Design Pattern · Sep 10, 2026

Evidence as the Product

A flight recorder for every recommendation and action: what happened, who initiated it, what data was used, which policy and model version were in force, what a human changed on review, and whether it was later judged helpful, neutral or harmful.

Under the pillar Zero Dashboard Experiences

Thesis

In a system that acts, the evidence record is the product. Everything else is an interface onto it.

The argument

Any vendor can produce a recommendation. What makes autonomy defensible a year later, in front of an auditor, is a record that answers a specific set of questions about a specific action taken on a specific day: what was done, what initiated it, which source records were read, what the system did not know at the time, which policy and model version were in force, whether a person reviewed it, what that person changed, and how it turned out.

Two entries in that list are unusual and both are essential. What a human changed on review turns overrides into signal: the nurse who adds that a patient shifted the time of day they take a medication has supplied context no source record contained, and that is exactly the material a model needs. And the later judgment, helpful, neutral, harmful, or not yet assessed, is what allows a claim about the system's value to be checked instead of asserted.

Blocked actions belong in the same record as completed ones. A drafted sentence rejected as ungrounded before anyone saw it is evidence that the grounding check works, and a system that only records what it did cannot demonstrate what it refused to do.

An evidence log listing agent-initiated, human-reviewed and blocked entries, each with a timestamp, an identifier, a description, the model version in force, what changed on review, and a later helpfulness judgment.
The flight recorder, including a blocked entry: a drafted sentence removed as ungrounded before review. Model and policy versions in force are listed beneath. Synthetic operating data.

What a legacy vendor would say

That they already have audit logs; that this volume of provenance is a storage and discovery liability; and that recording model versions invites questions in litigation that no one currently has to answer.

The discovery objection is not frivolous. A rich record is discoverable, and an organization that records what its system did not know at the time has created a document about its own uncertainty. The counter-argument is that the alternative, acting at scale with no such record, is worse in exactly the proceedings the objection is worried about.

What would settle it

A reconstruction test. Pick actions at random from six months ago and ask an independent reviewer to reconstruct, from the record alone, why each one was taken and whether it was reasonable at the time. The proportion reconstructable without asking anyone is the measure. Anything less than complete is an audit exposure.

Open questions

Who adjudicates helpful, neutral or harmful, and on what interval. How long evidence must be retained when a model version is long retired. Whether the record can be made legible to a patient who asks why they were contacted, without becoming a second product.