Practice
Practice Library
“What can institutions do?”
26governance patterns drawn from the PAN framework's lever catalog and the documented case histories: what each one changes in the system, who has the authority to pull it, what it looks like institutionally, and, for every pattern, what can backfire.
Patterns
Structural patterns
Change the system's wiring: what flows where, at what volume.
Pace the pipeline
Backfire notedMatch the flow of AI output to the real capacity of the people who must check it — throughput honesty as a safety control.
Put a verifier on the agent
Backfire notedAttach an independent checking step to the least-supervised operator — in PAN runs, the single highest-leverage move.
Improve the model
Backfire notedThe default instinct — buy or build a better model — is a real lever with an honest, limited reach.
Provenance labeling
Stamp unverified and AI-generated records so people and systems down-weight them instead of inheriting them as fact.
Data minimization
Backfire notedWrite less and keep less: the least data that does the job is the least there is to leak, to contaminate, and to purge later.
Peer-edge governance
Backfire notedGovern the sideways pathways — operator-to-operator forwarding, model-to-model hand-offs, and store-to-store replication — that multiply everything else.
Cross-model verification
Backfire notedAn independent second model across the first's outputs — correlated errors surface as disagreement instead of repeating silently across every case.
Reconcile copied records
Backfire notedCheck a downstream copy against its source before anyone acts on it — so a mistake written once isn't actioned everywhere the copy lands.
Content-aware decontamination
Backfire notedClean the record system by reading what you remove — deleting unread does not reduce contamination, it concentrates it.
Bounded output screening
Backfire notedAn automated gate on model output before it reaches people is a ceiling, not a substitute — hold the flow, but never trust it to clear the errors.
Vetted sources only
Backfire notedRestrict what the model can retrieve to a vetted corpus — a bound on the contamination that open auto-retrieval would carry back in, not a scrub.
Copy checker
Backfire notedA content-aware gate on a replication pathway that holds downstream copies until they are reconciled against source — before they drive enforcement.
Patterns
Procedural patterns
Change what people are required to do, and are given capacity to do.
Risk-tiered oversight
Spend scarce verification where stakes are highest: mandatory correction plus ground-truth checks for the high-stakes tier.
Human-in-the-loop write gating
Backfire notedRequire verified sign-off before anything enters the official record — govern the write, not just the read.
Framing and mirroring reduction
Train people and agents to prompt without leading — cutting the loop where the user's belief manufactures its own confirmation.
Deskilling-arrest mandate
A scheduled step — recertification, blind re-checks, unassisted rotations — that stops the quiet drift toward rubber-stamping.
Understand the system
Fund continuous learning about what the AI deployment is actually doing across the sociotechnical system, so a limited budget can target hidden dynamics and real failure modes instead of guessing.
Structured dissent
Backfire notedMake challenge a scheduled role — rotating second looks, a named devil's-advocate, blameless flagging — so peer checking survives the social pressure that erodes it.
AI literacy & boundary rules
Backfire notedTeach everyone who touches the system what it is and isn't — calibrated trust plus taught boundary rules, closing a documented training gap.
Verification training
Backfire notedTrain staff to actually check AI output — verification as a taught skill, deepest where checking is hardest: conceptual errors.
Patterns
Feedback patterns
Change how the system responds to what monitoring observes.
Deployment circuit-breaker
Backfire notedA pre-authorized clamp-down that fires when a measured signal crosses a threshold — the control Robodebt never had.
State-feedback vigilance
Correction effort that rises when observed error rises, and relaxes when it subsides — oversight as a thermostat, not a setting.
Patterns
Authority patterns
Change who may act: gates, grants, cadences, and review powers.
Connection authorization
Backfire notedNo data pathway exists until someone with authority approved it — the general edge-level access control.
Oversight cadence & retrospectives
Standing review on a mandated schedule — boards, audits, retrospectives — modeled on the actors who actually ended the documented failures.
Vendor quality gate
Procurement as governance: transparency, evaluation access, and exit terms decided while the institution still has leverage.
Conformity assessment gate
Backfire notedA formal pre-deployment authorization step — honestly framed: it changes who may act, not how the system behaves.
Patterns describe what institutions can do; the PAN Lab is where selected patterns can be stress-tested against scenarios, illustratively, with limits stated. For the documented histories behind them, see the Domain Atlas.
Which patterns matter, and in what order, depends on your system's actual shape. Ranking your options on evidence, with what can backfire stated, is engagement work.
Work With 1023AI