Organization Mode Operational Accountability, Planning Only
Problem Definition
Future Organization Mode needs a closed-loop way to track supplies and equipment such as notebooks, mop heads, cleaning solution, and program materials from report through acknowledgement, review, fulfillment, deferral, or unresolved status.
Future Organization Mode also needs a privacy-safe way to represent common-area detail assignment, completion, legitimate blockers, human verification, rework, reassignment, and excused status.
The shared dependency is essential: a resident must not be represented as failing a detail when the detail could not be completed because supplies, equipment, access, or authorization were unavailable.
This architecture records observable operational events and stated reasons, not inferred motives, staff compensation structures, bonus incentives, budget-preservation theories, or intentional-deprivation claims.
OM-001 Phase Identity
Phase
OM-001
Status
planning-only no-go
Implementation authorized
false
Live workflow active
false
Primary roadmap next phase
Phase 11.17 - Individual Mode Handoff Freeze
Parallel next phase
OM-002 - Synthetic Operational Accountability Prototype
Governing Principles
closed-loop-accountability
Operational needs, assignments, blockers, review, and closure should eventually be traceable from first report through final disposition.
dual-responsibility-visibility
Resident responsibility and organizational responsibility must both be visible in future workflow design.
blockage-vs-non-completion
Operational blockage must be distinguishable from individual non-completion.
events-and-reasons-not-motives
The architecture records observable events and stated reasons, not inferred motives, staff compensation theories, bonus incentives, or budget-preservation assumptions.
human-review-required
Human review remains required for blockers, disputes, verification, rework, reassignment, excused status, and closure.
minimum-necessary-data
Future data collection must be limited to the minimum necessary operational labels and evidence.
no-public-individual-scoreboards
The system must not create public individual scoreboards, resident leaderboards, staff leaderboards, or public failure lists.
no-clinical-interpretation
Operational accountability must not become diagnosis, treatment-progress interpretation, risk prediction, or clinical monitoring.
no-automated-discipline
No automated discipline, privilege automation, or punitive shortcut may be derived from operational records.
Needs and Supplies Ledger
Future closed-loop ledger for needed supplies, equipment, access, authorization, or program materials such as notebooks, mop heads, cleaning solution, and common-area program materials.
Planning labels only. No forms, schemas, endpoints, tables, storage, mutations, submissions, approvals, request records, or database behavior are created.
Future Request Lifecycle
Future Defer / Unable Reason Labels
Planning Field Labels Only
Closure Rules
- A future request may close only through fulfilled, deferred, unable-to-fulfill, or cancelled-or-duplicate disposition labels.
- Fulfilled should require appropriate requester confirmation when confirmation is appropriate.
- Deferred and unable-to-fulfill require a stated reason label and, when other-with-explanation is used, a brief explanation.
- Alternative-provided must preserve the original need and the substitution rationale.
- Closing a supply request does not automatically verify any linked detail.
Dispute Rules
- Future requester disagreement must remain reviewable without public display.
- Disputed closure should preserve the stated requester concern and reviewer response as event labels only.
- Dispute handling must not infer motive or compensation behavior from delay, denial, or aging patterns.
Detail Assignment and Verification
Future privacy-safe workflow for common-area detail assignment, completion, legitimate blockers, human verification, rework, reassignment, and excused status.
Planning labels only. No assignment runtime, submissions, blockers, confirmations, disputes, review actions, rework actions, photo handling, image storage, uploads, camera capture, EXIF handling, computer vision, AI review, or database behavior are created.
Future Detail Lifecycle
Future Blocker Reasons
Future Evidence Modes
Human Review Model
- Verification remains a human review action in any future pilot.
- A blocked state requires human review before it can become rework, reassignment, excused, or closed.
- Needs-rework should explain the observable issue without shaming or ranking the resident.
- Excused status must be available when completion was not reasonably possible or was formally excused.
- No AI-based pass/fail decision, image-based scoring, or automated discipline is allowed.
Dispute Rules
- A resident must be able to dispute a verification outcome, rework request, non-completion interpretation, or blocker rejection.
- Disputes must preserve observable events and stated reasons, not inferred motive.
- Dispute outcomes must not expose another resident evidence or private Individual Mode data.
Shared Blocker Linkage
- A detail may be blocked by a needs/supplies request.
- A blocked detail is not equivalent to non-completion.
- A missing-supply blocker should be capable of referencing an existing request only after live workflow authorization.
- A missing-supply blocker should be capable of initiating a future request only after live workflow authorization.
- Closing the supply request does not automatically verify the detail.
- Verifying the detail does not erase the supply-delay history.
- A detail blocked by required supplies should preserve both resident action history and organizational delay history.
- The relationship must preserve observable events and stated reasons without inferring staff motive, bonus incentives, compensation structures, or budget-preservation behavior.
Future Role Labels Only
resident
Status: label-only
Future Responsibilities
- May eventually view own request labels and own detail labels.
- May eventually state blockers, request review, and dispute future outcomes.
Prohibited Interpretations
- Not a public score subject.
- Not presumed non-compliant when a blocker exists.
- Not exposed to another resident evidence or private recovery data.
Role label only. No account, identity, permission, RBAC, assignment, or access-control implementation exists.
expeditor-or-house-operations
Status: label-only
Future Responsibilities
- May eventually acknowledge needs, coordinate ordering or alternatives, and update operational request status labels.
- May eventually identify operational blockers that require supply, equipment, access, or authorization resolution.
Prohibited Interpretations
- Not a motive label.
- Not a compensation or budget-incentive inference.
- Not a unilateral discipline authority.
Role label only. No account, identity, permission, RBAC, assignment, or access-control implementation exists.
staff-reviewer
Status: label-only
Future Responsibilities
- May eventually verify detail completion, review blockers, request rework, confirm excused status, or route disputes.
- May eventually review restricted evidence under approved privacy policy.
Prohibited Interpretations
- Not an automated pass/fail engine.
- Not clinical reviewer visibility by default.
- Not authorized to expose private Individual Mode reflections.
Role label only. No account, identity, permission, RBAC, assignment, or access-control implementation exists.
program-leadership-or-quality-assurance
Status: label-only
Future Responsibilities
- May eventually review aggregate house-level patterns, aging, blockers, and unresolved closure risks.
- May eventually oversee correction, retention, policy, and rollout gates.
Prohibited Interpretations
- Not a staff leaderboard.
- Not compensation calculation authority.
- Not public individual ranking or discipline automation.
Role label only. No account, identity, permission, RBAC, assignment, or access-control implementation exists.
Visibility and Privacy Matrix
own request
Future visible to role labels: resident, expeditor-or-house-operations, staff-reviewer
Limited to the requester and appropriate operational reviewers after authorization.
planning-only visibility concept; no access-control implementation exists
own detail
Future visible to role labels: resident, staff-reviewer
Limited to the assigned resident and appropriate reviewers after authorization.
planning-only visibility concept; no access-control implementation exists
operational review queue
Future visible to role labels: expeditor-or-house-operations, staff-reviewer
Work queue labels only after authorization; no public resident failure list.
planning-only visibility concept; no access-control implementation exists
aggregate house-level patterns
Future visible to role labels: program-leadership-or-quality-assurance
Aggregate review only after approval; no individual leaderboard or staff leaderboard.
planning-only visibility concept; no access-control implementation exists
restricted evidence
Future visible to role labels: staff-reviewer
Restricted by evidence policy; no resident access to another resident evidence and no public display of photographs.
planning-only visibility concept; no access-control implementation exists
audit history
Future visible to role labels: program-leadership-or-quality-assurance
Reviewable event history after approval; minimum necessary access and retention.
planning-only visibility concept; no access-control implementation exists
Privacy Boundaries
Photo and Evidence Boundary
- photos are optional and detail-specific, not universally required
- no photos in bathrooms, bedrooms, medication areas, clinical offices, or confidential spaces
- no intentional capture of other residents
- human verification alternative must exist
- future metadata stripping is required before any live pilot
- shortest defensible retention period must be decided before activation
- no face recognition
- no automated cleanliness scoring
- no AI-based pass/fail decision
- no permanent surveillance archive
Measurement Boundary
Future operational measures may be considered only after approval and only for operational review, not for individual ranking, discipline, privilege logic, or compensation calculations.
May Be Considered After Approval
Explicitly Blocked
Motive-Neutral Evidence Stance
- Record request events, detail events, blocker labels, reason labels, review labels, and dispute labels.
- Do not assert intentional deprivation.
- Do not assert staff compensation, bonus incentive, or budget-preservation motive.
- Make delays, denials, aging, fulfillment, and blocker patterns reviewable without encoding motive.
Phased Rollout Plan
OM-001: architecture and governance
Status: current-planning-only-no-go
Implementation authorized: false
Live workflow active: false
OM-002: synthetic interactive prototype
Status: parallel-next-planning-only
Implementation authorized: false
Live workflow active: false
OM-003: needs and supplies ledger pilot
Status: blocked-unauthorized
Implementation authorized: false
Live workflow active: false
OM-004: detail accountability pilot
Status: blocked-unauthorized
Implementation authorized: false
Live workflow active: false
OM-005: inventory, maintenance, and shift handoff
Status: blocked-unauthorized
Implementation authorized: false
Live workflow active: false
OM-006: aggregate oversight and institutional rollout
Status: blocked-unauthorized
Implementation authorized: false
Live workflow active: false
OM-003 and later remain blocked and unauthorized.
Activation Gates
- external staff/privacy review
- resident input on burden, fairness, and dispute process
- named data owner
- identity and authentication decision
- access-control and RBAC design approval
- retention and deletion approval
- evidence/photo policy approval
- shared-device logout/session policy
- incident response and correction process
- legal/compliance review appropriate to the organization
- technical threat model
- pilot success and stop criteria
Stop Conditions
- pressure to use photos universally
- use as a disciplinary shortcut
- inability to distinguish blockers from non-completion
- inability to correct or dispute records
- request closures without requester confirmation where confirmation is appropriate
- public individual ranking
- cross-mode access to private recovery data
- use of the system to infer staff motive or compensation behavior