ZoikoDigital
Human-in-Command Controls

People remain responsible for consequential decisions

Automation assists — it calculates, classifies, routes, summarizes, and flags. An authorized person reviews the evidence, can disagree with it, and owns the outcome. The affected worker can understand it, correct it, challenge it, escalate it, and see its history.

PrivacySecurityDeterministic ClassificationEvidence LedgerAI Governance

An authorized reviewer weighing the evidence behind a consequential decision before owning the outcome

What this page does not claim

Not "human in the loop" as a slogan. Not that every product action requires manual review. And not that human review guarantees a correct, fair, or lawful result — it guarantees an accountable one.

Authority invariant

A flag is evidence for review, not a decision.

Classifications, anomalies, exception states, scores, recommendations, and summaries cannot become automatic payroll, disciplinary, employment, or legal conclusions. There is no plan, tier, contract, or administrative setting that changes this — it is not a configurable behaviour.

Automation may calculate, classify, route, summarize or flag within an approved boundary. It may not convert those outputs into a consequential outcome without an authorized, attributable human decision.

Human-Only Decision Classes

Eight Outcomes That Automation Never Reaches

Consequence depends on the use and the outcome, not on the feature name. A low-risk calculation becomes consequential the moment it determines someone's pay.

Decision classHuman-only requirementProduct-supported control
Payroll-impacting approvalFinal approval or rejection of hours, breaks, adjustments, rates, or records that materially change pay.Source lineage, rule version, comparison, reason, authorized approval, correction history.
Disciplinary or misconduct conclusionAny finding that a person violated policy, acted dishonestly, or should receive discipline.Neutral flag, evidence review, protected context, reason, notice, challenge — and no automatic conclusion.
Employment eligibility or terminationDecisions affecting hiring, continued employment, termination, or material work access.No autonomous decision. Evidence and workflow may support an authorized external process only.
Legal or regulatory conclusionAny conclusion that a person or organization complied, breached, owes, is liable, or holds a legal status.Records and policy context shown; authorized professionals decide outside automatic classification.
Accommodation or protected-context outcomeDecisions materially affecting a request or protected circumstance.Restricted evidence, need-to-know access, conflict routing, human-only outcome.
Appeal or grievance outcomeAffirming, changing, remanding, or superseding a contested outcome.Independent authority, new evidence, reason, linked history.
Customer-specific security or privacy dispositionDeciding to disclose restricted evidence or to conclude an incident or request.Authorized security or privacy review, access level, reason, audit.
Public operational conclusionIncident impact, recovery, resolution, or any data-integrity conclusion.Authorized operations review and source-governed evidence.

Two things this list is not

It is not a universal legal definition of "consequential" — that varies by jurisdiction and context. And it does not imply that low-risk automation is consequence-free in every setting; the same calculation can be trivial in one workflow and decisive in another.

Assistive & Deterministic Actions

What May Be Automated, and What Must Stay Visible

ActionMay automate when approvedMust remain visible & reviewable
Arithmetic & time calculationYes, using versioned deterministic rules.Inputs, formula or rule, rounding, timezone, limitations.
Time classificationYes, as deterministic policy-bound output.Rule version, jurisdiction and context, source, correction route.
Anomaly or quality flagYes — deterministic, or approved ML within declared scope.Reason category, confidence limitation, source quality, human review.
Case routingYes, by role, entity, jurisdiction, workload, and conflict rules.Assignment reason, fallback, reassignment history.
Reminder or escalation timerYes, where policy allows.Timer basis, due state, recipient — and no automatic consequential outcome on expiry.
Evidence summaryYes, including Kairos where approved.Source references, omissions and limitations, human verification.
Proposed decision textOnly where approved, and clearly labelled as a draft.Human author or reviewer, source, edits — and no automatic issuance.
Final consequential decisionNo. Not under any configuration.Authorized human action, reason, evidence, and audit are all required.

Governed Review Lifecycle

Eleven Stages, One of Which Cannot Be Automated

The human-only step is marked. Everything before it prepares evidence; everything after it depends on the decision being attributable.

01

Create case

A signal, request, or exception opens a case with a neutral title.

System
02

Preserve source

Original records are preserved unchanged before anything is assembled.

System
03

Assign authority

Routed to a reviewer eligible for this decision class, scope, entity, and jurisdiction.

System, by policy
04

Present evidence

Source, timestamps, actor, policy version, quality, limitations, and conflicts.

System
05

Check conflicts

Separation of duties, recusal grounds, and delegation validity are verified.

System, disclosed to reviewer
06

Review

The reviewer inspects evidence, may disagree with it, and may request more.

Authorized human
07

Decide, defer, or escalate

Approve, correct, return, request information, defer, abstain, escalate — with a reason linked to evidence.

Human only · no automation
08

Notify

The affected person receives plain-language status, outcome, effective date, and options.

System, human-authored reason
09

Correct or challenge

Correction requests and challenges enter a governed path with the original preserved.

Affected person
10

Appeal

Independent reviewer where policy requires. Original and appeal records stay linked.

Independent authority
11

Close or supersede

Closure is attributable. Supersession preserves prior state and history.

Authorized human

No silent closure, no bulk finalization

A case never closes automatically on a timer. One-click bulk finalization is unavailable for protected decision classes unless separately approved with equivalent review evidence for each case — which largely defeats the point of bulk action, and is meant to.

Review Workspace

Human Review Is Not Rubber-Stamping

A forced approve-or-reject click is not meaningful human control. The interface has to make disagreement genuinely possible.

Always available to a reviewer

  • Inspect the underlying evidence
  • Disagree with a classification
  • Request more information
  • Correct a record
  • Declare evidence insufficient
  • Abstain, defer, or escalate
  • Choose a different outcome entirely

Four workspace panels

  • Case header neutral title, affected person, scope, state, due context, authority class

  • Evidence source, timestamp, actor, policy version, jurisdiction, quality, limitations, conflicts

  • Reviewer role, delegated scope, eligibility, conflict state, separation-of-duties check

  • Action with a required reason linked to evidence

Two interface prohibitions

No default-selected adverse outcome. No dark pattern that prioritizes speed over evidence review — the design must not make approving faster than reading.

Neutral States & Language

Labels describe process, not character

Governed state vocabulary

Needs informationPending reviewUnder reviewDeferredEscalatedCorrectedApprovedRejectedSupersededInsufficient evidence

Never applied from a signal alone

FraudTime theftMisconductNon-compliant

And no negative presumption is hidden in an icon or a colour. Notifications use the same neutral vocabulary as the interface — a worker should never learn from an email tone what the product would not say in text.

Evidence visibility & limitations

Current

Objective: show what supports a case and what remains uncertain, so a reviewer knows when not to decide.

Shown
Source records, collection method, policy and rule version, jurisdiction and timezone context, data quality, related evidence
Also shown
Missing evidence, conflicting sources, and stated limitations
Sufficiency
A case can be marked insufficient evidence — that is a legitimate outcome, not a failure to decide

Limitations: evidence is shown within role, policy, and privacy boundaries — confidential third-party evidence is not exposed. Evidence supports review; it does not prove legal sufficiency.

Human decision & reason

Current

Objective: require an accountable outcome rather than a mechanical confirmation.

Recorded
Reviewer identity and role, authority source and scope, selected outcome, effective timing
Reason
Structured around evidence, policy, and stated limitations — with alternatives considered where required
Attached
Conditions, follow-up, downstream handoff, confirmation, and an attributable audit event

Limitations: no system-authored final reason without human adoption and verification — a generated draft is a draft until a person owns it. And a well-formed reason does not prove legal sufficiency.

Notice, Correction, Challenge & Appeal

What the Affected Person Receives and Can Do

A remedy path that depends on knowing it exists is not a remedy. Notice carries the options with it.

Notice

  • Plain-language status and outcome
  • Source and reason, within privacy boundaries
  • Effective date and practical consequence
  • Correction, challenge, escalation, and appeal options
  • Representation or support route where configured
  • Accessible delivery, with acknowledgement where required

Acceptance is never a condition of viewing or challenging an outcome.

Correction & reopening

  • Identify the disputed field, source, and requested change
  • The original record stays visible in governed history
  • A decision may be reopened, remanded, corrected, or superseded
  • Downstream effects and reconciliation are tracked
  • The affected person receives status and outcome

A correction does not automatically mean the original reviewer acted improperly. Evidence changes; that is normal.

Challenge & appeal

  • Grounds, new evidence, requested remedy, and representation where applicable
  • Eligibility and time limits are configurable and jurisdiction-specific
  • Appeal reviewer independence and conflict checks apply
  • Outcomes: affirm, modify, reverse, remand, or request information
  • Original and appeal records remain linked

We do not promise a universal legal appeal right or deadline. An appeal is never routed back to the original decision-maker where policy requires independence.

No silent overwrite, anywhere. Corrections, reopenings, supersession, and appeal all preserve prior state with attributable history. What the record said before remains visible alongside what it says now.

Classification, AI & Kairos Boundaries

Three Mechanisms, None of Which Decides

Not AI

Deterministic classification

Policy-bound, versioned, reviewable.

  • Versioned rules and effective dates
  • Jurisdiction and context aware
  • Explainable trace
  • Correction route on every output
Assistive only

Approved ML & Kairos

Flags and explains. Concludes nothing.

  • ML may flag anomalies or signal-quality concerns
  • Kairos retrieves, summarizes, explains within permission
  • Outputs labelled and reviewable
  • Confidence limitations stated
Sole authority

Authorized human

Reviews, disagrees, decides, owns it.

  • Eligibility and conflict checks passed
  • Reason linked to evidence
  • Attributable audit event
  • Answerable for the outcome

Why classification is not called AI

Deterministic Time Classification is rule-based, versioned, and traceable. Branding it as AI would invite people to trust it in ways a rule engine has not earned — and to distrust it in ways that would be equally wrong. It is called what it is.

The one pattern with no exception

Non-human actors cannot hold final consequential permission. Not by delegation, not by configuration, not by escalation timeout, not in a break-glass scenario. There is no exception treatment for this rule.

Authority, Roles & Separation of Duties

A Manager Title Alone Is Not Authority

An authorized reviewer is someone currently eligible for this decision class, scope, entity, and jurisdiction, with no disqualifying conflict.

PatternDefault controlException treatment
Self-approvalThe requester or affected person cannot approve their own protected consequential decision.Only where formally approved, risk-scoped, and evidenced — never silent.
Rule author vs decision reviewerRule configuration and individual decision authority are separated for high-risk classes.Documented exception, secondary approval, audit.
Original reviewer vs appeal reviewerAppeals are assigned independently where policy requires.If unavailable, escalate and disclose the structural limitation openly.
Evidence preparer vs final approverSeparated for protected or disputed cases.Secondary check, or a documented small-team control.
Administrator vs auditAdministrators cannot delete or rewrite audit evidence of their own changes.Break-glass with an immutable event and review.
Automation vs human authorityNon-human actors cannot hold final consequential permission.No exception.
Support vs customer decisionSupport can explain product records but does not make customer employment or payroll decisions.Route to the authorized customer role.

Recusal is not a mark against anyone. It creates an attributable event with a safe reason category — and produces no negative signal about the reviewer or the worker. Expired, suspended, or conflicted delegation blocks the decision and routes to escalation rather than proceeding.

Control Evidence & Access

Public Commitments and Governed Artifacts

Human-only decision classes

Public

The eight classes, their human-only requirement, and the supporting control.

Owner
Product governance
Reviewed
04 Jul 2026
Status
Current

Limitation: not a universal legal definition of "consequential".

Neutral state vocabulary

Public

Governed state labels and the prohibited accusatory terms.

Owner
Product governance
Reviewed
04 Jul 2026
Status
Current

Limitation: describes product behavior, not your internal terminology.

Separation-of-duties patterns

Public

Default controls and how exceptions are treated per pattern.

Owner
Security & Product governance
Reviewed
01 Jul 2026
Status
Current

Limitation: your configured role model may differ.

Decision audit evidence

Controlled

Audit event structure, immutability controls, and retention approach.

Owner
Security
Reviewed
01 Jul 2026
Status
Current

Access: governed request. Never contains worker-case content.

Rule-change governance

Controlled

How deterministic rule versions are proposed, reviewed, and released.

Owner
Product governance
Reviewed
20 Jun 2026
Status
Current

Access: governed request via Trust Center review pathway.

Worker case records

Never public

Individual cases, reasons, evidence, and outcomes.

These do not appear on any public page, in any form, at any access level. Authenticated routes only.

Direct Answers

Eight Questions About Authority

No. Disciplinary conclusions and employment decisions are human-only decision classes — there is no autonomous path to either, under any configuration. The product may hold evidence and support a workflow, but your organization's disciplinary, grievance, and employment processes remain yours to run, and ZoikoTime does not provide employment advice.