White paper · Public program policy
Policy That Can Explain Itself
Eligibility, Exceptions, Appeals, and Authorized Determinations
Public policy becomes difficult to govern when eligibility, scoring, exceptions, notices, appeals, and funding limits live in separate implementations. This paper proposes a versioned decision model that can expose those relationships while preserving human and institutional authority.
Public funding decisions · 1:10
AI can prepare the award list. It cannot approve it.
Follow the rules, evidence, and exceptions that a responsible person must review before a public award is released.
An authored scenario that explains the idea. Read the story and its limits.
▶ 1:10
Decision anatomy
A public decision is a chain of accountable states.
A defensible result keeps governing authority, accepted facts, represented logic, review, official action, and later challenge connected without pretending they are the same act.
- Legal and policy authorityGoverning source
Bind the applicable statute, regulation, policy, interpretation, owner, and effective interval.
- Source and case recordAccepted case facts
Preserve provenance, observation time, quality state, disputes, missing evidence, and corrections.
- Governed modelEligibility and score
Execute only the represented predicates and arithmetic against the accepted case revision.
- Model plus qualified reviewExceptions and constraints
Stop visibly when a waiver, funding certification, legal judgment, or other named gate is unresolved.
- Program authorityAuthorized determination
Bind the exact reviewed revision to the person or institution holding the real decision right.
- Program and review authorityNotice, challenge, correction
Retain what was issued, what was contested, the accepted review record, the disposition, and every superseding state.
Jump to a section in this paper
A correct formula can still produce the wrong public action
A program rule rarely lives in one place. Eligibility may sit in a case system, scoring in a workbook, exceptions in a desk guide, available funding in a separate ledger, notice language in a template, and appeal history in another queue. When policy changes or a source fact is corrected, staff must discover which copies moved and which did not.
That fragmentation creates more than maintenance work. An eligibility finding can be mistaken for a final determination. A high score can be mistaken for entitlement. An exception can become an undocumented override. A polished notice can conceal the wrong rule revision. A corrected record can overwrite the evidence needed to understand an earlier action.
The public-sector design question is therefore not whether software can calculate a result. It is whether the program can preserve the relationship among governing source, accepted facts, effective policy version, eligibility, scoring, constraints, exceptions, explanation, reconsideration, authorized determination, and record—without assigning software powers that remain legal and institutional.
This paper first describes selected federal requirements and findings. It then presents a separate Grid proposition for making represented policy logic executable and inspectable. The sources do not endorse Grid, and the proposition does not establish legal sufficiency, due process, compliance, or authority for any program.
What the public record establishes
Eligibility depends on facts, yet official data can remain incomplete or inconsistent. In GAO-26-107466, GAO reported that agencies may use more than 100 federal data sources to verify award and payment eligibility. In the nine sources it reviewed, all had data-quality issues and seven had inconsistencies across sources. GAO also cautioned that matches between exclusion and award data did not by themselves establish that an award was improper or involved fraud; each case required specific evaluation. A match is evidence for review, not an automatic determination.
Federal law also places responsibilities around reasons, correction, and records, but their scope matters. For a denial of a written request made in connection with an agency proceeding, 5 U.S.C. § 555(e) generally requires prompt notice and, subject to stated exceptions, a brief statement of grounds. The Plain Writing Act of 2010 requires plain writing in covered federal documents, including communications about benefits and services; it does not make a notice legally sufficient merely because it is readable.
For federal Privacy Act systems of records, 5 U.S.C. § 552a addresses access, requests to amend records, agency review of refusals, and maintenance of information with accuracy, relevance, timeliness, and completeness reasonably necessary to assure fairness in determinations. It also limits information maintained in agency records to what is relevant and necessary to an authorized purpose and requires specified notices when an agency asks an individual to supply information. Those provisions do not resolve every program's correction or appeal process, but they show why fact provenance and contested-state handling cannot be an afterthought.
Substantive review rights are program-specific. For example, 42 U.S.C. § 405(b) assigns Social Security findings and decisions to the Commissioner and provides specified notice and hearing procedures. That statute is not a template that can be generalized to every grant, license, or service. The applicable statute, regulation, policy, delegation, and legal interpretation must define who may reconsider what, on which record, within which time, and with which effect.
Records and fiscal authority remain external controls. 44 U.S.C. § 3101 requires federal agency heads to make and preserve adequate and proper documentation of policies, decisions, procedures, and essential transactions, including records needed to protect legal and financial rights. 31 U.S.C. § 1301(a) limits appropriations to their authorized purposes unless law provides otherwise, while 31 U.S.C. § 1341 restricts obligations or expenditures beyond available amounts or in advance of appropriations absent legal authorization. A modeled funding line cannot create budget authority or obligate funds.
Accessibility and civil-rights obligations also attach to the actual program and surface. The U.S. Access Board explains that the Revised Section 508 Standards govern covered federal information and communication technology, including software, websites, and electronic documents. Title VI of the Civil Rights Act, 42 U.S.C. § 2000d prohibits exclusion, denial of benefits, or discrimination based on race, color, or national origin in covered programs receiving federal financial assistance. Neither accessibility nor civil-rights compliance follows from a reproducible calculation. The actual interfaces, data uses, policy effects, accommodations, language access, and administration require qualified evaluation.
Finally, the March 2026 revision of OMB Circular A-123 places responsibility on management for executive-branch internal control over operations, reporting, and compliance and describes reasonable, not absolute, assurance. The circular distinguishes that OMB guidance from the 2025 GAO Green Book, which is issued by a legislative-branch agency, is effective beginning in fiscal year 2026, and states federal internal-control standards and documentation expectations. Although they have distinct institutional bases, both independently reinforce a practical point: controls need owners, evidence, monitoring, and corrective action. A platform can help produce control evidence; management remains responsible for the control system.
When an executive-branch agency uses AI in the lifecycle, a second control frame may apply. OMB Memorandum M-25-21 directs covered agencies to use minimum risk-management practices for high-impact AI and states that officials retain the authorities and responsibilities established elsewhere in law and policy. That guidance does not turn every human-authored formula into AI, and it does not replace the program-specific legal analysis. It does reinforce the need to identify whether an AI output is merely drafting or summarizing, is materially shaping a finding, or is being treated as the basis for consequential action.
The Grid proposition: one represented policy case
Grid proposes a versioned computational object that keeps distinct parts of a policy case connected without collapsing their authority boundaries.
- Source package: governing citations, approved interpretations, owners, effective intervals, transition rules, and superseded versions.
- Case facts: subject and source identity, observation and effective time, provenance, quality checks, disputes, corrections, missing values, and declared uncertainty.
- Eligibility and scoring: hard predicates remain separate from comparative or discretionary scoring. A passing score cannot cure failed eligibility, and eligibility does not guarantee selection or funding.
- Exceptions: each exception is an authored path with its basis, eligible requester, required evidence, approving role, duration, and effect. An override without such a path remains outside the represented model.
- Resource constraints: represented caps, queues, priority categories, and remaining funds can constrain alternatives, while fiscal officials and source financial systems retain authority over availability and obligation.
- Finding and explanation: a result binds to the facts and policy revision that produced it, identifies material reasons and unresolved issues, and states what the model cannot conclude.
- Review and determination: staff may validate facts, resolve configured tasks, or recommend action. Only the actual authorized person or external process may issue the official determination, notice, payment, license, award, or denial.
When an accepted fact changes, dependent calculations can be reevaluated, and the same case revision can drive audience-specific views for staff, applicants, and oversight bodies, as well as reports and APIs. The earlier revision remains reconstructable. This is the same governed-surface problem examined in One Program Rule, Many Public Surfaces, now applied to a single determination lifecycle.
The model can explain its represented logic; it cannot interpret ambiguous law, decide whether constitutional or statutory due process has been satisfied, invent an exception, judge witness credibility, validate every source, or determine the legal consequence of an error. Those are explicit stops, not missing product features to disguise.
A fictional, non-live program fixture
Consider the North River Public Cooling Grant, a wholly fictional evaluation fixture. It is not a real program, deployed system, legal interpretation, funding recommendation, or automatic eligibility or benefits workflow.
Fictional policy revision NRPCG-27.2 represents a $3 million planning ceiling and a $150,000 per-award cap. Applicants must be a represented public or nonprofit operator, propose a site inside the authored service area, submit a complete package by the cutoff, and provide an accessible operating plan. Eligible applications receive authored points for area heat exposure, weekly public-access hours, backup capability, and implementation readiness. A ranked position is advisory: it does not reserve funds or create an award.
The fixture includes one narrow exception. Alternate evidence of site control may be reviewed when the standard document is unavailable, but only a named fictional program role may accept it. The model can mark the case exception review required; it cannot grant the exception.
Case NR-042 initially carries 12 public-access hours from source revision H-18, producing provisional score arithmetic of 74—below the fixture's current funding line. A draft explanation identifies the policy revision, accepted facts, score components, funding constraint, missing exception decision, and fictional review route. It is not an issued notice, eligibility determination, ranking decision, or reservation of funds.
During pre-determination fact review, a qualified staff member accepts a source correction showing 20 hours in revision H-19. The case advances to a new revision; the original input, result, and draft remain preserved. The provisional arithmetic recalculates to 82, but the case still cannot be ranked because the site-control exception is unresolved. After a separate exception reviewer accepts the fixture's alternate evidence, a source financial record shows only $100,000 remaining against the $140,000 request, with partial awards disallowed. The case becomes funding-constrained, not funded. The authorized fictional program official may then issue the fixture's non-selection determination; Grid performs none of those official acts.
| Revision | Accepted change | Represented result | Authority that remains outside the model |
|---|---|---|---|
r17 |
H-18: 12 public-access hours |
Provisional arithmetic: 74; exception unresolved | No eligibility, ranking, or funding decision |
r18 |
Steward accepts H-19: 20 hours |
Provisional arithmetic: 82; exception unresolved | Fact correction does not grant the exception |
r19 |
Named reviewer accepts alternate site-control evidence | Eligible under the fictional fixture; advisory score 82 | Eligibility does not select or fund the case |
r20 |
Financial source reports $100,000 remaining against $140,000 requested | Funding-constrained; no partial award permitted | Model does not certify availability or obligate funds |
r21 |
Authorized official issues a non-selection determination | Issued notice binds to r20 evidence and NRPCG-27.2 |
Only the program authority issues the determination |
r22 |
Applicant challenges the accepted hours and funding record | Linked review record opened; prior state preserved | Authorized reviewer defines the record and disposition |
This small scenario gives evaluators an oracle: the applicable policy version, expected calculations, required stop states, correction path, explanation fields, and authority boundary. It does not show that the policy is lawful, equitable, accessible, adequately funded, or effective.
Notices, reconsideration, and correction are separate acts
A useful explanation packet can assemble the accepted facts, policy revision, calculation path, material reasons, uncertainty, missing evidence, and next configured step. A notice is different. The responsible program must determine required content, language, accessibility, service, timing, contact information, appeal instructions, and legal review. A generated or templated notice must remain a draft until the authorized process validates and issues it.
A calculation trace and a contestable explanation are also different. The trace shows how represented inputs produced a value. A contestable explanation identifies which fact, source, rule, exception, constraint, and authority produced the consequence; what remains disputed; and which program-defined path can challenge it. The content and timing of that opportunity depend on the governing program and context. The due-process analyses in Goldberg v. Kelly and Mathews v. Eldridge illustrate why the required procedure cannot be inferred from a generic software workflow.
Reconsideration or appeal should open a linked review record, not silently rerun the case. Preserve what was challenged, the record accepted under the program's applicable timing and scope rules, new evidence, corrections, applicable policy version, reviewer authority, conflicts, and disposition. A correction should identify its source, reason, actor, and time, then create a new case state while retaining the earlier state. Whether the correction applies retroactively, changes a prior determination, requires a new notice, or affects payment is a program and legal decision.
Privacy minimization, records schedules, disclosure restrictions, accessibility tests, civil-rights review, and equity analysis must operate across that lifecycle. Protected characteristics should not enter a model merely because they are available; when they are lawfully needed for administration or evaluation, purpose, access, use, and retention require program-specific governance. Subgroup analysis can reveal disparities for investigation, but it cannot by itself establish discrimination, causation, or legal compliance.
A bounded evaluation, with receipts
Begin with one decision class and no live public consequence. Freeze the policy source, effective date, delegations, fixture data, expected results, and stop conditions before configuring Grid. Compare the proposed workflow with the current baseline: manual rekeys, rule-version disagreements, elapsed review time, notice correction rate, exception handling, funding reconciliation, appeal reconstruction effort, and unresolved cases hidden as completed.
Seed failures deliberately: a stale policy version, an effective-date boundary, missing and conflicting facts, a duplicate case, a threshold edge, an unauthorized protected attribute, exhausted represented funds, an exception beyond delegation, an unauthorized determination attempt, an inaccessible draft notice, a correction after determination, and an appeal evaluated against the wrong revision. Predefine whether each case should reject, remain unresolved, request evidence, route to review, or stop.
Measure at least six layers:
- Source and version integrity: material facts retain provenance and time; the correct policy revision applies; disputes and uncertainty stay visible.
- Calculation fidelity: independently calculated eligibility, scores, constraints, and exception states match; repeated runs are reproducible within the fixture.
- Explanation and notice support: qualified reviewers identify material facts, reasons, missing evidence, next steps, and limits; draft defects are detected before issue.
- Authority and correction: every official-state transition requires the fixture's authority evidence; seeded unauthorized actions are blocked; prior and corrected states remain reconstructable.
- Rights and control review: privacy, records, accessibility, equity, civil-rights, legal, and fiscal reviewers can inspect the artifacts they require without treating a technical pass as their approval.
- Work and coordination: compare rekeys, handoffs, inconsistent views, exception cycle time, reconsideration reconstruction time, and defects found after the represented decision point.
Retain the receipts: source snapshots, policy packages and hashes, data dictionaries, fixtures, expected and executed results, uncertainty and exception records, explanation and notice versions, reviewer actions, delegation evidence, appeal and correction links, accessibility results, environment manifest, defects, deviations, and signed evaluator findings.
Report evidence on the Grid FYI evidence ladder: conceptual architecture; illustrative fixture; research-grounded institutional context; product demonstration in declared cases; customer-controlled testing with actual sources and operators; and independently validated claims with disclosed method and boundary. Advancement is claim-specific. Calculation fidelity does not establish legal sufficiency, compliance, certification, authorization to operate, deployment readiness, program effectiveness, or public outcome.
Make the boundary as visible as the answer
The practical next step is to walk the shorter eligibility decision use case, pair it with the full authority-contract paper and evaluation guide, then record the baseline and acceptance evidence in the decision evaluation worksheet. Implementation teams can inspect Grid Developers guidance for explaining and validating a changing decision and canonical examples.
A policy that can explain itself is not a policy that can authorize itself. The stronger objective is a determination lifecycle in which the represented facts, rule, calculation, exception, reason, correction, review, and authority remain distinguishable—and reconstructable—when the answer is challenged.
Related films, scenarios, and next steps
Continue exploring
Follow the next question.
Authorize and Correct a Public Warning Across Evidence, Channels, and Jurisdictions
Connect incident evidence, scoped public-warning permissions, exact-message authorization, channel-specific receipts, and versioned corrections without treating technical acceptance as public receipt or a model as warning authority.
Understand · GovernSource-grounded ExploreHow Grid Works: From Typed Facts to Accountable Action
A technical and operational guide to the six-stage Grid chain: governed sources, a shared and versioned model, reactive constraint evaluation, coordinated surfaces, explanation and evidence, and AI assistance bounded by human authority.
Understand · EvaluateSource-grounded ExploreExplain Eligibility Decisions Without Hiding Exceptions
Keep governing sources, accepted facts, hard eligibility gates, scoring, exceptions, funding constraints, explanations, corrections, and authorized determinations distinct throughout a public-program decision.
Understand · GovernSource-grounded Explore