriate to your role and purpose.

Step 1

What are you evaluating?

Step 2

Scope

Step 3

Optional message and consent

Do not include

Credentials, worker-level records, prompts containing customer data, health information, union or representative details, legal strategy, or security-sensitive findings.

You receive a reference ID. No response time is promised, because none is approved for this route.

Direct Answers

Eight AI Questions

No. Time classification is deterministic and policy-bound — versioned rules producing repeatable output from the same governed inputs, with the rule version, inputs, and reason exposed. Approved machine learning may flag anomalies or source-quality concerns for human review, but that is a separate capability with a separate authority class.