IThe oldest instrument in the building

Somewhere in your company — a drawer, a policy portal, an annex to the articles of incorporation — there is a document that says who may sign what. The new analyst may commit the firm to five hundred euros; the department head to fifty thousand; above that, two signatures, one of them from the board. Banks have run on this for centuries: maker and checker, the four-eyes principle, limits per person, per amount, per day. Nobody calls it a philosophy. It is simply how you keep a company from being spent by whoever happens to be holding a pen.

Notice what that document really is: a map of exactly how much judgment the organization lends each of its people — written before anything goes wrong, reviewed when circumstances change, enforced without offense. No one is insulted by a signature limit. It is not distrust. It is architecture.

Then, sometime in the last three years, a new kind of employee arrived — software that drafts, prices, answers, filters, orders — and in most companies it walked straight past the drawer. The intern has a spending limit; the agent answering your customers all night does not. The clerk needs a second signature above ten thousand euros; the model that reorders stock, reprices the long tail or screens applicants was granted, on day one and in silence, more discretion than any human being was ever given in writing.

In the previous article I argued that a machine can be given execution but never accountability, and that the workable principle is a perimeter: the machine acts inside a boundary a human has signed, and a named person answers for the boundary itself. I also promised honesty about the hard part — where, exactly, the boundary should run — and said it deserved an article of its own. This is that article. The answer, it turns out, is not a doctrine. It is a discipline: five questions, asked of every class of decision, one class at a time. And the instrument that holds the answers is the one your company already trusts — the authority matrix, extended at last to the employee who never sleeps. We call it the decision charter.

Every company that has adopted AI already has a decision charter. In most of them, nobody wrote it: it is the sum of vendor defaults, individual experiments and silence. The only real choice is between the charter you wrote and the one you didn't.

IIFive questions

Here are the questions we ask, in order, of any class of decision a machine could take. None of them is exotic; together they place a line.

What breaks, and can it be unbroken? Consequence and reversibility — the classic axis, and the only one most frameworks bother with. A cancelled purchase order is not a shipped container; a re-sorted product page is not a rejected loan. Cheap and reversible earns a wide perimeter; expensive or irreversible narrows it. One warning, carried over from the drift argument: measure reversibility honestly, at the aggregate. A thousand individually reversible decisions, all leaning the same way, can add up to one irreversible drift.

What does it touch? Two decisions with identical price tags are not identical in the world. A discount is not a diagnosis; a shipment is not a child's essay. Some subjects outrank arithmetic — health, a livelihood, a person still in formation — and on those subjects the question is not whether the machine would perform well. It is whether performance was ever the point.

How fast must it be? Genuine urgency is the strongest honest argument for machine autonomy: some decisions live on clocks no human can keep, and waiting is the irresponsible choice. But genuine is the operative word — most "this must be real-time" claims dissolve under one question about what the extra hour would actually cost.

Who defined "urgent"? The question before the previous one, and the one almost nobody asks. Urgency is a classification, and someone makes it. If a named human classified this decision as time-critical, in daylight, in advance, with the reasoning written down — the label is governance. If the label arrived inside the vendor's onboarding defaults, or expands quietly every quarter because asking a human is friction — the label is the costume that convenience wears. In a well-run company, "urgent" is a word the charter defines, not a word the system claims.

What does deciding teach? The question that exists nowhere in the compliance literature and matters most for what your company becomes. Every decision class is also a training ground: the analyst who prices, errs and corrects is acquiring the calibrated judgment your firm will need in a crisis the model has never seen. If the honest answer to "who learns from this decision?" is the future leadership, keep it human — deliberately, at a known cost in efficiency. You are not buying the decision. You are buying the decider.

Five questions, no scorecard. They do not produce a number; they produce a conversation that ends in a written line — and two honest companies, asking them of the same decision, will sometimes write different lines. That is not a flaw in the method. It is the method. In an economy where everyone rents the same capability, your charter is one of the few documents a competitor cannot buy.

IIIFour decisions, four lines

Watch the questions work. Four ordinary decisions; the line lands in four different places.

The replenishment order. An industrial planner's daily bread: restock or don't, how much, when. Consequence is graded and mostly reversible below obvious thresholds — a modest order for a stable C-class part risks a little cash for a while; an A-class commitment before a demand shift risks the quarter. Subject: neutral. Urgency: moderate. Teaching value: real, but concentrated in the exceptions. So the line writes itself in two clauses: C-class item, value under the ceiling, stable supplier, no anomaly flags — the machine orders, and the ledger records it. Anything above the ceiling, any A-class item, any anomaly — a proposal, with its evidence attached, waits for a named planner. The ceiling itself is the point: it is a signed number with an owner and a review date — not a vendor default that nobody remembers agreeing to.

The refund. Here the arithmetic says automate everything: small sums, trivially reversible, high volume. The arithmetic is wrong, and the second question says why. The angry customer is not a cost line; the way your company treats them at their worst moment is, concretely, your company — this is exactly where the personality of the firm lives, and exactly where the drift toward everyone-else's-tone does its quiet damage. And the fifth question adds: this is where juniors learn the firm's voice. So the line sits higher than the euros suggest: the machine resolves the routine and drafts everything; a human sends every response above a value threshold or carrying any distress signal; and once a week a human reads a sample of what the machine resolved alone — not hunting errors, keeping the voice.

The hiring screen. The seductive case, because each unit looks harmless — one CV re-reviewed on appeal, what could be irreversible? The aggregate could. The screen decides the distribution of people who enter, which is to say it decides the future company; and a model, returning the centre of the distribution it learned, is structurally biased against the improbable great candidate — who is, by definition, off-distribution. The subject is a livelihood, and here society has already pre-drawn a coarse line: European law classes employment screening as high-risk, with human oversight mandated. The charter draws the finer one: the machine may search, sort, surface and summarize; it may not silently reject. Every "no" belongs to a human — or, at the hard-nosed minimum, machine rejections are sampled and audited by a human, and the sampling rate is itself written in the charter.

The fraud block at 3 a.m. The case that keeps the whole argument honest, because here the machine should decide. A card is being drained in real time; urgency is genuine; waiting for a human is the irresponsible choice; the line moves inside the machine. But look at what makes that safe rather than reckless: the envelope was signed in daylight. Which signals count, what thresholds fire, how long a hold may last, how much may be frozen before someone is woken — decided at a desk, at noon, by a person with a name, and written down. By morning, a human owns the apology and the release. Who defined "urgent"? The charter did — not the model at 3 a.m., and not the vendor's wizard. Machine autonomy at its best is not the absence of the line. It is the line, drawn earlier.

IVWhere the answer is no

And then there are the classes where the five questions return an answer that efficiency cannot argue with: not this one — not even done flawlessly.

A grading system could mark essays with superhuman consistency, and a school could buy it tomorrow. The teacher who reads the essays anyway is not being sentimental about technology. Reading them is how the teacher knows the child — which one is coasting, which one broke through, which one is quietly sinking — and the child is not a throughput problem. Delegate the grading and the grades will still arrive; what stops arriving is the knowing. The same structure holds at the hospital bedside, which is why the clinical reference tools we build refuse, by design, to decide anything at all: they cite, and the clinician remains the only author of the judgment. These are the second and fifth questions in their pure form — decisions inseparable from a relationship on one side and a formation on the other.

Statute will draw some of these lines for you, and you should know where it already has. But the law's lines are coarse, drawn for everyone at once, and "the law permits it" has never been the same sentence as "we do it." The fine lines are yours to draw — which is the last reason they are worth drawing: they are one of the few places left where a company gets to say, in writing, what it is.

VOne page

So what does the instrument actually look like? Deliberately boring, and deliberately short.

One page. Down the side, your decision classes — not hundreds; the dozen or two that matter. Across the top, six columns: the class · the named owner · what the machine may do alone · what escalates, and on what trigger · the health signals · the review date. That is the whole anatomy. A charter rather than a registry, because a registry records what happened and a charter grants and bounds authority — though it must live like a registry: current, dated, consulted, versioned.

Three rules keep it honest. Nothing unowned: every class carries a person's name, and "the committee" is not a name. Nothing unsigned: every freedom the machine enjoys traces back to a human signature — including the freedoms that arrived as vendor defaults, because a default you never overrode is a signature you never read. Nothing static: the charter changes only through its own gate, and its history is append-only, so five years from now you can see who widened which perimeter, when, and on what argument.

Keep it to the page. The authority matrix survived centuries because it fits on one; a binder is where accountability goes to hide. And write the first draft this week, in an afternoon, knowing it will be wrong. It will be wrong. Good. Yesterday the same wrongness was invisible and belonged to nobody.

VIHow we hold the line

A charter, like any gate, can die politely — observed in the letter, empty in fact. So we watch a small set of signals on our own systems, and I will offer them here as one practitioner's numbers rather than doctrine.

Rejection rate, per gate. The one from the previous article: a gate that has never said no is a rubber stamp with a salary. But the other tail is a finding too — a gate rejecting most of what the machine proposes means the perimeter is drawn wrong or the machine is not ready, and either way the charter has something to learn.

Reversals. How often does a decision, once through the gate, get unwound? Reversals measure whether the line sits where consequences actually change category, or merely where it was comfortable to draw.

Time-to-decision. The stealth killer. A gate that takes days teaches people to route around it, and shadow delegation — the machine autonomy nobody signed — is born exactly there. A slow gate is not a strict gate; it is a wrong gate, and it is how unofficial perimeters eat official ones.

Review triggers, not just review dates. Quarterly by calendar; immediately after any incident; and — the one that surprises people — after any model or vendor update. An updated model is a different decider standing inside your old perimeter, and it does not send a memo. When the thing inside the boundary changes, the boundary gets re-tested.

In Simon, the planning system we build for industrial companies, this is not an aspiration but a screen: every recommendation waits at its gate with the evidence attached, and the gates' rejection rates sit on the same dashboard as the stock levels. The health of the deciding, monitored like the health of the goods — in a journal no administrator can rewrite.

VIIDrawn in daylight

None of this is new governance. It is the oldest governance there is, applied to the newest employee. Your company already believes, without needing to be persuaded, that no clerk signs above their limit and no payment above a threshold moves on one pair of eyes. All the decision charter adds is the consistency to give the tireless employee a limit too — in daylight, on one page, with names on it.

We named our studio after the Roman surveyor's instrument, and the reason fits nowhere better than here. The groma never built a road. It decided where the road would run — before the first stone, in the open, by a person who could be found afterwards and asked why. That is the whole proposal, and the close of the argument that began two articles ago: someone must answer, by name; a company is what it refuses to delegate; and the rest — everything it does choose to delegate — runs inside lines drawn by a hand that signs.

The line is not where the machine stops. It is where your company begins.

Dan Olea

Founding partner, Groma — AI engineering studio. We build systems for professionals whose decisions carry weight: custossapiens.org · larespecoris.vet · lexvigilans.ro

Principal sources (checked on 31 August 2026):

· Regulation (EU) 2024/1689 (the AI Act) — Annex III (employment among the high-risk classes) and Article 14 (human oversight) · long-standing banking-supervision practice on delegated authority and dual control (the "four eyes" principle, maker–checker) · the cases and research grounding this argument — Moffatt v. Air Canada; the Replit and Deloitte incidents; Anthropic's GTG-1002 disclosure; Klarna's reversal; Doshi & Hauser (Science Advances, 2024); Wingate, Burns & Barney (MIT Sloan Management Review, 2025); Lee et al. (CHI 2025); Elish's "moral crumple zones" — are cited in full in the previous article, "Efficiency is loud. Drift is quiet."