Many consequence-bearing systems reduce human judgment to two buttons:
APPROVE
or
REJECT
That may be convenient for workflow design.
It is not sufficient for serious governance.
Reality is not always binary.
Evidence may be incomplete.
Conditions may have changed.
Authority may be uncertain.
The proposed action may be valid only within additional constraints.
The person receiving the decision may not possess standing to determine it.
A defect may be correctable.
Another authority may be required.
Or the available evidence may simply be insufficient to permit consequence.
The TA-14 Admissible Human Intervention Architecture therefore establishes explicit Human Intervention States.
Each state means something different.
Each changes the consequence route differently.
And none should be silently converted into another state merely to keep execution moving.
Consider a reviewer who receives insufficient evidence.
The interface offers:
APPROVE
REJECT
What should the person do?
Approval would manufacture certainty.
Rejection may imply that the proposed action has been substantively determined to be wrong.
But neither conclusion is supported.
The actual determination is:
A binary workflow forces a human to answer a question the evidence cannot support.
That creates governance distortion.
TA-14 instead requires the system to preserve the actual state.
ALLOW means the human has sufficient standing and the consequence route satisfies the conditions required for progression within the declared scope.
ALLOW does not mean:
“Everything is safe.”
“Nothing can go wrong.”
“The human guarantees the outcome.”
It means:
An ALLOW determination should be bounded to:
the specific action,
the specific scope,
the operative state,
the applicable authority,
the relevant evidence,
and any applicable time boundary.
An ALLOW should not become a reusable permission for unrelated execution.
Sometimes execution can proceed, but only if additional controls remain in force.
Examples:
reduced scope,
limited duration,
enhanced monitoring,
human presence during execution,
specific thresholds,
restricted permissions,
additional evidence capture,
rollback readiness,
or mandatory outcome review.
That is:
A Controlled Allow is not a weak approval.
It is a bounded authorization state.
The controls are part of the determination.
If those controls disappear, the authorization may disappear with them.
HOLD is one of the most important states in AHIA.
It means:
A HOLD may result from:
missing evidence,
stale evidence,
continuity uncertainty,
verification requirements,
authority questions,
dependency changes,
pending second review,
unresolved conflict,
or insufficient intervention time.
HOLD preserves uncertainty without manufacturing a conclusion.
The system should:
stop progression,
preserve state,
preserve evidence,
identify the unresolved condition,
and establish what must occur before reassessment.
It does not automatically mean no.
A HOLD state is meaningless if downstream execution continues anyway.
When HOLD is entered:
commitment should stop,
dependent actions should stop where required,
new reliance should be prevented,
the relevant state should be preserved,
and the route should remain suspended until declared release conditions are satisfied.
A system that records HOLD while continuing consequence-bearing execution has not implemented HOLD.
It has implemented a label.
DENY means the evidence and governing conditions support a determination that the proposed route should not execute.
The denial should preserve:
what was denied,
why,
under what authority,
on what evidence,
and whether reconsideration is possible.
DENY should not necessarily mean:
forever prohibited.
Some denials may be specific to:
the current evidence,
the current state,
the current scope,
the current authority,
or the current proposal.
If conditions materially change, a new route may require a new determination.
ESCALATE means the current human possesses enough standing to recognize that they should not carry the final consequence.
Reasons may include:
authority limits,
scope limits,
insufficient competence,
conflicting evidence,
high consequence,
legal or rights-based questions,
exception conditions,
conflict of interest,
or requirements for independent review.
Escalation is not indecision.
It can be an admissible determination.
When escalation occurs, the architecture should preserve:
the current state,
the evidence,
the unresolved question,
the reason for escalation,
the originating human determination,
and the authority being requested.
Execution should not continue simply because escalation takes time.
Where the decision requires resolution before consequence:
Sometimes the problem is identifiable and repairable.
Examples include:
incorrect evidence,
wrong configuration,
invalid input,
expired authority,
missing record,
scope mismatch,
or a known technical defect.
The appropriate state may be:
CORRECT means:
identify the defect,
preserve the pre-correction state,
perform the bounded correction,
record what changed,
then re-establish the required evidence before reconsidering progression.
Correction should not silently convert into approval.
This is especially important because intervention itself changes reality.
Once the human corrects something, the original evidence may no longer represent the current state.
Therefore:
That New Reality may require:
new evidence,
new continuity,
new diagnosis,
and a new determination.
The person should not rely automatically on the pre-correction determination.
This state protects both the person and the system.
A reviewer may understand the issue perfectly and still lack authority to determine it.
A technical expert may identify the correct action but lack organizational authority.
An executive may possess broad authority while lacking professional standing for a specialized determination.
The appropriate response is:
This is not failure.
It prevents authority from expanding merely because the person is available.
The route should identify the appropriate authority or enter escalation.
These states are related but distinct.
describes the standing of the current participant.
“This determination is not mine to make.”
describes the route transition.
“This condition must be routed to another authority.”
An OUTSIDE SCOPE determination will often produce ESCALATE.
But preserving both states tells us why authority moved.
This is stronger than HOLD.
HOLD says:
More evidence or resolution may permit reconsideration.
NOT ADMISSIBLE says:
Possible reasons include:
reality cannot be reliably established,
evidence integrity is materially compromised,
continuity cannot be restored,
authority cannot be validated,
the intervention window has collapsed,
human standing cannot be established,
verification is impossible,
or the route itself lacks sufficient governance.
NOT ADMISSIBLE prevents the system from pretending that uncertainty is merely an ordinary delay.
A route may become admissible later if the underlying defect is genuinely resolved.
But that requires a new governed state.
The architecture should not simply remove the NOT ADMISSIBLE label and resume.
It should establish:
what changed,
what evidence proves the change,
whether continuity has been restored,
and why the new route now possesses sufficient standing.
Human Intervention States are not:
“I feel comfortable.”
“I don't like this.”
“This seems okay.”
“I think we should probably proceed.”
They are governed determinations.
Each state should be supported by:
evidence,
standing,
authority,
scope,
and declared decision criteria.
Human judgment may be part of the determination where appropriate.
Unsupported preference should not substitute for governance.
A mature AHIA implementation should not preserve these states only in prose.
They should become structured governance objects.
For example:
Determination State: HOLD
Reason: Evidence continuity failure
Authority: Human Role H-17
Scope: Release R-482
Timestamp: Preserved
Commit Status: Blocked
Required Resolution: Re-establish current production state
Escalation: Not required
Revalidation Required: Yes
This allows the rest of the execution architecture to respond deterministically.
A route may transition:
HOLD → ALLOW
or
HOLD → DENY
or
ESCALATE → CONTROLLED ALLOW
or
CORRECT → HOLD → ALLOW
or
NOT ADMISSIBLE → reconstructed route → new determination
But transitions require evidence.
The architecture should be able to answer:
A human should not simply click a different button until the desired state appears.
If one human determines:
HOLD
and another person later enters:
ALLOW
the original determination should not disappear.
The record should preserve:
who issued HOLD,
why,
what evidence existed,
who changed the state,
what authority permitted the change,
what new evidence existed,
and why progression became admissible.
Where multiple humans participate, disagreement may be important.
Suppose:
Reviewer A: DENY
Reviewer B: ALLOW
Authority C: CONTROLLED ALLOW
The final determination should not erase the preceding disagreement.
The record should preserve the dissent and the evidence supporting it.
This becomes especially important if later outcomes validate the minority concern.
Some consequence routes may require more than one human.
AHIA can support:
One human with sufficient standing determines.
Two independently qualified authorities must concur.
One determination requires independent verification.
The determiner cannot also perform another consequence-bearing role.
Multiple governed participants contribute to the final state.
The required class should be established before the consequence route begins.
This returns to a foundational TA-14 concern.
If timestamped evidence, multiple witnesses, preserved continuity, declared thresholds, and diagnostic criteria establish a condition, a human should not be able to erase that condition simply by clicking:
ALLOW
Human intervention is not a license to corrupt evidence.
Where a human departs from the evidence-supported determination, the architecture should require a governed basis for that departure.
Not every state must originate from a human.
A governed system may automatically enter:
HOLD
when evidence becomes stale.
NOT ADMISSIBLE
when authority cannot be validated.
CORRECT
when a known bounded remediation is required.
Or DENY
where explicit deterministic criteria prohibit progression.
The human may then enter only where the decision class requires human standing.
This preserves the TA-14 principle:
Where a required condition cannot be established, the default should not silently become ALLOW.
A mature architecture should prefer:
unknown evidence → HOLD
invalid authority → NOT ADMISSIBLE
outside authority → OUTSIDE SCOPE / ESCALATE
correctable defect → CORRECT
prohibited condition → DENY
bounded acceptable condition → CONTROLLED ALLOW
fully supported progression → ALLOW
This is fail-closed determination logic.
Several AHIA states intentionally prevent execution:
HOLD
DENY
ESCALATE
CORRECT
OUTSIDE SCOPE
NOT ADMISSIBLE
When those states successfully prevent an unsupported consequence, the absence of execution is itself meaningful.
TA-14 calls this:
The record should preserve:
what would have occurred,
what state prevented it,
what evidence supported the intervention,
and what happened afterward.
Successful restraint should not disappear simply because nothing happened.
→ ALLOW
→ CONTROLLED ALLOW
→ HOLD
→ DENY
→ ESCALATE
→ CORRECT
→ OUTSIDE SCOPE
→ NOT ADMISSIBLE
The state should follow the governed condition.
The desired business outcome should not determine the state.
The purpose of AHIA is not to give humans more buttons.
It is to give consequence-bearing systems more truthful governance states.
Sometimes the truth is:
Sometimes:
Sometimes:
Sometimes:
Sometimes:
Sometimes:
Sometimes:
And sometimes:
A serious governance architecture must be capable of preserving all of them.
Now that the intervention states are defined, the next question is:
The next page establishes the six Human Intervention Admissibility Levels, from mere human presence to route-complete human governance.
AHI-0 — Presence Only
AHI-1 — Recorded Human Review
AHI-2 — Bounded Human Intervention
AHI-3 — Admissible Human Intervention
AHI-4 — Pressure-Survivable Human Intervention
AHI-5 — Route-Complete Human Governance
[EXPLORE AHI-0 THROUGH AHI-5 →]
TA-14 Admissible Human Intervention Architecture
Do not force certainty where admissibility does not exist.
No admissible evidence. No admissible execution.